Federal preemption plan would silence state AI laws
You might have just started feeling like your state is finally doing something about AI. Perhaps your governor signed a law requiring transparency when AI is used in hiring. Maybe your state attorney general announced an investigation into deepfake election ads. Or perhaps you live in California, where a flurry of bills aimed at everything from AI-generated child sexual abuse material to algorithmic discrimination in insurance pricing have been making their way through the legislature. You might have even felt a flicker of reassurance — someone, somewhere, is paying attention.
But there is a legislative draft circulating in Washington that, if passed, would make most of that state-level activity irrelevant for three full years. The Great American Artificial Intelligence Act of 2026, introduced by Representatives Jay Obernolte (R-CA) and Lori Trahan (D-MA), proposes a federal preemption of state AI laws — a legal mechanism that would effectively silence the patchwork of state regulations that have emerged in the absence of federal action. [6] This is not a small tweak to existing policy. It is a fundamental reordering of who gets to decide how artificial intelligence touches your life, your job, your privacy, and your safety.
The draft bill is bipartisan, which in today’s polarized political climate is itself a signal It has the backing of the White House, which released its own AI policy framework simultaneously, calling for the same preemptive approach. The argument is seductive: without a single national standard, the United States will fall behind in the global AI race. Companies will face a “patchwork of conflicting state laws” that will “undermine American innovation.” This is the fear the bill names and seeks to dispel — the fear that the United States will lose its technological edge because of fragmented regulation.
But the fear the bill does not name, and the one you should be paying attention to, is this: what happens when the federal government tells your state it cannot protect you from the most powerful information technology ever created? What happens when the legal framework for AI governance is designed primarily to ensure that the technology can scale without interruption, rather than to ensure it serves human interests?
The Architecture of Silence
The mechanism at the heart of this legislation is called federal preemption. It is not a new legal concept. The Constitution’s Supremacy Clause has long established that federal law can override state law when Congress intends it to. What is new is the scope of the preemption being proposed for AI. The draft bill would prohibit states from regulating the “development, training, deployment, or use” of artificial intelligence systems for three years. This is not merely about stopping new state laws. It would effectively freeze existing state AI regulations in place, preventing them from being enforced or updated.
The logic behind this preemption is rooted in a specific worldview about technological progress. The draft bill’s authors, and the White House that supports it, argue that AI is a national asset requiring uniform treatment. They point to the internet’s early days, when a similar fear of fragmentation led to policies that allowed e-commerce and social media to scale rapidly. The comparison is instructive but incomplete. The internet of the 1990s was a communications network. AI is a decision-making system that can automate hiring, determine creditworthiness, influence jury decisions, and generate content indistinguishable from human creation. The stakes are fundamentally different.
The preemption period is designed to give the federal government time to build its own regulatory infrastructure. The bill creates a Center for AI Standards and Innovation (CAISI) within the Department of Commerce, tasked with developing voluntary guidance and standards for frontier AI models. It establishes a licensing regime for independent verification organizations that would audit AI companies’ compliance with their own stated frameworks. It allocates $100 million annually for three years to fund this work, totaling $300 million. [1] But here is the structural problem: the bill does not mandate that these standards be binding. It does not require that the verification organizations have enforcement power. It does not create a private right of action for individuals harmed by AI systems.
What the bill creates, in essence, is a system of self-regulation with a government stamp of approval. Companies would develop their own AI governance frameworks, submit to audits by organizations they might help select, and then be largely free to operate without meaningful oversight. The preemption ensures that no state can step in to fill the gaps. The message to the public is clear: trust the process. The message to industry is equally clear: you have three years to shape whatever federal regulation eventually emerges.
The Workforce Question: Counting Bodies, Not Lives
The bill’s treatment of AI’s impact on the workforce is perhaps the most revealing section. It directs the Department of Labor to create an Artificial Intelligence Workforce Research Hub that would supply “clear statistics on changes in the labor market and AI workforce landscape.” It calls for an expert workshop to evaluate the Bureau of Labor Statistics’ understanding of AI’s workforce impact. It prioritizes AI literacy in K-12 education and creates Centers of AI Excellence through the National Science Foundation.
