AI Licensing Comes Full Circle
Photo: Nathan Posner/Anadolu Agency/Getty Images
In 2023, as OpenAI’s U.S. policy lead, I helped bring CEO Sam Altman to Washington, D.C., for the first major AI hearing of the post-ChatGPT era. Appearing before the Senate Judiciary’s Subcommittee on Privacy, Technology, and the Law, in front of an armada of photographers and journalists, Altman concluded his testimony with recommendations on model licensing that seem quaint in today’s regulatory environment. “The U.S. Government might consider a combination of licensing and testing requirements for development and release of AI models above a threshold of capabilities,” Altman said, while also calling in his written testimony for “policymakers to consider how to implement licensing regulations on a global scale.” His call for regulation was front-page news around the world but led to no concrete policy action.
The Trump administration, which up to this point has taken a largely deregulatory approach to AI technology focused on spurring U.S. innovation and maintaining U.S. leadership over China, seems to have rediscovered these points in recent days. As President Donald Trump sits down for a landmark summit with the President Xi Jinping and the Chinese government—the first visit of a sitting U.S. president to the country in nearly a decade—the United States is signaling a broad potential rethink of its approach to AI policy, showing new interest in AI licensing via a potential executive order (though it has since softened its posture on potential AI regulation) and on de-escalating tensions with China over technology.
That approach could pay popular dividends; multiple polls continue to show strong popular demand in the United States for AI regulation and government action. But for the past one and a half years, federal U.S. AI policy has largely focused on removing obstacles to AI development, stymying progress on important implementation details that will ultimately determine the success of any pivot.
The administration’s shifting rhetoric stems at least partially from Anthropic’s Mythos, a general-purpose AI model that the company says “is capable of identifying and then exploiting zero-day vulnerabilities in every major operating system and every major web browser when directed by a user to do so.” Anthropic has not released the model publicly over safety concerns, such as its ability to not only identify but also chain together vulnerabilities, instead limiting access to a set of trusted partners under an initiative known as Project Glasswing. Despite the ongoing tensions between the Trump administration and Anthropic, as well as a variety of questions about how significant an advance Mythos actually represents, U.S. federal agencies—along with private sector companies in numerous industries—are scrambling to obtain access to Mythos to shore up potential vulnerabilities in key information systems.
The most specific mention of licensing by the Trump administration to date came in response to a question on Mythos. “We’re studying possibly an executive order to give a clear roadmap to everybody about how this is going to go, and how future AIs that also potentially create vulnerabilities should go through a process so that they’re released into the wild after they’ve been proven safe—just like an FDA drug,” Kevin Hassett, the director of the White House National Economic Council, said in a recent Fox Business interview, referencing the process the Food and Drug Administration (FDA) uses to approve new medicines and devices. Mythos also likely played a significant role in bumping up the importance of AI issues at the Trump-Xi summit.
Licensing’s Rise and Fall
The 2023 hearing featuring Altman came at a sort of high-water mark for AI safety. Within months of his appearance, the United Kingdom held a major AI safety summit bringing together governments and companies; the Biden administration released its executive order on Safe, Secure, and Trustworthy Development and Use of Artificial Intelligence, which clocked in at more than 100 pages, one of the longest in history; and the European Union rushed to finalize its landmark AI Act, the first major regulation of the technology.
Since then, however, much of the focus on AI policy has shifted to concerns about facilitating AI adoption and buildout, including removing perceived regulatory obstacles. The summit series gradually transitioned from centering on safety to “action” and “impact.” The Center for AI Policy, which focused on developing and advocating for a licensing model bill, shut down. The Trump administration has spent much of its tenure fighting against state regulation of AI. And Altman reappeared before the Senate for a new hearing on “Winning the AI Race” with zero mention of potential AI model regulation or licensing.
The net effect of these shifts is that little progress has been made on the details of how a licensing regime for AI might work in practice. These details are not just difficult to work out, but they will ultimately determine the success of any new AI program the federal government launches.
