○ Growing concerns about the societal risks posed by advanced artificial intelligence (AI) systems have prompted debate over whether and how the U.S. government should promote stronger security practices among private-sector developers. Although some companies have made voluntary commitments to protect their systems, competitive pressures and inconsistent approaches raise questions about the adequacy of self-regulation. At the same time, government intervention carries risks: Overly stringent security requirements could limit innovation, create barriers for small firms, and harm U.S. competitiveness.
○ To help the U.S. government and AI industry navigate these challenges, RAND researchers identified four distinct governance approaches to strengthen security practices among developers of advanced AI systems:
- Government-enforced AI security standards for high-risk model developers
- Government-led AI developer authorization program conditioning federal use on security compliance
- Industry-led AI security certification to promote adoption of common standards
- Self-regulation combined with increased government-industry collaboration on security practices
○ By presenting a variety of practicable options, this work enables decisionmakers to better weigh trade-offs and find the right balance between strengthening security and preserving innovation.