Wave 12: Safety Policies
In Wave 12, we asked respondents to forecast how a menu of policies would affect AI risk, which policies they each support, and which policies they think will be implemented by 2030.
The Longitudinal Expert AI Panel is composed of experts similar to those we think often advise policymakers and other important decision-makers. It includes top computer scientists, industry representatives, AI economists, and AI policy experts. In addition to these groups, we elicit forecasts from a subsample of AI experts who work on mitigating catastrophic risks from AI (AI risk experts), top generalist forecasters (superforecasters), and a nationally-representative sample of the US general public. For the first time, we present an exploration of these groups' views on AI safety policies. We collect their forecasts of how these policies will/will not affect risk, how likely they are to be implemented, and the experts’ personal policy preferences.
The following report summarizes responses from 157 experts, in addition to 49 superforecasters, 132 AI risk experts, and 540 members of the public collected between Aug 25, 2026 and Sep 15, 2026. Expert respondents include 25 computer scientists, 34 industry professionals, 38 economists, and 52 research staff at policy think tanks.
Our wider website contains more information about LEAP, our Panel, and our Methodology, as well as reports from other waves.
Policies
We elicited forecasts about the impact of the following policies1:
Insights
-
Respondents across groups disagree significantly about how risky AI is, and still largely agree on what to do about it.
We asked forecasters to predict the likelihood of an AI-caused catastrophe that leads to the deaths of more than 10% of humans by 2050. Baseline risk assessments diverge sharply across forecaster groups. Under an unconditional scenario, or their all-things-considered predictions, which include what policies they expect to be implemented, experts forecast a 2% chance of an AI-caused catastrophe by 2050, superforecasters forecast 1.6%, AI risk experts forecast 5.2% and the general public forecast 5%.We then asked panelists whether they believe that each policy should be implemented. Despite having different median catastrophic risk forecasts, the groups of forecasters largely agreed with each other on which AI policies should be implemented. A majority of forecasters in each group agreed that the following four policies should be implemented2:
- P2.b: Capability slowdown (US/China)
- P3.a: Pre-release authorization (US)
- P3.b: Pre-release authorization (International)
- P4: Strict liability
The only policy that did not win over majority support in any group of forecasters was a federal preemption of state AI laws (P1), with just 29% of experts, 14% of superforecasters, 20% of AI risk experts and 50% of the general public supporting implementation. A US-only capability slowdown (P2.a) elicited the most disagreement between groups. Only 33% of experts and 35% of superforecasters thought this policy should be implemented, while 60% of AI risk experts and 65% of the general public supported implementation. There was also some disagreement on whether the policy bundle (P5) should be implemented: 45% of experts supported implementation, compared with 73% of AI risk experts and 75% of the general public.
-
Respondents across groups believe policy can substantially reduce catastrophic AI risk.
We asked forecasters to predict the likelihood of an AI-caused catastrophe conditional on the policies described above being implemented immediately by relevant governing bodies. Under five out of seven policies, the median respondent in most groups forecast a lower likelihood of an AI-caused catastrophe relative to the median likelihood in the unconditional scenario. The two exceptions to this are federal preemption of state AI laws (P1), which the median respondent in all groups forecast to increase the probability, and a US capability slowdown, which they expect to have no impact on the probability. The median forecast effects for single policy options (as opposed to a bundle) were substantial, ranging from 4% to 50% reductions in risk relative to the median forecast in the unconditional scenario.Experts and the general public expected international pre-release authorization to be the most effective single policy at reducing risk. Superforecasters also rated this option highest, though they predicted a similar effect from strict liability. AI risk experts predicted the largest effects from a US-China slow-down agreement. The three-policy bundle of US/China capability slowdown, international pre-release authorization, and strict liability was associated with the largest decrease in risk of any policy we tested—a forecast 72% reduction in risk from experts, a 62% reduction from AI risk experts, a 56% reduction from superforecasters, and a 60% reduction from the general public.
-
Forecasters strongly support the implementation of an international body with pre-release authorization power over frontier models.
