Insight

Breaking Down the Great American Artificial Intelligence Act

Executive Summary

  • The Great American AI Act (GAAIA) discussion draft represents Congress’ most significant attempt to establish a federal governance framework for frontier artificial intelligence (AI) development—the most advanced, powerful, general-purpose AI models available—while largely preserving state authority over AI deployment and consumer applications.
  • Amid a growing patchwork of state AI laws, the bill seeks to establish a single federal baseline—rooted in transparency and accountability standards—for the development of frontier AI, with proponents arguing that nationally consistent standards can better support innovation while reducing regulatory fragmentation.
  • While the bill seeks to offer a middle ground between highly prescriptive and lighter-touch approaches and addresses several important aspects of the AI policy debate, it also raises important questions about where to draw the line between AI development and deployment, whether transparency and accountability are sufficient to govern frontier AI risks, and whether state preemption leaves enough room to address other AI regulatory issues.

Introduction

The recently released Great American AI Act (GAAIA) discussion draft represents Congress’ most significant attempt to establish a federal governance framework for frontier artificial intelligence (AI) development—the most powerful and general-purpose AI models available—while largely preserving state authority over AI deployment and consumer applications. By releasing the bill as a discussion draft, the sponsors seek feedback from industry, academia, civil society, and the public before formally introducing the legislation.

Amid a growing patchwork of state AI laws, the bill seeks to establish a single federal baseline—rooted in transparency and accountability standards—for the development of frontier AI. Proponents argue that nationally consistent standards will reduce regulatory fragmentation and better support innovation.

While the bill seeks to offer a middle ground between highly prescriptive and lighter-touch approaches and addresses several important aspects of the AI policy debate, it also raises important questions about where to draw the line between AI development and deployment, whether transparency and accountability are sufficient to govern frontier AI risks, and whether state preemption leaves enough room to address other regulatory issues in AI.

Background

The release of the GAAIA discussion draft comes at a critical moment in the U.S. AI policy debate. As AI capabilities advance, policymakers have shifted between “precautionary principle” and “permissionless innovation” paradigms for governing AI. For example, the Biden Administration emphasized AI safety while the Trump Administration has focused on innovation and infrastructure expansion. Although the two administrations adopted different policy priorities, both primarily relied on executive orders, some voluntary guidelines, and agency guidance that can shift with each election cycle. Congress, meanwhile, has not passed any comprehensive legislation governing AI development, while states have been leading on preventing algorithmic discrimination, banning deepfakes, and enforcing safety requirements for AI systems.

While federal policies provided flexibility during the early years of generative AI—where the primary concerns were chatbot hallucinations or students using AI to complete assignments—they are proving insufficient as frontier AI systems raise broader questions related to cybersecurity, national security, health care, finance, and other critical sectors. The recent controversy surrounding Anthropic’s Mythos and Fable 5 models illustrates this challenge. Amid growing cybersecurity concerns from Anthropic models, the White House instituted ad hoc restrictions based on existing export control law, ordering the company to suspend access to any foreign users, which prompted Anthropic to completely ban the models from all its users to avoid noncompliance risks. This case highlights how, in the absence of a clear statutory framework, governments and developers alike may face uncertainty over how advanced AI systems should be managed. In this context, GAAIA represents one of Congress’ most ambitious attempts to establish an AI federal regulatory framework for those AI systems. Before formal introduction of the bill, its sponsors, Representatives Jay Obernolte (R-CA) and Lori Trahan (D-MA), released GAAIA as a discussion draft to invite feedback from industry, academia, civil society, and the public.

The Great American AI Act

At four titles and 269 pages, the GAAIA discussion draft covers a wide range of AI policy issues. Its core provisions focus on frontier AI governance, cybersecurity, and federal preemption, while other sections address workforce development, free speech, and international cooperation.

Frontier AI and Cybersecurity Governance

These provisions are the heart of the discussion draft, focusing on the risks arising from development of frontier AI systems and how to mitigate them, particularly those with implications for national security, cybersecurity, and catastrophic risk.

The draft bill would provide statutory authorization and funding for the Center for AI Standards and Innovation (CAISI). CAISI, a division of the National Institute of Standards and Technology, was first established as the U.S. AI Safety Institute by an executive order under the Biden Administration in 2023. Notably, CAISI would serve as the federal government’s technical authority on frontier AI, developing voluntary standards while evaluating the capabilities, risks, and evolution of frontier AI systems developed domestically and abroad.

