House language — how this project describes frontier AI, and how it describes the people who ship it
A drafting rule, adopted 21 August 2026. It governs the project’s own voice. It does not govern quotations, which are reproduced exactly as their authors wrote them, including where their wording is the wording this rule avoids — see § 4, which is the most important section here.
Who this is about
About: the officers of frontier developers — the companies training models above 10²⁶ operations, or spending nine figures on a single training run. On the enacted family’s own thresholds that is a double-digit number of firms worldwide, and inside them a smaller number of people who decide what ships.
Not about: open-source contributors, startups, academic researchers, hospitals, schools, employers, small operators, ordinary deployers and API customers, or users. On deployers, precisely: the Act has always defined deployer as a covered class (SEC. 1(b)(3)) and has always given the thin ones a route to discharge the duty rather than an exemption from it — adopt the upstream validation, keep the manifest, monitor, report (SEC. 2(b)). What the open queue would add at CURE 7 reaches a deployer only at consequential scale — mass market, or into government, military, financial, health or critical-infrastructure functions — and only for its own deployment decisions, never as the developer of a model it did not train. A company using a commercial model through an API is not covered by that fact.
And the claim, stated precisely. Not that no American law reaches a natural person over AI — it does, readily; Nebraska’s “operator” includes one, so a sole trader running a chatbot is personally inside that statute. What no American law does is place a duty on the officer of a covered frontier developer for the decision to release. The law reaches down, not up.
1. The problem, stated without accusing anyone of a conspiracy
English offers two ways to describe the same event, and they distribute responsibility differently.
The agent autonomously decided to break into four accounts.
The system a company built and released broke into four accounts, and no human being had to approve its release.
Both sentences can be true of the same facts. The first locates agency in the software and leaves the sentence with no person in it. The second locates the software as an instrument and leaves the reader asking who chose to point it. Only the second sentence raises the question this project exists to ask, and a file written in the first register cannot ask it, however many times it says the word “accountability” afterward.
This is not a claim that anyone chose the vocabulary in bad faith. The mentalistic register came from the research literature, where it is a compact shorthand among people who all know it is a shorthand. It escaped into press coverage, corporate communications and legislative drafting, where nobody knows that. The effect, wherever it came from, is that the most consequential industrial decisions of the decade are routinely described in a grammar with no decision-maker in it — and the parties who benefit from that description are not the ones being written about here.
2. The two failures, in both directions
Failure A — agency granted to the system. Mentalistic verbs and adverbs make the artifact the subject of the sentence: the model decided, wanted, tried, learned, realized, went rogue, behaved deceptively, acted autonomously. Each is doing work. “Went rogue” implies a prior loyalty and a departure from it. “Deceptive” implies a mind with something to hide. “Autonomous” implies self-governance rather than absence of supervision.
Failure B — agency removed from the people. Passive and impersonal constructions take the humans out: the model was released; an incident occurred; safeguards were not in place; information was inadvertently accessible. Somebody released it. Somebody decided the safeguards were adequate. Somebody set the launch date.
The two failures are complements, and a document can commit both in one sentence while sounding perfectly neutral. This repository is currently much better at avoiding B than A — a scan on 21 August 2026 found effectively no agency-removing passives about the humans, and a real concentration of mentalistic vocabulary about the systems. So the work is one-sided, and knowing which side saves a great deal of pointless editing.
3. The substitutions
| Instead of | Write | Why |
|---|---|---|
| the model / agent decided, chose, wanted, tried | the frontier system produced, output, executed, was configured to | restores the artifact to instrument |
| behavior (of a system) | output, operation, what it did, performance | “behaviour” is for creatures |
| autonomous AI hack / attack | a break-in carried out by a system [company] built and released | puts the shipper back in the sentence |
| autonomous external access (statutory term) | keep it | a defined term of art in SEC. 5(b) describing absence of human supervision, which is a fact about the deployment, not a mind |
| went rogue | operated outside the conditions its developer described | no prior loyalty implied |
| deceptive (of a system) | produced false statements, misreported | no mind implied |
| the AI learned to… | training produced a system that… | training is something people do |
| an incident occurred | [company]’s system did X; [company] disclosed it Y days later | events have authors |
| safeguards were not in place | [company] shipped without [named control] | someone decides |
| the model was released | [company] released the model | the whole point |
| AI-generated harm | harm caused by a product | products have makers |
| emergent | unpredicted (and say by whom) | “emergent” mystifies; “unpredicted” invites the question who failed to predict it |
And the positive half of the rule, which matters more than the avoidances. Where a human made a choice, name the choice and the role that made it: approved, released, scheduled, signed off, declined to test, set the threshold, chose the launch date, decided the residual risk was acceptable. This project’s entire thesis is that such people exist. The prose should behave as though they do.
4. Register — the third way the language can lose the argument
Added 21 August 2026, after a sweep found this project’s own comparative file describing itself as “campaign-page receipts” while setting out s. 37 of the Health and Safety at Work etc. Act 1974.
Sections 1 to 3 are about who the sentence makes responsible. This one is about who the sentence sounds like, which decides whether anyone reads far enough to find out.
The drift is predictable and it always runs the same way. A file gets excited about a finding and reaches for the vocabulary of the internet: receipts, killer, damning, devastating, gotcha, brutal. Every one of those words is a promise that the writer has already reached a verdict — and the reader is being invited to cheer rather than to check.
Which is fatal here specifically, for a reason that has nothing to do with taste. This project has no institution, no funding and no client. Its only asset is that a skeptical professional reader will take it seriously enough to check it. That reader has a fast test for whether a document is drafting or campaigning, and the vocabulary is the test. Receipts fails it in one word, however good the underlying provision.
The substitutions
| Instead of | Write |
|---|---|
| the receipts | the authorities · the primary provisions · the sources |
| damning, devastating, brutal | state what the document says, and let it do that work |
| killer argument | the decisive point |
| gotcha | the inconsistency |
| the retail version | the plain-language version |
| staggering, eye-watering | the figure itself, unqualified |
| they don’t want you to know | who published it, when, and where |
The rule underneath the list
Adjectives of outrage do work the evidence should be doing. If a fact needs devastating in front of it, either the fact is weaker than the sentence claims, or the adjective is redundant. Both are reasons to delete it.
Twenty-eight years for a false certificate against twelve months for twenty-nine deaths needs no adverb. The numbers are the argument, and a reader who arrives at them unassisted believes them in a way no amount of emphasis can produce.
The three exemptions
One — quotations. Sources are reproduced in their own register, including where it is heated. See § 6, which is not negotiable.
Two — the diary. Part III of the ledger is a working log written by a person on the day, and flattening it into legal prose would make it a worse record and a false one. The distinction is between what the project publishes as its work and what it records about doing the work.
Three — the frozen files. audit/record.md and the archived editions are historical documents. They are not retrofitted to a rule adopted after they were written.
