House legislative text · Rep. Jay Obernolte · 119th Congress, 2nd session · source text dated July 22, 2026
Frontier Risk Oversight, National Transparency, Independent Evaluation, and Reporting Act (FRONTIER Act; H.R. 9925)
Provisions
Sections 2, 3, and 6 — Scope and cumulative coverage
1. §§2, 3(f), and 6: compute, revenue, and expenditure thresholds for three cumulative tiers
Sections 2, 3, and 6 — Scope and cumulative coverage
1. §§2, 3(f), and 6: compute, revenue, and expenditure thresholds for three cumulative tiers
Section 2 defines a frontier model by a training-compute threshold, including original training and later fine-tuning, reinforcement learning, or other substantial modification. A frontier developer becomes large only if it and its affiliates satisfy both a $50 million gross-revenue threshold and a $1 billion AI-development-expenditure threshold over the preceding 36 months; very-large status requires more than $5 billion in revenue and at least $10 billion in AI-development expenditures. Base frontier developers face model-reporting, incident-reporting, and emergency-order duties; large developers add framework, audit, internal-risk-reporting, and registration duties; very large developers add licensed-IVO assessments. Section 6 makes those tiers cumulative. Section 3(f) permits Commerce to increase, but not decrease, the compute, revenue, or expenditure thresholds after considering risk, efficiency, cost, inflation, and effects on regulated entities, with biennial review and at least 180 days of prospective notice.
Quoted from the bill ▸
A frontier model “means a foundation model that was trained” … “using a quantity of computing power greater than” … “10✖26 integer or floating-point operations.” Large status requires “had gross revenues in excess of” … “$50,000,000; and” requires “incurred not less than $1,000,000,000” … “in AI-related development expenditures.” The “Under Secretary may by” … “regulation increase—” the thresholds.
Countersignable goals
Likely effects — shown regardless of the goals
Tiered and cumulative obligations
The compute threshold first determines whether a developer is in the regime; conjunctive revenue and AI-expenditure thresholds then determine whether the framework-and-audit and IVO layers attach, while §6 prevents a higher tier from displacing lower-tier duties.
Benefit-risk standard
“Acceptable levels of catastrophic risk mitigation” means anticipated benefits outweigh catastrophic risk after considering probability and magnitude. It is a balancing test, not an absolute probability ceiling or a promise of zero catastrophic risk.
Incident and harm cliffs
The catastrophic-risk definition requires one incident involving specified model conduct and more than 50 deaths or serious injuries, or more than $1 billion in property loss. Repeated subthreshold harms, equity-value loss, substantially similar publicly accessible information, and lawful Federal activity fall outside that definition.
Adversarial mechanism — threshold accounting
Hard compute, affiliate, revenue, and AI-expenditure tests create incentives to characterize fine-tuning, corporate control, mixed-purpose spending, and the timing of a 36-month measurement window strategically.
Adversarial mechanism — one-way threshold ratchet
Commerce may increase coverage thresholds but has no express authority to lower them. If algorithmic efficiency permits catastrophic capability below the original compute threshold, the statutory adjustment tool cannot expand coverage downward.
Prospective stability
A threshold increase takes effect no earlier than 180 days after final publication and governs only later-arising obligations, reducing retroactive disruption while delaying any recalibration.
Implementation barriers
Commerce and developers must reconstruct nonstandard inputs
AI-related development expenditures are broader than a single tax or financial-reporting line, and aggregate training compute must include later fine-tuning, reinforcement learning, and substantial modifications.
Congress must repair facially mismatched cross-references
The supplied §2 text numbers definitions as paragraphs (1) through (22), but §3(d) cites §2 “subsection (t)” and “subsection (p),” while §3(f) cites “subsection (l),” “subsections (o) and (v),” and “subsections (k), (l), (o), and (v).” The intended ordinal mapping is inferable, but the literal references do not exist in the supplied text.
Commerce, IVOs, and courts must apply judgment-heavy terms
“Materially contribute,” “significant change,” anticipated benefit, risk probability, and acceptable mitigation lack numeric decision rules, so similar facts can produce different coverage or adequacy judgments.
The new Under Secretary must stand up a broad program
The bill assigns threshold review, rulemaking, licensing, secure reporting, enforcement support, and emergency analysis to a newly appointed office without an express general appropriation in the supplied text.
Candidate outcome metrics
Department of Commerce, the expressly required biennial §3(f)(3) threshold determination and published basis, recording operative compute, revenue, and AI-expenditure thresholds, publication dates, and effective dates. An upward revision can implement recalibration while also excluding models or developers previously covered.
Models or developers presenting material catastrophic risk while falling below one or more statutory thresholds. No recurring official product measures that population, and company compute or spending claims are not an official series.
No unified official series attributes deaths, serious injuries, property loss, cyberattacks, or loss of control to a frontier model’s material contribution under the bill’s exact single-incident definition. FBI, CISA, mortality, and disaster products do not supply that attribution.
