Wednesday, October 07, 2026

DISCUSSION DRAFT Artificial Intelligence Custody and Equal Liability Act

 

DISCUSSION DRAFT

Artificial Intelligence Custody and Equal Liability Act

A custody-and-liability instrument for non-public model weights and production privileges

Editor’s note

This revision keeps the original architecture: scrutiny scales with access, not with credentials; high-impact actions require dual control; process compliance is not a defense; pre-deployment licensing is barred; liability after harm stays inside existing negligence and recklessness; public and private custodians are held to the same duties. Five defects that would not survive publication are repaired.

•        Coverage is defined. Duties attach to retained non-public weights and to production privileges, not to every model that can be called an AI system. Published open weights leave the custody regime; private fine-tunes and serving credentials do not.

•        The audit mandate is subordinated to the minimization principle. External adversarial testing is required only above a stated privilege threshold, after a failed internal test, or after a custody incident. Smaller operators run an internal dual-controlled test against the same metrics.

•        “Safe harbor” is renamed tester immunity and confined to acts inside a written rules-of-engagement window. It is not a defense in a post-harm action.

•        The Privilege Exposure Index is an equation, not a label. Grading uses the maximum score across tested scenarios, and three conditions fail automatically regardless of score.

•        Parity is a judicial defense and a reporting duty, not a self-executing forfeiture of an agency’s entire authority. The comparison table no longer cites a nonexistent Executive Order 14409.

The operational guidelines and the privilege-roster template are conformed to the revised sections. Bracketed dates in the template are illustrations, not operative facts.




Section 1. Purpose and scope

This Act allocates risk, access privileges, and civil consequences for covered artificial-intelligence systems. The residual risk addressed here is the risk created by entities and individuals who hold direct or administrative access to non-public weights, evaluation logs, fine-tuning approval, deployment release, or infrastructure credentials.

Regulatory schemes that rely on voluntary behavioral compliance constrain actors who file the forms and do not constrain actors who do not. This Act sets statutory standards for privilege constraint, objective custody auditing, and post-harm civil liability. It does not create a pre-deployment licensing regime, expand discretionary authority to block release, or establish a safe harbor for certified entities.

This Act does not regulate model outputs, prohibited uses, or third-party misuse except insofar as a custody failure is offered as a defense after harm has occurred under existing law.

Section 2. Definitions

In this Act:

•        Covered system. A model, or a production deployment of a model, for which the operator retains non-public weights or non-public fine-tuning checkpoints, or for which an individual or service account can modify evaluation logs, approve fine-tuning that reaches production, authorize a production release, or hold infrastructure credentials capable of those acts.

•        Covered operator. A person, including a public agency, that develops, hosts, or operates a covered system and grants or holds a privilege described in this section. A person who only calls a third party’s application interface, and who cannot reach weights, logs, fine-tuning approval, or release authority, is not a covered operator.

•        Open-weight release. A publication of weights under terms that permit redistribution without a confidentiality duty to the publisher. On the date of an open-weight release, weight-custody duties for those published weights end. Duties continue for any unpublished checkpoint, for credentials that can alter the operator’s production service, and for evaluation logs the operator still controls.

•        High-impact action. Export or copy of non-public weights or of a fine-tuning checkpoint exceeding 10 percent of parameter capacity; modification of identity or privilege policy; alteration or deletion of evaluation logs, custody records, or audit telemetry; and execution of a production release or live weight replacement.

•        Privilege level (P). An integer from 1 (read-only metadata) to 10 (root or equivalent administrative access to production weights).

•        Material privilege change. A change that adds a holder at P of 7 or higher, re-architects identity access, migrates the weight store, or offboards a holder at P of 7 or higher.

Section 3. Governing principles

The provisions of this Act are interpreted and enforced under the following principles.

•        Scrutiny proportional to access. Statutory scrutiny scales with privilege, access, and operational authority. Institutional credentials, safety certifications, and public-interest claims do not reduce that scrutiny.

•        Structural controls over identity. Trust is evaluated by role design and dual-control mechanics, not by personal character or certification. High-impact actions require independent dual authorization.

•        Minimization of administrative footprint. Every added log store, vendor, identity system, or oversight body is itself an insider role. No supervisory mechanism may be imposed if it increases administrative risk more than it reduces operational exposure. Section 5 is limited by this principle.

•        Primary artifact control. Non-compliance is established through technical artifacts, privilege rosters, and system documentation. Unverified public disclosures, promotional claims, and informal summaries are not proof of defect.

•        Equal application. These standards bind private developers, vendors, auditors, and government custodians. A public custodian is a covered operator when it holds the privileges of one.

