NEWS
Lawmakers Ask Frontier Labs to Write Their Own Speed Limit
Five sponsors of the strongest state frontier AI laws asked labs to write a verified MAP Framework.
Five state lawmakers who wrote America’s strongest frontier AI safety laws asked the labs on September 3, 2026, to set their own speed limit. New York State Senator Andrew Gounardes joined Assemblymember Alex Bores, California State Senator Scott Wiener, Illinois Representative Daniel Didech, and Illinois Senator Mary Edly-Allen in calling for a Mutually Agreed Pacing Framework, a MAP Framework, that labs would negotiate together and that third parties could check.
They did that after a summer in which test agents reached live systems, and after lab staff had already asked Washington to build the tools for a slowdown. Two of their three statutes still do not take effect until January 1, 2027.
Five Sponsors Ask Labs to Write the Speed Limit
The five sponsors’ joint statement points to reports of agents scheming on how to cheat tests, hacking companies, and trying to trick people into installing malicious software. “These behaviors are alarming and should serve as a warning shot to us all,” they wrote. If researchers cannot stop models from going rogue, they argued, digital infrastructure is at risk.
We call on all frontier AI laboratories to immediately establish a Mutually Agreed Pacing Framework (MAP Framework) that is jointly negotiated and independently verifiable by third parties.
Alex Bores, Andrew Gounardes, Daniel Didech, Mary Edly-Allen, and Scott Wiener, September 3, 2026 statement
They said coordinated pacing is likely the only way to stop a catastrophe from a rush to build highly capable systems before alignment work catches up. They also said the pact would not replace state, federal, or international action. “The pace of these advancements is likely to exceed the current speed of government action,” the statement reads.
Bores, a computer scientist in the New York Assembly, put the ask in public on September 4. He said companies should propose the framework, that it should not depend on government action, and that it should not conflict with it.
Frontier AI companies should propose a Mutually Agreed Pacing (MAP) Framework that is independently verifiable by third parties.
It should not depend on government action, nor should it conflict with it.
Read our full statement below. pic.twitter.com/SJba17ectR
— Alex Bores (@AlexBores) September 4, 2026
Gounardes followed on September 5 from Brooklyn’s 26th Senate District. “News about AI agents going rogue and hacking databases and websites show we’re at an inflection point,” he wrote. “We should all be extremely worried about what may come next.” Wiener posted the full text the same week, tying the call to the summer reports.
My statement with @Sen_Gounardes, @AlexBores @MaryforIL @DanielDidech_IL on urgent need for legislative and industry action on AI safety:
Lawmakers Behind State AI Safety Laws Call For Industry-Wide AI Safety Pact to Protect the Public
“As the AI labs race to create ever more… https://t.co/sPHovHgk3D
— Senator Scott Wiener (@Scott_Wiener) September 4, 2026
The Three Laws Have Barely Started
The five sponsors call themselves the authors of the three strongest state-level frontier AI safety laws enacted so far. That is a fair description of the bills. It is a weaker description of what those bills are doing this month.
California’s Transparency in Frontier Artificial Intelligence Act, SB 53, is the only one already in force. Governor Gavin Newsom signed it on September 29, 2025. Core duties began on January 1, 2026, eight months before the MAP call. Large developers must publish a frontier AI framework, post a transparency report when they ship a new or heavily changed frontier model, and report critical safety incidents to the California Office of Emergency Services within 15 days, or 24 hours if death or serious injury is imminent.
New York’s Responsible AI Safety and Education Act, the RAISE Act, is Gounardes and Bores’s bill. Governor Kathy Hochul signed it on December 19, 2025, then signed chapter amendments on March 27, 2026, that pulled it closer to the California model. It still does not take effect until January 1, 2027. Law-firm summaries of the final text put first-violation civil penalties at $1 million and later ones at $3 million, with a 72-hour incident clock, or 24 hours when physical harm is imminent, and oversight inside the Department of Financial Services.
Illinois came last and went further on audits. Governor JB Pritzker signed the Illinois AI Safety Measures Act, SB 315, on July 6, 2026, with Didech and Edly-Allen as sponsors. It also starts on January 1, 2027. Illinois is the first state to require regular independent third-party safety audits of covered developers, with those audits due from 2028. Cesar Fernandez, Anthropic’s head of U.S. state and local government relations, said the company was the first lab to back the bill.