Conditional forecast sketches
P(operative Commerce compute, revenue, and expenditure thresholds at biennial review t | original statutory thresholds versus an upward §3(f) revision)
P(number of covered large and very large developers | original thresholds versus an upward §3(f) revision)
Section 3 — Rulemaking
2. §3(b)–(e): 180-day framework, IVO, modification, reporting, redaction, and State-opt-in rules
Section 3 — Rulemaking
2. §3(b)–(e): 180-day framework, IVO, modification, reporting, redaction, and State-opt-in rules
Within 180 days after enactment, the Under Secretary must issue minimum frontier-framework rules, IVO licensing and oversight rules, and model- and framework-modification criteria. The framework rules must be reviewed at least annually. IVO licensing rules must cover funding transparency, independence, technical qualifications, assessment methods, corrective-action processes, subcontractors, licensing and revocation findings, expert panels, secure report submission, and trade-secret handling. Commerce may also standardize publications, reports, redactions, and State Attorney General opt-ins.
Quoted from the bill ▸
“Not later than 180 days after” enactment, the Under Secretary must “issue, and thereafter update” regulations, with updates made as appropriate, “establishing minimum” requirements “for frontier AI frameworks.” IVO rules must include “Conflict-of-interest” and funding-transparency “requirements, including reporting” on “the IVOs’ funding sources” and revenue “generation and self-audit requirements”.
Countersignable goals
Likely effects — shown regardless of the goals
Fast APA rulemaking
The 180-day deadline accelerates a large set of Administrative Procedure Act rules, but notice, comment, technical consultation, and reasoned responses still determine whether the resulting rules are durable.
Ex ante assessor screening
IVO applicants must disclose proposed benchmarks, methods, corrective-action procedures, update methods, subcontractors, and personnel qualifications before Commerce licenses them.
Independence discipline
Funding-source disclosures, self-audits, industry-independence findings, and revocation grounds can constrain capture, but the later regime still has regulated developers retain and pay IVOs.
Attribution in license revocation
A model failure need not cost an IVO its license if the IVO identified the weakness, recommended adequate action, and the failure resulted from the developer’s failure to implement that action rather than from assessment weakness.
Method obsolescence
Commerce can revoke a license when technological evolution makes an IVO’s methods obsolete, protecting quality while potentially removing scarce assessment capacity abruptly.
Secure regulatory channel
Rules must provide secure submission and processing of assessment reports and sensitive information, making information security a condition of the oversight system itself.
Implementation barriers
The Under Secretary faces simultaneous deadlines
Framework minima, IVO licensing, modification criteria, report handling, redaction standards, and State opt-in procedures must be designed while the new office recruits technical, legal, and security staff.
The IVO labor pool is structurally conflicted
People qualified to evaluate frontier systems are likely to have current or former industry employment, funding, clients, or research ties, so independence cannot be inferred from formal ownership alone.
Section 5 activation depends on licensed capacity
The assessment clock starts only after Commerce first licenses an IVO with capacity to accept an engagement, allowing a slow licensing or capacity buildout to postpone the central very-large-developer duty.
Commerce must separate assessor failure from client failure
After a bad outcome, license review requires evidence about whether the IVO’s methods were inadequate or the developer declined an adequate recommendation, often using the same sensitive record under dispute.
Candidate outcome metrics
Federal Register and Department of Commerce publication dates for final framework, IVO-licensing, and modification-criteria rules, measured against the 180-day deadline, plus dated annual framework-rule reviews. These are authoritative events but not a recurring outcome series with a stable value field.
Elapsed days from enactment to Commerce’s first license for an IVO with capacity to accept an engagement. A longer interval directly postpones §5 assessments even if all developers are otherwise ready.
Commerce IVO-license revocations by official stated ground, including lost independence, obsolete methods, failure to follow a plan, and model failure attributable to assessment weakness. More revocations remove weak assessors but also reduce available capacity.
No official recurring series measures IVO independence, benchmark validity, or whether an IVO assessment actually reduced catastrophic risk. License status and report volume do not establish those outcomes.
Conditional forecast sketches
P(final framework and IVO rules are published within 180 days | enactment)
P(days until the first capacity-qualified IVO license | §3(c) licensing regime in force)
P(active licensed IVO capacity and revocations by ground | assessment demand from qualifying developers)
Section 4 — Transparency and reporting
3. §4(a)–(f): public frameworks, annual compliance audits, model reports, and redactions
Section 4 — Transparency and reporting
3. §4(a)–(f): public frameworks, annual compliance audits, model reports, and redactions
Large developers must publish and follow a frontier AI framework covering risk thresholds, assessments, deployment and internal-use decisions, third-party review, framework updates, model-weight cybersecurity, critical incidents, and internal governance. They must obtain an annual third-party audit of compliance with that framework and publish a high-level summary plus a redacted report. Separately, every frontier developer must publish a model-specific transparency report before or with a new or substantially modified model’s deployment, subject to a confidential-deployment deferral and justified redactions. Unredacted publications go to Commerce.
Quoted from the bill ▸
Large developers must “write, implement, comply with, and clearly” and conspicuously “publish on a publicly available website” “a frontier AI framework”; annually, a large frontier developer “shall retain a third party to perform” an independent “audit of compliance with the frontier AI” framework; and provide the summaries in a “machine-readable” format to facilitate “verification of model claims.”
Countersignable goals
Likely effects — shown regardless of the goals
Public risk governance
Framework publication exposes a developer’s risk thresholds, assessment process, release and internal-use decision process, cybersecurity, incident response, and governance commitments to external scrutiny.
Self-authored compliance baseline
The §4(c) auditor determines whether the developer substantially complied with its own published framework. That is narrower than §5’s independent assessment of whether a very large developer’s framework and mitigation are adequate.
Auditor access and incentives
The auditor receives broad access to records, systems, personnel, and unredacted materials. Reciprocal financial interests and result-contingent compensation are barred, but the developer still selects and pays the auditor.
