Logo
FrontierNews.ai

Why AI Governance Is Fracturing Across America: Congress Faces a Critical Choice

Congress faces a critical decision: establish a unified federal AI governance framework now, or watch the strictest state regulations become the de facto national standard by default. As of March 2026, states have introduced more than 1,500 AI-related bills, with laws now covering not just specific use cases but how frontier AI models should be developed and deployed across the country.

What's Driving the State-Level AI Regulation Explosion?

The regulatory vacuum at the federal level has created an urgent problem. Colorado became the first state to enact comprehensive legislation regulating high-risk AI, though lawmakers substantially revised the measure before passage and later delayed its implementation. California followed with SB 53, and New York introduced the RAISE Act, both establishing frontier-model transparency, safety, and incident-reporting requirements. Illinois then passed SB 315 in July 2026, requiring annual third-party compliance audits, expanding developer responsibilities further than New York or California.

The patchwork is growing more complex. A Massachusetts Senate proposal goes even further by combining annual audits with independent catastrophic-risk evaluations at least every 120 days. These diverging approaches reveal little consensus about what baseline AI oversight should look like, creating compliance headaches for companies operating across multiple states.

Why Federal Preemption Alone Won't Solve the Problem?

The conventional argument for federal preemption rests on the threat of a state-law "patchwork," but this reasoning misses the reality of how AI models actually work. Foundation-model developers are unlikely to maintain fifty state-specific versions of the same system. Instead, the strictest state requirements may shape a single nationwide model, even as companies remain subject to divergent legal obligations across states.

The stronger case for federal action is that AI is inherently interstate, many of the nation's most durable technology rules have come from Congress, and Congress is uniquely positioned to harmonize emerging state approaches into a coherent national framework. Congress has reconciled comparable challenges before through laws such as Section 230, COPPA (Children's Online Privacy Protection Act), and the Stored Communications Act.

However, federal preemption cannot be an end in itself. A law that merely prevents states from acting would eliminate safeguards without addressing the risks that prompted state action in the first place. A durable and legally sound approach requires Congress to regulate private actors directly through robust federal protections while preserving state authority to address localized harms where federal protections are absent.

What Should a Federal AI Framework Actually Include?

The Chamber of Progress has released a comprehensive playbook proposing a federal framework built on three core pillars designed to balance innovation with safety:

  • Safety and Accountability: Establish rules for prohibited and high-risk uses, require human accountability for consequential decisions, strengthen protections for children, and address cybersecurity, privacy, and systemic risks.
  • Verifiable Compliance: Create risk-based evaluation, documentation, disclosure, incident reporting, and independent audit requirements supported by consistent federal standards.
  • Responsible Innovation: Invest in secure compute infrastructure, governed data environments, AI research, and controlled testing pathways that broaden participation in the AI ecosystem.

To implement these pillars, the playbook calls on Congress to establish federal leadership over frontier-model development, match requirements to risk, coordinate existing sectoral regulators, and target AI-enabled misconduct rather than the technology itself.

How Can Congress Build a Federal AI Standard Before Preemption?

The playbook outlines four legislative actions that must come first:

  • Leadership Over Frontier-Model Development: Congress should establish clear federal authority over how advanced AI models are built and deployed, preventing a race to the bottom where companies simply follow the strictest state rule.
  • Risk-Matched Requirements: Different AI systems pose different risks. Requirements should scale with the potential for harm, not apply uniformly to all AI development.
  • Coordinated Sectoral Regulators: Existing agencies like the FDA, FTC, and SEC already oversee specific industries. Congress should update and coordinate these agencies rather than create entirely new bureaucracies.
  • Enforcement Against AI-Enabled Misconduct: Target harmful conduct enabled by AI, such as fraud and impersonation scams, using laws the country already has rather than creating new regulatory categories.

Targeted federal proposals are already drafted on AI-enabled fraud, standardized model disclosures, impersonation scams, and sector-specific governance, each reaching harmful conduct through existing legal frameworks.

What Happens If Congress Continues to Delay?

The stakes are high. Experience with the European Union's General Data Protection Regulation (GDPR) suggests that companies operating across multiple jurisdictions ultimately standardize their practices around the most restrictive applicable rule rather than maintain separate compliance systems for every region. If Congress does not act, the same dynamic will play out across America, with the strictest state requirements becoming the national standard by default, but without the democratic debate and deliberation that should accompany such consequential policy.

States have acted because Congress has not, and their work provides valuable models for what federal legislation could look like. But the choice is not between federal inaction and indiscriminate preemption. It is between allowing national standards to emerge indirectly through individual state decisions and having Congress establish them deliberately through democratic debate. Preemption should follow from a strong federal framework, not substitute for one.

Why Gender-Based Violence Demands Urgent Attention in AI Governance?

While federal and state lawmakers debate AI regulation frameworks, an emerging threat is being overlooked: tech-facilitated gender-based violence (TFGBV). This includes online harassment, cyberstalking, doxxing, non-consensual image sharing, and AI-generated sexualized content. Rapid advances in AI and digital technologies are creating new forms of abuse faster than existing regulatory, institutional, and protective mechanisms can respond.

Young women, LGBTQI+ people, activists, and women journalists are particularly exposed to these harms. Gaps in digital literacy, policy frameworks, and institutional capacity further constrain effective prevention and response. The Africa Digital Rights Fund is launching a rapid action programme in South Africa to address these challenges through research, capacity building, and policy engagement.

The programme will map the forms and drivers of TFGBV, examine the role of AI in enabling and intensifying online harms including deepfakes and automated harassment, assess regulatory and AI governance gaps, identify vulnerable groups, and develop actionable recommendations for policymakers, platforms, civil society, and other institutional actors. This work highlights a critical gap in current AI governance discussions: the need for gender-responsive approaches to digital safety and AI ethics.

As Congress deliberates over federal AI standards, the window for action is narrowing. States will continue passing laws to fill the regulatory void, and the most restrictive requirements may become de facto national standards without congressional debate. The challenge ahead is not choosing between federal action and state innovation, but ensuring that federal action comes first, is robust and comprehensive, and addresses not only the risks that prompted state action but also emerging harms like gender-based violence that current governance frameworks have largely ignored.