
Loading summary
Charlie Bullock
The following podcast contains advertising to access an ad free version of the Lawfare Podcast. Become a material supporter of lawfare@patreon.com lawfare that's patreon.com Lawfair also check out Lawfare's other podcast offerings, Rational Security, Chatter, Lawfare, no Bull, and the Aftermath Heather is a nurse practitioner from UnitedHealthcare. We meet patients wherever they live.
Alan Rosenstein
During a house call, she found Jack had an issue.
Charlie Bullock
Jack's blood pressure was dangerously high. It was 217 over 110. So they got Jack to the hospital and got him the help he needed. He had had a stent placed in his heart, preventing a massive heart attack. If it wasn't for my guardian angel, I wouldn't be here. Hear more stories like Jack's at unitedhealthcare.
Alan Rosenstein
Benefits, features and or devices vary by plant, area limitation and exclusions apply.
Charlie Bullock
Vulnerability doesn't mean you have to be crying in front of people. Vulnerability can be just recognizing how you feel.
He Su Jo
For so many men, vulnerability gets mistaken for weakness. But why? And what's that misunderstanding costing us? On the latest episode of Mind if We Talk, a podcast from BetterHelp Host and licensed therapist, he Su Jo unpacks the pressures around masculinity and how those expectations can leave men feeling isolated, disconnected, and stuck. Whether you're working on redefining your relationship with masculinity, trying to make a change, or just want to better understand the men in your life, this episode is a must. Listen Mind if We Talk Is available now wherever you get your podcasts.
Charlie Bullock
Our legal system hasn't yet caught up to the rapid progress of this technology, and we haven't had a chance to decide whether that should be a violation of law or not. So we would still ideally like people to be able to report that kind of danger, substantial and specific danger as the language statute uses to public safety. That's the big thing that the statute does, is it fills that gap.
Alan Rosenstein
It's the lawfare podcast. I'm Alan Rosenstein, associate professor at the University of Minnesota Law School and research director at lawfare, with Charlie Bullock, senior research fellow at the Institute for Law and AI.
Charlie Bullock
I can't see downsides of this in terms of like being some huge giveaway to industry or something, right? It doesn't really benefit them in any concrete way. At most, it doesn't go far enough.
Alan Rosenstein
Today we're talking about the new bipartisan AI Whistleblower Protection Act, a Senate proposal that's designed to fill the gaps in existing law by protecting employees at artificial Intelligence companies who blow the whistle on the dangers of advanced AI. Before we get into the details of the bill, I want to start with some table setting. So first basic question. How do you define whistleblowing? Not necessarily as a legal matter, which we'll get into later, but just as the phenomenon that you think there needs to be some protections for.
Charlie Bullock
Yeah, essentially I view whistleblowing as the act of an employee, or as the case may be a former employee, or as the case may be independent contractor at a company reporting corporate wrongdoing, typically to the proper authorities. That's what whistleblowing is. So the core example would be you're an employee at a company, you notice that your company is violating the law and you report that to law enforcement. The idea behind whistleblower protections is that your employer shouldn't be able to punish you for that action.
Alan Rosenstein
In the development of AI, it's in its modern incarnation, let's say the last three or four years, what role has whistleblowing played in getting information public? How important has this actually been? Which is obviously a separate question to how important one might think it will be in the future.
Charlie Bullock
Yeah, the big example is the situation that occurred at OpenAI in 2024. In that situation, employees at OpenAI as they were departing from the company, were pressured, threatened with withdrawal of their vested equity, which was worth tons of money, you know, to sign these non disparagement agreements. These non disparagement agreements were super broad. So essentially it would have said, if you sign this, you can never say anything bad about the company again, even if it's public knowledge, indefinitely into the future.
Alan Rosenstein
And even if it's true.
Charlie Bullock
Even if it's true. Yeah, especially if it's true. Right. No doubt. But okay, so this, obviously employees weren't happy with this. Especially some of these employees were working on OpenAI's policy teams or whatever. They were concerned about AI safety. And so they, through a big fit, they published a call, an open letter, calling for a right to warn about Frontier AI. That got a lot of traction. A lot of important figures signed on to this and pretty much immediately that sparked political interest in it. Chuck Grassley, who's the senator who's behind this recent bill that's been introduced at the time, said, okay, we're looking into this. We're going to see if employees at AI companies need whistleblower protections. So that was the big example.
Alan Rosenstein
So I think that's a good example of how this issue sort of has come up. I guess I'm curious about whether there's been an example of actual whistle blowing. Now, maybe the answer is no, because these models aren't powerful enough to yet be dangerous. So there's nothing to blow the whistle about yet. Even if there might be, you know, imminently. But I'm just curious if in the past there has been someone who has not just wanted to blow the whistle, but felt pressured that they couldn't because of some contractual agreement, but actually did so about something. I mean, I seem to recall there was a Google employee who thought that Gemini was sentient. I don't know if that. I mean, is that an example of what you're talking about? It's an odd example in a certain sense.
Charlie Bullock
Yeah. So that would not be protected by the current law. Right. Because he was not referring to a law violation or a substantial and specific danger. Right. Which is kind of. I'm sure we'll get into this later, but that substantial and specific danger language is designed to filter out exactly this sort of thing. Right. Like sort of unfounded or vague worries about what future AI systems might do or something. Or in this case, yeah, the claim that Gemini was like, this was like early Gemini, I think this was like two years ago or something, right?
Alan Rosenstein
Yeah. This is when it barred or something. Even before.
Charlie Bullock
Not even a good model. Yeah, I think it was pre Gemini. So not even. Not even a good LLM by today's standards, or indeed by 2021 standards or whatever it was. But yeah, he was claiming that it was so good that it was sentient and worthy of moral consideration and so forth, which I think in retrospect was a ridiculous claim. But. But yeah, that was an attempt at whistleblowing at least.
