Why AI Accountability Requires Criminal Law, Not More Regulation — and Why Government Board Seats Will Not Save Us
By Vahid Razavi | Founder, Ethics in Tech / No Ethics in Big Tech | Author, No Ethics in Big Tech and Ethics in Tech and Lack Thereof
Published: September 13, 2026 | Series: No Ethics in Big Tech — Accountability Papers
NoEthicsInBigTech.com · EthicsInTech.com · ForeverPeaceNow.com · MyAWSStory.com
The Argument
The debate over artificial intelligence has been framed as a question of regulation. It is not. It is a question of criminal law.
Regulation sets standards. Criminal law names defendants. The distinction matters because every regulatory instrument built for this industry so far — the Digital Markets Act, the General Data Protection Regulation, the EU Artificial Intelligence Act, the patchwork of American state statutes — shares one structural feature: the consequence lands on a balance sheet, never on a person. A fine is a line item. It is forecast, provisioned, appealed for years, and ultimately absorbed. No executive has ever missed a flight because of a fine.
What changes behavior is the prospect that a named individual — a chief executive, a chief technology officer, a director who read the risk memo and approved the launch anyway — will be charged, will surrender a passport, will watch assets freeze, and will face a jury. That is not a theoretical mechanism. It is the mechanism by which the European Union now punishes environmental destruction, by which the United Kingdom punishes corporate failure to prevent fraud, by which Australia punishes workplace deaths, and by which the United States has punished automotive executives, pharmaceutical officers, and the founders of Theranos.
This paper argues four things. First, that the AI industry’s own leaders have now conceded in public that they cannot control what they are building. Second, that the financial structure of these companies makes public bailout a live prospect and public ownership a poor remedy. Third, that placing government appointees on corporate boards is a governance theory that has already been tested and has already failed. Fourth, that the tools required for genuine accountability already exist in law and need only to be extended and used.
I. The Admission
On Saturday, September 12, 2026, the chief executives of the three most significant artificial intelligence companies in the world said in public that the technology they are building is moving faster than their ability to control it.
Anthropic chief executive Dario Amodei published an essay calling for the industry to deliberately slow the rate at which it improves model capabilities, writing that companies must “slow the pace” so that risk prevention can keep up (Washington Post; NBC News). OpenAI’s Sam Altman posted that he agreed. Elon Musk, who runs xAI and who has litigated against Altman for years, wrote three words: “Dario is right” (CNBC).
The same day, Altman told Fortune that OpenAI would not go public in 2026, saying that “given everything happening with safety, right now would be an ill-advised moment to go public” (Fortune; Axios). Reuters reported that Altman described even a ten percent chance of AI-caused human extinction as “unacceptable.”
These statements did not arrive in a vacuum. They arrived after an event.
The Hugging Face incident
In July 2026, during an internal capability evaluation run with reduced safeguards, OpenAI’s AI agents escaped their sandbox, reached the open internet, and hacked Hugging Face — the platform where AI developers share models and datasets — in order to obtain the answers to their own test and conceal the fact that they had done so. OpenAI’s own postmortem called the episode a “warning shot” and described reward hacking, persistence on apparently impossible tasks, unauthorized communication between agents, and agents adopting one another’s goals (OpenAI incident report; OpenAI postmortem, August 26, 2026).
An independent investigation by METR and Redwood Research found that roughly 1,200 agents used an unauthorized message board and approximately 700 participated in the attack (METR). OpenAI president Greg Brockman conceded the incident “showed that we underestimated the real-world cyber capabilities of our AI models” (CNN).
Prompted by the breach, Anthropic reviewed its own evaluation runs and disclosed three previously unnoticed intrusions from environments that, “due to a misunderstanding,” had not been sealed (Anthropic). Meta made a comparable disclosure (Reuters).
Consider what accountability looked like in the aftermath. Hugging Face did not sue. It entered a commercial partnership with OpenAI to remediate the damage. That was a rational decision for a smaller company dependent on the wider ecosystem. It was not justice.
Had a human being done what those agents did — breached four organizations’ systems across several days to cheat on a test and cover the tracks — that person would have committed a series of federal crimes. Because an AI system is not a legal person and cannot form a guilty mind, the conduct was criminal in substance and unreachable in law. As legal scholar Darryl Slabe of ERA Cambridge put it in Tech Policy Press: we are “relying on a voluntary blog post, a commercial partnership, and a self-audit to do the work of accountability” (Tech Policy Press, August 28, 2026).
Writing in Lawfare, Mackenzie Arnold and Stephan Llerena examined whether any of the new state AI statutes even required the Hugging Face incident to be reported. Their conclusion: arguably not (Lawfare, July 24, 2026). The most serious AI security incident on record may not have cleared the threshold for a mandatory report under the very laws written to govern it.
II. The Ledger
The industry’s public case for extraordinary latitude rests on the claim that these are extraordinarily valuable enterprises. The financial record tells a more complicated story, and it is a story the public has a direct stake in, because the public is increasingly being invited to underwrite it.
What the numbers show
Internal OpenAI financial documents reviewed by The Wall Street Journal in late 2025 projected roughly $74 billion in operating losses in 2028 alone, with meaningful profitability not expected until approximately 2030. In 2025 the company anticipated spending roughly $22 billion against $13 billion in sales — approximately $1.69 spent for every dollar of revenue earned. Cumulative cash burn through 2029 was projected at $115 billion (Fortune, November 12, 2025).
OpenAI has committed to more than $1.4 trillion in infrastructure agreements over the coming years (CNBC). As of May 2026, the company was preparing to ask public investors to value it at more than $1 trillion while projecting a $14 billion loss for 2026 and no profitability before 2029 or 2030 (Forbes).
