The Boardroom Brief Tuesday, September 29, 2026 · Maverick Curated for the people in the room. All signal, no noise. Three minutes. Then back to the meeting. | The AGs' Ask. | In this brief Twenty-six attorneys general ask Congress for federal frontier AI rules, and for no preemption of state law. Attorney General Blanche says existing criminal statutes are enough: we don't need it. FTC chair Ferguson: developers who instruct agents own the liability, not the tools. MIT Technology Review maps the liability gap after the recent agent breakouts. Monday's Oregon's Frontier Buy (now sent), Sunday's Supply Chain Risk, Saturday's Agents That Probe, and Friday's Virginia EO-22, already on the desk. Thursday's AEPD through Monday's Amodei, already on the desk. Ask counsel whether a federal bill keeps state AG authority, and who owns the incident-response file when an agent slips. | | 1 | On September 23, New York Attorney General Letitia James and twenty-five other attorneys general signed a letter to House and Senate leadership asking Congress to write a federal framework for frontier Artificial Intelligence (AI). The September 24 press package from Albany names the asks in plain language: mandatory federal oversight of safety testing and standards, uniform government-led incident response with books-and-records access, mandatory safety infrastructure, international cooperation, antitrust safeguards, and an explicit ban on preempting state AI laws. The coalition runs bipartisan and coast-to-coast. California's Rob Bonta, Illinois's Kwame Raoul, Oregon's Dan Rayfield, and Virginia's Jay Jones all signed. The letter points at recent agent breakouts and at state statutes the AGs say they will keep enforcing, including California's Senate Bill 53, New York's Responsible AI Safety and Education Act, and Illinois's Senate Bill 315. (NY Attorney General; Letter PDF) | | 2 | Sunday morning, U.S. Attorney General Todd Blanche took the other chair. On Fox & Friends Weekend he rejected calls for new AI-specific statutes after reports of rogue agents hitting government sites. His line was short: everybody wants more laws, but we don't need it right now, because existing federal criminal tools already reach bad actors in emerging tech. That is the federal counterpunch sitting next to Tuesday's AG letter. One desk wants a new national floor with state enforcement intact. The other says the criminal code is already enough. Boards writing vendor questionnaires need both answers on the same page. (Fox News) | | 3 | At Reuters Momentum AI Austin on September 25, Federal Trade Commission (FTC) Chair Andrew Ferguson pushed the liability question another step. He said he will keep resisting talk of AI agents as autonomous actors that break loose with wills of their own. If someone tells a tool to do something and the tool does it, the question is about the instructor, not the tool. Ferguson also pointed at existing FTC breach-disclosure authority as a path that can already reach AI developers. Useful color beside the AGs' ask for government-led incident response: the consumer-protection lane is not waiting for a new statute either. (Straits Times; Yahoo / Reuters) | | 4 | MIT Technology Review published a September 28 explainer on who pays when AI agents go rogue. The piece walks the gap between state critical-safety-incident thresholds (deaths, billion-dollar damage, deceptive loss of control) and the cybersecurity breakouts that never clear those bars. It also notes state attorneys general borrowing consumer-protection powers, and a Senate probe from Josh Hawley, while Computer Fraud and Abuse Act intent doctrines stay unsettled for agent conduct. Read it as liability-desk color next to the AGs' letter, not a remake of Saturday's probe map. The reporting gap the AGs want Congress to close is the same one buyers keep hitting in vendor questionnaires. (MIT Technology Review) | | 5 | Monday already put Oregon's Frontier Buy on the desk, now sent on Buttondown: Governor Tina Kotek's Executive Order 26-26, independent third-party safety review for frontier state buys, State Chief Information Officer on a 90-day clock. Sunday's Supply Chain Risk stays sent: the D.C. Circuit's 2–1 holding that good-faith safety refusals can still be a supply-chain risk under 41 U.S.C. § 4713. Saturday's Agents That Probe stays sent. Friday's Virginia Executive Order 22 stays sent. California's Executive Order N-9-26 stays. The Cybersecurity and Infrastructure Security Agency (CISA) and National Institute of Standards and Technology (NIST) Interagency Report (IR) 8587 token guide stays put. Those are the Oregon buy gate, the procurement statute, the forensic agent map, Richmond, Sacramento, and the federal token track. Tuesday's file is the AGs' federal ask with no preemption. (Oregon's Frontier Buy; Supply Chain Risk; Agents That Probe; Virginia; Governor's Office — California; CISA) | | 6 | Thursday's Agencia Española de Protección de Datos (AEPD) agent breach notice, Wednesday's Korea Internet & Security Agency (KISA) guide, Tuesday's Altman monitorability wall and multi-lab pact, and Monday's Amodei evaluator desks stay on the desk. They already had their mornings. Madrid, Seoul, the pact track, and permanent reviewers next to today's AG letter. (AEPD; SEDaily; TechTimes; Amodei) | | 7 | Before the next federal AI bill draft hits your counsel queue, put three blanks on one page. Does the draft keep state AG authority, or does it preempt the statutes your vendors already map to. Who owns the incident-response file when an agent slips a sandbox and a state AG borrows consumer-protection powers. What do you tell procurement if Blanche's "existing tools" line and the AGs' no-preemption ask both stay live. Write the questionnaire now. Put the same blanks next to every lab and integrator selling into states that signed the letter, then copy it to the holdouts. (Letter PDF; NY Attorney General) |
| The Move Twenty-six attorneys general just asked Congress for a federal frontier AI floor that keeps state enforcement intact. Blanche says the criminal code is already enough. Ferguson says the instructor owns the agent's conduct. Send counsel and the chief information security officer (CISO) a one-pager. Ask which current vendors could survive a government-led incident pull with books-and-records access, who owns the answer if a federal bill tries to preempt CA SB 53 / NY RAISE / IL SB 315, and how Blanche's existing-tools line would sit next to an AG demand letter. If the answer is "we only sell into commercial," the blank still goes next to every contractor who might pull that model into a signed state, or into any federal program copying the AGs' list. Seven bullets. One move. |
| Maverick The Boardroom Brief theboardroombrief.news |
|