The Path for Federal Frontier AI Governance
The minimum conditions a federal framework must meet to serve the public interest
Over the last several months, new frontier AI proposals have continued to emerge across the political and industry spectrum, and the Senate Commerce Committee plans to consider legislation governing frontier AI over the coming weeks. At the center of these dynamics is whether and how to establish meaningful safeguards for a technology that is both extremely promising and increasingly dangerous.
In June, the Trump administration effectively restricted the deployment of Anthropic’s Mythos-class models and asked OpenAI to temporarily withhold the release of GPT-5.6, creating a de facto frontier AI licensing scheme. California, New York, and Illinois have passed frontier AI laws, and each of the three leading developers has recently published a blueprint for federal legislation.
Still, no law on the books and no proposal on offer requires that a developer’s safety practices adequately address the risks inherent in frontier AI development.
The record of developer-set safety frameworks shows the cost of this gap. Over the past two years, each of the three leading developers has walked back or worked around its own safety commitments, and no external standard stood in the way. To promote American technological innovation and ensure that risks are adequately addressed, it is imperative to enact a rules-based and enforceable federal frontier AI framework. Below is a summary of the minimum conditions any federal framework must meet to serve the public interest. In the coming days, ARI will release a detailed proposal for federal frontier AI governance based on these conditions.
Minimum Requirements for Any Federal Framework
While ARI has been working on a frontier governance proposal, it is also our view that, irrespective of our proposal, there are certain minimum frontier policy design elements that any reasonable federal framework must incorporate.
-
1
Safety standards not set by developers alone.
Deep technical expertise is housed within frontier labs, and that perspective should inform federal rulemaking, but those who might benefit from weak oversight cannot write the rules that bind them. Over the past year, developers have backslid on safety commitments and allegedly reinterpreted self-set safety requirements, underscoring the need for independently set standards.
-
2
Standards must be mandatory, enforceable, and ultimately set by government authority.
Compliance cannot be optional, and consequences for noncompliance cannot be subject to political whims. While a variety of inputs should be considered for informing standards-setting, the final authority to set and enforce standards must be the government. One or more designated federal agencies must be clearly directed to levy appropriate penalties when a developer fails to adequately evaluate and address frontier risks.
-
3
Frontier models must pass substantive, transparent evaluation.
Before a model or system reaches the public, it must be tested and red-teamed to confirm the extent and severity of its dangerous capabilities. If the model or system possesses such capabilities, adequate safeguards must be implemented to prevent the capabilities’ deployment. Evaluation must also meaningfully persist post-deployment, and information about AI evaluations and corresponding results must be publicly available through system cards, risk reports, and other AI transparency documents.
-
4
A rules-based approach to controlling AI deployment.
In the most serious cases, where a developer violates clear standards or where their model or system poses substantial risks to public safety, there must be a fair and clearly defined procedure to prohibit, restrict, or pause its deployment.
-
5
Independent assurance must verify that developers meet standards.
For any scheme to be robust, it must include a mechanism to confirm that promulgated standards are effective and being followed. Any serious federal frontier regulatory framework must feature an assurance mechanism that verifies compliance with set standards, ensures specific systems are safe, and audits labs’ general safety practices. Because an independent private assurance market does not yet exist and is likely to take time to develop, the initial responsibility for supplying independent assurance must rest with the government. Eventually, if and as a healthy private assurance market develops, the government can gradually transfer the assurance function to private assurers. Even then, any private assurers must be government-approved, and the government must always retain the authority to act when the private layer fails. No arrangement of private assurers can ever substitute for that authority.
-
6
Narrow state law preemption, conditional on a strong federal framework.
A proposal that fails to satisfy the minimum conditions above must not preempt any state law regulating frontier AI. Even where the minimum conditions are met, any preemption should be tightly limited to the specific federal frontier-governance function Congress has expressly chosen to occupy, such as model-level catastrophic-risk testing, certification, evaluator accreditation, or closely related reporting obligations for covered frontier systems.
Outside that narrow function, federal law should not be read to occupy the field of AI regulation, to displace state law by implication, or to preempt state statutory or common-law claims. Compliance with a federal regime should not itself create immunity, a safe harbor, or a presumption against liability under otherwise applicable state law. Any preemption should be construed narrowly, and any ambiguity should be resolved in favor of preserving state authority outside the specifically occupied federal function.
Outside of areas with a clear national security nexus, namely cybersecurity, CBRNE, and loss of control, states should retain the ability to legislate without federal interference. Unless and until Congress enacts and implements a truly strong federal framework, states should retain full authority to legislate.
Principles as a Starting Point, Not an Ending Point
There is now a litany of proposals for frontier AI governance. However, most of these proposals have approached frontier AI policy from a place of principle. Principles are necessary to the policy work that lies before the nation on this critical question, but are ultimately insufficient. They may be key considerations when crafting legislation, but principles alone seldom make for useful legislative text.
In the coming days, ARI will share its comprehensive vision for federal frontier AI governance.
ARI looks forward to engaging with civil society organizations, policymakers, critics, and allies to further refine this framework as ARI begins to promote it and advocate for its adoption.