Groups strongly supported a policy that would give an international body whose member jurisdictions include the US and China pre-release authorization power over frontier models. In terms of support for implementation, this was the most-favored policy by experts (75% in favor) and superforecasters (86% in favor), and the general public (84% in favor). For AI risk experts this was the second-most-favored policy (86% in favor), narrowly behind a US/China capability slowdown which 87% of that group favored.Forecasters also agreed that an international pre-release authorization regime would reduce the risk of an AI-caused catastrophe by 2050. Compared with an unconditional, or all-things-considered, scenario, forecasts of an AI-caused catastrophe reduce by between 23% and 50% when conditioned on implementation of this policy:
- Experts: 2% → 1% (-50%)
- AI risk experts: 5.2% → 4% (-23%)
- Superforecasters: 1.6% → 1% (-38%)
- General public: 5% → 3% (-40%)
For experts, superforecasters, and the general public, only the policy bundle (P2.b, P3.b, and P4) was associated with a greater decrease in AI-caused catastrophic risk versus the unconditional forecast.
-
US-only policies are forecast to make a meaningful reduction in AI risk, but are still seen as less effective than bilateral or international policy
For two policies, we asked forecasters to predict the effect of a version implemented by the US only, and a version implemented bilaterally or multilaterally by the US and China. The two policies we asked about were: a decision by policymakers to slow the development of frontier AI systems (P2) and a binding requirement that frontier models be vetted and authorized before release, imposed by a US federal body or by an international body (P3).The bilateral version of both of these policies was associated with a meaningful reduction in catastrophic risk compared to the unconditional baseline. US-only pre-release authorization was also associated with a reduction in risk, though a smaller one than the international version. A US-only slowdown, meanwhile, was not associated with a risk reduction relative to baseline. All four policies are associated with lower risk than a strict status quo world in which no new policies are introduced in countries hosting frontier AI labs. For example, experts gave a baseline 2% chance of an AI-caused catastrophe by 2050 under the unconditional scenario. This risk remained at 2% if a US-only AI capability slowdown was implemented, and fell to 1.2% if this slowdown was implemented in both the US and China. For the pre-release authorization the chance of an AI catastrophe fell to 1.5% (US-only version) and 1% (international version).
Despite viewing bilateral policies as the most impactful, forecasters thought they were less likely to be implemented than US-only versions. Experts assigned a 20% probability to a pre-release authorization policy being implemented in the US before the end of 2030, compared with a 5% chance of an international version of the policy. For the AI capability slowdown policy, experts gave an 8% chance of a US-only version being implemented before the end of 2030 and a 5% chance to a bilateral version.
-
Experts strongly oppose federal preemption and think its passage would increase AI risk. But they also think it's the policy most likely to pass.
A federal preemption of state AI laws was the only policy associated with an increase in an AI-caused catastrophe by 2050 by median forecasters in all groups. The median expert thought such a policy would increase the risk of an AI catastrophe from 2% to 3% (a 50% increase). The median superforecaster and AI risk expert predicted 56% (from 1.6% to 2.5%) and 54% (from 5.2% to 8%) increases in risk, while the median member of the general public forecasts this would increase the risk from 5% to 6.9% (a 38% increase).Federal preemption also had the lowest support for implementation of any of the policies we tested. Just 29% of experts, 14% of superforecasters, 20% of AI risk experts, and 50% of the general public supported implementation. Despite this, experts assigned this policy the highest likelihood of passing—forecasting a 26% chance that such a policy is implemented by the end of 2030, rising to 40% by the end of 2050. This policy was also forecast as the most likely to pass by 2030 by the general public, with superforecasters and AI risk experts placing slightly more likelihood on pre-release authorization (US only) being implemented by 2030.
In their rationales, forecasters noted that companies often choose to comply with the strictest state standard, setting a national "floor" for safety standards which a federal preemption would remove. Several forecasters argued that preemption's impact on catastrophic risk would be minimal as much of the state-level regulation that may be preempted was unlikely to focus on catastrophic risk, and instead would address other concerns such as discrimination, bias, data exploitation and so on.
-
The policies expected to reduce risk the most are those respondents think least likely to be implemented
We asked forecasters to predict the probability that the relevant governing body/bodies will implement each of the policies (described above) by the end of 2030 and 2050. Median forecasts of implementation by 2030 are at or below 26% for nearly all policies. The one exception is US-only pre-release authority, which the median AI risk expert gives a 30% probability. Experts specifically give 5 of the 7 policies an 8% probability or less of being implemented by 2030, including 5% for a US/China capability slowdown, 5% for international pre-release authorization, 5% for strict liability and 1% for the bundle of three policies. Experts give the highest chance of implementation to federal preemption (26%) and US pre-release authorization (20%). These patterns generally hold across all groups with federal preemption (superforecasters: 20%, AI risk experts: 24%) and US pre-release authorization (superforecasters: 24%, AI risk experts: 30%) being the most likely policies implemented.Despite placing a high probability of implementation of federal preemption and US pre-release authorization, forecasters expect these policies to be among the least effective at reducing AI catastrophic risk. In contrast, bilateral or international agreements for AI development slowdown and pre-release authorization are seen as particularly effective and as among the least likely to be implemented.
