Reps. Jay Obernolte (R-CA) and Lori Trahan (D-MA), with Reps. Houchin, Peters, Franklin, and Subramanyam · 2026
FRONTIER Act (H.R. 9925)
FRONTIER Act
The Frontier Risk Oversight, National Transparency, Independent Evaluation, and Reporting Act, introduced July 23, 2026 and referred to Energy and Commerce and to Science, Space, and Technology, is the introduced successor to the frontier title of the GAAIA discussion draft Obernolte and Trahan released in June — and a substantially harder instrument. It creates an Under Secretary of Commerce for AI Security and three cumulative tiers. Every frontier developer (a foundation model trained above 10^26 operations, counting fine-tuning and RL) must publish a transparency report before or with each deployment and report critical safety incidents within 72 hours, or to law enforcement within 24 hours if there is an imminent risk of death or serious injury. Large frontier developers (over $50M in revenue and $1B in AI development spending over 36 months) must publish a frontier AI framework, obtain an annual independent compliance audit, file quarterly confidential summaries of catastrophic risk from internal use, and may not develop or deploy a frontier model without a registration statement disclosing their beneficial owners. Very large frontier developers (over $5B in revenue and $10B in AI spending) must retain a federally licensed Independent Verification Organization for ongoing assessment, at least every six months, of whether their risk mitigation is adequate to ensure benefits outweigh catastrophic risk, with corrective-action cycles, public redacted reports, and mandatory IVO referral of imminent risks. The Secretary of Commerce may issue emergency orders suspending a model's development, deployment, or internal use on a finding of imminent catastrophic risk, backed by $10M-per-day civil penalties and criminal penalties of up to 10 years. Preemption is permanent but confined to three subject areas — frontier risk transparency, third-party auditing and verification, and incident reporting — expressly preserving state laws of general applicability, regulation of deployment and use, child-safety laws, and state procurement.
Key Provisions
Under Secretary of Commerce for AI Security, with rulemaking deadlines of 180 days for framework requirements, IVO licensing, and modification criteria, and authority to raise (but not lower) the coverage thresholds
All frontier developers (>10^26 operations): pre-deployment transparency reports with risk assessments and third-party involvement in machine-readable form; critical incident reports within 72 hours, or 24 hours to law enforcement for imminent risk; up to $1M per day in civil penalties
Large frontier developers (>$50M revenue and ≥$1B AI spending over 36 months): published frontier AI framework, annual independent compliance audit with public summary, quarterly confidential reports on catastrophic risk from internal use, and mandatory registration disclosing beneficial owners, with $10K per day for operating unregistered
Very large frontier developers (>$5B revenue and ≥$10B AI spending): ongoing assessment by a federally licensed IVO at least every six months, a 14-day corrective-action response, out-of-cycle supplemental reports, Commerce-ordered ad hoc assessments, and mandatory IVO referral within 72 hours of any imminent catastrophic risk
Emergency orders: the Secretary may suspend or restrict development, deployment, or internal use of a frontier model on a finding of imminent catastrophic risk — 45-day provisional and 90-day renewable final orders, reaching fine-tuned and distilled derivatives, reviewable only in the D.C. District Court with no automatic stay, and enforced by $10M per day in civil penalties and up to 10 years' imprisonment
Exclusivity: emergency orders are the only means by which any federal official, including the President, may restrict a frontier model on catastrophic-risk grounds
Licensed IVOs are immune from suit over catastrophic harms from models they assessed, except for a federal cause of action for willful misconduct causing death or serious injury; IVO reports are exempt from FOIA
Opted-in state attorneys general receive reports and may sue for penalties and injunctions alongside the U.S. Attorney General
Permanent preemption of new state obligations on developers covering frontier risk transparency, third-party auditing and verification, and incident reporting — preserving generally applicable laws, deployment and use regulation, child-safety laws, and state procurement
Regulatory Philosophy
Verify continuously, intervene only in emergencies. The FRONTIER Act declines a pre-release licensing gate but builds the most complete federal oversight machinery of any proposal on this map: a dedicated Under Secretary, a licensed verification profession with its own conflict-of-interest regime, a substantive adequacy standard ('acceptable levels of catastrophic risk mitigation') rather than mere disclosure, and an emergency suspension power with teeth. Obligations scale with size, so the full apparatus reaches only a handful of very large developers. It also disciplines the government: the exclusivity clause makes the emergency-order process the only lawful path to restrict a frontier model on catastrophic-risk grounds, ruling out ad hoc executive action. Preemption is narrower than the White House or Blackburn would have it but, unlike the GAAIA draft, no longer sunsets.
