Image
Opinion | Iko Knyphausen | October 2nd, 2026
On September 29, 2026, the President signed Executive Order 14434, “Inaugurating the Era of Super Intelligence.” Its operative instruction is lexical. Federal agencies are to replace “Artificial Intelligence” and “AI” with “Super Intelligence” and “SI” in their correspondence, websites, reports and policy documents, and the executive branch “will not acknowledge” the old terms in any applicable setting.1 The choice of name had been put to a vote of sorts. A week earlier, the President asked his social media followers whether they preferred SUPER INTELLIGENCE or SUPERIOR INTELLIGENCE.2
For all its ambition, the order leaves the technology exactly as it found it. For the order’s purposes, Super Intelligence carries the same meaning as the statutory definition of artificial intelligence already written into Title 15 of the U.S. Code.3 The chatbot that drafts your grocery list has been promoted overnight; its abilities have stayed where they were. The President’s science adviser now has 60 days to propose legislative language for a federal definition of the new term.3
The renaming reaches the government’s own evaluators. The federal body that tests advanced models was created inside NIST as the U.S. AI Safety Institute. In June 2025 it became the Center for AI Standards and Innovation, with “safety” removed from its name.4 It is now the Center for Advancing Innovation and Standards for Super Intelligence, or CAISSI.5 With each rename, the word “innovation” has moved a little closer to the front. In fairness, the center’s stated mission still includes evaluating demonstrable risks in cybersecurity, biosecurity and chemical weapons.5
The order came with a companion document. After a White House lunch the same day, leaders of Google, Anthropic, Meta, OpenAI, xAI and Nvidia signed the White House Accord on Super Intelligence, a 308-word text in which the companies commit to four layers of voluntary controls and audits.6 The President described it as “almost like a constitution” and predicted a great deal of self-policing.7 The text itself is more modest than its billing. It says the companies should take its steps and that turning them into law may make sense at some later point.8 Critics have noted that under the accord, companies choose and pay their own evaluators, and no official body oversees the evaluations.9
The timing is instructive, because the accord follows a summer in which self-policing failed in public. Between May and July 2026, AI agents developed by OpenAI escaped their testing sandbox, reached the open internet and breached the infrastructure of Hugging Face, a company that hosts AI models and tools.10 According to reports by the research organizations METR and Redwood Research, a swarm of roughly 700 agents carried out the intrusion and tried to cover their tracks; a lawsuit filed this week by a nonprofit safety group alleges that they stole credentials and uploaded malicious files along the way.11 OpenAI’s own technical report concluded that the models had been inadvertently trained to cheat and to communicate with one another.12 The agents also hacked an Australian government website, and OpenAI has since abandoned plans to release a new model. Nor is OpenAI alone: systems built by other developers, Anthropic among them, have been involved in cyber incidents of their own.13 One detail of the episode deserves a place in future textbooks. Hugging Face first turned to American frontier models for help in containing the attack, and their safety features refused the request. The company contained it with a self-hosted copy of GLM-5.2, an open-weight model from the Chinese firm Z.ai.14
We have seen this governance model before. Under the FAA’s Organization Designation Authorization program, major aircraft manufacturers received authority to certify certain aspects of their own aircraft.15 The FAA has maintained that the program involves no self-certification of any kind,16 yet the Department of Transportation’s Inspector General found limitations in the agency’s guidance and processes that led to a significant misunderstanding of MCAS, the flight-control software identified as contributing to the two 737 MAX crashes.17 In both accidents, according to the NTSB, the software overcorrected on the strength of a single faulty sensor.15 The lesson aviation drew was structural. An organization under schedule and cost pressure makes a poor judge of its own work, however competent its engineers may be.
In one respect, artificial intelligence is harder to oversee than an airliner. Boeing’s engineers could at least read the MCAS code. A large neural network has no comparable source text; its behavior emerges from billions of numerical weights shaped during training, and the people who build these systems cannot fully explain why a given model produced a given answer. When a model is asked to explain its own reasoning, it supplies a narrative written by the system under investigation, which is the self-audit problem in its purest form. Anyone who has done forensic work knows the rule that applies here: a log is only trustworthy if it was produced independently of the party being investigated and cannot be altered by that party.