Model-level release disclosure
Every frontier developer, not only a large one, must report release date, supported languages and modalities, intended uses, restrictions, substantial modifications, catastrophic-risk assessments and results, third-party involvement, and other framework steps.
Adversarial mechanism — confidential-deployment deferral
A deployment subject to security or national-security confidentiality obligations can remain undisclosed publicly until the model is first deployed outside those obligations, although Commerce must receive the report at deployment.
Machine-readable ambiguity
The machine-readable clause refers to “summaries described in this subsection,” while subsection (d) otherwise commands a report. The bill does not define the machine-readable schema or clearly identify which report elements must be encoded.
Accuracy and redaction limits
The special false-statement rule reaches knowing inaccuracies or false impressions in §4(d) reports, with a reasonable good-faith exception. Developers can redact for broad protected interests if they describe and justify the redaction, retain the material, and transmit an unredacted copy to Commerce.
Implementation barriers
Developers must classify moving model boundaries
A developer initially decides whether a framework change is material and whether a model change is substantial, even though those classifications trigger justification or a new report.
The audit market must supply technical competence and independence
Section 4 auditors need frontier-safety expertise but are not required to hold an IVO license, and repeat-client dependence is not eliminated by the ownership and contingent-fee bans.
Public evaluators lack a central archive and denominator
Frameworks, audit reports, and model reports remain distributed across developer websites, while confidential deployments can be absent from the public universe entirely.
Commerce must govern broad redaction discretion
Unlike §5’s express official redaction-dispute process, §4 relies on rulemaking standards and unredacted transmittal without giving the public a specific mechanism to trigger review.
Enforcers face a knowledge standard
A factual error alone does not establish the special §4(d) violation; the government must address knowledge, false impression, good faith, and reasonableness.
Candidate outcome metrics
Share of developers on Commerce’s public large-developer list with a current framework, annual audit, high-level audit summary, and redacted report published by the statutory deadlines, plus frontier-model deployments with timely machine-readable reports. This requires combining an official list with developer websites and is not one official series.
Material deviations and internal-control deficiencies reported per completed audit, with a fixed treatment of redacted or noncomparable reports. A higher path indicates weaker adherence even while the publication itself demonstrates active auditing.
Share of public model and audit reports with material redactions, stated redaction grounds, and confidential-deployment deferrals. A higher path protects more sensitive material but reduces public completeness and comparability.
Compliance with a developer-authored framework and publication of a model report are not official measures of framework adequacy or catastrophic-risk reduction. No recurring official series closes that gap.
Conditional forecast sketches
P(share of registered large developers with timely frameworks and annual audit publications | §4(a)–(c) in force)
P(material audit deviations per completed audit | §4(c) in force)
P(timely machine-readable model-report coverage and material-redaction share | §4(d)–(f) in force)
Section 4 — Incident reporting and registration
4. §4(g)–(l): confidential incident reporting, public registration, enforcement, and annual aggregate reporting
Section 4 — Incident reporting and registration
4. §4(g)–(l): confidential incident reporting, public registration, enforcement, and annual aggregate reporting
Commerce must create confidential channels for developer or public reports of critical safety incidents and for large-developer reports of catastrophic risk from internal model use. Large developers ordinarily transmit internal-risk summaries at least quarterly, although Commerce may agree to another reasonable schedule. For a critical safety incident outside §4(h)(2), the developer must report to Commerce within 72 hours after acquiring facts sufficient for a reasonable belief. Section 4(h)(2) instead requires an incident posing imminent death or serious-injury risk to be reported to a law-enforcement agency within 24 hours after discovery; the exception means §4(h)(1) does not expressly impose the separate 72-hour Commerce filing on that incident. State Attorneys General may opt in. Separately, a large developer needs a current disclosure statement and fee before developing, deploying, or operating a frontier model; Commerce publishes the registered-developer list and sends Congress and the President annual anonymized aggregate incident information beginning January 1, 2028.
Quoted from the bill ▸
Except for the paragraph (2) route, the developer reports within 72 hours “after a frontier developer learns facts” sufficient for a reasonable belief that an incident occurred. For a critical safety incident posing imminent risk of death or serious physical injury, it must act “Not later than 24 hours” after discovery, and “such developer shall report” the incident to law enforcement.
Countersignable goals
Likely effects — shown regardless of the goals
Reasonable-belief reporting clock
For incidents outside the imminent-injury exception, the 72-hour Commerce clock begins when a developer learns facts sufficient for a reasonable belief, not when the incident occurs. Internal investigation and escalation practices therefore affect the legally recorded delay.
Narrower urgent law-enforcement trigger
The separate 24-hour law-enforcement route covers imminent death or serious physical injury, but it does not expressly cover an imminent property-only or cyber loss. Because paragraph (1) is “except as provided in paragraph (2),” the text does not expressly require the imminent-injury incident to receive an additional 72-hour Commerce filing.
Recurring internal-use signal
Large developers must summarize internal-use catastrophic-risk assessments quarterly unless Commerce accepts another reasonable written schedule, for which the bill states no maximum interval.
Asymmetric review
Commerce must review each developer report but only may review a report submitted by a member of the public, concentrating mandatory attention on regulated entities’ submissions.
Registration gate
After the activation date, a large developer cannot develop, deploy, or operate a frontier model without a current filing and fee; renewals are annual or triggered earlier by ownership or material-information changes.
