Back to News
RSS feedwww.eff.org

EFF Urges Lawmakers to Base AI Cybersecurity Rules on Best Practices

Summary

The Electronic Frontier Foundation (EFF) says lawmakers considering frontier AI regulation should prioritize demonstrated cybersecurity risks at AI laboratories rather than focus mainly on catastrophic scenarios. Citing reported breaches, including the OpenAI–Hugging Face incident, the organization argues that existing cybersecurity practices could have prevented or substantially reduced the incidents currently known. It recommends minimum requirements when an AI developer or deployer conducts a test or task likely to harm third parties, such as attempting to access another person’s computers. Those activities should take place in properly sandboxed environments disconnected from other systems, with monitoring and logging in place. EFF argues that legislation should be tied to established, evidence-backed security protocols instead of requirements limited to today’s AI technologies, allowing the rules to remain useful as technology changes. It also calls for laws to mandate and fund independent third-party investigations into serious incidents during AI lab testing, with investigation reports made public. The organization says this transparency would strengthen public oversight, while emphasizing that any cybersecurity regulation should be precise, practical, and careful not to impede future AI development.