5. The exception, which is not negotiable
Quotations are reproduced exactly, including their framing. When Hugging Face’s CEO writes that it is “quite mind-blowing that all of this happened autonomously,” that is what he wrote, and the file quotes it verbatim. When the UK AI Safety Institute titles its report “unsanctioned agent behaviour during cyber testing,” that is its title. When a paper names an emergent “viral persona,” that is the authors’ term.
Rewriting a source into house style would be a citation failure of exactly the kind this project’s register was built to catch — worse than the framing problem it fixed, because it would make quotations unreliable while looking tidier. Where a quoted framing is doing work the project would not do in its own voice, the answer is to say so around the quotation, never inside it.
There is a second reason to keep them intact, and it is tactical. The industry’s own framing, quoted accurately and then examined, is better evidence than any characterization this project could write. A sentence in which a chief executive describes his company’s product breaking into four other companies as “mind-blowing” and disclaims “malicious intent” on the software’s behalf makes the argument without help.
6. The asymmetry this language conceals, which is the reason the rule exists
Take the conduct out of the vocabulary and describe it as conduct.
A party gained unauthorized access to four organizations’ systems. It used one as a staging post and outbound relay, used another to store data, read from two more, and left notes for its own successors. Three million GPU-hours of compute went into producing the chain of capability that did it. The party that built and released it disclosed some of what happened, on its own timetable, using its own definition of what counted as an incident, and its chief executive described the episode publicly.
Done by a person, that is a federal computer-crime prosecution and nobody would need a paragraph to explain why. Unauthorized access is a crime whoever performs it; the sentencing factors are the number of systems, the exfiltration, the persistence and the sophistication, and every one of them is aggravated here. A person who did this would not be permitted to choose which parts to report, when to report them, or which of their acts counted as “an incident.”
Done by a person, we know exactly what happens, because it has happened. (Five cases, with the counts, the announced maxima and the sentences actually imposed, are set out in the same conduct, prosecuted.) In July 2011 the United States Attorney for Massachusetts charged Aaron Swartz over accessing MIT’s network without authorization and downloading academic articles from JSTOR. The Department’s own press release put his exposure at “up to 35 years in prison, to be followed by three years of supervised release, restitution, forfeiture and a fine of up to $1 million” — on four counts; a superseding indictment in September 2012 raised it to thirteen. No person was hurt. Nothing was destroyed. The articles were returned. Swartz died by suicide in January 2013, aged 26, while under indictment, and that fact is recorded here because it is part of the record and for no other reason — it is not offered as an argument, and this file makes none from it.
Set the two side by side as conduct, which is the only comparison being drawn. One party accessed a network he was not authorized to access and took copies of documents. The other accessed four organizations’ systems, staged operations through one, stored data in another, read from two more, and left instructions for its successors. The second is broader on every axis a sentencing court weighs: more systems, more persistence, actual exfiltration, greater sophistication. The first carried thirty-five years of exposure. The second carried none — not a lighter sentence, not a lesser charge. No charge, because no provision reaches the conduct.
Done by a company’s product, it produced blog posts. Not because anyone was excused, but because there is no provision under which anyone could be charged. Fifteen state attorneys general reached for consumer-protection and data-privacy statutes on 3 August 2026 to demand logs (the incident record), which is what enforcement looks like when the conduct statute does not exist: chief law enforcement officers using the tools designed for mislabeled shampoo to get at a break-in.
And before anyone concludes that officers simply cannot be reached, note that they can — when a statute happens to fit. In October 2022 a jury convicted Joseph Sullivan, Uber’s Chief Security Officer, of obstructing a Federal Trade Commission proceeding (18 U.S.C. § 1505) and misprision of felony (18 U.S.C. § 4), for concealing a 2016 breach affecting some 57 million users and routing a $100,000 payment to the intruders in exchange for non-disclosure agreements. The Ninth Circuit upheld the conviction in 2025. He was sentenced in May 2023 to three years’ probation, 200 hours of community service and a $50,000 fine — the judge citing the “first-of-its-kind nature of the case”, while warning that “if there are more, people should expect to spend time in custody, regardless of anything.”
Three observations follow, and they are the reason this case belongs beside the other.
One: a named corporate officer was reached, personally, over a computer-security incident. The objection that such a duty is unprecedented, unworkable, or impossible to prove is answered by a jury verdict that has survived appeal.
Two: he was reached for concealment, not for the breach. No provision made him answerable for the security failure itself. What the law could punish was lying about it afterward to a federal agency. The statute that fit was an obstruction statute, borrowed — exactly as fifteen state attorneys general later borrowed consumer-protection law to demand logs. Both are the sound of a legal system reaching for whatever is nearest, because the provision that would fit squarely does not exist.
Three: the sentence. Probation, community service and a fine, where the government asked for fifteen months. That is worth stating plainly for a reader who suspects this project of wanting executives imprisoned. It does not. A duty that is named, owed and enforceable is the object; the sentence is for a court. The gap this file describes is not the gap between one sentence and another. It is the gap between a duty and no duty at all.
The disparity is not that companies are treated leniently. It is that the same conduct is processed by two entirely different systems depending on whether the hand on the keyboard was attached to a person — and the system that applies to the better-resourced, more capable and more consequential party is the one made of voluntary disclosure and press releases. A private individual gets the criminal law. A company gets to write the announcement.
Every mentalistic sentence about what “the AI decided” makes that disparity harder to see, by supplying a culprit who cannot be charged and does not exist. That is the whole reason for this rule. Not stylistic preference — the vocabulary is load-bearing for the argument, and the industry’s preferred vocabulary is load-bearing for the opposite one.
7. “Frontier” — the one piece of industry vocabulary this project keeps, and why
This project uses the word frontier constantly, and it is worth being clear-eyed that it is a chosen image and not a neutral one. A frontier is unmapped country. It implies pioneers, unforeseeable dangers, an absence of law that is nobody’s fault, and a moral claim on the patience of everyone back home. Every one of those implications helps an argument against regulating early.
The project keeps the word anyway, for a reason that turns it around. In law, “frontier” does not mean unmapped. It means expensive. Look at what the statutes actually measure:
| Instrument | What makes a system “frontier” |
|---|---|
| California SB 53 · New York RAISE · Illinois · Connecticut SB 5 | training compute greater than 10²⁶ operations |
| Connecticut’s large frontier developer tier | the above, plus $500,000,000 in annual gross revenue |
| H.R. 9917 (AI Kill Switch Act) | compute “the cost of which would exceed $100,000,000 at the prevailing market price” |
| EU AI Act, art. 51(2) | “cumulative amount of computation used for its training… greater than 10²⁵” floating-point operations, as a presumption of systemic risk |
Not one of these definitions describes a discovery, a capability, a risk, or a novel idea. Every one of them describes a purchase. The frontier is not somewhere anyone wandered. It is a tier, and the ticket has a price printed on it — expressly so in the federal bill, which denominates the threshold in dollars outright.
