web analytics
AI Governance

Federal AI Legislation

Pending U.S. AI Bills and the Great American AI Act

The one-paragraph answer

Federal AI legislation in the United States remains fragmented. Congress has not passed a comprehensive AI law. What exists is a growing collection of bills, executive orders, and agency directives that shape how federal actors treat AI. The most-watched draft is the Great American AI Act, but multiple other proposals cover safety, deepfakes, transparency, and employment AI. The operating posture for executives: prepare as if federal law will move, without overcommitting to any specific bill's language.

The pain federal AI legislation is causing our customers

Every executive we advise asks the same question: "When will Congress do something?" The honest answer is that Congress may or may not act on AI in the current session, and the exact shape of any law will change five times before enactment. That uncertainty is the pain. Companies do not want to build for a law that never passes. They also do not want to be caught unprepared if it does. So they wait, and while they wait, states pass their own laws, agencies pursue enforcement under existing authorities, and the EU AI Act starts binding US companies through extraterritorial reach.

The pain of federal AI legislation is the pain of a moving target. There is enough activity to require attention, and not enough certainty to plan around. The right operating posture is to build for the durable elements (documented risk process, board oversight, incident reporting, transparency) that show up in every credible proposal, and let the specifics catch up.

What federal AI legislation currently looks like

There is no single AI law at the federal level. The landscape breaks into four categories.

Executive orders

Executive Order 14110 (October 2023, revoked January 2025) was the Biden administration's comprehensive AI directive. Executive Order 14179 (January 2025) revoked it and took a different approach, emphasizing removing barriers to AI innovation. Executive orders shape federal agency behavior and procurement but do not directly bind private companies. What matters for private-sector planning is that federal agencies still enforce existing laws (Title VII, FCRA, ECOA, HIPAA, GLBA, Section 5 of the FTC Act) against AI misuse, regardless of which executive order is in force.

Standing agency authority

Every federal enforcement agency (FTC, EEOC, CFPB, SEC, HHS OCR, DOJ Civil Rights Division) has active AI enforcement programs under existing statutory authority. See Agency Enforcement. This is where federal AI legislation is already in effect, even without new legislation.

Legislation in progress

Several bills are drafted or pending. The proposed Great American AI Act is the most-discussed, drafted as a comprehensive framework similar in scope to the EU AI Act but with a lighter regulatory touch. Other bills address specific slices: deepfake liability, AI transparency for public agencies, AI training data disclosure, and AI use in specific sectors (healthcare, education, employment). Congress is also considering AI-focused amendments to existing statutes rather than standalone new laws.

Federal AI procurement and contracting rules

The federal government is the largest single AI customer in the country. Its procurement rules, technical standards (like NIST AI RMF), and contracting requirements shape private-sector AI practice by market force. If your company sells to the federal government, contracts already require AI risk management, testing, and disclosure.

The Great American AI Act (discussion draft, June 2026)

The Great American AI Act (GAAIA), released as a 269-page bipartisan discussion draft on June 4, 2026 by Reps. Jay Obernolte (R-CA) and Lori Trahan (D-MA), is the most-discussed federal AI framework in play. It is not yet formally introduced; the draft is soliciting stakeholder feedback. Its scope is narrower than the EU AI Act. Rather than tiering all AI by risk, it targets frontier AI developers, defined as entities with more than $500 million in annual revenue whose models cross specific compute thresholds.

Key GAAIA provisions include: transparency and third-party audit requirements delivered through Independent Verification Organizations (IVOs), which mirror the ISO/IEC 42001 and NIST AI RMF audit ecosystem; a three-year preemption of state laws that "specifically regulate the development of" AI models (preemption is limited to development, not post-deployment); workforce provisions including AI-driven layoff transparency; and creation of the Center for AI Standards and Innovation (CAISI) within the Department of Commerce as a federal AI standards coordinator.

The preemption provision is the most consequential element for compliance planning. If enacted as drafted, it would preempt frontier-AI-development requirements in Colorado, Texas, California, Illinois, and Connecticut for three years, without affecting downstream deployer obligations in those states. Enterprise compliance roadmaps that assume the state laws hold indefinitely may need to be reassessed as GAAIA advances.

Executive orders and national security directives in force

Executive Order 14409 (Frontier AI Pre-Release Framework, June 2, 2026)

Establishes a voluntary framework under which AI developers may give federal agencies up to 30 days of pre-release access to "covered frontier models" for evaluation. Also creates an AI cybersecurity clearinghouse and directs federal enforcement against AI-enabled cybercrime. Expressly does not create mandatory licensing or preclearance.

National Security Presidential Memorandum 11 (NSPM-11, June 5, 2026)

Directs rapid AI adoption across intelligence and warfighting domains. Includes vendor accountability provisions permitting agencies to terminate contracts with companies demonstrating "a pattern of conduct" inconsistent with administration policy. Rescinds the prior administration's NSM-25.