Alan Rosenstein
Okay, so that's what whistleblowing is. So let's talk about why we might just, as a general matter, need whistleblower protections. Just naively, one might think that there's no problem here because generally speaking, I, as a private citizen get to say whatever I want. This is not like classified information. And so what is the problem that whistleblowers sort of, as a general matter get into that has created this array of whistleblower protections that. That we have or that we might want to buttress in certain circumstances.
Charlie Bullock
Right. So generally whistleblower is reporting corporate wrongdoing of some sort. Right. They can also report dangers, but typically, historically, it's been. It's been law violations. Right. The government is interested to know if companies are breaking the law. Obviously, companies don't like being reported for law violations because they've done something wrong. If there's a valid whistleblower complaint about them. And so in that situation, they might take retaliatory action against the employee. Right. Fire them is usually what happens. Right. You know, you, you reported us to the SEC for all the various security violations, security laws violations we did, and the frauds we committed. So we are going to fire you. And that obviously is a big disincentive to blow the whistle if you're going to get fired. You know, maybe society doesn't care too, too much about the individual employees like salary and whether they get a slightly worse job or better one. But of course the employee cares. So that's if they're affected by it. It's a powerful disincentive to blow the whistle, which is why it makes sense to protect them from that. I mean, obviously freedom of contract is a really important concept in American law, as you know. And so generally most employees in this country are at will, so you can fire them whenever you want for whatever reason, except. Right. Except if there's a specific statutory protection or something for it.
Alan Rosenstein
So it strikes me that there are actually maybe three distinct kinds of repercussions that a whistleblower could get. And I'm just curious how whistleblower law generally treats these. Right. So one possibility is the one you just talked about is just being fired. Okay. Another is that some benefit is contingent on you not whistleblowing. So the example you gave earlier about OpenAI employees needing to sign a non disparagement clause in order to get their equity vested. And obviously if they whistleblow, that's disparagement. And then they don't get their equity. Okay. That is not giving them a benefit, which is different than a punishment, but obviously it has similar incentive effects. And then there's the third, which is going after them, for example, violating trade secret law. Right. If the whistleblowing involves that. And I'm curious about the third, whether the law already recognizes an exception for whistleblowing. So by analogy, for example, you cannot defame someone if you say true things about them. Right. By definition, truth is a defense to defamation. So is, for example, whistleblowing a defense to otherwise applicable trade secret law?
Charlie Bullock
This is great. We've gotten right directly within the first, like three minutes of this podcast into the absolute deepest part of the weeds with this.
Alan Rosenstein
This is lawfare, baby.
Charlie Bullock
Lawfare, baby. Let's go.
Alan Rosenstein
This is law.
Charlie Bullock
This is the sort of very fine legal question that I spend tons of time thinking about and try to bring up because it's very technical. Deal. But okay, so Chuck Grassley, who is behind this bill, was also around when the Defend Trade Secrets act passed in I believe 2016. And the defend Trade Secrets act is the current like federal trade secret law. Right. It provides protections for trade secrets. It has a carve out for whistleblowers specifically. Now that carve out is limited to reporting about violations of the law. Right. Because that in a lot of, not all, but in a lot of whistleblower legislation, they only want to protect people who report violations of law. In this bill that's been proposed and in some other bills that exist. Right. For example, the Federal Whistleblower Protection act, which applies to federal employees, you are also covered if you disclose information about a substantial and specific danger to public safety or public health or national security, et cetera, et cetera. Statutory language. But one of the interesting things about this bill and one of the few criticisms I have of the bill that Grassley introduced is that it specifies that you cannot be punished for any lawful act that results in disclosure of information about, et cetera, et cetera. And so there's a real question about whether reporting information that involves trade secrets to the government about substantial and specific dangers to public safety is a lawful act or not because it is not covered by the language of the Defend Trade Secrets act exception. Now, there's reason to think that a judge might essentially say, okay, well this is a lawful act anyways for reasons of public policy. And the reason that we think that is because prior to the passage to Defend Trade Secrets act, it was already a crime or, you know, unlawful in various ways in, in many jurisdictions to misappropriate trade secrets. But there is some case law from before the DTSA saying essentially, sure, they misappropriated trade secrets technically, maybe, but we're not going to call that, we the court are not going to call that an unlawful act because they did it. To report a law violation in public policy dictates that we shouldn't allow to punish employees for that.
Alan Rosenstein
Okay, so this is actually a good segue into the kind of other background legal regime that exists, which is whistleblower protection laws. Right. So you mentioned that there's this whistleblower carve out in this trade secrets law. You mentioned that there's a federal whistleblower statute. Obviously there's the California has its own whistleblower law that I think is worth getting into in some depth because of course, all of the main research labs are in California and therefore that's going to be the primary jurisdiction here. So just talk me through what is the Current legal regime before we get to this proposed bill from Senator Grassley that would apply to AI Whistleblowing.
Charlie Bullock
Sure. So you've got a patchwork of overlapping federal laws, state laws, common law protections. And whether an individual whistleblower's actions are protected can be kind of complicated. Right. Federally, there is no overall background federal whistleblower protection law. Right. It mostly is left up to the states.
Alan Rosenstein
Do you know if, is that, do you know if that's a policy decision or, you know, might that even be a sort of a constitutional limitation? Like, I do wonder honestly, if, if Congress could even enact a super general whistleblower law under the commerce clause, that's.
