On Wednesday, October 7, Sen. Maria Cantwell (D‑WA) released an outline for AI regulation that spells out six principles that she believes “must drive the legislative and executive actions needed to address catastrophic risks and other AI harms.” As the Ranking Member of the Senate Committee on Commerce, Science, and Transportation, her word on what the next AI policy priorities should be is a sign of what the Democratic Party seeks to achieve through AI regulation. The framework spans a broad range of topics, from federal standards for AI development and transparency and disclosure requirements to youth safety and international cooperation agreements.
Some proposals in this outline draw and build on ideas already circulating in legislative text or rumored to appear in forthcoming bills, which could indicate that Congress might start coalescing around a potential framework. A broad framework will naturally have both positive proposals and notable flaws. As with any AI framework, Cantwell’s proposal has strengths and weaknesses. As members of Congress look for ways to translate overlapping ideas into tangible legislation, they should be aware of the nuances that could turn benign policies into harmful regulations.
The Good
To start, Cantwell’s proposal includes several important policies that address key concerns. One concern involves the recent incidents in which rogue models have led to increased calls for a standard that ensures the safe deployment of AI. Most of these calls envision these deployment standards as a prescriptive, top-down mandate that labs must adopt to develop frontier AI systems. Senator Cantwell’s proposal would, in theory, instead rely on standards set by the National Institute of Standards and Technology (NIST), which typically issues nonbinding, voluntary frameworks. The benefit of this approach is that while these standards are widely adopted across industries and could be considered sector-wide regulations, their flexible, voluntary nature makes them less susceptible to the pitfalls of traditional regulatory tools. NIST’s guidance is usually developed in cooperation with the private sector, is continuously updated and revised, and serves as a guidance document that companies are usually eager to adopt. But it is (usually) not mandatory. A standards-setting regulation that relies on NIST is, in theory, less likely to result in prescriptive, heavy-handed regulation.
The outline also places a strong emphasis on government preparedness, with hopes of building resilience in local and state governments’ infrastructure to prepare for the arrival of higher-capability AI systems. Tasking federal agencies, which are more likely to have the technical expertise and resources, with leading this process in their own local and state subdivisions seems like the most straightforward way to achieve this goal. Additionally, the proposal calls for the government to collaborate with industry to develop defensive AI tools to equip against potential cyberattacks better. Building a more resilient and secure IT infrastructure should be a priority at all levels of government in an era when cyberattacks might become significantly more common.
Senator Cantwell also recognizes the importance of the United States taking proactive measures to secure a position of global leadership in AI standards-setting and regulation. Just as a state-level patchwork will harm companies domestically—something the outline unfortunately does not address—differing international standards also drive up compliance costs and often single out American businesses. Creating a uniform international standard is a big step toward positioning American firms for success, but it is not enough on its own. It is important, however, that this uniform approach allows innovation to flourish rather than the more restrictive approaches seen in Europe. A US-led approach should offer an alternative that addresses specific concerns and provides the needed certainty for industry and investors, without limiting the broader potential of a technology to curtail risks, whether material or hypothetical.
The Bad
Some of the biggest concerns with this framework lie in its omissions. Among the most notable is the lack of a firm stance on whether this framework believes the executive should have the power to freely pull models from the market or prevent their release in the first place. In the introduction to this framework, Cantwell claims that “covered models should not be released until they have undergone an independent audit confirming that they meet these safeguards and standards.” However, in a later section describing a proposal for independent auditing, the outline does not explicitly state that this auditing process is a prerequisite for launch. Similarly, the standards proposal highlighted above could become problematic if it were to adhere to a NIST framework mandatory, as that would undermine its voluntary, nonbinding nature. The lack of clarity about how these proposals could be used to remove products from the market or to restrain their entry at all would turn what could be innocuous or even positive measures into an “FDA for AI” regime that would threaten speech and innovation.
Similarly, the framework is conspicuously silent on whether a comprehensive federal AI bill would preempt state AI laws. The proliferation of state-level AI laws and proposals makes an AI governance patchwork inevitable unless Congress steps in. The experience with data privacy legislation has shown that this approach is costly, confusing for businesses and consumers alike, and self-defeating. A federal regulation that serves merely as a floor, on which states can impose additional regulations, would add to the overall regulatory burden. This becomes a throttle for the industry at large, particularly for smaller players. It would also add confusion for consumers, who would have different rights and duties depending on the state where they are located, which is why a federal standard is desirable in the first place.
The proposals on youth safety, unfortunately, seem to draw on some of the most popular federal proposals for social media, such as design mandates or prohibitions on “harmful content.” As my colleagues have previously pointed out in more detail, these laws often contravene the Constitution and have a proven track record of failing to ameliorate the issues they claim to solve.
