Staged Access and Liability for Dual-Use Artificial Intelligence
How should early defensive access to a dual-use AI model be combined with liability for harm? I model a bank and an attacker searching for unknown vulnerabilities in the bank’s software. The bank repairs what it finds; the attacker needs one finding to cause a breach. The policy analysis follows a regular equilibrium at sufficiently small initial exposure. A defensive window gives the bank time to remove opportunities before an attack begins, while liability determines how strongly it uses that time. Partial liability can be optimal even with a positive window: stronger incentives induce more defence, but anticipated repair also makes the attacker hurry, so the additional defensive expenditure can exceed the reduction in expected harm. Longer preparation calls for weakly higher liability because it allows stronger incentives to operate while the attacker is excluded. In the leading low-exposure problem, a long enough window makes full liability optimal, but the cost of delaying broader access can favour a shorter window with partial liability. Jointly choosing liability and timing yields withholding, staged access or immediate release. Greater availability value can justify both a shorter window and weaker liability. Common improvements in search productivity expand the circumstances favouring staged access, but need not lengthen exclusive access windows.
-
-
Copy CitationJoshua S. Gans, "Staged Access and Liability for Dual-Use Artificial Intelligence," NBER Working Paper 35586 (2026), https://doi.org/10.3386/w35586.Download Citation
-