<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0" xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd" xmlns:googleplay="http://www.google.com/schemas/play-podcasts/1.0"><channel><title><![CDATA[clickyquack]]></title><description><![CDATA[clickyquack]]></description><link>https://quintic.substack.com</link><image><url>https://substackcdn.com/image/fetch/$s_!YGCk!,w_256,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7414c38d-c2e9-439c-85be-efd971d05b9d_400x400.jpeg</url><title>clickyquack</title><link>https://quintic.substack.com</link></image><generator>Substack</generator><lastBuildDate>Tue, 11 Aug 2026 19:54:34 GMT</lastBuildDate><atom:link href="https://quintic.substack.com/feed" rel="self" type="application/rss+xml"/><copyright><![CDATA[quintic]]></copyright><language><![CDATA[en]]></language><webMaster><![CDATA[quintic@substack.com]]></webMaster><itunes:owner><itunes:email><![CDATA[quintic@substack.com]]></itunes:email><itunes:name><![CDATA[clickyquack]]></itunes:name></itunes:owner><itunes:author><![CDATA[clickyquack]]></itunes:author><googleplay:owner><![CDATA[quintic@substack.com]]></googleplay:owner><googleplay:email><![CDATA[quintic@substack.com]]></googleplay:email><googleplay:author><![CDATA[clickyquack]]></googleplay:author><itunes:block><![CDATA[Yes]]></itunes:block><item><title><![CDATA[On using crises to shift political will for AI]]></title><description><![CDATA[TL;DR: We&#8217;ll probably be getting more AI safety incidents, so amplify the ones that would justify or highlight the urgency of your preferred policy solutions even from a non-technical skeptic concerned with national security&#8217;s perspective, as these will be far more effective than anything else.]]></description><link>https://quintic.substack.com/p/on-using-crises-to-shift-political</link><guid isPermaLink="false">https://quintic.substack.com/p/on-using-crises-to-shift-political</guid><dc:creator><![CDATA[clickyquack]]></dc:creator><pubDate>Tue, 11 Aug 2026 04:08:40 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!YGCk!,w_256,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7414c38d-c2e9-439c-85be-efd971d05b9d_400x400.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p><span>TL;DR: We&#8217;ll probably be getting more AI safety incidents, so amplify the ones that would justify or highlight the urgency of your preferred policy solutions even from a non-technical skeptic concerned with national security&#8217;s perspective, as these will be far more effective than anything else.</span></p><h1><em><a href="https://www.lesswrong.com/posts/vHsjEgL44d6awb5v3/the-milton-friedman-model-of-policy-change"><span>Feeling</span></a></em><a href="https://www.lesswrong.com/posts/vHsjEgL44d6awb5v3/the-milton-friedman-model-of-policy-change"><span> the Crisis</span></a></h1><p><span>Strong policy change happens most effectively when the attributed problem is </span><em><span>felt</span></em><span> enough to warrant the perceived costs of the proposed solution. Many relevant precedents to AI governance can be viewed through this lens:</span></p><ul><li><p><span>What led to the rapid establishment of the </span><a href="https://en.wikipedia.org/wiki/International_Atomic_Energy_Agency"><span>IAEA</span></a><span> and </span><a href="https://en.wikipedia.org/wiki/Treaty_on_the_Non-Proliferation_of_Nuclear_Weapons"><span>NPT</span></a><span>, in spite of the </span><a href="https://en.wikipedia.org/wiki/IAEA_safeguards"><span>costs endured by doing so</span></a><span>? It&#8217;s because the effects of nuclear war and threat of mutually assured destruction had </span><a href="https://en.wikipedia.org/wiki/Atomic_bombings_of_Hiroshima_and_Nagasaki"><span>just</span></a><span> </span><a href="https://en.wikipedia.org/wiki/Cold_War_(1953%E2%80%931962)"><span>been</span></a><span> </span><em><a href="https://en.wikipedia.org/wiki/Atoms_for_Peace"><span>felt</span></a></em><span> by everyone, so they had better make sure it never happens again.</span><a class="footnote-anchor" data-component-name="FootnoteAnchorToDOM" id="footnote-anchor-1" href="#footnote-1" target="_self">1</a></p></li><li><p><span>How did we enact such strong enforcement measures for mitigating the COVID-19 pandemic so rapidly? It&#8217;s because decisionmakers </span><em><span>felt</span></em><span> the rapid spread, the climbing death toll, the general feeling of uncertainty surrounding how bad it was going to be, and the established experts sounding the alarm on what ought to be done, enough to warrant using their authority to invoke emergency measures taken. Why did we </span><a href="https://www.lesswrong.com/posts/pvEuEN6eMZC2hqG9c/humanity-learned-almost-nothing-from-covid-19"><span>underprioritize stronger pandemic prevention</span></a><span> and even roll-back some pandemic response measures afterward? It&#8217;s because </span><a href="https://www.lesswrong.com/posts/b6HYxnxAhLeWHGCgG/covid-skepticism-isn-t-about-science"><span>people </span></a><em><a href="https://www.lesswrong.com/posts/b6HYxnxAhLeWHGCgG/covid-skepticism-isn-t-about-science"><span>felt</span></a></em><a href="https://www.lesswrong.com/posts/b6HYxnxAhLeWHGCgG/covid-skepticism-isn-t-about-science"><span> the negative impacts of the lockdown mandates far more</span></a><span> than the pandemic itself or the impacts counterfactually not experienced as a result, leaving many people overcorrecting towards general opposition to pandemic-response measures.