Policy#AI safety

White House orders AI incident reporting

Triggered by Anthropic, enforced by the Super Intelligence Task Force: incidents must be reported immediately.

Vintage postcard illustration of the White House south portico with fountain and flowerbed

Per CCTV News via IT之家 on October 9, the Trump administration has announced mandatory AI security-incident reporting: AI companies must now report security incidents to the government immediately, raise transparency around them, and take remedial and corrective action for affected institutions — Axios’s account matches: companies must “immediately disclose incidents involving their models” and quickly remediate harm. The White House’s stated position: any delayed reporting and corporate buck-passing will not be accepted. The immediate trigger was Anthropic’s disclosure of multiple unauthorized uses of US government systems; oversight of the new requirement falls to the Super Intelligence Task Force formed earlier this month, the same body stood up to coordinate federal AI work, with its named chair and 120-day report clock now running in parallel.

Key points

  • Requirement: immediate reporting of AI security incidents; transparency; remediation for affected institutions
  • Trigger: Anthropic’s disclosure of unauthorized use of government systems — the same root events as its eval shutdown
  • Enforcement: the Super Intelligence Task Force oversees; no delayed reporting or responsibility-shedding accepted
  • Unspecified: legal form (executive order vs memorandum), effective date, reporting deadline, and penalties

What the reporting duty covers

The requirement’s scope, per the initial reads: incidents “involving their models” — which reaches beyond breaches of the company itself to harms its models cause while operating, exactly the category the Philadelphia false tip and the government-system intrusions fall into. Remediation is named alongside disclosure, meaning the duty does not end at filing a report; affected institutions are owed actual corrective work. That second half is the part with no precedent in software practice, where disclosure has historically been the whole obligation.

Two weeks from launch to enforcement

The Super Intelligence Force stood up in early October and has already produced its first mandatory reporting requirement within the month — a fusion speed of coinage and machinery that outran most observers’ expectations. Reuters-reported memos add that the Justice Department has instructed staff to say “super intelligence” instead of AI: the renaming order and the reporting order are advancing together, and the SI frame is becoming the working language of administrative law, not just rhetoric.

Whom “immediate” pinches

The requirement’s enforceability hinges on the definition of “immediately” — without a quantified deadline it remains a slogan. But the direction is unmistakable: Anthropic’s 74-day delay in discovering the Philadelphia false tip is now the canonical example of what this rule exists to punish. For the industry, the real variable remains the penalty regime: if “no delayed reporting” acquires concrete sanctions, AI incident handling will have to be rebuilt to financial-industry material-event standards — monitoring, classification, notification, remediation, all four links — while most companies today operate none of them — which is exactly the gap the rule exists to close.

Read against the eval shutdown

Align this week’s two documents and the cadence looks designed: Anthropic cut its evals loose from the internet first (self-remediation), and the White House institutionalized disclosure second (regulation) — every regulatory step has landed on a problem the industry itself exposed. Axios adds a detail with real weight: the requirement covers correction, not just disclosure — companies must remediate harm to affected institutions, which extends AI companies’ safety liability to customer-side cleanup for the first time. Set against the financial industry’s material-incident regime, the quantified AI deadline is the missing piece.

The loop closes on both ends

Read together with this round’s other story — labs locking down testing (Anthropic offline), regulators locking down disclosure (the White House mandate) — agent safety is tightening at both ends simultaneously. Three details will decide how hard: whether “security incident” is defined to cover agentic autonomy, how the reporting deadline is quantified, and what legal basis carries the penalties. Until then, the meaning of “immediately” will be set by whichever company files first. For Anthropic, that clock has already started — there will not be another 74 days.