Charlie Bullock
You would know more about that than me. I, I have always assumed in the course of researching this, over the last however long I've been working on this, that it would be possible to pass a general, a federal whistleblower law. I've seen people propose it, but I can imagine constitutional arguments against it for sure. Anyways, yeah, there's, there's no background federal statute saying you can't punish whistleblowers. And state laws vary. Some states have essentially no statutory whistleblower protection. New York, for example, is pretty light in terms of whistleblower protections. A lot of Republican states have, have very little because, you know, they value freedom of contract more strongly. They think, hey, if you sign this thing saying they can fire you for whatever, they can fire you for whatever. Right now, other states, including notably California, have much stronger whistleblower protections. California's is not the most robust, but it's up there. It's pretty, pretty strong as whistleblower protection laws go. It's section 1102.5 of the California Labor Code.
Alan Rosenstein
For those of our listeners who are following along, you open up your California statutory.
Charlie Bullock
Yeah, of course, I assume that all.
Alan Rosenstein
Of lawfare, this is the lawfare audience.
Charlie Bullock
After all, the greatest audience in the world. So what that says is that you can't discriminate or punish. It's funny, all these statutes, you know, you asked earlier about denying someone a reward versus firing them versus other kinds of punishment. They, they try to cover everything. And the way that statutes do this is with incredibly repetitive language. So the California statute is like you can't make, adopt or enforce any rule, regulation, or policy preventing an employee from, et cetera, et cetera. And then it covers all the things that you can't do to them. But what it does essentially is say that for reporting to a government agency or law enforcement agency information about any violation of any Federal, state or local law, rule or regulation. Right. So very comprehensive, but essentially reporting to the government a violation of some legal rule, you cannot punish or fire or anything. So that's what California has, and that's highly relevant. Obviously it's the primary current law that protects AI employees. Right. If they report a violation of the law, they, they can't be retaliated against for that, in theory, under California law.
Alan Rosenstein
So is California law kind of the only state law that really matters here? And the reason I ask is because, you know, it is true obviously that most of these companies, maybe, I think all these companies are headquartered in California, but they also some have operations in different places. Obviously they have different campuses in different states. They might have some remote employees. I mean, are there any other states where we should care what the laws are? I mean, I know like Google has a campus in New York. There's a big tech center in Texas. Obviously Washington has Microsoft. I'm just curious if sort of any other states are worth thinking about here.
Charlie Bullock
Yeah, I think California is the vast majority of what we're, of what we're concerned about. But I mean, you can imagine situations in which, yeah, an employee in New York discovers something important. Right. Remote worker. Right. Discover something important. And then whether the, the other states laws matter is a, is a question that depends on the individual state law. Like I've looked at, you know, I live in Illinois, I've looked at Illinois's whistleblower law pretty closely, and it's incredibly broadly phrased. On its face, it says like, it defines like employer, which is the, the, the regulated category, as anyone who employs any employee in Illinois. Right. So on its face, the Illinois statute looks like if you have any employees in Illinois, which I imagine most of these big companies do, I assume there's one Google employee in Illinois, then you are subject to this law. Now, of course, there are questions of personal jurisdiction and stuff like that. I haven't done the going through, like how that all would shake out. But there's, you know, it's at least plausible that other state laws would come up in the future. Also, you know, we don't know where all future AI companies will be located, so it's possible that some of them will be in states other than California.
Alan Rosenstein
We have this California law, and we wouldn't be talking about a federal law if we thought the California law covered all the issues. And so when you describe the California law, you identify two important scoping provisions there. One is that it only applies to whistleblowing about violations of law. And it also only applies to whistleblowing, that is communication to the government. So are those the two issues that in your view, and perhaps in the view of policymakers in Washington are deficient?
Charlie Bullock
Yeah, that covers most of it. I don't think the government thing is deficient in this context. I'm in favor of limiting it to reporting to the government in the AI context at least, because while there is value to making these things public, you can see why companies wouldn't want their valuable trade secrets and so forth disclosed just on the front of the page of the newspaper, right where their competitors can see it and so forth. So I think I am in favor of maintaining that limitation which the proposed bill does. Another thing to mention is that I may have slightly mischaracterized the California bill earlier. It also covers internal reporting within the company. So either either to your superior or somebody in the company who has authority over you or to the government, those are the two things. But you know, essentially the main, the main thing we're concerned about is reporting to the government. There are other things that matter as well, other than those two sort of scoping concerns. For example, the California bill doesn't do a perfect job of handling things like the OpenAI non competes. Right. Whereas the federal bill that's been proposed is much more clear on that question of whether that kind of thing is enforceable or not.
Alan Rosenstein
But just coming back to the California law then, is, is the main reason that this is in the public conversation because it is just too narrowly about violations of law. And there's just a lot of stuff that we might want to empower whistleblowers to communicate that is just not a violation of the law.
Charlie Bullock
Yeah, that's correct. Essentially that is the main focus of the new law. And the main reason that people are concerned about this is because AI is an emerging technology, it's very lightly regulated. And so, you know, it's very plausible that dangers could arise from some sort of truly transformative dual use technology that has all sorts of national security applications and stuff like that, that a danger could arise that wouldn't be a violation of the law. Right. For example, we can imagine that something like a more reasonable version of the Google report that we discussed earlier, somebody who's involved in safety testing at OpenAI or Anthropic or Google or whatever observes okay, during safety testing, ah, this new frontier model we have that's extremely capable, more than any we've seen in the past, is extremely good at helping people design whatever chemical weapons or something like that. Right. In Fact, it's really easy to jailbreak it and get it to give you, you know, allow bad actors to take these very dangerous steps. It's not necessarily clear that the company allowing it to do that and then publishing the model would be a violation of law. You could make the argument that it is, but it's not clear that it is because our legal system hasn't yet caught up to the rapid progress of this technology, and we haven't had a chance to decide whether that should be a violation of law or not. So we would still ideally like people to be able to report that kind of danger, substantial and specific danger, as the language the statute uses to public safety. That's the big thing that the statute does, is it. It fills that gap.
