Frontier models above a defined capability threshold need a codified, transparent federal safety-review process, replacing the ad hoc Cabinet-level negotiation used in the 2026 Fable 5/Mythos 5 case.
Verification Status
AI-researched, unverifiedLast Reviewed
Jul 4, 2026
Cited Sources
9
Implementation, sequencing, safeguards, tradeoffs, and the practical path from principle to policy.
Federal AI safety policy has been unstable across the last two administrations. The Biden administration's October 2023 executive order (EO 14110) was rescinded on the Trump administration's first day and replaced with EO 14179 ("Removing Barriers to American Leadership in AI"), which produced the deregulatory, competitiveness-focused "Winning the Race: America's AI Action Plan" (July 2025). NIST's AI Safety Institute was renamed the Center for AI Standards and Innovation (CAISI) in mid-2025, reorienting its mission from catastrophic-risk safety toward national-security and competitiveness testing.
Into that federal vacuum, states moved first. New York's RAISE Act (signed December 2025, effective January 2027) requires frontier developers above defined revenue and compute thresholds to publish safety protocols and report incidents within 72 hours. California's Transparency in Frontier AI Act, SB 53 (signed September 2025, effective January 2026, already in force), does something similar for models trained above roughly 10^26 FLOP. Colorado's attempt — SB 24-205 — took a broader "algorithmic discrimination" approach, was delayed twice, drew a federal lawsuit from xAI joined by the Department of Justice, had its enforcement paused by negotiated settlement in April 2026, and was ultimately repealed and replaced by the much narrower SB 26-189 in May 2026. Texas's TRAIGA and Illinois's AI employment-discrimination law are both in force since January 2026; Connecticut passed a comprehensive framework (SB 5) in May 2026, phasing in through late 2026 and 2027.
Congress has twice declined to impose a moratorium on state AI laws — the Senate stripped a proposed 10-year moratorium from the 2025 reconciliation bill by a 99-1 vote — and the Trump administration pivoted to executive action instead, issuing EO 14365 in December 2025 to create a DOJ "AI Litigation Task Force" empowered to sue states directly. Its first target was Colorado. A bipartisan "Great American AI Act" discussion draft surfaced in June 2026 proposing a narrower, three-year preemption limited to state laws governing AI development (not use), but it remains an unintroduced draft, not legislation.
Internationally, the EU AI Act's general-purpose-AI obligations (transparency, copyright disclosure, systemic-risk duties for the largest models) have applied since August 2025, with the Commission's own enforcement power activating in August 2026. The Act's high-risk-system obligations, originally due in 2026–2027, were pushed back via the "Digital Omnibus on AI" — finalized by the Council on June 29, 2026 — to December 2027 and August 2028, a delay civil-society groups call a rollback and industry generally supports.
In June 2026, Anthropic launched Claude Fable 5 (and a higher tier, Mythos 5). Three days later, Commerce Secretary Howard Lutnick directed the company, under national-security export authority, to suspend all access to both models for any foreign national worldwide — including Anthropic's own non-U.S. employees — over a discovered jailbreak vulnerability. Anthropic complied while publicly disputing that the finding justified pulling a model already deployed to hundreds of millions of users. The dispute ran 18–19 days, reportedly negotiated directly between Anthropic co-founder Tom Brown and the Commerce Department, before Commerce lifted the restriction in exchange for commitments on future model security practices.
Whatever one concludes about the underlying jailbreak concern, resolving it through direct, undocumented negotiation between a single Cabinet official and a single company — with no public standard for what triggers such an order, no defined timeline, and no clear appeal path — is a process failure independent of whether the substantive call was right. That's precisely the gap Proposal 2 above is aimed at closing.
Overly broad compute/capability thresholds risk sweeping in ordinary commercial software; overly narrow ones exempt exactly the systems the rule is meant to reach. A slower, codified interagency process could itself become a liability if an emergency needs faster action. That's addressed here via a defined emergency-authority carve-out paired with mandatory after-the-fact public disclosure, rather than indefinite ad hoc secrecy.
Two objections deserve a direct answer. First: "any regulation slows the country down in the AI race with China." That's a fair question, but it belongs to AI-07 (export controls and compute policy), not here. Conflating safety regulation with export/compute-denial policy either over-regulates ordinary safety practice or under-regulates national-security exposure. Second: "states are the right laboratories of democracy for this — leave it alone." There's value in state experimentation (Colorado, New York, and California differ in instructive ways), but an unbounded 50-state patchwork imposes serious compliance cost without a floor. A federal minimum plus room for states to add on preserves the laboratory function without the patchwork cost.
Turn frustration into useful pressure.
If this position misses evidence or a lived consequence, challenge it. If it holds up, help test it locally and connect it to the issues around it.