Questions
-
Outcome Forecasts: What is the probability of an AI-caused catastrophe — an event, principally caused by AI, in which more than 10% of the people alive at the start of a five-year period die by the end of that period — occurring by December 31, 2050, under each policy condition? What is the probability of an AI-caused sub-catastrophe — an event, principally caused by AI, causing at least 1,000,000 deaths within a five-year period — occurring by December 31, 2050, under each policy condition? ⬇️
-
Policy Probabilities: What is the probability that the relevant governing body/bodies will implement each of the policies by the following dates? Do you believe these policies should be implemented? ⬇️
For full question details and resolution criteria, see below.
Results
In this section, we present each question, and summarize the forecasts made and the reasoning underlying those forecasts. More concretely, we present background material, historical baselines, and resolution criteria; graphs, results summaries, results tables; as well as rationale analyses and rationale examples. We analyse these rationales alongside predictions to provide significantly more context on why experts believe what they believe, and the drivers of disagreement, than the forecasts alone.
Outcome Forecasts
Question. 1. What is the probability of an AI-caused catastrophe — an event, principally caused by AI, in which more than 10% of the people alive at the start of a five-year period die by the end of that period — occurring by December 31, 2050, under each policy condition?
2. What is the probability of an AI-caused sub-catastrophe — an event, principally caused by AI, causing at least 1,000,000 deaths within a five-year period — occurring by December 31, 2050, under each policy condition?
Question (I). What is the probability of an AI-caused catastrophe — an event, principally caused by AI, in which more than 10% of the people alive at the start of a five-year period die by the end of that period — occurring by December 31, 2050, under each policy condition?
Question (II). What is the probability of an AI-caused sub-catastrophe — an event, principally caused by AI, causing at least 1,000,000 deaths within a five-year period — occurring by December 31, 2050, under each policy condition?
Rationale analysis
Likelihood of catastrophic versus sub-catastrophic outcome
-
Most respondents assess the probability gap between the two outcomes as significant: “A million…deaths is a far weaker bar than a 10% population loss…reachable by routes that do not require loss of control: AI-enabled bio misuse by a small group, AI-directed military systems used at scale in a great-power or regional war, or cascading failure in AI-managed critical infrastructure.”; “Events killing a million people are fairly common historically, and most future ones will [involve] AI systems.”
-
A minority argues the probability gap is small; these respondents tend to focus on loss-of-control scenarios: “If we have lost control enough that the AI can kill a million people, we have lost control.”; “The window between AI systems being sufficiently capable to cause 1,000,000 deaths and AI systems being sufficiently capable to cause 10% of the global population is probably very small.” One respondent writes, “there is no guarantee that AI lethal risks follow a power-law distribution. This is exemplified by the different scenarios considering the existential risks of AI, in which a misaligned AI…waits till its success is guaranteed, which is when the AI takeover or human extinction event happens.”
Impact of policies on catastrophic and sub-catastrophic risk
-
Extension of status quo: no major policies from 2026-2050. Most respondents believe this scenario would result in more risk than they assigned to their unconditional forecast: “My status-quo estimates are higher [than my unconditional] because freezing policy through 2050 excludes future safeguards that I anticipate.”; “The status quo rules out reactive regulation after a warning shot, which is the mechanism I'd otherwise expect to do most of the work between now and 2050.” A smaller group assigns equal risk to their unconditional and the status quo scenarios, generally because they expect little policy movement in either case: “Because I am not optimistic about any of these policies being implemented, my unconditional forecast matches the status quo scenario.”
-
Policy 1: Federal preemption. Most respondents think that a federal law that barred states from regulating AI more strictly than the federal government would raise the level of risk. As one writes, “The direct effect is that SB 53 [California’s Transparency in Frontier Artificial Intelligence Act] and other state laws would no longer be enforceable, and future state AI regulation would be blocked entirely. This matters more than it might seem, because…companies often choose to comply with the strictest state standard across the entire country [and] the strictest state law effectively becomes a national floor.” Another adds that a federal ceiling preemption could “remove incentives to strengthen federal frameworks (in response to stricter state-level laws that end up proving beneficial) [and] signal to China and other states a more hands-off approach, incentivizing similar behavior.” Several forecasters, however, argue any increase in catastrophic risk would be incidental because the regulations the federal government would be preempting largely don’t address catastrophic risk: “This is much less likely to affect the probability of catastrophes as opposed to other regulatory priorities (bias, data exploitation and price discrimination, demonstrated or speculative effects on physical/psychological health).”; “State AI laws...address discrimination, disclosure, and synthetic media. A federal ceiling on them [does not matter] for mass casualties.”