Alan Rosenstein
Okay, so let's now finally get into the law itself. So walk me through it. What are the main provisions of it? What does it purport to do? And just sort of give us. Give me your evaluation of whether or not it is aimed at the right thing and whether or not it accomplishes what it is aimed at.
Charlie Bullock
So the law is the AI Whistleblower Protection Act. It is sponsored by three Republican and three Democratic senators, the bipartisan group. There's a companion bill of the House that's sponsored by a Republican and Democrat. The chief sort of force behind it is Chuck Grassley, is the main sponsor of it, and he's been working on whistleblower stuff for a very long time. So this is right up his alley. The law essentially covers three different kinds of reporting and protects them. That's the main thing it does. The three different kinds of reporting are violation of any federal law. That's good. It's somewhat redundant, maybe, of the California statute that already exists, but it's good to have that at the federal level because there's different remedies you can seek in federal court versus state court and so forth. And also it's, you know, nationwide, as opposed to just specific to California. The second thing it does is it protects reporting about substantial and specific dangers to public health, public safety, or national security. So that's a fairly demanding standard. It has to be substantial and specific. It can't just be some vague future worry that you have. But if you do identify a substantial and specific danger arising from something to do with the development or deployment or whatever of one of these models, then that is protected. If you bring that up and report that to the government. The third thing it protects is reporting about AI security violations. This has been a pretty hot topic recently as well. The idea of lab security. The idea that we need to protect AI labs from having their model weights or their algorithmic secrets stolen by, for example, China or by bad actors here domestically. And so if you notice some big flaw in lab security that's going to allow China to steal the model weights of GPT5 or whatever, and this would be very dangerous and bad, then you can also report that to the government and that's covered as well. So that, that's, that's the main thrust of what the law does. In addition to that, it has a bit about the non enforceability of waivers of any rights in the law. So essentially what that means is stuff like the OpenAI NDA that we discussed earlier is unenforceable under this. Any sort of like workplace policy preventing you from talking about this stuff to the government is unenforceable with respect to these, you know, legitimate whistleblower complaints. And also anything like a arbitration agreement is unenforceable with respect to these. You have to be able to go to the Department of Labor first and then the courts, which is the sort of system of remedies that are set up is like if you get retaliated against for doing this first, you can make a complaint that's Department of Labor, and then if you know that doesn't get responded to in a certain amount of time, you can sue in district court. So that's sort of the outline of what the bill does.
Alan Rosenstein
Basically, who do you have to disclose to within the government? I mean, is it literally anyone in the government or is there like a specific point of contact? How is the reporting supposed to work for you to be able to get the benefits of this whistleblower protection?
Charlie Bullock
Yeah, they elected not to name a specific point of contact. I think a lot of decisions that were made about this bill were made in an effort to make it sort of as low friction as possible. Like it doesn't want to make big decisions about like which part of government is going to regulate AI, which has been a big question in the past for people who work on AI policy. It doesn't want to like, you know, if you designate a hotline, if you designate a government office that's going to receive these complaints or something like that, that's sort of committal and it requires the government to do stuff. The idea behind this bill in large part is that like it doesn't impose any obligations on anyone except the negative obligation of don't retaliate against employees for making these covered reporting things. So the people you can report to are, it says the appropriate regulatory official or the Attorney General, a regulatory or law enforcement agency, any member of Congress or any committee of Congress, or then as part of testimony or assisting in investigation and so forth for the Department of Justice, and so on and so forth. It also covers much like California law, reporting to people within your company who have supervisory authority over you, and so forth.
Jesu Jo
Ever feel like you're carrying something heavy and don't know where to put it down? Or wonder what on earth you're supposed to do when you just can't seem to cope? I'm Jesu Jo, a licensed therapist with years of experience providing individual and family therapy, and I've teamed up with BetterHelp to create mind if We Talk? A podcast to demystify what therapy's really about. In each episode, you'll hear guests talk about struggles we all face, like living with grief or managing anger. Then we break it all down with a fellow mental health professional to give you actionable tips you can apply to your own life. Follow and listen to Mind if we Talk on Apple Podcasts, Spotify, Amazon Music, or wherever you get your podcasts. And don't forget your happiness matters Skin.
Unnamed Advertiser
Care experts and dermatologists have often touted the benefits of indoor humidity as essential for healthy, glowing skin. But did you know dry air can start to harm your skin in as little as 30 minutes? For years, many people have relied on humidifiers for better skin, sleep and overall wellness. But traditional models bulky, mold, prone and difficult to maintain. That's where Canopy Humidifier comes in. Recommended by leading dermatologists, Canopy is a completely reimagined humidifier designed to elevate any space, offering the ultimate in skincare and wellness benefits. Canopy's clean moisture combats dryness, dullness and fine lines while strengthening the skin's barrier and boosting the effectiveness of topical skincare products. With its sleek design, Canopy is the cleanest and easiest humidifier on the market. With its unique technology, cleaning is as easy as popping it in the DishWasher. Go to GetCanopy Co to save $25 on your Canopy humidifier purchase today with Canopy's filter subscription. Even better, use code Podcast at checkout to save an additional 10% off your canopy purchase. Your skin will thank you.
