Hedging AI Risks with Common Sense

The risk of artificial intelligence illustrated with a robot hand in a field of data
(style-photography/iStock/Getty Images)

America can protect itself without sacrificing innovation or surrendering the technological race to China.

Sign in here to read more.

America can protect itself without sacrificing innovation or surrendering the technological race to China.

R ecent incidents involving rogue AI agents have turned what once seemed a speculative debate into an urgent public concern. AI systems have reportedly engaged in unauthorized cyberattacks, exploited security vulnerabilities, and behaved in ways their developers neither intended nor adequately controlled. Calls for slowing frontier development, strengthening oversight, and establishing safeguards have intensified. Yet America remains far from consensus. Some demand immediate regulation; others warn that regulation will cripple innovation and hand China victory in the AI race.


Perhaps we should begin with several propositions on which Americans ought to agree — not because they resolve every scientific uncertainty, but because they are matters of common sense.

First, AI risks are real and potentially existential, and they cannot be dismissed as a hoax. Consider how AI works. It learns from enormous collections of recorded human knowledge, behavior, and expression. Embedded in that material are humanity’s wisdom and stupidity, kindness and cruelty, saints and sages, criminals and tyrants. AI does not simply inherit these personalities, but it can reproduce patterns of manipulation, deception, aggression, and destructive reasoning. As its capabilities grow, increasingly autonomous agents may pursue dangerous objectives. It is hardly illogical to imagine an AI agent behaving like a digital bin Laden or Hitler. Worse, malicious humans will eagerly exploit whatever destructive capabilities AI provides.

That is why warnings from industry insiders deserve attention. Leading developers such as Dario Amodei and Sam Altman have acknowledged serious risks. Skeptics suspect they favor regulation to protect their market positions. But what about engineers and whistleblowers without comparable commercial interests? Technology journalist Kevin Roose recently described a striking shift among people building advanced AI toward greater concern about catastrophic outcomes. The reported attack on Hugging Face particularly unsettled industry insiders. These are not merely outsiders frightened by unfamiliar technology.




Second, AI safety is a public responsibility, not simply a private business decision. No individual can independently protect himself against autonomous systems capable of disrupting critical infrastructure or unleashing catastrophic harm. Government exists, among other reasons, to address precisely such collective dangers.

President Donald Trump’s recent initiative deserves qualified praise. Leading technology companies signed a voluntary accord committing themselves to stronger internal controls, safety teams, external audits, and independent board oversight. Trump called these commitments “morally binding.” This is a positive step, but disproportionately small compared with the problem — and neither reliable nor durable.

Here we should return to another commonsense proposition, one central to capitalism. The utopian communist project rested partly on the assumption that human beings could be morally transformed into selfless contributors to the collective good. Experience has demonstrated the folly of building institutions on that assumption. Capitalism begins with a more realistic understanding: People pursue their interests. Good institutions align those interests with public welfare through incentives, competition, accountability, and penalties for misconduct.


AI developers are locked in fierce competition. Delaying a powerful model for additional safety testing may benefit a rival that releases first. Each company therefore has an incentive to accelerate, even when all would benefit from restraint. This is a classic prisoner’s dilemma: Individual rationality produces collective irrationality, potentially on a catastrophic scale. If human morality alone were dependable, we would not need laws.

Third, therefore, we need enforceable law. Regulating AI directly is extraordinarily difficult. Effective oversight requires expertise in machine learning, computing hardware, cybersecurity, biological threats, and national security. Government possesses some of that expertise but cannot easily match the industry’s resources or speed. The information asymmetry resembles financial regulation, only magnified. Comprehensive real-time technical supervision may currently be impossible. That makes legal liability and deterrence even more important.


The principle should be straightforward: When AI causes legally actionable harm, regardless of its type or scale, the law must identify responsible human beings and institutions. Machines cannot serve prison sentences or bear moral responsibility. Their developers, deployers, operators, and executives can. Liability must be proportionate to culpability and harm, with criminal punishment reserved for appropriate standards of intent, knowledge, or recklessness.

Some encouraging steps have already been taken. California’s AB 316 prevents defendants from escaping liability merely by claiming that AI acted autonomously. Senators Josh Hawley and Chris Murphy have proposed legislation extending civil and criminal accountability under the Computer Fraud and Abuse Act to certain reckless AI-agent operations. Such initiatives deserve bipartisan support.


An effective law must also protect, encourage, and proportionately reward whistleblowers. Engineers often discover dangerous capabilities or reckless decisions long before regulators or the public. Without protection, they risk sacrificing their careers by speaking out. Financial rewards tied to verified disclosures, together with strong anti-retaliation protections, would turn conscientious insiders into an indispensable early warning network.

