The Electronic Frontier Foundation has issued formal guidance to lawmakers cautioning against AI cybersecurity regulations built on speculative superintelligence scenarios, urging instead that any new rules be anchored in established best practices and empirical evidence. The organization's recommendation comes amid a surge in proposed legislation addressing AI safety, much of which frames cybersecurity threats around advanced AI systems that may not yet exist. The EFF argues this approach risks creating rules that miss current, demonstrable threats while imposing compliance burdens based on theoretical harms. Rather than starting from doomsday assumptions, the advocacy group contends regulators should build frameworks on existing security standards like NIST cybersecurity guidelines and CIS controls that have proven effective across industries.

The EFF's position reflects growing tension between different camps in AI policy circles. While some legislators and researchers emphasize existential risks from powerful AI systems, cybersecurity experts point out that immediate, measurable threats—such as adversarial attacks on deployed models, data poisoning, and inference manipulation—already warrant attention under conventional security frameworks. The organization has specifically cautioned against regulatory approaches that assume AI systems will behave in unpredictable or fundamentally alien ways requiring novel security paradigms. This stance aligns with cybersecurity professionals who argue that incremental improvements to existing practices address near-term risks more effectively than regulations premised on speculative future capabilities.

Technology companies have expressed cautious support for evidence-based approaches, though some worry that relying solely on established frameworks may underestimate novel vulnerabilities specific to machine learning systems. Industry groups have noted that AI introduces genuine new attack surfaces—model extraction, prompt injection, and supply-chain vulnerabilities in training data—that don't fit neatly into traditional cybersecurity categories. The debate highlights a fundamental challenge in AI policy: distinguishing between genuine emerging risks requiring new regulatory tools and hypothetical scenarios that may distract from near-term priorities. As lawmakers draft cybersecurity measures, the tension between precautionary principle and empirical pragmatism will likely shape what regulations ultimately emerge.