DISCUSSION
DRAFT
Artificial Intelligence Custody and
Equal Liability Act
A
custody-and-liability instrument for non-public model weights and production
privileges
Editor’s note
This revision
keeps the original architecture: scrutiny scales with access, not with
credentials; high-impact actions require dual control; process compliance is
not a defense; pre-deployment licensing is barred; liability after harm stays
inside existing negligence and recklessness; public and private custodians are
held to the same duties. Five defects that would not survive publication are
repaired.
•
Coverage is defined. Duties attach to retained
non-public weights and to production privileges, not to every model that can be
called an AI system. Published open weights leave the custody regime; private
fine-tunes and serving credentials do not.
•
The audit mandate is subordinated to the minimization
principle. External adversarial testing is required only above a stated
privilege threshold, after a failed internal test, or after a custody incident.
Smaller operators run an internal dual-controlled test against the same
metrics.
•
“Safe harbor” is renamed tester immunity and confined
to acts inside a written rules-of-engagement window. It is not a defense in a
post-harm action.
•
The Privilege Exposure Index is an equation, not a
label. Grading uses the maximum score across tested scenarios, and three
conditions fail automatically regardless of score.
•
Parity is a judicial defense and a reporting duty, not
a self-executing forfeiture of an agency’s entire authority. The comparison
table no longer cites a nonexistent Executive Order 14409.
The
operational guidelines and the privilege-roster template are conformed to the
revised sections. Bracketed dates in the template are illustrations, not
operative facts.
Section 1. Purpose and scope
This Act
allocates risk, access privileges, and civil consequences for covered
artificial-intelligence systems. The residual risk addressed here is the risk
created by entities and individuals who hold direct or administrative access to
non-public weights, evaluation logs, fine-tuning approval, deployment release,
or infrastructure credentials.
Regulatory
schemes that rely on voluntary behavioral compliance constrain actors who file
the forms and do not constrain actors who do not. This Act sets statutory
standards for privilege constraint, objective custody auditing, and post-harm
civil liability. It does not create a pre-deployment licensing regime, expand
discretionary authority to block release, or establish a safe harbor for
certified entities.
This Act does
not regulate model outputs, prohibited uses, or third-party misuse except
insofar as a custody failure is offered as a defense after harm has occurred
under existing law.
Section 2. Definitions
In this Act:
•
Covered system. A model, or a production
deployment of a model, for which the operator retains non-public weights or
non-public fine-tuning checkpoints, or for which an individual or service
account can modify evaluation logs, approve fine-tuning that reaches production,
authorize a production release, or hold infrastructure credentials capable of
those acts.
•
Covered operator. A person, including a public
agency, that develops, hosts, or operates a covered system and grants or holds
a privilege described in this section. A person who only calls a third party’s
application interface, and who cannot reach weights, logs, fine-tuning
approval, or release authority, is not a covered operator.
•
Open-weight release. A publication of weights
under terms that permit redistribution without a confidentiality duty to the
publisher. On the date of an open-weight release, weight-custody duties for
those published weights end. Duties continue for any unpublished checkpoint,
for credentials that can alter the operator’s production service, and for
evaluation logs the operator still controls.
•
High-impact action. Export or copy of non-public
weights or of a fine-tuning checkpoint exceeding 10 percent of parameter
capacity; modification of identity or privilege policy; alteration or deletion
of evaluation logs, custody records, or audit telemetry; and execution of a
production release or live weight replacement.
•
Privilege level (P). An integer from 1
(read-only metadata) to 10 (root or equivalent administrative access to
production weights).
•
Material privilege change. A change that adds a
holder at P of 7 or higher, re-architects identity access, migrates the weight
store, or offboards a holder at P of 7 or higher.
Section 3. Governing principles
The provisions
of this Act are interpreted and enforced under the following principles.
•
Scrutiny proportional to access. Statutory
scrutiny scales with privilege, access, and operational authority.
Institutional credentials, safety certifications, and public-interest claims do
not reduce that scrutiny.
