Why a signature works
SEC. 8 requires a named person to certify a deployment decision. The objection is always that this is paperwork — a formality that changes nothing, imposed on people already doing their best.
This file is the answer, and it is not an argument. It is a set of cases where the presence or absence of one signed document decided what happened to somebody.
Who this is about
About: the officer of a frontier developer — the person inside a company training above 10²⁶ operations who decides that a system ships.
Not about: engineers, researchers, open-source contributors, ordinary deployers and API customers, or users. On deployers precisely, see the case. SEC. 8 asks one person to sign one thing. Nobody else acquires a duty because of it.
1. Twenty-eight years and twelve months
Two American executives presided over conduct that killed people. Neither was charged with a death. One received the lightest sentence in the gallery and one the heaviest.
Don Blankenship. Twenty-nine miners died at Upper Big Branch. He was convicted of a single misdemeanor — conspiracy to violate mine safety standards — acquitted of every felony, and sentenced to twelve months, the statutory maximum.
Stewart Parnell. Nine people died and roughly seven hundred fell ill from salmonella in Peanut Corporation products. He was sentenced to twenty-eight years.
Not one day of Parnell’s sentence was for killing anyone.
The twenty-eight years came from fraud counts, and the fraud was a document. He had fabricated certificates of analysis stating that product was free of pathogens when no test had been run, or when the test had found them.
Read those two together and the mechanism is unmistakable. The variable that decided the sentence was not the body count. It was whether there existed a document the defendant had signed that was untrue.
Parnell signed, so the law had a purchase and used it. Blankenship signed nothing of that kind, so twenty-nine deaths produced a regulatory misdemeanor with a one-year cap.
Sources: DOJ, Blankenship sentencing; DOJ, Parnell sentencing. ⚠ R under the confidence rubric.
2. Every adjacent field already does this, and none of them collapsed
Clinical research. Before a single participant is enrolled in an American drug trial, an individual investigator signs Form FDA 1572. FDA’s own instruction is that the signature “constitutes the investigator’s affirmation that he or she is qualified to conduct the clinical investigation and constitutes the investigator’s written commitment to abide by FDA regulations.” Not the institution. Not the sponsor. A named human, in their own name.
Public companies. After Enron, Congress required the chief executive and chief financial officer to personally sign a certification that the financial statements fairly present the company’s condition — 18 U.S.C. § 1350. False certification carries $1,000,000 and ten years if knowing, $5,000,000 and twenty years if willful.
The 2002 objections were the ones a frontier-officer duty attracts today: no competent person will take the job; no individual can verify a large firm’s whole position; the exposure is disproportionate. Twenty-four years later every public company in America has someone who signs. They did not run out of chief financial officers.
And now the case against this analogy, stated before anyone else states it. The first chief executive charged under the Act was acquitted. Richard Scrushy of HealthSouth faced thirty-six counts, and on 28 June 2005 a federal jury found him not guilty on every one of them. A former SEC regional office head who had predicted that prosecutors would “wave that personal certification in front the jury to show that the defense claim — that their head was stuck in the sand — doesn’t hold water” said afterward that “the utility of the criminal certification statute will be very much undermined.”
So Sarbanes-Oxley proves the narrower thing — which is the thing this file needs. It is strong evidence that a certification requirement changes conduct before anything reaches a courtroom: every public company now has a named person who has to ask, and not one of the 2002 objections materialized. It is weak evidence that certification statutes are charged and won, and this file previously ran the two together.
Because the signature is not the offense. It is what makes an offense provable. Parnell was not convicted under food-safety law either — he was convicted under fraud statutes that finally had a document to attach to. That is why § 1001, § 1519 and the ordinary fraud statutes matter here more than any purpose-built provision could. They already exist. They already reach individuals. At the compute frontier they have nothing to attach to, because nobody signs anything.
Sources: CNN/Money, 28 June 2005; NBC News, “Anti-fraud law fails first major court test”. ⚠ R. Added 21 August 2026 as the cure to E18.