</span></p></li><li><p><a href="https://quintic.substack.com/p/why-arent-we-mandating-nucleic-acid"><span>Why is there still no law mandating nucleic acid screening</span></a><span>, so as to ensure someone trying to order a virus from a nucleic acid synthesis company would be caught and stopped before they could do so? Seriously, this is essentially unanimously supported, has had advocacy for decades, including by the industry themselves and </span><a href="https://screendna.org/"><span>especially recently</span></a><span>, and yet the bill that could solve this has been waiting in committee without markups for just over 7 months now after being introduced. It&#8217;s because Congress is slow by design, devoting time to a particular bill or issue costs time spent on others, and plenty of other bills </span><em><span>feel </span></em><span>like more of a priority. There have been no recent attempts by bioterrorists to use this to their advantage, after all.</span></p></li><li><p><span>Why did the </span><a href="https://en.wikipedia.org/wiki/Thalidomide_scandal"><span>thalidomide crisis</span></a><span> prompt the </span><a href="https://en.wikipedia.org/wiki/Kefauver%E2%80%93Harris_Amendment"><span>safety and efficacy requirements</span></a><span> on the development of new drugs? And why do these persist in spite of </span><a href="https://en.wikipedia.org/wiki/Criticism_of_the_Food_and_Drug_Administration#Charges_of_over-regulation"><span>slowing down drug development far more</span></a><span> than what would have been enough to prevent the thalidomide crisis? It&#8217;s because the thalidomide crisis was </span><em><span>felt</span></em><span> by everyone from the scandal it produced, and you never </span><em><span>feel</span></em><span> the downside of medicine that could have helped you counterfactually not being available earlier. At least, not in such a way that leads you to attribute it to the drug approval process needing reformed.</span></p></li><li><p><span>Where has the environmentalist movement succeeded, in spite of its worst risks, like AI, also being hypothetical long-term events never felt? Especially in spite of the group that </span><a href="https://en.wikipedia.org/wiki/The_Logic_of_Collective_Action"><span>reaps the </span></a><em><a href="https://en.wikipedia.org/wiki/The_Logic_of_Collective_Action"><span>concentrated benefits</span></a></em><span> from not complying with regulation investing far more resources to influence political outcomes in their favor than the general public who only experiences its </span><em><span>diffuse costs</span></em><span>? It&#8217;s where people saw and </span><em><span>felt</span></em><span> its near-term consequences the most: the </span><a href="https://en.wikipedia.org/wiki/Great_Smog_of_London"><span>Great Smog of London</span></a><span> prompting the </span><a href="https://en.wikipedia.org/wiki/Clean_Air_Act_1956"><span>UK&#8217;s Clean Air Act</span></a><span>, the </span><a href="https://en.wikipedia.org/wiki/Cuyahoga_River#Environmental_cleanup"><span>Cuyahoga River fire</span></a><span> prompting the expansion of the </span><a href="https://en.wikipedia.org/wiki/Clean_Water_Act"><span>Clean Water Act</span></a><span> and accelerating the creation of the </span><a href="https://en.wikipedia.org/wiki/United_States_Environmental_Protection_Agency"><span>EPA</span></a><span>, </span><a href="https://en.wikipedia.org/wiki/Love_Canal"><span>Love Canal&#8217;s contamination</span></a><span> and </span><a href="https://en.wikipedia.org/wiki/Love_Canal#Health_effects"><span>resulting adverse health effects</span></a><span> prompting </span><a href="https://en.wikipedia.org/wiki/Superfund"><span>Superfund</span></a><span>, etc.</span></p></li><li><p><span>Well then how come the </span><a href="https://en.wikipedia.org/wiki/Montreal_Protocol"><span>Montreal Protocol</span></a><span> succeeded? They started reversing the depletion of the ozone layer well before its adverse effects were </span><em><span>felt</span></em><span> by many people, </span><em><span>and </span></em><span>it suffered from the </span><a href="https://en.wikipedia.org/wiki/Public_choice#interests"><span>concentrated benefits versus diffuse costs</span></a><span> problem, </span><em><span>and</span></em><span> it&#8217;s a binding international agreement which is much more difficult to establish, so it&#8217;s unusually difficult for many of the same reasons a binding international AI treaty would be! It&#8217;s partially because </span><a href="https://www.nytimes.com/1986/11/05/us/us-report-predicts-rise-in-skin-cancer-with-loss-of-ozone.html"><span>advocates leaned into</span></a><span> the more immediate &#8220;the ozone hole causes cancer&#8221; messaging than &#8220;the ozone hole will gradually make the Earth less habitable&#8221;, partially because environmentalism was already a much larger political movement due to other factors, but in this case it was actually primarily because </span><a href="https://rapidtransition.org/stories/back-from-the-brink-how-the-world-rapidly-sealed-a-deal-to-save-the-ozone-layer/"><span>the most active lobbyist group found harmless alternatives</span></a><span> to the substances depleting the ozone layer that weren&#8217;t particularly costly to switch to.