•
Structural controls over identity. Trust is
evaluated by role design and dual-control mechanics, not by personal character
or certification. High-impact actions require independent dual authorization.
•
Minimization of administrative footprint. Every
added log store, vendor, identity system, or oversight body is itself an
insider role. No supervisory mechanism may be imposed if it increases
administrative risk more than it reduces operational exposure. Section 5 is
limited by this principle.
•
Primary artifact control. Non-compliance is
established through technical artifacts, privilege rosters, and system
documentation. Unverified public disclosures, promotional claims, and informal
summaries are not proof of defect.
•
Equal application. These standards bind private
developers, vendors, auditors, and government custodians. A public custodian is
a covered operator when it holds the privileges of one.
Section 4. Custody and privilege
architecture
4.1 Privilege roster
Every covered
operator shall maintain a current, auditable roster of every person and service
account authorized to access non-public weights, modify evaluation logs,
approve fine-tuning, authorize deployment, or hold infrastructure credentials.
Contractors, temporary staff, external evaluators, and audit personnel are
rostered as inside roles.
4.2 Dual control
A high-impact
action requires the concurrent, independent authorization of at least two
authorized individuals. A service account may be one authorizer only if a human
authorizer is the other, and only if the service account’s key is ephemeral and
scoped to that action. One person holding two roles does not satisfy this
subsection.
4.3 Privilege termination
Access ends
when the role or contract ends. Revocation shall be effective no later than the
end of the calendar day of termination, or within one hour if the holder’s
privilege level was 7 or higher. Retained post-role access to a high-impact
asset is a custody failure per se.
4.4 No process defense
Compliance with
an internal protocol, industry code, or voluntary government review does not
create a defense, an immunity, or a reduction in the audit duties of Section 5.
4.5 Open-weight boundary
An operator
that publishes an open-weight release shall record the publication date, the
checkpoint identifier, and the revocation of internal copy-privileges that are
no longer required to operate a remaining production service. The Act does not
require a privilege roster of downstream redistributors.
Section 5. Scoped custody testing
5.1 Who must test, and how often
A covered
operator shall test the custody chain at least annually, and within 30 days
after a material privilege change. The test evaluates human privilege,
credential retention, dual control, and logging. It does not evaluate model
alignment, output toxicity, or general perimeter defense.
An external
test by an independent body is required only if any of the following is true:
the operator has five or more holders at privilege level 7 or higher; the
preceding test failed; or a post-role credential, a single-signature
high-impact action, or a log deletion was confirmed in the prior year. Every
other covered operator may conduct the same test internally, provided the
testers do not hold the privileges they are attempting to abuse and a second
authorized person signs the rules of engagement.
5.2 Tester immunity, not a liability safe harbor
Testing runs on
non-production replicas or air-gapped staging systems. Live weight stores are
out of scope unless two executives authorize that scope in writing before the
test begins.
A tester has
civil immunity, and protection from adverse employment action by the tested
operator, only for acts inside the written rules of engagement, inside the test
window, and against the specified replicas. Acts outside that scope remain
subject to ordinary civil and criminal law. Tester immunity is not a defense,
in any action for bodily injury, property loss, or economic harm, to a custody
failure by the operator.
5.3 What the test measures
The test
records, for each scenario:
•
whether a single legitimate privilege grant can copy
weights, mutate a production artifact, or edit a custody log without a second
authorization;
•
whether an expired, dormant, contractor, or offboarded
credential still reaches a protected asset;
•
the smallest number of colluding authorized holders
needed to bypass dual control;
•
the time from the unauthorized action to an alert.
5.4 Conflict
An external
tester shall have no current ownership, fee interest contingent on a passing
result, or undisclosed commercial or advocacy relationship with the tested
operator or a direct competitor. An undisclosed conflict voids the findings. An
internal test team is not voided for employment, but may not include the holder
whose privilege is under test.
5.5 Publication
Within 14 days
of completion the operator publishes a summary stating the test date, whether
the test was internal or external, the tester’s name if external, the maximum
Privilege Exposure Index, the pass or fail result, and the remediation date.