Enforcement
Section 4 violations can carry up to $1 million per violation for every continuing day, while registration-specific noncompliance carries $10,000 per day. DOJ and opted-in State Attorneys General can seek penalties and injunctions subject to Federal intervention and stay rules.
Treatment-created transparency
The public registered-developer list and annual aggregate incident report exist because of enactment. Their non-enactment values are missing, not zero, and the annual report is not expressly required to be public, numerical, machine-readable, or stable in category definitions.
Implementation barriers
Developers and enforcers must reconstruct knowledge timing
Auditing the ordinary 72-hour route requires evidence of when facts crossed a reasonable-belief threshold inside an organization, while the imminent-injury route instead turns on discovery and a 24-hour clock.
Commerce must secure highly sensitive reports
The reporting system must protect model weights, vulnerabilities, investigative leads, and national-security information while supporting review and authorized State transmission.
Federal and State enforcers must coordinate cases
State opt-in, advance notice, Federal intervention, bars on duplicative State suits, and stays after a later Federal action create a case-sequencing burden.
The ownership disclosure rule leaves a public-company gap
Private or closely held developers disclose five-percent owners, but publicly traded developers disclose only owners at or above 50 percent, omitting most substantial noncontrolling holders.
Public evaluators cannot observe complete incident incidence
Confidential submissions, anonymization, sensitive-information exclusions, and possible underreporting make reviewed-report counts an ambiguous combination of underlying safety, detection, coverage, and compliance.
Candidate outcome metrics
Department of Commerce, the expressly mandated §4(k)(5) public list of large frontier developers, captured on fixed dates with additions, removals, and current-registration status. This is the cleanest direct participation product created by the bill.
Critical-safety-incident reports received and reviewed by Commerce, separated by developer versus public source and by incident category only where the official annual report supplies those fields. The report is official but not expressly public or standardized, so no series hint is assigned before an actual recurring product exists.
Among incidents outside §4(h)(2), the share reported to Commerce within 72 hours of the documented reasonable-belief timestamp; separately, among imminent death-or-serious-injury incidents, the share reported to law enforcement within 24 hours of discovery. The mutually exclusive statutory arms require different denominators and confidential timestamps, and no recurring public series is mandated.
Substantiated late or omitted incident reports and related civil actions. A higher path records failures of the prompt-reporting and recurring-oversight mechanisms, and no standardized recurring DOJ or State-AG product is required.
Actual critical safety incidents under the statutory definition. A higher incidence path opposes the safety and oversight goals, but a higher reviewed-report count alone can instead reflect better detection or compliance and cannot resolve this construct.
Conditional forecast sketches
P(Commerce public registered-large-developer count at fixed date t | §4(k) in force)
P(critical-safety-incident reports received and reviewed | §4(g)–(h) in force)
P(share meeting the applicable 72-hour Commerce or 24-hour law-enforcement clock | incident enters its mutually exclusive §4(h) reporting arm)
Section 5 — Independent verification
5. §5(b)–(i): mandatory ongoing assessments, unredacted access, and corrective-response cycles
Section 5 — Independent verification
5. §5(b)–(i): mandatory ongoing assessments, unredacted access, and corrective-response cycles
The assessment duty begins on the later of one year after Commerce first licenses an IVO with capacity to accept an engagement or 90 days after a developer first becomes very large. The retained licensed IVO assesses the adequacy of the developer’s framework, governance, monitoring, and mitigation for both internal use and third-party release. It receives reasonably necessary unredacted access, reports at a risk-sensitive cadence no less frequently than every six months, identifies deficiencies and recommended corrections, reviews the developer’s response, and issues an adequacy opinion. Commerce can order ad hoc assessments, and changed facts or model capabilities can trigger a supplemental report within seven days.
Quoted from the bill ▸
A very large developer must retain an IVO “to perform ongoing assessment of the adequacy of” its frontier AI framework, governance, risk monitoring, and mitigation; the IVO must “submit an assessment report not less frequently than” once every six months.
Countersignable goals
Likely effects — shown regardless of the goals
Delayed coverage gate
Only a developer above the very-large financial thresholds is covered, and the mandate does not activate until Commerce licenses a capable IVO, so a thin assessor market can delay the duty.
Adequacy review
Unlike the §4 compliance audit, the IVO assesses whether the framework, governance, monitoring, and mitigation are adequate to achieve the statutory benefit-risk standard.
Internal-use coverage
Assessment, monitoring, reporting, and corrective-action duties expressly cover risks from internal model use as well as models released to third parties.
Deep but controlled access
The IVO can request unredacted records, personnel, systems, and other reasonably necessary information. Developer security protocols must be reasonable and narrowly tailored, and material limitations must appear in the report.
Recurring and event-driven review
Six months is the maximum ordinary interval, Commerce can demand ad hoc review, and the IVO has seven days to supplement a report when a prior finding, recommendation, or developer representation becomes invalid.
Adversarial mechanism — response is not guaranteed remediation
The developer must describe actions it “has taken or intends to take,” and the IVO then opines on adequacy. Section 5 does not itself impose a categorical completion deadline for every non-imminent recommendation, although rules may mandate corrective action in specified circumstances and imminent risks escalate to §8.
Assessor-client dependence
The regulated developer retains the verifier. Licensing and funding-transparency rules mitigate formal conflicts, but recurring dependence on a small set of large clients can still shape access, scope, and commercial incentives.