These are not bad ideas. Understanding how AI is changing employment is essential. But the framing is telling. The bill asks for statistics, not protections. It calls for education, not unemployment insurance reform. It funds research into the problem while leaving the people who will be displaced by AI to fend for themselves during the three-year preemption period.
Consider what this means in practice. A state like New York, which has been exploring ways to regulate AI in hiring to prevent algorithmic discrimination, would be unable to enforce those protections. A state like Illinois, which has a biometric privacy law that has been used to challenge AI-powered surveillance systems, would find that law effectively suspended for AI applications. A state like Colorado, which passed a comprehensive AI law in 2024 requiring risk assessments for high-risk AI systems, would see that law nullified.
The people most affected by this preemption are not AI researchers or tech executives. They are workers who might be screened out of job opportunities by automated resume parsers that have been shown to discriminate against women and minorities. They are patients whose health insurance claims might be denied by AI systems that have been found to be less accurate for Black patients. They are tenants whose rental applications might be rejected by AI models trained on historically discriminatory data. These are not hypothetical scenarios. They are documented realities that state legislators were beginning to address. The federal preemption would stop that work cold.

The Cybersecurity Gambit: Protection Through Access
The bill’s cybersecurity provisions reveal another layer of the trade-off being proposed. It would reauthorize and extend the Cybersecurity Information Sharing Act of 2015 until 2035, directing the Department of Homeland Security to develop outreach plans for small and rural critical infrastructure operators. It would have the Cybersecurity and Infrastructure Security Agency (CISA) and CAISI work together to assist open-source software maintainers in their defensive efforts. Open-source maintainers would be eligible for funding to help detect and patch vulnerabilities through “controlled access to select frontier models.”
This sounds sensible on its face. AI systems can indeed help identify security vulnerabilities faster than human analysts. But the provision also creates a dependency relationship. Open-source maintainers, who are often volunteers or underpaid developers, would need to submit to government-facilitated access to AI models controlled by the same companies whose products they might be trying to secure. The bill does not specify what “controlled access” means, who controls it, or what happens if a maintainer’s findings conflict with a company’s interests.
More broadly, the cybersecurity section frames AI as a tool for defense while remaining silent on its use as a weapon. The bill does not address the proliferation of AI-powered cyberattack tools. It does not regulate the development of autonomous offensive cyber capabilities. It does not require companies to disclose when their AI models are used to generate malware or phishing campaigns. The focus is entirely on using AI to protect existing systems, not on protecting society from AI-enabled threats.
The Research Paradox: Funding Innovation, Not Oversight
The final section of the bill is dedicated to research and development, with the explicit goal of ensuring the United States continues to lead in AI innovation. It creates a new testbed program involving national laboratories, federal laboratories, NIST, and private sector entities. It formally establishes the National AI Research Resource (NAIRR) as a permanent program within the National Science Foundation, capable of accepting donations of cash, services, and personal property from private sector entities. [4] It directs the Office of Science and Technology Policy to develop a prioritized list of federal datasets for public release to support model training.
The research provisions are generous. The oversight provisions are not. The testbeds are tasked with conducting “security risk and vulnerability assessments,” but these assessments are focused on technical vulnerabilities — autonomous offensive cyber capabilities, software ecosystem weaknesses, chemical and biological threats. They are not tasked with assessing social risks — algorithmic bias, job displacement, democratic erosion, privacy violations. The bill treats AI safety as a technical problem requiring technical solutions, ignoring the social and political dimensions that state legislators have been grappling with.
The NAIRR’s ability to accept private donations is particularly noteworthy. While the bill frames this as a way to leverage private sector resources for public research, it also creates a channel for industry influence over the direction of federal AI research. Companies that donate computational resources or datasets could shape which research questions are asked and which are ignored. The bill does not include conflict-of-interest provisions or transparency requirements for these donations.
