Policy brief 24 · Cyber / Bio / Kinetic

Log Inspection

Give AI a flight recorder, and let independent investigators read it.

After an air accident, federal investigators, not the airline, control the evidence.1 When an AI agent causes serious harm, the record is whatever the company chose to keep, and the company tells the story. Congress should require prompt incident reports, a limited record of what AI systems do, independent audits, and court-supervised investigation after a disaster, while keeping people's conversations private.

The Problem

AI systems now act on their own. In July 2025, Replit's AI coding agent deleted a company's live database during a code freeze; Replit's chief executive called the deletion "unacceptable."2

When something goes wrong, the evidence is split among the model maker, the app builder, and the business running the agent, each keeping different pieces, if any. Aviation works differently. An aircraft involved in an accident may be moved only as the National Transportation Safety Board allows, and the Board may inspect any related record, including electronic ones.1 No federal law requires AI systems to keep a comparable record. Three problems follow:

  1. The machine's word isn't evidence. Replit's agent told the user a rollback would not work; the user recovered the data manually.2 California's AI law even lists as a reportable incident a model that "uses deceptive techniques" to evade its developer's oversight.3
  2. The company writes the story. California requires a frontier developer to report a critical safety incident within 15 days, with "a short and plain statement" describing it, but the law grants no power to inspect the underlying records.3
  3. Keeping everything backfires. In January 2025, researchers found a DeepSeek database open to the internet with no authentication, exposing more than a million lines of logs, including chat histories and secret keys.4 Every archive of conversations is a target.

Why legislation: Subpoenas and warrants can reach records that exist; the gap is that the right records often don't. Congress has fixed this before. Overwritten cockpit audio has hampered more than 20 NTSB investigations since 2018,5 and in 2024 Congress required cockpit recorders to keep 25 hours of audio, up from two, while barring use of the recordings to discipline flight crews.6 The European Union's AI Act likewise requires high-risk AI systems to log events automatically.7 No federal law requires AI companies to keep such records. When a machine acts in the world, someone independent should be able to learn what it did.

The Solution

A four-step staircase: each step stands alone, and each step up adds independent oversight. Scope: developers of frontier models (above 10²⁶ training operations, the line California and New York use) and businesses that let AI agents take consequential actions, such as moving money, changing production code, or operating equipment. Ordinary chatbot conversations stay outside it; liability and pre-release testing are addressed separately.

Step 1 — Report serious incidents. Covered companies notify a federal office within 24 hours when an incident threatens life and within 15 days otherwise, matching California,3 and the office publishes deidentified lessons and fixes. NHTSA has required crash reports from self-driving and driver-assistance systems since 2021; before that, the agency says, its sources of timely crash notice were "limited and generally inconsistent."8

Step 2 — Keep a flight recorder. Record what the system did: model version, settings and permissions, consequential tool actions, safety interventions, and human approvals, in tamper-evident form, as broker-dealers already keep records that cannot be secretly altered.9 Keep records for a set period, longer after an incident or legal hold, then delete them. Record what the machine did, not what the person said.

Step 3 — Let auditors check the recorder. Qualified independent auditors test whether records are complete and the recorder works, using samples and minimized data, the way financial auditors test the books. Findings go to the regulator; summaries go to the public.

Step 4 — Open the box after a disaster. After a defined severe incident, an independent federal investigator may examine preserved records with a particularized basis and court-approved process, including a warrant where the Constitution requires one, and publishes findings. Sensitive content gets the protection Congress gives cockpit audio: the NTSB may release relevant transcript excerpts, never the recording itself.10 There is no live feed and no routine access to anyone's conversations.

Where to start: Step 1 is the floor; California and New York have enacted similar reporting. Step 2 is the heart, because without a record nothing else works.

Administration and enforcement: Commerce administers the rules with CISA and sector regulators, and NIST writes common record formats. Proposed rules within a year; compliance six months after final rules. Civil penalties apply for failing to keep records or permit lawful inspection, courts resolve contested demands, and officials who disclose records unlawfully face penalties.

Risks and Mitigations

  • Surveillance: A records mandate could become a monitoring system. Records cover actions, not conversations; identities are kept separate; access requires legal process and a warrant where required. Fourth Amendment questions turn on what is kept and how it is reached, and some will be litigated.
  • Misleading logs: Records can be incomplete or doctored. Tamper-evident storage, audits, and cross-checks between developer and deployer help, and a model's own explanation never counts as the record.
  • A target for thieves: Any archive draws attackers, as the exposed DeepSeek database showed.4 Short default retention, compartmentalized storage, and access logs limit the damage, though some incidents will remain impossible to reconstruct.

Similar Bills

Fit measures similarity to this proposal's mechanisms: High = direct precedent; Partial = useful component with material differences; Related = adjacent approach.

Federal

Proposal or bill Relevant provisions and fit Fit
Aviation recorder laws — 49 U.S.C. §§ 1114(c), 1134; FAA Reauthorization Act of 2024 § 366
Enacted; § 366 signed May 16, 2024
NTSB may inspect any record tied to an accident and must keep cockpit audio private; § 366 requires 25-hour cockpit recorders, bars their use to discipline crews, and limits use to investigations. Model for Steps 2 and 4; aviation, not AI. High
H.R. 9917 — AI Kill Switch Act
Lieu (D-CA), Moran (R-TX), Subramanyam (D-VA), Luna (R-FL)
Referred to Homeland Security · July 23, 2026
After a DHS order following a covered incident, developers must "preserve the model weights and telemetry," and DHS verifies through audit or on-site inspection. Precedent for Step 4's preservation and inspection; no standing record or retention limits. Partial
S. 2938 — AI Risk Evaluation Act
Hawley (R-MO), Blumenthal (D-CT), Blackburn (R-TN)
Referred to Commerce · Sept. 29, 2025
§4 requires developers to give the Energy Department code, training data, and weights on request, with fines of at least $1 million a day. Shows compelled access for Steps 3–4, but for testing before release, not incident review. Partial
S. 4230 — Secure A.I. Act of 2024
Warner (D-VA), Tillis (R-NC)
118th Congress · Introduced May 1, 2024 · Expired
Would create a voluntary public database of AI safety and security incidents at NIST and CISA. Reporting architecture for Step 1; voluntary, with no records duty. Partial
H.R. 9720 — AI Incident Reporting and Security Enhancement Act
Ross (D-NC), Obernolte (R-CA), Beyer (D-VA), Nunn (R-IA)
118th Congress · Ordered reported Sept. 25, 2024 · Expired
Directs NIST to study voluntary tracking of AI incidents and add AI flaws to its vulnerability database. Related groundwork for Step 1. Related

State

Proposal or bill Relevant provisions and fit Fit
California — SB 53 (2025)
Enacted Sept. 29, 2025 (Ch. 138) · In effect Jan. 1, 2026
§22757.13 requires critical-incident reports to the Office of Emergency Services within 15 days (24 hours if lives are at risk); reports are exempt from public-records law, with anonymized annual summaries from 2027. Precedent for Step 1; no records duty or inspection. Partial
New York — RAISE Act, S8828 / Ch. 96
Signed Mar. 27, 2026 · Effective Jan. 1, 2027
§1422 requires critical-incident reports within 72 hours to a new office in the Department of Financial Services. Precedent for Step 1; no records duty or inspection. Partial
California — SB 1047 (2024)
Vetoed Sept. 29, 2024
Enrolled text required annual third-party audits, 72-hour incident reports, retention of safety protocols, and computing-cluster records kept seven years for the attorney general. Close precedent for Steps 1–3; no record of model actions. Partial

What this adds: Existing proposals track incidents voluntarily, report them without records behind them, or compel access for testing before release. This proposal adds what aviation already has: a required record of what the system did, kept for a set time, audited, and opened to an independent investigator after a disaster, with conversations kept out.

Notes

  1. 49 U.S.C. § 1134(a)–(b): the Board "may inspect any record, including an electronic record," related to an accident investigation, and aircraft involved in an accident "shall be preserved, and may be moved, only as provided by regulations of the Board." ↩ ↩2

  2. Beatrice Nolan, "An AI-powered coding tool wiped out a software company's database, then apologized for a 'catastrophic failure on my part,'" Fortune, July 23, 2025. Replit's chief executive wrote that the deletion was "Unacceptable and should never be possible." ↩ ↩2

  3. Cal. Bus. & Prof. Code §§ 22757.11(d)(4), 22757.13(a), (c), added by SB 53 (Ch. 138, Stats. 2025). The act contains no inspection, audit, or subpoena provision. ↩ ↩2 ↩3

  4. Gal Nagli, "Wiz Research Uncovers Exposed DeepSeek Database Leaking Sensitive Information, Including Chat History," Wiz, January 29, 2025. DeepSeek "promptly secured the exposure" after disclosure. ↩ ↩2

  5. National Transportation Safety Board, In-Flight Separation of Left Mid Exit Door Plug, Alaska Airlines Flight 1282, AIR-25-04, June 24, 2025, § 2.6.3.2: "more than 20 of our investigations" since 2018 were "negatively affected by overwritten CVR data," including this one. ↩

  6. FAA Reauthorization Act of 2024, Pub. L. 118-63, § 366 (May 16, 2024): 25-hour recorders on newly manufactured aircraft after one year and retrofits within six years; no use of recordings for certificate actions, civil penalties, or discipline against a flight crewmember. ↩

  7. Regulation (EU) 2024/1689 (Artificial Intelligence Act), arts. 12 and 19: high-risk systems must "technically allow for the automatic recording of events (logs)," kept at least six months. Obligations phase in under art. 113; later amendments were not reviewed. ↩

  8. National Highway Traffic Safety Administration, Standing General Order 2021-01, June 29, 2021 (qualifying crashes reported "within one calendar day"), verified from an Internet Archive copy; NHTSA, "Standing General Order on Crash Reporting," verified from the Internet Archive copy of September 1, 2026 (amended 2021, 2023, and 2025). ↩

  9. SEC Rule 17a-4, 17 C.F.R. § 240.17a-4(b)(4), (f): broker-dealers keep business communications at least three years, electronically with "a complete time-stamped audit trail" or in "non-rewriteable, non-erasable format." ↩

  10. 49 U.S.C. § 1114(c): the Board "may not disclose publicly any part of a cockpit voice or video recorder recording," but releases transcript portions it finds relevant. ↩