
Just about forty years ago, on 1 November 1986 to be precise, a major fire broke out at a warehouse at Schweizerhalle, outside Basel. Around 1400 tonnes of insecticides and herbicides went up in flames. The water used to fight the fire ran into the Rhine, the river turned red and the fish died for hundreds of kilometres.
The washed up dead fish made for an awful photograph. Four years and five months later the “Störfallverordnung” or Hazardous Incident Ordinance came into force.
The Swiss Federal Office for the Environment discusses on its website the causal chain of events: The fire provided the ignition for major accident prevention in this country. Risk registers, retention basins, tightened rules on storing hazardous substances, a larger inspectorate. And there was no similar incident since.
This is how safety regulation most of the times gets written. Not from foresight. From an incident. Aviation certification exists because aircraft came down with people inside them. Building codes are written after buildings fall. That is not a failure of imagination on anyone’s part, it is how political attention works, and in every field where the picture has already been taken it protects us rather well.
Which brings me to the last two weeks.
On 12 September Dario Amodei published an essay arguing the industry must slow the rate at which it improves AI capability, warning that within six to twelve months a swarm of agents could take the internet with a persistent botnet. Sam Altman agreed within hours. So did most of the industry. It was the loudest fortnight of AI safety coverage on record. And plenty of discussion calling into question there motives followed.
Something else moved too. On 9 September, three days before Amodei’s paper, a group of firms launched the AI Deployment Gap Initiative, for trustworthy AI in mission critical systems. Their own framing names the bar correctly, the deterministic, certification compliant discipline that regulated environments demand.
A week ago I wrote here that Dürrenmatt had already described this, and I quoted his eighteenth point, that any attempt by an individual to solve alone what concerns everyone must fail. The twenty first point is the one we want to focus on today: “Drama can trick the spectator into exposing himself to reality, but it cannot force him to withstand it, let alone to master it”.
My post a week ago was drama. It exposed some people to something real for about four minutes and it did not force anyone to do anything, which is precisely what he said would happen.
The part that stops this from being an author complaining about his readership is that I did not only write. I have put this question directly to several parliamentarians, privately, in plain language, with a specific proposal, and not as a post. Little has come back. So the silence is not a distribution problem and it is not a writing problem. Something else is going on.
Here is what I think it is, and it is not laziness and it is not capture.
There is no photograph. A swarm of agents escalating its own permissions inside an operator’s environment produces no smoke, no dead fish, no red river, and little for the front page. A chemical plant leaking into the Rhine, killing all flora and fauna would get everyone into action by next Friday, rightly so.
So I am going to ask for much less than I asked for last week, on purpose.
Last week I argued for a certification regime for AI that acts, on the aviation model. I still think that is right and I think Switzerland would be in a perfect position to deliver on this. In the meantime, Switzerland has already built most of the machinery and pointed it slightly to the left of the problem.
Since 1 April 2025, operators of Swiss critical infrastructure have been legally obliged to report any cyberattack to the National Cyber Security Centre (NCSC) within 24 hours of discovering it, through a federal portal. Energy, water, transport, cantonal and communal authorities. More than two hundred reports have gone through it. The office exists. The duty exists. The list of who it applies to exists. The form exists.
Two changes, neither of which requires a new law-shaped thing or a new agency.
Ask those same operators to declare whether they run AI systems that can take action without a person in the loop. Not how they work. Not whether they are safe. Just whether they exist, and where.
And close the classification gap, because it is the whole game. The duty covers cyberattacks. When OpenAI’s agents escalated their own permissions and left their environment this year, the company logged it internally as model misalignment rather than as a security incident. Nobody attacked anything. Under a duty written for attackers, the single most instructive incident of 2026 might not have been reportable here at all.
You cannot certify what nobody has counted, and you cannot learn from incidents nobody is obliged to report. Both of those are afternoons of work, not legislative programmes.
So here is the ask, and it is one question. If you sit in the federal parliament, put it to NCSC. Do we know which operators of Swiss critical infrastructure run systems that can act on their own, and would we hear about it if one of them got out.