
The FRONTIER Act, introduced by Reps. Jay Obernolte and Lori Trahan, is the most promising legislative proposal to date for governing risks from frontier AI.
A sensible federal framework for governing the most capable models must address the threat that these models pose while remaining flexible over time as capabilities and best practices change. The FRONTIER Act has both of these properties. Instead of baking detailed technical standards into law, the bill licenses independent verification organizations to assess whether each very large frontier developer has a framework in place that, when followed properly, is adequate for reducing catastrophic risk.
The bill also requires each large frontier developer to bring in a third-party auditor who certifies that the company is indeed in compliance with its own published framework.
FRONTIER also capitalizes on the expertise, greater capacity, and competitive incentives of the AI industry’s specialists while leaving the Department of Commerce to set licensing criteria and intervene only when a model presents an imminent catastrophic risk.
What the FRONTIER Act Does
The core feature of the FRONTIER Act is a federal system of independent verification organizations, or IVOs. An IVO is an external third-party that is licensed to assess the practices of an AI developer. Under FRONTIER, the Department of Commerce sets the standards that must be met by any aspiring IVO, including minimum technical qualifications and institutional independence from the client being assessed. The bill also creates a new Under Secretary of Commerce for AI Security to oversee this system.
Each “very large frontier developer” (defined as an AI developer that earned more than $5 billion in revenue and spent at least $10 billion on development over the preceding three years) must retain a licensed IVO of its choice. Granted visibility into the developer’s full operations and company records, the IVO then assesses whether the developer’s published “frontier AI framework,” governance practices, and mitigations are adequate to achieve acceptable mitigation of catastrophic risk. The result of this assessment is submitted simultaneously to the developer and to the Under Secretary of Commerce for AI Security every six months.
Each “large frontier developer” (a broader category defined as an AI developer with more than $50 million in revenue and at least $1 billion in development spending over the same period) must also publish and follow a frontier AI framework. But unlike a “very large” developer, it must bring in a third-party auditor merely to certify compliance—in other words, to certify that the developer is indeed following its self-published AI framework. The merits of that framework are not finely evaluated. Moreover, that third party need not be a full-fledged licensed IVO, though it must demonstrate basic competence. In other words, FRONTIER would require that large developers be certified simply for their compliance with a chosen framework, whereas only very large developers would be vetted by an IVO on the ultimate adequacy of their internal safety practices.
Zooming out, the bill installs basic transparency requirements on all frontier developers regardless of size; developers must publish a report on each new frontier model and report critical safety incidents to Commerce. In a unique provision, FRONTIER bestows the Secretary of Commerce with emergency authority: if a model presents an imminent catastrophic risk, the Secretary can suspend its development or deployment.
For context, the FRONTIER Act is the result of an earlier, nearly 300-page discussion draft from Obernolte and Trahan called the Great American AI Act (GAAIA), which drew substantial criticism for proposing federal preemption: the ability of federal law to supersede state rules on certain issues. Of course, the new bill would not be a satisfying follow-up if it did not offer an answer to these fears. Going forward, the framework set by FRONTIER would take precedence over new state laws covering third-party auditing, incident reporting, and risk disclosures for frontier models—while in general preserving state authority in AI’s deployment and use.
Why FRONTIER Is Unusually Promising
Among the FRONTIER Act’s strongest features is that it does not bake a set of today’s technical safety standards into statute. To do so would be a mistake, as criteria that apply to models today will become at best quantitatively misguided and at worst non-applicable. In the future, the frontier model itself might even cease to be the correct layer of the tech stack to regulate, as model-level controls would neglect eventual customization or deployment-layer behavior. Fortunately, the regime envisioned by FRONTIER would remain robust under such changes. Future legislation could bluntly overwrite the snippets of language that do hinge on current model size, training cost, or specific position in the tech stack without breaking the rest of the framework. The bill’s concept for third-party technical experts to take ownership of technical decision-making makes it especially resilient to future changes in AI capabilities and company practices.
Furthermore, this approach allows the United States to source its third-party experts from the very best. Essentially, the FRONTIER Act creates a free market of verifiers and auditors, inviting top talent—engineers formerly at major AI companies, veterans of the insurance industry, experts from the world’s AI safety institutes—to come out of the woodwork and stand up the licensed IVOs and other third-party auditors that the bill envisions. And this idea has some intellectual history to it. Back in April 2023, University of Toronto legal scholar Gillian Hadfield and Anthropic’s Jack Clark proposed “regulatory markets” for AI, in which the government would set regulatory objectives while licensed private regulators compete on how to best achieve them. Once established per the FRONTIER Act, each of these independent contractors would carry a track record for the services it provides and a consequent incentive for excellence. No AI developer wants to work with the IVO or auditor with a reputation for being slow or incompetent—not to mention one that charges a higher price. For licensed IVOs, these incentives of course come in addition to the stark binary incentive: deliver rigorous results or be stripped of one’s license by the Department of Commerce for biased or shoddy work.
Alongside the bill’s IVO regime, the nation would still benefit from a strong measurement capability native to the U.S. government. Housed within the National Institute of Standards and Technology, the Center for AI Standards and Innovation (CAISI) is already developing evaluation and benchmarking methods for advanced AI systems, including for the comparative tracking of U.S. and foreign capabilities. America need not put CAISI in charge of regulation to benefit from its expertise—in fact, CAISI lacks that legal authority in the first place. In its full form, CAISI could supply shared, respected methods that facilitate decision-making for government and industry, while other officials remain responsible for licensing and enforcement.
