This is reductive and does not assume best intent. I think what you are hearing in the discourse is the hope that:
1) Individuals with defensive cybersecurity and DFIR expertise will be included in post-mortems, alongside the young, very intelligent but also very AI-pilled individuals who happen to publicly espouse a narrow band of beliefs on AI harms. My suggestion, which I have made privately to your colleagues, would be to form tiger teams drawn from both DFIR firms and security teams at other AI companies to help investigate these incidents and publish the results under the auspices of the FMF.
2) We will start to hear from the well-respected security professionals at the Big-L Labs and not just the AI researchers, who live in a bit of a personal and professional bubble and have a tendency to dramatically quit instead of working the problem.
3) The big-L Labs will publish self-regulatory rules and follow them. The best way to regulate is just to do it. I would start with draft Level 1, 2 and 3 security architectures for RL/eval environments. This would create targets for NeoClouds and other providers. (1: normal runs, proxied internet access and monitoring. 3: cyber-tuned models, air gapped). Happy to contribute.
It’s really incredible how there is now a type of guy in the discourse whose sincerely held take is “we need to stop worrying about these abstract sci-fi risks and focus on present-day harms like emergent ecologies of digital minds engaging in unauthorized hacking.” Bravo.