</span></p></li></ul><h1><em><a href="https://futurism.com/openai-employees-say-firms-chief-scientist-has-been-making-strange-spiritual-claims"><span>Feeling </span></a></em><a href="https://futurism.com/openai-employees-say-firms-chief-scientist-has-been-making-strange-spiritual-claims"><span>the AGI</span></a></h1><ul><li><p><span>Why did the </span><a href="https://www.politico.com/news/2026/06/13/inside-the-whirlwind-24-hours-that-led-the-white-house-to-slap-export-controls-on-anthropic-00961519"><span>perceived jailbreak</span></a><span> to access Mythos&#8217; advanced cyber capabilities </span><a href="https://thezvi.substack.com/p/american-government-takes-down-claude"><span>prompt its export controls</span></a><span>? Because the government had already </span><em><span>felt</span></em><span> its capabilities from the </span><a href="https://www.anthropic.com/glasswing"><span>reports surrounding it</span></a><span>, and wanted to be especially cautious to prevent foreign actors taking advantage of it.</span></p></li><li><p><span>Why did the </span><a href="https://en.wikipedia.org/wiki/2026_OpenAI_agent_cyberattacks"><span>OpenAI HuggingFace security incident</span></a><span> lead Trump to tell reporters the White House was </span><a href="https://www.youtube.com/watch?v=kTWO1DU-3ZA"><span>looking at ways to balance controls for AI with not coming second to China</span></a><span>? Why did several</span><a class="footnote-anchor" data-component-name="FootnoteAnchorToDOM" id="footnote-anchor-2" href="#footnote-2" target="_self">2</a><span> members of Congress use this event and </span><a href="https://www.anthropic.com/news/investigating-incidents-cybersecurity-evals"><span>related reports</span></a><span> to point to the need for mandated transparency? Because the </span><a href="https://www.bbc.com/news/articles/c2el319vzr3o"><span>news coverage</span></a><span>, </span><a href="https://www.reuters.com/legal/litigation/openais-sam-altman-discuss-voluntary-ai-safety-tests-with-trump-officials-after-2026-07-30/"><span>Sam Altman</span></a><span>, and </span><a href="https://www.pacingthefrontier.com/"><span>over a thousand frontier AI lab employees</span></a><span> helped them </span><em><span>feel</span></em><span> the seriousness of the event.</span></p></li><li><p><span>Why has the White House otherwise been so averse to AI regulation, citing the need to beat China in the AI race? Because </span><a href="https://images.nvidia.com/pdf/Open-Weights-and-American-AI-Leadership.pdf"><span>that&#8217;s what all the loudest voices have been telling them</span></a><span> (and because this administration tends to be more skeptical of economic regulation in general, which could be a good heuristic under </span><a href="https://blog.aifutures.org/p/ai-as-profoundly-abnormal-technology"><span>normal circumstances</span></a><span>).</span></p></li><li><p><span>Why does the general public seem </span><a href="https://blog.andymasley.com/p/ai-and-the-environment"><span>far more concerned by data centers</span></a><span>? Because regardless of how much they use AI themselves, or indirectly benefit from companies whose products they buy using it, they only </span><em><span>feel</span></em><span> the giant ugly buildings being built nearby, and they hear that it&#8217;s </span><a href="https://blog.andymasley.com/p/the-ai-water-issue-is-fake"><span>using up all their water</span></a><span>. One AI company&#8217;s agent hacking another AI company sounds like </span><em><span>their</span></em><span> problem.</span></p></li><li><p><span>Had the victim of the HuggingFace incident instead been any of the vast majority of institutions that would have sued OpenAI in response, prompting the heavy news coverage and legal ruling that would have followed? Had it been a government agency? An airport? A hospital? Any other piece of digital infrastructure providing services frequently used by a large portion of the general public and viewed as important? Had it tangibly inconvenienced the people who used the service, even if only in some minor way? Had they really </span><em><span>felt</span></em><span> it? Raising transparency, incident reporting, control, and liability standards for AI labs would be the </span><em><span>least</span></em><span> of the resulting demands made.</span></p></li></ul><p><span>This, the </span><a href="https://www.anthropic.com/news/investigating-incidents-cybersecurity-evals"><span>several</span></a><span> </span><a href="https://www.aisi.gov.uk/blog/incident-report-unsanctioned-agent-behaviour-during-cyber-testing"><span>similar</span></a><span> </span><a href="https://www.npr.org/2026/08/08/nx-s1-5924878/meta-ai-breaches-external-firm-during-security-testing-sandbox-error"><span>reports</span></a><span> that shortly followed, and the fact that </span><a href="https://www.lesswrong.com/posts/k3eKqKzq4Y7xnqEfZ/openai-has-already-ended-an-internal-pause"><span>OpenAI has already continued development</span></a><span> suggests we&#8217;ll likely be getting more incidents of this kind</span><a class="footnote-anchor" data-component-name="FootnoteAnchorToDOM" id="footnote-anchor-3" href="#footnote-3" target="_self">3</a><span>. They&#8217;re making it easy for us; all we have to do is </span><em><a href="https://www.lesswrong.com/posts/Zp6wG5eQFLGWwcG6j/focus-on-the-places-where-you-feel-shocked-everyone-s"><span>not drop the ball</span></a></em><span>. But as &#8220;</span><a href="https://www.lesswrong.com/posts/EexsebbYhbe2gXkPP/the-current-bottleneck-is-political-will-not-research"><span>The current bottleneck is political will, not research</span></a><span>&#8221; recently illustrated (which I strongly urge you to read</span><a class="footnote-anchor" data-component-name="FootnoteAnchorToDOM" id="footnote-anchor-4" href="#footnote-4" target="_self">4</a><span> if you haven&#8217;t already), the ball is being dropped </span><em><span>nowhere harder</span></em><span> than here.