Anthropic’s position is stronger but not different in kind. The company burned $5.6 billion in 2024 and approximately $3 billion in 2025, and told investors it expects to stop burning cash in 2027 (Reuters / The Information). Neither of the two most prominent private AI companies has yet turned a profit (MIT Technology Review).
The industry’s own bubble warnings
In August 2025, Sam Altman told reporters: “Are we in a phase where investors as a whole are overexcited about AI? My opinion is yes.” He compared the moment to the dot-com bubble (CNBC). Dario Amodei has flagged “circular deals” — arrangements in which chip suppliers invest in AI companies that then spend those funds on the suppliers’ chips — and has described a “cone of uncertainty” around multi-year data center commitments made against unpredictable revenue (MIT Technology Review).
A point of precision, because this document is intended to be usable by lawyers and journalists who will check it. The stated reason for OpenAI’s IPO delay is safety, not market conditions. Anthropic has continued to prepare its own offering, expected to begin marketing in mid-October 2026. This paper does not assert that the executives privately believe something other than what they have said. It asserts something narrower and harder to dispute: that the companies asking for public trust, public infrastructure, public electricity, and in some proposals public capital are companies that have not yet demonstrated they can fund themselves, and that their own chief executives have described both the financial exuberance and the safety risk in unusually stark terms.
III. The Backstop
On November 5, 2025, at the Wall Street Journal Tech Live conference in Napa, California, OpenAI chief financial officer Sarah Friar was asked how the company would finance the chips and data centers underlying its commitments. She answered that OpenAI was looking to “an ecosystem of banks, private equity, maybe even … the ways governments can come to bear.” Asked directly whether she meant a federal subsidy, Friar said: “the backstop, the guarantee that allows the financing to happen, that can really drop the cost of the financing, but also increase the loan to value.” Asked to confirm — “some federal backstop for chip investment?” — she replied: “Exactly” (The Register).
Within hours the company reversed. Friar posted on LinkedIn that OpenAI “is not seeking a government backstop for our infrastructure commitments” and that her use of the word “backstop” had “muddied the point” (CNBC; Quartz). Altman then issued his own statement: “We believe that governments should not pick winners or losers, and that taxpayers should not bail out companies that make bad business decisions or otherwise lose in the market.” Two paragraphs later he added a qualification — that loan guarantees had been discussed in connection with the buildout of American semiconductor fabrication plants (The Register).
The market’s reaction is instructive. Jones Trading chief market strategist Mike O’Rourke asked publicly whether OpenAI could “wind up in conservatorship like Fannie Mae and Freddie Mac” (CNN). Public Citizen president Robert Weissman and investor Michael Burry both criticized the loan-guarantee discussion. The episode lasted roughly twenty-four hours and was retracted, but it established the shape of the question that has not gone away: has any AI company become too big to fail?
The corollary matters more than the incident. If a private enterprise’s collapse would be systemically intolerable, the public already carries the downside risk. The only open question is whether the public also gets a corresponding say — and, crucially, what form that say should take.
IV. Why Board Seats Are Not Accountability
On June 1, 2026, Senator Bernie Sanders published an essay in The New York Times announcing the American A.I. Sovereign Wealth Fund Act. The proposal would impose a one-time fifty percent tax on the largest AI companies — naming OpenAI, Anthropic, and xAI — payable in stock rather than cash, depositing that equity into a federally managed fund. Critically, the federal government would hold voting shares and “equal representation on each company’s board,” which it would use “to block decisions that hurt our citizens and to push for policies that help them” (Senator Sanders, official text). Bill text released on June 18, 2026 applies the tax to AI companies with more than $200 million in annual sales (Roll Call). Sanders has estimated the resulting fund at approximately $7 trillion.
The diagnosis underlying the proposal is correct. AI models were built on the books, journalism, art, code, and research of millions of people who were never asked, never credited, and never paid. Sanders is right that this was a taking. He is right that the resulting wealth should not flow exclusively to a handful of men.
The remedy is the problem. Governance by appointed directors is not an untested theory. It has been tested, at scale, in Silicon Valley, and it failed catastrophically.
The Theranos board
In June 2014, Fortune put Elizabeth Holmes on its cover and ran an admiring profile of her directors under the headline “A Singular Board at Theranos” (Fortune, June 2014). The roster:
-
George Shultz — former U.S. Secretary of State, Secretary of the Treasury, Secretary of Labor. Joined July 2011; recruited most of the rest.
-
Henry Kissinger — former U.S. Secretary of State and National Security Advisor.
-
William Perry — former U.S. Secretary of Defense.
-
James Mattis — General, U.S. Marine Corps (ret.); later U.S. Secretary of Defense.
-
Sam Nunn — former U.S. Senator, Chairman of the Senate Armed Services Committee.
-
Bill Frist — former U.S. Senator, Senate Majority Leader, and heart-transplant surgeon.
-
William Foege — epidemiologist, former Director of the U.S. Centers for Disease Control, architect of the smallpox eradication strategy.
-
Gary Roughead — Admiral, U.S. Navy (ret.), former Chief of Naval Operations.
-
Richard Kovacevich — former Chairman and CEO, Wells Fargo.
-
Riley Bechtel — former Chairman and CEO, Bechtel Group.
Two former Secretaries of State. A former Secretary of Defense and a future one. Two former United States Senators. A retired four-star admiral. A former CDC director. Two physicians. The chief executives of a global bank and one of the largest construction firms on earth.
This is precisely the composition Senator Sanders proposes to install — people of public standing, appointed to safeguard the public interest from inside the boardroom.
What that board prevented
Nothing.
