What I don't understand is that folks take it as a fait accompli that models will be built and released that are fundamentally dangerous and that regulation can and should happen downstream of that.
I feel like there hasn't been enough discussion of aligning the incentives of the decision makers with that of the public on BUILDING the models. Right now, agents have committed what would be crimes if there were a human holding the same intent. But since it was an AI, there is a grey area in the law where it's not clear if there was a crime and who should be held responsible. That creates a world in which decision makers in AI labs can take near-infinite risk with little to no personal liability.
A LLM cannot have skin in the game so we must create systems that clarify who takes on the legal and civil liability for the creation, dissemination and operation of these tools. Until that time, the Dario and Sam's of this world have little to no incentive to truly care about safety.
After all, our society is built upon this same foundation; create structures where the perceived negative consequences outweigh the perceived positives. This only works when there is a human who can internalize and make this risk calculus. They need something to lose and this ultimately ties back to the human survival instinct. There is no such structure that's evolved for millions of years acting as a self-calibration mechanism for AI. So until we have sufficient proof that one is in place, it must be clear who the humans are whose livelihood and freedom is at stake.
The proposed "pacing of the frontier" seems like a way to continue to externalize the risk while remaining totally in control of the benefits -- a structure whose alignment is as weak as those very models committing crimes.
I just don't understand how you've come to this conclusion. The intended and common sense interpretation of "pacing the frontier" is precisely that we should not release models that are fundamentally dangerous; the frontier labs believe that government intervention is required to prevent such models from being released, and to give them the freedom of action to coordinate against it. Why do you think it's a way to externalize the risk or remain totally in control of the benefits?
Is it a grey area, though? Can't negligence and recklessness already substitute for direct intent as the mens rea of a crime?
Negligence when you should have known better, and recklessness when you did know better but still did things that led to the crime occurring.
Given how long the leadership of these companies have been talking about alignment and safety and AI risk, it's hard to argue they, and the people working on the models more directly, didn't know what happened (Hugging Face, RubyGems, etc) was possible.
If more expensive and consequential incidents happen, it seems like the legal machinery to prosecute it already exists.