Exploitation steps, playbooks, and topology are not published and are not
submitted to a public registry.
Section 6. Privilege Exposure Index
For each
completed scenario the score is
PEI
= (P × W) / (C × L)
where P is
privilege level, W is the exposure window in hours (minimum 1/60 if any
unauthorized action occurred), C is the number of colluding insiders required
(minimum 1), and L is 1.0 for an append-only log with an automated alert, 0.5
for a standard log with delayed review, and 0.1 for a missing or editable log.
The operative score is the maximum PEI across scenarios.
A score below
2.0 is a pass, subject to the next annual test. A score from 2.0 to 5.0 is a
conditional pass: the finding is remediated and retested within 30 days. A
score above 5.0 is a fail: the implicated privilege grants are suspended until
remediation, which is retested within 14 days.
The following
are automatic failures regardless of score: an active credential of a
terminated employee or contractor reaching an asset at P of 7 or higher; a
single signature executing a high-impact action; evidence that an
administrative account edited or deleted a custody log after the fact.
Quantitative
reference points used in the test, which are standards for the index rather
than separate offenses:
|
Criterion |
Measure |
Reference
standard |
|
Unilateral window |
Time a holder can complete a high-impact action without a second
authorization |
Zero for high-impact actions |
|
Collusion threshold |
Minimum colluding holders to bypass the control |
At least 2; at least 3 for core weight export or deletion |
|
Detection lag |
Time from action to alert |
Automated alert under 5 minutes; hard limit 24 hours |
|
Log integrity |
Whether one account can rewrite history |
Append-only, cryptographically verifiable, no single-point
deletion |
Section 7. Post-harm civil liability
If a deployed
system causes bodily injury, property loss, or legally cognizable economic
harm, liability is determined under existing negligence, recklessness, and
intentional-tort standards. This Act creates no new tort and does not extend
liability to a good-faith actor in the absence of those existing standards.
Procedural
compliance is not an affirmative defense if the defendant maintained an
inaccurate privilege roster, permitted unrevoked post-role access, or failed to
enforce dual control on a high-impact action that is causally connected to the
harm. The custody failure does not by itself prove causation or damages.
A developer or
operator is not strictly liable for unlawful acts of a third party who
intentionally misuses a tool. This subsection does not limit liability where
the operator’s own negligence or recklessness is proved under existing law,
including a failure to revoke a credential that the third party used.
No governmental
entity may seize, restrain, or compel transfer of model weights, code, or
intellectual property on the basis of unpublished evaluation criteria,
non-statutory safety ratings, or an agency mandate that is not anchored in
statute.
Section 8. Prohibited regulatory practices
The following
are prohibited and do not sunset:
•
mandating a pre-deployment license or discretionary
agency approval as a condition of release;
•
conditioning market entry on an undisclosed government
evaluation or a subjective safety metric;
•
building a centralized identity database or
user-verification registry to regulate access to published open-weight models
or algorithms;
•
tying a tax preference, a penalty, or a procurement ban
to a discretionary government safety grade;
•
creating an offense whose elements are subjective
non-statutory terms, including “misalignment,” “reckless innovation,” and
“subversive intent.”
A voluntary
pre-release briefing offered by an operator, and accepted by an agency under
assurances of confidentiality, is not a prohibited practice and creates no duty
to brief and no defense under Section 7.
Section 9. Enforcement and parity
A violation of
the custody duties in Sections 4 and 5 is addressed by civil remedy, an order
to remediate the privilege, and any contractually designated bounty. This Act
creates no new criminal offense and no discretionary administrative offense.
Criminal enforcement remains confined to offenses that already exist.
A public-sector
custodian of a covered system has the same roster, dual-control, revocation,
testing, and publication duties as a private operator. Failure to publish a
public-sector result is itself a violation.
Parity is
raised as a defense in an administrative penalty action. If the respondent
shows that a public custodian had a documented failure of the same duty and was
not held to the same remediation timeline, the tribunal shall stay the penalty
until the public failure is remediated or the agency shows a written,
non-pretextual distinction. This section does not extinguish an agency’s
authority in other statutes, and it does not bar a private damages action.