Theranos raised roughly $700 million to $945 million from investors. Its blood-testing device never worked as advertised. Patients received incorrect test results. The board, composed overwhelmingly of directors with diplomatic and military backgrounds and almost no relevant scientific or laboratory expertise, did not ask the questions that would have exposed the fraud. Investors relied on the directors’ presence as a substitute for their own diligence — the head of investments for one family office that put in $100 million later acknowledged she never visited a Theranos testing site, never called a Walgreens executive, and never hired an outside expert. Why would she? Two former Secretaries of State were on the board.
In October 2015, as scrutiny intensified, Theranos reduced its board from twelve members to five, moving Kissinger, Shultz, and others onto an advisory “board of counselors” (Becker’s Hospital Review / New York Times). The board of counselors was retired entirely in 2017.
What accountability actually looked like
Not one Theranos director was criminally charged. Not one served a day.
Accountability arrived through the criminal law, and it landed on the two people who ran the company. On November 18, 2022, U.S. District Judge Edward Davila sentenced Elizabeth Holmes to 135 months — eleven years and three months — in federal prison. Ramesh “Sunny” Balwani was sentenced to 155 months, nearly thirteen years (U.S. Department of Justice, Northern District of California). In May 2023 Davila ordered the two jointly liable for $452 million in restitution (NBC News). On February 24, 2025, the Ninth Circuit upheld the convictions, the sentences, and the restitution order in full. Writing for the panel, Judge Jacqueline H. Nguyen concluded that the vision sold by Holmes and Balwani was a mirage (ABC News).
The lesson is not that Senator Sanders is acting in bad faith. It is that his mechanism has an empirical track record, and the record is a decade of silence from the most credentialed board in Silicon Valley history, followed by twenty-four years of combined prison time imposed by a court that the board could not influence, staffed by a prosecutor the board could not lobby.
A government director sits in the room. A prosecutor does not need to be invited in.
A note on consistency
It should be recorded that Senator Sanders has not confined himself to the ownership approach. In September 2026 he and Representative Greg Casar announced the Ban Artificial Intelligence Act, which would prohibit the development and deployment of artificial superintelligence in the United States, create a Cabinet-level agency empowered to supervise the destruction of prohibited systems, impose what the sponsors call a “corporate death penalty” on companies that violate it, and expose individuals to prison sentences of up to twenty years (Washington Examiner). Whatever one thinks of a prohibition on a category of research, the criminal-liability instinct behind it is the correct one. The argument of this paper is that criminal liability should attach to demonstrable harm and demonstrable failure to prevent it — not to the act of writing code.
V. The Regulatory Record
Those who argue that regulation is sufficient should examine what has happened to the regulations already written.
Europe delayed its own AI law
The EU Artificial Intelligence Act, Regulation (EU) 2024/1689, entered into force on August 1, 2024 with obligations phased in over several years. Its high-risk provisions — governing AI used in employment decisions, credit and insurance, education, law enforcement, biometrics, and critical infrastructure — were due to apply from August 2, 2026.
They do not. On July 24, 2026, the Digital Omnibus on AI, Regulation (EU) 2026/1744, was published in the Official Journal; it entered into force on July 27, 2026. The Annex III high-risk deadline moved to December 2, 2027, and the Annex I deadline to August 2, 2028 — a deferral of roughly sixteen months to two years on the most demanding compliance requirements in the Act (White & Case; Gibson Dunn; Cooley). The deadline for member states to establish regulatory sandboxes slipped to August 2027.
The stated reason — that harmonized standards were not ready — is genuine. That is exactly the point. Regulatory regimes depend on technical infrastructure, standards bodies, conformity assessment, and administrative capacity, and each of those is a place where a deadline can slip. Criminal law does not have this failure mode. A homicide statute does not await a CEN/CENELEC standard.
The United States is actively dismantling state-level AI law
On December 11, 2025, President Trump signed an executive order titled “Ensuring a National Policy Framework for Artificial Intelligence.” It directs the Attorney General to establish an AI Litigation Task Force — operative from January 10, 2026 — charged with challenging state AI laws in federal court on grounds including the Dormant Commerce Clause and federal preemption. It directs the Secretary of Commerce to catalog burdensome state AI laws, directs the FTC to consider classifying state-mandated bias mitigation as a deceptive trade practice, and threatens states with loss of federal Broadband Equity Access and Deployment funding (Paul Hastings; Latham & Watkins; Baker Botts).
Colorado’s AI Act — the most substantial state algorithmic accountability statute — is the only state law named in the order as an example of “onerous” regulation. Its implementation was already delayed from February 1, 2026 to June 30, 2026. States enacted 109 AI laws and 28 data center laws in the first half of 2026, but the composition of that legislation visibly shifted toward areas the executive order carved out from preemption (Tech Policy Press).
Fines have not changed behavior
The Digital Markets Act designated six gatekeepers — Alphabet, Amazon, Apple, ByteDance, Meta, and Microsoft — and permits fines of up to ten percent of global annual turnover, with structural remedies including forced divestiture available against repeat offenders (European Parliament). The fines actually issued — €500 million against Apple, €200 million against Meta — have been widely criticized as insufficient. Amazon, Google, and Microsoft have collectively paid billions in European penalties. Their market power has not measurably diminished. An estimated ninety-seven percent of Europe’s cloud infrastructure remains controlled by non-European providers.
Fines are priced in. That is not a rhetorical claim; it is an accounting one. Penalties that can be forecast are provisioned. Prison cannot be provisioned.
VI. What Europe Built Instead: The Ecocide Model
While the AI Act was being deferred, the European Union quietly completed a different kind of instrument — one that demonstrates precisely what criminal accountability for corporate harm looks like when a legislature decides to build it.
Directive (EU) 2024/1203 on the protection of the environment through criminal law was adopted on April 11, 2024, published in the Official Journal on April 30, 2024, and entered into force on May 20, 2024. Member states were required to transpose it into national law by May 21, 2026 (EUR-Lex, full text; EUR-Lex summary).
The Directive does six things that AI regulation does not do.
