The ideal case is a statutory agency with regulatory authority that sets very clear standards for what model capabilities can and cannot release. Those are set ahead of time and well known by frontier model providers.
Most normal regulations are managed through the administrative procedures act process. That’s a legal requirement that involves deliberation and public comment.
I’d argue you could pretty easily enumerate most capabilities that have been obvious concerns for a while. For example, cyber security.
This structure can last decades and reassure players they can operate in the market without rules changing suddenly without warning.
Some kind of sudden, temporary action like this export control tool is legally fragile. Even if sometimes necessary in exceptional cases. But if the administration sees this as a permanent way of working, they won’t be helping anyone (but maybe themselves through grift).
If the administration truly cares about functional regulation (which maybe they don’t) they need a sturdier legal structure that lasts past Trump. Not flimsy edicts that change with the wind
But yes crazy things happen. Maybe it won’t catch everything.
The right answer are giving the govt / this agency explicit legal, short term model pause capabilities to let the rule making process happen if something completely out of band happens. Or let the agency study/approve models prior to release.
Not sudden, unexpected application of export laws.
Yet in this case, for Fable, cybersecurity risks have been well know for some time. A rule created years ago when we knew this would happen could have given frontier labs and the market predictability.
Is there a jurisdiction that HAS created legislation or regulations that takes it into account? I would think that if it is super easy to foresee and formulate practical and effective regulations for AI, then it must already exist somewhere.