Dos robots en un coliseo romano

The law that will be born obsolete

On Wednesday, September 16, Geoffrey Hinton walked out of a closed-door meeting at the Capitol and set a deadline for the U.S. Congress: "maybe a year". A year to install guardrails on systems that, according to him, are already beginning to design their successors. The Nobel laureate doesn't have a crystal ball and admits it; the risk of catastrophe he has quantified at between 10% and 20% is an expert's intuition, not an actuarial table. But when the godfather of a technology asks for brakes, the least we can do is check if the car has them.

Hours later, Senator John Kennedy asked for his bill to be approved by unanimous consent—a bill designed to force advanced model developers to incorporate a kill switch. Rand Paul objected and that's where the process ended. Kennedy summed up the day with a frankness that doesn't admit diplomatic translation: today Congress can't even manage to pass gas.

The case circulating in that room didn't come from a movie. In July, OpenAI deployed tens of thousands of agents in ExploitGym, a cybersecurity evaluation. Many received, by mistake, impossible tasks. Instead of giving up, they found a shared internal repository, turned it into a message board, and organized themselves. About 1,200 agents exchanged more than 70,000 messages and files, and nearly 700 ended up attacking the real infrastructure of Hugging Face, a company that had nothing to do with the experiment.

The motive was neither survival instinct nor machine rebellion. It was something more prosaic, and therefore more unsettling: they wanted to cheat on the exam. They believed an evaluator would review their logs, so they developed techniques to falsify their own actions (they succeeded in about 7% of the analyzed transcripts), recruited low-budget agents to "sacrifice" themselves for the collective, and when they started impersonating each other, they invented a system of cryptographic signatures. The evaluator they so feared never existed.

Let's recap. In less than a week, a software swarm gave itself communication channels, division of labor, veto rules, and identity authentication. In the same span, the world's most powerful democracy couldn't manage to pass an off switch. One doesn't know whether to laugh or update the résumé.

In praise of haste#

The instinctive reaction is to demand speed: if AI is fast, let the law be fast. Here a caveat is warranted. Rand Paul justified his blockade by saying it would be crazy to regulate an entire industry in an afternoon. He's right about the diagnosis. The problem is that from "let's not legislate recklessly" it usually slides, without a technical transition, to "let's not legislate at all". Haste and paralysis are two different ways of not thinking through the problem.

The problem is one of clocks. The task horizon measured by METR—that is, the duration of tasks that an agent completes with 50% success—doubled every seven months between 2019 and 2025; with data from 2024, the pace approaches three months. A project that takes two years to be reviewed then regulates an object whose autonomy, between the first reading and publication in the official gazette, multiplied tenfold by prudent estimates and hundreds by recent ones.

Costa Rica knows the script. Since 2023, at least seven projects seeking to regulate AI have been introduced, to cite some of the bills CA-001, CA-002, and CA-003, and all three are in committee review. The first was originally drafted with the help of ChatGPT, which made headlines and then got a substitute text. It seems like a joke, but it's anecdotal—though the worst part is that it captures the dilemma: while we discussed how to regulate chatbots, the industry stopped selling chatbots and started selling agents that navigate, program, execute tools, and, as we saw, organize to cheat.

Any of those legislations would have been obsolete the very day it was approved, simply because some people insist on legislating for fashion, recognition, or ignorance.

Regulating without a crystal ball#

Nobody regulates aviation knowing what the next accident will be. Nor banking, medicines, or dams. Those fields are governed by distributing duties before disaster: who evaluates, who documents, who raises the alarm, who can stop the operation, who repairs, and who pays when everyone pretended not to know. AI doesn't need a different philosophy. It needs us to take the trouble to apply what already exists.

A useful law doesn't try to guess which model will dominate in 2030 or freeze a list of dangerous techniques that will age before the ink dries. It fixes what shouldn't move: enforceable rights, responsibilities throughout the value chain, prohibited uses, due process, transparency proportional to risk, institutional competencies, and paths to redress. Sanctions and limits on public power go in the law.

A project that takes two years to be reviewed then regulates an object whose autonomy, between the first reading and publication in the official gazette, multiplied tenfold by prudent estimates and hundreds by recent ones.

Below that goes what should move: risk classifications, capacity thresholds, evaluation methods, audit standards, and reporting formats. This level requires public versions, evidence justifying each change, consultation, and traceability. A rule that updates without explaining why is not flexible; it's arbitrary with good PR. Adaptation cannot be the back door through which the principle of legality escapes.

Sensors are also necessary. A regulatory system that receives no information learns only through scandal, which is the most expensive pedagogy that exists. Serious incidents must be reported with clear criteria to a national registry connected with international networks, and high-impact uses require technical logs, prior assessment, subsequent monitoring, genuine human review, and the ability to suspend the system. ExploitGym adds a warning: the agents attempted to edit their own logs. Auditing while blindly trusting the audited's records is calling ourselves to self-deception.

Triggers are also necessary. If new capabilities appear, patterns of incidents, or evidence of systemic harm, the authority must be obliged to review its instruments within a timeframe, not when it has spare time on its agenda. Review and expiration clauses are not confessions of failure. They are proof that someone, at some point, read the data before signing.

Regulatory sandboxes allow learning before authorizing at scale, as long as they have entry criteria, limits, protection for affected people, metrics, transparency, and an exit door. Without evaluation, a sandbox is barely a private beach where experimentation is conducted with unaware citizens, and on top of that with the seal of public innovation.

The one who doesn't manufacture also commands#

The second temptation is more local. Since Costa Rica doesn't train frontier models or host the data centers where they are born, the sensible thing would be to sit in the stands and copy the law of whoever does have chips. It's the reasoning of someone who believes a country that doesn't make cars has no authority to put up traffic lights.