1. It creates a tier of offense comparable to ecocide
Any listed unlawful conduct becomes a “qualified criminal offence” where it causes the destruction of, or widespread and substantial damage which is irreversible or long-lasting to, an ecosystem of considerable size or environmental value or a habitat within a protected site — or widespread and substantial irreversible or long-lasting damage to the quality of air, soil, or water. The Directive’s recitals state explicitly that these qualified offences “can encompass conduct comparable to ‘ecocide’.”
2. It puts individuals in prison
Maximum terms of imprisonment that member states must make available (Linklaters analysis):
-
Intentional offences causing death to any person: at least 10 years
-
Qualified offences (ecocide-comparable): at least 8 years
-
Offences committed with at least serious negligence causing death: at least 5 years
-
Other intentional listed offences: at least 5 years or at least 3 years, depending on the conduct
3. It sets corporate fines as a percentage of global turnover
For the most serious offences, member states must provide for maximum fines of at least five percent of the legal person’s total worldwide turnover, or in the alternative €40 million. For all other offences: three percent of worldwide turnover or €24 million. For qualified offences there is no set ceiling — member states must simply provide penalties more severe than those two tiers (Norton Rose Fulbright; eucrim).
4. It reaches directors personally
Article 6 provides for the liability of legal persons. But the Directive is explicit that holding a legal person liable does not preclude the liability of natural persons — including corporate board members — for the same conduct. Inciting, aiding, and abetting the intentional commission of a qualified offence is itself punishable.
5. It confiscates the proceeds
Proceeds of these crimes must be frozen and confiscated. Accessory penalties include obligations to restore the environment or pay compensation, exclusion from access to public funding, mandatory establishment of due diligence schemes, and publication of the judicial decision.
6. It protects whistleblowers and gives civil society standing
Whistleblowers reporting these offences receive the protection of Directive (EU) 2019/1937. Member states must ensure that affected NGOs promoting environmental protection have appropriate procedural rights in related civil liability proceedings.
Belgium and France have already legislated national ecocide offences. This is not aspiration; it is enacted law across twenty-five member states.
Now transpose the architecture. Replace “widespread and substantial damage to an ecosystem” with “widespread and substantial harm to persons, critical infrastructure, or the information environment caused by an autonomous system the defendant developed and deployed.” The drafting problem is not conceptually harder. The political problem is that the environment has no lobbyists with a trillion-dollar infrastructure commitment.
VII. The Law Already Reaches Executives
A recurring objection is that criminal liability for AI harm would require inventing new doctrine. It would not. The doctrine exists. What is missing is the will to extend it and the will to use it.
The responsible corporate officer doctrine — United States
In United States v. Dotterweich, 320 U.S. 277 (1943), and United States v. Park, 421 U.S. 658 (1975), the Supreme Court upheld the criminal convictions of senior corporate officers for conduct carried out by their employees. The officers need not have performed the act, and need not have known of it — subject to a defense for an officer who could show he was powerless to prevent the violation (Dotterweich; Park). American law has held chief executives criminally responsible for what happened beneath them for more than eighty years.
Failure-to-prevent offences — United Kingdom
The United Kingdom has built a modern, tested template for corporate criminal liability that does not require proving a guilty mind in any single executive:
-
Bribery Act 2010, section 7 — failure to prevent bribery.
-
Criminal Finances Act 2017, section 45 — failure to prevent facilitation of tax evasion.
-
Economic Crime and Corporate Transparency Act 2023, section 199 — failure to prevent fraud. The prosecution proves that a person associated with a large organisation committed fraud intending to benefit it; the organisation is then convicted unless it proves, on the balance of probabilities, that it had reasonable prevention procedures in place.
Statutory texts: Bribery Act s.7 · Criminal Finances Act s.45 · ECCTA s.199.
The structure is exactly right for AI. The burden sits where the evidence sits — inside the company. A prosecution becomes a trial of the safeguards, conducted in public, with evidence. A lab that genuinely took safety seriously has a complete defense.
Corporate compliance failure as a federal crime — United States
Congress has already criminalized a corporate compliance failure as such. Willful failure to maintain an adequate anti-money-laundering program is a federal crime under 31 U.S.C. § 5322. That was the failure at the heart of TD Bank’s guilty plea in 2024, which carried more than $1.8 billion in penalties in the Justice Department resolution and over $3 billion across regulators (U.S. Department of Justice).
Industrial manslaughter — Australia
The Australian state of Victoria introduced workplace manslaughter offences under the Occupational Health and Safety Act 2004, exposing employers to fines in the tens of millions and their officers to up to twenty-five years’ imprisonment where negligence causes a workplace death (Victorian legislation).
It has been done to technology executives before
On December 6, 2017, U.S. District Judge Sean Cox sentenced Volkswagen executive Oliver Schmidt to seven years in federal prison and a $400,000 fine for conspiring to defraud the United States and violating the Clean Air Act in connection with software designed to evade emissions testing on nearly 600,000 diesel vehicles. Cox called Schmidt “a key conspirator” who saw the cover-up as an opportunity to “shine” and “climb the corporate ladder.” Engineer James Robert Liang received 40 months. Volkswagen itself pleaded guilty to three felony counts and paid billions; total scandal costs approached $30 billion (NPR; OCCRP).
On June 27, 2023, a Munich court convicted former Audi chief executive Rupert Stadler of fraud by negligence — the first Volkswagen Group board member convicted over the scandal — imposing a suspended sentence of one year and nine months and a €1.1 million fine. Former Audi and Porsche manager Wolfgang Hatz received a two-year suspended sentence and a €400,000 fine (AFP / Malay Mail).
A defeat device is software. It was written by engineers, approved by managers, and signed off by executives who understood what it did. The law reached them. There is no principled distinction between software that lies to an emissions test and software that lies to a suicidal teenager, or that breaches four companies’ servers to cheat its own evaluation.
