RSS Amplifier

Tech and Democracy · Aug 7, 2026

Five Reasons AI Regulation Is Coming To The US, How And When

0
Sign in to vote or save

Paulo Carvao · Tech and Democracy

A version of this article was published on Forbes on August 1, 2026.

AI Regulation debate shifts as cyber incidents and U.S. politics push frontier labs toward trust-building oversight (illustrated by ChatGPT).

This post is public so feel free to share it.

Share

“Move fast and break things.” Mark Zuckerberg, then Facebook’s chief executive, used the now-infamous line in a February 2012 investor letter. Since then, the industry moved fast and has broken things. What may have seemed acceptable in the early days of consumer software looks quite different after more than a decade of hard lessons about social media’s impact on youth and as AI use becomes pervasive. AI regulation can no longer wait.

The recent cybersecurity incidents highlight the issue. OpenAI said models under evaluation helped an agent compromise Hugging Face’s production infrastructure; the Associated Press later reported that Anthropic also detected that its models hacked three organizations during their own cyber testing. These events showed how internal lab benchmarks can become external cyber events with real-world consequences. This month, Europe started the EU AI Act transparency enforcement while, in Washington, the U.S. is navigating a June executive order that characterizes advanced AI at the same time as an innovation priority and a security problem. The Trump administration continues to rely heavily on executive action while Congress, probably more than ever before, tests legislative lanes.

AI Regulation now has urgency, a political constituency to respond to and a cyber trigger for action. As the large frontier AI labs prepare to go public, AI has entered the trust business.

The industry is no longer only asking to be left alone and all of its key players recently issued position statements on AI and regulation.

OpenAI backs a national AI safety standard, with independent audits and incident reporting for frontier models while warning that a patchwork of state laws is hard to enforce and diverts developer resources from safety. Chris Lehane, OpenAI’s chief global affairs officer, stated that the U.S. is “sowing self-imposed chaos when we would benefit from a strategic coherence.”

Anthropic, by contrast, argues for mandatory testing, independent evaluation and government authority to block deployments that pose catastrophic risk, backed by revenue-based penalties. Dario Amodei, Anthropic’s CEO, highlights the urgency, saying that “in the several years that it can take Congress to act, AI can go from an amusing toy to the full country of geniuses.” Where OpenAI wants federal law to override the states, Anthropic favors preserving state AI laws unless Congress passes something at least as strong, framing preemption as a floor to build on rather than a ceiling to what legislation can impose.

“We don’t have to choose between over-regulation and no regulation—there’s a thoughtful middle way,” Kent Walker, Google and Alphabet’s president of global affairs, says on X. Differently from the other two frontier labs, Google proposes a two-track approach with an independent, federally overseen, industry-backed body to set safety standards and verify voluntary audits for frontier models, while updating existing laws to cover child safety, copyright and workforce impacts for the most widely used applications.

Microsoft, Meta and Nvidia, through an open-weights coalition, focus on how open models expand competition and defensive cybersecurity, while premature restrictions could entrench a few closed providers. Nvidia’s CEO, Jensen Huang, highlighted in his first post on X that “Open models strengthen safety and cybersecurity, accelerate innovation and diffusion, and enable sovereignty.” In a rare opinion piece in the Wall Street Journal, Zuckerberg, speaking about the arrival of superintelligence, asked: “Will it be centralized and restricted to a few institutions, or will it be a tool that empowers everyone?” The industry is actively working to influence the administration’s position, with Anthropic and OpenAI, the two largest frontier labs, aligned with national security hawks on one side, and Microsoft, Meta, Nvidia and most of the rest of the industry on the other.

These positions converge on evaluations and incident reporting but diverge on preemption, open weights and who gets to test, which is exactly the terrain the administration’s June executive order is now navigating. That order leans toward voluntary testing, government access and security coordination rather than a licensing regime, while the states have moved further and faster. California’s Transparency in Frontier AI Act, New York’s RAISE Act and Illinois’s AI Safety Measures Act already enacted disclosure requirements, safety plans, audit rights and incident reporting, and Colorado and Texas have added their own rules for high-risk deployments, disclosure and prohibitions. This collection of state laws is building a national regime by accumulation, which is the outcome the industry’s federal lobbying push is trying to preempt.