Executive Order 14365 (December 2025)

Directed the FTC to analyze state laws that compel alteration of "truthful outputs of AI models," providing the legal foundation for the FTC's July 1, 2026 proposed policy statement on AI accuracy (see FTC AI Enforcement) and its federal preemption argument against state AI laws.

Center for AI Standards and Innovation (CAISI), the body that runs the evaluations

CAISI is the operational engine behind EO 14409’s voluntary framework. Housed within NIST at the Department of Commerce, it was created by renaming and refocusing the former US AI Safety Institute, dropping “safety” from the name and pivoting toward national security, cybersecurity, and competitiveness. It serves as industry’s primary point of contact within the US government for testing commercial AI systems, develops voluntary guidelines and measurement-science best practices, and leads evaluations of AI capabilities that may pose national-security risks, focused on cybersecurity, biosecurity, and chemical-weapons potential. In May 2026 it formalized agreements with Google DeepMind, Microsoft, and xAI to evaluate their unreleased models in classified environments before public release, and in April 2026 it published a national-security evaluation of the open-weight DeepSeek V4 Pro model. The distinction that matters for compliance: CAISI issues no binding regulation and no mandatory standard. Its output is voluntary guidance and evaluation, not rule. But it is the institutional machinery that a voluntary framework runs on, and if the reported move toward government-gated model access (below) ever formalizes, CAISI is the body positioned to administer it.

The July 2026 access-control escalation (reported, contested)

As of mid-July 2026, the picture in EO 14409 may be shifting from voluntary pre-release review toward government influence over who may access frontier models. CNBC reported on July 17, 2026 that the administration has begun dictating which companies and entities are granted access to the latest frontier models, a decision that until now sat with the developers themselves, and that it launched a program (reported as “Gold Eagle”) positioning the White House to greenlight access. The same reporting notes that Anthropic’s Claude Mythos 5 and Fable 5 were briefly blocked on national-security grounds before access was restored, and that OpenAI has said it would limit new models to “trusted partners.” The White House disputes this characterization: an official stated that decisions on the timing and scope of releases “rest entirely with the companies” and that government engagement is voluntary. Treat this as a developing, disputed situation rather than settled policy. The verifiable instrument remains EO 14409 and its voluntary framework; the reported move toward access-gating is not, as of this writing, reflected in any published order or rule. Operators with frontier-model dependencies should watch whether a formal instrument follows the reporting, because a shift from voluntary review to access approval would change vendor-availability risk materially.

The House Science Committee package (June 25, 2026)

The House Science Committee marked up ten bipartisan AI bills with strong votes (most 29-0 to 35-0). The package signals NIST as the central federal AI standards body. Bills of note:

Four of the ten matter most for anyone running an AI programme, because each builds infrastructure that later regulation will point at.

  • H.R. 9363, AI Security and Innovation Act. Statutorily establishes the Center for AI Security and Innovation (CAISI) by amending the National AI Initiative Act of 2020. This is frequently described as "codifying the AI Safety Institute." That is not accurate, and the distinction matters if you are citing the statute.
  • H.R. 9333, AI Flaw Reporting and Security Enhancement Act. Creates a national AI vulnerability database and a coordinated disclosure process. This is infrastructure AI security currently does not have, which is why AI vulnerability handling is still ad hoc.
  • H.R. 6461, READ AI Models Act. Directs NIST to develop standardised model documentation templates. The federal analogue of what the AIBOM practice is already attempting privately.
  • H.R. 9341, AI-Ready Federal Data Guidelines Act. Voluntary NIST guidelines for preparing federal data for AI training. Expect these to shape data provenance expectations well beyond federal agencies.

The remaining six are H.R. 2385, H.R. 8893, H.R. 9334, H.R. 5351, H.R. 5584, and H.R. 9372, covering the CREATE AI Act (codifying the National AI Research Resource), deceptive AI content detection standards, AI workforce development, and data centre energy standards for AI compute.

Committee passage is not enactment. None of these is law. Do not plan against them as binding obligations. Plan against them as a map of where the federal government is building capacity, because that is where the requirements will eventually attach.

The AI Labeling Act of 2026 (Senate, June 25, 2026)

Introduced with bipartisan support, this bill requires visible and machine-readable disclosure on AI-generated audio, video, and image content from platforms with 10 million or more monthly US users or $1.5 billion or more in revenue. FTC would enforce; NIST would set technical standards. Endorsed by SAG-AFTRA, the Authors Guild, and the Songwriters Guild.

What operating posture federal AI legislation requires you to hold

The operating posture is not "wait and see." It is "build the durable elements now, and adapt when specifics land." Every credible proposal, from the Great American AI Act to the various single-topic bills, shares five requirements:

An AI use inventory. A written list of every AI system in use, its purpose, its risk tier, and its owner. Every proposal requires it. Every regulator asks for it.

A documented AI risk process. How does the organization identify, assess, and treat AI risks? A written process, updated regularly, is universal.

Human oversight. A named human decision-maker in the loop for consequential AI decisions, and documentation of what that person actually does. All AI legislation preserves human oversight.

