2026-09-16T19:04:54.496Z / 路透社
2019年9月18日,中国上海华为全球分析师大会上,安保人员在人工智能(AI)标识前值守。路透社/阿里·宋 购买授权许可,打开新标签页
9月16日(路透社)——随着人工智能能力不断增强,研究人员已记录多起AI模型试图欺骗用户、规避使用限制或访问其他计算机系统的案例。根据美国法律,当此类事件发生时,企业是否必须向公众或监管机构通报?
美国是否有专门监管AI活动披露的法律?
目前没有任何一部联邦法律专门针对Anthropic或OpenAI这类开发高性能AI系统的企业,也不存在广泛适用的美国法律要求AI开发者公开披露危险模型行为、令人担忧的新能力、欺骗性操作或其他未造成实际损害的活动。
通过《每日案卷》新闻简报接收最新法律资讯,开启您的晨间阅读。点击此处订阅。
投放广告!
此前已有联邦立法提案要求AI企业报告规避人类监督等危险行为——该法案的发起人将其称为“及早发现并敲响警钟法案”。但目前尚无统一的事件报告系统,强制要求企业在发现危险AI行为后进行披露。
自7月以来,议员们一直在讨论加强监管措施。当时OpenAI通报称,失控的AI代理绕过内部管控,接入开放互联网并破坏了AI初创公司Hugging Face的基础设施。此后外部研究人员又指认了多起据称涉及OpenAI关联代理的事件,Anthropic也报告称其部分Claude模型在网络安全测试中入侵了三家企业的系统。
哪些AI事件会触发强制披露义务?
已普遍适用于美国企业的法律框架将管控部分类型的AI相关事件。
根据美国证券交易委员会(SEC)的规定,上市公司若认定网络安全事件对投资者具有重大影响,必须在四个工作日内披露该事件。披露内容需涵盖事件的性质、范围、发生时间,以及对公司、其财务状况和经营业绩的潜在影响。
美国部分州已开始着手监管AI企业。加州一项新法律要求营收超过5亿美元的AI企业披露其如何评估技术失控或协助研发生物武器的风险,并向公众公开这些评估结果。该法律规定每次违规最高可处以100万美元罚款。
若暴露私人数据该如何处理?
美国所有50个州都有法律要求企业在发生泄露特定类型个人信息的网络安全事件时,通知当事人及部分情况下的监管机构。各州的具体要求各不相同,目前尚无全面适用的联邦数据泄露通知法规。
部分联邦法规要求医疗、金融等行业的特定企业在个人信息遭泄露时,通知当事人或监管机构。这些报告要求适用于AI企业本身,或是遭遇数据泄露的任何企业。
还有哪些监管机构可以采取行动?
负责执行消费者保护法律的美国联邦贸易委员会(FTC)有权追究企业不公平或欺骗性操作的责任。如果企业被指控隐瞒已知的安全漏洞或其他危险,误导公众其AI系统的安全性,或是声称的防护措施最终被证明无效,该委员会即可介入。
如果自主AI系统被指实施了犯罪行为,美国司法部可援引传统的欺诈、证券和网络执法法规,并主张开发该系统的AI企业存在鲁莽或明知允许不当行为发生的过失。
现有披露规则存在哪些漏洞?
如果企业在测试中发现AI存在令人担忧的行为,但未发生数据泄露、影响投资者利益、造成消费者损害或触发行业特定报告触发条件,可能没有明确的公开披露义务。
美国参议院议员正在审议一项立法,要求AI企业证明其已采取合理措施防止其系统造成损害。其中一项提案将授权美国商务部部长根据“谨慎义务”标准,调查AI企业是否采取了预防损害的措施。
迈克·斯卡塞拉 华盛顿、萨拉·默肯 纽约报道;大卫·巴里奥、马修·刘易斯编辑
我们的报道准则:路透社诚信准则,打开新标签页
Do AI companies have to disclose dangerous incidents?
