Pending U.S. AI Bills and the Great American AI Act
The one-paragraph answer
Federal AI legislation in the United States remains fragmented. Congress has not passed a comprehensive AI law. What exists is a growing collection of bills, executive orders, and agency directives that shape how federal actors treat AI. The most-watched draft is the Great American AI Act, but multiple other proposals cover safety, deepfakes, transparency, and employment AI. The operating posture for executives: prepare as if federal law will move, without overcommitting to any specific bill's language.
Every executive we advise asks the same question: "When will Congress do something?" The honest answer is that Congress may or may not act on AI in the current session, and the exact shape of any law will change five times before enactment. That uncertainty is the pain. Companies do not want to build for a law that never passes. They also do not want to be caught unprepared if it does. So they wait, and while they wait, states pass their own laws, agencies pursue enforcement under existing authorities, and the EU AI Act starts binding US companies through extraterritorial reach.
The pain of federal AI legislation is the pain of a moving target. There is enough activity to require attention, and not enough certainty to plan around. The right operating posture is to build for the durable elements (documented risk process, board oversight, incident reporting, transparency) that show up in every credible proposal, and let the specifics catch up.
There is no single AI law at the federal level. The landscape breaks into four categories.
Executive Order 14110 (October 2023, revoked January 2025) was the Biden administration's comprehensive AI directive. Executive Order 14179 (January 2025) revoked it and took a different approach, emphasizing removing barriers to AI innovation. Executive orders shape federal agency behavior and procurement but do not directly bind private companies. What matters for private-sector planning is that federal agencies still enforce existing laws (Title VII, FCRA, ECOA, HIPAA, GLBA, Section 5 of the FTC Act) against AI misuse, regardless of which executive order is in force.
Every federal enforcement agency (FTC, EEOC, CFPB, SEC, HHS OCR, DOJ Civil Rights Division) has active AI enforcement programs under existing statutory authority. See Agency Enforcement. This is where federal AI legislation is already in effect, even without new legislation.
Several bills are drafted or pending. The proposed Great American AI Act is the most-discussed, drafted as a comprehensive framework similar in scope to the EU AI Act but with a lighter regulatory touch. Other bills address specific slices: deepfake liability, AI transparency for public agencies, AI training data disclosure, and AI use in specific sectors (healthcare, education, employment). Congress is also considering AI-focused amendments to existing statutes rather than standalone new laws.
The federal government is the largest single AI customer in the country. Its procurement rules, technical standards (like NIST AI RMF), and contracting requirements shape private-sector AI practice by market force. If your company sells to the federal government, contracts already require AI risk management, testing, and disclosure.
The Great American AI Act (GAAIA), released as a 269-page bipartisan discussion draft on June 4, 2026 by Reps. Jay Obernolte (R-CA) and Lori Trahan (D-MA), is the most-discussed federal AI framework in play. It is not yet formally introduced; the draft is soliciting stakeholder feedback. Its scope is narrower than the EU AI Act. Rather than tiering all AI by risk, it targets frontier AI developers, defined as entities with more than $500 million in annual revenue whose models cross specific compute thresholds.
Key GAAIA provisions include: transparency and third-party audit requirements delivered through Independent Verification Organizations (IVOs), which mirror the ISO/IEC 42001 and NIST AI RMF audit ecosystem; a three-year preemption of state laws that "specifically regulate the development of" AI models (preemption is limited to development, not post-deployment); workforce provisions including AI-driven layoff transparency; and creation of the Center for AI Standards and Innovation (CAISI) within the Department of Commerce as a federal AI standards coordinator.
The preemption provision is the most consequential element for compliance planning. If enacted as drafted, it would preempt frontier-AI-development requirements in Colorado, Texas, California, Illinois, and Connecticut for three years, without affecting downstream deployer obligations in those states. Enterprise compliance roadmaps that assume the state laws hold indefinitely may need to be reassessed as GAAIA advances.