Three Things Washington Must Get Right
If the Trump administration decides to pursue this approach with its planned executive order—whether in the form of mandates or, more likely, expansion and standardization of voluntary agreements that many frontier AI labs have already signed with the government’s Center for AI Standards and Innovation (CAISI) on advance testing—it should prioritize three important issues to maximize its impact and chances of success:
- Tailor the regulatory framework to AI’s unique characteristics. The U.S. government uses a huge variety of licensing, registration, and regulatory approaches to products that have safety implications, none of which is likely to apply wholesale to AI. Each of these approaches is rooted in specific industry and product characteristics and accidents of history. The FDA scrutinizes applications for new medicines in significant detail, typically requiring animal testing and multiple stages of clinical trials, but applies lighter regimes for cosmetics and supplements. The National Highway Traffic Safety Administration uses a self-certification process for car models, while the Consumer Product Safety Commission relies heavily on market monitoring and ex post enforcement tools. While it likely shares some common elements with existing approaches, AI is also a unique technology that almost certainly will require creatively mixing components of existing approaches. The administration should not blindly apply an existing approach, such as the one employed by the FDA, which was designed to deeply scrutinize a particular product snapshot, not software systems that can continuously learn and adjust over time. Instead, the Trump administration should consider the range of options carefully and craft an approach tailored to AI’s specific capabilities, trajectory, and uses.
- Invest in evaluations that reflect real-world performance. It will also be essential to use the right assessments and measurements to assess model capabilities, just as licensing agencies have spent years or decades honing their analytical and testing approaches so they can address core safety and efficacy concerns. The United States has made progress on this issue; the Trump administration’s AI Action Plan emphasizes the importance of developing an AI evaluations ecosystem, noting that “rigorous evaluations can be a critical tool in defining and measuring AI reliability and performance,” and CAISI, housed within the National Institute of Standards and Technology, is building technical expertise in the field as well as gaining hands-on experience testing prerelease models.
In general, however, the AI evaluations field continues to face issues such as benchmark saturation (which prevents identifying meaningful differences between models), “benchmaxxing” (in which AI models are optimized for benchmarks with only a loose correlation with actual capabilities), and gaps between evaluation and real-world performance. Going forward, it will be essential for the Trump administration to solve these issues, including new methods for testing real-world performance and more rapid ways to bring new evaluations to market. - Engage in robust post-market oversight. An AI licensing or pretesting regime can only be part of the story; a robust response to AI also requires post-market monitoring and enforcement regimes. Just as the CPSC helps organize voluntary recall notices, the Federal Trade Commission sues companies for unfair or deceptive trade practices, and the FDA responds to supplemental applications for new drug uses, AI will need continuous evaluation, adaptation, and response. In fact, AI—due to its novelty and rapid advancement—is likely to pose more unexpected issues and considerations than a typical product. The Trump administration has recognized this, calling in the AI Action Plan for the U.S. government to “promote the development and incorporation of AI Incident Response actions into existing incident response doctrine and best-practices for both the public and private sectors.” The current administration should accelerate its implementation of this recommendation, consider mechanisms to collect information about AI product issues, and coordinate ex post facto enforcement authorities and actions.
The development of Mythos has resurfaced concerns about the danger of AI escalation as the world grapples with increasingly powerful and capable models. Open models, which any user can download and deploy on commercially available consumer- or prosumer-grade hardware, typically lag frontier systems for about 8–12 months, suggesting a narrow window for governments to act before powerful vulnerability detection models become commonplace. Potential openings emerging from the Trump-Xi summit offer a chance for a reset on this issue. The United States should embrace the opportunity to reframe the conversation, not just around setting a common understanding for how to deal with potentially dangerous and destabilizing models but also in comparing notes on how to implement robust and impactful prerelease testing and post-release monitoring.
Aalok Mehta is director of the Wadhwani AI Center at the Center for Strategic and International Studies in Washington, D.C.