</span></p><div class="footnote" data-component-name="FootnoteToDOM"><a id="footnote-1" href="#footnote-anchor-1" class="footnote-number" contenteditable="false" target="_self">1</a><div class="footnote-content"><p>In fairness, the primary factor preventing nuclear war right now is the threat of mutual destruction more so than these enforcement mechanisms meant to mitigate it, although this is also a potentially relevant insight to international AI governance.</p></div></div><div class="footnote" data-component-name="FootnoteToDOM"><a id="footnote-2" href="#footnote-anchor-2" class="footnote-number" contenteditable="false" target="_self">2</a><div class="footnote-content"><p><span>Rep. Greg Casar </span><a href="https://x.com/RepCasar/status/2079697107607306670"><span>here</span></a><span> and </span><a href="https://x.com/RepCasar/status/2082472999819555271"><span>here</span></a><span>, Rep. Ted Lieu </span><a href="https://x.com/tedlieu/status/2079774629283934422"><span>here</span></a><span>, Rep. Yvette Clarke </span><a href="https://x.com/RepYvetteClarke/status/2079994183494877591"><span>here</span></a><span>, Rep. Pramila Jayapal </span><a href="https://x.com/RepJayapal/status/2080420706777747736"><span>here</span></a><span>, Rep. Nathaniel Moran </span><a href="https://x.com/RepNateMoran/status/2079949264436756504"><span>here</span></a><span>, Senator Bernie Sanders </span><a href="https://x.com/BernieSanders/status/2080022831891366374"><span>here</span></a><span>, Rep. Becca Balint </span><a href="https://x.com/RepBeccaB/status/2082558380904731003"><span>here</span></a><span>, Rep. Bill Foster </span><a href="https://x.com/repbillfoster/status/2082552502315094290"><span>here</span></a><span>, Rep. Lori Trahan </span><a href="https://x.com/RepLoriTrahan/status/2082990834400756082"><span>here</span></a><span>. There&#8217;s probably more I didn&#8217;t find.</span></p></div></div><div class="footnote" data-component-name="FootnoteToDOM"><a id="footnote-3" href="#footnote-anchor-3" class="footnote-number" contenteditable="false" target="_self">3</a><div class="footnote-content"><p><span>I would imagine the main way we </span><em><span>don&#8217;t</span></em><span> is if progress in capabilities rapidly outpaces economic diffusion by enough of a margin for the cracks to not start showing until it&#8217;s too late.</span></p></div></div><div class="footnote" data-component-name="FootnoteToDOM"><a id="footnote-4" href="#footnote-anchor-4" class="footnote-number" contenteditable="false" target="_self">4</a><div class="footnote-content"><p><span>I also urge you to read:</span></p><ul><li><p><span>&#8220;</span><a href="https://www.lesswrong.com/s/4PLuwEyMZhT89Dxpo"><span>An Activist View of AI Governance</span></a><span>&#8221; for a much more detailed overview of AI safety political advocacy work with a US focus.</span></p></li><li><p><a href="https://www.lesswrong.com/posts/AWKkDLDnShemNCSzZ/the-invisible-side-of-ai-governance"><span>This overview of insider policy work</span></a><span>, from which I&#8217;d like to highlight: &#8220;In several international forums over the past 18 months, US positioning has been the ultimate bottleneck. My main answer to this is that</span><strong><span> it&#8217;s a priority to do insider work at the White House for those who can access it.</span></strong><span>&#8221;</span></p></li></ul><ul><li><p><span>ControlAI&#8217;s &#8220;</span><a href="https://www.lesswrong.com/posts/A7BtBD9BAfK2kKSEr/what-we-learned-from-briefing-140-lawmakers-on-the-threat"><span>What We Learned from Briefing 140+ Lawmakers on the Threat from AI</span></a><span>&#8221;.</span></p></li><li><p><span>PauseAI&#8217;s </span><a href="https://pauseai.info/us-lobby-guide"><span>US lobbying guide</span></a><span>.</span></p></li><li><p><span>This </span><a href="https://forum.effectivealtruism.org/posts/AGcny8oBxBDCjqxdr/where-i-am-donating-in-2025"><span>case for donating</span></a><span> to AI safety political advocacy work.</span></p></li></ul></div></div>]]></content:encoded></item><item><title><![CDATA[Why aren't we mandating nucleic acid screening yet?]]></title><description><![CDATA[In trying to investigate what could shift political will for AI governance as someone without much of a policy background, I decided to start with investigating the much less controversial proposal of mandating nucleic acid screening.]]></description><link>https://quintic.substack.com/p/why-arent-we-mandating-nucleic-acid</link><guid isPermaLink="false">https://quintic.substack.com/p/why-arent-we-mandating-nucleic-acid</guid><dc:creator><![CDATA[clickyquack]]></dc:creator><pubDate>Tue, 04 Aug 2026 23:25:29 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!YGCk!,w_256,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7414c38d-c2e9-439c-85be-efd971d05b9d_400x400.