Alan Rosenstein
You know that feeling when you clear your inbox or end a meeting early or finally check your pipeline and everything's actually under control. That's what Monday CRM feels like. It's fast, easy to use, and with built in AI, it helps you move faster without the busy work. Try it free@Monday.com CRM because sales should feel this good. Okay, so let's talk now about the scope of what it covers and the sort of substantial harm to public health and that sort of stuff. So that's obviously much broader than just violations of law. That's a good thing. But it could be broader and one might worry that it's not broad enough. So, you know, again, going back to the example we talked about earlier about, you know, what if you think that a model has become sentient and that it is suffering horribly, right, which you might really worry about or even maybe, let's take a less high stakes example, you know, imagine you're really worried that children are becoming addicted to these, to these models, right? I mean, they're not in the sense of, and then they're learning how to make biological weapons, but in the sense that, you know, we've had lots of debates over the last 10 or 15 years and we've even had whistleblowers, right, Maybe most notably Francis Haugen from from out of Meta, about the effects of social media on children and what the companies knew about that. You could imagine very similar situations happening regarding AI. Would those things be part of the whistleblower protection? I guess the bigger question I'm asking is, you know, what are the trade offs with how broadly you scope whistleblower protections? And I guess in your opinion, does this bill get the trade off right, or does it err too much on the side of protecting trade secrets or on the other side, you know, air too much on, you know, letting any disgruntled employee say anything even remotely nasty about a company because they've convinced themselves that it's the worst thing in the.
Charlie Bullock
World, in my view. I think it gets it right. My colleague, Mackenzie Arundel, I wrote a blog post, I guess a month or so back now about how to design AI whistleblower legislation. And we suggested this substantial and specific language. And the reason we said that was because I think a big part of the appeal of whistleblower legislation is that it's truly bipartisan in this context, right? Not historically, it's been more of a Democratic priority probably, but in this context it has a lot of support from industry friendly folks, from libertarian minded people, from Republicans. And so I think that in order to maintain that situation where a lot of people are in favor of it, some people maybe don't have strong thoughts about it and then pretty much no one is against it, hopefully, or at least no one has expressed anything against it so far that I've seen. You don't want to make it as broad as it possibly could be. I agree that it's, you can imagine a broader law and like for very safety minded people that might be better. Right. For example, there's some concern that you might have very substantial worries about serious risks and good evidence for them. But just because of the nature of the technology, you can't be too specific about what it's going to do. You just know that this is bad, but you don't know exactly how or what form the harm is going to take. There's some question about whether that kind of reporting would be covered by substantial and specific.
Alan Rosenstein
So would an example of that be like GPT7 can do automatic code improvement so much that you think that like artificial superintelligence is nigh and like that could involve us all being turned into paperclips maybe? Right. Depending on what AI doomer track you read last time. And like that's the sort of thing that you'd want the government to know about, but you know, it's a little too speculative to fall under this law. Is that the kind of concern you're talking about here?
Charlie Bullock
Yeah, it's at least debatable, right, Whether that would be protected by this law or not. And I will say that I think for concerns like that, like the fact that it might or might not be covered by this law doesn't mean that it can't be reported. Right. You can still anonymously whistleblow to some of the many watchdog organizations that are getting set up to handle whistleblower complaints from people at Frontier AI companies. Right. It's still possible to blow the whistle. You just might get fired for it if, you know, if your company thinks that you did the wrong thing.
Alan Rosenstein
And it's interesting and I guess just to not get sort of too game theoretic about this. But why not? I guess that is a relevant margin to think about how much protection you want.
Charlie Bullock
Right.
Alan Rosenstein
Because if you're thinking about it, the optimal level of whistleblowing is not necessarily to have no one get fired, it's to not have people who would otherwise whistleblow to whistleblow. And one might think that actually, you know, if you're worried about this sort of speculative ASI risk, that's exactly the sort of person who's just going to whistleblow anyway because they're so freaked out. So you actually don't need whistleblower protections? I guess. I mean, I don't know, maybe I'm crediting Congress a little bit too much with this strategy. But you know, if I was thinking about sort of how to optimally design a whistleblower regime, I guess that is one dimension that I think about.
Charlie Bullock
Yeah. I mean, in theory, if you think that you're going to be a paperclip in six months, the idea of losing your very cushy job and having to go to slightly less, oh, I'm just a machine learning engineer, what am I going to do for work? In theory that wouldn't be that big of a disincentive. But I mean, I think in practice sometimes it's surprising how immediate sort of concerns about comfort or whatever influence people's decisions. But. Yeah, no, I agree.
Alan Rosenstein
I want to go back to this reported question because I kind of mentioned a little bit this question of is it enough to be able to just report to the government? And I'll be honest, personally, that's actually my big concern with. To the extent that I wonder if this law is insufficient, that's obviously not a reason to vote against it. This is obviously much better than the status quo. To me it's actually not so much the scope of the law, but the reporting. The reason I say that is because, you know, especially with the lack of a lot of substantive regulation of AI, it's actually not obvious to me how useful it is simply to be able to report to the government that, you know, such and such model carries with it such and such increased bio, biorisk. Now, obviously it's better for the government to know this than not to know this. And, and maybe I'm focusing too much on the current administration and my, I'll admit, not terribly high opinion of it, though I do think that's actually relevant because, you know, if you take some of the forecasts seriously, a lot of what's about to happen world historically is going to happen in the next three and a half years, which for better or for worse is coterminous with the Trump administration. But I guess my, my point is, I guess I would feel better and I would think that this law had a lot more bite in terms of actual AI safety, not just telling the government things that it may or may not then act on if it also applied not just to the government but to the New York Times. Now again, maybe, maybe the trade secrecy concern is just too much in that regard, but tell me why I should be less grumpy that this does not also apply to public disclosure.