Cantwell also pushes for AI companies to “help fund apprenticeships, education and other worker training so that AI expands workers’ skills, productivity and earning power rather than displacing them.” This proposal stems from the popularized notion that AI will lead to job displacement and mass unemployment. Early evidence suggests the opposite. Retraining programs and apprenticeships are not a bad idea per se, but mandating that companies fund them is. This is largely redundant and unnecessary, as companies are already funding these programs without a mandate in place. In fact, these expenditures will likely rise on their own as AI and data center jobs face a worker shortage, incentivizing companies to attract new talent to the sector.
Another concerning proposal is the “consequential decision” framework, which emulates the approach of other problematic state bills, namely Colorado’s infamous SB24-205/SB26-189. As my colleague David Inserra has pointed out, demanding that AI systems be “fair” when making part of a “consequential” decision is likely to lead to various breaches of free speech rights.
Most of the negatives in the framework stem from the looming threat that some of these policies could be used to introduce a vetting or licensing regime through seemingly innocuous measures. Additionally, some of the design and content provisions are likely to infringe on the speech rights of AI labs and consumers alike. The framework’s silence on potential preemption of state laws would pave the way for a more heavily regulated AI industry, as states would still be able to pass legislation that goes beyond what it proposes. Ultimately, this would not be a federal standard, as states can still impose their will by making their state-level laws the most onerous to comply with, making them the actual de facto standard.
The Uncertain
As is only natural in a framework that focuses on big picture ideas, some parts remain unclear or uncertain. How these ideas translate into legislative text will shape whether they could be good or bad.
In theory, Senator Cantwell’s proposal for an audit, disclosure, and incident reporting system could be a net positive for public trust and for building safety guardrails that mitigate development risks. But when put into practice, the devil is in the details. Depending on how such bills are drafted, what could be a pro-innovation measure could quickly become a pathway for heavy-handed government regulation of an industry. For example, a worrisome component of the audit proposal is that it stipulates audits by both the government and independent verifiers. If taken with the earlier statement that these audits would be a prerequisite for launch, this proposal could become a prerelease vetting regime, in which the potential for government abuse increases significantly.
A similar situation could arise with disclosure or incident reporting mandates. In these cases, usually less is more. A mandate that is general and principle-based and that either avoids going deep into specifics or delegates that task to organizations like NIST, tends to be better at achieving its objective of informing the public without burdening innovators. However, when disclosure laws veer into micromanagement territory by listing specific requirements and dictating what constitutes an appropriate disclosure, they risk becoming increasingly onerous for companies to comply with, hurting smaller businesses and entrenching incumbents. Unrealistic disclosure timelines are another common pitfall in this sort of proposal. Other provisions, such as the whistleblower protections, can only be properly evaluated once the text is released, as their scope and latitude can make them ripe for abuse when employees use them as a shield against layoffs or firings.
Conclusion
Overall, Senator Cantwell’s framework makes the right call by advocating for greater government preparedness before the arrival of advanced AI capabilities, especially by ramping up cybersecurity investment and training to ensure that federal, state, and local governments are well prepared against cybercriminals. Its potential reliance on NIST and soft-law tools to guide the standards-setting process would strike a balance between establishing meaningful guardrails to mitigate risk and protecting free speech and innovation in the AI industry.
Unfortunately, much of the potential good that could come from this framework is contingent on what it fails to address or addresses ambiguously. While some of its proposals could be benign, such as the independent-verifier system or the transparency and incident reporting mandates, the risk that they become a backdoor for government micromanagement or the introduction of a prerelease vetting system could quickly transform them into harmful policy. Granting the executive unchecked power to pull models from the market or prevent their entry opens the door to weaponization, as we have already seen under the Trump administration. As AI is a technology with such expressive potential, these companies are likely to draw the ire of politicians regardless of political affiliation, and any power to pull or block models could easily become a tool for censorship.
A federal AI framework could have a positive impact on consumers and industry. But to do so, it must be a unifying, preemptive statute. The experience with other digital technologies has taught the United States that a regulatory patchwork is costly, confusing, and self-defeating.
AI policy is at a pivotal moment, with an apparent appetite in Congress to pass a comprehensive AI law. If that is the case, the passing of this law will be a make-or-break moment for the development of one of the most promising technologies in decades. Cantwell’s release of this framework signals what one side of the aisle is looking for as it heads to the negotiating table. Understanding the nuances of the existing proposals from both sides of the aisle is key to ensuring that the hypothetical framework gets this issue right.