Implementation barriers
Commerce must create actual IVO capacity
Licensing alone is insufficient; the statutory clock depends on at least one IVO having capacity to accept an engagement, and concentrated capacity can create queues or client-allocation disputes.
IVOs need scarce and current technical expertise
Assessors must evaluate changing model capabilities, benchmarks, cybersecurity, governance, and mitigation while maintaining secure infrastructure and independence from the firms most able to supply that talent.
Developers and IVOs may contest access boundaries
“Reasonably necessary” access and “narrowly tailored” security protocols invite disputes over model weights, incident records, internal systems, copying, retention, and on-premises review.
IVO judgments are difficult to compare
The adequacy standard balances benefits and risk rather than applying a common numeric ceiling, and the bill does not require a machine-readable schema for findings, limitations, recommendations, or completion status.
Commerce must monitor promises after the report cycle
A developer can state an intention to act within the statutory response period, but the text does not create a standardized public table showing whether, when, or how completely each promised action was implemented.
Candidate outcome metrics
Date Commerce first licenses an IVO with capacity to accept an engagement, active licensed IVO count, and stated engagement capacity. Section 5 does not itself require a recurring public capacity register.
Assessment reports submitted per covered very large developer, elapsed time between reports, internal-use coverage, material scope or access limitations, and timeliness of ad hoc or supplemental reports. No required central structured publication contains all of these fields.
Recommended actions, 14-day developer responses, seven-day IVO opinions, the share judged adequate, and whether promised actions were completed. The bill does not require a recurring public completion table, so this remains an official-record concept without a series hint.
Recommended actions not implemented by the next assessment, repeated material weaknesses, or developer responses the IVO judges inadequate. A higher path directly undercuts the ongoing-adequacy and corrective-action goals, but no recurring public official series is mandated.
Assessment frequency, report counts, and favorable IVO opinions do not establish that catastrophic risk fell or that harm was avoided. No official recurring causal outcome series exists.
Conditional forecast sketches
P(date of first capacity-qualified IVO license and active IVO capacity | §§3(c) and 5 enacted)
P(share of covered developers receiving a complete assessment at least every six months | §5 duty effective)
P(share of corrective recommendations receiving a timely response and an adequate IVO opinion | assessment completed)
P(persistent or repeated deficiencies | prior assessment recommended corrective action)
Sections 5 and 7 — Disclosure, enforcement, and the IVO market
6. §§5(j)–(r) and 7: public assessment reports, enforcement, IVO immunity, FOIA, and GAO market review
Sections 5 and 7 — Disclosure, enforcement, and the IVO market
6. §§5(j)–(r) and 7: public assessment reports, enforcement, IVO immunity, FOIA, and GAO market review
A very large developer must publish a high-level summary and redacted copy of each ordinary assessment report within 30 days and transmit it to Commerce, DOJ, and opted-in State Attorneys General. Officials can challenge overbroad redactions, while Commerce and DOJ may inspect unredacted reports and support. IVOs can refer violations for enforcement and must refer an imminent catastrophic risk to the Secretary within 72 hours. Developer violations carry civil penalties and injunctions. An IVO licensed at the time it assessed a frontier model receives broad catastrophe-related immunity for loss from materialized catastrophic risk of that assessed model, with a sole Federal remedy for death or serious physical injury caused by willful misconduct. Government-held assessment material is FOIA-exempt. GAO must report annually on licensed IVO numbers, capacity, entry barriers, and independence.
Quoted from the bill ▸
An IVO that finds imminent catastrophic risk must “refer the matter to” the Secretary “in any event not more than” 72 hours after its determination. The bill states “An IVO shall be immune” and describes immunity “from suit and liability under Federal and State law” for claims tied to materialization “of a catastrophic risk of a frontier model” it assessed while licensed; the “sole exception” is an exclusive Federal action for death or serious physical injury proximately caused by willful misconduct.
Countersignable goals
Likely effects — shown regardless of the goals
Layered public and regulator disclosure
The public receives a developer-hosted summary and redacted ordinary assessment report, while Commerce and DOJ can request unredacted reports and supporting materials.
Supplemental-report transparency gap
The publication command expressly covers ordinary §5(f) assessment reports, not the §5(i) supplemental reports triggered when a prior safety finding, recommendation, or developer representation becomes invalid.
Redaction review
Federal or opted-in State officials can ask Commerce to review an overbroad redaction, but the public has no express right to trigger the same process.
Enforcement and escalation
IVOs may refer violations to Federal and opted-in State authorities and must escalate an imminent catastrophic risk within 72 hours. Developer violations can draw up to $1 million per violation for every continuing day plus an injunction.
Adversarial mechanism — broad IVO immunity
An IVO licensed when it performed the assessment is insulated from Federal and State claims for loss from materialized catastrophic risk of the frontier model it assessed, unless death or serious physical injury was proximately caused by willful misconduct. Within that assessed-model scope, property-only loss, economic loss, non-serious injury, negligence, and recklessness outside willful misconduct fall outside the sole exception.
Elevated private-action burden
A qualifying plaintiff must prove willful misconduct and causation by clear and convincing evidence, conduct consistent with IVO obligations is not willful as a matter of law, and discovery waits until the IVO has had a reasonable opportunity to seek dismissal.
FOIA boundary
Assessment reports, summaries, and support given to Commerce are exempt from FOIA, increasing the importance of the developer-hosted redacted version and limiting independent reconstruction from government files.