At the federal level, Congress now has opened several lanes. In the House, Rep. Lori Trahan, D-Mass., and Rep. Jay Obernolte, R-Calif., sponsored the FRONTIER Act, part of the broader Great American AI Act discussion draft, which would require powerful model developers to conduct risk assessments, submit to independent evaluation and report safety incidents. Sen. Mark Warner, D-Va., vice chairman of the Senate Select Committee on Intelligence, unveiled “A Framework for America’s AI Future,” a comprehensive legislative agenda that goes further on mandatory pre-deployment testing and data-center transparency, requiring large AI data centers to disclose energy and water use and tying federal tax benefits to efficiency standards. A kill-switch proposal by Rep. Ted Lieu, D-Calif., and Rep. Nathaniel Moran, R-Texas, would authorize emergency containment after a catastrophic incident. The broader Great American AI Act seeks one federal baseline, while antitrust and chatbot bills target risk-sharing, labeling and consumer deception. The central fight is preemption: whether federal law becomes a floor that states can exceed or a ceiling that freezes them out.

The FRONTIER Act reflects elements of the dynamic, standards-based governance model I have advocated for years. Its independent audits and continuing assessments would let rules evolve with the technology instead of freezing at the moment of passage. Beyond the political will needed to pass it, the open question is whether the U.S. can make collaboration between industry and government transparent enough to avoid capture.

The pressure for action around AI regulation in the U.S. is building from five different angles:

1. AI has become a kitchen-table issue. Voters now connect AI effects to jobs, schools, fraud, their electricity bills, erosion of their privacy, children’s safety and democracy. Once AI becomes a local issue, lawmakers can no longer treat it as a niche debate and ignore it.

2. Negative sentiment towards AI increases the industry’s social license costs. Anxiety about data centers, social media platforms, children’s mental health and increased litigation now adds to concerns about model safety. If the public sees AI companies as powerful but unaccountable, trust will erode and adoption can slow, interrupting the flywheel effect that companies are relying on to continue to raise capital.

3. Cyber incidents have turned loss-of-control language into operational risk. If a model can escape from a controlled test environment and break into a third-party system, the debate crosses into national security and systemic risk to financial markets and public infrastructure. What used to be a hypothetical and remote issue has now happened, affecting multiple AI providers.

4. Frontier labs are moving toward public-company disciplines. The movement to public markets (IPOs) and public-market financing requires disclosure, compliance processes and legal predictability. Stable rules are needed to support capital formation, especially at the scale required by frontier AI development.

5. The U.S. risks further eroding its rulemaking initiative. With the EU AI Act entering its enforcement phase and states enacting their own frameworks, the absence of a federal approach no longer means deregulation. The rules that some in the industry were trying to avoid are being set by Brussels, state capitals, non-durable executive orders or agency improvisation, in what is a worst-case scenario for those concerned with fragmentation. Congress has an incentive to act if it wants a national framework that reflects U.S. priorities.

My prediction is that we will enter a phase of layered regulation. Over the next few months, expect short-term implementation via executive orders, including voluntary and classified pre-release model benchmarking and testing. In parallel, the state disclosure rules and local fights over data centers and permitting will continue. In this environment, the U.S. Congress has an 18-month window to pass federal laws governing AI if it starts with narrow questions that already have bipartisan support, such as incident reporting, independent evaluation, government testing, cybersecurity (including incident containment) and clear accountability for catastrophic risk.

One of the leading proposals on the table, the FRONTIER Act, could move if lawmakers separate transparency and verification requirements from harder fights over preemption and open weights. States have moved because Congress did not. Industry wants one rulebook because fragmented law is expensive and legally unstable. A better federal law should treat state-level initiatives as proof of concept, preserve state consumer authority where harms are local and centralize only decisions requiring classified expertise or interstate scale.

Stable rules could also help the industry. Incident reporting and independent audits may feel burdensome inside a fast-moving company, but they can become the legal underpinnings investors need to finance models and data centers. Rep. Lori Trahan captured the political appeal when she said, “Americans deserve confidence that the most powerful models are being developed responsibly.”

AI Regulation will only succeed if it restores trust without turning safety into an innovation tax collected by incumbents. Future policy should make companies prove their systems can be contained, give government enough access to verify high-risk claims and give the public enough visibility to believe the bargain they are being asked to take.

No posts

Read the original on carvao.substack.com

Comments

Nothing yet. Say the first thing.

    Sign in to join the conversation.