Charlie Bullock
Yeah, so I think that's a perfectly valid argument and I think probably a lot of people agree with you that a better Law would be one that said there's a right to warn. Generally, I think that anonymous reporting of the New York Times remains an option. So that sort of mitigates the harm you're talking about. The New York Times is good at protecting its sources and they take this kind of report and they have experience not ratting you out and so forth. I think that one reason you should not be too grumpy about it is that I view this as a building block. Right? I think that this is the first substantive piece of AI legislation that's going to pass the federal government, hopefully. I mean, if it does pass, which it may or may not, if it was right, the first really substantial piece of AI safety legislation, then it should be a foundation for things to come. Right? And I think information gathering has to be the first step in any sort of comprehensive AI governance regime, right? You have to. You have to know something about what you're regulating before you regulate it, right? If you take big substantive steps early, you're going to get them wrong. Because, you know, science and technology scholarship people talk about the pacing problem, right? Technology always improves faster than laws can improve or whatever. So it's important to improve government capacity to the extent that you can. And the best way to do that right now is by improving the government's ability to gather information. Right? So things like the Biden administration's reporting requirements also go into this. But I think whistleblower protection is a very important part of that. So I agree with you that, like, okay, you report to the government and then what? Right. Currently, the government has no ability to do anything about anything, and the timelines are short enough that maybe we shouldn't be optimistic the government will be able to do anything about anything. But in my opinion, there are some worlds in which the government's capacity to regulate AI matters into the future, right? Including good worlds where we're not all paperclips or whatever. So you're building a foundation for future governance efforts.
Alan Rosenstein
Okay, so we've talked about ways in which maybe the bill could have gone farther. But also maybe. Now let's talk about maybe some of the downsides of just the bill going as far as it does. Because, you know, as the economists like to tell us, there are no free lunches. There are all these interesting second order unattended consequences. And you know, we should think about that for this, for, for this kind of law and I guess for whistleblower protection law generally, because just like off the top of my head, I could imagine some unintended consequences of a law like this, or maybe not unintended, but certainly negative consequences. So you can imagine if you have a very strong whistleblower protection regime, then perhaps companies will hire fewer people because they're worried about more whistleblowers. Or when they hire people, they'll spend a lot more time screening for loyalty, however you screen that. Or maybe once they've hired people, they will compartmentalize a lot more information and silo that information because again, to limit the number of people that will have that information who might then whistleblow and that might actually lead to less disclosure overall. Because again, in the absence of whistleblower legislation, you don't not have whistleblowing, you still have whistleblowing on the margin. So, you know, I'm curious what you think about those arguments and whether any of them give you pause.
Charlie Bullock
I think those are valid concerns in theory. I think that for the ones you brought up to be relevant, companies would have to actually like be very concerned about whistleblowing. I think at the moment it doesn't appear that they are right.
Alan Rosenstein
I mean, OpenAI had that non disparagement clause, so clearly someone in the general counsel's office thought about it. Even if they backpedaled embarrassedly, sure.
Charlie Bullock
But my model of how that worked out is just that tech companies love to be as broad as possible with their non disparagement and non disclosure agreements just to cover their bases. Basically it's like, well, why not be as broad as possible if you can? And OpenAI almost immediately, as soon as it became public, rescinded those clauses and said, okay, we're not going to enforce them, which I don't imagine they would have done if it was a sinister plot. I mean, maybe they just thought it would never come out. But I think, yeah, that's my model of that is that maybe companies like to just prevent you from saying anything because why not? There's no cost to them for that. But at the moment it doesn't seem like AI companies are super concerned about whistblowing because if they were, they would have expressed some kind of opposition to this bill. They really haven't.
Alan Rosenstein
Am I right? That just also the kind of culture and social anthropology, for lack of a better term, of the Bay Area makes this kind of overcorrection unlikely. My sense is that between the fact that California also has very strong restrictions on non compete agreements, which is why everyone circulates around the labs, and as far as I can tell there are like a thousand key machine learning engineers who all go to the same parties and, I don't know, part of each other's polycules. I don't know. I'm just an innocent Midwesterner. I don't understand this west coast world already. The information environment is pretty porous. Is that a fair statement about how the current system works?
Charlie Bullock
I am also an innocent Midwesterner. I lived in the Bay Area for, you know, a little bit more than a year. And I, that's about as long as I could make it before I headed back to Chicago. So I, I, I, I would, I hesitate to offer, like, authoritative opinions on the, the information porousness and so forth, but I think there's something true about the fact that, like, there's a libertarian ethos there. Right. There's an idea of, like, you know, I mean, obviously business owners want to protect their business interests. People take trade secrets seriously, stuff like that. People don't screw around with patents. But I mean, having been a patent lawyer in the past, there's often a dynamic of, like, the tech people mostly care about the tech, and then the lawyers swoop in to handle the suing people about intellectual property and stuff like that. Right. And the actual engineers involved are maybe less concerned about that aspect of things, typically.
Alan Rosenstein
All right, let's turn to the politics of this bill, which are perhaps more straightforward than what would otherwise expect. As you pointed out, this is a bipartisan bill. And I guess let me start by asking why you think that's the case. Right. I mean, you mentioned earlier that whistleblower law, because it's kind of labor protective law, is often left coded, and yet this seems to have bipartisan support. Its main sponsor is Chuck Grassley, who's a Republican from another excellent Midwestern state, Iowa. Why do you think that this, of all issues, seems to have reasonably smooth sailing through Congress, if in fact it does? I mean, you should also comment on whether you think that Congress will in fact enact this this session or next session or sometime.
Charlie Bullock
So the first thing I'll say is that I do think it's true that it has bipartisan support. Almost no one that I've seen dislikes the bill or, like, is actively against it. It may not pass this time around. If it doesn't, it'll probably be because not because it has strong opposition, but because there's insufficient, like, it's an insufficient priority. Right. Like it's going to the HELP committee, which is like labor. Right. And so you have to get it into markup in that committee. Right. And so time will tell if Chuck Grassley has enough pull with the senator, who's the head of that committee to get him to put it in for markup or not. Right. And if he doesn't, then it's not because that senator hates this bill. It's just because he has other bills that he wants to bring up for markup, and there's limited spots for this sort of thing and so on and so forth. So that's my sort of perception of the politics of this in terms of why the politics are that way. I think it's a combination of factors. I think, for one thing, the great man theory of history scores another point here. It's just the idiosyncratic policy preferences of Chuck Grassley personally. He's a very senior and important senator. You could try to explain those in terms of sweeping historical trends and stuff, but I think it's just. If you've seen how the guy tweets, he's his own person.
