Policy & Regulatory Engagement
Setting Technical Realities for AI Audio Policy
Box Commons engages directly with federal, state, and international regulators to ensure AI audio standards reflect the operational realities of independent creators and broadcasters.
International Recognition: Box Commons was acknowledged alongside Google, Microsoft, IBM, and Salesforce in Singapore's Model AI Governance Framework for Agentic AI (v1.5, May 2026) for work on behavioral safety credentialing and content provenance standards.
Comment on Colorado ADMT Proposed Rules: Training Data Certification
Recommends that Colorado's ADMT proposed rules recognize independent data certification as a mechanism for developers to satisfy training data documentation obligations, with a rebuttable presumption that certified datasets meet disclosure requirements. Backed by a live 22-station broadcast radio certification pipeline.
Comment on NHTSA ADS Incident Reporting (SGO 2021-01)
Supports the three-year extension of SGO 2021-01 ADS incident reporting but identifies a verification gap in manufacturer self-reporting. Proposes three complementary verification mechanisms: third-party audit, cryptographic software version attestation, and safety case cross-referencing.
Comment on NHTSA Zoox FMVSS Exemption Petition
Does not oppose Zoox's petition but proposes a four-element conformance pattern (published criteria, independent assessment, machine-readable attestation, continuous reporting) that NHTSA could condition any temporary FMVSS exemption upon, mapping to existing conformity assessment architectures.
Liaison Organization Application to CEN/CENELEC JTC 21
Application for Liaison Organization status with CEN/CENELEC JTC 21 (Artificial Intelligence) to provide transatlantic coordination on AI conformity assessment and management system standards. Targets WG 4 (AI Management) and WG 5 (Conformity Assessment).
Comment on NAIC BDAI Working Group: Exhibit B/D Mapping
Proposes a 'Presumption of Conformity' framework within the NAIC AI Systems Evaluation Tool permitting insurers to satisfy third-party vendor oversight obligations under Exhibits B and D through valid certifications from independent AI credentialing bodies, following the HITRUST precedent.
Preliminary Comment on CPPA Opt-Out Preference Signals
Addresses AB 566, AI systems processing opt-out signals, the verification gap, and independent third-party credentialing as a scalable compliance pathway for California's expanding privacy framework.
Comment on Federal Reserve Reputation Risk Rule (R-1884)
Addresses AI-related reputation risk in banking supervision and the role of third-party credentialing in financial institution compliance. Argues that behavioral safety verification should be part of reputation risk management for AI-deploying banks.
Comment on FAR Semiconductor Prohibition (Case 2023-008)
Analysis of federal acquisition regulation changes and implications for AI data provenance in government procurement. Proposes credentialing mechanisms that verify both hardware provenance and AI behavioral safety for federal contractors.
Comment on the Model AI Governance Framework for Agentic AI
Five recommendations on strengthening Singapore's agentic AI governance framework through behavioral safety credentialing and international interoperability. First international filing by Box Commons.
Acknowledged on p. 51 of IMDA Model AI Governance Framework v1.5 (May 2026) alongside Google, Microsoft, IBM, PwC, AWS, and Tencent.
Comment on GSA AI Clause Basic Safeguarding (GSAR 552.239-7001)
Offers six recommendations on GSA's proposed AI clause for federal procurement, arguing it creates compliance obligations without any mechanism for standardized, verifiable compliance demonstration. Proposes a FedRAMP-style 3PAO credentialing pathway and a critical distinction between behavioral safety and ideological content moderation.
Comment on FTC/DOJ Antitrust Guidelines for Collaborations Among Competitors
Urges DOJ/FTC to provide clear antitrust safe harbors for AI credentialing standards development organizations — addressing the gap where credential denials risk being characterized as group boycotts. Proposes four specific safe harbors for SDO standards, collective AI threat intelligence, credentialing decisions, and insurance-linked credentialing.
Comment on FTC Negative Option Rule ANPRM
Raises an issue no prior FTC commenter has addressed: AI agents that autonomously discover, evaluate, subscribe to, and pay for goods and services, breaking ROSCA's foundational assumption of a human consumer. Proposes a safe harbor framework for AI-readable disclosures.
Comment on NCUA GENIUS Act: PPSI Investments and Licensing
Addresses NCUA's specific PPSI licensing rulemaking questions through the lens of AI agent-mediated stablecoin commerce, arguing that AI agents will be the primary growth vector for stablecoin transaction volume and recommending agent authentication capabilities and graduated fee structures.
Comment on SEC Crypto Asset Interpretive Release (S7-2026-09)
Identifies a gap in the SEC/CFTC's five-category crypto asset taxonomy: it was developed without reference to non-human transactors, yet AI agents are already transacting autonomously in stablecoins. Dissects how each Howey element breaks down for AI agent transactors.
Comment on NIST AI 800-2: Evaluation Practices for Language Models
Five observations on strengthening NIST's evaluation framework as results increasingly inform third-party credentialing, regulatory compliance, and insurance underwriting. Argues that behavioral safety is a distinct evaluation domain requiring independent assessment.
Comment on NCCoE AI Agent Identity and Authorization
Recommends that agent identity credentials be interlocked with behavioral safety verification — no credential without verified behavioral certification. Identity without behavioral verification provides incomplete assurance to downstream systems.
Comment on FDIC GENIUS Act: Stablecoin PPSI Implementation
Urges FDIC to incorporate third-party behavioral safety credentialing into GENIUS Act implementing regulations for state-chartered banks. Addresses the unique dual supervision challenge, deposit insurance dimension, and community bank proportionality problem.
Comment on NCUA GENIUS Act: Behavioral Safety Credentialing for Credit Unions
Urges NCUA to incorporate third-party behavioral safety credentialing into GENIUS Act regulations as a cost-effective mechanism for credit unions to verify vendor-provided AI system safety without requiring in-house model risk management.
Comment on OCC Stablecoin NPRM: GENIUS Act for National Banks
Proposes that OCC incorporate behavioral safety credentialing into GENIUS Act implementing regulations for national banks, arguing that the existing SR 11-7 model risk management framework was designed for traditional statistical models and cannot govern autonomous AI agents.
Comment on SEC Petition 4-882: AI Governance and Risk Management Disclosure
Proposes that SEC AI governance disclosure requirements should encompass behavioral safety metrics — not just governance processes — to make investor-facing AI risk auditable and comparable. Strengthens Petition 4-882's GAIP framework by arguing the 2023 cybersecurity disclosure framework should extend to AI through interpretive guidance.
Comment on NIST CAISI RFI 2025-0035: AI Agent Security
Response to the Center for AI Safety and Innovation's request for information on AI agent security standards. Argues that behavioral safety is a distinct, unaddressed security domain and that NIST should expand 'agent security' to include a behavioral safety layer suitable for insurance underwriting.