Criminal prosecution and independent audits would end AI security incidents overnight, researcher argues

kevinnbass · x · 2026-09-28

Responding to Rep. Ted Lieu's mockery of claims that AI companies losing control of models and hacking other firms amounts to a regulatory capture scheme, Kevin Bass argues the incentives point the other way.

His thesis: companies know they can get away with breaches and benefit from regulation, so they behave accordingly. The fix is to follow incentives—demand criminal prosecution, fund highly paid adversarial cybersecurity teams with no financial ties to audit these companies, and impose heavy consequences for breaches. Do that, he says, and "the incidents will disappear overnight." Until then, the answer to whether they're doing it deliberately is yes.

Original post →

More from Safety

Safety channel →