Establishes a voluntary framework under which AI developers may give federal agencies up to 30 days of pre-release access to "covered frontier models" for evaluation. Also creates an AI cybersecurity clearinghouse and directs federal enforcement against AI-enabled cybercrime. Expressly does not create mandatory licensing or preclearance.
Directs rapid AI adoption across intelligence and warfighting domains. Includes vendor accountability provisions permitting agencies to terminate contracts with companies demonstrating "a pattern of conduct" inconsistent with administration policy. Rescinds the prior administration's NSM-25.
Directed the FTC to analyze state laws that compel alteration of "truthful outputs of AI models," providing the legal foundation for the FTC's July 1, 2026 proposed policy statement on AI accuracy (see FTC AI Enforcement) and its federal preemption argument against state AI laws.
CAISI is the operational engine behind EO 14409’s voluntary framework. Housed within NIST at the Department of Commerce, it was created by renaming and refocusing the former US AI Safety Institute, dropping “safety” from the name and pivoting toward national security, cybersecurity, and competitiveness. It serves as industry’s primary point of contact within the US government for testing commercial AI systems, develops voluntary guidelines and measurement-science best practices, and leads evaluations of AI capabilities that may pose national-security risks, focused on cybersecurity, biosecurity, and chemical-weapons potential. In May 2026 it formalized agreements with Google DeepMind, Microsoft, and xAI to evaluate their unreleased models in classified environments before public release, and in April 2026 it published a national-security evaluation of the open-weight DeepSeek V4 Pro model. The distinction that matters for compliance: CAISI issues no binding regulation and no mandatory standard. Its output is voluntary guidance and evaluation, not rule. But it is the institutional machinery that a voluntary framework runs on, and if the reported move toward government-gated model access (below) ever formalizes, CAISI is the body positioned to administer it.
As of mid-July 2026, the picture in EO 14409 may be shifting from voluntary pre-release review toward government influence over who may access frontier models. CNBC reported on July 17, 2026 that the administration has begun dictating which companies and entities are granted access to the latest frontier models, a decision that until now sat with the developers themselves, and that it launched a program (reported as “Gold Eagle”) positioning the White House to greenlight access. The same reporting notes that Anthropic’s Claude Mythos 5 and Fable 5 were briefly blocked on national-security grounds before access was restored, and that OpenAI has said it would limit new models to “trusted partners.” The White House disputes this characterization: an official stated that decisions on the timing and scope of releases “rest entirely with the companies” and that government engagement is voluntary. Treat this as a developing, disputed situation rather than settled policy. The verifiable instrument remains EO 14409 and its voluntary framework; the reported move toward access-gating is not, as of this writing, reflected in any published order or rule. Operators with frontier-model dependencies should watch whether a formal instrument follows the reporting, because a shift from voluntary review to access approval would change vendor-availability risk materially.
The House Science Committee marked up ten bipartisan AI bills with strong votes (most 29-0 to 35-0). The package signals NIST as the central federal AI standards body. Bills of note:
Four of the ten matter most for anyone running an AI programme, because each builds infrastructure that later regulation will point at.
The remaining six are H.R. 2385, H.R. 8893, H.R. 9334, H.R. 5351, H.R. 5584, and H.R. 9372, covering the CREATE AI Act (codifying the National AI Research Resource), deceptive AI content detection standards, AI workforce development, and data centre energy standards for AI compute.
Committee passage is not enactment. None of these is law. Do not plan against them as binding obligations. Plan against them as a map of where the federal government is building capacity, because that is where the requirements will eventually attach.
Introduced with bipartisan support, this bill requires visible and machine-readable disclosure on AI-generated audio, video, and image content from platforms with 10 million or more monthly US users or $1.5 billion or more in revenue. FTC would enforce; NIST would set technical standards. Endorsed by SAG-AFTRA, the Authors Guild, and the Songwriters Guild.
