With doomsday AI scenarios dominating the news, lawmakers are rightly concerned about reports concerning security breaches at major US AI labs, such as the OpenAI–Hugging Face incident and the many others reported in its aftermath.

As they consider potentially regulating frontier AI, they should focus any new legislation on the immediate, demonstrated risks from those incidents.

Post-incident reports show that the Hugging Face incident could have been mitigated or prevented by following longstanding cybersecurity best practices, like stronger sandboxing and monitoring.

Following these fundamental best practices would have prevented or substantially mitigated all of the incidents at AI labs that we currently know about.

Tying any new mandates to evidence-backed security protocols also protects the public without impeding future AI development.