The FRONTIER Act Narrows the Federal AI Preemption Fight

Editorial legal-tech image showing federal AI oversight documents, audit checklists, and frontier-model governance controls.

The FRONTIER Act Narrows the Federal AI Preemption Fight

The Great American AI Act draft was a warning shot.

The FRONTIER Act is the narrower bill.

On July 23, 2026, Representative Jay Obernolte introduced H.R. 9925, the Frontier Risk Oversight, National Transparency, Independent Evaluation, and Reporting Act, or FRONTIER Act, with Representative Lori Trahan and other bipartisan cosponsors. GovInfo lists the bill as introduced in the House and referred to the House Committee on Energy and Commerce and the House Committee on Science, Space, and Technology.

That matters because the earlier Great American AI Act materials were still a discussion draft. Clearon's earlier coverage treated them that way. H.R. 9925 is different: it is introduced bill text, though still only a pending bill, and it shows where the sponsors moved after the first round of criticism.

The short version is this: the bill still tries to create a federal rulebook for frontier AI risk. But the state-law preemption clause is more targeted than the broad discussion-draft fight suggested.

What The Bill Would Cover

The FRONTIER Act is not a general AI law for every company using automated tools.

It is aimed at frontier models and frontier developers. The bill defines a frontier model as a foundation model trained using more than 10^26 integer or floating-point operations, including the original training run and later fine-tuning, reinforcement learning, or other substantial modification.

It then builds tiered duties around developers that meet revenue and AI-development-spending thresholds. Some duties apply to frontier developers generally, while the public-framework, audit, registration, and independent-verification layers turn on the larger statutory tiers.

A "large frontier developer" would have to have gross revenues in excess of $50 million and incur at least $1 billion in AI-related development expenditures, measured together with affiliates during the preceding 36-month period and determined as of the first day of each calendar month. A "very large frontier developer" would have to have gross revenues in excess of $5 billion and incur at least $10 billion in AI-related development expenditures under the same affiliate-inclusive, monthly measurement structure.

Those thresholds are doing important work. The bill is not trying to regulate ordinary business AI deployments, routine SaaS use, or most smaller model builders in the same way. It is aimed at the companies training and operating the most capable frontier systems.

The Public Framework Requirement

For large frontier developers, the main operational duty starts with a public frontier AI framework.

By the later of one year after enactment or 90 days after first qualifying as a large frontier developer, the developer would have to write, implement, comply with, and clearly publish a frontier AI framework on a public website.

That framework would have to address how the developer identifies catastrophic-risk thresholds, assesses whether a model could cross those thresholds, reviews the results of risk assessment and mitigation before deployment or internal use, uses third parties to assess risk, updates the framework, secures nonpublic model weights, responds to critical safety incidents, and implements internal governance.

This is more concrete than a voluntary responsible-AI pledge. It would turn frontier risk governance into a public compliance artifact.

That does not mean every detail becomes public. The bill allows redactions to protect trade secrets, risk-prevention mechanisms, cybersecurity, public safety, national security, or compliance with federal or state law. But the structure still points toward a world where the largest developers need a publishable governance file, not just internal assurances.

Audits, Reports, And Incident Duties

By the later of one year after enactment or 90 days after first qualifying as a large frontier developer, and annually thereafter, the bill would require a large frontier developer to retain a third party to audit compliance with the developer's own frontier AI framework.

The audit structure matters because it would not merely ask whether the developer has a framework. It would ask whether the developer is following it. The auditor would need demonstrated competence, including access to technical expertise in frontier-model safety, and the bill bars either side from holding a financial interest in the other.

H.R. 9925 also would require model-level transparency reports before or concurrent with deployment of a new frontier model or a substantial modification. Those reports would include release date, supported languages, output modalities, intended uses, restrictions or conditions, catastrophic-risk assessments, assessment results, third-party involvement, and other steps taken under the framework. The summaries would have to be provided in machine-readable format to facilitate verification of model claims.

Critical safety incidents get a separate clock. The bill would require the Under Secretary of Commerce for AI Security to create a confidential reporting mechanism within 180 days after enactment. A frontier developer would have to report a critical safety incident within 72 hours after learning facts sufficient to establish a reasonable belief that one occurred. If the incident poses an imminent risk of death or serious physical injury, the developer would have to report to law enforcement within 24 hours.

For compliance teams, those deadlines are the practical signal. If the bill moves, frontier developers would need escalation criteria and evidence records before an incident happens.

The Independent Verification Layer

The heaviest obligations fall on very large frontier developers.

By the later of one year after the Under Secretary first licenses an independent verification organization with capacity to accept an engagement or 90 days after a developer first qualifies as very large, the developer would have to retain a licensed IVO to perform ongoing assessments.

Those assessments would cover the adequacy of the developer's frontier AI framework, governance practices, risk monitoring, and mitigation of detected risks. They would apply not only to released models, but also to catastrophic risks from internal use of frontier models.