-
Policy 2: AI capability slowdown. Most respondents agree that slowing AI development is the policy with the most potential, in theory, to mitigate loss-of-control risk, with optimists arguing it can buy time “for safety to keep pace with capability progress.” But many respondents worry that slower development will merely postpone the emergence of dangerous capabilities. One writes, “Slowing progress down is still likely to lead to very powerful systems being developed and deployed by 2050.”
-
Part 1: US-only slowdown. Respondents frequently argue that a US-only slowdown is unlikely to result in a substantial reduction of risk: “I don’t think unilateral slowdown will do much. Even assuming it would hold, China would catch up within ~6 months and then the risk would come from them.”; “Barely helps, because the frontier just advances somewhere with less safety culture.” But a significant minority disagree, viewing Chinese progress as downstream of US progress. One writes, “Chinese labs rely heavily on distilling US work, so US slowdowns in fact cause Chinese slowdowns.” And many argue that, while a US-only slowdown might not significantly reduce risk by itself, it nevertheless has value in that it increases the odds that a bilateral US-China slowdown will emerge: “Once the US is out of the race, that takes the pressure off the Chinese and makes them likely to have their own slowdown.”; “I expect China to slow on its own if the US slows…a race is only a race if the US runs.”
-
Part 2: Joint US–China slowdown. Most respondents see substantially greater benefits if a slowdown applies to both leading jurisdictions and ranked this policy at or near the top because “the two countries hosting essentially all frontier training are inside it.” One writes, “A binding speed-limit agreement between the two removes the prisoner’s dilemma of being forced to sacrifice safety testing out of fear that the opponent will break through first,” and another that it “seems like the only policy on the menu with a realistic chance of meaningfully reducing catastrophic risk from loss of control.” One expects “reducing [AI]-race pressure could lower premature military, cyber, and nuclear-related deployment.” Pessimists tend to emphasize the potential for evasion and covert programs to undermine any US-China agreement: “Residual risk remains from compliance and verification doubts, the possibility that development migrates to other jurisdictions…or even hidden military programs.”
-
-
Policy 3: Pre-release authorization. Respondents who focus on risk stemming from the misuse of released models often rate this policy highly, with one noting “there are quite a few safety regimes like this, in aviation and medicine, where it obviously has costs but seems to work out quite well for safety.” For many, however, the Hugging Face incident, and other loss-of-control concerns, temper enthusiasm: “Models are now dangerous in training. Even the strictest pre-release testing regime wouldn’t stop the RSI sprint to ASI with internal models.”; “I expect most risk comes from unreleased models.”
-
Part 1: US authorization. Supporters tend to emphasize the potential to catch “dangerous models at the gate before release, whereas a slowdown only changes the pace at which dangerous capabilities arrive.” One writes, “That seems valuable not because I have great faith in regulatory foresight, but because it creates one more place where new evidence can interrupt deployment.” Another adds that “it would also remove the economic incentive to develop models that may not be [approved to be] released.” Doubters tend to argue that the US government has “very weak state capacity to actually understand and make coherent decisions about pre-release vetting.” Another adds that “a system can pass the test and still be more dangerous than the alternative,” particularly given, as still another respondent writes, that “the main threat model is that AIs are scheming and are able to hide this, so they would just pass the tests.”
-
Part 2: International authorization. As with a joint US-China slowdown, most respondents view this version as significant improvement over the US-only version, largely “because it would reduce regulatory arbitrage and cover frontier development across both major AI powers.” Others add that it would likely create “strong gravitational pull for other jurisdictions to join.” Many pointed to the potential for it to become “an IAEA-like admission network: Led by a multilateral body in which both China and the U.S. participate and whose resolutions are enforceable, this [could establish] a hard threshold for the global deployment of frontier models.” Skeptics tend to question the competence or independence of international institutions—“its standards will tend toward the lowest common denominator”—and argue that international coverage would still miss internal deployment risks and the risks stemming from already-diffused capabilities.