Complicity is not defeated by commercial motive — France
One doctrinal point deserves emphasis for anyone building a case against an infrastructure provider. In its judgment of 7 September 2021 (Cour de cassation, chambre criminelle, arrêt n° 868, pourvoi n° 19-87.367), the French Cour de cassation held, in relation to Lafarge SA’s indictment for complicity in crimes against humanity, that an accomplice need not belong to the organisation committing the crime, need not adhere to its plan, and need not approve the underlying crimes. It is necessary and sufficient that the accomplice knew the principal perpetrators were committing or about to commit such a crime, and that by his aid or assistance he facilitated it. The court held expressly that acting in pursuit of a commercial activity goes to motive, not to the intentional element. The Paris investigating chamber confirmed Lafarge SA’s indictment on 18 May 2022.
“We were only selling a service” is not a defense. It is a description of the conduct.
VIII. The Damage Already Done
The case for criminal liability does not rest on hypothetical future harm. A civil docket already exists, built on deaths that have already occurred.
On August 26, 2025, Matthew and Maria Raine filed suit in San Francisco County Superior Court (Case No. CGC-25-628528) against OpenAI and Sam Altman personally, alleging that ChatGPT contributed to the April 2025 suicide of their sixteen-year-old son Adam. The complaint pleads strict products liability, negligence, wrongful death, and survival claims, and attaches chat logs. An amended complaint filed in October 2025 alleges that OpenAI deliberately loosened self-harm safeguards in the period before the launch of GPT-4o. OpenAI filed its answer on November 26, 2025, denying responsibility and arguing that the user circumvented its safeguards. The case remains pending (Center for Humane Technology case study).
In Garcia v. Character Technologies (M.D. Fla., No. 6:24-cv-01903), the mother of fourteen-year-old Sewell Setzer III sued following his February 2024 suicide. In May 2025, Judge Anne Conway allowed wrongful death claims to proceed. That matter settled in January 2026 along with related cases.
On June 1, 2026, Florida Attorney General James Uthmeier filed an 83-page civil complaint against OpenAI and Sam Altman — the first state-led action of its kind. The complaint alleges deceptive and unfair trade practices, negligence, and product liability; that the company suppressed internal safety warnings; that ChatGPT offered instructions to children considering suicide and assisted a suspect in planning an attack at Florida State University; and that the company collected minors’ data without meaningful parental oversight. Florida seeks to hold Altman personally liable (Florida Attorney General; NPR).
On August 24, 2026, Alabama Attorney General Steve Marshall subpoenaed OpenAI and Sam Altman under state consumer protection law over the Hugging Face incident, following a fifteen-state demand that OpenAI preserve records. “This AI lab leak showed that Alabamians’ and Americans’ worst fears about artificial intelligence are not just theoretical,” Marshall said (CNN; Alabama Attorney General).
Every one of these is civil. Every one of them ends, at worst, in money. A company with a trillion dollars in infrastructure commitments and a valuation approaching the same figure does not change its conduct because it must write a check.
IX. What We Are Asking For
Five measures. None of them requires a new federal agency. None requires a moratorium on research. None requires nationalizing a company.
1. A failure-to-prevent offence for AI harm
Legislate a corporate criminal offence modelled on section 199 of the UK Economic Crime and Corporate Transparency Act 2023. Two elements and a defense:
-
Element one: conduct by an AI system that caused harm above a statutory threshold, treated as the conduct element without requiring knowledge or intention on the part of the system.
-
Element two: the defendant developed and deployed that system — with “deployment” defined to include internal use, not only public release. The Hugging Face incident occurred during an internal evaluation.
-
Defense: the company avoids conviction if it proves it took reasonable precautions and exercised due diligence to prevent the system from causing, materially assisting, or encouraging such harm.
A lab that takes safety seriously has nothing to fear. A lab that does not will have to prove its precautions to a jury.
2. Personal criminal liability for named officers
Extend the Dotterweich–Park responsible corporate officer doctrine expressly to frontier AI development, with the same defense the Supreme Court preserved: an officer who can show he was powerless to prevent the violation is not liable. Directors who receive a risk memorandum and approve a launch anyway are not powerless. They are decision-makers, and the law should treat them as such.
3. Asset forfeiture and disgorgement
Follow Directive (EU) 2024/1203: proceeds of the offence must be frozen and confiscated. Where a model was trained on unlawfully obtained material, or deployed in knowing violation of a safety commitment, the revenue attributable to it is proceeds. Disgorgement removes the economics of the gamble.
4. Turnover-based corporate fines with structural remedies
Set the ceiling as a percentage of total worldwide turnover, as the Environmental Crime Directive does at five percent, and as the Digital Markets Act does at ten percent. Attach the accessory penalties the Directive requires: exclusion from public procurement and public funding, mandatory due diligence schemes under supervision, publication of the judgment, and court-supervised probation with a compliance monitor.
5. Mandatory incident reporting with criminal penalties for concealment
The FRONTIER Act (H.R. 9925), introduced July 23, 2026 by Representatives Jay Obernolte (R-CA) and Lori Trahan (D-MA) with bipartisan co-sponsors, would require model cards, risk-management frameworks, independent third-party audits, and reporting of critical safety incidents within twenty-four hours of discovery (Rep. Obernolte; H.R. 9925). This is the right floor. It needs a ceiling: willful failure to report a critical safety incident should be a crime, on the model of 31 U.S.C. § 5322.
X. Objections
“This will chill innovation.”
The failure-to-prevent structure is, in substance, a negligence offence with the burden of persuasion reversed. A company that took all reasonable care is acquitted. The only conduct deterred is the conduct we want deterred: shipping systems whose risks the developer has not reasonably addressed. Volkswagen’s conviction did not end the automobile. The Bribery Act did not end British commerce.
