The Great American AI Act Draft Is Really a Federal Preemption Fight With a Frontier-Audit Regime

The Great American Artificial Intelligence Act is easy to describe badly.

It is not an enacted Federal AI law. It is not even an introduced bill yet. It is a discussion draft released by Representatives Lori Trahan and Jay Obernolte with official supporting materials inviting feedback before formal introduction.

That said, it is still worth reading because it shows what one serious bipartisan Federal AI framework may try to do.

The most important point is not just that the draft creates frontier-model transparency, audits, and a new Federal standards center. It is that the draft tries to split AI regulation into two lanes:

  • Federal rules for model development and frontier safety; and
  • continued state authority over deployment, use, and generally applicable law.

That split is where the real fight will be.

The Short Answer

  • The Great American AI Act is currently a discussion draft, not introduced legislation and not law.
  • The draft would create a Federal frontier-governance regime centered on published risk frameworks, model-specific transparency reports, critical-safety-incident reporting, independent verification audits, and whistleblower protections.
  • It would also preempt state laws that specifically regulate AI model development, while preserving state laws of general applicability and state rules governing deployment or use of AI systems after the model stage. The official FAQ says that preemption would sunset three years after enactment.

The Draft Is Trying To Create One Federal Rulebook For Frontier Development

The official section-by-section and FAQ materials make the architecture fairly clear.

The draft would formally establish a Center for AI Standards and Innovation, or CAISI, within the Department of Commerce. According to the section-by-section summary, CAISI would develop voluntary standards and best practices, evaluate AI systems, support synthetic-content detection tools, and administer the licensing regime for independent verification organizations.

The frontier-governance pieces then stack on top of that center.

According to the section-by-section summary, large frontier developers would have to write, implement, comply with, and publicly post a frontier AI framework covering catastrophic-risk thresholds, model-weight cybersecurity, internal and external deployment decisions, and related governance practices. Before or at deployment of a new frontier model, they would also have to publish a model-specific report describing release date, supported languages, modalities, intended use, restrictions, risk assessments, and mitigation steps.

The section-by-section summary also says developers would have to report critical safety incidents to CAISI, with State attorneys general able to opt into receiving those reports.

That is already a lot more concrete than generic calls for "responsible AI."

The Audit Structure Is Not Voluntary

Another major part of the draft is the independent verification regime.

The section-by-section summary says CAISI would license independent verification organizations, or IVOs, and large frontier developers would have to retain licensed IVOs to audit compliance and assess whether the developer’s framework achieves acceptable levels of catastrophic-risk mitigation.

Those organizations would get access to company materials, submit reports to CAISI, and provide a channel for corrective action and more frequent review if risk changes.

That matters because the draft is not relying only on self-attestation. It is trying to build a recurring third-party review structure around the largest frontier developers.

If a future bill keeps that structure, companies should expect the compliance file to include more than a policy page and a red-team slide deck. It would need documented frameworks, incident reporting, audit access, governance controls, and a defensible explanation of how catastrophic risk is being measured and mitigated.

The Sharpest Provision Is The Preemption Section

The real legal flashpoint is section 121.

The draft says no state or political subdivision may establish or enforce any law or regulation specifically regulating the development of any AI model. That is the clean preemption sentence.

The surrounding text matters just as much. The same section says it does not preempt:

  • state laws of general applicability;
  • common-law remedies; or
  • state laws and regulations that apply to activities occurring upon or after deployment, including implementation, deployment, distribution, offering, or use of AI systems, products, or services built from the model.

The official FAQ goes further and says the framework would preserve state regulation of post-deployment or use-stage harms, including areas like hiring, housing, health care, education, chatbots, deepfakes, child sexual abuse material, and consumer privacy. The same FAQ says the preemption would sunset three years after enactment.

That is why this draft is better understood as a Federal-state line-drawing proposal than a generic AI bill.

Why The Preemption Debate Will Be Hard

The draft is trying to do something politically familiar.

It says model development should face one Federal rulebook, while states keep room to regulate downstream uses and harms. The official materials even compare that structure to national vehicle standards with state rules of the road.

There is a logic to that.

Frontier developers do not want fifty different state development-stage obligations, especially when those duties touch testing, documentation, training, or internal governance. At the same time, states are unlikely to give up their role in policing consumer protection, employment, health care, education, or chatbot harms that show up after deployment.

The practical question is where "model development" stops and "deployment or use" begins.

That line will not always be clean. A transparency rule, watermarking rule, or documentation rule can look like development-stage governance from one angle and user-facing product regulation from another. The official FAQ itself highlights that tension by listing specific state laws the drafters view as federalized or preempted.

The Draft Also Shows Which Companies The Drafters Care About Most

The supporting materials suggest the framework is aimed at the largest frontier developers rather than every startup or open-source project.

The section-by-section summary says the transparency regime would apply to large frontier developers with more than $500 million in revenue. The FAQ also frames the bill as focusing obligations on frontier companies while giving startups and smaller builders more room.

That does not mean smaller companies can ignore it.

If Congress keeps this structure, the Federal debate may center on a frontier tier first, while states keep regulating use-stage harms lower down the stack. Smaller companies could still feel those downstream state laws even if the heaviest Federal development-stage duties land elsewhere.

What Companies Should Watch

For now, this is still a discussion draft. That status matters and should not be blurred.

Still, the draft is worth tracking closely if any of these questions matter to the business:

  • would the company fall into a frontier-developer bucket if revenue and model-capability thresholds survive;
  • does the company already have a publishable risk framework, incident-reporting process, and audit-ready governance file;
  • how much of the company’s state-law exposure sits at the model-development layer versus the deployment or product-use layer; and
  • would preemption help the company, or would the operational pain simply move into downstream state rules on use, distribution, privacy, employment, health care, or consumer deception.

The most useful reading is not "Federal AI bill exists." It is "a bipartisan draft is trying to define which AI risks belong to Washington and which still belong to the states."

Bottom Line

The Great American AI Act discussion draft is not law yet, but it is a serious marker of where Federal AI governance negotiations could go.

Its structure matters more than its name. The draft would pair frontier transparency, incident reporting, third-party audits, and whistleblower protections with a temporary preemption rule for state laws specifically regulating model development, while preserving state authority over use-stage harms and general law.

That is the real issue to watch. If Congress moves on AI, one of the hardest questions will not be whether there should be regulation. It will be who gets to regulate which layer of the stack.

Sources