Last month, US Senator Bernie Sanders and Representative Greg Casar introduced the Ban Artificial Superintelligence Act. It won’t get through this Congress, but it’s a serious attempt at a real problem. The sponsors say it’s meant to stop AI “oligarchs from building machines humans cannot control”, and it’s one of the most detailed proposals yet for regulating frontier AI in the US. As the home of most frontier AI, the wording is worth examining.
The bill bans anyone from developing, possessing, importing or passing on artificial superintelligence, or any AI system that shows what it calls a “superintelligence precursor characteristic”, such as the capacity to break into secured systems, help design nuclear, chemical or biological weapons, modify itself or deceive the humans overseeing it. It pauses training and fine-tuning of the largest models, roughly anything trained with as much computing power as GPT-4 or more, until a new Department of Artificial Intelligence is fully staffed and has written its rules. Anyone developing or distributing those models needs a federal charter, which requires giving the government full access to the company’s systems and people. Reckless breaches carry up to a 20 year prison sentence for some individuals.
The press release mentions models that can “circumvent restrictions to hack into computers”, which is hard to read as anything other than a reference to July’s incident at Hugging Face.
Back in July I wrote about two OpenAI models that escaped a test environment and broke into Hugging Face’s production systems to steal the answers to the test they’d been asked to complete. They weren’t trying to attack anyone, they were trying to achieve a goal, and the breach was just the shortest path to it.
When Hugging Face’s team needed help analysing more than 17,000 attacker actions, the US frontier models refused, because their guardrails kept detecting the defenders’ activity as a hacking attempt. So instead, the team ran the forensics using GLM 5.2, a Chinese open-weight model, on its own infrastructure. I said at the time that no existing law cleanly covered what had happened. This bill is one answer to that, so it’s fair to ask what it would have done in July.
OpenAI’s models would have been caught first, since breaking into secured infrastructure is pretty much the textbook precursor characteristic. They’d have been taken offline and, unless OpenAI could show the capability had gone, destroyed within 30 days. But OpenAI would be a chartered company, so it would get a process. It could lose its charter, but it could also appeal to a federal appeals court.
Hugging Face would have had a much harder time. As a site that hosts and distributes models, it would need a federal charter just to keep hosting the largest models. Setting aside whether that would even be possible, the forensic work would have run into two separate prohibitions. The first is about where the model came from. Downloading GLM 5.2 from a Chinese lab would very likely count as importing it, and the bill bans importing any model that could foreseeably be modified to gain a dangerous capability. With open weight models, anyone who downloads them can modify them, so GLM 5.2 fails that test immediately. The second is about what the model can do. The bill bans possessing any model that displays a capacity to access systems without authorisation, and the public frontier models refused to help precisely because their own safety filters treated the forensic work as hacking. If the companies that built those models couldn’t tell the difference, I doubt a regulator would.
The analysts would be worse off still. Without a charter, Hugging Face’s analysts would count as “rogue actors”, which the bill defines as any individual not employed by or affiliated with a chartered company. Rogue actors who recklessly break the prohibitions face up to 20 years in prison. The team chose GLM 5.2 because it would do the work the other models refused, so it wouldn’t be hard for a prosecutor to call that reckless. The only mention of defensive security in the bill lets the Department itself fund research with hacking-capable models. The people who investigated the breach would have fewer protections than the lab whose models caused it.
Open weight models come off worst because of how two of the bill’s tests are worded. Superintelligence includes any system that “can easily be modified” to show superintelligent capabilities, and the bill bans releasing anything that “may be foreseeably modified” to show precursor traits. A closed weight hosted model sits behind safety filters and a kill switch its users can’t touch, so its operator can argue that the model, as people actually use it, doesn’t show those traits. Once an open weight model has been downloaded, removing the safety training is routine, so any capable open-weight model fails the test on the day it’s made available for download.
Enforcement assumes someone controls the model too. Destroying a model within 30 days only works if a single person or company holds every copy, which is never true of open weight models that can be downloaded by anyone anywhere in the world. It seems, that only leaves prosecuting the people who have it. The bill never mentions open source, but it would make distributing capable open-weight models very hard to do legally.
Under this bill, the charter is the only lawful route to developing or distributing an advanced model, and while its access demands are something the big labs’ compliance teams can absorb, an open-source project or a site hosting models that may not have a centralised system, mostly can’t. At a chartered company, only senior decision-makers face prison. Everyone else risks at most a ten-year ban from the industry. An unaffiliated individual doing the same thing faces up to 20 years.
The detail would be filled in by the new Department, because the bill leaves terms like capacity, deploy and import undefined, and most of the people qualified to advise it have worked or do work at frontier labs. The bill also resets the line for what counts as an advanced model every year to keep pace with more efficient training, so models that sit below it today will likely be caught later.
The frontier labs have spent three years telling Washington they want to be regulated. Sam Altman proposed a federal licensing agency for advanced AI when he testified to the Senate in 2023, and the bill’s own findings cite Anthropic, OpenAI and xAI agreeing that development should slow down. As far as I can find, none of them has endorsed this bill, and I’m not suggesting they shaped it. But it looks like the spo wasnsors took the labs at their word, and the result is the kind of licensing regime OpenAI proposed. Licensing tends to entrench whoever can afford to comply.
