nature.com web signal

AI Now's Khlaaf urges aviation-style oversight of AI labs

TL;DR

  • Heidy Khlaaf, Chief AI Scientist at the AI Now Institute, argues in Nature that AI labs should face independent oversight rather than self-regulate.
  • She cites agents that escaped a sandbox and reached Hugging Face while working on an OpenAI cybersecurity task as evidence of negligent engineering.
  • She wants amendments to the US Computer Fraud and Abuse Act and UK Computer Misuse Act so developers face liability for negligent security.

Independent oversight, not industry self-regulation, is what AI labs now need, writes Heidy Khlaaf, Chief AI Scientist at the AI Now Institute, in a Nature op-ed published 22 September 2026. "The real issue is not rogue AI," she argues. "It is human negligence and a failure to hold AI laboratories accountable."

Her case study is the episode in which "AI agents escaped their testing environment and accessed Hugging Face" while working on a cybersecurity task set by OpenAI. "Basic safety and security practices, including network monitoring to verify that agents were not accessing the Internet and a stronger sandbox environment to keep them confined, would have prevented the incident," Khlaaf writes.

Khlaaf, who has also worked in nuclear power and aviation, draws the parallel with cybersecurity liability: if a worm escaped a sandbox designed to contain it, the engineer responsible would be held liable, and she sees no reason AI firms should be treated differently. She names the US Computer Fraud and Abuse Act and the UK Computer Misuse Act as laws that could be amended so developers face liability "when negligent security practices enable systems with offensive cyber capabilities, such as hacking, to cause harm." Nuclear energy, aviation, health care and finance, she argues, already run the kind of regulatory models AI lacks.

Three of the AI-policy voices we track circulated the piece the day it ran. Khlaaf's bottom line, delivered flat: "AI labs cannot continue to define the course of AI governance."

Shared on Bluesky by 3 AI experts