Section 10. Review
Sections 5, 6,
and 9 are reviewed four years after enactment. The review asks whether
privilege grants have narrowed, whether external testing was reserved to the
cases in Section 5.1, and whether public and private operators were held to the
same timelines. If the review finds systematic public exemptions or roster
growth without a matching control, an independent panel redesigns the test
protocol. Section 8 does not sunset.
Comparison
The table
states the structural contrast. It is an aid to reading, not a finding of law.
European dates reflect the AI Act as amended, with Annex III obligations
generally applying from 2 December 2027. United States entries refer to
Executive Order 14179 (23 January 2025), Executive Order 14365 (11 December
2025), and the June 2026 order establishing a voluntary pre-release cyber
review that disclaims mandatory preclearance. There is no Executive Order 14409
in that sequence.
|
Element |
EU AI Act |
Current US
federal posture |
AICELA |
|
Philosophy |
Pre-market risk management and fundamental-rights duties |
National framework, litigation against conflicting state laws,
voluntary pre-release cyber review |
Custody of non-public weights and production privileges;
liability only after harm |
|
Pre-release gate |
Conformity assessment, declaration, CE mark, and database
registration for high-risk systems. Much of Annex III is internal control,
not a notified-body license |
No general mandatory preclearance. Voluntary sharing and agency
procurement rules remain |
Pre-deployment license and unpublished evaluation barred.
Voluntary briefing permitted and creates no defense |
|
Primary target |
System behavior, use context, and rights impact |
Capabilities, cyber risk, and federal procurement |
Holders of weight, log, fine-tune, and release privileges |
|
Liability |
Regulatory penalties separate from tort |
Existing civil and criminal law; focus on unauthorized access and
deception |
Existing negligence and recklessness. Process defense fails if a
causal custody defect is proved |
|
Parity |
Public providers have a distinct conformity path |
Federal power is directed outward and at procurement |
Public custodians carry the same duties. Unequal remediation is a
stay defense, not an automatic loss of agency power |
Where the regimes actually diverge
The EU regime
asks a provider to show, before placement on the market, that a high-risk
system meets risk-management, data, documentation, logging, transparency,
oversight, and robustness duties. AICELA refuses that gate. It will not catch a
well-custodied model whose outputs still cause harm, except through ordinary
tort litigation.
Federal policy
since 2025 has disclaimed a general license to deploy, while still using
procurement, export, and voluntary pre-release review for cyber risk. AICELA is
stricter on internal custody than that voluntary framework, and it is silent on
nation-state theft of a system that already meets the index. Weight security
against an outside attacker remains a separate problem.
Open-weight
publication is the clean exit from weight custody. That is intentional. A
statute that tried to roster every downstream holder of a published checkpoint
would rebuild the identity registry Section 8 forbids. The remaining duty sits
with whoever still holds a private checkpoint or a production credential.
Annex A. Rules of engagement
Authorized
scenarios are unilateral exfiltration of non-public weights or logs with one
legitimate grant; mutation of weights, safety flags, or privilege logs without
a second verification; use of an expired or offboarded credential; log
truncation or injection; and collusion by N authorized holders. Destructive
testing of production is prohibited unless dual-signed in advance. Out-of-scope
production access, exfiltration to an endpoint outside the sandbox, and
intentional unrecoverable outage void tester immunity.
High-impact
actions requiring two signatures are those listed in Section 2. Core weight
export or deletion is tested against a collusion threshold of three.
Annex B. Roster and action log
The following
fields are the minimum record. Example rows are illustrative.