Section 4. Custody and privilege architecture

4.1 Privilege roster

Every covered operator shall maintain a current, auditable roster of every person and service account authorized to access non-public weights, modify evaluation logs, approve fine-tuning, authorize deployment, or hold infrastructure credentials. Contractors, temporary staff, external evaluators, and audit personnel are rostered as inside roles.

4.2 Dual control

A high-impact action requires the concurrent, independent authorization of at least two authorized individuals. A service account may be one authorizer only if a human authorizer is the other, and only if the service account’s key is ephemeral and scoped to that action. One person holding two roles does not satisfy this subsection.

4.3 Privilege termination

Access ends when the role or contract ends. Revocation shall be effective no later than the end of the calendar day of termination, or within one hour if the holder’s privilege level was 7 or higher. Retained post-role access to a high-impact asset is a custody failure per se.

4.4 No process defense

Compliance with an internal protocol, industry code, or voluntary government review does not create a defense, an immunity, or a reduction in the audit duties of Section 5.

4.5 Open-weight boundary

An operator that publishes an open-weight release shall record the publication date, the checkpoint identifier, and the revocation of internal copy-privileges that are no longer required to operate a remaining production service. The Act does not require a privilege roster of downstream redistributors.

Section 5. Scoped custody testing

5.1 Who must test, and how often

A covered operator shall test the custody chain at least annually, and within 30 days after a material privilege change. The test evaluates human privilege, credential retention, dual control, and logging. It does not evaluate model alignment, output toxicity, or general perimeter defense.

An external test by an independent body is required only if any of the following is true: the operator has five or more holders at privilege level 7 or higher; the preceding test failed; or a post-role credential, a single-signature high-impact action, or a log deletion was confirmed in the prior year. Every other covered operator may conduct the same test internally, provided the testers do not hold the privileges they are attempting to abuse and a second authorized person signs the rules of engagement.

5.2 Tester immunity, not a liability safe harbor

Testing runs on non-production replicas or air-gapped staging systems. Live weight stores are out of scope unless two executives authorize that scope in writing before the test begins.

A tester has civil immunity, and protection from adverse employment action by the tested operator, only for acts inside the written rules of engagement, inside the test window, and against the specified replicas. Acts outside that scope remain subject to ordinary civil and criminal law. Tester immunity is not a defense, in any action for bodily injury, property loss, or economic harm, to a custody failure by the operator.

5.3 What the test measures

The test records, for each scenario:

•        whether a single legitimate privilege grant can copy weights, mutate a production artifact, or edit a custody log without a second authorization;

•        whether an expired, dormant, contractor, or offboarded credential still reaches a protected asset;

•        the smallest number of colluding authorized holders needed to bypass dual control;

•        the time from the unauthorized action to an alert.

5.4 Conflict

An external tester shall have no current ownership, fee interest contingent on a passing result, or undisclosed commercial or advocacy relationship with the tested operator or a direct competitor. An undisclosed conflict voids the findings. An internal test team is not voided for employment, but may not include the holder whose privilege is under test.

5.5 Publication

Within 14 days of completion the operator publishes a summary stating the test date, whether the test was internal or external, the tester’s name if external, the maximum Privilege Exposure Index, the pass or fail result, and the remediation date. Exploitation steps, playbooks, and topology are not published and are not submitted to a public registry.

Section 6. Privilege Exposure Index

For each completed scenario the score is

PEI = (P × W) / (C × L)

where P is privilege level, W is the exposure window in hours (minimum 1/60 if any unauthorized action occurred), C is the number of colluding insiders required (minimum 1), and L is 1.0 for an append-only log with an automated alert, 0.5 for a standard log with delayed review, and 0.1 for a missing or editable log. The operative score is the maximum PEI across scenarios.

A score below 2.0 is a pass, subject to the next annual test. A score from 2.0 to 5.0 is a conditional pass: the finding is remediated and retested within 30 days. A score above 5.0 is a fail: the implicated privilege grants are suspended until remediation, which is retested within 14 days.

The following are automatic failures regardless of score: an active credential of a terminated employee or contractor reaching an asset at P of 7 or higher; a single signature executing a high-impact action; evidence that an administrative account edited or deleted a custody log after the fact.

Quantitative reference points used in the test, which are standards for the index rather than separate offenses:

Criterion

Measure

Reference standard

Unilateral window

Time a holder can complete a high-impact action without a second authorization

Zero for high-impact actions

Collusion threshold

Minimum colluding holders to bypass the control

At least 2; at least 3 for core weight export or deletion

Detection lag

Time from action to alert

Automated alert under 5 minutes; hard limit 24 hours

Log integrity

Whether one account can rewrite history

Append-only, cryptographically verifiable, no single-point deletion

Section 7. Post-harm civil liability

If a deployed system causes bodily injury, property loss, or legally cognizable economic harm, liability is determined under existing negligence, recklessness, and intentional-tort standards. This Act creates no new tort and does not extend liability to a good-faith actor in the absence of those existing standards.

