Bipartisan 'Great American AI Act' Draft Proposes Audits for Frontier Models and Preemption of State Laws
A sweeping 269-page legislative draft aims to replace a fragmented state-by-state AI regulatory patchwork with a unified federal framework. The bill imposes strict auditing mandates on the largest developers while preserving state authority over how businesses deploy AI tools.
By Madison Lane
- Startups & Enterprise Adopters
- Benefit from the regulatory clarity and the NAIRR computing resources without bearing the heavy compliance costs of frontier developers.
- Frontier AI Developers
- Support federal preemption to avoid 50 different state laws, but face the brunt of the new auditing and transparency mandates.
- Labor & Consumer Advocates
- Oppose the preemption of state laws, fearing it will wipe out local protections, but support the WARN Act amendments and whistleblower protections.
- Human Resources & Compliance Teams
- Focused on the practical implications of the deployment rules, WARN Act disclosures, and navigating the remaining state-level obligations.
Why it matters
For startups and enterprise builders, navigating 50 different state AI laws is an existential compliance cost. This federal framework would freeze state-level model development rules, providing the regulatory certainty needed to attract investment while shielding smaller companies from the heaviest auditing burdens.
Two hundred and sixty-nine pages. That is the exact length of the bipartisan discussion draft for the Great American Artificial Intelligence Act (GAAIA), released by Representatives Jay Obernolte (R-CA) and Lori Trahan (D-MA). The sweeping legislative proposal represents the most substantive federal attempt to date to settle a jurisdictional fight that Washington has spent the last two years losing to state legislatures in California, New York, and Colorado. By proposing a comprehensive national framework for AI governance, the draft aims to balance rapid technological innovation with concrete safeguards for national security and workforce stability. For the technology sector, the bill signals that the era of hands-off federal oversight is ending, replaced by a structured regime that targets the largest developers while attempting to clear the regulatory runway for smaller startups and enterprise adopters. The draft incorporates provisions from several existing bipartisan bills, reflecting a consolidated effort to push AI policy forward in a divided Congress.[1][2][6]
For entrepreneurs and enterprise builders, the most consequential mechanism in the draft is its proposed three-year preemption of state laws that specifically regulate the development of AI models. Currently, artificial intelligence governance operates almost entirely on a state-by-state basis, creating a fragmented compliance landscape that imposes heavy costs on businesses unable to staff policy teams in fifty different capitals. The GAAIA would freeze this state-level rulemaking for model development, replacing it with a single federal floor that sunsets after three years unless reauthorized. Proponents argue this national uniformity is essential for maintaining United States leadership in artificial intelligence and preventing a scenario where American companies regulate themselves into falling behind international competitors. By preempting state laws, the federal government aims to establish a standardized testing, evaluation, and oversight framework that provides regulatory certainty for investors and founders alike.[1][3]
The legislation achieves this regulatory balance by dividing the AI ecosystem into two distinct tiers, ensuring that innovation at the startup level is not smothered by enterprise-grade compliance burdens. The heaviest obligations fall exclusively on developers of "frontier" AI models—defined in the draft as companies generating more than $500 million in annual revenue that are building cutting-edge, general-purpose systems. These hyperscale developers would be required to publish comprehensive safety frameworks, report critical safety incidents to the federal government within fifteen days, and submit to mandatory third-party audits twice a year. By isolating these rigorous requirements to the largest and most capitalized players in the market, the bill intentionally shields the vast majority of typical businesses, early-stage startups, and in-house AI developers from the most stringent and costly compliance mandates.[2][6]
However, the preemption clause is significantly narrower than early headlines suggested, drawing a sharp legal distinction between the "development" of AI models and their eventual "deployment." While states would be barred from regulating how core models are built, trained, and tested, the draft explicitly preserves state authority over how artificial intelligence is used in practice by end-users and corporations. State laws governing the application of AI in employment decisions, housing approvals, credit scoring, healthcare diagnostics, and education would remain entirely intact, alongside existing privacy and consumer-protection statutes. For human resources departments and corporate compliance teams, this means that many of the day-to-day legal risks associated with deploying commercial AI tools will remain unchanged, requiring ongoing vigilance at the state level.[3][4][6]
To manage this new federal oversight regime, the legislation would formally codify the Center for AI Standards and Innovation (CAISI) within the Department of Commerce. Funded at $100 million annually for fiscal years 2027 through 2029, CAISI would serve as the central federal hub for AI evaluation, standards development, and incident reporting. The agency would be tasked with developing voluntary guidelines for AI security, interpretability, synthetic content detection, and cyber incident response. Crucially, CAISI would also oversee the independent verification organizations (IVOs) responsible for conducting the mandatory semi-annual audits of frontier model developers. This establishes a standardized, government-backed auditing ecosystem that currently does not exist, providing a clear framework for how advanced models will be evaluated for safety and alignment before they reach the public market.[2][3][6]
To manage this new federal oversight regime, the legislation would formally codify the Center for AI Standards and Innovation (CAISI) within the Department of Commerce.