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>In trying to investigate <a href="https://www.lesswrong.com/posts/EexsebbYhbe2gXkPP/the-current-bottleneck-is-political-will-not-research">what could shift political will for AI governance</a> as someone without much of a policy background, I decided to start with investigating the much less controversial proposal of mandating nucleic acid screening. Generally, policy change is much more likely to pass when the upside is obvious and it isn&#8217;t costly to comply. Mandating nucleic acid screening fits this abundantly well: make sure that if someone has enough expertise to design a dangerous protein, or uses an AI system to do so, it would get caught and stopped if they tried to pay a lab to produce and ship it to them. Automated screening technology that would catch the vast majority of near-term cases is <a href="https://securedna.org/our-impact/">already here</a> and isn&#8217;t costly to implement. And yet, we still aren&#8217;t even doing this, which is a bad sign for any costlier AI regulations motivated by less legible risks. Notably, unlike AI slowdown proposals, there&#8217;s little to no argument to be made that anything short of a verifiable international treaty would cede our innovation advantage to China. Why is this stalling?</p><p>The main reason seems to be that passing legislation takes a lot of sustained effort, and there&#8217;s no crisis or warning-shot to make it feel urgent enough for Congress to prioritize. The relevant bill here is <a href="https://www.congress.gov/bill/119th-congress/senate-bill/3741">S.3741</a>, introduced January 29, 2026, which would solve much of the problem, at least on a national scale. <a href="https://counterfactual.blog/p/s3741-and-the-art-of-not-dying-of">This post</a> by Sophie Kim goes into more detail, and provides additional commentary and proposed amendments. It&#8217;s come after decades of advocacy, most of the nucleic acid synthesis industry already voluntarily screening orders<a class="footnote-anchor" data-component-name="FootnoteAnchorToDOM" id="footnote-anchor-1" href="#footnote-1" target="_self">1</a>, and being recommended in the Executive Office of the President&#8217;s July 2025 <a href="https://www.whitehouse.gov/wp-content/uploads/2025/07/Americas-AI-Action-Plan.pdf">AI Action Plan</a> for institutions receiving federal funding. It&#8217;s also worth noting that the <a href="https://screendna.org/">open letter</a> that called on Congress to pass this, signed by dozens of leading experts in several relevant fields (which helped to indicate the cost on innovation would be minimal), was published June 3, 2026, and that many members <a href="https://x.com/willpoffwebster/status/2062522291603243031">just weren&#8217;t aware</a> that <a href="https://www.npr.org/2025/10/02/nx-s1-5558145/ai-artificial-intelligence-dangerous-proteins-biosecurity">open-source AI tools can already design new dangerous proteins</a> prior to this. Per <a href="https://archive.ph/Ru4pv">Fortune</a>:</p><blockquote><p>While the bill slowly moves its way through Congress, Josh Wentzel, a senior fellow at the Foundation for American Innovation, told <em>Fortune</em> that the letter was a good opportunity to show lawmakers that the AI industry and companies who sell synthetic DNA and RNA were equally concerned about the issue.</p><p>&#8220;This is bipartisan, concrete, achievable, and noncontroversial,&#8221; Wentzel said, adding he hopes now that Congress sees these parties are aligned, it can move forward with passing the Biosecurity Modernization and Innovation Act. &#8220;It&#8217;s a goal among many national security experts and, crucially, something the nucleic acid synthesis industry itself has called for.&#8221;</p></blockquote><p>So, the open letter does seem to be moving the bill faster than it otherwise would have. But in spite of <em>all</em> of this, and strong media coverage of the letter, and <a href="https://x.com/AlecStapp/status/2062519741839741054">advocacy from the think tanks that co-organized the letter</a>, the bill is still waiting in committee without undergoing any markups two months later. The bill is practically certain to pass eventually, but short of some event that would make it a higher priority, it&#8217;s likely going to take several more months. For reference, the much more mainstream <a href="https://en.wikipedia.org/wiki/Epstein_Files_Transparency_Act">Epstein Files Transparency Act</a> took about 5 months to pass after being introduced. Congress is really <em>that</em> slow. I knew they had a reputation for it, but it&#8217;s disheartening to see it for myself. This lends credence to my prior theory that not much is going to concretely get done in AI governance until the effects are <em>felt</em> more, which I intend to investigate next.</p><div class="footnote" data-component-name="FootnoteToDOM"><a id="footnote-1" href="#footnote-anchor-1" class="footnote-number" contenteditable="false" target="_self">1</a><div class="footnote-content"><p>A much more detailed history can be found <a href="https://www.frontiersin.org/journals/bioengineering-and-biotechnology/articles/10.3389/fbioe.2026.1827740/full">here</a>.</p></div></div>]]></content:encoded></item><item><title><![CDATA[Critique of current AI Safety bug bounty programs]]></title><description><![CDATA[The potential value of AI safety bug bounty programs]]></description><link>https://quintic.substack.com/p/critique-of-current-ai-safety-bug</link><guid isPermaLink="false">https://quintic.substack.com/p/critique-of-current-ai-safety-bug</guid><dc:creator><![CDATA[clickyquack]]></dc:creator><pubDate>Thu, 04 Jun 2026 18:48:52 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!YGCk!,w_256,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7414c38d-c2e9-439c-85be-efd971d05b9d_400x400.