The draft bill would also establish a frontier AI transparency and independent verification regime. Rather than requiring government approval before deployment, the bill requires companies to publicly disclose how they identify, evaluate, and mitigate catastrophic risks associated with their models. Developers must publish a frontier AI safety framework, report on their testing and risk mitigation practices, and notify regulators when serious safety incidents occur. Additionally, licensed third-party auditors, known as Independent Verification Organizations, would be responsible for reviewing whether companies are complying with their own safety frameworks and whether their risk mitigation measures are adequate.

Finally, the draft bill’s cybersecurity provisions focus on strengthening the infrastructure and software systems that support frontier AI models. It would reauthorize the Cybersecurity Act of 2015 through 2035, allowing companies to share cyber threat information without raising antitrust concerns. It also provides additional support for maintainers of critical open-source software and requires studies on the security of AI model weights, data centers, and open-source infrastructure.

Federal Preemption

The draft bill preempts state laws that regulate the development of frontier models—including training requirements, model evaluation standards, and release conditions—for three years. The intent is to avoid fragmentation and keep frontier AI governance centralized at the federal level through CAISI and the bill’s transparency and audit system. At the same time, it preserves state authority over consumer protection and generally applicable laws. In other words, states would still be able to regulate deceptive practices, product liability, and other harm caused by deployed systems, but they would not be able to create AI-specific rules that function as model development regulations.

Other Provisions

While the core focus of the draft bill is on establishing a federal framework for frontier AI model development and preempting states from regulating development, it also contains provisions addressing other concerns. Its workforce provisions establish measures to better understand how frontier AI may reshape labor markets, identify occupations most vulnerable to displacement, and support retraining and upskilling initiatives, particularly in cybersecurity and AI-related fields. The draft also includes measures aimed at protecting free speech by examining potential government influence on AI companies’ content moderation practices, while reinforcing international U.S. leadership in frontier AI through investments in research and development and supporting engagement in international AI standards-setting.

Questions the Framework Leaves Open

One of the core tensions of the draft bill is that it implicitly builds a division between the governance of frontier AI development, which becomes federally standardized, and AI deployment, where states retain authority to regulate both deployment of AI systems and the impact of their use. Treating AI development and deployment as distinct regulatory problems appears to be an intuitive and logical approach as it recognizes that both offer their own opportunities and challenges. Frontier AI development benefits from economies of scale and raises national security concerns, making it ideal for a uniform federal framework. By contrast, AI deployment often involves consumer-facing harms that have traditionally fallen within state regulatory authority. In practice, however, the boundary may be difficult to draw because frontier AI systems continue to evolve after deployment through fine-tuning, systems updates, and integration into applications, with most AI consumer-facing tools usually built on top of frontier AI models rather than as stand-alone systems. As a result, questions remain about where “development” ends and “deployment” begins. This further complicates efforts to assign regulatory responsibility, with responsibility for AI-related harms distributed across foundational model developers, application providers, and even users.

Additionally, rather than requiring government approval before the release of frontier AI systems, the bill proposes a governance system centered on transparency, documentation, audits, and accountability. This reflects a procedural approach to AI governance where instead of setting prescribed rules on how companies must build AI systems, it requires them to demonstrate that they have identified and managed potential risks. If harm emerges, regulatory scrutiny will likely begin with the companies’ own documentation. Yet questions persist on whether these measures will be enough. Because although building on transparency requirements can establish clearer expectations for AI developers, AI risks may be uncertain and difficult to anticipate.

Finally, while the bill addresses questions such as frontier AI governance, cybersecurity, and workforce, it gives comparatively little attention to other critical issues such as kids’ safety, privacy, and intellectual property protections. While some of these may already fall under existing legal frameworks, their absence raises broader questions about the scope of the proposed regulatory model, including whether these risks should be addressed through federal legislation or left primarily to the states, and whether states will retain sufficient authority to respond effectively.

Conclusion

The significance of GAAIA is not that it answers every question about AI regulation, but that it proposes a governance framework that will likely influence future debates on AI regulation. The success of the framework will depend on whether Congress can maintain the distinction between frontier development and deployment while ensuring that transparency-based oversight is sufficient for managing frontier AI systems and that state preemption leaves enough room to address other regulatory issues in AI.

Disclaimer