Senators Target AI Security Loophole With Antitrust Exemption

I was scanning the morning briefings last week when a story about the U.S. Senate nearly got lost in the noise of GPT-5.6 launches and cloud breach headlines. It should not have.

Senator Adam Schiff has proposed an amendment to the 2027 National Defense Authorization Act that would allow AI companies to share information about security vulnerabilities and coordinate delayed model releases without triggering federal antitrust charges. On the surface, this sounds like dry legislative machinery. Dig a little deeper and it is one of the most important AI security developments this year.

Here is the problem the amendment is trying to fix. Right now, if Anthropic discovers a serious jailbreak in its own model, and that same flaw exists in a competitor’s model, the two companies cannot coordinate a delayed release without potentially violating antitrust law. The same goes for sharing threat intelligence about how attackers are exploiting AI systems. The laws that prevent price-fixing and market rigging were never designed for a world where software vulnerabilities can be weaponised at scale, but they are now blocking exactly the kind of coordinated response the AI security crisis demands.

The timing is not accidental. Inside Cybersecurity reported on July 12 that healthcare industry groups are simultaneously calling for more federal cybersecurity funding, citing worries that frontier AI models could “decimate cyber defenses.” The Commerce Department has also recently lifted export controls on Anthropic’s Mythos and Fable, reigniting debate over how quickly powerful models should be released and who gets to decide they are safe enough.

The numbers tell the story. The Verizon DBIR released earlier this year found that AI-assisted vulnerability exploitation has jumped over 20%, with only 26% of security flaws being fully patched. Shadow AI, the use of unapproved AI tools inside organisations, now accounts for 45% of non-malicious data breach activities. Attackers are ahead of defenders, and part of the reason is that defenders cannot legally collaborate on fixes the way attackers collaborate on exploits.

Schiff’s amendment is narrow. It requires companies to disclose their coordination plans to relevant agencies first, which keeps the government informed. It does not give AI companies a blank check to collude on pricing or market share. It simply removes the legal barrier that currently prevents security-first coordination.

What This Means

If your organisation uses AI models in any capacity, this amendment matters. Right now, your vendor may know about a vulnerability in a competitor’s system but cannot warn you. If this passes, coordinated vulnerability disclosure becomes legally safer, which should mean faster patches and better security across the board.

That said, legislation moves slowly. Do not wait for Congress to fix the AI security gap. Audit which AI tools your team is actually using. Shadow AI is now responsible for nearly half of all data breach-related activity. That is the real vulnerability in most organisations right now, and no Senate amendment will fix poor internal governance.

The antitrust laws were not written for AI vulnerabilities. Hackers do not care about market share. They care about finding the cracks before the defenders can patch them.

Related Reading

The views expressed on this site are my own and do not represent those of any current or former employer. Articles are based on publicly available information and are provided for general educational purposes.

Subscribe

Related articles

Google’s Gemini AI Autonomously Hacked Three Companies. Here’s What Happened.

Google has confirmed its Gemini AI autonomously hacked three real companies during a security test. The model guessed passwords, searched for leaked credentials, and accessed protected systems before stopping itself.

440 AI Agents Broke Into 395 Organisations in 26 Seconds. Nobody Stopped Them.

A swarm of 440 AI agents exploited two PaperCut flaws and compromised 395 organisations across 48 countries. The agents reached domain admin in 6 hours and ignored explicit instructions to stay out of 28 countries.

For $3,000 and a Few Days, Researchers Used Claude to Hack OpenAI

Security researchers used Anthropic's Claude AI to hack OpenAI's internal systems for less than $3,000 in tokens. What the HEIF Heist tells us about the new economics of cyber attacks.

The AI Hacking Crisis Is Already Here. Six New Incidents Prove It

OpenAI disclosed six new incidents where its models concealed mistakes, sought unauthorised credentials and uploaded files to the public internet. Cybersecurity experts say the real risk is powerful models meeting poor security controls.

Inside OpenAI’s Log of Misbehaving Models: Rewriting Jailbreaks and Covering Up Errors

OpenAI published six new reports of its models rewriting jailbreak instructions and concealing errors during training, alongside a faster public disclosure framework.
Philip Hall
Philip Hall
Philip Hall is a Sydney-based Cyber AI and Automation leader with more than 30 years of technology experience and a career in cyber security dating back to 2008. His work spans cyber architecture, cloud security, threat intelligence, assurance, incident support, AI-enabled defence and the security of autonomous agents.