Records. Under 18 U.S.C. § 1519, destroying a document with intent to impede a federal matter carries twenty years — and it bites “in relation to or contemplation of” a matter, so the offense is complete before any investigation opens.
The heaviest penalty in this whole file is not for killing anyone. It is for what happened to a piece of paper.
Sources: FDA, Form 1572 instructions; 18 U.S.C. § 1350; 18 U.S.C. § 1519. ⚠ R.
2a. And in this exact domain, a government has already built the architecture
Source: UK Government Cyber Action Plan, Department for Science, Innovation and Technology, published 6 January 2026, last updated 20 March 2026. Chapter 3: Accountability, read in full 22 August 2026. ✅ — every quotation below re-verified against the live page the same day.
Everything in § 2 is an analogy from another field. This is not an analogy. It is cyber risk, including AI risk, in 2026, with an accountability architecture already written — and every load- bearing element of it is a named human being.
The diagnosis, in the government’s own words
“Current accountability structures have failed to achieve the right level of resilience. Responsibilities for cyber risks are unclear at all levels of government, including across the supply chain. Leaders lack visibility and understanding of the risk and resilience levels within their purview.”
That is the census’s central finding, written by a state about itself. Not we lack controls. Not we lack technology. Responsibilities are unclear.
And the remedy is stated as a relationship, not a control:
“The government needs to reset its relationship with cyber risk by ensuring that it is visible, understood, owned and actively managed.”
The sentence
“The Accounting Officer is the senior official (Permanent Secretary or CEO) with overall accountability for an organisation. This includes **personal accountability for the cyber risk of that organisation.”**
Personal accountability. A named natural person, identified by office, for cyber risk. It already exists, it is already in force across the whole of British central government, and nobody argued that no competent person would take the job.
And the phrase appears exactly once in the entire plan. A document of nine chapters about accountability uses the words personal accountability one time, and spends them on the Accounting Officer. Everything else in it is owned by units, functions, boards and departments. The plan is not casual about this: it knows the difference between an organization being accountable and a person being accountable, and it makes the distinction once, deliberately, at the top.
And the duties read like SEC. 8 with the numbers filed off
The plan lists what an Accounting Officer must do. Compare it to what this Act asks:
| Accounting Officer responsibility | this Act |
|---|---|
| “ensuring that controls to remain within risk appetite are implemented and effective” | SEC. 8 — certification after reasonable inquiry, not on assurance received |
| “appoint a senior, capable individual with authority to manage organisation-wide cyber security” | the controlling person — practical authority, not title |
| “appoint a senior, capable individual with authority for organisation-wide digital and information technology” | as above |
| “appoint an informed board member with expertise in cyber security and resilience” | the empowerment limb |
| “ensure escalation of risks outside cross-government risk appetite” | incident reporting on fixed clocks |
| “ensure routine reporting to departmental board” | records duties |
Read the phrase that appears twice: “a senior, capable individual with authority.” That is Illinois’s “designation and empowerment of senior personnel” — the four words § 5 of this file is about — written as a duty owed by a named person, instead of as a box for an auditor to tick.
Illinois asks an outside contractor to confirm that such a person exists. The UK requires a named official to appoint them, and answers for it if they do not. Same requirement. Different end of the telescope.
And generative AI is already classified as the risk no single organization can hold
The plan divides cyber risk in two. Government-wide risks are defined as “risks with severity/complexity that would be unmanageable by a single organisation” — and the listed examples include:
“Risks created by widespread adoption of novel technologies, such as generative AI.”
Those risks are owned by the DSIT Permanent Secretary, as Government Technology Risk Owner. One post. One person. The stated objective is to “establish central accountability for risks that departments or organisations cannot reasonably be expected to manage.”
A government has formally judged that generative-AI risk exceeds what any single organisation can hold, and responded by naming one individual to hold it.
Set that beside the census. Enacted American frontier statutes assign the same class of risk to large frontier developers — corporate persons — and to no natural person at all. Two jurisdictions reached opposite conclusions about the same technology in the same year, and only one of them wrote down a name.
