HR-9925-119
Referred to the Committee on Energy and Commerce, and in addition to the Committee on Science, Space, and Technology, for a period to be subsequently determined by the Speaker, in each case for consideration of such provisions as fall within the jurisdiction of the committee concerned.
Sponsored by Jay Obernolte (R-CA)
What it does
The FRONTIER Act would establish a federal regulatory framework for the development and deployment of the most powerful artificial intelligence models — called "frontier models" — trained using more than 10²⁶ computing operations. It would require large AI developers (those with over $50M in revenue and $1B in AI spending over 36 months) to publish safety frameworks, undergo annual third-party compliance audits, and report critical safety incidents to the federal government. Very large developers (over $5B in revenue and $10B in AI spending) would additionally be required to retain licensed Independent Verification Organizations (IVOs) for ongoing, semi-annual assessments of catastrophic risk mitigation. The bill would create a new Under Secretary of Commerce for AI Security to administer the program, with civil penalties of up to $1,000,000 per day for violations.
Who benefits
The general public, who would gain access to published safety frameworks and audit summaries for the most powerful AI systems. Researchers and journalists who would benefit from mandatory public disclosures. Smaller AI companies that fall below the compute and revenue thresholds and face no new compliance burdens. State Attorneys General who opt in to receive safety reports and gain new enforcement authority. Licensed independent auditing and verification firms, which would constitute a new industry created by the bill. Workers and communities that could be harmed by catastrophic AI incidents — such as cyberattacks, CBRN weapon assistance, or loss of AI control — that the bill aims to prevent. National security agencies that would receive early warning of critical safety incidents.
Who is hurt
Large frontier AI developers — primarily a small number of companies such as those currently training the most powerful foundation models — who would bear significant compliance costs including mandatory audits, IVO retainers, disclosure filings, and registration fees. Startups approaching the revenue and compute thresholds that may face regulatory uncertainty as they scale. Employees at covered companies who may face increased administrative and legal overhead. Competitors in jurisdictions with lighter AI regulation who may gain a cost advantage over U.S.-based developers. Consumers and downstream businesses that may face higher prices or slower AI product releases if compliance costs slow development cycles. Academic and open-source AI researchers who, depending on regulatory interpretation, could face ambiguity about whether their activities trigger coverage.
Supporters argue
Supporters argue that frontier AI models — trained at costs exceeding tens of billions of dollars — represent a qualitatively new category of technology capable of providing meaningful assistance in creating weapons of mass destruction, conducting autonomous cyberattacks, or evading human control, risks that existing regulatory frameworks were not designed to address. They contend that the bill's tiered structure — applying lighter disclosure requirements to large developers and more intensive IVO assessments only to the very largest — is carefully calibrated to avoid burdening smaller innovators while targeting the handful of actors whose systems pose the most serious catastrophic risks. They further argue that mandatory public transparency reports and independent verification, modeled on financial auditing frameworks, would give the public and policymakers reliable information rather than relying solely on self-reported safety claims from companies with commercial incentives to minimize disclosed risks.
Opponents argue
Opponents argue that the bill's core concepts — "catastrophic risk," "acceptable levels of catastrophic risk mitigation," and "frontier AI framework" adequacy — are inherently subjective and vague, creating legal uncertainty that could chill legitimate research and development without producing measurable safety gains. They contend that the IVO licensing regime, administered by a newly created Under Secretary with broad rulemaking authority, concentrates significant discretionary power in a single executive branch official with limited congressional oversight, and that post-Loper Bright, courts will independently scrutinize whether the bill's broad delegations are sufficiently clear. They further argue that compliance costs and mandatory disclosures could push frontier AI development offshore to jurisdictions with no equivalent requirements, undermining both U.S. competitiveness and the bill's safety goals by reducing federal visibility into the most capable systems.
Constitutional context
Congress's authority to regulate frontier AI developers operating in interstate and foreign commerce rests squarely on the Commerce Clause (Art. I, §8, cl. 3). The bill's broad delegation of rulemaking authority to the Under Secretary — including authority to define key thresholds and assessment standards — faces heightened judicial scrutiny following Loper Bright v. Raimondo (2024), which overruled Chevron deference and requires courts to independently assess whether agency interpretations of statutory terms are correct. The mandatory public disclosure requirements and IVO assessment regime do not appear to raise First Amendment compelled-speech concerns under Moody v. NetChoice (2024), as they regulate commercial conduct rather than editorial content decisions.
Checks and balances
The executive branch — specifically a newly created Under Secretary of Commerce for AI Security — gains significant new regulatory authority to license IVOs, set assessment standards, and impose civil penalties; checks include notice-and-comment rulemaking under the APA, enforcement actions requiring the Attorney General, opt-in State Attorney General co-enforcement, mandatory annual congressional reporting, and judicial review of agency rules under the heightened post-Loper Bright standard.
Historical precedent
The EU AI Act (2024) established a tiered risk-based regulatory framework for AI systems in the European Union, including conformity assessments for high-risk systems, though no directly analogous federal U.S. statute has previously been enacted for AI safety oversight at this scope.