The IVO would need access to unredacted materials, records, personnel, systems, and other information reasonably necessary for the assessment. The developer could impose reasonable security and confidentiality protocols, but material limits on access would have to be described in the assessment report.

The IVO report would have to address scope, limitations, the adequacy of the developer's framework and governance, identified failures or weaknesses, recommended corrective actions, and certifications about accuracy, qualifications, conflicts of interest, and compliance with regulations.

That is a significant compliance design. It would create a regulated market for AI verification organizations and make the independence of that market a policy issue in its own right. The bill recognizes that by requiring annual Government Accountability Office reports on the IVO market, including barriers to entry and threats to independence from the AI industry.

The Preemption Clause Is Narrower, But Still Important

The earlier discussion draft drew attention because it tried to divide federal and state authority over AI. H.R. 9925 keeps that fight, but narrows the covered field.

Section 9 preempts state and local laws that impose new substantive obligations on artificial intelligence developers with respect to a defined "Covered Subject Area." For this section, the bill uses a broader definition of "artificial intelligence developer": an entity that builds, designs, codes, produces, trains, or owns an AI model for internal or third-party use, excluding entities that are solely deployers.

That means Section 9 is not limited to the bill's narrower "frontier developer" definition, even though the covered subject areas are tied to frontier AI risk transparency, frontier AI third-party auditing and independent verification, and frontier AI incident reporting.

That is not the same as preempting all state AI law.

The bill expressly preserves generally applicable laws that do not target AI developers. It also preserves state authority to regulate the use or deployment of AI systems by deployers or users, including through consumer protection, civil-rights, contract, criminal, or privacy laws, so long as those laws do not impose substantive obligations on developers with respect to model development, training, evaluation, or release.

It also preserves state laws specifically relating to protection of minors from harms arising from AI systems, including sexually explicit content, self-harm content, exploitation, age verification, parental controls, and similar matters. And it preserves state procurement and use rules for state governments.

That narrowing is the legal story. The sponsors appear to be moving from a broader preemption fight toward a more focused claim: if Congress creates a federal catastrophic-risk transparency, audit, verification, and incident-reporting regime for frontier developers, states should not create parallel developer-side obligations in the same lane.

States would still have room to regulate many downstream AI uses. The hardest disputes would sit at the boundary. A state rule framed as product transparency, child safety, consumer protection, or procurement may be preserved. A rule that reaches developer-side frontier risk testing, reporting, audits, certifications, or release conditions may be challenged as preempted.

Emergency Orders Are The Enforcement Backstop

H.R. 9925 also gives the Secretary of Commerce emergency-order authority.

The Secretary could suspend or restrict a frontier developer's development, deployment, or internal use of a frontier model upon finding that the activity presents an imminent catastrophic risk. The bill sets procedures for written findings, technical assessments where methods have been published, consultation with the Under Secretary, provisional and final orders, judicial review, and penalties.

Violating an emergency order could trigger civil penalties of up to $10 million per violation. Willful violations could carry criminal penalties of up to $1 million per violation, imprisonment for up to 10 years, or both.

Those provisions are narrow, but they show the bill is not only a reporting proposal. It would give the federal government a direct intervention tool for imminent catastrophic risk.

What Companies Should Watch

Most companies would not become frontier developers under H.R. 9925. But the bill still matters outside the frontier lab because it sketches the federal-state boundary Congress may try to draw.

Frontier developers should watch the thresholds, the definition of catastrophic risk, the content of the public framework, the 72-hour and 24-hour incident clocks, the registration/disclosure duty, and the IVO assessment process.

Companies that deploy third-party AI systems should watch a different issue: what the bill leaves to states. H.R. 9925 preserves state regulation of deployers and users, including consumer protection, civil rights, privacy, contract, criminal law, child safety, procurement, and state-government use. That means a federal frontier bill would not erase downstream state compliance work.

Audit and assurance providers should watch the IVO licensing rules. The bill would require independence, conflict-of-interest controls, technical competence, access to developer records and systems, and signed certifications. That is closer to regulated assurance than ordinary consulting.

State-policy teams should watch the boundary language. The next fight will not be "federal law or state law." It will be whether a particular state rule targets developer-side frontier risk governance or downstream use.

Bottom Line

The FRONTIER Act is the introduced-bill version of a narrower federal AI bargain.

It would place public frameworks, third-party audits, incident reporting, independent verification, registration, and emergency-order authority around the largest frontier developers. In return, it would limit state and local developer-side obligations in the covered catastrophic-risk transparency, audit, verification, and incident-reporting lanes.

That is why H.R. 9925 is worth tracking even if it is far from enactment. It is one of the clearest current attempts to answer the question that keeps coming back in U.S. AI law: which layer belongs to Washington, and which layer remains with the states?

Sources

Comments

Leave a Reply

Your email address will not be published. Required fields are marked *