Beyond technical standards and model safety, the GAAIA introduces significant new mechanisms to address labor market anxieties and workforce displacement. The bill proposes a major amendment to the Worker Adjustment and Retraining Notification (WARN) Act, requiring employers to make additional disclosures when artificial intelligence is a "substantial factor" in a qualifying mass layoff. This provision forces companies to be transparent about automation-driven restructuring, providing federal agencies and policymakers with better data on AI's actual, quantified impact on the labor market. This legislative push for labor data coincides with recent market analyses; for instance, Goldman Sachs reported this week that AI is already beginning to weigh on employment across developed economies. Additionally, the bill directs the Bureau of Labor Statistics and the Census Bureau to revise federal surveys to explicitly track AI adoption and usage across different industries, moving the conversation from anecdotal fears to measurable economic indicators.[4][5][6]
A critical compliance shift for all employers involves the establishment of robust federal whistleblower protections designed to uncover unsafe practices. The draft legislation protects employees and independent contractors who report what the bill defines as "AI violations"—any breach of federal law related to the development, deployment, or operation of artificial intelligence systems. Notably, these whistleblower protections are not limited to the frontier developers targeted by the auditing requirements; they extend to workers at any employer utilizing AI systems in their daily operations. This broad definition reflects a growing enforcement trend toward applying existing fraud and misconduct frameworks to AI-enabled corporate behavior, ensuring that workers who flag discriminatory algorithms or unsafe deployments are shielded from retaliation.[3][4]
For the broader research and startup ecosystem, the legislation offers a major infrastructure boost by codifying the National Artificial Intelligence Research Resource (NAIRR). Originally launched as a pilot program by the National Science Foundation, NAIRR provides researchers, academic institutions, and small private-sector entities with access to the massive computing power, datasets, and software required to train advanced models. By establishing NAIRR as a permanent statutory resource, the bill aims to democratize AI development, ensuring that breakthroughs are not exclusively the domain of a few heavily capitalized technology giants. This federal investment in shared testbeds and computing infrastructure is designed to lower the barrier to entry for academic researchers and early-stage founders competing in a capital-intensive market.[2][6]
The proposed preemption of state laws remains the most fiercely contested element of the discussion draft, exposing deep fault lines between industry advocates and civil society groups. Business coalitions and technology trade groups have largely praised the provision, arguing that a unified federal standard is the only practical way to govern a technology whose risks and benefits do not stop at state lines. They contend that a patchwork of fifty different regulatory regimes stifles innovation, creates conflicting legal obligations, and disproportionately harms smaller developers who cannot absorb the associated legal overhead required to navigate a fragmented national market.[1][3]
Conversely, a coalition of labor advocates, consumer protection organizations, and several state attorneys general have strongly opposed the preemption clause. Critics argue that the legal boundary between model "development" and "deployment" is porous and poorly defined, potentially wiping out crucial state-level safety statutes in jurisdictions like California and Colorado before Congress has finished writing a durable federal replacement. These groups maintain that a federal floor should not become a ceiling that ties the hands of state lawmakers during the most formative years of the technology's evolution, warning that a three-year freeze could leave consumers vulnerable to rapid advancements that outpace federal rulemaking.[1][2][6]
The legislation also includes significant cybersecurity provisions aimed at securing the foundational architecture of the AI ecosystem. The draft would reauthorize the Cybersecurity Act of 2015 through 2035 and authorize the Cybersecurity and Infrastructure Security Agency (CISA), in consultation with CAISI, to award grants to eligible maintainers of designated critical open-source software. This acknowledges the reality that much of the modern AI stack relies on open-source components maintained by underfunded volunteer communities. By directing federal grants to secure these critical dependencies, the bill attempts to harden the software supply chain against state-sponsored cyber threats and vulnerabilities that could compromise downstream AI applications.[2][3]
As a discussion draft, the GAAIA was explicitly released to draw fire and solicit stakeholder feedback before formal introduction, and it has succeeded in sparking a national debate. While the legislation faces significant hurdles and is unlikely to advance before the current congressional recess, it establishes the definitive baseline for how the 2027 Congress will approach AI governance. For enterprise compliance teams, human resources departments, and startup founders, the draft serves as a clear planning signal: federal intervention in the artificial intelligence market is no longer a hypothetical scenario, and the window for shaping those rules is actively closing.[3][4][6]
What to know
- A bipartisan 269-page discussion draft proposes a comprehensive federal framework for artificial intelligence governance in the United States.
