Congress Must Act Now on AI Governance, Experts Warn, as Companies Face Compliance Chaos
Congress needs to pass a comprehensive federal AI governance law that establishes clear standards, mandatory third-party audits, and international coordination, according to policy experts at Brookings. Without swift legislative action, American companies face a patchwork of conflicting regulations, and public trust in AI continues to erode.
Why Is Federal AI Legislation Becoming Urgent?
Political leaders and industry executives have been oscillating between two extremes: aggressive government promotion of AI technology on one hand, and exclusively industry-led self-regulation or strict pre-market approval requirements on the other. This volatility leaves companies uncertain about compliance obligations and creates a fragmented regulatory landscape that hampers innovation while failing to adequately protect the public.
The stakes are high. At a recent G7 summit in Évian, France, heads of state from the world's leading democracies sat alongside chief executives of major AI companies to discuss governance frameworks. This shift reflects how consequential AI regulation has become to global stability and economic competitiveness.
Technology companies launching AI systems face immediate practical challenges. A startup deploying an AI tool on the Spanish market, for example, may struggle to answer basic questions: What role does the company hold under the AI Act? Is the system classified as high-risk? What data was used to train the model? Who is liable if the system makes an incorrect decision?. These gaps create legal exposure and slow product launches.
What Should a Federal AI Governance Framework Include?
Experts propose a governance model based on four core principles. First, any regulatory framework should aspire to be international in scope, ensuring consistency across markets. Second, human-centered decision-making must remain central to accountability. Third, civil society voices, creators, users, and those affected by AI should have representation in rule-making. Finally, policymakers can learn from governance models in other sectors, such as finance and accounting.
The bipartisan Great American AI Act, a discussion draft by Representatives Jay Obernolte (R-California) and Lori Trahan (D-Massachusetts), offers a concrete starting point. It correctly identifies mandatory third-party audits as the baseline for responsible frontier AI development. This requirement is already becoming the state-level standard; Illinois recently enacted the first mandatory annual third-party auditing requirement for large-scale AI models, following legislative models in California and New York.
How Should Companies Prepare for New AI Regulations?
- Conduct a Role Assessment: Determine whether your company acts as a provider (developing and marketing an AI system), deployer (using AI in professional activities), integrator (embedding third-party AI into your own product), or distributor (marketing another provider's system). Obligations vary significantly by role.
- Classify Your System by Risk Level: The AI Act distinguishes between unacceptable risk (prohibited), high-risk (subject to strict requirements), transparency risk (requiring user disclosure), and minimal or low risk (basic governance needed). Classification depends on what the system does, which sector it operates in, and who it affects.
- Document Data and Testing Thoroughly: Companies must be able to account for training data sources, model testing, error logs, system changes, and controls. This traceability is essential for compliance and liability protection.
- Review Contracts with Clients and Suppliers: Ensure agreements clearly allocate responsibilities, define data use rights, specify audit rights, and establish limitations of liability. Ambiguous contracts create disputes when AI systems fail or cause harm.
- Don't Wait for Perfect Regulation: Aviation policy experts advise companies not to delay compliance efforts while waiting for comprehensive federal frameworks. Instead, organizations should look to established safety assurance procedures, such as those used by the Federal Aviation Administration (FAA), which already provide guidance on risk management and accountability measures.
A critical structural issue complicates current proposals. The House draft relies on a "developer versus deployer" distinction to avoid preemption conflicts, but this distinction fails to capture modern tech industry reality. OpenAI, Anthropic, and Google act as both developers and deployers simultaneously. The distinction creates a loophole that invites regulatory evasion, allowing companies to pass accountability between entities. Federal law should instead dictate that whoever provides the AI model to the public is covered by the regulatory framework, eliminating this loophole.
What Specific Risks Should Regulation Target?
Rather than attempting to regulate all AI applications, experts recommend focusing initially on significant "material" risks that can be clearly articulated and measured. These include cybersecurity threats (AI-facilitated cyberwarfare, critical infrastructure disruption, large-scale data breaches), biological risks (synthesis of novel viral pathogens or bioweapon design), and loss of control (AI systems taking harmful autonomous action without meaningful human oversight).
High-risk systems warrant particular scrutiny. AI used in recruitment and hiring may cause employment discrimination. AI for employee performance evaluation impacts working conditions. AI for credit scoring affects financial access. AI in healthcare, education, and essential services can harm vulnerable populations. These applications require risk management, documentation, human oversight, data governance, audit logs, and cybersecurity measures before deployment.
"Congress should seek to deter bad actors by using responsible parties to set standards, created by both industry and civil society, requiring audits from certified independent external groups, and providing for serious criminal and civil penalties for material non-compliance," stated David Beier and Mark MacCarthy of Brookings.
David Beier, Managing Director at Bay City Capital, and Mark MacCarthy, Nonresident Senior Fellow at Brookings
How Can Export Controls Be Aligned With Domestic Regulation?
A major gap exists between domestic AI governance and export control authority. The current administration retains unfettered, opaque export control power that operates independently of any federal AI framework. If the executive branch can bypass statutory law to issue arbitrary enforcement letters, it will inevitably circumvent new federal regulations to pursue short-term objectives.
To ensure success, Congress must mandate specific modifications to export control application. Export control authority should not operate as a "black box" parallel to AI governance; it must be reconciled with it. Without statutory guardrails binding executive branch export directives to the same standards as the broader regulatory regime, the industry will remain in perpetual instability.
The ultimate objective must be rejecting volatile, ad hoc, executive-led decision-making in favor of clear, congressionally enacted laws. Rather than attempting a sweeping, all-or-nothing approach to federal preemption, Congress should pursue a highly targeted preemption strategy that occupies the field exclusively where national security is paramount while leaving traditional legal frameworks and state consumer protection laws intact.
Many Americans currently do not trust AI, and only swift legislative action by Congress can restore that trust and allow American technology to flourish globally. The window for proactive governance is narrowing as AI capabilities advance and regulatory fragmentation increases.
" }