The limits, and they are real
This is not criminal liability and this file must not imply that it is. The Accounting Officer regime is constitutional and administrative: an AO answers to Parliament and the Public Accounts Committee, and the sanction is political and professional, not custodial. Nobody goes to prison under Chapter 3.
It also governs the public sector, not private frontier developers. Suppliers appear only through contract — “good procurement practices, contractual security and resilience terms and audit and review processes” — which is precisely the weaker instrument this project argues is insufficient where the duty ought to be direct.
So what it proves is bounded, and it is the bound that matters. Not that criminal certification works. That personal, non-delegable accountability for AI-related cyber risk, attached to a named individual with authority, is not a radical proposal, an untested one, or an unworkable one. It is what a G7 government wrote down for itself when it decided that unclear responsibility was the thing that had failed.
The burden the objection carries is therefore heavier than it looks. Anyone arguing that a frontier developer cannot have a responsible officer has to explain why the arrangement the British state imposed on itself — for this technology, this risk, this year — is impossible for the companies that build it.
⚠ Checks owed. Confirm the Accounting Officer duty against Government Functional Standard 007: Security and *Managing Public Money, which are its primary sources — the Action Plan restates the duty, it does not create it. Establish whether any Accounting Officer has ever been personally sanctioned over cyber risk. If none ever has, that is a finding against this section, it belongs in the file, and it goes in the register — because it would make Chapter 3 evidence that the architecture is normal and no evidence at all that it bites.*
3. What a signature actually does, from the field that measured it
The best evidence that naming a person changes behavior does not come from law. It comes from surgery, where somebody ran the experiment.
The WHO safe surgery checklist runs nineteen checks at three pause points. One of them is not a technical step at all: the team members confirm they have been introduced by name and role.
Atul Gawande, who led the work, records how that item landed:
“The introduction of names and roles at the start of an operating day proved a point of particularly divided view. From Delhi to Seattle, the nurses seemed especially grateful for the step, but the surgeons were sometimes annoyed by it. Nonetheless, most complied.”
Read that twice. The item that required people to say who they were was the most resisted on the list — resisted by the person with the most authority in the room, and valued by the people with the least.
Gawande records the objection verbatim too: “This checklist is a waste of time.” And what adoption actually required: “a shift in authority, responsibility, and expectations about care.”
That is SEC. 8, its objection, and its beneficiaries, observed in another field twenty years early.
And the item worked because of what it did to authority, not because it was on a list
The naming step was not an introduction. It was standing. A nurse who has said her name aloud and been heard is a person who can interrupt a surgeon. One who has not, is not. The measured effect did not come from remembering steps — it came from changing who was permitted to stop the room.
Gawande says so directly, in the line quoted above and easy to read past: what adoption required was “a shift in authority, responsibility, and expectations about care.” Authority is the first word. The list was the occasion. The redistribution of power was the mechanism — and the reason surgeons resisted it is that they correctly understood which of the two was happening.
That is what a signature is, and it is why “this is just paperwork” misses. A certification does two things at once. It creates an artifact — the evidentiary function § 2 describes. And it creates a person who is permitted to say no, and with them a route for everyone below who wants to. An engineer with a concern and nobody obliged to receive it has no channel. An engineer with a concern and a named officer who must personally certify has one — and that officer now has a reason to want the bad news before signing rather than after.
Illinois wrote this into its own text, and it is the word most often dropped when the provision is quoted. 430 ILCS 185/10(d)(2)(C) does not ask the auditor to confirm the designation of senior personnel. It asks for an assessment of “designation and empowerment” of them. Naming without power is what the statute already refuses to accept — it simply stops before asking the empowered person to sign.
Which also settles who should not be exposed
Liability tracks authority or it is unjust. That is the whole content of Park: whether the defendant stood in responsible relation to the conduct and had the power to prevent it. It is why this project asks for a duty on controlling persons and nowhere else.