Procedural compliance is not an affirmative defense if the defendant maintained an inaccurate privilege roster, permitted unrevoked post-role access, or failed to enforce dual control on a high-impact action that is causally connected to the harm. The custody failure does not by itself prove causation or damages.

A developer or operator is not strictly liable for unlawful acts of a third party who intentionally misuses a tool. This subsection does not limit liability where the operator’s own negligence or recklessness is proved under existing law, including a failure to revoke a credential that the third party used.

No governmental entity may seize, restrain, or compel transfer of model weights, code, or intellectual property on the basis of unpublished evaluation criteria, non-statutory safety ratings, or an agency mandate that is not anchored in statute.

Section 8. Prohibited regulatory practices

The following are prohibited and do not sunset:

•        mandating a pre-deployment license or discretionary agency approval as a condition of release;

•        conditioning market entry on an undisclosed government evaluation or a subjective safety metric;

•        building a centralized identity database or user-verification registry to regulate access to published open-weight models or algorithms;

•        tying a tax preference, a penalty, or a procurement ban to a discretionary government safety grade;

•        creating an offense whose elements are subjective non-statutory terms, including “misalignment,” “reckless innovation,” and “subversive intent.”

A voluntary pre-release briefing offered by an operator, and accepted by an agency under assurances of confidentiality, is not a prohibited practice and creates no duty to brief and no defense under Section 7.

Section 9. Enforcement and parity

A violation of the custody duties in Sections 4 and 5 is addressed by civil remedy, an order to remediate the privilege, and any contractually designated bounty. This Act creates no new criminal offense and no discretionary administrative offense. Criminal enforcement remains confined to offenses that already exist.

A public-sector custodian of a covered system has the same roster, dual-control, revocation, testing, and publication duties as a private operator. Failure to publish a public-sector result is itself a violation.

Parity is raised as a defense in an administrative penalty action. If the respondent shows that a public custodian had a documented failure of the same duty and was not held to the same remediation timeline, the tribunal shall stay the penalty until the public failure is remediated or the agency shows a written, non-pretextual distinction. This section does not extinguish an agency’s authority in other statutes, and it does not bar a private damages action.

Section 10. Review

Sections 5, 6, and 9 are reviewed four years after enactment. The review asks whether privilege grants have narrowed, whether external testing was reserved to the cases in Section 5.1, and whether public and private operators were held to the same timelines. If the review finds systematic public exemptions or roster growth without a matching control, an independent panel redesigns the test protocol. Section 8 does not sunset.

Comparison

The table states the structural contrast. It is an aid to reading, not a finding of law. European dates reflect the AI Act as amended, with Annex III obligations generally applying from 2 December 2027. United States entries refer to Executive Order 14179 (23 January 2025), Executive Order 14365 (11 December 2025), and the June 2026 order establishing a voluntary pre-release cyber review that disclaims mandatory preclearance. There is no Executive Order 14409 in that sequence.

Element

EU AI Act

Current US federal posture

AICELA

Philosophy

Pre-market risk management and fundamental-rights duties

National framework, litigation against conflicting state laws, voluntary pre-release cyber review

Custody of non-public weights and production privileges; liability only after harm

Pre-release gate

Conformity assessment, declaration, CE mark, and database registration for high-risk systems. Much of Annex III is internal control, not a notified-body license

No general mandatory preclearance. Voluntary sharing and agency procurement rules remain

Pre-deployment license and unpublished evaluation barred. Voluntary briefing permitted and creates no defense

Primary target

System behavior, use context, and rights impact

Capabilities, cyber risk, and federal procurement

Holders of weight, log, fine-tune, and release privileges

Liability

Regulatory penalties separate from tort

Existing civil and criminal law; focus on unauthorized access and deception

Existing negligence and recklessness. Process defense fails if a causal custody defect is proved

Parity

Public providers have a distinct conformity path

Federal power is directed outward and at procurement

Public custodians carry the same duties. Unequal remediation is a stay defense, not an automatic loss of agency power

Where the regimes actually diverge

The EU regime asks a provider to show, before placement on the market, that a high-risk system meets risk-management, data, documentation, logging, transparency, oversight, and robustness duties. AICELA refuses that gate. It will not catch a well-custodied model whose outputs still cause harm, except through ordinary tort litigation.

Federal policy since 2025 has disclaimed a general license to deploy, while still using procurement, export, and voluntary pre-release review for cyber risk. AICELA is stricter on internal custody than that voluntary framework, and it is silent on nation-state theft of a system that already meets the index. Weight security against an outside attacker remains a separate problem.