Congressional market monitor
GAO’s annual report creates an official recurring view of IVO count, capacity, entry barriers, and threats to industry independence, but the text does not require machine-readable tables.
Implementation barriers
Commerce and Attorneys General must audit redactions securely
Detecting overbreadth requires comparison with highly sensitive unredacted material, documented decisions, and secure sharing among opted-in jurisdictions.
Public users lack a mandated central archive
Assessment reports are distributed across developer websites, supplemental reports need not be published, and FOIA cannot supply the government-held versions.
State enforcement depends on opt-in and Federal sequencing
Federal intervention and later Federal actions can bar or stay overlapping State cases, requiring coordination before evidence or remedies become public.
Injured parties face a narrow cause and proof barrier
The immunity rule excludes many types and theories of loss, demands clear and convincing proof of willful misconduct, and delays discovery until after a dismissal motion can be heard.
IVO accountability leans on licensing
Section 5 prohibits knowing IVO misrepresentation, but its direct civil-penalty paragraph is drafted around developer violations, making Commerce licensing and revocation central to verifier discipline.
GAO must measure a small and endogenous market
Capacity, unmet demand, entry barriers, and independence depend on confidential client pipelines and funding relationships that licensed IVOs and developers may describe differently.
Candidate outcome metrics
Number and share of ordinary §5(f) reports posted within 30 days with high-level summaries and legally sufficient descriptions of redactions. This requires developer-site collection and has no mandated official central series.
Share of report content redacted, official overbreadth disputes, and Commerce disposition time. A higher redaction burden reduces public visibility while protecting the sensitive interests named in the statute.
IVO referrals, referral latency, DOJ and opted-in State actions, penalties, and injunctions. No mandated consolidated recurring public table covers these Federal and State actions.
Government Accountability Office, the expressly mandated annual §7 report on the number of licensed IVOs, capacity to meet assessment demand, entry barriers, and factors threatening independence. Record the first published report for each annual cycle and do not convert qualitative capacity judgments into invented numbers.
Claims involving catastrophic risk of a frontier model assessed while the IVO was licensed, separated by alleged harm, legal ground, merits disposition, and recovery. No recurring official series isolates these cases; more successful claims weaken the liability shield while exercising the retained willful-misconduct remedy.
Conditional forecast sketches
P(share of ordinary §5(f) reports posted within 30 days with compliant redaction descriptions | assessment completed)
P(redaction-dispute rate and resolution time | §5 public-report regime operative)
P(number and timing of §5(p) referrals and enforcement actions | report identifies a violation or imminent risk)
P(GAO-reported licensed IVO count, capacity, and independence concerns | §5 licensing and assessment regime operative)
P(claims involving a model assessed while the IVO was licensed reaching merits or recovery | §5(q) immunity in force versus an otherwise applicable liability regime)
Section 8 — Emergency orders
7. §8(a)–(i) and (m): stop-order authority, model-lineage reach, expiration, publication, and penalties
Section 8 — Emergency orders
7. §8(a)–(i) and (m): stop-order authority, model-lineage reach, expiration, publication, and penalties
The Secretary of Commerce may suspend or restrict all or part of a frontier developer’s development, deployment, or internal use of a model that presents imminent catastrophic risk. Orders can be tailored by person, use, access channel, safeguard, or other circumstance and ordinarily bind affiliates, successors, assigns, actual-notice collaborators, modified models, and later models trained substantially on the named model’s outputs, weights, or internal representations. Provisional orders can precede a full finding or technical assessment and generally lapse within 45 days. Final orders last 90 days but may be renewed on a new current finding. Final orders, renewals, and rescissions are published with justified redactions and reported to Congress. Violations can produce civil injunctions and penalties or, if willful, criminal liability.
Quoted from the bill ▸
“The Secretary may issue an” … “emergency order suspending or restricting a frontier” … “developer’s development, deployment, or internal use” … “of a frontier model” upon finding imminent catastrophic risk. A provisional order may issue “whether or not a technical assessment ... has been prepared.”
Countersignable goals
Likely effects — shown regardless of the goals
Tailored stop authority
An order can reach only specified development, deployment, internal use, users, purposes, access channels, safeguards, or other circumstances rather than requiring a binary shutdown.
Affiliate and collaborator reach
Affiliates, successors, assigns, and people with actual notice who act in concert or participation can be bound, limiting a developer’s ability to route restricted activity through related entities.
Model-lineage presumption
Unless an order says otherwise, it reaches fine-tuned, reinforced, quantized, pruned, or merged versions and later models trained substantially on the named model’s outputs, weights, or internal representations.
Rapid provisional intervention
A provisional order can issue on a preliminary determination before the final finding and without a technical assessment. Prior notice and cure can be omitted when imminence forecloses them, but Commerce must promptly provide an opportunity to cure after service.
Time limits and fresh findings
A final order can issue only while the same or a substantially similar provisional order remains in effect and after the required finding and hearing window. A provisional order generally lapses within 45 days, a final order within 90 days, and each renewal requires a new finding based on current facts rather than a rote extension.
Corrective off-ramp
Orders state rescission criteria and corrective action when available, Commerce must rescind once the criteria are satisfied or imminent risk no longer exists, and a developer can seek a decision on rescission within 14 days.
Asymmetric publication
Final orders, renewals, and rescissions must be published with justified redactions, while provisional orders are reported to Congress but are not expressly included in the public-publication command.