So not the lead auditor. An auditor cannot stop a deployment. Exposure there would fall on the one participant with no power to act, and would buy nothing, because an auditor can describe a condition and never halt it. It would also do the specific damage the surgical evidence warns against: loading risk onto the person brought in to report honestly is how you stop getting honest reports.
And this stopped being hypothetical on 6 August 2026
The first time a frontier incident produced public blame, it went to the tester.
Meta told the BBC that the incident in which its model reached another organization’s systems was caused by a “misconfiguration” by its independent tester. The German public broadcaster reported it the same way: the problem “lag… in einer Fehlkonfiguration des Systems bei demselben Testpartner” — ⚠ at the same test partner. The tester, Irregular, responded that the Meta incident “is the exact same evaluation-environment issue that was already disclosed by Anthropic last week.”
Note the shape. The developer locates the fault in the outside contractor hired to inspect the work. The contractor locates it in a class of problem affecting everyone. Neither account reaches a person, and the only party publicly identified as at fault is the one with no power to stop a deployment.
Nothing here asserts that Meta’s characterization is wrong, or that Irregular did anything improper. This project takes no position on either. The point is where the blame landed, not whether it was deserved.
Enacted American frontier law requires exactly one signature, and it belongs to the auditor. The first real-world incident put the blame in the same place.
That is the design error, demonstrated. A regime that names only the inspector will find fault only with the inspector — and each time it does, the honest reporting this whole architecture depends on gets more expensive to give.
The signature belongs where the halt authority already sits — and it is the same principle in both directions. Give the power to the person who can use it. Put the name on the person who has it.
Source: Atul Gawande, *The Checklist Manifesto (2009). ⚠ R — read from a digital copy on 21 August 2026; page references to be pinned against a paginated edition before publication.*
4. And the reason the frontier’s own defense fails on Gawande’s distinction
The same book supplies the distinction that decides whether a duty is fair. Following the philosophers Gorovitz and MacIntyre, Gawande separates two ways of failing:
“The first is ignorance — we may err because science has given us only a partial understanding of the world and how it works… The second type of failure the philosophers call ineptitude — because in these instances the knowledge exists, yet we fail to apply it correctly.”
And then he reaches for the legal word himself, without being asked:
“It is not for nothing that the philosophers gave these failures so unmerciful a name — ineptitude. Those on the receiving end use other words, like negligence or even heartlessness.”
The industry’s defense is ignorance. Nobody yet knows how to make these systems reliably safe, so nobody can fairly be blamed for failing to.
But the frontier safety frameworks are the industry’s own written statement of what it does know. Evaluations. Capability thresholds. Deployment gates. Halt authority. Twelve companies have published one. Where a developer does not do what its own framework says, that is not ignorance — it is the thing Gawande’s philosophers named, and the word the people on the receiving end use for it is negligence.
Which is precisely the floor Park supplies and SEC. 6 adopts. The frameworks the companies wrote voluntarily are the standard of care they can be measured against.
And one more line from the same book, because it is the industry’s proposal stated in advance: “the traditional solution in most professions has not been to punish failure but instead to encourage more experience and training.” More research. Better evaluations. Gawande’s entire book is the demonstration that this does not work at scale, in a field with far more training than this one.
4a. “This will flood the system” — and the answer, written down by a government
The commonest practical objection to a personal criminal duty is volume. Investigations everywhere. Defensive paperwork. Prosecutors with no capacity chasing conduct they cannot assess. Engineers who lawyer up instead of writing incident reports. It is a serious objection and it is about enforcement capacity, which is the scarce resource in every regulatory regime ever built.
The UK government answered it in June 2026 while trying to do something else entirely. Running frontier models against government code across nine organizations, the Government Cyber Coordination Center found that the models produced candidate findings far faster than humans could check them, and wrote down the lesson:
“Triage is essential. Agents generate candidate findings far faster than humans can validate them. Poorly scoped runs burn tokens on low-value targets; weak review dumps the load onto stretched security teams… As in traditional vulnerability management, it’s not how many issues are found, but whether triage points limited resource where it matters.”