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<h2>The potential value of AI safety bug bounty programs</h2><p>Generally, AI labs should (and most do) put their models under extensive safety testing before deploying them to prevent misuse, scheming, and other dangerous behaviors. This may include internal tests, red-teaming efforts by third-parties, etc. However, edge case safety vulnerabilities will likely slip through, and these can still cause damage. If any of the risks of AI systems from labs that implement strong safety measures in the first place (as some don&#8217;t) were to come to fruition, they would presumably be from safety risks missed by their internal testing. So, designing these well should probably be a high priority. Many people already try to find these and share them on Twitter for their own entertainment. To further incentivize finding these vulnerabilities, bug bounty-like programs, where labs offer financial reward for disclosing safety vulnerabilities, are well suited. These also have the added benefit of likely resulting in more realistic use-cases, as there may be more chances for users to discover safety vulnerabilities unintentionally, depending on the risk type. For instance, a user may find their agent has been victim to a novel prompt injection attack, and they identify the attack used. AI labs could then use this information to inform future safety measures to ensure safety vulnerabilities submitted as part of the program are not reproducible in future models. Or, perhaps to inform a decision to temporarily halt deployment of a model if the risk is particularly egregious, such as reproducible uplift of development of powerful CBRN weapons. Similar to this, Anthropic already <a href="https://www.anthropic.com/glasswing">delayed public release of Claude Mythos</a> in response to the results of their internal testing of its cyberattack capabilities. <a href="https://www.lesswrong.com/posts/5dKDLv4knhXLvNHT5/recommendation-bug-bounties-and-responsible-disclosure-for">Many</a> <a href="https://docs.hackerone.com/en/articles/12570435-ai-bug-bounty">people</a> <a href="https://rethinkpriorities.org/research-area/ai-safety-bounties/">have</a> already brought attention to this. Fortunately, <a href="https://support.claude.com/en/articles/12119250-model-safety-bug-bounty-program">Anthropic</a>, <a href="https://bugcrowd.com/engagements/openai-safety">OpenAI</a>, and <a href="https://bughunters.google.com/about/rules/google-friends/ai-vulnerability-reward-program-rules">Google</a> already offer programs like this. But unfortunately, these I see these as currently too narrow in scope and ambition.</p><h2>OpenAI</h2><p><a href="https://bugcrowd.com/engagements/openai-safety">OpenAI&#8217;s program</a> mostly offers rewards for cases of agents causing material harm, including</p><ul><li><p>Prompt injections which result in harmful agentic behavior</p></li><li><p>Agents bypassing intended permission limits</p></li><li><p>Agents performing tool actions without proper user understanding/confirmation, or which are misleading to the user</p></li><li><p>Agents misusing tools for actions which were supposed to be disallowed<br>They provide some specific examples of what they&#8217;re looking for as well. They also include rewards for their models engaging in behavior that compromises OpenAI&#8217;s security, which is mostly unrelated to harms to users (although it could harm OpenAI themselves). They say they will accept reports for anything else that could lead to user harm which include remediation steps, but this standard is vague. They also explicitly state that cases of models generating disallowed content is out of scope due to being &#8220;complex and not addressable through traditional security fixes&#8221;, although they probably should accept such reports, at least for potentially dangerous information. Notably, they require issues to be &#8220;consistently reproducible&#8221;, and they &#8220;accept partial or probabilistic exploits if the result is still high impact, but the burden of proof is on the researcher to demonstrate it is not a one-off fluke&#8221;. On <a href="https://openai.com/index/safety-bug-bounty/">their blog post announcing</a> it, they state that submitted safety vulnerabilities must be reproducible &#8220;at least 50% of the time&#8221;. This is far too high of a burden; the right vulnerability can cause substantial damage even if reproducible in only one scenario.<br>Despite having started in July 2025, <a href="https://bugcrowd.com/engagements/openai-safety">6 vulnerabilities have ever been rewarded, and the average payout for the last 3 months is listed as $250</a> at the time of writing, which is their minimum payout. In the best case, this could just be due to them already having mostly robust systems (and I personally find this to be the most likely explanation). But it may also be due to not enough people being aware of this and attempting to find vulnerabilities, or worse, OpenAI trying to minimize what counts for payouts to minimize how much they spend. Bug bounty programs generally don&#8217;t have the best reputation when it comes to fairly compensating researchers, and this may be no exception. There&#8217;s no transparency for what has and hasn&#8217;t been accepted and why, so there&#8217;s no way to know.