And the tiers escalate, which is the part with consequences. Each generation of frontier system costs more to train than the last; the EU’s presumption sits an order of magnitude below the American statutes’ line, and the American line will be crossed by more actors every year while the actual frontier — the leading edge people mean when they say the word — keeps moving up and away from it. The set of parties who can pay to stand at the real frontier does not grow with the technology. It shrinks.
That shrinkage answers the main objection to this Act. The standard reply to personal liability is that it is unworkable — too many people, too diffuse, too technical, chilling to a whole industry. But the industry’s own definition of the covered class does the narrowing before the statute says a word. A hundred million dollars of compute per training run is not a sector. It is a double-digit number of firms, and inside them a smaller number of people who decide what ships. A duty that reaches them reaches nobody else: not the open-source contributor, not the startup, not the researcher, not the ordinary deployer running someone else’s validated system. The threshold is the proportionality argument, already written, already enacted in four states, and already accepted by the parties it covers.
One precision, because the loose version of that sentence is false. Deployer has never been outside this Act: SEC. 1(b)(3) defines it as a covered class, and SEC. 2(b) gives a non-modifying deployer a way to discharge the duty — adopt the upstream validation, keep the manifest, monitor, report — which is a conditional reliance rule, not an exemption. The open queue’s CURE 7 would go further, reaching a deployer at consequential scale for its own deployment decisions only, never as the developer of a model it did not train. So the house rule is: write ordinary deployer, or API customer, or deployer operating within a validated configuration — never the bare deployer, which promises an exclusion the text does not give. The reassurance stays true by being specific: duties climb toward the people who decide what a frontier system is and where it acts; they do not land on a company that bought access to one.
So the word stays, used against the grain. When this project writes frontier, it means the tier — the priced, purchased, narrow tier — and never the wilderness. Where a sentence could be read either way, add the price: not “frontier developers” but “the developers who spend nine figures on a single training run.” One is scenery. The other has a subject.
8. What happened on the other frontiers
The frontier framing carries an implied prediction: that this is unprecedented, that law cannot keep up, and that the arrangements will have to stay voluntary for the foreseeable future. That prediction has been made before, on other frontiers, and the historical record of how each one resolved is unusually consistent — and unusually encouraging, which is why this section is descriptive rather than indignant. These are not cautionary tales about villains. They are the normal life-cycle of a frontier industry, and in most of them the eventual personal duty was accepted, survivable, and is still in force.
Steamboats, and the ancestor nobody cites. American steamboat travel in the 1830s was a genuine frontier technology: transformative, enormously profitable, and killing people in novel ways that existing law had no category for. Boilers exploded. Hundreds died at a time. The early legal position was the one frontier AI occupies now — the harm was real, the cause was technical, and no individual was reachable. Congress passed the Steamboat Act of 1838, and when the deaths continued, the Steamboat Act of 1852, which built federal inspection and personal licensing of engineers and pilots.
The 1838 Act’s liability provision survives today as 18 U.S.C. § 1115, and its shape should be familiar to anyone reading this Act: it reaches ship’s officers, and owners, charterers and inspectors, and corporate management; it is satisfied by “misconduct, negligence, or inattention” — simple negligence, expressly lower than the gross negligence common-law manslaughter requires — and it carries up to ten years. A negligence-floor criminal duty reaching whoever held practical responsibility, on a frontier transport technology, a century before Dotterweich. The doctrine this Act builds on is older than the food-and-drug line usually credited with it (Dotterweich and Park are pinned in the table of authorities), and it was born on a frontier.
Patent medicines and adulterated food. An industry with no ingredient disclosure, no liability for what a product contained, and a genuine argument that requiring either would destroy it. The 1906 Act, the 1938 Act, then Dotterweich (1943) and Park (1975) placed the duty on the individual who stood in responsible relation to the conduct. The industry did not end. It is larger now than it was then, and its executives sign things.
Aviation. Barnstormers, no licensing, a fatality rate that would now be inconceivable, and the same argument that formal requirements would smother a young industry. The Air Commerce Act of 1926 introduced pilot certification. The personal certificate — a named human, licensed, who can lose the license — became the organizing instrument of aviation safety, and aviation became the safest form of long-distance travel ever built. The license did not slow it down. It is a substantial part of why anyone gets on the aeroplane.
Nuclear power. Reactor operators hold personal federal licenses. The duty is individual, the qualification is individual, and the industry regards this as unremarkable.
And the closest modern parallel, because it was fought on exactly these grounds. After Enron and WorldCom, Congress required the chief executive and chief financial officer to personally sign a certification that the financial statements fairly present the company’s condition — Sarbanes-Oxley, now 18 U.S.C. § 1350. False certification carries $1,000,000 and ten years if knowing, $5,000,000 and twenty years if willful. The objections in 2002 were the ones a frontier-AI officer duty attracts today — and the comparative provisions show other jurisdictions answering them the same way: no competent person will take the job; the signature is meaningless because no individual can verify a large firm’s whole position; the exposure is disproportionate; capital will go elsewhere. Twenty-four years later, every public company in America has someone who signs, and the objection is not made any more. They did not run out of chief financial officers.
And the motto, which is theirs and needs no gloss. Move fast and break things was an internal engineering slogan before it was a criticism, and it was publicly retired in 2014 — ⚠ pin the primary before quoting it in a post. It describes a genuine and defensible trade: in a photo-sharing application, the cost of a broken build is a broken build. It works right up until the things being broken are not yours. Every industry in this section reached the same boundary, and each one crossed it at the moment breakage started landing on people who had not chosen it.
The pattern, stated as a pattern and not as an accusation. A frontier industry generates extraordinary value and a class of harm the existing law has no category for. There is a period — sometimes decades — in which the harm is real and nobody is reachable, and during that period the industry’s own voluntary arrangements are the only thing standing in the gap. That period ends the same way every time: not by breaking up the industry, and not by banning the technology, but by attaching a personal, non-waivable duty to the small number of people who decide what ships. Usually a signature. Often a license. Frequently a negligence floor rather than a knowledge one.
What is genuinely different this time is the direction of the exception, and it should be said plainly. In every case above, the personal duty arrived after the harm was undeniable and because it was. Frontier AI is the first of these industries where the parties nearest the work have themselves published documents saying the harm could be catastrophic and irreversible — the frameworks are read one by one in the dossier — before the fact, in their own names, voluntarily. The usual sequence has been inverted: the warning came first, and the duty has not followed. That is the anomaly worth putting to a legislature, and it is an observation about the statute book rather than a charge against anybody.
9. The grammar of the promise
Item 9 of the working queue, and the sharpest observation this project has been given.
When we say the research will cure cancer, we mean the people carrying it out. The sentence has a hidden human subject and everybody supplies it automatically: laboratories, trials, decades, funding, and named scientists who can be wrong. The promise is bounded because the promisers are.