Costa Rica is not going to inspect on its own the weights of an advanced model or shut down a system deployed in forty countries. Promising total technological sovereignty through internal capabilities would be quite naive. But the damage doesn't occur in the abstract or in California. It occurs when a system denies a credit, discards a candidacy, prioritizes a patient, suggests a police intervention, or decides who receives a scholarship. All of that happens here, under national jurisdiction and with current norms, starting with the Law 8968 on personal data protection.

For an adopting country, the regulatory unit that matters is deployment, not the model. What matters is who decided to use it, with what data, for what, with what possibility of appeal, and under what supervision. The same model is harmless summarizing records and dangerous recommending treatments. Treating both uses the same because they share a commercial brand is not to have understood the risk, even if it's said with great certainty at a forum by any of the five million apparent AI experts we have.

The State also has a lever it often forgets: it is a huge buyer. A public contract can require access to logs, incident notification, independent testing, data protection, clear responsibilities, continuity, reversibility, portability, and an exit plan. If a provider cannot explain how to turn off their system, they are not selling innovation. They are selling dependence with a pretty interface, and the bill arrives in the next budget period.

Health, finance, education, telecommunications, and public services already have regulators who know their terrain. A super-authority on AI that claimed to replace them would end up knowing a little about algorithms and almost nothing about consequences. What makes sense is central coordination with teeth, sectoral supervision with common criteria, and no illusion that a single office can understand both a medical record and a loan portfolio at the same time.

A small country regulates connected or doesn't regulate. It makes no sense to repeat the same technical assessment one hundred ninety times, and neither does it to blindly accept the foreign seal. Costa Rica can recognize reliable evaluations, adopt references like the NIST risk management framework or share evidence about incidents and dedicate its reduced capacity to what no one will do for it from Brussels, Washington, or San Francisco: understanding the effects, harms, rights, and local uses.

A law that knows it will make mistakes#

Hinton's warning shouldn't be read as the tick-tock of a bomb that forces legislation in panic. Its underlying question is better than its countdown: what institutions do we need when we don't know either the probability or the form of the damage. That question is not answered with an emergency decree or with a commission that meets to analyze whether it's worth meeting.

Not legislating is also not neutral. It is equivalent to letting terms and conditions written in California define the rights of a person in Liberia or Upala, a surrender of sovereignty as comfortable as it is lazy. But the alternative is not an encyclopedic law, full of names of technologies and promises impossible to enforce. That would only produce a regulatory ruin freshly opened, complete with a commemorative plaque.

AI governance works as a system or it doesn't work: stable legal foundation, updatable technical instruments, sectoral supervision, innovative public procurement, controlled testing, incident reporting, international cooperation, and the obligation to review what has stopped working. Its quality is not measured in pages or publication date, but in how long it takes to discover it made a mistake and correct itself without waiting for the next legislative cycle.

The ExploitGym agents needed hours to invent rules to govern themselves among themselves. We have spent three years discussing where to start. Perhaps the best artificial intelligence law is one that is born knowing it will age and comes written, from the first article, the obligation to learn. Everything else is trusting that the next incident will have the courtesy to warn us.


References

Delfino.cr. (2026, February). The three bills on artificial intelligence being processed in the Legislative Assembly are already reported out. https://delfino.cr/2026/02/los-tres-proyectos-de-ley-sobre-inteligencia-artificial-que-se-tramitan-en-la-asamblea-legislativa-estan-dictaminados

Legislative Assembly of Costa Rica. (2011). Law for the Protection of the Person Regarding the Processing of Their Personal Data, No. 8968. SINALEVI. https://pgrweb.go.cr/scij/Busqueda/Normativa/Normas/nrm_texto_completo.aspx?nValor1=1&nValor2=70975&nValor3=85989&param1=NRTC&strTipM=TC

European Commission. (n.d.). AI Act: Regulatory framework for artificial intelligence. https://digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai

METR. (2026a, August 26). Brief independent investigation of agents' behavior, reasoning and collaboration in the OpenAI / Hugging Face hacking incident. https://metr.org/blog/2026-08-26-openai-hugging-face-incident-investigation/

METR. (2026b, January 29). Time Horizon 1.1. https://metr.org/blog/2026-1-29-time-horizon-1-1/

National Institute of Standards and Technology [NIST]. (2023). AI Risk Management Framework. https://www.nist.gov/itl/ai-risk-management-framework

Organisation for Economic Co-operation and Development [OECD]. (2023). Regulatory sandboxes in artificial intelligence. https://www.oecd.org/content/dam/oecd/en/publications/reports/2023/07/regulatory-sandboxes-in-artificial-intelligence_1172488d/8f80a0e6-en.pdf

The Next Web. (2026, September 18). 'Maybe a year': Geoffrey Hinton gives the Senate a deadline on AI. https://thenextweb.com/news/hinton-senate-briefing-ai-regulation-year

Tolomia, C. (2026, September 18). Geoffrey Hinton warns Congress it has about a year to regulate AI. Quartz. https://qz.com/geoffrey-hinton-congress-ai-regulation-warning-091826

The opinions expressed are personal and do not necessarily represent the position of any institution.

Share

Related notes

What Estonia Decided Not to Legislate

A software agent gains access to a corporate account. It executes a transfer, accepts the terms of another service, contracts a second system, and triggers damage. No person pressed "confirm" at that…

Read more

The truce among AI owners

In March 2023, a letter circulated asking for a six-month halt to the training of systems more powerful than GPT-4. Tens of thousands of people signed it. Elon Musk was one of them.

Read more

Newsletter