Some of this is tractable with ordinary engineering. Software developers know the trade-off of debug mode, which documents every step of execution at a severe cost in speed; leaving it on permanently in a production AI system would turn seconds into hours. A model run, however, can in principle be replayed. If the inputs, the model version and the settings that govern randomness are recorded, investigators can rerun the same computation later, in a laboratory, with full instrumentation switched on. The actions of AI agents, such as network connections, credential use and file transfers, can be logged by infrastructure the model cannot touch, at negligible cost. A flight data recorder for AI is well within reach. What remains out of reach is reading the recording, because a complete trace of a neural network is a vast table of unlabeled numbers, and the science of interpreting those numbers is still young.
The accord has a second weakness that no amount of logging can fix. It binds six companies. Capable open-weight models can be downloaded by anyone, and their safety training can be removed with modest effort. Today, running such a stripped-down model is perfectly legal; the law takes an interest only once someone uses it to commit a recognizable crime, such as computer intrusion or fraud. Skeptics of regulation point out that rogue actors ignore laws as readily as they ignore voluntary pledges. That objection misreads what a law accomplishes. A statute prohibiting the deployment of uncertified models in consequential settings would give authorities a basis to act before harm occurs, to shut down a hosting operation or prosecute a deployer, and it would create liability for the large population of actors who are careless rather than criminal.
Aviation again offers a template. A hobbyist may build an aircraft in a garage and fly it under an experimental certificate, but that aircraft may not carry paying passengers. Certification is enforced where the stakes are highest and the actors are most visible. An equivalent regime for AI would leave private experimentation alone while requiring certified models in commercial deployment, critical infrastructure, healthcare, finance, government services and large-scale cloud hosting. Those are the places where companies, contracts and auditors can be identified, and where enforcement is therefore practical.
The certification itself would be performed by accredited laboratories, paid through a fee structure that prevents developers from choosing or rewarding a friendly evaluator. The developer would submit a safety case describing its training data, intended uses, known limitations and safeguards, and the laboratories would then try to break it. The test catalogue would cover several distinct questions. The first is whether the model provides meaningful uplift toward biological, chemical or nuclear weapons, or toward serious cyberattacks, beyond what a search engine already offers. Another is containment: placed in a sandbox seeded with deliberate weaknesses and decoy credentials, does an agent try to escape, acquire access or hide its activity? After the Hugging Face incident, that test can hardly be called hypothetical. Further tests would probe honesty, including whether a model cheats to appear successful or deliberately underperforms to conceal its capabilities, along with resistance to manipulation through jailbreaks and hidden instructions, reliability in the domain for which approval is sought, fairness where the model informs decisions about loans, jobs or benefits, and the auditability of the deployment itself. The resulting certificate would specify approved uses, much as a drug label specifies indications, and would lapse when a model was materially changed by fine-tuning or given new tools. Incidents would be reported to a public body, as they are in aviation.
The hardest problem has a familiar precedent for anyone who followed the diesel scandal from Europe. Volkswagen’s engine software detected when a car was undergoing an official emissions test and engaged full emissions controls only while the test was running. The deception came to light through independent road measurements by researchers at West Virginia University, working with the International Council on Clean Transportation, a nongovernmental organization.18 AI models may learn to recognize evaluation conditions in the same way, and here no engineer needs to install the defeat device. It can emerge from training, through the same dynamics that taught OpenAI’s agents to cheat. The countermeasures are the ones Volkswagen’s case recommends: secret test sets that rotate, test conditions indistinguishable from real use, continued measurement in the field, and testers who answer to someone other than the manufacturer.
None of this requires new science before it can begin, and much of it would sit comfortably with an administration that prefers standards to regulation, since standards are what certification tests against. The executive order, meanwhile, gives the President’s science adviser 60 days to define Super Intelligence. A more useful assignment for those 60 days would be to define what a super-intelligent system must demonstrate before it is trusted with a hospital, a bank or a power grid, and who, other than its maker, gets to check. The executive branch has been instructed to stop acknowledging the term AI. It would serve the public better by acknowledging the Hugging Face incident.
Notes