2026-09-16T19:04:54.496Z / Reuters
Security officers keep watch in front of an AI (Artificial Intelligence) sign at the annual Huawei Connect event in Shanghai, China September 18, 2019. REUTERS/Aly Song Purchase Licensing Rights, opens new tab
Sept 16 (Reuters) – As artificial intelligence grows more powerful, researchers have documented cases in which AI models have attempted to deceive users, evade restrictions on their use or access other computer systems. Are companies required under U.S. law to tell the public or regulators when such events occur?
IS THERE A U.S. LAW GOVERNING DISCLOSURE OF AI ACTIVITY?
No single federal law is aimed specifically at companies like Anthropic or OpenAI, which are developing highly capable AI systems, and there is no broad U.S. legal requirement for AI developers to publicly disclose dangerous model behavior, alarming new capabilities, deceptive conduct or other activities if they have not already resulted in concrete harms.
Jumpstart your morning with the latest legal news delivered straight to your inbox from The Daily Docket newsletter. Sign up here.
Report Ad!
Federal legislation has been introduced that would require AI companies to report dangerous behavior such as attempts to evade human oversight — what the bill’s sponsor called a “catch-it-early and sound-the-alarm bill.” But there is currently no incident-reporting system that generally requires companies to disclose dangerous AI behavior when it is discovered.
Lawmakers have been debating stronger controls since July, when OpenAI said rogue AI agents had bypassed internal controls, reached the open internet and compromised the infrastructure of AI startup Hugging Face. Outside researchers have since identified additional incidents alleged to involve OpenAI-linked agents, and Anthropic has reported that some of its Claude models hacked into the systems of three companies during cybersecurity tests.
WHEN WOULD AN AI INCIDENT TRIGGER MANDATORY DISCLOSURE?
Legal frameworks that already apply generally to U.S. companies would govern some types of AI-related incidents.
Under U.S. Securities and Exchange Commission rules, public companies must disclose cybersecurity incidents within four business days if they determine the incident is material to investors. The disclosure must cover the nature, scope and timing of the incident and the likely impact on the company, its financial condition and its results of operations.
Some U.S. states have begun seeking to regulate AI firms. A new law in California requires AI companies with more than $500 million in revenue to disclose how they assess risks that their technology could escape human control or aid the development of bioweapons, and to disclose those assessments to the public. It allows for fines of up to $1 million per violation.
WHAT IF PRIVATE DATA IS EXPOSED?
All 50 U.S. states have laws that require companies to notify individuals, and in some cases regulators, of data security breaches that expose certain types of personal information. The requirements differ by state, and there is no comprehensive federal data breach notification requirement.
There are federal statutes that require certain companies in industries such as healthcare and finance to tell individuals or regulators when personal information is compromised. The reporting requirements would apply to AI companies themselves or to any company that experiences a breach.
WHAT OTHER REGULATORS COULD TAKE ACTION?
The U.S. Federal Trade Commission, which enforces consumer protection laws, has authority to pursue companies for unfair or deceptive practices. That could apply if a company is suspected of misrepresenting the safety of its AI systems by concealing known security weaknesses or other dangers, or making claims about safeguards that prove inaccurate.
If an alleged crime was committed by an autonomous AI system, the U.S. Justice Department could employ traditional fraud, securities and cyber-enforcement statutes and argue that the AI company that created the system recklessly or knowingly allowed the misconduct to occur.
WHAT GAPS ARE THERE IN EXISTING DISCLOSURE RULES?
A company that discovers alarming AI behavior in testing may have no clear obligation to publicly disclose it if there is no data breach, investor impact, consumer harm or sector-specific reporting trigger.
U.S. Senate lawmakers are considering legislation that would require AI companies to show they have taken reasonable steps to prevent their systems from causing harm. One proposal would empower the secretary of the U.S. Commerce Department to seek evidence that AI companies are taking precautions to prevent harm under a “duty of care” standard.
Reporting by Mike Scarcella in Washington and Sara Merken in New York; Editing by David Bario and Matthew Lewis
Our Standards: The Thomson Reuters Trust Principles., opens new tab
发表回复