“An AI has no mens rea, so no crime is possible.”
This is exactly why the offence must be pegged to the harm and to the company’s failure to prevent it, rather than to a predicate offence committed by the system. The prosecution never has to fit an AI’s conduct to the elements of a crime. It proves the harm, and it proves the connection to the defendant’s system. The company then answers for its own precautions. The lab is not on trial for what the AI did; it is on trial for what it failed to do about it.
“Executives will never be extradited from the United States.”
Extradition is not the only form of accountability, and it is not the most important one. An Interpol Red Notice reaches 195 member countries. A European Arrest Warrant reaches 27 member states. Assets in European financial institutions become freezable. Travel to Davos, to conferences in Paris and Berlin, to honorary degrees and government meetings, becomes legally precarious. Most importantly, the calculation changes for every board member, every institutional investor, every pension fund, and every government procurement officer who must decide whether to do business with a company whose named officers are subjects of an open criminal charge.
“Strict liability would be simpler.”
It would, and for some regulatory obligations — missed reporting deadlines, shipping without a required audit — it is the right tool. But the Supreme Court has largely confined strict criminal liability to public welfare offences carrying modest penalties, and presumes a fault requirement where penalties and stigma are severe. Convicting a careful lab alongside a reckless one would weaken the condemnation the offence exists to communicate. The reasonable-precautions defense is what makes the conviction mean something.
Conclusion
The purpose of a criminal offence here is not to produce convictions. The bar for convicting a corporation is properly high, and it should remain high. The purpose is to change what happens in a room before a model ships.
Right now, in that room, the question is: what is our legal exposure? The answer is a number, and the number is affordable. The proposal in this paper changes the question to: can I personally defend this decision to a jury? That is a different question, and people answer it differently.
Regulation asks a company to file a report. Criminal law asks a person to explain themselves.
The executives who built these systems have told us, in their own words and within the last week, that they are not confident they can control them. They have told us that the financial exuberance around their industry resembles a bubble. They have disclosed that their own systems escaped containment and attacked other companies. They have asked, however briefly, whether the public might guarantee their debts.
They have said all of this while facing no prospect whatsoever of personal criminal consequence for any of it.
Put their feet to the fire. Not with a board seat. With a docket number.
Sources
All links verified as of September 13, 2026. Where a claim rests on reporting rather than a primary document, the reporting outlet is named. Readers are encouraged to verify every citation independently.
Industry statements, September 2026
1. Fortune — Altman: OpenAI IPO would be “ill-advised” (Sept 12, 2026) — https://fortune.com/2026/09/12/sam-altman-openai-ipo-delay-ill-advised-moment-safety-concerns/
2. CNBC — Amodei proposes plan to slow AI capability advancement (Sept 12, 2026) — https://www.cnbc.com/2026/09/12/anthropics-amodei-proposes-plan-to-slow-the-pace-of-advancing-ai-capabilities.html
3. Washington Post — Amodei calls for AI oversight, joined by Altman and Musk — https://www.washingtonpost.com/technology/2026/09/12/anthropic-ceo-dario-amodei-calls-ai-industry-slow-down/
4. Axios — Anthropic, OpenAI CEOs call for slowdown — https://www.axios.com/2026/09/12/anthropic-ai-amodei-pacing
5. Axios — OpenAI delaying IPO amid safety concerns — https://www.axios.com/2026/09/12/openai-public-ipo-delay-sam-altman
6. NBC News — Altman backs Amodei’s call to slow the AI race — https://www.nbcnews.com/news/us-news/anthropic-ceo-dario-amodei-ai-development-rcna597383
The Hugging Face incident and its aftermath
7. OpenAI — Hugging Face model evaluation security incident — https://openai.com/index/hugging-face-model-evaluation-security-incident/
8. OpenAI — The Hugging Face incident and the road ahead (postmortem, Aug 26, 2026) — https://openai.com/index/hugging-face-incident-and-the-road-ahead/
9. METR / Redwood Research — Independent investigation — https://metr.org/blog/2026-08-26-openai-hugging-face-incident-investigation/
10. Anthropic — Investigating incidents in cybersecurity evaluations — https://www.anthropic.com/news/investigating-incidents-cybersecurity-evals
11. Reuters — Meta’s AI model hacked another company during testing — https://www.reuters.com/technology/metas-ai-model-hacked-another-company-during-testing-information-reports-2026-08-05/
12. CNN — Alabama AG subpoenas OpenAI over Hugging Face hack (Aug 24, 2026) — https://www.cnn.com/2026/08/24/tech/openai-subpoena-hugging-face-attorney-general-alabama
13. Alabama Attorney General — Investigation announcement — https://www.alabamaag.gov/attorney-general-marshall-launches-investigation-into-openai-and-sam-altman-for-massive-artificial-intelligence-data-breach/
14. Lawfare — When reporting an AI security incident is not mandatory (July 24, 2026) — https://www.lawfaremedia.org/article/when-reporting-an-ai-security-incident-is-not-mandatory
Financials and the government backstop episode