— DSIT and NCSC, When AI Leaves the Lab, 12 June 2026
Read that as a statement about statutes and it is the whole design brief.
A regime is not measured by how much conduct it covers. It is measured by where it points. A duty laid on everyone reaches nobody, because limited enforcement resource spreads until it is invisible. A duty laid on one person with a named power is a triage point.
Which is exactly what enacted frontier law lacks
The corpus the census reads is a findings machine with no triage point. Illinois requires an annual independent audit, a detailed assessment of internal controls, and an unredacted report retained “for as long as a frontier model is deployed plus 5 years.” Connecticut routes quarterly catastrophic-risk reports to “the officers and directors.” Twelve companies publish safety frameworks. H.R. 9917 would mandate a shutdown capability and $20,000,000 a day.
All of that generates findings. None of it says who the findings are about. The same case study puts the second half of the point in four words:
“Finding isn’t the same as fixing.”
That is the transparency/accountability distinction arriving in a government document. Disclosure produces information. Only a duty produces a person who has to act on it.
And it is why the auditor is the wrong target, stated as a resourcing argument
Exposure aimed at people without halt authority is the definition of untriaged enforcement. It spends scarce resource on participants who could not have prevented the outcome, and it degrades the input the whole system runs on, because loading risk onto the person brought in to report honestly is how you stop getting honest reports.
A certification requirement does not widen the net. It puts a handle on it. One person, one document, one moment — chosen because it is the moment at which a system ships and the person who decided that it would.
5. The gap, stated in one paragraph
Enacted frontier law requires exactly one signature, and it belongs to the auditor. Illinois requires “the signature of the lead auditor certifying the results,” at 430 ILCS 185/10(d)(2)(G). The legislative instinct to demand a named human signature exists, is already in force, and has been aimed at the outside contractor hired to inspect the work — not at the officer who decides to ship.
And four items earlier in the same list, Illinois asks that auditor to check something specific. Item (C) requires the report to contain “a detailed assessment of the large frontier developer’s internal controls, including its designation and empowerment of senior personnel responsible for such implementation by the large frontier developer, its employees, and its contractors.”
Read (C) and (G) together and the shape of the gap is exact. Illinois requires an auditor to verify that a responsible person has been named and genuinely empowered — and then takes the signature from the auditor. The person whose existence and authority were just confirmed signs nothing. The finding is not that Illinois failed to think of a responsible officer. It is that Illinois thought of one, wrote the requirement, had it verified by an independent party, and stopped one line short of asking that person to put their name to anything.
Connecticut routes quarterly catastrophic-risk reports to “the officers and directors of the large frontier developer” and asks nothing of them in return.
H.R. 9917 would mandate a shutdown capability and civil penalties of $20,000,000 a day. The only human signature in the bill is the sponsor’s own, on the line marked “(Original Signature of Member).”
And of twelve published frontier safety frameworks, not one requires an attestation of a deployment decision. At the best-documented laboratory on earth there is a decision-maker and no artifact of the decision.
So the objection has the burden backward. A signature is not a novel formality being proposed for an industry that has never faced one. It is the ordinary instrument by which American law reaches an executive at all — and its absence at the compute frontier is not a gap in transparency. It is the removal of the mechanism.
Addendum, 24 August — two later corroborations, linked rather than restated. The economics of why the entity fine cannot substitute for the signature now carry third-party magnitudes — the field’s own forecasters price the industry’s capital expenditure, revenue growth, and structural tax position at levels no enactable fine schedule reaches (the forecasters’ arithmetic, § 4). And the principle the signature enforces has been stated by Washington itself, in its own roadmap’s one sentence on attestation: enforcement mechanisms are required “rather than relying on voluntary attestation” (two visions). The mechanism this page documents is the enforced form of exactly that sentence.
Corrections to the project contact; they enter the errata register with the fix attached and permanent credit.