On July 24th, the Massachusetts State Senate passed a major economic development bill, An Act Relative to Economic Development in the Commonwealth, after adding a number of amendments. Its text includes many policy additions and changes, including several which relate to artificial intelligence.
The bill puts in place regulations on so-called frontier models, which are artificial intelligence models whose training required more than a threshold level of computing power. Developers of frontier models who also, along with their affiliates, have annual gross revenues greater than $500 million are required to write and maintain a frontier AI framework that applies to their frontier models and describes in detail how the developer handles catastrophic risks.1
The bill requires the attorney general to establish a reporting mechanism for critical safety incidents2 for use by developers of frontier models and members of the public. Large frontier developers that fail to follow the reporting requirements or their own framework are subject to a civil penalty of a maximum of $1 million for a first violation and a maximum of $3 million for subsequent violations. It also provides whistleblower protections for employees of these developers.
The bill also creates a special commission to make recommendations on the regulation of frontier artificial intelligence models. The commission will review the risks of frontier models, how risk can be measured, practices in other states, and the feasibility of using third party auditors to assess models. The commission is required to report its findings by March 1st, 2027.
Although any regulation is welcome, we should be clear about what this bill does and does not do. It is focused on catastrophic threats from large models created by large developers. Certainly, there should be rules in place to reduce the likelihood of such events and handle them if they occur. This approach is, however, a narrow one. It does not set any rules regarding how personal data is used in training models. It does not put in place any environmental protections to manage the impact of the data centers used by those models. It does not address the effects of exposure to generative artificial intelligence on children nor the consequences of shifting decision-making authority from humans to tools driven by large language models. There are a multitude of issues that don’t necessarily arise from a single catastrophic event but are still hazards that need to be addressed.
The aforementioned gaps in regulation are all the more striking when considering what else the bill does. Embedded in its provisions are multiple streams of funding for artificial intelligence projects. The two most significant are a $75 million program for the development and application of artificial intelligence technologies in various sectors of the state’s economy and a $100 million program for the defense sector which explicitly includes artificial intelligence as one of it’s targets. An additional $1.5 million is provided for the redevelopment of Worcester Memorial Auditorium into an artificial intelligence innovation center and entertainment facility. Public funding of artificial intelligence development should follow the creation of a serious regulatory framework for artificial intelligence. Until that is put in place, any state money being used in this manner is underwriting an unacceptable risk to the residents of Massachusetts.
- A catastrophic risk is defined as “a foreseeable and material risk that a frontier developer’s development, storage, use or deployment of a frontier model will materially contribute to the death of, or serious injury to, not less than 50 people or not less than $1,000,000,000 in damage to, or loss of, property arising from a single incident involving a frontier model that: (i) provides expert-level assistance in the creation or release of a chemical, biological, radiological or nuclear weapon; (ii) engages in conduct with no meaningful human oversight, intervention or supervision that is either a cyberattack or, if the conduct had been committed by a human, would constitute the crime of murder, assault, extortion or theft, including theft by false pretense; or (iii) evades the control of its frontier developer or user; provided, however, that “catastrophic risk” shall not include a foreseeable and material risk from: (A) information that a frontier model outputs if the information is otherwise publicly accessible in a substantially similar form from a source other than a foundation model; (B) lawful activity of the federal government; or (C) harm caused by a frontier model in combination with other software if the frontier model did not materially contribute to the harm.” ↩︎
- A critical safety incident is defined as “(i) unauthorized access to, modification of, inadvertent release of or exfiltration of, the model weights of a frontier model; (ii) harm resulting from the materialization of a catastrophic risk; (iii) loss of control of a frontier model that causes death or bodily injury or that demonstrates materially increased catastrophic risk; or (iv) instance where a frontier model that uses deceptive techniques against the frontier developer to subvert the controls or monitoring of its frontier developer outside of the context of an evaluation designed to elicit this behavior and in a manner that demonstrates materially increased catastrophic risk.” ↩︎
Leave a Reply