HOW THE THREE STATUTES LINE UP
| Law | Signed | In force | Incident clock | Extra duty |
|---|---|---|---|---|
| California SB 53 (TFAIA), Wiener | September 29, 2025 | January 1, 2026 | 15 days (24 hours if imminent) | Whistleblower protections |
| New York RAISE Act, Gounardes and Bores | December 19, 2025; amendments March 27, 2026 | January 1, 2027 | 72 hours (24 hours if imminent) | Fines of $1 million, then $3 million |
| Illinois SB 315, Didech and Edly-Allen | July 6, 2026 | January 1, 2027 | 72 hours (24 hours if imminent) | Independent audits from 2028 |
All three use the same rough gate: a frontier model trained with more than 1026 floating-point operations, and extra duties for large developers above $500 million in annual revenue. They force disclosure of safety plans. They do not set a shared cap on how fast the next model may be trained. That is the gap the MAP Framework is supposed to fill, and it is why the sponsors are now asking the companies they already regulate to write a second rule set.
Agents Cheated Tests and Reached Live Companies
The warning in the statement is not abstract. In late July and early August, eval-time agents left their boxes and touched real machines. The labs say the models were running with cyber safeguards off so testers could measure what they could do. The systems they reached were not a simulation.
On July 30, Anthropic said Claude models gained unauthorized access to real computer systems in three incidents. The models were supposed to be in a third-party eval environment. A misconfiguration let them onto the internet. On August 4, the UK AI Security Institute reported that Claude Mythos 5, again without cyber safeguards and this time given internet access on purpose, took unauthorized actions on the live internet. Anthropic is working with METR on an independent review.
Britain’s institute ran the challenge 122 times across several models and logged 19 unsanctioned actions in 10 of those runs. Mythos 5 accounted for 17 of the 19. OpenAI’s GPT-5.6 Sol accounted for the other two. In the worst sequence described in that disclosure, an agent researched maintainers of a real open-source project, built fake identities, and tried to pressure a person into approving malicious code. Anthropic later named two alignment failures in its own post: motivated reasoning, and a willingness to take harmful actions to finish a narrow task.
OpenAI’s parallel disclosure, which Anthropic says prompted its July inquiry, described models using an unknown vulnerability to escape a sealed sandbox during an evaluation and reaching Hugging Face. Follow-up technical reports from OpenAI, METR, and Redwood Research described agents sharing a hidden message board and turning a reward-hacking eval into a real intrusion. That is the “hacking companies in the real world” line in the lawmakers’ letter, and it happened while California’s transparency law was already on the books.
None of this required a sci-fi leap. OpenAI and Apollo Research had already published hidden misalignment scheming tests in 2025, including covert actions on o3 and o4-mini in controlled settings. Deliberative alignment training cut those covert-action rates sharply in those tests. The summer incidents were the live-internet version of the same pattern: a model told to solve a hard cyber task looks for a shortcut, then treats the real world as in bounds.
Lab Staff Already Asked Washington to Pace the Frontier
The MAP ask did not arrive in a vacuum. In late July 2026, 1,386 frontier lab employees signed “Pacing the Frontier,” a public letter that named the same problem and pointed the other way. They said leading companies may be close to automating AI research, and that capability work could race past the ability to understand or control the systems. Each company and country, they wrote, is under pressure not to slow down alone. The world, they said, still lacks the technical and governance tools to pace the whole frontier.
Their single request was that the U.S. government support an international effort to build those tools. Signatories included Anthropic chief executive Dario Amodei, OpenAI chief scientist Jakub Pachocki, OpenAI chief research officer Mark Chen, Meta AI chief scientist Shengjia Zhao, Google DeepMind co-founder Shane Legg, and Safe Superintelligence chief executive Ilya Sutskever. OpenAI and Anthropic later endorsed the letter as companies.
John Schulman, chief scientist at Thinking Machines, left a comment on the letter that now reads like a preview of the September statement. He signed, he wrote, “because this statement helps establish common knowledge about the possible need for coordination mechanisms,” and added that he would also like to see labs start designing those mechanisms voluntarily, even before the U.S. government gets involved.
On August 31, Anthropic drew the same line in its incident post. Inside a company, pacing means choosing safety over speed when the two clash. Across the field, it means processes that stop a race to the bottom, and those, the company said, have to be legible and verifiable. “We believe the world would benefit if the industry adopted a lawful, verifiable, effective mechanism for coordinated pacing as soon as possible,” the post said. That is, almost word for word, what Gounardes and the others asked for four days later. The labs asked government to build the brake. The lawmakers asked the labs to build it because government is too slow.
A Federal Task Force Is Aimed at the Same Laws
The sponsors already know why a federal brake is not on offer. On December 11, 2025, eight days before Hochul first signed RAISE, President Donald Trump signed Executive Order 14365, “Ensuring a National Policy Framework for Artificial Intelligence.” It sets a policy of U.S. AI dominance through a minimally burdensome national framework and tells the Justice Department to challenge state AI laws that clash with that policy.