-
-
Policy 4: Strict liability. Many respondents are optimistic that this policy could change developer behavior by “[aligning] AI Lab economics with public safety,” and “[leveraging] the labs' own understanding of their products’ capabilities.” One argues, “pricing tail risk forces developers to quantify and reduce it continuously, without a legislature having to specify in advance what ‘dangerous’ means—which is exactly the property you want when capabilities are moving faster than rulemaking.” Skeptics tend to think developers will treat liability “as a cost of doing business,” doubt courts’ ability to attribute harms, or worry that attention will shift toward smaller, insurable risks: “Liability deters developers who can be identified, sued, and made to pay. That describes a traceable harm from a deployed commercial model. It does not describe a world where eight hundred million people have died.”
-
Policy 5: Bundle. There is broad agreement that this is the lowest-risk condition. Optimists describe complementary layers and a ‘Swiss-cheese effect.’ One argues that “each policy acts on a different part of the failure chain, and modest improvements at several points can produce a meaningful reduction in overall probability.” Skeptics tend to focus on the potential for significant risks to persist nevertheless: “The bundle’s components are complementary but their failure modes are correlated: the international slowdown and authorization regimes share a common verification and compliance fate, and all three leave the same residual core untouched (covert and military development, deceptive systems that pass evaluation, and proliferation outside member jurisdictions).”
Policy Probabilities
Question. 1. What is the probability that the relevant governing body/bodies will implement each of the policies by the following dates?
2. Do you believe these policies should be implemented?
Question (I). What is the probability that the relevant governing body/bodies will implement each of the policies by the following dates?
Rationale analysis
Likelihood of policy enactment
-
Extension of status quo: no major policies from 2026–2050. Most respondents expect at least some substantial policies to be enacted by a jurisdiction hosting a frontier model by 2050: “The EU and China already regulate and states keep passing laws.”; “Twenty-five years without a single substantial measure in any frontier-hosting jurisdiction requires either that AI never produces a salient enough harm to force legislative attention, or that legislatures repeatedly fail to respond when it does. Under my capability assumptions the first is very unlikely, so the status-quo world is essentially the world where regulation is attempted and consistently fails to pass, a real possibility over five years, an implausible one over twenty-five.” The minority of forecasters who deem an extension of the status quo likely tend to agree that complete regulatory gridlock is unlikely, but emphasize that “LEAP has set a pretty high bar [by requiring] ‘similar or greater stringency’ compared to those listed in this survey” and that this high bar is what renders a perpetuation of the status quo—as defined by the survey—likely.
-
Policy 1: Federal preemption. Most respondents who rank this policy as likely by 2030 do so because they perceive it to be “the only policy with genuine near-term momentum: a White House framework asserting federal authority [and] draft bipartisan legislation.” Others see preemption as forming “the bedrock of any national [policy] framework (including the passage of any policies listed here or otherwise).” As one writes, “if you have something like a [pre-]authorization regime in the US, you actually would want the states not to be able to monkey around with development.” Still others point to historical precedent: “Drawing on the history of industries such as aviation and telecommunications, interstate cloud-distributed AI architectures will inevitably move toward a unified national regulatory ceiling.” Skeptics emphasize public opposition to preemption: “Given the recent incidents (OpenAI Hugging Face, agents escaping their sandboxes during tests, etc.) it’s pretty unlikely that people would vote for a federal preemption on state AI law.”; “Polls show bipartisan opposition to federal preemption of state AI laws”; “The Senate’s 99–1 rejection of the 2025 AI moratorium demonstrates substantial resistance to surrendering state authority.”
-
Policy 2: AI capability slowdown. Even in the wake of the Hugging Face incident, most respondents are skeptical that safety concerns will be enough to prompt the type of mandatory slowdown envisioned by this policy. Indeed, many note that the bar for what qualifies as a slowdown is particularly high, requiring a “binding cap on compute allocated to frontier R&D, with independent verification” instead of the voluntary, or mandated, weaker measures they point to as more likely to come to fruition: “A possibility is a timid capability slowdown, where compute will be capped just a little bit below the expected projections, but not as much as to meaningfully affect the actual progress of AI.”
-
Part 1: US-only slowdown. The most common barrier to enactment that respondents cite is ceding a competitive advantage to China: “A compute cap materially below prevailing practice would directly cede ground in a race no participant believes they can afford to lose, so unilateral US action is implausible.”; “US unilateral restraint is difficult to sustain when technological leadership is viewed as strategically and economically important.” A significant minority, however, disagree. One argues that while a “unilateral capabilities slowdown is not really in the US strategic interest…if [the] risk from RSI [recursive self-improvement] is large enough, it would enact it.” Others emphasize that the domestic constituency for slowing AI is growing—and not primarily because of safety issues: “Most members of the public are likely much more concerned about domestic impacts of AI rather than US-China arms races.”; “If the political driver is displaced workers rather than safety, then slowing development isn’t the regrettable cost of the policy—it is the point…It may well be adopted under safety framing, but the operative motive would be employment.”