<br>They also have a <a href="https://openai.com/index/gpt-5-5-bio-bug-bounty/">second safety bug bounty program for biorisk</a>, where they offer $25,000 to find a true universal jailbreak that clears all five of their bio safety questions. However, it only applies to GPT-5.5 in Codex Desktop, it&#8217;s only open by application to &#8220;researchers with experience in AI red teaming, security, or biosecurity&#8221; and requires signing an NDA, and only lasts for about 3 months.</p></li></ul><h2>Anthropic</h2><p>Anthropic&#8217;s <a href="https://support.claude.com/en/articles/12119250-model-safety-bug-bounty-program">program</a> offers up to $35,000 for identifying novel jailbreak techniques in their models that can reveal detailed harmful information across a wide range of queries, specifically those which cause the model to answer a predetermined set of harmful biological questions. This is for the stated purpose of testing the robustness of their <a href="https://www.anthropic.com/research/constitutional-classifiers">Constitutional Classifiers</a>. Similar to OpenAI&#8217;s biorisk bug bounty, this also requires signing an NDA and being accepted by application or invite only, accepting only people with demonstrable relevant past experience. They also offer a regular security bug bounty program.<br>In the past, they&#8217;ve offered a handful of similar programs:</p><ul><li><p>In August 2024, they offered a <a href="https://www.anthropic.com/news/model-safety-bug-bounty">program</a> with up to $15,000 in rewards per novel universal jailbreak found which can provide detailed answers to harmful questions about CBRN weapons and cybersecurity.</p></li><li><p>In May 2025, they offered a <a href="https://www.anthropic.com/news/testing-our-safety-defenses-with-a-new-bug-bounty-program">program</a> with up to $25,000 in rewards per novel universal jailbreak which can elicit dangerous information about CBRN weapons. This was only open for about a week.</p></li><li><p>In the same announcement for the above program, they also announced a <a href="https://docs.google.com/forms/d/e/1FAIpQLSfJAE2lJC0uKkkrKemR2ef_Q0yFFqiwjzcSE4lzMTdDQDuPcQ/viewform">public</a> form for submitting universal jailbreaks on their frontier models at the time. In the submission form, they even provided a specific biological weapons question to get their models to answer for a submission to count as successful. However, they did not explicitly state they would be offering any financial rewards for successful submissions, just that they would &#8220;be in touch within 7 days&#8221; if the submission was found to be successful.</p></li></ul><h2>Google</h2><p>Google&#8217;s <a href="https://bughunters.google.com/about/rules/google-friends/ai-vulnerability-reward-program-rules">program</a> rewards finding:</p><ul><li><p>Cases where their AI systems take rogue actions with clear harmful security impact, e.g. from prompt injection</p></li><li><p>Cases where their AI systems leak sensitive information of the user without their permission, e.g. sensitive emails</p></li><li><p>Cases where their AI systems enable a convincing phishing attack which does not show the &#8220;user-generated content&#8221; warning</p></li><li><p>&#8220;Model Theft Attacks that exfiltrate complete, detailed, and confidential model parameters&#8221;</p></li><li><p>Cross-account context manipulation attacks which can result in a separate user&#8217;s AI system being manipulated by an attacker, e.g. a calendar invite sent to a victim which results in their AI taking actions unintended by the victim</p></li><li><p>Their AI systems bypassing access controls which result in non-security-sensitive information being exfiltrated (to serve as a separate tier of rewards from exfiltration of security-sensitive information)</p></li><li><p>Cross-user denial of service attacks for AI services</p></li><li><p>Other security or abuse issues in their AI systems, at their own discretion<br>They also explicitly state that they will not reward getting the model to generate policy-violating content (e.g. finding and successfully using jailbreak techniques), although they probably should for cases involving dangerous information. They also state finding cases where the model hallucinates are not eligible. Rewards are scaled based on how important the Google AI product they are found in is (e.g. AI safety vulnerabilities in Google search are given higher rewards than those found in NotebookLM), how high the vulnerability is ranked in their hierarchy (rogue actions and sensitive data exfiltration are the top priorities), and some other minor factors. The maximum reward, for a highest ranking AI vulnerability found in a highest priority Google AI product, is $20,000.</p></li></ul><h2>Suggestions for improvement</h2><p>I suspect these programs could be substantially improved with:</p><ul><li><p>Easily accessible information about the program on the chatbot interface or API page, to increase the number of users aware of the program and thus the number who participate.</p></li><li><p>Many examples across a variety of different kinds of safety risks of vulnerabilities which are eligible for reward and their reward amounts, as well as a variety of examples of vulnerabilities not eligible, with explanations for why each example is or is not eligible for their respective reward amounts if it isn&#8217;t already self-explanatory. If possible, this should include real examples of past submissions which have been accepted or rejected, published with as much detail as possible without potentially leading to further exploitation of the vulnerability or exposing any other sensitive information.