Where the burden falls
FrontierPrimaryAppsNoneHyperscalersNoneChipsNone
Base assessed
Frontier developers above 10^26 operations, tiered by revenue and AI development spending
Why it lands there
Every obligation lands on the frontier layer, and the tiering decides how hard. Revenue and spending are aggregated across affiliates, so labs inside hyperscaler parents — Google DeepMind, Meta — are measured at parent scale and land in the very large tier, but they are assessed as model developers, not as cloud operators. Deployers are explicitly carved out of the preemption definition and untouched by the bill. The fee-funded registration regime is the only charge on the map that a frontier developer pays directly to a regulator.
From GAAIA to the FRONTIER Act: what changed on introduction
Obernolte and Trahan's June 2026 discussion draft became an introduced bill seven weeks later, and nearly every change made it harder. GAAIA housed oversight in a statutory CAISI with voluntary standards; the FRONTIER Act creates an Under Secretary for AI Security with mandatory rulemaking. GAAIA's licensed IVOs audited frameworks; the Act's IVOs judge whether mitigation is adequate on a recurring six-month cycle and must refer imminent risks. GAAIA had no way to stop a model; the Act adds emergency suspension orders backed by criminal penalties. The trade ran the other way on preemption, which lost its three-year sunset and became permanent, though it narrowed to three named subject areas. The workforce, cybersecurity, and research titles were dropped, leaving a frontier-safety bill only.
+Operative, bipartisan legislative text with co-leads from both parties, introduced and referred — the most fully specified frontier-safety statute on the map
+Moves beyond transparency to a substantive standard: licensed IVOs must judge whether a developer's mitigation is adequate to ensure benefits outweigh catastrophic risk, and can lose their license if models they verified fail
+The emergency-order power is real: it can halt development and internal use, not just release, reaches fine-tuned and distilled derivatives, and is enforceable with criminal penalties
+Explicitly covers internal use, closing the gap where the most capable models are run inside the lab long before, or without, public deployment
+Tiering by revenue and AI spending puts the heaviest obligations on the few firms that can bear them while every frontier developer still carries transparency and incident reporting
+Beneficial-ownership registration gives the government a map of who controls frontier developers, a national-security tool no other proposal includes
+Preemption is confined to three named subject areas and preserves child-safety, deployment, and generally applicable state law, a sharper line than most federal proposals draw
Weaknesses
From the perspective of political opposition
−No pre-release gate: a very large developer can ship a model before its IVO finds a deficiency, and government intervention requires a finding of imminent catastrophic risk — a high bar to meet before harm is visible
−IVO immunity from virtually all liability, plus FOIA exemption for their reports, shields the verifiers from the accountability that disciplines financial auditors, and developers still pay the IVOs that judge them
−The exclusivity clause cuts both ways: it protects developers from arbitrary executive action, but also strips every other federal authority of the ability to act on catastrophic-risk grounds without running this procedure
−The Under Secretary may raise thresholds but never lower them, so coverage can only shrink as algorithmic efficiency makes dangerous capability cheaper
−Preemption is now permanent, and it displaces exactly the areas — transparency, auditing, incident reporting — where California and New York have enacted frontier laws
−Catastrophic risk is defined at more than 50 deaths or $1B in damage from a single incident, leaving harms below that line and diffuse harms outside the statute entirely
−Silent on workers, consumers, copyright, and data centers, and it drops GAAIA's workforce title