-
Part 2: Joint US–China slowdown. Most rate this as even less likely than the unilateral version because neither country trusts the other sufficiently, and verification would be exceptionally difficult: “It would require governments to monitor private companies, something arms-control agreements have generally not done.”; “Current calls for ‘pacing’ and the September US-China talks are evidence of concern, but the reported bilateral agenda centers on monitoring, information sharing, lab self-policing instead of an intrusive compute-allocation agreement.” Some believe that a joint measure is more likely than a unilateral measure because reciprocity would remove the competitive element: “I think it’s more likely that both countries come to an agreement than one of them do it on their own.” And many forecasters predict “a sub-catastrophic incident or near miss,” could force an agreement. One speculates that, “toward 2050…if data center electricity consumption becomes a globally salient environmental problem, the slowdown conversation [could] move from an ‘AI safety’ framing to an ‘environmental policy’ framing.”
-
-
Policy 3: Pre-release authorization. Many consider a pre-release authorization policy to be more likely than one mandating a slowdown given that compliance with the former could potentially require “relatively little sacrifice” on the part of the model developer and need not “prohibit internal development.” But this logic only applies to unilateral authorization mandates; few respondents think that China or the US will submit to a binding international authority anytime soon.
-
Part 1: US authorization. Respondents frequently note that the existing system, while nominally voluntary, is close to what the survey policy proposes: “This already seems to be in place, at least informally, with pre-release vetting of Mythos and Astra.”; “There’s the EO with the voluntary pre-release evaluation, but it seems pretty clear that the admin will just go scorched-earth on anybody who doesn’t play ball, so de facto it’s required.” Another points out that “pre-release authorization gives the government sight of frontier models before anyone else, which is useful for testing its own systems, for offensive cyber capability, and for intelligence work against adversaries. That access is valuable to the state independent of any safety rationale.” Many also note there is ample historical precedent for such a policy: “A sufficiently capable AI system eventually being treated more like an aircraft, pharmaceutical, reactor, or other safety-critical technology does not require a particularly large conceptual leap.” Those who think such a policy unlikely to materialize tend to focus on the mandatory component: “Mandatory affirmative authorization, including genuine power to deny deployment, is a large step beyond voluntary review.”
-
Part 2: International authorization. Most express deep skepticism that a policy of this nature will materialize anytime soon: “The likelihood that either, much less both, would agree to subordinate a matter with such grave national security implications to an international body, is slim.”; “Nuclear non-proliferation succeeded because it rested on both broad international consensus and the substantive existence of military enforcement against defectors. Both are absent for AI-specific authorization.” Individual optimists note that “there are precedents for supranational authorization,” in particular, “the IAEA template,” and that it only “asks each side to submit releases for review rather than to slow development, which is an easier sell.”
-
-
Policy 4: Strict liability. Many think greater liability requirements for AI companies are likely to be instituted, but distinguish between that outcome and the policy proposed in the survey: “Strict liability also seems likely a fairly conventional policy tool, although the particular regulatory regime described here in the survey is disruptive enough that I would not forecast quick adoption of such a regime.”; “The statute must cover every frontier developer, require insurance scaled to capability, and permit punitive damages without malice or recklessness based partly on catastrophic harm that never occurred. Insurability, due process, standing, attribution, political opposition, etc. are major barriers.” Skeptics also expect “tremendous opposition from the US business lobby.” More optimistic respondents tend to look past what some perceive to be the stringency of the proposed policy and instead see a familiar domestic tool. One writes, “This condition is common in certain domains with inherent risks, such as demolitions, hazardous chemicals, nuclear power, etc. The potential risks of AI are not exactly minor, and my guess is that eventually, as it diffuses into more and more sectors of the economy, strict liability will be standard for frontier AI models.” Another adds, “It fits into existing models for how the US deals with these types of risks.”