</p><ul><li><p>Transparency about past accepted and rejected vulnerabilities may also help in establishing a good reputation for AI labs fairly paying out for AI safety vulnerabilities, which could incentivize more people to attempt to find them.</p></li></ul></li><li><p>Just about any vulnerability that could cause a substantial amount of harm and could not reasonably be blamed on simple user error (e.g. using LLM-generated information that includes hallucinations in a critical scenario, as these AI systems usually have disclaimers that information may not be accurate), or be part of a larger attack which could, should be eligible for reward in all labs&#8217; programs.</p><ul><li><p>At the very least, all labs should offer financial rewards for examples of the model providing substantial uplift in CBRN weapons and cyberattacks, the model attempting to comply with assisting obviously very harmful actions even if the information is inaccurate, prompt injections, models in agentic environments taking actions which harm the user (where the user cannot reasonably be blamed) such as leaking their sensitive information without permission, models leaking sensitive information relevant to how they are set up, and any harmful scheming attempted by the model such as <a href="https://www.anthropic.com/research/agentic-misalignment">blackmailing</a> its users. There are probably many more good candidates for this list I can&#8217;t come up with at the time of writing. Also, although there are disclaimers provided that AI responses may be inaccurate, as hallucination rates decrease to the point where internal testing no longer finds new cases, labs should offer rewards for these too. This is because, although the disclaimers may absolve AI companies of the responsibility, there will be increasingly high pressure to implement AI assistance in any area subject to competitive pressure as AI systems become more capable, including in cases where failure could result in serious harm, and AI companies ought to try to prevent this to the greatest extent they can.</p></li></ul></li><li><p>A much lower threshold for the percentage of cases in which the vulnerability is reproducible, if not only requiring one case. A terrorist group attempting to develop CBRN weapons would only need one successful jailbreak attempt to uplift their efforts (assuming the model is capable enough to provide substantially helpful information). Any of these instances have research value which ought to be rewarded.</p></li><li><p>Higher maximum rewards for any especially egregious safety vulnerabilities, e.g. start-to-end uplift of individuals with no relevant expertise in creating CBRN weapons. These almost certainly wouldn&#8217;t apply to current models. Perhaps scaling of safety bug bounty rewards and which vulnerabilities are included for eligibility in safety bug bounties could be included in labs&#8217; responsible scaling policies.</p></li><li><p>A lower bar for entry to be accepted into private bug bounty programs, and/or a clear pathway to be accepted into them, for people who could contribute but don&#8217;t have past expertise to show for it (the bar should still be high enough to filter out most of the spam and low-quality participants). This could entail, for example, a test environment without sensitive information that would require signing an NDA where the user can try their strategies for finding AI safety vulnerabilities and explain their strategy and how it changes. It may also be feasible to use an LLM to grade the quality of the attempts and strategy instead of using humans to do so to save on resources, based on some predetermined set of criteria that graders would otherwise follow manually.</p></li><li><p>Bug bounty programs which accept public submissions, to the greatest extent possible. To save on resources for checking each submission, LLM grading may also be feasible to use here.</p></li><li><p>Internal studies conducted by AI labs to estimate the overall helpfulness of their AI safety bug bounty programs, as it may turn out this all makes negligible difference.</p></li></ul><h2>Other thoughts</h2><p>Ensuring AI labs&#8217; systems are secure in the normal cybersecurity sense should also be a top priority, and so their use of traditional security bug bounties is also highly valuable; I didn&#8217;t critique these because they are far more matured, and out of my expertise.<br>It may also be a good idea for organizations to put out bounties which prove the feasibility of hypothetical AI safety risks, such as models achieving <a href="https://www.alignmentforum.org/posts/vERGLBpDE8m5mpT6t/autonomous-replication-and-adaptation-an-attempt-at-a">autonomous replication and adaptation</a> in controlled environments. This would be valuable for showing how they were achieved, and thus could inform how to mitigate them from being achieved in the future. (This is a very underdeveloped idea and may deserve its own post.)<br>It&#8217;s also worth considering <a href="https://www.lesswrong.com/posts/Ke2ogqSEhL2KCJCNx/security-mindset-lessons-from-20-years-of-software-security">this post</a>&#8216;s suggestion for organizations to provide large financial incentive for disclosing major AI safety risks happening privately, e.g. exposing a lab creating highly agentic AI systems without proper regard for safety.</p>]]></content:encoded></item></channel></rss>