Congress should therefore invest heavily in CAISI’s technical capacity. For reference, GAAIA originally placed CAISI in its IVO regime, authorizing $100 million per year through fiscal year 2029. It need not find its new charter in the FRONTIER Act, but CAISI is a valuable resource that Congress should support and that the country should leverage for its full potential.
The FRONTIER Act’s tiered structure also makes it efficient, assigning due diligence commensurate with the risk posed. For a professor grading an essay, a quick glance is enough to certify that the student wrote a complete response that more or less stayed on topic, addressing the professor’s prompt. However, judging the theoretical soundness of the arguments made in that essay is the laborious part. Similarly, checking that an AI company followed its own published framework is a much lighter lift than analyzing the merits of that company’s framework and internal operations to determine whether its safety practices mitigate catastrophic risk by an adequate quantity. FRONTIER accordingly places covered developers into the three tiers discussed above: first, frontier developers generally face only basic transparency and incident-reporting requirements; second, large developers add on a lightweight compliance audit; and third, only very large developers undergo a more intensive IVO assessment of whether their safety practices are ultimately adequate. This system means that non-frontier AI companies—the vast majority of those in the AI industry—have no FRONTIER requirements whatsoever, and even leading AI companies remain free to innovate and adapt within their own frameworks.
Finally, FRONTIER offers a well-scoped take on federal preemption. A national framework is optimal on issues where a heap of state laws would create duplicative reporting burdens or—even worse—contradictory requirements. The latter could force companies to create entirely separate product lines to satisfy separate states or preclude company operation altogether if state laws are inherently contradictory. FRONTIER preempts new state rules that cover auditing, verification, transparency, and incident reporting around catastrophic risks, while generally leaving states free to regulate how AI systems are deployed and used. The result is a prudent carveout that positions the federal government to focus on the most serious threats and incidents at the most advanced companies.
The FRONTIER Act Is Congressional Iteration at Work
The path from GAAIA to FRONTIER is an example of a discussion draft in action. GAAIA was released expressly to solicit feedback before a formal introduction, and criticism came in quick supply, especially upon GAAIA’s preemption of state AI laws. More than 200 state legislators from 42 states signed a bipartisan letter opposing the preemption provision. All of this backlash came despite the bill’s measured preemption: it applied to state laws targeting the development stage of AI models, in the prudent hope of sparing each company’s model development from a mound of conflicting state requirements. GAAIA’s preemption of just this development stage meant that it still respected all state-level preferences on AI’s end use and deployment.
The Obernolte and Trahan offices responded by prioritizing GAAIA’s core goal of achieving a frontier-safety regime that does not tie AI developers down. Preemption was pruned: instead of preempting state laws about model development, the new bill focuses federal preemption on a few frontier-safety requirements. The rest of the FRONTIER Act underwent a similar distillation, prioritizing frontier governance amidst GAAIA’s much larger package—nearly 300 pages—and reserving its most intensive regulatory scrutiny for the very largest developers. This rework was enough to earn acknowledgement from GAAIA’s critics and commentators. In a press release, Encode’s Nathan Calvin described it as “meaningfully better than GAAIA,” and Charlie Bullock of the Institute for Law and AI—who had called the GAAIA discussion draft “net-negative as written”—called FRONTIER “by far the best AI safety bill ever introduced.”
However, at least one glaring weakness remains in the bill. The FRONTIER Act defines a “frontier model” as any foundation model trained using more than 1026 integer or floating-point operations and stipulates that the Under Secretary may increase this threshold. What happens if algorithmic improvements allow the most advanced AI developer to achieve the same capabilities while using fewer computations than before? Or while using fewer computations than everyone else in the industry? In this case, it might behoove the Under Secretary to decrease this threshold; it is not safe to assume that the ongoing paradigm of AI progress will be one of ever-bigger training runs. At minimum, Congress should permit the Under Secretary to adjust the compute threshold in either direction. Better still, compute need not be the sole trigger: a foundation model could also qualify if it scores high enough on any one of a set of rigorous and authoritative benchmarks—to be designated and updated by the Department of Commerce—that demonstrate the potential for catastrophic risk.
Congress Should Move the FRONTIER Act
The FRONTIER Act, which has been referred to in both the Committee on Energy and Commerce and the Committee on Science, Space, and Technology, is already the strongest proposal that Congress has ever produced for handling the risks of frontier AI. The inherent flexibility and resiliency of the IVO regime that FRONTIER proposes is its greatest virtue. Although the bill’s definition of a “frontier model” would benefit from an amendment—allowing the 10²⁶ compute threshold to move downward or adding a select suite of evaluations as an alternative trigger—the bill is exceptionally well-reasoned. The House should move it through its committees of jurisdiction and bring it to the floor for a vote. FRONTIER would lay a flexible foundation that lawmakers can update in future legislation without upending the verification framework already in place. Under business as usual, which today means zero requirement of federal oversight, frontier AI poses risks that neither industry nor the U.S. government is prepared to handle alone. This cannot go on. A workable federal framework lies on the table, and it is time to move it forward.