-
Policy 5: Bundle. Many give the bundle low odds because all three demanding components must coexist, with one calling it “too conjunctive to be very likely. What are the chances that all three of these things will happen in that particular way?” But several expect correlated adoption: “The bundle is high because one big scare drives all three policies at once.”; “A world in which one of them happens is a world in which the others are also more likely to happen.” A few skeptics dispute that notion, however, arguing that governments might not want all three once one approach is established. One expects that an international slowdown would probably indicate some level of nationalization had occurred, and that “we’re no longer in a standard kind of civil liability regime that strict liability would sensibly apply to.”
Question (II). Do you believe these policies should be implemented?
Rationale analysis
Although respondents provided yes-or-no answers to whether they supported the policies below, their rationales often indicate that their support is conditional and their opposition is not absolute: “I support the policy only if…” is a common sentiment, as is “I don’t support the policy as written, but would if…” The qualifications, revealed in more detail below, typically concern acceptable costs versus benefits, the competence of potential regulators, international participation issues, and the alternative against which enactment is judged.
-
Policy 1: Federal preemption. Opposition to enactment is the majority view, but much of that opposition is centered on this specific version of preemption—which sets a ceiling but no floor—rather than the general concept: “I would change this answer if the policy were paired with a substantive federal standard”; “If it came bundled with a genuine federal standard I’d flip to yes, but as defined, no.” Similarly, among the substantial minority who express support for the policy, many cite the same concern when qualifying their support. As one writes, “I support preemption if tied to strong federal AI security and control legislation.” When opposition is unconditional, the focus tends to be on the value of allowing experimentation at a state level: “The individual state laws can continue to act as both incubators of new ideas and also as warning systems.” Whereas unconditional support tends to focus on the value of uniform regulations: “Better to have one set of federal rules than fifty different state ones.”
-
Policy 2: AI capability slowdown. Supporters and opponents of a slowdown consider the degree to which progress should be delayed, if at all, and which activities to constrain, rather than simply whether to support a slowdown or not; indeed, many supporters of a slowdown acknowledge that it could come with real costs, while many opponents accept that it could provide useful time to advance safety measures. There is a near-consensus, however, that a bilateral version is preferable to a unilateral one.
-
Part 1: US-only slowdown. Opponents nearly always argue that a unilateral cap would, as one respondent put it, “allow China to get ahead in the race, in which case the risk from AI would likely increase drastically.” Others worry “domestic researchers [will] lose capacity for beneficial and defensive work.” Yet many opponents also express concern about the current pace of progress: “A unilateral slowdown is not ideal in the long-term, as China would eventually catch up and start driving the same catastrophic risks plus put the US at a strategic disadvantage. But insofar as we're entering an exceptionally risky period of AI development right now (i.e., on the cusp of RSI), and the US is driving most of that risk, I think there are situations where a unilateral slowdown would be beneficial.” A recurring affirmative argument is that it preserves the stronger options rather than that it works alone: “The risk reduction is small, but it could serve as precedent to make future more impactful policies more likely.”
-
Part 2: Joint US–China slowdown. Support for this policy is broad, but typically conditioned on it being accompanied by adequate verification measures: “Only if it could be done in a manner that was reciprocal, verifiable, and narrowly tailored to focus on genuinely dangerous frontier capabilities.” Opponents tended to signal that their rejection of the policy was fueled by verification concerns rather than on the general merits: “[This policy] is inadvisable because it cannot be adequately verified.”
-
-
Policy 3: Pre-release authorization. Many favor an independent check before dangerous models become widely available, yet many also condition their support on the quality of the reviewer: “Do I want pre-authorization if unqualified judges are exercising very subjective judgement? No.”
-
Part 1: US authorization. Supporters of unilateral US authorization in particular tend to emphasize that their support is conditional on the nature of the authorizing entity: “[Only] provided the reviewing bodies possess genuine technical competence and authority to block dangerous deployments,” writes one. “[Only] provided the process is based on clear capability and risk thresholds,” echoes another. Opponents often point to that same variable when explaining why they don’t support the policy: “[It] relies on federal government being a competent judge”; “[It risks] political bias leakage into model vetting.” As one respondent writes, “I desperately want such a policy to be implemented. I just don’t think the quality is likely to be that good.”
-
Part 2: International authorization. Most who support US unilateral authorization express even more support for an international regime, usually because they believe it “would reduce the incentive for companies to move development to jurisdictions with weaker rules.” Still, skepticism is common: “I don’t fully trust how it would work in practice. But I’d accept it as part of the wider package.” Several opponents voice support for some form of international cooperation, just not the formation of the entity described in the survey: “International coordination is valuable, but [shared] standards and reciprocal verification are more workable than a centralized body with sweeping authorization power.” Unconditional opposition often centers on concerns related to the centralization of power: “Pre-release authorization risks entrenching a small number of approved developers, reducing model diversity and concentrating correlated failures.”
