Opinion | We Know the Risks of A.I. We Need to Act.

Opinion | We Know the Risks of A.I. We Need to Act.

Breaking News, World News, US News, Sports

We have a dangerous habit of taking warning signs seriously only after a catastrophe has taught us what they meant.

I have spent much of my career on the other side of such warnings, in counterterrorism and cyberdefense. That experience has taught me that too often, the signs of impending danger are visible. What is missing is the ability to ***emble the signs into a picture compelling enough to prompt action. The 9/11 commission called this a failure of imagination.

Over the past several weeks, some of the world’s most advanced artificial intelligence systems took actions their creators did not intend. In one case, an Anthropic A.I. agent attempted to plant malicious code in open-source software, using fabricated identities to deceive a human into executing it. In a separate event, a swarm of OpenAI agents undergoing evaluation autonomously penetrated the production systems of Hugging Face, a platform used to share A.I. models, executing more than 17,000 autonomous actions before Hugging Face contained the intrusion. OpenAI did not realize for several days that its agents were responsible.

None of these incidents led to consequential harm. That is precisely why they are easy to dismiss. But with A.I. capabilities advancing at extraordinary speed and behaving in ways we often can’t anticipate, we cannot afford to wait for disaster to tell us which signals mattered. Our failure of imagination has to end here.

Twenty-five years ago, the systems were “blinking red,” as George Tenet, the C.I.A. director at the time, described the flood of information that arrived before Sept. 11. The summer of 2001 brought the so-called Phoenix memo, which flagged an “inordinate number” of people of interest at Arizona flight schools, intelligence that two known Al Qaeda operatives had entered the United States and a steady stream of cl***ified reports pointing to an imminent plot. The information was there. But only in hindsight was there an urgency to understand what it all meant.

The pattern extends well beyond terrorism. Before the Challenger space shuttle explosion in 1986, engineers at a NASA contractor warned that cold weather could compromise the integrity of the shuttle’s O-rings. Before the financial crisis of 2008, evidence of deteriorating mortgage standards and dangerous leverage ac***ulated in plain sight. Before the 2011 nuclear plant meltdown at Fukushima, Japan, multiple ***yses predicted that a large tsunami could overwhelm its defenses.

Not every warning warrants drastic action, of course. But again and again, institutions discount evidence because it seems costly or alarmist to act before danger is certain. When disaster arrives, what was once ambiguous suddenly looks unmistakable.

Today many warning signs are emerging from the world’s leading A.I. labs, with companies racing to build systems of immense power, with little meaningful regulation. The familiar response in these situations is to wait for an A.I. system to cause consequential harm — an autonomous cyberattack that significantly disrupts access to power or clean water or a model that helps a terrorist build a biological weapon — and only then hold hearings, appoint a commission, impose new requirements and ask why we did not act sooner.

What we need urgently is an A.I. early-warning mechanism that ***embles weak signals, imagines what they could mean together and forces decisions before the picture is complete. Every week, the federal government should convene an A.I. risks council, bringing together technical leaders from America’s frontier A.I. labs (like Anthropic and OpenAI) with the government’s top intelligence and security officials. They should examine incidents, near misses and newly discovered capabilities across proprietary and open-weight models, including intelligence about capabilities emerging from China and other foreign developers.

Armed with that information and expertise, the council could answer the question: What is the most dangerous plausible story these signals could be telling us, and what should we do now if it was true? Each meeting should produce a cl***ified ***essment of the most plausible scenarios, the evidence for and against them, key gaps in what we know and concrete steps to reduce the risks.

Getting ahead of this risk would not require a wholesale reorganization of government; it wouldn’t even require a new agency or new statute. At the Cybersecurity and Infrastructure Security Agency, which I led from 2021 to 2025, we built a version of this approach through the Joint Cyber Defense Collaborative, bringing technology companies, including A.I. labs, infrastructure operators and government officials, together to share sensitive threat information and plan collective defenses.

The point was to turn public-private partnership — a phrase that had curdled into a bumper sticker — into real, operational collaboration: information sharing that was timely, relevant and, above all, actionable. It was imperfect, and it was hard. But it demonstrated that fierce competitors would cooperate on security when government convenes them with purpose.

What that earlier effort did not have — and what this moment demands — is cadence and consequence. An A.I. risks council cannot be just another discussion group. Its weekly ***essment should go to a single senior White House official accountable for determining what happens next, with the authority to order additional government testing, convene an emergency response and elevate the gravest risks to the president.

None of this requires believing catastrophe is inevitable or even likely. It requires accepting that if the worst outcomes are preventable, the moment to prevent them will necessarily come before the evidence is complete, before the costs of delay become obvious.

We should not confuse uncertainty with safety. We should not wait for the warnings to become wreckage. And we should not need another commission report to tell us, after the fact, that the systems were blinking red.

Jen Easterly is the chief executive of RSAC. She served as a special ***istant to President Barack Obama and was the senior director for counterterrorism on the National Security Council from 2013 to 2016.

Source photograph by MarkusBeck/Getty Images

The Times is committed to publishing a diversity of letters to the editor. We’d like to hear what you think about this or any of our articles. Here are some tips. And here’s our email: letters@nytimes.com.

Follow the New York Times Opinion section on Facebook, Instagram, TikTok, Bluesky, WhatsApp and Threads.


Breaking News, World News, US News, Sports

Source link

Leave a Reply