Staged Access and Liability for Dual-Use Artificial Intelligence
How should regulators combine staged access to a dual-use AI model with developer liability? I model a defender and an adversary searching for the same software flaws. After release, liability induces more defensive search but also makes the adversary search harder, limiting its effect on harm. Exclusive access removes this strategic response, so staged access and liability are complements in protection. Defensive effort rises towards the release date, making additional delay progressively less productive. Optimal evaluation windows are therefore bounded, and their response to greater harm saturates. Because defensive search uses real resources, the efficient liability rate can be below full internalisation of harm. That rate generally cannot induce the developer to choose the regulator's preferred release date, leaving a distinct role for a timing mandate.
-
-
Copy CitationJoshua S. Gans, "Staged Access and Liability for Dual-Use Artificial Intelligence," NBER Working Paper 35586 (2026), https://doi.org/10.3386/w35586.Download Citation