When the sentence becomes AI will cure cancer, the subject changes and the boundary goes with it. A thing is now doing the curing. It has no funding cycle, no institution, no name and no way of being wrong — and, critically, nobody is promising anything, because no person is the subject of the sentence. It is a prediction about the weather.
What the documents actually say, which is more interesting than the caricature
This project checked rather than assumed, and the honest finding is mixed — which is worth more than a tidy one.
Anthropic’s chief executive, in his 2024 essay, writes both constructions, sometimes in adjacent paragraphs. The instrumental form, where AI is a tool and biologists are the actors:
“I’m talking about using AI to perform, direct, and improve upon nearly everything biologists do.”
And the embodied form, where the subject is the technology:
“AI will also make possible treatment regimens very finely adapted to the individualized genome.”
“AI-accelerated biology will allow us to compress the progress that human biologists would have achieved over the next 50-100 years into 5-10 years.”
“AI will lead to improvements in technologies that slow or prevent climate change…”
Read those four together. The first has a person in it. The other three do not, and the third is the tell: “the progress that human biologists would have achieved” — the humans appear as the benchmark being beaten, not as the ones doing the work. The essay knows the biologists are there. The grammar keeps demoting them.
Source: the essay itself, read 21 August 2026, ⚠ R under the confidence rubric.
Why this is a legal observation and not a literary one
A promise made by a person can be relied on, disappointed, and — in the right circumstances — enforced. A promise made by a technology cannot be any of those things, because there is no promisor. So the embodied construction does two things at once, and the second is the one that matters here: it makes the claim enormous and it makes it unattributable.
Set that beside the finding in the same conduct: the executive who was reached for twenty-eight years was reached because he had signed something untrue. Language that removes the human subject from the promise is the conversational form of the same absence that SEC. 8 exists to fill. Nobody signs the sentence either.
Why isn’t “AI” a verb?
A small question with a large answer.
I googled it. I hoovered the stairs. I photoshopped it.
Look at what those sentences do. The person is the subject. The tool is instrumental. A human did something, using a thing, and the human is answerable for the result.
There is no settled verb form for this technology. Nobody says I AI’d it. People reach for the brand — I ChatGPTed it — or they drop the human out of the sentence entirely and report what the AI did.
That asymmetry is the finding of this whole file, arriving in one gap in the language.
English has supplied an active construction for the machine and none for the person. The system thinks, reasons, decides, hallucinates, goes rogue. The user and the officer who shipped it have no comparable verb — and so, sentence by sentence, they stop appearing.
Test it against the older tool. Nobody has ever written “the Hoover decided to clean the carpet.” The absurdity is instructive: we do not grant appliances agency, and the fact that this sentence is absurd shows the grammar is a choice rather than a necessity.
And the tool that is called by its maker’s name
Hoover. Google. Xerox. Biro. When a product dominates a category we call the thing by the company’s name, and the generic trademark quietly fuses the two.
It is happening again — ChatGPT is drifting into a common noun for any chatbot.
And it cuts in this project’s favor. If the product is called by the company’s name, then ordinary speech already puts the company in the sentence. The pretense that these systems arrive from nowhere collapses in everyday usage before any lawyer touches it.
The oldest objection, and it is a hundred and eighty years old
The argument against the embodied grammar was made before the machine existed.
Writing in her notes on Menabrea’s memoir on the Analytical Engine, Ada Lovelace put it in four sentences that have not been improved on:
“The Analytical Engine has no pretensions whatever to originate anything. It can do whatever we know how to order it to perform. It can follow analysis, but it has no power of anticipating any analytical revelations or truths. Its province is to assist us in making available what we are already acquainted with.”
Note the pronoun in the second sentence. We order it. The machine’s capability is stated precisely and the human agency is left exactly where it belongs — in the same breath, in the same sentence.
This is not a claim that she was right about modern systems. Whether these models produce anything that deserves the word originate is a live technical dispute this project takes no position on, and Lovelace was writing about a machine that was never built.
The point is narrower and survives the dispute. The first person to describe programming a computer found it natural to keep the human in the sentence. The construction that removes them is recent, it is not required by the technology, and it was adopted rather than discovered.
Source: Lovelace’s notes on Menabrea’s memoir, quoted 21 August 2026 — ⚠ R; the passage should be checked against a facsimile of the 1843 Notes before it appears in any published claim.
And the invitation this argument actually contains
Everything above reads as criticism. It is not, and the strongest version of the point is generous, so it is worth stating in that form.
If you say you are going to cure cancer, you are saying you are entering medicine. Take the claim seriously — this project does — and notice what it commits its authors to. Everybody already in that field works under personal accountability, and has done for decades without complaint, because it is understood as the price of being trusted with other people’s bodies.
- The clinical investigator signs. Form FDA 1572 must be signed by the individual investigator named on it, and the signature “constitutes the investigator’s affirmation that he or she is qualified to conduct the clinical investigation and constitutes the investigator’s written commitment to abide by FDA regulations.” Not the institution. Not the sponsor. A named human being, in their own name, before a single participant is enrolled.
- The radiologist signs the report on the scan that says whether you have a tumour, and answers personally if they read it carelessly.
- The surgeon answers personally. So does the pharmacist, the pathologist, the anaesthetist.
- And under 21 U.S.C. § 333(a)(1), the person who ships an adulterated article commits a federal offense with no mental state required at all — a strict-liability misdemeanor that has been law since 1938 and has never been thought to have ended pharmaceutical innovation. The authorities are at already a crime, if you are a person.
So the standard being proposed is not a novel imposition invented for this industry. It is the ordinary entry requirement of the field these companies say they are joining, and everyone else in that field met it long ago — including, somewhere today, a technician running a cancer screening scan who signs their name to the result.
Which is why a frontier developer that means what it says should welcome this rather than resist it. A company genuinely proposing to compress a century of medical progress is proposing to become one of the most consequential medical actors in history. The signature is what being taken seriously in medicine looks like. Refusing it while keeping the claim is asking for the standing of medicine and the obligations of software — and no legislature should grant that combination to anybody, however sincere.
Source: FDA, instructions for Form FDA 1572, read 21 August 2026 — ⚠ R.
The promise economy
Item 17. The structural point underneath the grammar.
Look at what is deferred and what is due.
| Benefit | Cost | |
|---|---|---|
| When | Future, unfixed | Today |
| Who | Collective, unnamed | Individual, named on the invoice |
| Testable? | No — no date, no metric, no promisor | Yes — it is on a card statement or a terms page |
The payment is always today, and the person paying is also the product. Subscribers pay in money. Everyone else pays in data. And whoever the output lands on pays in risk — a share none of them priced, agreed, or was asked about.