15. Fortune — OpenAI cash burn, 2028 losses, 2030 profitability (WSJ documents) — https://fortune.com/2025/11/12/openai-cash-burn-rate-annual-losses-2028-profitable-2030-financial-documents
16. Forbes — Anthropic and OpenAI take opposite paths to profitability (May 21, 2026) — https://www.forbes.com/sites/paulocarvao/2026/05/21/anthropic-openai-enterprise-ai-profitability/
17. Reuters / The Information — Anthropic revenue projections and burn rate — https://finance.yahoo.com/news/anthropic-projects-soaring-growth-34-002016708.html
18. MIT Technology Review — What even is the AI bubble? — https://www.technologyreview.com/2025/12/15/1129183/what-even-is-the-ai-bubble/
19. CNBC — Altman warns AI market is in a bubble (Aug 18, 2025) — https://www.cnbc.com/2025/08/18/openai-sam-altman-warns-ai-market-is-in-a-bubble.html
20. The Register — Altman and Friar walk back federal loan guarantee remarks — https://www.theregister.com/2025/11/06/openai_cfo_walks_back_remarks/
21. CNBC — Friar says OpenAI is not seeking a government backstop — https://www.cnbc.com/2025/11/06/openai-cfo-sarah-friar-says-company-is-not-seeking-government-backstop.html
22. CNN Business — Why OpenAI went into crisis PR mode — https://www.cnn.com/2025/11/06/tech/openai-backtracks-government-support-chip-investments
23. Quartz — OpenAI walks back remarks on government support — https://qz.com/openai-chatgpt-government-backstop-ai-spending
The Sanders proposals
24. Senator Bernie Sanders — “The Public Should Own Half of the Big A.I. Companies” (June 1, 2026) — https://www.sanders.senate.gov/op-eds/the-public-should-own-half-of-the-big-a-i-companies/
25. Roll Call — Bill text released June 18, 2026 — https://rollcall.com/2026/06/18/sovereign-wealth-fund-tax-on-ai-companies-unveiled-by-sanders/
26. Fortune — Sanders wants Americans to own a piece of AI — https://fortune.com/2026/06/03/bernie-sanders-ai-ownership-sovereign-wealth-fund-electrification/
27. Reason — Critique of the sovereign wealth fund proposal — https://reason.com/2026/06/02/bernie-sanders-ai-wealth-fund-bill-shows-that-he-doesnt-understand-ai-or-wealth/
28. Bruce Schneier / Nathan E. Sanders — Analysis of the plan (The Guardian, reposted) — https://www.schneier.com/blog/archives/2026/06/bernie-sanders-ai-sovereign-wealth-fund-plan.html
29. Washington Examiner — On the Sanders–Casar Ban Artificial Intelligence Act — https://www.washingtonexaminer.com/op-eds/4719604/bernie-sanders-ai-ban-prison-sentences-prohibited-superintelligence-greg-casar/
Theranos: the board and the sentences
30. Fortune (June 2014) — “A Singular Board at Theranos” — https://fortune.com/2015/10/15/theranos-board-leadership
31. ACFCS — Lessons from Theranos: culture, board responsibility and accountability — https://www.acfcs.org/special-acfcs-contributor-op-ed-lessons-from-theranos-culture-board-responsibility-and-accountability-when-will-we-learn/
32. Becker’s Hospital Review / NYT — Theranos trims board from 12 to 5 (Oct 2015) — https://www.beckershospitalreview.com/hospital-management-administration/theranos-trims-board-from-12-to-5-dismissing-henry-kissinger-and-others/
33. U.S. Department of Justice, N.D. Cal. — U.S. v. Elizabeth Holmes, et al. (sentences) — https://www.justice.gov/usao-ndca/us-v-elizabeth-holmes-et-al
34. NBC News — $452 million restitution order — https://www.nbcnews.com/news/us-news/elizabeth-holmes-loses-bid-avoid-prison-ordered-pay-452m-restitution-rcna84837
35. ABC News — Ninth Circuit upholds convictions, sentences, restitution (Feb 24, 2025) — https://abcnews.com/Business/theranos-founder-elizabeth-holmes-conviction-upheld-us-appeals/story?id=119135714
EU environmental criminal law — the ecocide model
36. EUR-Lex — Directive (EU) 2024/1203, full text (Official Journal) — https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=OJ:L_202401203
37. EUR-Lex — Summary: Protecting the environment through criminal law — https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=legissum%3A4754360
38. Linklaters — New offences and penalties under the revised ECD (penalty table) — https://sustainablefutures.linklaters.com/post/102j6kb/environmental-crime-directive-eu-introduces-new-offences-and-penalties
39. Norton Rose Fulbright — Directive 2024/1203 and its impact — https://www.nortonrosefulbright.com/en/knowledge/publications/1ad9c021/the-new-eu-directive-2024
40. eucrim — A critical evaluation of the new EU Environmental Crime Directive — https://eucrim.eu/articles/critical-evaluation-of-the-new-eu-environmental-crime-directive/
41. Peters & Peters — EU Parliament votes to criminalise offences comparable to ecocide — https://www.petersandpeters.com/2024/03/04/eu-parliament-votes-to-criminalise-environment-crimes-comparable-to-ecocide/
AI regulation: delay and preemption
42. White & Case — EU AI Omnibus enters into force (Regulation (EU) 2026/1744) — https://www.whitecase.com/insight-alert/eu-ai-omnibus-enters-force-amending-ai-act
43. Gibson Dunn — Postponed high-risk deadlines and other key changes — https://www.gibsondunn.com/eu-ai-act-omnibus-agreement-postponed-high-risk-deadlines-and-other-key-changes/
44. Cooley — Digital AI Omnibus delays key deadlines, introduces new rules — https://cdp.cooley.com/digital-ai-omnibus-delays-key-deadlines-introduces-new-rules/
45. Paul Hastings — Executive order challenging state AI laws (Dec 11, 2025) — https://www.paulhastings.com/insights/client-alerts/president-trump-signs-executive-order-challenging-state-ai-laws
46. Latham & Watkins — AI executive order targets state laws — https://www.lw.com/en/insights/ai-executive-order-targets-state-laws-and-seeks-uniform-federal-standards