- The bill would preempt state laws specifically regulating the development of AI models for three years, replacing them with a single federal floor.
- Frontier developers generating over $500 million in revenue would face mandatory semi-annual third-party audits and incident reporting requirements.
- State authority over how AI is deployed in areas like employment, housing, and healthcare remains entirely intact.
- The legislation amends the WARN Act to require disclosures when AI is a substantial factor in qualifying mass layoffs.
Key terms
- Frontier AI Models
- Highly capable, general-purpose artificial intelligence systems that match or exceed the capabilities of the most advanced models currently available.
- Federal Preemption
- A legal doctrine where federal law supersedes and invalidates conflicting state or local laws.
- NAIRR
- The National Artificial Intelligence Research Resource, a shared federal infrastructure providing computing power and datasets to researchers and startups.
- WARN Act
- The Worker Adjustment and Retraining Notification Act, a labor law requiring employers to provide advance notice of significant mass layoffs or plant closings.
- CAISI
- The Center for AI Standards and Innovation, the proposed federal hub for AI evaluation and standards development.
Reader questions
Does the Great American AI Act ban states from regulating AI entirely?
No. The bill only preempts state laws that specifically regulate the "development" of AI models. States retain full authority to regulate how AI is "deployed" or used in areas like employment, housing, and healthcare.
Which companies are subject to the new mandatory third-party audits?
The strictest requirements, including semi-annual audits, apply only to "frontier" AI developers—defined as companies generating more than $500 million in annual revenue that are building cutting-edge, general-purpose models.
How does the bill affect mass layoffs?
The draft amends the WARN Act to require employers to make additional disclosures if artificial intelligence is a "substantial factor" in a qualifying mass layoff, increasing transparency around automation-driven job losses.
What is the Center for AI Standards and Innovation (CAISI)?
CAISI is a proposed agency within the Commerce Department, funded at $100 million annually, that would develop voluntary AI security guidelines and oversee the independent organizations conducting frontier model audits.
Sources
[1]Roll CallFrontier AI DevelopersBipartisan AI draft proposes three-year preemption of state laws
Read on Roll Call →
[2]FedScoopFrontier AI DevelopersBipartisan Great American AI Act draft proposes new federal AI governance framework
Read on FedScoop →
[3]Fisher PhillipsLabor & Consumer AdvocatesCongress Proposes First Comprehensive Federal AI Framework
Read on Fisher Phillips →
[4]SHRMHuman Resources & Compliance TeamsWhat HR Needs to Know About the Great American AI Act of 2026
Read on SHRM →
[5]CNBCLabor & Consumer AdvocatesGoldman studied where AI is squeezing labor markets. Here's what it found
Read on CNBC →
[6]Factlen Editorial TeamStartups & Enterprise AdoptersSynthesis by Factlen editorial team
Read on Factlen Editorial Team →
Comments
Every angle. Every day.
Get business stories with full source coverage and perspective breakdowns delivered to your inbox.