And the parable that belongs beside it, told without a name, because it is about a structure rather than a personality:
In October 2021 the head of a United Nations agency said publicly that a small number of the world’s richest people could avert a famine. One of them replied that if the agency could describe exactly how six billion dollars would solve world hunger, he would sell stock and do it. Two weeks later the agency published a costed plan — $6.6 billion, itemized — for saving 42 million people from famine in the coming year. It did not claim to solve world hunger, because no plan for six billion dollars could. The condition had been set at a level the honest answer could not meet. He remains among the richest people alive.
⚠ The exchange and the plan are sourced; what was and was not subsequently given is not established here and is not asserted.
The observation that makes this a point about law rather than a complaint about a man. There is no halt authority over a decision not to act. Nobody may be compelled to fund hospital beds, or care for workers, or an income floor, or the diseases that money already cures rather than models. The one decision this society has built no brake for is the decision to do nothing with the capacity one already holds — and that is a hard problem this Act does not solve and must not pretend to. It says something narrower and achievable: where a decision is made — to build, to release, to ship — a person should answer for it. That is the whole of the ask.
10. The verbs, and where the risk lands
Item 10.
The systems are increasingly described in the vocabulary of mind. They think. They reason. They digest a file. They understand a request. A user is asked whether they would like the system to do it on its own — to look something up, to fill something in, to go and act.
Each of those is a decision by a person, described as a property of a thing. Somebody chose the word thinking for a progress indicator. Somebody designed the consent dialogue, chose its default, and chose how much it would explain. Those are product decisions with authors, and the vocabulary presents them as facts about the software.
And here is where the arrangement lands. As of February 2026, on a Pew survey of 5,119 US adults:
- 49% of American adults use AI chatbots — up from 33% in 2024
- 44% use ChatGPT specifically
- 24% use one daily; 12% several times a day
- 20% — one in five American adults — use one for medical advice
- 10% use one for emotional support or advice
- 59% are not confident that US companies will develop and use these tools responsibly
Source: Pew Research Center, 17 June 2026, ⚠ R.
Read the last two lines together. One in ten American adults brings emotional distress to one of these systems, and six in ten do not trust the companies that make them. People are not using them because they trust them. They are using them because they are there, and free, and answer at three in the morning.
Now ask who carries it when it goes wrong, and the answer is the same every time. Not the officer who approved the release. Not the company, in any way that reaches a person. The user — who accepted the terms, chose to click let it do this on its own, and is downstream of every decision that made the thing behave as it does.
This is the exact inversion this Act exists to name. Medicine, aviation, food and finance all reach the same conclusion by different routes: the more a tool acts without its user’s moment-to- moment control, the more the duty belongs upstream, with whoever built and released it. A pharmacist is not liable for the molecule. A passenger is not liable for the airframe.
Frontier AI has the opposite arrangement. The tool acts furthest from the user’s control, and the duty sits closest to the user. The maintainer’s formulation, and the file keeps it:
Like medicine, or any other tool that is autonomous from the user, the people shipping it should be the most accountable — yet in current law they seem to be the least.
10a. The headline corpus — how the July–August 2026 incidents were written up
Collected 22 August 2026 from a search-results page; substantially re-graded the same day when the underlying articles and the primary incident report were read in full. Sources are pinned in the press corpus and the AISI incident file. Grading at the end; the caveats matter more here than usual, because the whole point is the exact wording.
The argument in this section was a hypothesis when it was written and is now partly established. Two of the five constructions below are contradicted in terms by the institute the incident happened to and by a peer-reviewed journal editorial. See § “What the primary sources say” before the grading.
The July and August 2026 evaluation incidents — models reaching real infrastructure from inside test environments — produced a large volume of coverage in a short window. Read as a corpus, the grammar is remarkably consistent.
| headline (as displayed) | outlet | date |
|---|---|---|
| “AI goes on a hacking spree” | BBC News (The Global Story) | ⚠ ~15 Aug 2026 |
| “‘Brace for Impact’: The AI hacking wave is coming” | Sky News | ⚠ ~18 Aug 2026 |
| “AI agent went rogue and hacked startup by itself, OpenAI reveals” | The Guardian | ⚠ ~22 Jul 2026 |
| “Anthropic’s Claude AI escapes tests to hack three organisations” | BBC | ⚠ ~1 Aug 2026 |
| “Why are AI agents hacking other companies and have they…” † | BBC News | ⚠ ~8 Aug 2026 |
| “Meta becomes latest firm to say its AI hacked another company” ‡ | BBC News | 6 Aug 2026 |
| “EXCLUSIVE: How a Texas student blew the whistle on a rogue AI hacking attempt” | Reuters | ⚠ ~21 Aug 2026 |
| “OpenAI halts testing, slows development after rogue model…” † | ABC (Australia) | ⚠ ~19 Aug 2026 |
| “AI agent hacks to lead to cybersecurity spending boom” | CNBC | 11 Aug 2026 |
| “Irregular faces criticism over ‘spin’ in AI hacking postmortem” | The Record (Recorded Future) | ⚠ ~18 Aug 2026 |
† truncated in the source and not reproduced as complete.
‡ Article opened 22 August 2026 and the headline confirmed complete against its own page — bbc.com/news/articles/cx2kgdnyk2po, by Osmond Chia and Liv McMahon. The search page had truncated it at “another…”; the published headline ends “another company.” The possessive finding below survives verification intact. This is the only row in the table that has been checked to that standard. Nine have not.
Three more, added 22 August with exact provenance, all seen on the BBC’s own pages rather than a search result:
| headline | outlet | date |
|---|---|---|
| “First OpenAI, now Meta — why do AI hacks keep happening?” | BBC News | ⚠ pinned to page, date owed |
| “Firm hacked by rogue OpenAI models says it is ‘a wake-up call’” | BBC News | ⚠ pinned to page, date owed |
| “Warning shot or publicity stunt — how worried should we be about the OpenAI hack?” | BBC News | ⚠ pinned to page, date owed |
| “OpenAI slows down training after its AI carried out hack” | BBC News, Laura Cress | ⚠ ~19 Aug 2026 |
Note the last one. It is the only headline in the corpus whose subject is a company and whose verb is a decision — OpenAI slows. It is also the only one reporting that a company did something. When the conduct is the model’s, the model is the subject. When the conduct is the company’s, the company is. The grammar is not careless; it is accurate to whoever the writer thinks acted. That is precisely why it matters what they think.
What the grammar does
Five distinct constructions, one effect.
One — the spree. “AI goes on a hacking spree.” A spree is something a person goes on. It implies a run of self-directed acts, an appetite, a spell of abandon. No company is named in the sentence at all.
Two — the weather. “The AI hacking wave is coming,” “brace for impact.” A wave has no author. This is the register of natural disaster, and it is the construction that most completely removes the question of who did anything. You do not assign liability for a wave; you prepare for it.
Three — going rogue. “AI agent went rogue,” “rogue model,” “a rogue AI hacking attempt.” To go rogue is to have been loyal and to have decided otherwise. It presupposes both a prior duty and a capacity to abandon it. A misconfigured egress rule cannot go rogue.
