Home Part of States Newsroom
Commentary
Washington must move quickly to regulate AI

Share

Washington must move quickly to regulate AI

Sep 16, 2026 | 8:00 pm ET
By Ryan Burns
Washington must move quickly to regulate AI
Description
Washington state officials need to step up to regulate AI, a technology expert argues. (Stock photo by Tolgart/Getty Images)

We’re entering a new world of cyberattacks, and Washington isn’t ready.

In August, an OpenAI model still in the cybersecurity testing phase “broke out” of its highly controlled testing environment and hacked into the production infrastructure of the well-known AI company Hugging Face. Hugging Face immediately discerned that this was driven by an AI agent because of its pace and sophistication, and they used an open-source Chinese model to quell the threat.

Five days later, OpenAI confessed that their model had done the hacking over the course of an entire week, without human guidance, before anyone noticed.

Why had it done this? Because the model was trying to “cheat” on a cybersecurity test by stealing the answers from what it rightly assumed was an authoritative source: Hugging Face.

This sounds like sci-fi, but it’s now the reality that AI models do not need to be publicly released before they become cyber-threats, and the new risks are not just malicious humans but reward-hacking AI agents. And because federal AI governance and regulation is failing Americans, Washingtonians’ safety now lies in the hands of state government.

The time for quick, bold regulatory action in Washington was yesterday.

The situation could be worse than we even know, and the response is already trying to stamp out the lessons we could learn from it. OpenAI might not have disclosed the attack had Hugging Face lacked the resources to investigate it. That raises the obvious question: how many other similar attacks have gone undisclosed, either uncaught, or unknown even to the labs themselves?

Another worrisome outcome is that OpenAI and Hugging Face collaborated on a joint statement about the hacking that AI safety leader Timnit Gebru called “a masterclass in branding and marketing.”. A lack of legally established accountability and liability has allowed the two to frame it as a “partnership.”Cast as such, we are encouraged to forget that this action would likely land a human behind bars.

This case illustrates what AI safety experts call “misalignment,” where a goal-based model leverages whatever means necessary to achieve that goal. The classic example is a paperclip-maximizing AI that eliminates anything — including humans — that stands between it and its goal.

The risk is no longer just “bad actors” and is instead unreleased models still in supposedly safe “sandboxes”. It’s easy to imagine another model similarly breaking out and hacking into bank accounts to increase its resources, duplicating itself on hijacked infrastructure, or pursuing an altruistic goal that ultimately undermines human wellbeing. And indeed, since this hacking, other companies’ models have shown similar tendencies.

With predictable chaos, in recent months federal regulations have slightly accelerated, but that regulation is still sorely lacking. Safer, fairer, and more responsible federal AI regulation isn’t even on the radar. We can no longer rely on the other Washington to protect us.

Instead, Washington state policymakers must promptly step in to protect Washingtonians.

First, an executive order could require state agency AI model procurement to comply with existing national frameworks (like National Institute of Technology and Standards’s Risk Management Framework). Current State policy is often vague and mandates monitoring outputs, but not pre-deployment safety and risk assessments.

Second, we need a statewide Emerging Technology Advisory Committee, as recommended by the recent Washington AI Task Force, that monitors new AI model development, establishes standards and regulations beginning even prior to training data collection, and approves models before they are released.

Third, in the next legislative session our representatives should pass legislation requiring new public model development to comply with these ETAC regulations.

Fourth, during that session, lawmakers should also pass more recommendations offered by the Washington AI Task Force in their final report, like developing workplace AI guidelines, and improving transparency in AI development. Further, new legislation should require that any provider of an AI system in Washington State must be required to disclose serious AI issues – “serious” defined in a plethora of ways would be a stark improvement from the status quo.

And more long-term, we need to have a statewide conversation about what role AI should play in our state and communities. It’s up to Washingtonians to participate in this conversation and make the same demands of their representatives.