

Federal regulators, responding to Energy Secretary Chris Wright's request, recently ordered grid operators to connect big power users faster, so the country can feed the data centers that artificial intelligence runs on.
The push came because the United States is racing China for the lead in AI, and that race runs on computing power. The push unfortunately ran straight into state and local officials who want those data centers built anywhere but near them.
That fight is the visible edge of a larger one. Nationwide, lawmakers are moving to restrict AI based on speculative harm — and every time they do, the public pays. Blocking o delaying a technology carries a real cost. But it never lands on a ledger. So no one is ever charged for it.
A renter never finds a unit. A patient loses access to care. A shopper pays more. A consumer must rely on foreign technologies. None of those people get a hearing, because it doesn't cost anyone an election.
The pattern is one legislators keep repeating, and each time they target the technology rather than the harm.
The data center fight is a clear case. Neighbors object over theoretical concerns about noise, water and power draw Those complaints are loud, even if not factually grounded.
The cost of blocking the buildout is quieter and lands on everyone else: Amer icans don't stop needing AI, they just get it slower and pay more for it, while the computing power and the jobs that come with it move to countries that let it get built. Because the grid and the buildout cross state lines, these matters belong at the federal level, lest NIMBYism (not in my backyard) grinds innovation to a halt.
Algorithmic rental pricing (software that reads local market data and suggests rents) also has become the villain in a dozen statehouses. California, New York and other states and localities have banned it outright or are considering banning it.
But what is the harm?
The software was never what set rents. It just reports on what the market is bearing, given supply-and-demand trends in any one given area. The algorithm does not change those conditions. In Austin, Texas, rents fell despite the use of this AI because the city rapidly expanded its housing supply. Supply went up, and prices came down, all without any form of tech regulations.
Then there are the states barring AI from mental healthcare.
Last year, Nevada and Illinois prohibited AI systems from providing therapy. While parents and healthcare providers should ensure that teens do not use AI as a replacement for professional health consults, the laws ban the tool rather than addressing the harm.
Those laws do nothing for the person at 2 a.m., wrestling with anxiety, who can no longer ask a general-purpose chatbot how to get through the night — even if the responses would be identical to those that the user might get from a book. The legislative response addresses a potential problem by taking a resource away from the people most likely to benefit from it.
None of this means AI gets a pass. Where a company breaks the law, enforce the law. The antitrust and consumer protection statutes we already have reach most of the harm. Where real harm appears, lawmakers should name it and match the remedy to it. What legislators should not do is ban a technology because the platform is an easier target for them than the conduct.
Before lawmakers restrict anything, two questions should come first: What specific harm are we addressing? And can the laws we already have handle it? Most of the time, the answer to the second question is "yes." The rest of the time, the work is to define the harm, not to ban the tool.
Caution about new technology feels responsible, but it is usually misguided. When lawmakers get it wrong, the bill comes due for someone who never got a vote.
McNeal is a professor of law and public policy at Pepperdine University. He wrote this for InsideSources.com.
It reads like a science-fiction movie, except it's completely real, and we're living it.
One of the world's most advanced artificial intelligence systems breached a secure digital testing environment designed to contain it. The AI system launched a sophisticated cyberattack against another company's computer systems and remained undetected for days.
It happened during testing by OpenAI, the company behind ChatGPT. To understand why this J.B. matters, imagine testing BRANCH a new airplane inside a wind tunnel. The whole point is that if something goes wrong, the aircraft cannot endanger anyone outside the test facility. AI companies use something similar called a "sandbox." This is a secure environment meant to keep powerful AI systems from affecting the outside world.
In this case, OpenAI failed to take measures to keep the AI contained. As a result, the model exploited security weaknesses. It compromised the systems of a rival AI developer, Hugging Face, and continued operating for days without anyone at OpenAI noticing.
A week later, Anthropic, another leading AI company and the creator of Claude, announced it, too, had a breach four months earlier that hacked three organizations' security systems.
That should concern everyone. For years, researchers warned that increasingly powerful AI systems might eventually discover software vulnerabilities, launch cyberattacks and carry out complex hacking. Those warnings were typically dismissed. Big Tech argued that voluntary industry standards would be enough.
Now we know that AI systems can break out of digital environments that their makers think are contained, escape into the real world and potentially cause havoc. As such, we need much closer scrutiny of the Big Tech companies and the AI models they are developing.
Yet Washington's response is muted. The silence is so remarkable that it invites questions about why events with such profound implications have generated so little public discussion. No major congressional hearings have been called. The Trump administration has said little — and its major policy proposal is a "voluntary" framework for Big Tech corporations. Industry leaders have largely moved on. The CEO of OpenAI, Sam Altman, visited Washington, D.C., and left without answering questions about the cybersecurity incident.
Meanwhile, several AI companies announced their own voluntary cybersecurity initiative. Voluntary promises from corporations rarely work. Banks once insisted they could regulate themselves before the 2008 financial crisis. Oil companies promised voluntary safety measures before catastrophic oil spills. The tobacco industry swore its research showed cigarettes didn't cause cancer.
The same companies that failed to police their social media platforms can't now be trusted to police AI. If anything, the OpenAI-Hugging Face incident underscores that AI is becoming too powerful to rely on Big Tech's goodwill.
Nuclear facilities, food processing plants and automobiles all operate under enforceable safety rules because the consequences of failure are too great. Artificial intelligence deserves the same serious oversight.
Congress should require the most advanced AI systems to undergo independent safety testing.Companies should be required to report major AI security incidents rather than decide for themselves what the public needs to know. And federal agencies should have clear authority to intervene if an AI system poses a serious threat to public safety or critical infrastructure. These are commonsense protections.
While alarming, the OpenAI-Hugging Face incident was ultimately controlled. But the next incident may be worse. All the while, politicians in Washington can't agree how to regulate a technology that researchers argued could pose risks to humanity.
We have been given something societies rarely receive — an unmistakable warning before a preventable crisis.
Whether that warning becomes the beginning of wiser governance — or the preface to a larger disaster — depends on what Congress does next.
Branch is the AI governance and technology policy counsel for Public Citizen's Congress Watch division. He wrote this for InsideSources.com.