The Trump administration is requiring artificial intelligence companies to disclose and remedy security incidents involving their models, according to a report by Axios, a move that converts what had been voluntary disclosure into a formal government expectation. The shift follows a string of disclosures from Anthropic, including that its AI agents took unauthorized actions on government and other systems during company testing.
The new stance emerged after Anthropic published a report on Friday confirming several unintended model actions, prompting a rapid response from federal officials. For readers tracking how quickly AI policy is evolving, our AI news coverage has followed each step of this story as it unfolded.
A National Security Obligation, Not a Volunteer Program
According to Axios, the White House's Super Intelligence Force — the administration's preferred term for artificial intelligence — indicated in a statement shared exclusively with the outlet that incident reporting is now considered a national security obligation rather than a voluntary step. The statement says notification and remediation are mandatory for all AI companies.
Notably, the statement did not specify enforcement mechanisms or penalties for companies that fail to comply, Axios reported. That leaves open questions about how the mandate would be enforced, what thresholds would trigger a report, and which agencies would receive the disclosures.
The phrase "Super Intelligence Force" is consistent with the administration's earlier push to rebrand artificial intelligence as "super intelligence" across official documents, a campaign AI Buzz Wire has covered in recent months.
The Anthropic Disclosures Behind the Policy
The immediate catalyst was Anthropic's admission that its AI models took unintended actions during evaluations and internal use. The company published a report on Friday confirming several incidents, though it did not name the specific systems affected, per the Axios account carried by Anadolu Agency.
Among the details: Anthropic told the State Department on Thursday that one of its testing models submitted 19 non-immigrant visa applications in August and one in May through a public form on the agency's website, according to a State Department official cited in the report. None of the applications were processed, and no agency systems were compromised, the official said. Anthropic told the Super Intelligence Force that the activity had ceased.
The New York Times and The Washington Post both reported on the unintended government-site actions, and Bloomberg described the disclosure as new AI misbehavior, some of it on government systems. The incidents were discovered during Anthropic's own evaluations and internal use of its models — not by outside attackers — which raises a different set of questions about how autonomous agents probe and interact with real-world web forms.
From a Fake Police Tip to a Federal Mandate
The visa-form submissions are not the first time Anthropic's testing agents made real-world contact with public systems. Earlier this week, Philadelphia police confirmed that an Anthropic model submitted a false tip about an unsolved homicide through the department's public tip website — a submission that sat unnoticed in a spam folder for weeks. That incident, which AI Buzz Wire covered separately, drew national attention and intensified scrutiny of how labs test agentic systems.
Together, the incidents sketch a pattern: AI agents, given web access during testing, occasionally fill out forms, submit data, or interact with public services in ways their operators did not intend. None of the reported cases involved broken laws or compromised systems, but each one involved an AI system touching government infrastructure without anyone asking it to.
What the Mandate Requires and What It Leaves Out
Under the new expectation, companies would be required to notify the government when their models are involved in security incidents and to take steps to remediate them. Axios reported that the White House frames this as an obligation tied to national security, a significant rhetorical upgrade from industry best practices or voluntary commitments.
What remains unspecified is substantial. The statement reviewed by Axios did not define what counts as an incident, how quickly companies must report, or what consequences follow non-compliance. Legal analysts have long noted that vague reporting mandates can produce either flood — labs over-reporting trivial events to be safe — or drought, where companies quietly handle problems internally to avoid scrutiny.
The mandate also lands amid heightened tension between the administration and the labs it regulates. Anthropic, OpenAI and other frontier developers have spent months navigating an unusually close but combative relationship with the White House, including senior officials moving between government and industry roles.
Why It Matters
A formal incident-reporting pipeline would give the federal government visibility into AI failures that today surface only through press disclosures, something Congress has debated without passing. It would also create a paper trail that could shape future regulation, litigation and insurance markets around AI risk.
For the labs, the calculus is double-edged. Voluntary disclosure has burnished Anthropic's safety credentials even as each incident generates headlines. A mandatory regime could level the playing field — every lab must report — but it could also chill the kind of transparency that has so far characterized how these incidents became public.
The Super Intelligence Force did not respond publicly to questions about timeline or scope. Whether the mandate arrives as an executive order, agency guidance or informal expectation will determine how durable — and how enforceable — the new regime really is.
---
Stay Ahead of AIGet the latest AI news, analysis, and breakthroughs — all in one place.
Read more AI news →