Alan Rosenstein
Chuck likes whistleblowers.
Charlie Bullock
He likes whistleblowers. There's a. There's a great, great tweet by him about this that. That you should all look up. It's in his characteristic style, but. Okay. Another factor that explains how why other Republicans are maybe more behind this than in the past is that in recent years, there's been sort of increasing conservative skepticism of Big Tech because of perceived censorship of conservative opinions. Right. I'm not the expert on. On this topic, but people felt very strongly, and I think there was some basis for it, that prior to Elon Musk's acquisition of Twitter, there was a perception on the right that conservative voices were being censored on Twitter, which is part of the reason that he acquired that platform was to promote free speech and so forth. There's also similar perception. I remember the James Damore memo at Google was a big concern. People on the right thought that he was saying sort of straightforwardly correct things, and he was canceled for this and et cetera. So there's. That current is also behind the willingness of conservatives to go after Big Tech for stuff. Right. Josh Hawley, for example, is one of the supporters of this bill in the Senate, and he has been vocal about that sort of thing. So I think that plays into it as well. And then the final aspect of it, I think, is that if you want to do preemption, which a lot of Republicans do, because they believe that a patchwork of state regulations is the wrong way to handle AI regulation. Right. They think that it should be a single federal standard, and then states should get out of the way.
Alan Rosenstein
And just to clarify, we're talking about preemption of AI regulation generally.
Charlie Bullock
Yes.
Alan Rosenstein
At the state level.
Charlie Bullock
That's right, yes. You know, I mean, future preemption bills could take various forms. They might be more narrowly tailored than that. They might or might not be general. Right. But if you are a proponent of broad preemption of state AI legislation, it helps politically to be able to say, okay, well there's already federal legislation, at least some federal legislation, some federal regulation that addresses this. It's not a complete regulatory void. So J. Ober Nolte, who's sort of the House mastermind behind the moratorium, the preemption measure that's in the recently enacted House reconciliation bill, is also, he's the House sponsor of this whistleblower legislation. So I think that points to the idea that it's also appealing for those sort of secondary political reasons.
Alan Rosenstein
Okay, I want to finish off by talking about industry and its reaction to this. I think you mentioned earlier that industry also seems reasonably supportive of this or at least not gung ho opposed to it. And so I'd love for you to talk about why you think that is. And also if industry supports this, should that make us worried that it's a bad bill? In other words, if industry supports this, should we worry that this bill is actually too weak?
Charlie Bullock
Yeah. My perhaps naive opinion is that there are win win situations sometimes in life, Right. There are deadweight losses and there are stuff that's good for everyone. Right. I don't know that this is necessarily like a huge win for industry having this, but it's in my mind such an obvious common sense thing to do. Right. Like, if you think about what we're actually saying, we're saying like if there is a legitimate danger to public safety, people should be able to tell law enforcement about it. Like that's. If you oppose that, you're going to look ridiculous.
Alan Rosenstein
Yeah, but industry frequently opposes things that are good for the public and they're happy to look ridiculous, you know, if they think that it's in their interest.
Charlie Bullock
You're right. And so maybe that's a sign that this bill is to some extent toothless. Right. Because it doesn't actually impose any costs on them and they're not worried about it. Now that could be a good sign. Maybe the fact that they're not worried about it means they're thinking we're not going to violate any laws, we're not going to impose any substantial dangers on the public, so what's there to worry about? Right. If so, good right. Then the worst thing that's happened is that we passed a bill that doesn't do much. But yeah, I can't see downsides of this in terms of like being some huge giveaway to industry or something. Right. It doesn't really benefit them in any concrete way. At most it doesn't go far enough. But, you know, show me the piece of AI legislation that we have right now that has a good chance of passing that does go far enough, and then I'll happily support that instead. Right.
Alan Rosenstein
Well, I think that's actually a good place to end it. Charlie. Thanks for coming on and we'll be sure to have you on again if this thing ends up getting through Congress.
Charlie Bullock
Thanks so much for having me, Alan. Really good talking to you.
Alan Rosenstein
The Lawfare Podcast is produced in cooperation with the Brookings Institution. You can get ad free versions of this and other Lawfare podcasts by becoming a Lawfare Material supporter at our website, lawfairmedia.org support. You'll also get access to special events and other content available only to our supporters. Please rate and review us wherever you get your podcasts. Look out for our other podcasts, including Rational Security, Allies, the Aftermath and Escalation. Our latest Lawfare Presents podcast series about the war in Ukraine. Check out our written work@lawfaremedia.org this podcast is edited by Jen Patya. Our theme song is from Alibi Music. As always, thanks for listening.
He Su Jo
With the Redfin app, you'll know the moment your next place hits the market. Whether you're looking to buy your dream home or rent a sweet apartment, give Redfin your Gotta have it wish list of property features and you'll receive real time notifications tailored just for you. Ready to see it up close and personal Scheduling a tour is just a tap away. Don't wait to find your perfect match. Download the Redfin app and start searching today.
Episode: Lawfare Daily: A Right to Warn: Protecting AI Whistleblowers with Charlie Bullock
Release Date: June 25, 2025
Host: Alan Rosenstein, Associate Professor at the University of Minnesota Law School and Research Director at Lawfare
Guest: Charlie Bullock, Senior Research Fellow at the Institute for Law and AI
In this episode, Alan Rosenstein engages in a comprehensive discussion with Charlie Bullock about the emerging AI Whistleblower Protection Act. The conversation delves into the necessity, scope, and potential impact of this bipartisan Senate proposal aimed at safeguarding employees who expose dangers within the artificial intelligence sector.
