Guardrails on Testing and Cybersecurity Can Keep AI Moving Fast

Karen McCormick of Beringea argues that shared standards for testing, security, and incident reporting can address rising risks without forcing companies to slow frontier development.

The news

Karen McCormick, chief investment officer at Beringea, says companies should adopt common guardrails around testing, cybersecurity, and incident reporting rather than accept slower AI progress. She made the case in an interview on Bloomberg Tech. The position comes as competition at the leading edge of model development grows more intense and the question of acceptable risk becomes harder to ignore.

Context

AI tools already let teams ship features and products on shorter cycles. At the same time, the pressure to stay ahead pushes organizations to accept greater uncertainty in how models behave once deployed. McCormick’s view is that the solution lies in consistent practices that do not require a pause in research or deployment. The prior state was largely ad-hoc risk management inside individual labs and product groups, with little shared expectation about what must be checked or disclosed.

McCormick frames these guardrails as practical requirements rather than broad restrictions. Testing standards would focus on repeatable evaluations before release. Cybersecurity expectations would cover how models and the data they touch are protected. Incident reporting would create a channel for sharing what went wrong after deployment so others can learn from the same events. She presents these measures as compatible with continued speed because they target known failure modes instead of attempting to limit the pace of capability gains.

Details

The interview does not supply specific benchmarks or timelines for these practices. It also does not name particular companies or regulators that should set the standards. McCormick’s emphasis remains on the idea that shared expectations can reduce downside without requiring every participant to throttle its own work. The discussion centers on the reality that AI is already accelerating product cycles, yet that same acceleration raises the stakes when models are released with incomplete understanding of their edge cases.

McCormick notes that frontier competition makes unilateral restraint difficult. One lab slowing its release cadence to run deeper tests risks losing ground to others that move faster. Common guardrails change the calculation by making certain baseline checks the default across the industry. This approach avoids the need for any single firm to decide unilaterally how much risk is tolerable. It also avoids the blunt instrument of mandated pauses that would apply equally to every research direction.

The three areas she highlights—testing, cybersecurity, and incident reporting—each address a distinct operational gap. Testing standards aim at consistent pre-release checks that can be compared across organizations. Cybersecurity expectations focus on protecting both the models themselves and the training or inference data they rely on. Incident reporting creates a feedback loop so that failures observed in production can inform the next round of evaluations everywhere. None of these steps requires halting capability advances.

Why it matters

For teams shipping AI products today, the argument points to a narrow but concrete set of obligations that could become table stakes. If testing, security, and reporting practices converge, engineering groups will spend more time documenting evaluations and preparing incident summaries. That overhead is real, yet it replaces the larger cost of uncoordinated breaches or model failures that damage multiple organizations at once. Investors and operators who have watched safety discussions swing between total deregulation and calls for broad pauses now have a middle option that keeps release velocity intact while addressing the most immediate operational risks. Whether the standards emerge from industry groups or later regulation will determine how uniform they become, but the core claim is that speed and basic safeguards are not in direct conflict.

The practical effect would be felt first in how release processes are documented and reviewed. Teams would need to demonstrate that a defined set of tests had been run and that results met an agreed threshold. Security reviews would shift from internal checklists to expectations that can be audited or compared. Post-deployment reporting would turn isolated incidents into shared data points rather than proprietary lessons. Over time this could lower the frequency of high-impact surprises that currently force every participant to react independently.

McCormick’s stance treats the current moment as one where the cost of uncoordinated risk is rising faster than the cost of modest coordination. The alternative—each lab setting its own bar—leaves open the possibility that the weakest practice becomes the de facto industry standard when a failure propagates. Shared guardrails on the three operational areas she names reduce that exposure without inserting a governor on the rate of model improvement itself.

---

Sources:

{"word_count": 682}

No comments yet