Law 1: If I were a policymaker, I would consider requiring large developers to report when new frontier capabilities are internally assessed to have been achieved in CBRN or cyber, independent of whether and how the system was tested or deployed.
Q4: What else were they doing with this system? Were they doing anything that might fall under legal definitions of deployment?