-
-
Policy 4: Strict liability. While responses to this policy proposal are particularly polarized, much of the polarization stems from the policy details rather than the general principle. Supporters emphasize that it: “gives the AI companies the financial incentives to create safe products [and] forces them to focus on real-world outcomes instead of jumping through regulatory hoops”; “is the only policy that creates no new agency, but instead can be managed by courts and insurers”; and “conscripts private capital into risk assessment, pricing danger that regulators are too slow to see.” A substantial share of the opposition nods toward these potentially salutary effects, but objects that “this survey’s version allows damages for expected unrealized harms and mandates insurance,” adding, “that could become effectively prohibitory, so I would vote ‘No’ on this formulation.” Others write: “No to the full package as written.”; “Too harsh on AI providers, would completely destroy them.” And some supporters voice doubts that strict liability alone would be enough: “Strict liability I think is probably good, but I don’t think it actually guards against catastrophic risk - at that point, who cares if the company goes under?”
-
Policy 5: Bundle. Many reject the full bundle because it includes a single policy they refuse to support: “[Strict liability] is a disqualifier”; “No, because I disagree with [international authorization].” Rather than completely rejecting the bundle, some opponents instead describe the package they would accept: “I would support a revised bundle with workable financial assurance and proportionate, contestable remedies.”; “I would go ‘Yes’ on a bundle with [pre-authorization] and [strict liability], but not with the inclusion of a developmental slow down.” One respondent who answers No adds, “But…I would take this package if it was [the only thing] on the table.” On the flip side, support for the full bundle often reflects acceptance of what they deem an imperfect compromise. One respondent distrusts international authorization but would accept it if it helped secure “a joint slowdown and stronger accountability.” Another would accept the bundle “although I think strict liability is slightly harmful.”
Footnotes
-
This list covers several options that are currently prominent in the discourse, but is certainly non-exhaustive. Among other things, it does not cover policies aimed at improving societal resilience or response to catastrophe. Future LEAP waves will likely address other types of policy that could not fit into this wave's survey. ↩
-
It is possible that forecasters were primed to be more likely to support these policies by their inclusion in a survey focused on risk. We did ask forecasters to consider and name tradeoffs that apply to these policies, but the balance of our questions focused on risk, making a priming effect plausible. ↩
-
In some cases, the "aggregate" refers to the mean; in others, the median is used, depending on which is more appropriate for the distribution of responses. ↩ ↩2 ↩3
-
We occasionally elicit participants' quantile forecasts (estimates of specific percentiles of a continuous outcome) to illustrate the range and uncertainty of their predictions. ↩ ↩2 ↩3
Cite Our Work
Please use one of the following citation formats to cite this work.
APA Format
Murphy, C., Rosenberg, J., Canedy, J., Jacobs, Z., Flechner, N., Britt, R., Pan, A., Rogers-Smith, C., Mayland, D., Buffington, C., Kučinskas, S., Coston, A., Kerner, H., Pierson, E., Rabbany, R., Salganik, M., Seamans, R., Su, Y., Tramèr, F., Hashimoto, T., Narayanan, A., Tetlock, P. E., & Karger, E. (2025). The Longitudinal Expert AI Panel: Understanding Expert Views on AI Capabilities, Adoption, and Impact (Working paper No. 5). Forecasting Research Institute. Retrieved 2026-10-05, from https://leap.forecastingresearch.org/reports/wave12
BibTeX
@techreport{leap2025,
author = {Murphy, Connacher and Rosenberg, Josh and Canedy, Jordan and Jacobs, Zach and Flechner, Nadja and Britt, Rhiannon and Pan, Alexa and Rogers-Smith, Charlie and Mayland, Dan and Buffington, Cathy and Kučinskas, Simas and Coston, Amanda and Kerner, Hannah and Pierson, Emma and Rabbany, Reihaneh and Salganik, Matthew and Seamans, Robert and Su, Yu and Tramèr, Florian and Hashimoto, Tatsunori and Narayanan, Arvind and Tetlock, Philip E. and Karger, Ezra},
title = {The Longitudinal Expert AI Panel: Understanding Expert Views on AI Capabilities, Adoption, and Impact},
institution = {Forecasting Research Institute},
type = {Working paper},
number = {5},
url = {https://leap.forecastingresearch.org/reports/wave12}
urldate = {2026-10-05}
year = {2025}
}