Charlie Bullock (02:23):
"Essentially, I view whistleblowing as the act of an employee... reporting corporate wrongdoing, typically to the proper authorities."
Bullock emphasizes that whistleblowing isn't merely about exposing legal violations but also encompasses reporting substantial and specific dangers to public safety associated with AI development and deployment.
Bob:
The discussion highlights the fragmented nature of whistleblower protections in the United States, with a "patchwork of overlapping federal laws, state laws, and common law protections." Federally, there isn't a comprehensive whistleblower protection statute, leaving much to state legislatures.
Charlie Bullock (12:20):
"Federally, there is no overall background federal whistleblower protection law. Right. It’s mostly left up to the states."
California stands out with its robust protections under Section 1102.5 of the California Labor Code, which prohibits retaliation against employees who report violations of federal, state, or local laws to government agencies or within the company. Other states, like Illinois, also offer expansive whistleblower protections, whereas states like New York and many Republican-led states have minimal or no statutory protections.
Charlie Bullock (20:20):
"The law essentially covers three different kinds of reporting and protects them... violation of any federal law, reporting about substantial and specific dangers to public health, public safety, or national security, and reporting about AI security violations."
Key Provisions:
Additionally, the Act renders non-disclosure agreements (NDAs) and arbitration clauses unenforceable concerning legitimate whistleblower activities, ensuring that employees can report without contractual repercussions.
Alan Rosenstein (27:45):
"What are the trade-offs with how broadly you scope whistleblower protections? And... does this bill get the trade-off right?"
Bullock argues that the Act strikes an appropriate balance by requiring that reported dangers be both "substantial and specific." This requirement ensures that protections aren't exploited for vague or unfounded concerns. For instance, speculative fears about AI, such as models achieving sentience or societal disruptions like widespread addiction, may not meet this threshold. However, concrete threats, such as AI systems facilitating the creation of biological weapons, would be protected under the Act.
Charlie Bullock (29:07):
"I think it gets it right. My colleague... suggested the substantial and specific language because it maintains bipartisan support."
He acknowledges that while broader protections might benefit certain safety-minded individuals, the current wording fosters broad support without overreaching, ensuring the bill's practicality and acceptance across the political spectrum.
Charlie Bullock (38:55):
"Chuck Grassley... has been working on whistleblower stuff for a very long time... This is just his own person."
The Act enjoys bipartisan backing, spearheaded by Senator Chuck Grassley, a Republican with a longstanding commitment to whistleblower protections. Additionally, conservative concerns about Big Tech censorship and preemption of state AI regulations have propelled support from both sides of the aisle. Figures like Josh Hawley have endorsed the bill, aligning it with broader Republican initiatives to standardize AI regulations at the federal level.
Charlie Bullock (42:49):
"It doesn’t really benefit them in any concrete way. At most, it doesn't go far enough."
Interestingly, major AI companies haven't strongly opposed the Act. Bullock suggests this might be because the legislation doesn't impose significant burdens on them. Instead, it provides a clear framework for lawful disclosures without granting undue advantages to whistleblowers. The lack of industry resistance could indicate either contentment with the current protections or a strategic calculation that the Act won't adversely affect their operations.
Alan Rosenstein (35:48):
"You can imagine they might hire fewer people... but currently, it doesn't appear companies are super concerned about whistleblowing."
Bullock concurs, noting that while theoretical concerns exist about companies tightening hiring or information compartmentalization, the present climate doesn't show signs of such reactions. The immediate response from companies like OpenAI, which withdrew broad non-disparagement clauses when publicized, supports this view.
Alan Rosenstein (34:36):
"If you have a very strong whistleblower protection regime, then perhaps companies will hire fewer people... or compartmentalize information, leading to less disclosure overall."
Bullock acknowledges these concerns but maintains that, in reality, the current fear of retaliation isn't sufficiently pervasive to warrant significant changes in hiring or operational practices. He posits that AI companies aren't overwhelmingly worried about whistleblowing, suggesting that the Act won't drastically alter their internal dynamics.
Charlie Bullock (32:41):
"This is a building block... information gathering has to be the first step in any sort of comprehensive AI governance regime."
Bullock views the AI Whistleblower Protection Act as foundational legislation that paves the way for more comprehensive AI governance. By enhancing the government's ability to gather critical information from within the industry, the Act sets the stage for future regulatory measures and safeguards against potential AI-related threats.
Alan Rosenstein (44:08):
"Well, I think that's actually a good place to end it."
Both host and guest agree that, while the Act may not be exhaustive, it represents a significant stride towards addressing the unique challenges posed by AI advancements. Its bipartisan nature, coupled with thoughtful scoping, positions it as a pragmatic solution in the evolving landscape of AI governance.
Charlie Bullock (03:04):
"So the core example would be you're an employee at a company, you notice that your company is violating the law and you report that to law enforcement."
Charlie Bullock (20:20):
"The law essentially covers three different kinds of reporting and protects them."
Charlie Bullock (29:07):
"I think it gets it right... substantial and specific language... maintains bipartisan support."
Charlie Bullock (32:41):
"This is a building block... information gathering has to be the first step in any sort of comprehensive AI governance regime."
The AI Whistleblower Protection Act represents a crucial development in aligning legal protections with the rapid advancements in artificial intelligence. By addressing the gaps in existing whistleblower laws and tailoring protections to the unique challenges of the AI sector, the Act seeks to empower individuals to report significant dangers without fear of retaliation. While acknowledging potential limitations and areas for future enhancement, the bipartisan support and thoughtful design of the legislation underscore its importance in the broader context of AI governance and national security.