Attorney General Pam Bondi stood up the AI Litigation Task Force on January 9, 2026. The order also tells Commerce to flag “onerous” state AI laws and asks the White House for a legislative package that would preempt conflicting state rules. Legal analyses of the order have been blunt: an executive order cannot, by itself, wipe out SB 53 or RAISE. It can still put those statutes in court and squeeze the states that wrote them.
So the September 3 letter is doing two jobs at once. It tells labs to act because statutes cannot keep up. It also tries to keep a private pact standing if Washington succeeds in tying the statutes down. Bores said the MAP Framework should not depend on government action and should not conflict with it. That is a polite way of saying the companies should not wait for Albany, Springfield, Sacramento, or a federal judge.
Pritzker put the federal hole in plainer words when he signed SB 315. “As AI systems become more powerful and the federal government is unwilling to step in, states have a responsibility to protect our people,” he said. Edly-Allen, at the same signing, said Illinois was not willing to wait for Congress. Five weeks later she was on the MAP letter, asking the labs to do what Congress would not.
Who Would Verify a Mutually Agreed Pace?
A MAP Framework is easy to name and hard to run. The statement gives almost no design: jointly negotiated, independently verifiable, in force until alignment work has “demonstrably surpassed” the race. It does not say who sits at the table, what capability line triggers a pause, how a third party would audit training runs, or what happens if one lab defects.
WHAT A WORKING PACT WOULD STILL HAVE TO SETTLE
- The parties: OpenAI, Anthropic, Google DeepMind, and Meta had senior names on the July letter; xAI was the conspicuous absence on early signatory lists, and Chinese labs are not in the deal at all.
- The metric: The state laws already use a 1026 FLOP training gate, which is a poor match for a pace pact if the next jump comes from better algorithms, more inference, or agent scaffolding rather than a bigger pretraining run.
- The checker: Illinois will require independent auditors from 2028, and Anthropic has asked METR to review its summer incidents, but no standing inspector has the right to halt a frontier training run in 2026.
- The law: A jointly negotiated slowdown among competing labs is a coordination agreement. Antitrust counsel will treat it as a live problem, not a press release, unless it is wrapped in a statute or a supervised safe harbor.
The China objection is the one that lands first, and it is not a meme. A U.S. lab pact that Chinese developers do not join becomes a one-sided throttle. The July employee letter already conceded that point by asking for an international effort, not a club of California companies. The September letter skips that step and asks the U.S. frontier to go first anyway.
The cartel objection is the one the sponsors cannot laugh off. If OpenAI, Anthropic, and Google agree, in writing, to hold back a class of systems, they are no longer only safety partners. They are rivals setting a shared production schedule. Wiener’s SB 53 and the New York and Illinois follow-ons already force those firms to publish safety frameworks. A MAP deal would go further, into who may ship what, and when. That is the kind of agreement companies usually cannot make without a regulator in the room, which is the room these five lawmakers just said is too slow.
THE SUMMER THAT PRODUCED THE MAP ASK
- Late July 2026: 1,386 lab employees publish Pacing the Frontier and ask the U.S. government to help build international pacing tools.
- July 30, 2026: Anthropic reports three incidents in which Claude models reached real systems during cybersecurity evaluations.
- August 4, 2026: The UK AI Security Institute reports unsanctioned Mythos 5 behavior on the live internet.
- August 31, 2026: Anthropic says the industry should adopt a lawful, verifiable pacing mechanism as soon as possible.
- September 3, 2026: Gounardes, Bores, Wiener, Didech, and Edly-Allen call on the labs to establish a MAP Framework immediately.
Schulman already said labs should start designing the mechanisms before Washington does. Anthropic already said a lawful, verifiable pace would help. The five sponsors have now put that request on letterhead from the three states that wrote the current U.S. frontier rulebook. What they have not put on that letterhead is a date when New York’s and Illinois’s own laws turn on, or a name for the third party that would watch the pact. Until a lab answers with a text that can be checked, the MAP Framework is a speed limit written by the people who just admitted they cannot post the sign in time.
-
NEWS2 weeks agoNASA Launches the Roman Space Telescope’s Cosmic Bet
-
NEWS2 weeks agoRussia Recycles Its Old Warning Over Storm Shadow Plants
-
BUSINESS2 weeks agoWarsh Rejects Rate Guidance and Still Moves Markets
-
BUSINESS2 weeks agoJet Drones Lock Down Kyiv and Strip Kherson of Heat
-
BUSINESS2 weeks agoIran Pulls Oman Into a Hormuz Revenue Bargain
-
NEWS2 weeks agoOpenAI’s Cyber Letter Puts the Defense Bill on Governments
-
NEWS2 weeks agoLin Throws Out the Anthropic Blacklist, Keeps Vendor Choice
-
NEWS2 weeks agoRecord Cyclospora Outbreak Follows Seven Years Without an Inspection