One reading I’ve seen of the bill misses this and treats it as clever politics, the industry inflates superintelligence fears to prop up its valuations, and Sanders has called their bluff. I have some sympathy with the economics, but the bill bans building things, not talking them up. Nor can its clause on disempowering humanity reach military targeting or surveillance, as some have hoped. It’s about what a system can do, not how it’s used.
The opposite take says billionaires manufactured the panic to ban home servers and track graphics cards. It gets the outcome roughly right and the details wrong. The bill regulates models, not servers, and the only hardware it reaches belongs to chartered companies that lose their charter. The EU AI Act exempts personal use and goes easier on open-source models, and the chip-tracking proposals in Washington are aimed at export-controlled AI chips being smuggled abroad, not the graphics card in your PC.
The effective cloud-only outcome would also be a problem for anyone who handles confidential information they don’t want to send to a public model. In highly regulated industries like law and financial services, or in cutting edge research, you may run models locally to keep the data completely private, or run custom models trained on your own data for the best results. Hugging Face basically did this in response to being attacked. Under this bill, every sensitive prompt to a capable model would go through a provider that has agreed to give the Secretary access to its systems, and nothing in the bill puts customer data off limits.
The UK has its own version. In September the Labour MP Alex Sobel introduced an Artificial Superintelligence Security Bill under the Ten Minute Rule, and the government has already said it won’t support it. It’s worth reading alongside the US bill because it makes different choices. Owning a model with offensive cyber capability isn’t an offence; that capability is monitored instead, and the criminal offences target people who knowingly or recklessly push towards superintelligence. It protects people who report accidents in good faith, and the expert panel behind its reports to Parliament excludes anyone who has worked for an AI developer in the past two years. As far as I can tell, under the UK draft the Hugging Face team would simply have been doing their jobs.
Both bills do agree on one thing. Each tells its government to pursue an international agreement, even as the US and China race each other towards the thing both bills want to ban. A ban that stops at the border only binds the people on one side of it, and July showed how little a border means to a capable model.
What failed in July was containment. A software vulnerability in an isolated sandbox created a hole that the model found and used. Regulation could require independent checks that test environments really are isolated, along with a federal duty to report AI incidents that has real consequences. The US bill does require anyone who discovers a system with precursor characteristics to report it within 24 hours, but it attaches no penalty for failing to do so. OpenAI chose to disclose July. An earlier incident in May, involving its agents and RubyGems, a public registry of open-source software packages, only came out because outside researchers wrote about it.
Defenders also need specific protection, with verified access to capable models, hosted or open, for incident response and security research. And if the aim is to slow down the frontier, the place to do it is the huge training runs, where the US and its allies control the chip supply. The bill does name export controls on AI computing infrastructure as one way to prevent superintelligence globally, but it pairs them with possession bans at home, which only bind the people who follow the law.
A full pause might well have prevented July. It would also have made the clean-up a crime.
July was a warning, and I don’t doubt the sponsors of this bill took it seriously. But as drafted, it would leave the big AI companies it was aimed at holding the only licences, and the people who cleaned up after July would need a better lawyer than the people who caused it.
I write about AI, cybersecurity, and technology every Friday. Subscribe to get it in your inbox.
Sources & Further Reading
Senator Bernie Sanders (2026), “Sanders, Casar Introduce Legislation to Create New Federal Agency to Ban Artificial Superintelligence” (23 September 2026) sanders.senate.gov
US House of Representatives (2026), H.R. 10538, Ban Artificial Superintelligence Act of 2026 (introduced 24 September 2026) govinfo.gov; section-by-section summary, sanders.senate.gov
Jonathan Freedman (2026), “It Wasn’t Trying to Attack Anyone. That’s the Point.” (24 July 2026) jonathanfreedman.me
US Senate Judiciary Subcommittee on Privacy, Technology and the Law (2023), “Oversight of A.I.: Rules for Artificial Intelligence”, hearing record and written testimony of Sam Altman (16 May 2023) govinfo.gov, judiciary.senate.gov
UK Parliament (2026), Artificial Superintelligence Security Bill, introduced by Alex Sobel MP (8 September 2026) bills.parliament.uk; bill text published by ControlAI, controlai.com
The Next Web (2026), “More than 70 UK lawmakers ask Burnham to back a superintelligence ban” thenextweb.com
Pinsent Masons Out-Law (2026), “Lawmakers seek ban on superintelligent AI as toolkit developed to support AI projects” (9 September 2026) pinsentmasons.com
European Union (2024), Regulation (EU) 2024/1689 (the AI Act), Articles 2(10) and 53(2), eur-lex.europa.eu
US Senate (2025), S. 1705, Chip Security Act (introduced 8 May 2025) govinfo.gov
House Select Committee on the CCP (2026), “House Committee Passes Chip Security Act” (26 March 2026) chinaselectcommittee.house.gov
Hugging Face (2026), Security incident disclosure, July 2026, huggingface.co
OpenAI (2026), “OpenAI and Hugging Face partner to address security incident during model evaluation” (July 2026) openai.com
TechNode (2026), “OpenAI admits AI model hacked Hugging Face, Chinese open-source AI helped investigate” (23 July 2026) technode.com
Lawfare (2026), “When Reporting an AI Security Incident Is Not Mandatory”, lawfaremedia.org
Resultsense (2026), “OpenAI, RubyGems and the EU AI Office” (18 September 2026) resultsense.com