The operating posture is not "wait and see." It is "build the durable elements now, and adapt when specifics land." Every credible proposal, from the Great American AI Act to the various single-topic bills, shares five requirements:
An AI use inventory. A written list of every AI system in use, its purpose, its risk tier, and its owner. Every proposal requires it. Every regulator asks for it.
A documented AI risk process. How does the organization identify, assess, and treat AI risks? A written process, updated regularly, is universal.
Human oversight. A named human decision-maker in the loop for consequential AI decisions, and documentation of what that person actually does. All AI legislation preserves human oversight.
Incident reporting. A defined process for identifying AI incidents, investigating them, and (where required) reporting them externally. Timelines vary by proposal but the requirement is universal.
Transparency. AI-generated content is disclosed. AI-driven decisions are explainable to affected parties. AI systems used in high-stakes contexts have documentation available.
Building these five practices today puts you ahead of nearly every version of federal AI legislation that could pass.
Even before Congress passes anything, federal AI legislation shapes your operating environment. Executive orders drive federal agency behavior. Agency enforcement under existing statutes is expanding. State laws are filling federal gaps and creating a patchwork that federal law will eventually consolidate. The EU AI Act creates extraterritorial obligations. Insurance carriers price AI risk. Buyers demand AI compliance. All of this happens whether Congress acts or not.
The right posture is to be surprised by neither passage nor stalling. Companies that build the durable practices are ready either way. Companies that wait for legal certainty end up scrambling under whichever pressure moves first, and it will not be Congress.
The academic literature on federal AI legislation is ahead of most corporate practice, and it is unusually blunt. Two findings are worth putting in front of any executive who thinks this is a compliance formality.
“the shortcomings of conventional ex ante and ex post review under current administrative law doctrines”
That is the gap between having AI and governing it. The second finding is the one that tends to change the room.
“The promise of efficient, low-cost, or 'neutral' solutions harnessing the potential of big data has led public bodies to adopt algorithmic systems.”
Neither of these is a fringe position. Both come from peer-reviewed work, and both describe the condition most organisations are actually in when the question about federal AI legislation arrives from the board, the buyer, or the regulator.
This is the sequence that works, and it is not the sequence most organisations choose. They start with the framework and work backwards toward reality. Start with reality.
Done in this order, federal AI legislation becomes tractable. Done out of order, it becomes a document nobody uses and a control nobody exercises.
Unknown. The odds of comprehensive AI legislation in the current session are moderate. The odds of narrow, single-topic AI provisions being added to unrelated bills are higher. Congressional inaction on the comprehensive front does not mean nothing happens; it means action happens in pieces.
No. EO 14179 changed federal agency direction but did not eliminate the underlying statutory authority every federal agency uses to enforce against AI misuse. Federal enforcement continues. See Agency Enforcement for detail.
Federal law generally preempts state law when the two conflict, but AI is currently a mixed picture. Some state laws (Colorado, Texas) may be preempted by future federal law; others (Illinois biometric privacy, California disclosure rules) are likely to survive alongside federal law. See State AI Laws.
That is a business decision, not a compliance question. Industry lobbying on AI is intense. Trade associations are the most efficient channel for most operators. Direct lobbying only makes sense for firms whose business models are directly affected by specific pending language.
The AI Communication Alignment Protocol™ from Volume III (The AI Risk & Governance Review™) includes the discipline for monitoring federal legislative and regulatory developments and translating them into operating posture without over-committing to bills that may not pass. The Federal Register monitoring cadence is documented in Chapter 8.
The authoritative texts and agency pages behind this summary. We keep this page current, but where a compliance decision turns on exact wording, read the source. Anything concerning federal AI legislation that carries legal consequence should be confirmed against the enrolled text or the issuing body, not against a secondary summary, including this one.
The AI Business Enablement Audit™ measures your organization against every framework in this library, including Federal AI Legislation, and delivers a defensible governance dossier. Start or finish your audit below.
Start or finish your AI Audit →