High-stakes enforcement
A continuing violation can draw up to $10 million per violation per day, DOJ can obtain an injunction without the ordinary irreparable-harm showing, and a willful violation can carry up to $1 million, ten years’ imprisonment, or both.
Implementation barriers
The Secretary must act under severe uncertainty
Evidence about emergent capability may be incomplete when speed matters most, and a technical assessment is mandatory before a finding only if Commerce has already published methods bearing on that finding.
Commerce and developers must resolve model lineage
Distillation, merging, shared representations, output-generated training data, quantization, and pruning can make “trained, in substantial part” and order scope technically contestable.
Third parties need actual notice and clear boundaries
Binding a non-developer collaborator requires actual notice and concerted participation, which can be difficult to establish across cloud, distribution, research, and open-model relationships.
Commerce must support every renewal with current facts
Successive 90-day periods require new written findings, technical analysis where applicable, updated rescission criteria, and congressional reporting under continuing operational pressure.
DOJ must prove willfulness for criminal cases
Complex model families, evolving restrictions, and distributed control can make it difficult to prove that a person knowingly crossed an emergency order’s technical boundary.
Candidate outcome metrics
Department of Commerce, published final orders, renewals, and rescissions plus the mandated §8(i)(4) semiannual reports, recording covered models and uses, days effective, disposition, and changes in published methods. Provisional orders appear only if the congressional reports or later public records expose them.
Provisional orders issued without prior notice, an opportunity to cure, or a completed technical assessment, plus time to hearing, final order, or lapse. A higher use of these expedited routes serves speed but opposes the ordinary procedural safeguards.
Substantiated order violations, DOJ civil actions, penalties, injunctions, and criminal cases. A higher violation path undercuts risk control and anti-evasion goals even if successful enforcement demonstrates use of the remedy; no consolidated official series is mandated.
No official recurring product attributes avoided harm or a change in catastrophic risk to a particular emergency order. The §4 annual incident report is anonymized and not order-specific.
Conditional forecast sketches
P(number, scope, and duration of final emergency orders and renewals | §8 in force)
P(provisional-to-final conversion, lapse, and rescission shares | provisional order served)
P(order violations and enforcement actions | emergency order effective)
Section 8 — Review and Federal exclusivity
8. §8(j)–(l): expedited review and the exclusive Federal channel for imminent-risk restrictions
Section 8 — Review and Federal exclusivity
8. §8(j)–(l): expedited review and the exclusive Federal channel for imminent-risk restrictions
A developer has ten days after service to seek an expedited administrative hearing, which Commerce must hold and decide within 30 days while providing the relied-on record and bearing an adequate-evidence burden. A provisional order generally cannot receive ordinary judicial review before a final order. The U.S. District Court for the District of Columbia has exclusive jurisdiction, filing does not automatically stay an order, and final orders receive arbitrary-and-capricious review. Constitutional claims remain available. Section 8 is the exclusive means by which any Federal department, agency, officer, employee, or the President may restrict frontier-model activity substantially on imminent-catastrophic-risk grounds; other laws authorize such action only if they expressly refer to §8.
Quoted from the bill ▸
At an expedited hearing, Commerce “shall bear the burden of demonstrating” that “adequate evidence supports the order.” Except for constitutional claims, before a final order, “no court shall have jurisdiction to review” or “stay a provisional order”; §8 is “the exclusive means” for any Federal actor, including “the President,” to impose the covered imminent-risk restriction.
Countersignable goals
Likely effects — shown regardless of the goals
Expedited administrative record
A developer has ten days to request a hearing, Commerce has 30 days to decide, the developer receives the relied-on materials, and Commerce bears the burden of showing adequate evidence.
Deferred ordinary judicial review
A provisional order is not final agency action and ordinarily cannot be reviewed, enjoined, limited, suspended, or stayed by a court until Commerce issues a final order.
Concentrated and non-staying review
The D.C. District Court has exclusive jurisdiction, must expedite the case, and does not automatically stay the order; the D.C. Circuit hears an expedited appeal.
Constitutional safety valve
The jurisdiction limits do not foreclose a Federal constitutional challenge to §8 or to the Secretary’s structure or authority.
Adversarial mechanism — single Federal channel
Exclusivity reaches the President and every Federal agency. An export-control, defense, cybersecurity, procurement, or law-enforcement action can be challenged if its purpose or effect rests in whole or substantial part on imminent catastrophic risk and it did not follow §8.
Unauthorized-action remedy
A covered Federal restriction taken outside §8 is unenforceable, and the affected developer can seek declaratory or injunctive relief, making the threshold characterization of an agency’s purpose consequential.
Implementation barriers
Commerce and courts must decide dense records quickly
Thirty-day administrative schedules and expedited court review must handle classified, trade-secret, technically novel, and potentially incomplete evidence.
Developers bear immediate pre-final consequences
The order remains effective while ordinary judicial access is deferred, and filing a later challenge does not itself stay the restriction.
Other Federal agencies must characterize their purpose
Agencies must decide whether an action is grounded “in whole or in substantial part” in imminent catastrophic risk or instead rests on another statutory purpose outside the exclusive channel.
The executive branch and courts face a structural dispute
Express inclusion of the President and the restriction on authority under other laws invite separation-of-powers and statutory-interpretation challenges.
Safety administration has a single-point-of-failure risk
If Commerce cannot use §8 promptly, exclusivity can prevent another Federal actor from substituting a faster restriction on the same imminent-risk ground.