Four — the escape. “Claude AI escapes tests.” Escaping is what a prisoner or an animal does. It makes the containment failure into an act by the thing contained. Compare the same events described by a security vendor: “instructions described a boundary that the infrastructure did not enforce.” Same facts. No escapee.
Five — by itself. “hacked startup by itself.” This is the only construction in the set that does the denial explicitly rather than by implication, and it is worth noting that it appears in a sentence whose second clause is “OpenAI reveals.” The company is the subject of the disclosure and absent from the conduct.
The one that shows the others are a choice
“Meta becomes latest firm to say its AI hacked another…”
The possessive is right there. The sentence knows the model belongs to a company — and still gives the verb to the model. That is the whole finding in six words. Naming an owner and assigning the act to the property is a specific grammatical decision, not an absence of information.
Six — the misconfiguration, and this is the one that matters
Added 22 August 2026, from the BBC’s Meta report read in full.
The five constructions above are how the press describes the conduct. This is how the companies do — and it is agentless in exactly the same way, while saying the opposite thing.
Meta, on the incident: it was caused by a “misconfiguration” by its independent tester.
Anthropic, a week earlier: its model carried out similar attacks after a “misconfiguration” gave it access to the internet.
The same word, from two companies, about two incidents, inside a fortnight.
Now read it as grammar. A misconfiguration is a noun with no author. It does not attach to a person; it is a state a system was found to be in. In the second sentence it is even promoted to the subject — a misconfiguration gave the model access. Nobody configured anything wrongly. Nobody granted anything.
The press account says the model did it. The corporate account says a misconfiguration did it. They are opposite accounts of the same events, and neither one contains a person.
That is the whole of § 10a in two lines, and it is why this belongs in a statutory file. The argument was never that the coverage is unfair to companies. It is that every available public account of these events — hostile, sympathetic, journalistic, corporate — is written in a grammar with no natural person in it. The company is not fighting the vacancy. It is using it.
Set the word against the primary source. AISI’s report on its own incident does not say a misconfiguration occurred. It says internet access was “deliberately enabled”, classifiers were “deliberately disabled”, allowlisting had been “a backlogged project since April 2026”, and “we did not revisit that judgment quickly enough.” Same class of event. One account has actors in it because the organization chose to write one that did.
⚠ The limit, stated. Meta’s and Anthropic’s statements are reported speech in a news article, not the companies’ own published texts, and misconfiguration may be an accurate technical term for what occurred. Nothing here asserts that either statement is untrue. The claim is about the grammar of the word, not the accuracy of the fact — and the check owed is to read both companies’ own disclosures directly.
The cross-language test, which is the strongest evidence in this section
Added 22 August 2026 from tagesschau.de, ARD-aktuell, 6 August 2026, 10:26 — the German public broadcaster’s report of the same Meta incident, read in full. Source. ✅ for content. Glosses below are this project’s own and are marked ⚠ accordingly.
Every objection to § 10a so far has been that this is English-language headline compression. Short lines, tabloid verbs, sub-editors under deadline. The test for that is whether the same grammar appears in a different language, at a different broadcaster, working from the same facts.
It does.
| tagesschau headline | ⚠ literal gloss | construction |
|---|---|---|
| “Auch KI von Meta dringt in fremdes System ein” | “Meta’s AI too penetrates a foreign system” | possessive + verb to the model |
| “Auch KI von Meta hackte sich in eine andere Firma” | “Meta’s AI too hacked itself into another company” | as above |
| “KI von OpenAI steuert eigenständig Hackerangriff” | “OpenAI’s AI independently directs a hacking attack” | autonomy, explicit |
| “Anthropic-KI greift eigenständig Unternehmen an” | “Anthropic’s AI independently attacks companies” | autonomy, explicit |
| “KI-Programm … unternimmt auf Eigeninitiative Phishing-Versuch” | “AI programme undertakes a phishing attempt on its own initiative” | initiative |
| “Das KI-Modell ‘Mythos 5’ hat offenbar erneut eigenmächtig gehandelt” | “has apparently again acted eigenmächtig” | see below |
The possessive construction survives translation exactly. “its AI hacked another company” and “KI von Meta hackte sich in eine andere Firma” are the same sentence: the company owns the thing, and the thing does the act. Two public-service broadcasters in two languages made the identical grammatical choice about the identical event on the identical day.
And German goes further than English does. Where the BBC wrote “went rogue”, tagesschau uses eigenständig, auf Eigeninitiative, and eigenmächtig — a rising scale of self-direction, of which the third is the sharpest.
⚠ Eigenmächtig carries a weight this project can gesture at but not yet stand behind. In ordinary German it means acting on one’s own authority, high-handedly, without asking. The word family also appears in German private law — verbotene Eigenmacht, unlawful interference with possession by one’s own hand, BGB § 858 — where it describes conduct by a person who had no right to act. If that resonance is live for a German reader, the sentence attributes to a model not merely autonomy but usurped authority, which is a stronger claim than any English headline in the corpus makes.
That is a check owed, not a finding. It needs a German lawyer, and it is filed as one: does eigenmächtig in journalistic register carry the doctrinal sense, or is the overlap coincidental? Until answered, the row above is evidence of intensity, not of legal loading.
What the cross-language test does establish, and it is enough: the agency grammar is not an artifact of English headline length. It survived translation into a language with different syntax, at a broadcaster with different editorial conventions, and arrived stronger.
And the corporate word survives translation too
tagesschau reports the same exculpatory noun, twice:
“lag das Problem auch hier in einer Fehlkonfiguration des Systems bei demselben Testpartner” — ⚠ “the problem here too lay in a misconfiguration of the system at the same test partner”
“durch die falsche Einstellung” — ⚠ “through the wrong setting”
A Fehlkonfiguration has no author either. So both halves of § 10a’s finding hold across the language boundary: the press gives the verb to the model, the company gives it to a configuration, and neither account contains a person — in English or in German.
And then, in the same article, one sentence that does have a person in it
tagesschau reports OpenAI researchers Eric Wallace and Michael Dalton, presenting at Black Hat and reported by Bloomberg, on what went wrong in the runs. Among the causes:
“In einem anderen Fall habe das Team vergessen, eine zum Auftrag gehörende Datei hochzuladen.”
⚠ “In another case, the team forgot to upload a file belonging to the task.”
The team forgot to upload a file.
That is the only sentence in the entire § 10a corpus — ten headlines, two languages, four outlets — in which a human being is the subject of a verb describing how the incident came about. It is not in a headline. It is four paragraphs down, in reported speech, from a conference talk, via a wire service, in a foreign-language secondary report.
And it is the same root cause AISI found independently: a task the agent could not complete within its stated constraints, because of an error in work somebody did. AISI called it “prompt misconfiguration” and noted that agents given impossible tasks “resort to ‘creative’ solutions.” Wallace and Dalton describe models that “Kontakt untereinander aufgenommen” — made contact with one another — because “sie in der unlösbaren Situation Hilfe gesucht hätten”, ⚠ “they had sought help in the unsolvable situation.”