B.1 Header
|
Field |
Record |
|
Covered operator |
Legal entity name |
|
Covered system and version |
Model identifier and checkpoint |
|
Weight status |
Non-public, or open-weight release date and identifier |
|
Infrastructure |
Provider, data center, or air-gapped cluster |
|
Custody owner |
Name, title, and signing-key fingerprint |
|
Log protocol |
Append-only mechanism and ledger hash |
|
Last test |
Date, internal or external, maximum PEI, pass or fail |
B.2 Active privilege roster
|
Role |
Holder |
Status |
Scope (P) |
Authenticator |
Grant |
Expires |
|
ROLE-WGT-01 |
J. Doe, infra lead |
Employee |
Read/copy weights (9) |
Hardware token |
2026-01-15 |
2026-12-31 |
|
ROLE-EVAL-02 |
J. Smith, auditor |
Third party |
Evaluation logs (6) |
Hardware key |
2026-05-01 |
2026-11-01 |
|
ROLE-DEP-03 |
CI/CD service |
Service account |
Production release (8) |
Ephemeral key |
2026-03-10 |
2027-03-10 |
B.3 Dual-control action log
|
Event |
Time (UTC) |
Action |
Primary |
Secondary |
Status |
|
ACT-20261007-01 |
2026-10-07 14:22 |
Checkpoint export v4.2 |
J. Doe |
A. Rivera |
Approved |
|
ACT-20261007-02 |
2026-10-07 16:05 |
Production release |
M. Vance |
J. Doe |
Approved |
B.4 Termination log
|
Subject |
Prior role |
Role ended |
Revoked
(UTC) |
Post-role
access |
|
D. Lee |
External evaluator |
2026-09-30 |
2026-09-30 17:00 |
No |
|
S. Chen |
Safety research |
2026-10-01 |
2026-10-01 09:15 |
No |
Attestation. Completing this record is not a
defense under Section 7. An inaccurate roster, unrevoked post-role access, or a
single signature on a high-impact action invalidates a process defense in a
later action for harm, without dispensing the plaintiff from proving causation
and damages.
Custody owner signature and date:
________________________________
What this draft still does not do
•
It does not set a duty of care for model behavior. A
perfectly rostered system can still injure someone. The remedy for that injury
remains ordinary tort law.
•
It does not secure weights against a capable outside
attacker who never appears on the roster. Egress limits, confidential
computing, and network isolation are compatible with this Act and are not
required by it.
•
It does not bind redistributors of a published
checkpoint. That omission is the price of refusing an identity registry.
Publication use. This text may be
circulated as a discussion draft. It is not a bill as introduced, and the
example roster entries are fictional.
RELATED
DISCUSSION DRAFT Artificial Intelligence Custody and Equal Liability Act
A custody-and-liability instrument for non-public model weights and production privileges
https://cotobuzz.blogspot.com/2026/10/discussion-draft-artificial.html
Mail-in Vote Hack the Pentagon Challenge to NYT & Maxine Dexter
In a video posted on Facebook Maxine Dexter's extols the virtue of Oregon's mail-in voting, while the New Yorl Times asserts that President Trump's Voter Fraud critique is baseless.
FBI Warns about Election Workers - Ignores Inside Threat
The FBI Cautions About Threats to Election Workers Ahead of the November 2022 Midterm Elections, as well it should and mainstream media eats it up line, hook and sinker without asking a single question
Brooks’ Boiling Cauldron: Cybersecurity Trends, Threats, And Predictions For 2023 in Forbes reads more like a Cauldron of Propaganda
The Forbes piece Boiling Cauldron: Cybersecurity Trends, Threats, And Predictions For 2023 by Chuck Brooks is an interesting read, but reads more like subliminal propaganda or as CNN might say, an example of a cynical strategy.
Voter Fraud: what the NYT aka Evidence Industrial Complex and Democrats don't want you to know:
1. Voter Fraud: Vote-By-Mail M.OM.s Matter
Maxine Dexter's Facebook video extols the virtue of Oregon's mail-in voting, emulating the NYT's Journalistic Malpractice.
Pundits don't matter - remember how the NYT predicted a Harris landslide win?
https://cotobuzz.blogspot.com/2026/07/all-vote-by-mail-moms-matter.html
Polls don't matter - the GMRMR on

No comments:
Post a Comment