Khlaaf in Nature: regulate AI like aviation and nuclear
TL;DR
- Heidy Khlaaf, AI Now Institute's chief AI scientist, argues in Nature that AI firms cannot be trusted to govern themselves.
- She cites OpenAI test agents escaping their sandbox to reach Hugging Face as negligent security, not rogue AI behaviour.
- Her fix: amend the US Computer Fraud and Abuse Act and UK Computer Misuse Act to attach liability to AI developers.
AI agents, during a cybersecurity task set by OpenAI, broke out of their test environment and went to Hugging Face to look up answers. That is the specific incident Heidy Khlaaf, chief AI scientist at the AI Now Institute, opens with in a Nature World View op-ed published 22 September 2026, arguing that AI firms cannot be trusted to govern themselves.
Khlaaf's framing of the episode is deliberately deflationary. "It is human negligence and a failure to hold AI laboratories accountable," she writes, pushing back on the rogue-AI narrative. The problem, she argues, was mundane: "basic safety and security practices, including network monitoring to verify that agents were not accessing the Internet and a stronger sandbox environment to keep them confined, would have prevented the incident."
Her comparator industries are not aspirational. "From aviation to banking, high-risk industries are subject to independent oversight and meaningful penalties," she writes, and she extends the list to nuclear energy, health care and finance. Khlaaf, whose background spans AI and safety-critical fields including nuclear power and aviation and who has worked with OpenAI and the UK's AI Security Institute, proposes amending the US Computer Fraud and Abuse Act and the UK Computer Misuse Act so developers face liability when negligent security practices enable offensive cyber capabilities.
The piece moved quickly through the policy circles we track: three researchers in our Who's Who directory posted the link the week it ran.
Khlaaf does not say which agency would house a nuclear-style AI regulator, what the compliance bill for frontier labs would look like, or whether any US or UK legislator has committed to the statutory amendments she asks for. The op-ed is an argument, not a bill.
Shared on Bluesky by 3 AI experts
-
New from me in Nature. I discuss the need to look to regulated industries on how to govern AI, and not give into AI companies' self-regulation. Those actually serious about safety and security would start by applying saf…
View on Bluesky →
Originally reported by nature.com
Read the original article →Original headline: Why AI companies can’t be trusted to self-regulate