It's not that big
(1) The artificial intelligence model was trained using a quantity of computing power greater than 10^26 integer or floating-point operations.
(2) The artificial intelligence model was trained using a quantity of computing power sufficiently large that it could reasonably be expected to have similar or greater performance as an artificial intelligence model trained using a quantity of computing power greater than 10^26 integer or floating-point operations in 2024 as assessed using benchmarks commonly used to quantify the general performance of state-of-the-art foundation models.
…and have the following:
“Hazardous capability” means the capability of a covered model to be used to enable any of the following harms in a way that would be significantly more difficult to cause without access to a covered model:
(A) The creation or use of a chemical, biological, radiological, or nuclear weapon in a manner that results in mass casualties.
(B) At least five hundred million dollars ($500,000,000) of damage through cyberattacks on critical infrastructure via a single incident or multiple related incidents.
(C) At least five hundred million dollars ($500,000,000) of damage by an artificial intelligence model that autonomously engages in conduct that would violate the Penal Code if undertaken by a human.
(D) Other threats to public safety and security that are of comparable severity to the harms described in paragraphs (A) to (C), inclusive.
…In which case the organization creating the model must apply for one of these:
“Limited duty exemption” means an exemption, pursuant to subdivision (a) or (c) of Section 22603, with respect to a covered model that is not a derivative model that a developer can reasonably exclude the possibility that a covered model has a hazardous capability or may come close to possessing a hazardous capability when accounting for a reasonable margin for safety and the possibility of posttraining modifications.
So in practice, only the flops criteria matters. Which means only giant companies with well-funded legal departments, or large states, can build these models, increasing centralization and control, and making full model access a scarce resource worth fighting over.
I've been actually thinking there should be a bounty for a real hazardous use of AI identified. The problem would be defining hazardous (which would hopefully itself spur conversation). On one end I imagine trivial "hazards" like what we test models with today (like asking to build a bomb) and on the other it's easy to see there could be a shifting goalposts thing where we keep finding reasons something that technically meets the hazard criteria isn't reall hazardous.
A harms-based approach, regardless of the model used, seems more able to be put into practice.
[1] https://www.whitehouse.gov/briefing-room/presidential-action...
There is freedom of speech regardless if it's written in English or C.
It was also tried in a very different time. Given that we can't even allow free speech on digital platforms today, I'm not sure that many courts would allow for free speech claims to fall under the first amendment.
- Developers must assess whether their AI models have hazardous capabilities before training them. They must also be capable of promptly shutting down the model if safety concerns arise.
- Developers must annually certify compliance with safety requirements. They must report any AI safety incidents to a newly created Frontier Model Division within the Department of Technology.
- Cluster Operation Regulation: OOpolicies to assess whether customers intend to use the cluster for deploying AI models. Violations may lead to civil penalties.
- A new division within the Department of Technology will review developer certifications, release summarized findings, and may assess related fees.
- The Department of Technology will establish a public cloud computing cluster named CalCompute, focusing on safe and secure deployment of large-scale AI models and promoting equitable innovation.
My outsider's understanding is that we really don't know specifically how the models learn what they learn or why they give specific answers. Is it possible that we could even know whether a model could present hazardous capabilities prior to training it? Or after it for that matter?