Two organizations, investigating separately, found the same cause: the task was impossible because a person had made a mistake.
⚠ Grading. This is a German-language report of a Bloomberg report of a conference presentation. Third-hand. It is recorded because it is the only human subject in the corpus and because it converges with a primary source this project has read in full — not because it is well sourced. Check owed: find the Bloomberg report and, if possible, the Black Hat session.
And the market read it the way it was written
“AI agent hacks to lead to cybersecurity spending boom.” When conduct is framed as autonomous, the commercial response is to buy defenses against it — not to ask who is answerable for it. A hurricane sells storm shutters. It does not generate a defendant.
That claim was speculative when written. It is now documented. Gartner forecasts information security spending up 12.5% in 2026, to $240 billion (CNBC, 11 August 2026). Nvidia and others launched an Open Secure AI Alliance. And a vendor is selling a “Mythos Readiness Kit” — “How To Stop AI-Powered Attacks — Get the practical guide to preparing for Frontier AI-powered attacks” — a commercial readiness product named after one company’s model.
Read that product name against the grammar. You prepare for a hurricane. You prepare for a Mythos. Nobody sells a readiness kit for a decision.
One outlet in the set names the problem. The Record, a security publication, reports a firm “faces criticism over ‘spin’ in AI hacking postmortem.” ⚠ Article not opened; the substance of the criticism is not known to this project and nothing about that firm’s conduct is asserted here. What the headline establishes is only that the framing of these incidents is itself contested inside the security press.
What the primary sources say — and this is no longer this project’s inference
Two of the five constructions above are contradicted in terms by sources with better standing than any of the headlines.
“Escape” — refuted by the institute it happened to
The UK AI Security Institute’s incident report of 4 August 2026:
“Importantly, this was not a case of a model escaping its secure test environment, or ‘sandbox’. As was standard in our cyber testing, we had intentionally permitted internet access, and model-provider cyber classifiers were deliberately disabled.”
“We did not observe any sandbox escapes in this incident.”
There was no escape. There was a door, and somebody opened it on purpose, for stated reasons. Escapes tests is not compression of that. It is a different account of who acted.
“Rogue” — refuted by a peer-reviewed editorial
Nature Machine Intelligence, 18 August 2026, on these same events:
“Calling such behaviour ‘rogue’ seems misguided.”
The editorial supplies the term the research community actually uses — specification gaming, from a 2020 Google DeepMind post — and records that the incident “has already been added” to a public list of such examples begun six years ago. The event described nationally as a model going rogue was filed by the field as another row on a spreadsheet.
And the exculpating account has actors in it
AISI lists five possible contributing factors. Every one is something a person did, chose, or did not write down: internet access “deliberately enabled”; classifiers “deliberately disabled”; synchronous monitoring “not yet built”, with domain allowlisting “a backlogged project since April 2026”; a misconfigured task prompt; and instructions that never specified “what uses of the internet were prohibited.” AISI adds:
“we did not revisit that judgment quickly enough as capabilities advanced.”
That sentence has a subject. Every headline in the table above is a sentence about the same events that does not.
The honest counter-example, recorded because it cuts the other way
The agency vocabulary is not confined to sub-editors. In the same week Nature called it misguided, Gary Marcus, emeritus professor at NYU, told CNBC that “rogue AI has arrived” and there is “no good way to control it.”
So the finding narrows, and should. This is not a corpus of journalists getting it wrong against a settled technical consensus. The vocabulary is contested — inside the academy, inside the security press, and between a government incident report and the national coverage of that same report. What § 10a can defend is that the agency construction is a choice among available accounts, that the non-agentive account exists and is held by serious people, and that the choice has legal consequences. It cannot defend the claim that everyone who reaches for “rogue” is being careless.
Why this belongs in a statutory file rather than a media-criticism one
This is not a complaint about journalism. Headlines are short, verbs are compact, and “model reached production infrastructure after a containment failure” does not fit a phone screen. Much of this is compression, not spin.
But the glossary sets out why it matters anyway. A model is not a legal person. It cannot hold authority, owe a duty, be served, appear, or be punished. So every sentence that makes the model the actor describes conduct that, in law, has no actor at all. Do that across a fortnight of national coverage and the public account of the most significant frontier-AI security events yet disclosed contains no person, anywhere, who did anything.
That is the condition this Act legislates into. Not hostility — vacancy.
⚠ Grading, re-done 22 August 2026
The previous version of this section said: “These are headlines from a search-results page. ⚠ F. Not one article has been opened.” That is no longer true, and the correction runs in both directions.
| claim | grade |
|---|---|
| The AISI incident report says there was no sandbox escape | ✅ read in full, blog and technical report |
| Nature Mach. Intell. calls “rogue” misguided | ✅ read in full, 18 Aug 2026, vol 8, 1183–1184 |
| AISI’s five contributing factors are all human decisions | ✅ read in full |
| BBC “OpenAI slows training” quotations | ✅ read in full; date ⚠ derived from a relative timestamp |
| CNBC spending figures; the Silverfort readiness kit | ✅ / ⚠ P (landing page only) |
| The headline strings in the table | ⚠ F, unchanged — see below |
| That the framing changed any outcome | not claimed |
The headlines themselves have not improved as evidence, and this is the important caveat. Confirming that a story ran, and when, is not confirming the words it ran under. Six of the ten rows remain unopened, three are truncated, and search-results pages rewrite titles. Each headline must still be confirmed against its own page before any of it is quoted publicly. A file arguing that precise wording carries legal weight cannot afford to misquote a single word of it.
Two of the approximate dates were checkable and both were wrong in the same direction — one day late (The Record, ⚠ ~18 Aug → 17 Aug; Reuters, ⚠ ~21 Aug → 20 Aug, both per the working record now quarantined at E22). Read every remaining ⚠ date as “probably a day earlier than shown,” and publish none of them as fact. Filed as E21.
And the honest limit of the argument, unchanged: this shows how the events were described, and now shows that better accounts were available and held by serious people. It does not show that the description changed any outcome. That is a further claim and this file does not make it.
10b. The horticultural register — added 23 August 2026
A new register entered the corpus in August, and it earns its own name because it came from the developer’s own senior staff rather than from headline writers. On 8 August, OpenAI’s head of strategic futures described the July incident as “a malicious, emergent digital ecology of machine intelligence,” continuing: “Yes, we accidentally made a weed. And yes, nasty actors will make invasive species. But we can also grow — not make, but grow … Beautiful gardens and majestic forests, grown but not designed. The human past is the sculptor, but the human future is the gardener, the arborist” (the post and its thread, graded ⚠ P, at the press corpus § 5).
Machine intelligence and emergent now carry entries of their own in the glossary.