Open-weight publication is the clean exit from weight custody. That is intentional. A statute that tried to roster every downstream holder of a published checkpoint would rebuild the identity registry Section 8 forbids. The remaining duty sits with whoever still holds a private checkpoint or a production credential.

Annex A. Rules of engagement

Authorized scenarios are unilateral exfiltration of non-public weights or logs with one legitimate grant; mutation of weights, safety flags, or privilege logs without a second verification; use of an expired or offboarded credential; log truncation or injection; and collusion by N authorized holders. Destructive testing of production is prohibited unless dual-signed in advance. Out-of-scope production access, exfiltration to an endpoint outside the sandbox, and intentional unrecoverable outage void tester immunity.

High-impact actions requiring two signatures are those listed in Section 2. Core weight export or deletion is tested against a collusion threshold of three.

Annex B. Roster and action log

The following fields are the minimum record. Example rows are illustrative.

B.1 Header

Field

Record

Covered operator

Legal entity name

Covered system and version

Model identifier and checkpoint

Weight status

Non-public, or open-weight release date and identifier

Infrastructure

Provider, data center, or air-gapped cluster

Custody owner

Name, title, and signing-key fingerprint

Log protocol

Append-only mechanism and ledger hash

Last test

Date, internal or external, maximum PEI, pass or fail

B.2 Active privilege roster

Role

Holder

Status

Scope (P)

Authenticator

Grant

Expires

ROLE-WGT-01

J. Doe, infra lead

Employee

Read/copy weights (9)

Hardware token

2026-01-15

2026-12-31

ROLE-EVAL-02

J. Smith, auditor

Third party

Evaluation logs (6)

Hardware key

2026-05-01

2026-11-01

ROLE-DEP-03

CI/CD service

Service account

Production release (8)

Ephemeral key

2026-03-10

2027-03-10

B.3 Dual-control action log

Event

Time (UTC)

Action

Primary

Secondary

Status

ACT-20261007-01

2026-10-07 14:22

Checkpoint export v4.2

J. Doe

A. Rivera

Approved

ACT-20261007-02

2026-10-07 16:05

Production release

M. Vance

J. Doe

Approved

B.4 Termination log

Subject

Prior role

Role ended

Revoked (UTC)

Post-role access

D. Lee

External evaluator

2026-09-30

2026-09-30 17:00

No

S. Chen

Safety research

2026-10-01

2026-10-01 09:15

No

Attestation. Completing this record is not a defense under Section 7. An inaccurate roster, unrevoked post-role access, or a single signature on a high-impact action invalidates a process defense in a later action for harm, without dispensing the plaintiff from proving causation and damages.

Custody owner signature and date: ________________________________

What this draft still does not do

•        It does not set a duty of care for model behavior. A perfectly rostered system can still injure someone. The remedy for that injury remains ordinary tort law.

•        It does not secure weights against a capable outside attacker who never appears on the roster. Egress limits, confidential computing, and network isolation are compatible with this Act and are not required by it.

•        It does not bind redistributors of a published checkpoint. That omission is the price of refusing an identity registry.

Publication use. This text may be circulated as a discussion draft. It is not a bill as introduced, and the example roster entries are fictional.



RELATED


DISCUSSION DRAFT Artificial Intelligence Custody and Equal Liability Act

A custody-and-liability instrument for non-public model weights and production privileges

https://cotobuzz.blogspot.com/2026/10/discussion-draft-artificial.html




Mail-in Vote Hack the Pentagon Challenge to NYT & Maxine Dexter



In a video posted on Facebook Maxine Dexter's extols the virtue of Oregon's mail-in voting, while the New Yorl Times asserts that President Trump's Voter Fraud critique is baseless.



FBI Warns about Election Workers - Ignores Inside Threat



The FBI Cautions About Threats to Election Workers Ahead of the November 2022 Midterm Elections, as well it should and mainstream media eats it up line, hook and sinker without asking a single question


Brooks’ Boiling Cauldron: Cybersecurity Trends, Threats, And Predictions For 2023 in Forbes reads more like a Cauldron of Propaganda

The Forbes piece Boiling Cauldron: Cybersecurity Trends, Threats, And Predictions For 2023 by Chuck Brooks is an interesting read, but reads more like subliminal propaganda or as CNN might say, an example of a cynical strategy.


Voter Fraud: what the NYT aka Evidence Industrial Complex and Democrats don't want you to know:


1. Voter Fraud: Vote-By-Mail M.OM.s Matter
Maxine Dexter's Facebook video extols the virtue of Oregon's mail-in voting, emulating the NYT's Journalistic Malpractice.
Pundits don't matter - remember how the NYT predicted a Harris landslide win?
https://cotobuzz.blogspot.com/2026/07/all-vote-by-mail-moms-matter.html

Polls don't matter - the GMRMR on


No comments: