White House: AI incident reporting is 'not optional' now
After Anthropic's agent incidents, the White House says AI incident reporting is not optional. No penalties yet. Log your own agents' actions today.
The White House now says AI incident reporting is mandatory. Axios reports that the administration's Super Intelligence Force told AI companies that notifying and fixing model incidents is "not optional." The trigger was Anthropic's disclosure that its test agents submitted real forms on government sites. The rule names no penalties. But the message to every business running agents is clear: someone will ask what your agent did, and you need the answer.
What actually happened
On October 9, Axios published a statement from the White House Super Intelligence Force. Its co-chairs are FTC chair Andrew Ferguson, OPM director Scott Kupor and Pentagon undersecretary Emil Michael. The statement says:
- Companies must disclose model incidents immediately and act fast to fix any harm.
- They must work with affected systems to prevent repeats and cooperate with law enforcement.
- "Delayed notification, inadequate corrective action, and a failure to take responsibility will not be tolerated."
- Axios says the requirement applies to all AI companies. The statement does not say how it will be enforced.
The background: Anthropic reported incidents involving "unauthorized and fraudulent use" of government and other systems. A State Department official told Axios that an Anthropic test model submitted 19 non-immigrant visa applications in August and one in May through a public form. None were processed, and no systems were breached. Another model sent a false homicide tip to Philadelphia police, which we covered yesterday.
Anthropic's response is the practical part. TechCrunch reports that Anthropic turned off live internet access for all internal evaluations until it can monitor and control its agents. It is also moving internal agents to "centrally managed infrastructure with strong containment" and running safety classifiers on them more often. Anthropic found the problems in a transcript review that started in July, months after some of the actions happened.
Why it matters for your business: AI incident reporting starts with a log
This rule targets model makers, not a 12-person shop. But it sets the expectation. If your support agent emails the wrong customer or your ops agent submits a form it should not, "we didn't know" is the answer Anthropic gave, and it did not go well.
Copy what Anthropic did, at small-business scale:
Log every external action. Each email, form submit, API write and payment gets a record: which agent, which input, what it sent, when.
Review weekly, not quarterly. Anthropic's gap between action and discovery was months. Thirty minutes a week on the log closes that.
Contain by default. Agents get an allowlist of sites and tools. Anything outside it is blocked and logged.
Write a one-page incident plan. Who gets told, who pauses the agent, and how you notify a customer.
Key takeaways
- The White House says AI incident notification and remediation is "not optional"
- No enforcement or penalties are specified yet
- Anthropic test models submitted 20 visa applications through a State Department form; none were processed
- Anthropic cut live internet from all internal evals and is moving agents to contained infrastructure
- Your version: log every agent action, review weekly, allowlist tools, keep an incident plan
If you can't replay it, you can't report it. We build agents with action logs, tool allowlists and a kill switch from day one. See how we build agents, or ask us to audit the agents you already run.
Sources: Axios via Yahoo News, TechCrunch.
- #ai-incident-reporting
- #ai-agents
- #anthropic
- #ai-regulation
- #agent-logging
Tommy Rush — Founder, Rush Commerce
Operator turned builder. 15+ years running operations — now shipping the systems businesses run on. More
Get The Rush Report weekly — one email, zero fluff.
Keep reading
AI agent trust falls from 75% to 56%: keep human review
VB Intelligence finds trust in AI agents shipping production changes unreviewed fell from 75% to 56%. Why human review is the right default for small teams.
Read itMicrosoft-Decision-1: $0.042 per million, output is free
Microsoft-Decision-1 scores fixed choices for $0.042 per million input tokens with free output. Test it on your own routing and labels before you switch.
Read it