5 Breakthrough Deals Will Govern US Frontier AI

5 Breakthrough Deals Will Govern US Frontier AI
Key Takeaways

  • The bipartisan “Great American AI Act of 2026,” introduced by Representatives Jay Obernolte and Lori Trahan, proposes $100 million annually for the Center for AI Standards and Innovation from fiscal 2027-2029, with a three-year preemption of state AI development laws that has drawn opposition from labor and civil society groups.
  • A June 2026 Executive Order invites AI developers to voluntarily submit “covered frontier AI models” for a 30-day federal cybersecurity review before release, with no mandatory licensing requirement, making uptake dependent entirely on industry willingness.
  • Colorado’s 2026 ADMT Act grants companies an affirmative defense against enforcement if they comply with the NIST AI Risk Management Framework, converting a voluntary federal standard into a concrete legal shield, a model other states may follow.

A comprehensive federal AI law in the United States remains out of reach, but June 2026 produced two concrete developments that are quietly reshaping the governance picture anyway: a detailed bipartisan legislative draft and a White House executive order that sidesteps the licensing debate entirely. Together, they reflect a deliberate strategy of narrowing ambition to find workable ground.

Bipartisan Frontier AI Governance

Representatives Jay Obernolte (R-Calif.) and Lori Trahan (D-Mass.) released the “Great American AI Act of 2026” in June, a 269-page bipartisan discussion draft focused primarily on “frontier AI models.” The proposal would codify and significantly expand the Center for AI Standards and Innovation (CAISI) within the Commerce Department, authorising roughly $100 million per year for fiscal years 2027 through 2029. Companies covered by the bill would face safety testing requirements, independent auditing, transparency reporting and an obligation to report “critical safety incidents” to federal authorities.

The bill’s bipartisan backing does not insulate it from controversy. Its provision preempting state laws specifically regulating AI model development for three years has drawn pushback from labor advocates and civil society groups, who argue it would freeze accountability measures that states have spent years building. For businesses, the framework offers the prospect of a unified federal compliance baseline, reducing the friction of navigating state-by-state rules, but the temporary preemption creates its own uncertainty: whatever clarity emerges would need to be renegotiated when the three years expire.

Voluntary Cybersecurity Review for Advanced AI

On June 2, 2026, the Trump Administration issued an Executive Order titled “Promoting Advanced Artificial Intelligence Innovation and Security,” establishing a voluntary review process for advanced AI models before public release. Under the framework, AI developers can grant federal agencies access to their models for up to 30 days for cybersecurity and national security assessments. The administration was explicit that the order does not authorise mandatory licensing or preclearance, the entire mechanism depends on developers choosing to participate.

The order also directs agencies including the Department of Treasury, the National Security Agency and the Cybersecurity and Infrastructure Security Agency (CISA) to establish an AI cybersecurity clearinghouse, coordinating vulnerability discovery and remediation with industry. For AI developers, voluntary participation could build credibility with federal agencies and get ahead of potential national security concerns. The absence of mandates, though, means the framework’s reach will be determined largely by how much industry sees to gain from engaging, and how much it fears the alternative if voluntary cooperation is later deemed insufficient. This connects to a broader question Congress is working through, as covered in our analysis of Pentagon AI acceleration and congressional oversight.

NIST’s Expanding Influence on De Facto Standards

The National Institute of Standards and Technology‘s AI Risk Management Framework (AI RMF), originally published in January 2023, was designed as voluntary guidance. It is becoming something more. Colorado’s 2026 ADMT Act, which replaced the earlier Colorado AI Act, grants organisations an affirmative defense against regulatory enforcement if they can demonstrate compliance with the AI RMF. That single provision changes the calculus considerably: alignment with a voluntary federal framework now carries potential legal protection in at least one state.

Federal contractors face growing expectations to align with NIST guidelines as well. The practical effect is that the AI RMF is being pulled into the compliance infrastructure even without a congressional mandate driving it. For businesses assessing AI governance priorities, adopting the framework is no longer a question of best practice signalling, it is a hedge against enforcement exposure in jurisdictions where it carries legal weight, and likely more will follow Colorado’s lead.

Targeted Federal Agency Directives

The June 2026 Executive Order’s agency-level provisions illustrate a parallel track in federal AI governance: using existing authority to move quickly on specific risks, rather than waiting for comprehensive legislation. Tasking CISA, NSA and Treasury with standing up an AI cybersecurity clearinghouse targets a concrete and politically uncontroversial concern, the national security risks posed by advanced AI, through mechanisms those agencies already have authority to deploy.

For companies operating in critical infrastructure or developing AI for federal use, these directives translate into heightened cybersecurity expectations and a reasonable expectation of government coordination requests. The pace here is faster than the legislative track, and the scope is narrower, which is precisely the point. Agencies can act on cyber threats from AI without resolving the harder political questions about liability, auditing or preemption that have stalled broader bills.

State-Level Sector-Specific and Risk-Based Laws

With federal legislation still unsettled, states have continued to fill the gap. As of early 2026, 45 states had introduced more than 1,500 AI-related bills, according to reports, covering generative AI, algorithmic accountability and deepfake protections. Illinois recently passed legislation requiring AI companies to develop frameworks addressing “catastrophic risks,” including scenarios where AI systems could facilitate the development of chemical, biological or nuclear weapons, or be used to commit serious crimes. New York City’s Local Law 144, meanwhile, requires bias audits for automated employment decision tools.

These state measures tend to succeed where federal bills have stalled, largely because they target specific, high-impact harms rather than attempting to regulate AI broadly. That narrowness makes them harder to oppose on political grounds. The compliance burden for businesses, however, accumulates: a patchwork of state-specific rules focused on consumer protection, ethical use and civil rights creates real operational complexity, and it is that complexity, more than any single law, that gives federal preemption proposals their appeal to industry. For a broader view of how this federal-state tension is playing out across AI policy, see our recent AI policy roundup.

What the five tracks described here, bipartisan frontier legislation, voluntary cybersecurity review, NIST framework integration, agency-level directives and state-specific laws, share is a recognition that a single comprehensive federal AI law is not imminent. The governance architecture being built in its place is incremental and deliberately fragmented, pieced together from narrower agreements, existing authority and voluntary mechanisms. Whether that architecture proves durable or simply delays harder questions about accountability and enforcement is the central uncertainty that businesses and policymakers alike are navigating. For more coverage of AI policy and regulation, visit our AI Policy & Regulation section.

Jordan Mills
Jordan Mills

Jordan covers AI policy, regulation, and ethics across global markets. With a focus on governance frameworks and compliance, Jordan tracks the regulatory forces shaping the AI industry.

📰 Journalists welcome — cite Auton AI News with attribution. Press & Media → | press@autonainews.com