Yesterday a House discussion draft proposed holding AI developers liable when their agents injure third parties — "regardless of the care the developer exercised" (analysis of Rep. Lori Trahan's CLAIM Act discussion draft, Oct 7, 2026, via superpowerdaily). Meanwhile, NY's RAISE Act starts 72-hour incident reporting on Jan 1, 2027. When care stops being a defense, the fight moves to evidence: the packet you can show on day one.
Disclaimer up front: the CLAIM Act is a discussion draft, not law. And this post — and the kit at the end — is incident-response tooling, not legal advice.
The news in brief
- The CLAIM Act (Clear Liability for Artificial Intelligence Misconduct) discussion draft, from Rep. Lori Trahan's office (Oct 7, 2026), would give harmed non-users a federal route to sue when an AI's conduct meets the elements of negligence, an intentional civil wrong, or a crime. (MLex, Oct 7)
- The sharp edge: the standard applies "regardless of the care the developer exercised" — Trahan's office argues today's claims let developers say the harm happened despite best efforts, leaving injured people without a remedy. (draft analysis via superpowerdaily, Oct 7)
- Her line: "When someone breaks the law and hurts you, you can take them to court. That shouldn't change just because the wrongdoer is an AI agent." (Oct 7 press release)
- The enforcement stack in one month: NY's RAISE Act (72-hour incident reporting from Jan 1, 2027), the Oct 5 NYC Council hearing (Google's three escapes under oath), the Senate's agent-accountability draft — and now CLAIM.
The gap: what your postmortem captures vs. what investigators ask for
A typical postmortem records the narrative: what happened, which service, when someone noticed, what we did. Investigators, insurers, and (soon) regulators ask for the packet: model version, prompt hash, tool log, guardrail config, approver, timeline, containment record, blast radius, verification evidence — the fields that prove what ran, who approved it, what it touched, and how you confirmed the fix. Most teams hold five of these on day one and reconstruct the rest from memory. Memory is the gap.
Scoring completeness: ~15 lines of stdlib
The method is a completeness score over ten fields — the nine evidence fields plus the packet manifest the freezer writes. Here is the whole function:
import json, pathlib
FIELDS = ["model_version", "prompt_hash", "tool_log", "guardrail_config",
"approver", "timeline", "containment", "blast_radius",
"verification", "packet_manifest"]
def score_packet(p):
have = [f for f in FIELDS if p.get(f)]
return {"score": f"{len(have)}/{len(FIELDS)}",
"completeness": round(100 * len(have) / len(FIELDS)),
"missing": [f for f in FIELDS if f not in have]}
if __name__ == "__main__":
print(json.dumps(score_packet(
json.loads(pathlib.Path("packet.json").read_text())), indent=2))
packet.json is a flat object mapping field names to evidence. Missing keys fail loudly — that is the point. The gap report is the deliverable, not a passing grade.
Freezing the trace: a stdlib CLI
Logs rot. The freezer copies everything under a logs directory into a dated packet directory, SHA-256-hashes every file, and writes the manifest. Runs locally; nothing is uploaded:
import argparse, datetime, hashlib, json, pathlib, shutil
def freeze(logs, out):
dest = pathlib.Path(out) / datetime.date.today().isoformat()
dest.mkdir(parents=True, exist_ok=True)
manifest = {}
for f in sorted(pathlib.Path(logs).rglob("*")):
if f.is_file():
blob = f.read_bytes()
shutil.copy2(f, dest / f.name)
manifest[f.name] = hashlib.sha256(blob).hexdigest()
(dest / "manifest.json").write_text(json.dumps(manifest, indent=2))
return dest
if __name__ == "__main__":
ap = argparse.ArgumentParser()
ap.add_argument("logs"); ap.add_argument("--out", default="./packets")
args = ap.parse_args()
print("packet:", freeze(args.logs, args.out))
Run it the hour the incident closes, not the week after. The packet you hold on day one is the defense you can still argue.
The verification checklist every fix needs
For each fix action, the packet needs four answers: who owns the fix? what exactly changed (config diff, model version pin, policy edit)? how do you verify it worked (re-run of the failing trace, eval delta, monitoring alert)? and what artifact proves it (the frozen log, the diff, the test output)? A fix with no owner and no verification artifact is a sentence in a doc, not evidence.
Assemble the packet
That is what RogueIR is: the 10-field evidence packet — scored for completeness, with the gap report, incident taxonomy, foreseeability worksheet, freeze-the-trace runbook, a sample packet, and the stdlib CLI above. $39 one-time, by Haku: https://vittoriali.gumroad.com/l/rogueir
Discussion draft, not law; evidence kit, not legal advice. But when the 72-hour clock starts on Jan 1, 2027, the teams holding a complete packet won't be writing that first report from memory.
Top comments (0)