EFF urges lawmakers to base AI cybersecurity rules on established best practices
Linking AI cybersecurity law to established best practices could reduce lab breaches without stifling innovation.
ADTP Regulatory Watch· September 18, 2026
ImpactModerate 41
Type📋 Proposed Regulation
Statusproposednot law
JurisdictionUS
What happened
The EFF recommends that any new AI cybersecurity legislation focus on proven security measures such as sandboxing, monitoring, and logging to mitigate risks demonstrated by recent AI lab incidents. It calls for minimum safety requirements for high‑risk AI tests and for mandatory, funded independent investigations with public reporting. The guidance stresses flexibility to adapt to evolving technology while anchoring rules in longstanding cybersecurity practices.
Why it matters for trust and compliance
Its status is proposed. It is not law yet. Track it, but do not treat it as an obligation.
Linking AI cybersecurity law to established best practices could reduce lab breaches without stifling innovation.
Who is affected
technologydeveloperdeployerOpenAIHugging FaceEFF
Recommended actions
Check that privacy notices describe the practices this addresses.
Map the security requirements to existing controls and close gaps.
Identify affected vendors and update due-diligence and contract terms.
Inventory AI or automated decision systems in scope and their assessments.
Schedule or refresh the risk or impact assessments this calls for.