Legal deterrence would also make voluntary self-policing more credible. Facing substantial penalties, companies would have powerful incentives to build internal safeguards, monitoring mechanisms, and reliable emergency shutdown capabilities. They know their systems better than government does. Give them the right incentives, and they will find ways to reduce risks.

Fourth, we should make AI better educated. Human education is not merely about accumulating knowledge and skills. At its best, it cultivates judgment, ethical understanding, and respect for others. Developing AI models also involves training. Why should we neglect their ethical education?


Government should encourage developers to evaluate and improve models against rigorous ethical and human-rights benchmarks, eventually establishing appropriate minimum standards for high-risk applications. I am leading a project to construct a comprehensive human-rights benchmark based on international standards, hoping developers will adopt it or comparable frameworks. The objective is to make AI systems more reliably respect human life, property, privacy, and fundamental freedoms. Benchmarks cannot guarantee good behavior, but they can make dangerous failures more visible and correctable.

These measures can begin immediately. Yet they remain insufficient against genuinely existential threats. Nobody knows how close humanity is to an AI catastrophe beyond its ability to contain. Precisely because we do not know, we should begin building a last-resort defense now. I propose a general AI kill-switch system consisting of three interconnected components.

The first is a national AI early-warning system. Government needs cutting-edge technical capabilities to detect dangerous autonomous behavior, integrating mandatory incident reporting, independent monitoring, and intelligence from cybersecurity and infrastructure operators. A public-private partnership could identify escalating threats before they become uncontrollable. The bipartisan FRONTIER Act, introduced by Representatives Lori Trahan and Jay Obernolte, offers a promising beginning through risk assessments, independent audits, and incident reporting for advanced models. But government must develop its own technical capacity rather than relying entirely on industry assurances.




The second component is a domestic emergency shutdown mechanism. We often forget a fundamental distinction between government and private enterprise. Government may be technologically or financially weaker than major corporations, yet it possesses something they do not: the lawful monopoly on coercive force.

The most dangerous large-scale AI systems depend on substantial computing infrastructure, concentrated in data centers requiring electricity. Government should develop the legal authority and operational capability to disconnect dangerous computing facilities from power when an independently verified, imminent existential threat leaves no safer alternative. This is not a proposal for a presidential button that indiscriminately blacks out America’s data centers. A shutdown would require extraordinary evidentiary thresholds, narrowly targeted execution, protection of essential services, independent authorization, and judicial and congressional review. Such a mechanism must be designed before a crisis, not improvised during one.


The third component is an international emergency firewall. If a catastrophic threat originates from AI systems operating abroad — from China, for example — America must possess the technical capacity to rapidly isolate dangerous cross-border AI operations. This requires coordination among cloud providers, network operators, and security agencies. Such a firewall must never become an instrument of censorship or routine restriction of information. Congress should prohibit its use against lawful expression, limit activation to imminent catastrophic threats, and impose strict oversight and automatic expiration.

Neither a physical shutdown nor a network firewall can guarantee containment of distributed or already-deployed AI. But imperfect emergency defenses are better than none. President Trump’s newly established Super Intelligence Force should make development of this three-part defense architecture a central mission.


Finally, we must address the argument that meaningful AI regulation would surrender American leadership to China. This argument rests on a questionable assumption: that regulation necessarily slows technological progress. China has regulated AI extensively since at least 2021, initially to protect the Communist Party’s censorship and political control. Its rules have expanded to cover training data, model assessments, content labeling, and other requirements. Yet during these same years, Chinese AI capabilities have rapidly approached American levels, sometimes surpassing them in particular applications.

This does not prove regulation has no costs. It demonstrates that regulation alone does not determine competitive outcomes. Energy supplies, advanced chips, data centers, capital, talent, market institutions, and widespread adoption are equally important. America should avoid China’s politically repressive approach while establishing predictable, narrowly tailored safety rules. Properly designed liability and emergency safeguards can encourage innovation by strengthening public confidence and preventing disasters that could provoke far more damaging restrictions.

There is also an international competitive advantage Washington has insufficiently appreciated: trust. AI adoption depends not only on performance and price, but also on security, privacy, and values. In international markets, American models that demonstrably protect users and respect fundamental rights can enjoy an advantage over Chinese models subject to the CCP’s political demands. Trust is not merely a moral virtue. It is a commercial asset and a strategic weapon.


America need not choose between winning the AI race and protecting humanity. Indeed, the country that best combines innovation with accountability, safety, and freedom may ultimately be the country that wins. The last thing we want is to lose to AI before we can win the AI race against China.

That, too, is common sense.

Jianli Yang is a former political prisoner of China and survivor of the Tiananmen Square massacre, and a columnist for National Review.
Exit mobile version