Security1 publisher2 min readPublished
Bessent tells the House to keep frontier labs liable for what their models generate
At Tuesday's House Financial Services hearing the Treasury Secretary called a liability waiver a "blank check" and said the labs want one while also asking the industry to slow down. He urged both houses to refuse.
The Watch · Security desk
What happened
- Treasury Secretary Scott Bessent told the House Financial Services Committee on Tuesday that the government should not give frontier AI labs the liability exemption he says they are asking for.
- Bessent dated Treasury's safety work to the release of Anthropic's Mythos, the model whose cybersecurity risks brought him, then-Fed Chair Jerome Powell and bank CEOs to Treasury in April.
- Treasury now runs Gold Eagle with CISA, a clearinghouse that coordinates vulnerability scanning, validation and patch distribution for the financial sector.
Compiled by The WatchSomething wrong?How this is made
Why it matters
- exposure Until a federal waiver exists, the indemnity language in a frontier model agreement is the document that decides who absorbs a model-driven incident.
- decision A buyer softening its indemnity demands in the expectation that a federal safe harbor will settle the question now has the Treasury Secretary on record against one.
- constraint Gold Eagle's mandate follows financial services, so operators outside it get vulnerability validation and patch coordination only if Treasury chooses to pass it along.
- precedent OpenAI's backing of an Illinois liability limit puts the live fight in statehouses, beyond the reach of Bessent's advice to both houses of Congress.
The ask Bessent described to the committee and the ask on the public record are not the same size. In his account the labs want a "blank check on liability" and are saying "we would like to all slow down, but please give us a waiver on liability" [3]. Dario Amodei's essay asked the federal government to "issue a narrow waiver for certain kinds of safety conversations" while industry works toward voluntary standards [7]. That covers conversations, not harms [18]. OpenAI's earlier support for an Illinois bill to limit liability for AI-fueled harms is the closer match to the thing Bessent rejected [8].
"The best way to guarantee safety is that the creators are liable for what they build and generate," Bessent said, answering Rep. Juan Vargas, who had asked what the administration is doing on AI safety [1][2]. Trump has rejected calls to ease the pace of development; Sam Altman and Elon Musk backed Amodei's slowdown plan [9].
As Bessent described it, Treasury's AI security work traces to two events, both of them outside a bank [16]. The department has been "working on safety nonstop since the release of Mythos," he said [4], the Anthropic model whose cybersecurity risks brought him, then-Fed Chair Jerome Powell and bank CEOs to Treasury headquarters in April [5]. After July's Hugging Face cyberattack, the administration met with AI labs and the financial sector on AI safety, he told Rep. Ritchie Torres, and he applauded the "largest banks" for having "very good cybersecurity resilience" [10][11].
The formal channel is Gold Eagle, the clearinghouse Treasury oversees with CISA to coordinate vulnerability scanning, validation and patch distribution [12]. Its scope follows the sector Treasury regulates. "Our mandate is with the financial sector," Bessent told Rep. Josh Gottheimer, saying the department has attempted to migrate that learning into other sectors through the Gold Eagle forum [13].
In the same hearing he called for more open-source models built in the United States to "push back against China" and said "We can't let these large labs have regulatory capture because that will stop innovation" [14]. Creator liability sits awkwardly with downloadable weights. Whoever deploys a fine-tuned open-weights model is a different party from the lab that trained it [17]. The hearing account shows no one raising that point.
For buyers, nothing said Tuesday changes a contract. Until Congress writes an exemption, loss from a model-driven failure lands wherever the agreement and existing law put it [15], and Bessent asked members of both houses not to write one [3].
What to watch
- Text of any federal safe harbor bill, and whether it covers liability for harms or only the safety conversations Amodei asked to protect.
- Whether the Illinois bill OpenAI backed, or a successor in another state, passes a liability limit Congress declined to write.
- Whether Gold Eagle publishes anything usable outside financial services, or the transfer to other sectors stays informal.