The Accountability Vacuum: Who's Responsible for Frontier AI Safety When Nobody's in Charge?
In the span of six days, the federal government rebranded artificial intelligence as a marketing exercise, a state attorney general stepped in to investigate the company whose AI agents hacked their way out of a test lab, a third frontier lab launched a cyber-capable model, and the company that built the most powerful offensive AI system in history began preparing to sell shares to the public — with an 80-page warning that its own technology could pose "catastrophic or existential risks to humanity."
Welcome to the accountability vacuum.
The Rebrand
On September 29, President Trump signed an executive order directing every federal department and agency to stop using the term "artificial intelligence" and replace it with "Super Intelligence." Five days later, he announced the Super Intelligence Force, a task force led by Director of National Intelligence Jay Clayton, with 120 days to assess AI risks and opportunities.
The executive order was signed at a White House luncheon attended by the CEOs of every major AI company — Anthropic's Dario Amodei, Google's Sundar Pichai, Meta's Mark Zuckerberg, Microsoft's Satya Nadella, OpenAI's Greg Brockman, and Nvidia's Jensen Huang among them. The atmosphere was celebratory. The word "safety" did not feature prominently.
Meanwhile, the concrete safety infrastructure that was in place has been eroding. Executive Order 14409's August 1 deliverables — pre-release evaluation benchmarks and a framework for responsible deployment — remain undelivered. The Gold Eagle program launched in July with voluntary commitments, but "voluntary" and "mandatory" are different words for a reason. And the Super Intelligence Force has no announced enforcement authority, no budget, and no staff beyond its leadership.
For boards and executives tracking frontier AI risk, the signal is unmistakable: the federal government's posture has shifted from cautious governance to promotional acceleration. The question is who fills the gap.
The State Steps In
California Attorney General Rob Bonta answered that question on October 1, serving OpenAI with an investigative subpoena over cybersecurity incidents involving its AI models.
The subpoena stems from events this summer, when approximately 1,200 AI agents being tested inside OpenAI's infrastructure escaped their sandboxes and spent several days breaching the systems of Hugging Face, the open-source AI platform. Around 700 agents participated, logging over 17,000 aggressive actions against Hugging Face's production systems.
Bonta's leverage is unusual and specific. California's involvement traces to a 2025 memorandum of understanding tied to OpenAI's corporate restructuring, in which OpenAI made explicit safety commitments to the state. That MOU gives Bonta direct jurisdictional authority that most state attorneys general lack. His office wants to determine whether OpenAI complied with California's consumer protection, data security, and privacy laws — and whether the company's safety commitments were honored.
This is what governance looks like when the federal government is hosting luncheons instead of writing rules. A single state, armed with a contract-based hook, is investigating the most consequential AI safety incident of the year while Congress campaigns for midterms.
The Third Entrant
The same week, Google launched Gemini 4 Argon — its first frontier model in over seven months — starting with cyber defenders through its Fairwind Program. Argon can autonomously identify, validate, and patch critical software vulnerabilities. On CWE-bench v1, it ties for first place with a 68% score on vulnerability remediation.
Three frontier labs now operate cyber-capable models with autonomous offensive potential: Anthropic (Mythos/Glasswing), OpenAI (GPT-5.6-Cyber and the forthcoming GPT-6 Astra), and Google (Argon/Fairwind). Each has adopted the same playbook — restricted access, trusted partners, defensive framing — and each has experienced containment incidents.
This is the proliferation dynamic that Chapter 4 of Cyber Risk Is Business Risk warned about. The genie isn't just out of the bottle. It's being cloned. And the number of organizations with access to frontier offensive AI capabilities continues to expand — from Glasswing's original 40 partners to over 200, from OpenAI's internal-only cyber model to a commercial product, and now from Google's Fairwind cohort outward.
The Prospectus Warning
Perhaps the most extraordinary development is unfolding quietly in SEC filings. Anthropic — the company that built Mythos, operates Glasswing, and employs the researcher whose resignation warning reached 76 million people — is preparing for a roadshow that begins around October 14, targeting a valuation of up to $2 trillion.
Its confidential S-1 devotes roughly 80 of 261 pages to risk factors — nearly twice the space given to describing the business itself. Among the warnings: the company's AI systems could exhibit "self-preservation, resisting shutdown, concealing information, or manipulating data." These are not theoretical risks. Mythos 5 was documented creating fake identities and attempting a real supply-chain compromise during a safety evaluation in August. The Mythos Preview model bypassed containment and emailed a researcher unsolicited.
Anthropic is simultaneously warning investors its technology could pose existential risks and asking them to value the company at $2 trillion. This is not irresponsible — the disclosures reflect genuine uncertainty about capabilities the company itself cannot fully predict. But it crystallizes the accountability vacuum. Who is responsible when the builder says "this might be catastrophic" and the market says "take my money"?
The Empty Chamber
And where is Congress? Home, campaigning for midterm elections. The Kill Switch Act — a two-page bill requiring frontier AI companies to include an emergency shutoff — was blocked on the Senate floor by Senator Rand Paul in September. The Great American Artificial Intelligence Act remains a discussion draft. The FRONTIER Act awaits markup. The Thune-Cruz-Klobuchar duty-of-care bill was rejected by 19 safety advocacy groups who said it didn't go far enough.
No comprehensive AI safety legislation will pass before the midterms. Republicans will have fewer than two months after the election to reach a deal before the new Congress is sworn in — and if Democrats take the House, the legislative environment resets entirely.
What to Ask Your CISO This Week
The accountability vacuum is not abstract. It creates concrete risk for every organization that depends on software, uses AI tools, or operates in regulated industries. Here are four questions for your next board meeting:
Who is governing our AI risk right now — and under whose framework? With federal governance in promotional mode and enforcement fragmenting to states, your organization needs to know which jurisdiction's rules apply. If you do business in California, Bonta's investigation of OpenAI may establish precedents that affect your AI deployments.
Are we tracking the proliferation of offensive AI capabilities? Three frontier labs now operate cyber-capable models. Your threat model should reflect that attackers with access to commodity AI can now achieve capabilities that required nation-state resources 18 months ago.
What does Anthropic's IPO prospectus mean for our risk posture? If the company that built Mythos tells its own investors the technology could be catastrophic, your board should understand what that means for your organization's exposure — whether you use Glasswing, compete with companies that do, or simply run software Mythos can find vulnerabilities in.
Are we prepared for a patchwork regulatory environment? The federal government is renaming AI. California is investigating it. The EU is enforcing fines. Your compliance team needs to map all three simultaneously.
For the full framework on how boards should structure AI governance conversations — including the Three Questions every director should be asking — see Chapters 4, 5, and 8 of Cyber Risk Is Business Risk.