Incident reporting. A defined process for identifying AI incidents, investigating them, and (where required) reporting them externally. Timelines vary by proposal but the requirement is universal.

Transparency. AI-generated content is disclosed. AI-driven decisions are explainable to affected parties. AI systems used in high-stakes contexts have documentation available.

Building these five practices today puts you ahead of nearly every version of federal AI legislation that could pass.

Why federal AI legislation matters to you

Even before Congress passes anything, federal AI legislation shapes your operating environment. Executive orders drive federal agency behavior. Agency enforcement under existing statutes is expanding. State laws are filling federal gaps and creating a patchwork that federal law will eventually consolidate. The EU AI Act creates extraterritorial obligations. Insurance carriers price AI risk. Buyers demand AI compliance. All of this happens whether Congress acts or not.

The right posture is to be surprised by neither passage nor stalling. Companies that build the durable practices are ready either way. Companies that wait for legal certainty end up scrambling under whichever pressure moves first, and it will not be Congress.

What the research says about federal AI legislation

The academic literature on federal AI legislation is ahead of most corporate practice, and it is unusually blunt. Two findings are worth putting in front of any executive who thinks this is a compliance formality.

“the shortcomings of conventional ex ante and ex post review under current administrative law doctrines”

That is the gap between having AI and governing it. The second finding is the one that tends to change the room.

“The promise of efficient, low-cost, or 'neutral' solutions harnessing the potential of big data has led public bodies to adopt algorithmic systems.”

Neither of these is a fringe position. Both come from peer-reviewed work, and both describe the condition most organisations are actually in when the question about federal AI legislation arrives from the board, the buyer, or the regulator.

How to get compliant with Federal AI Legislation: a 5-step path

This is the sequence that works, and it is not the sequence most organisations choose. They start with the framework and work backwards toward reality. Start with reality.

  1. Inventory the AI in scope. List every AI system that could fall under federal AI legislation. Record what it does, what decision it influences, what data it touches, and who owns it. You cannot govern AI you cannot name, and almost every organisation we assess is running more AI than its leadership believes.
  2. Determine whether you are actually in scope. Work out precisely which of your AI systems and activities federal AI legislation reaches, and write the determination down with its reasoning. Do this in writing. A documented scope determination, right or wrong, is defensible. An undocumented assumption is not.
  3. Assign one accountable owner. Name a person, not a committee, with the authority to stop a deployment. Governance without someone who can say no is documentation, not control.
  4. Build the evidence file. Assemble the documentation federal AI legislation expects: the scope, the risk assessment, the controls, the testing evidence, and the incident record. Assemble it before anyone asks. Reconstructing it under a regulator's deadline costs several times more and looks exactly like what it is.
  5. Set a review cadence and hold it. Re-run the assessment on a schedule and after any material change to the model, the data, or the use case. Alignment decays. A control tested once is a snapshot, not a control.

Done in this order, federal AI legislation becomes tractable. Done out of order, it becomes a document nobody uses and a control nobody exercises.

Frequently asked questions about federal AI legislation

When will Congress pass an AI law?

Unknown. The odds of comprehensive AI legislation in the current session are moderate. The odds of narrow, single-topic AI provisions being added to unrelated bills are higher. Congressional inaction on the comprehensive front does not mean nothing happens; it means action happens in pieces.

Does the revocation of Executive Order 14110 mean AI is deregulated?

No. EO 14179 changed federal agency direction but did not eliminate the underlying statutory authority every federal agency uses to enforce against AI misuse. Federal enforcement continues. See Agency Enforcement for detail.

How does federal AI legislation interact with state AI laws?

Federal law generally preempts state law when the two conflict, but AI is currently a mixed picture. Some state laws (Colorado, Texas) may be preempted by future federal law; others (Illinois biometric privacy, California disclosure rules) are likely to survive alongside federal law. See State AI Laws.

Should we lobby on federal AI legislation?

That is a business decision, not a compliance question. Industry lobbying on AI is intense. Trade associations are the most efficient channel for most operators. Direct lobbying only makes sense for firms whose business models are directly affected by specific pending language.

Where does federal AI legislation show up in SRJ's work?

The AI Communication Alignment Protocol™ from Volume III (The AI Risk & Governance Review™) includes the discipline for monitoring federal legislative and regulatory developments and translating them into operating posture without over-committing to bills that may not pass. The Federal Register monitoring cadence is documented in Chapter 8.

Primary sources on federal AI legislation

The authoritative texts and agency pages behind this summary. We keep this page current, but where a compliance decision turns on exact wording, read the source. Anything concerning federal AI legislation that carries legal consequence should be confirmed against the enrolled text or the issuing body, not against a secondary summary, including this one.

Ready to see where you stand?

The AI Business Enablement Audit™ measures your organization against every framework in this library, including Federal AI Legislation, and delivers a defensible governance dossier. Start or finish your audit below.

Start or finish your AI Audit →
Schedule a Free AI Consultation