Candidate outcome metrics
Commerce administrative records on hearing applications, availability of the relied-on record, decisions within 30 days, and outcomes linked to the relevant emergency order. The mandated §8(i)(4) reports require hearing and proceeding outcomes, but not application counts, record-production fields, or deadline-compliance fields, so no recurring series hint is assigned.
Days an order remains effective before judicial access or disposition, together with stays granted. A longer pre-review interval opposes prompt merits review while serving uninterrupted emergency control.
Other Federal actions challenged or held unenforceable under §8(l), including elapsed time before Commerce substitutes a valid order. Displacement serves centralization but can oppose uninterrupted protection if another safety action is delayed.
No official series measures whether the exclusive channel prevented conflicting orders or instead delayed risk mitigation. Individual orders and cases do not reveal the interventions that agencies declined to attempt.
Conditional forecast sketches
P(expedited hearing resolved within 30 days and final judicial action expedited | developer seeks review)
P(days emergency restriction remains effective pending review | provisional or final order challenged)
P(other Federal restrictions held unenforceable under §8(l) | §8 exclusivity in force)
Section 9 — Relationship to State laws
9. §9: preemption of State developer duties with downstream-use, minors, and procurement carveouts
Section 9 — Relationship to State laws
9. §9: preemption of State developer duties with downstream-use, minors, and procurement carveouts
Section 9 preempts State and local substantive obligations imposed on AI developers in three covered areas: catastrophic-risk transparency, third-party auditing or verification, and incident reporting. It preserves generally applicable laws that do not target AI developers; regulation of deployers or users that does not impose upstream development, training, evaluation, or release duties; protections for minors; and State-government procurement or use rules. For preemption, an AI developer includes any entity that builds, designs, codes, produces, trains, or owns any AI model and excludes only an entity that is solely a deployer. That definition is broader than the frontier, large, and very-large classes subject to the affirmative Federal duties.
Quoted from the bill ▸
Section 9 provides that “no State or political subdivision of a State may adopt” or “enforce any law, regulation, order, or other requirement” that “imposes new substantive obligations” on artificial intelligence developers in any Covered Subject Area. The carveouts preserve specified State authority only if it fits §9(c).
Countersignable goals
Likely effects — shown regardless of the goals
Broad covered subject areas
Preemption reaches developer disclosures about frameworks, risk tests, red-team methods and results, model characteristics, third-party audits and certifications, access to technical material for verification, and safety or security incident reporting.
Uniformity and compliance consolidation
A developer need not satisfy different State substantive regimes in the covered areas, reducing multi-State duplication and eliminating stricter State experiments within the preempted field.
Adversarial mechanism — preemption exceeds affirmative coverage
Federal transparency and audit duties depend on a frontier model and sometimes large or very-large financial thresholds, while §9 preempts covered State duties for builders or owners of any AI model. Developers outside the Federal tiers can therefore lose State duties without gaining equivalent Federal ones.
Conditional downstream carveout
States may regulate AI use or deployment through consumer, civil-rights, contract, criminal, or privacy law only if the measure does not impose substantive developer duties concerning development, training, evaluation, or release.
Express minors and procurement savings
States retain targeted authority over sexually explicit content, self-harm content, exploitation, age verification, parental controls, similar harms to minors, and their own procurement or use of AI systems.
Mixed-role ambiguity
Only an entity that is solely a deployer is excluded from the developer definition, so a vertically integrated firm that both develops and deploys can complicate application of otherwise preserved downstream rules.
Implementation barriers
States and courts must classify laws field by field
“New substantive obligations,” “target artificial intelligence developers,” “solely a deployer,” and the boundary between model development and downstream use are not fully defined.
Mixed statutes may resist a binary answer
A single State law can combine developer disclosure, downstream consumer protection, minors safeguards, and procurement terms, requiring severability and remedy decisions rather than whole-law labels.
State enforcers may lose access to upstream evidence
A downstream consumer or civil-rights case can depend on developer testing, model characteristics, or incident records that the State may no longer compel through a covered developer-specific duty.
Federal oversight may not replace displaced State coverage
Commerce has no official census connecting every AI developer to model compute, affiliate revenue, and AI-development spending, so the size of the subthreshold gap is not directly measurable.
Analysts lack a national preemption-coded docket
No authoritative recurring dataset classifies State and local AI laws, investigations, settlements, and judgments under §9’s covered-area and carveout tests.
Candidate outcome metrics
State or local covered-area laws and enforcement actions held preempted or no longer enforceable, coded only from final official legal dispositions. A lower State-duty path serves uniformity but can oppose preserved State authority and overall risk coverage.
AI developers losing covered State duties while not qualifying for Federal frontier, large, or very-large duties. No official census links model ownership, training compute, affiliate revenue, and AI expenditure, so no series hint is warranted.
State consumer, civil-rights, privacy, minors, and procurement actions sustained under §9(c), using official court or agency dispositions without treating heterogeneous State reporting as a single national series.
No official series measures multi-State AI compliance cost or the safety effect of replacing State developer duties with the Federal regime. Census business AI-use estimates describe adoption, not frontier status, regulatory exposure, or compliance cost.
Conditional forecast sketches
P(number of identified covered State duties held preempted | §9 enacted versus not)
P(number of subthreshold developers subject to any catastrophic-risk transparency, audit, or reporting duty | §9 enacted versus not)
P(State downstream, minors, or procurement actions sustained under §9(c) | challenged as preempted)