The Democratic Deficit: Who Wasn’t at the Table
The draft bill has received bipartisan support from its sponsors, but the House Democratic Commission on AI and the Innovation Economy has explicitly declined to endorse it. “This document cannot serve as the basis for productive dialogue,” the commission stated, citing concerns from civil society organizations, industry, labor, and academia. This is a significant political signal. It suggests that even within the party that helped draft the bill, there is recognition that the legislation does not go far enough in addressing the real harms AI systems can cause.
The commission’s criticism points to a deeper democratic deficit in how the bill was constructed. The preemption provision was not the result of extensive public consultation. It was not debated in state legislatures. It was not the subject of town halls or public hearings. It emerged from a closed process involving federal lawmakers, White House officials, and industry representatives. The people who will be most affected by this legislation — workers, consumers, patients, citizens — had no meaningful voice in its creation.
This is not an argument against all federal AI regulation. There are legitimate reasons to prefer national standards over state-by-state patchworks. Companies that operate across state lines face compliance costs that can be significant. Smaller states may lack the resources to effectively regulate complex AI systems. International competitiveness is a real concern. But the solution to these problems is not to silence state voices while building a federal regulatory system that may never materialize in meaningful form. The solution is to build federal regulation that is robust enough that states do not need to act on their own.
The Three-Year Window: What Happens When the Clock Runs Out

The bill’s three-year preemption period is arguably its most consequential and potentially deceptive feature It creates the impression of urgency — we need to act now, before the states create chaos — while actually buying time for industry to shape whatever permanent regulatory structure eventually emerges. Three years is an eternity in AI development. The models available today are dramatically more capable than those available three years ago. The models available three years from now will likely be more capable still, with capabilities we cannot currently predict.
During those three years, the federal government would be building its regulatory infrastructure through CAISI, the verification organization licensing regime, and the testbed program. But none of these institutions would have enforcement power. None of them would be able to stop a company from deploying a harmful AI system. None of them would be able to compensate a worker who lost their job to an algorithm that systematically discriminated against them. The bill asks for trust — trust that the process will work, trust that industry will self-regulate responsibly, trust that the federal government will eventually get it right.
History suggests this trust is misplaced. The financial industry’s self-regulation before the 2008 crash. The social media industry’s self-regulation before the 2016 election. The pharmaceutical industry’s self-regulation before the opioid crisis. In each case, industry promised to police itself, and in each case, it failed. The consequences were borne by the public, not by the executives who made the promises.
The Map Coordinates: Where We Stand
The Great American AI Act of 2026 is not yet law. It is a discussion draft, subject to revision and debate. But it represents the most serious attempt yet to create a comprehensive federal framework for AI governance, and its preemption provision is the most consequential element. If passed, it would mark a fundamental shift in how the United States regulates technology — from a system of distributed experimentation, where states can serve as laboratories of democracy, to a system of centralized control, where Washington decides what protections exist and where.
The bill’s sponsors would argue that this centralization is necessary for competitiveness. They would point to China’s unified approach to AI development and warn that the United States cannot afford to be divided. They would frame the preemption as a pragmatic response to a genuine problem. And they would not be entirely wrong. But they would be missing the deeper question: competitiveness for whom? A nation that competes by sacrificing worker protections, consumer safeguards, and democratic accountability is not a nation that has won anything of value.
The coordinates of this moment are precise. We are standing at the intersection of technological capability and political will. The technology is advancing faster than our institutions can adapt. The political will to regulate it is present but fragmented. The bill before Congress represents one vision of how to resolve this tension — a vision that prioritizes speed over deliberation, industry over citizens, and federal power over state experimentation. Whether this is the right vision depends on what you believe AI is for. If you believe it is a tool to be deployed as quickly as possible, with the hope that its benefits will outweigh its harms, then the bill makes sense. If you believe it is a technology that requires careful, democratic governance, with meaningful protections for the people it affects, then the bill is a step in the wrong direction.
The map of ongoing work is being drawn now, in congressional hearing rooms, industry boardrooms, and state legislative chambers. The question is who gets to hold the pen — and whether the public will have a say in the final design.
Sources
1. National Science Foundation
2. Department of Homeland Security
3. National Institute of Standards and Technology
4. National AI Research Resource
5. Office of Science and Technology Policy
6. House Democratic Commission on AI and the Innovation Economy