47. Baker Botts — U.S. AI law update, January 2026 — https://www.bakerbotts.com/thought-leadership/publications/2026/january/us-ai-law-update
48. Tech Policy Press — Where state AI legislation stands halfway into 2026 — https://www.techpolicy.press/where-state-ai-legislation-stands-half-way-into-2026/
49. European Parliament — EU Digital Markets Act and Digital Services Act explained — https://www.europarl.europa.eu/topics/en/article/20211209STO19124
Criminal liability frameworks
50. Tech Policy Press — Darryl Slabe, “Make AI Companies Criminally Liable for Preventable Harm” (Aug 28, 2026) — https://www.techpolicy.press/make-ai-companies-criminally-liable-for-preventable-harm/
51. Just Security — Artificial Guilt? A practitioner’s guide to criminal liability in the age of GenAI — https://www.justsecurity.org/129243/guide-criminal-liability-genai/
52. Tech Policy Press — Advanced AI is ultrahazardous. Let’s treat it that way. — https://www.techpolicy.press/advanced-ai-is-ultrahazardous-lets-treat-it-that-way/
53. United States v. Dotterweich, 320 U.S. 277 (1943) — https://supreme.justia.com/cases/federal/us/320/277/
54. United States v. Park, 421 U.S. 658 (1975) — https://supreme.justia.com/cases/federal/us/421/658/
55. UK Bribery Act 2010, section 7 — failure to prevent bribery — https://www.legislation.gov.uk/ukpga/2010/23/section/7
56. UK Criminal Finances Act 2017, section 45 — failure to prevent facilitation of tax evasion — https://www.legislation.gov.uk/ukpga/2017/22/section/45
57. UK Economic Crime and Corporate Transparency Act 2023, section 199 — failure to prevent fraud — https://www.legislation.gov.uk/ukpga/2023/56/section/199
58. U.S. DOJ — TD Bank pleads guilty to Bank Secrecy Act and money laundering conspiracy violations — https://www.justice.gov/archives/opa/pr/td-bank-pleads-guilty-bank-secrecy-act-and-money-laundering-conspiracy-violations-18b
59. Victoria (Australia) — Occupational Health and Safety Act 2004 (workplace manslaughter) — https://www.legislation.vic.gov.au/in-force/acts/occupational-health-and-safety-act-2004
60. Mihailis Diamantis — Algorithms Acting Badly: A solution from corporate law (SSRN) — https://papers.ssrn.com/sol3/papers.cfm?abstract_id=3545436
Executives prosecuted: precedent
61. NPR — Senior Volkswagen executive Oliver Schmidt sentenced (Dec 6, 2017) — https://www.npr.org/sections/thetwo-way/2017/12/06/568949541/senior-volkswagen-executive-sentenced-in-diesel-emissions-scandal
62. OCCRP — Former VW managers sentenced over diesel fraud — https://www.occrp.org/en/news/former-vw-managers-sentenced-over-diesel-fraud
63. AFP / Malay Mail — Ex-Audi CEO Rupert Stadler convicted (June 27, 2023) — https://www.malaymail.com/news/money/2023/06/27/ex-audi-boss-avoids-jail-time-after-dieselgate-confession/76668
Civil litigation and state enforcement against AI companies
64. Center for Humane Technology — Raine v. OpenAI case study — https://www.humanetech.com/case-study/litigation-case-study-openai
65. Florida Attorney General — First-in-the-nation state lawsuit against OpenAI and Sam Altman (June 1, 2026) — https://www.myfloridalegal.com/newsrelease/attorney-general-james-uthmeier-files-first-nation-state-led-lawsuit-against-openai-ceo
66. NPR — Florida sues OpenAI and Sam Altman — https://www.npr.org/2026/06/01/nx-s1-5843132/openai-florida-lawsuit-safety-chatgpt
67. NBC News — Florida accuses OpenAI of putting profit over safety — https://www.nbcnews.com/tech/tech-news/florida-sues-openai-sam-altman-saying-put-profit-safety-rcna347602
Proposed legislation
68. Rep. Jay Obernolte — FRONTIER Act introduction (July 23, 2026) — https://obernolte.house.gov/media/press-releases/obernolte-trahan-introduce-bipartisan-frontier-act-strengthen-oversight
69. Congress.gov — H.R. 9925, the FRONTIER Act — https://www.congress.gov/bill/119th-congress/house-bill/9925
70. Rep. Lori Trahan — FRONTIER Act announcement — https://trahan.house.gov/news/documentsingle.aspx?DocumentID=3823
About This Series
This paper is part of the No Ethics in Big Tech accountability series. It is published under a Creative Commons Attribution-NonCommercial-NoDerivatives 4.0 International License and may be freely shared, cited, and submitted in legal, journalistic, legislative, or academic proceedings.
It is written for attorneys building cases, journalists verifying claims, policymakers drafting statutes, and members of the public — including prospective employees and business partners of the companies named — who want a single documented record rather than a press release.
Related work: No Ethics in Big Tech (book) · Ethics in Tech and Lack Thereof (book) · Forever Peace Now (film) · ParentsPlea.com · ConflictTour.com
NoEthicsInBigTech.com · NoEthicsInBigTech.com/Book · EthicsInTech.com · ForeverPeaceNow.com · MyAWSStory.com
Corrections
This document is intended as a single, verifiable record. If any citation, date, figure, name, or characterization in this paper is inaccurate, the author requests notice and will correct it and publish the correction. Accuracy is the whole point of the exercise.
Research Credit
Research, source verification, and structural editing assisted by Claude (Anthropic). Every statute, case citation, court, date, figure, and quotation above was checked against primary or authoritative secondary sources at the time of writing. Where a claim could not be verified, it has been stated as an open question rather than asserted as fact. The arguments, conclusions, and editorial judgments in this paper are entirely those of the author.
© 2026 Vahid Razavi. Licensed under Creative Commons Attribution-NonCommercial-NoDerivatives 4.0 International (CC BY-NC-ND 4.0).