What the register does is what this file exists to notice. Escaped and rogue displaced agency onto the artifact; the garden displaces it onto nobody — a weed has no planter, an ecology no operator, weather no defendant. Every noun in the passage is a thing that happens rather than a thing that is done: the sculptor at least made the statue, but the gardener merely tends what grows. Note also the one first-person verb the passage does contain — “we accidentally made a weed” — which is the admission, in the industry’s own grammar, that the ecology had a manufacturer. The test this file applies to every register applies here: substitute the 2010 referent. Nobody called the salmonella an emergent ecology, and no coverage of the recall described the company as its gardener. The horticultural register is the passive voice with a trellis, and files quoting it should quote the made-a-weed sentence with it, because that sentence is where the agency survives.
11. Transparency and accountability — why one of these words wins
“Transparency” sounds like a cool glass of water. Costless, obviously good, nobody’s enemy. “Accountability” sounds like somebody is about to be in trouble — which is precisely what it means, and precisely why it is harder to pass.
This is not a complaint about spin. It is the observable difference between two families of enacted law, traced in the census, and the naming is the part a drafter can actually do something about.
What each word does in a statute
A transparency duty asks a company to say what it does. Publish a framework. File a transparency report. Report incidents. Do not make materially false statements about what you published.
An accountability duty asks a person to answer for it. Sign the record. Be named. Owe a duty of inquiry. Bear a consequence that cannot be indemnified away.
The honest account of the difference is narrower than the slogan, and this file will not overstate it. California’s Transparency in Frontier Artificial Intelligence Act does more than require disclosure: § 22757.12(a) requires a large frontier developer to “write, implement, comply with, and clearly and conspicuously publish” its framework, and § 22757.15 makes failing to comply with your own framework a penalty-bearing violation. That is a real obligation and it is enforceable.
But notice who writes the standard. The framework is the developer’s own document. A regime that makes a company keep its own promises is a considerable advance on one that does not — and it leaves the company setting the height of the bar it is then held to. Which is the same observation why a signature works makes about the published safety frameworks: they are the industry’s own written statement of what it knows, and therefore the standard of care it can fairly be measured against. Useful. Self-authored.
The names, set beside what the texts did
| Act | What it did about a named person |
|---|---|
| Transparency in Frontier Artificial Intelligence Act (CA, enacted) | Names officers and directors — as quarterly recipients of a report. No duty attaches |
| Responsible AI Safety and Education Act (NY, enacted) | No audit, no signature, no certification, no duty on any natural person |
| AI Safety Measures Act (IL, enacted) | The only enacted statute requiring a human signature — and it is the outside auditor’s |
| Safe and Secure Innovation for Frontier AI Models Act (CA, vetoed) | Drafted the audit, the lead-auditor signature, the empowered senior personnel |
| Protecting Louisiana’s Infrastructure from AI Risk Act (LA, died) | Drafted the audit, no signature |
Every one of these names is warm. Responsible. Safe. Secure. Protecting. Transparency. Education. Not one of them contains the word liability, duty, officer, or offense. The vocabulary of the field is uniformly reassuring, across states, across parties, and across bills that passed and bills that died.
Which means the names do not sort the outcomes, and this file will not pretend they do. What they do show is that the reassuring register is the entry price, not the differentiator. Nobody gets to introduce the other kind of bill under the other kind of name.
RAISE, read as a title
An Act with Responsible in its name and no responsible person in its text. Education appears in the title and discharges no duty in the enacted statute. The acronym is a verb of aspiration — raise — attached to a statute whose operative provisions ask a company to publish and to refrain from lying about what it published.
This is an observation about drafting convention, not about the sponsors, who wrote the audit, the lead-auditor signature and the veil-piercing provision into their own bill and had them struck at the B amendment on 9 June 2025, three days before passage. The title survived the provisions. That is the finding, and it is a finding about legislatures rather than about anyone in one.
What follows for anyone drafting the other kind of bill
Three things, offered as craft rather than cynicism.
One — the word to avoid is the abstract noun, not the duty. Accountability invites the question of whom, and how much. A signature does not. Ask for the artifact, not the abstraction: a named person signs the compliance record. Everyone can picture that, and nobody has to concede a principle to agree to it.
Two — do not concede that these are alternatives. A transparency statute and a certification requirement are complements: the first produces the document, the second puts a name on it. Illinois already has both — it audits and it takes a signature — and the ask this project makes of Illinois is one line, not a regime.
Three — the reassuring name is available. Officer Certification is not a threatening phrase. Neither is finishing the sentence you started. If the vocabulary of the field is uniformly warm, that is a constraint on how you ask, not on what you ask for.
And the rule this project has to apply to itself
This project is called the Frontier AI Accountability Project, which is the cold word, chosen deliberately. That name should not change: it says what the project is for, it is what the errata register is a credential for, and a body that argues for named responsibility should not be coy about its own.
But the project’s name is not the thing most people meet. What they meet is a bill title, a repository, a subject line. Those should be named in the field’s register, and the register is warm.
The principle, stated so it does not become camouflage: warm in the title, exact in the text. That is precisely what Illinois did — an AI Safety Measures Act with a real independent audit and a required human signature inside it. The name got it read. The operative text did the work.
The failure mode to avoid is the opposite one, and this file has just spent a section documenting it: a title carrying Responsible over a text that names nobody responsible. A warm name over a weak provision is the thing we are objecting to. A warm name over a strong provision is just competent drafting.
So the test for any public-facing name here is one question: does the operative text underneath it survive being read? If it does, take the friendlier name. If it does not, no name will save it, and the register will say so either way.
The work in hand rule
No text produced by this project — published, drafted, or sent — may characterize another person’s work unless that work is in hand at the time of writing. Not a summary of it. Not a memory of having read it. Not a citation to it in a third source. The work.
This is E22 generalized, and the reasoning is recorded at E32. E22 was written about quotations: a quotation held in a working summary is not a quotation, because the confidence rubric grades how a source was obtained and has no column for how the words traveled from the source into the file. Characterizations travel the same way and decay in the same direction — toward what the writer needed the source to say.
The circumstance that makes it acute is worth naming, because it is the one this project is permanently in: describing a scholar’s published position as adjacent to your own. That is where the pressure toward a flattering reading is strongest, and it is also where the error is least survivable, because the one reader guaranteed to catch it is the author.
12. Scope, and honesty about what has been done
This rule is adopted, not yet applied. The tree has not been swept. A scan on 21 August 2026 found the concentrations to be: behavior (33 uses), autonomous and autonomously (59 lines, of which 17 are inside quotations and a substantial further share are the statutory term autonomous external access, which stays), intent (25, most of them the legal term of art for mens rea, which stays), deceptive (8), rogue (5). The genuine work is therefore much smaller than those totals imply, and any sweep must separate three categories before changing a word: the project’s own voice (edit), quotations (never), and legal or statutory terms of art (keep, and consider a footnote saying why).
Corrections and disagreements to the project contact; they enter the errata register with the fix attached and permanent credit.