Skip to content
Menu
Menu

ARI Proposes Federal Safety Rules and Audits for Largest AI Developers

The proposal would require covered companies to meet federal safety standards, undergo government reviews, and report how they automate AI research.

Key Takeaways

  • The proposal would require AI developers that meet both training thresholds to follow federal safety standards, undergo government examinations, and file reports.
  • Developers would be covered only if they have trained, or started training, a model using at least 1026 computing operations and spent at least $100 million on AI model training during the previous year.
  • Senior federal officials could temporarily halt dangerous AI development or deployment, subject to expedited court review.

Americans for Responsible Innovation (ARI), a nonprofit AI policy group, proposed federal AI safety rules that would require the largest developers to follow government-set safety requirements and prove that they are meeting them.

The proposal is not legislation and would not create immediate obligations for AI companies. ARI released it as a model for federal lawmakers developing AI policy.

The plan combines three forms of oversight: federal safety standards, government examinations of developers, and confidential reports about companies using AI to automate their own research.

Proposal targets a small group of developers

ARI’s Responsible Innovation at the Frontier report would apply only to developers that meet two thresholds.

A covered developer must have trained, or started training, an AI model using at least (10^{26}) computing operations. This is a technical measure of how much computing work is used to train a model, and the report says only the largest training projects currently reach that level.

The developer must also have spent at least $100 million on AI model training during the previous year.

Both requirements would have to be met. ARI said this would initially limit the rules to a handful of well-funded developers.

The federal regulator would periodically review the computing threshold because improvements could allow companies to produce equally capable AI systems with less computing power.

Federal standards would govern company safety plans

Covered developers would have to publish safety plans that meet minimum federal standards. The plans would explain how companies test their AI models, which results require safeguards, and when they must notify federal authorities.

The plans would have to address how AI could enable major physical attacks or cyberattacks. They would also cover risks from automated AI research, large-scale manipulation, and systems operating beyond human control.

Each developer would have to name an officer responsible for maintaining and carrying out its safety plan. The federal regulator would publish the plans in a public catalog.

The government would periodically update the minimum standards using company practices, federal technical reviews, independent research, and examinations of developers. Later updates could change technical requirements, but they could not reduce the overall level of protection or allow model behavior that earlier standards prohibited.

Government would examine models and safety practices

The proposal would initially place responsibility for examining covered developers with the federal government.

Federal teams would test AI models and inspect company practices to determine whether a developer follows its published safety plan and whether that plan meets federal requirements.

Accredited private examiners could later assist if the government determined that enough qualified organizations were available. The government would continue conducting some examinations, supervising private examiners, and deciding whether a company had violated the rules.

Developers would report automated AI research

Covered developers would file confidential quarterly reports describing how they use AI systems to perform parts of their AI research and development.

The reports would measure how much of that work AI performs independently and how much receives human review.

A developer would also have to report a major increase in AI-performed research within four business days of discovering it.

The government would publish combined reports about the overall use of automated AI research without releasing protected trade secrets. Companies could face penalties for knowingly making false statements or failing to keep required records, but not for making a truthful disclosure.

Emergency orders could halt dangerous work

The proposal would give designated senior federal officials authority to temporarily stop AI development, internal use, or public release of an AI model when existing standards fail to address an immediate danger.

Officials could also order specific safeguards or recall a deployed model if it risks causing, or has caused, severe harm.

An emergency order would take effect immediately but expire after 72 hours unless the government asked a court to extend it. A court would need substantial evidence of present or imminent severe harm to uphold the order.

States could impose stronger requirements

Following a federal rule would also satisfy a state rule only when both address the same activity and the federal rule is at least as strict.

States could keep other AI laws and adopt stricter rules. Developers that meet the federal requirements could still be sued under state law.

The proposed federal rules would end after nine years unless Congress renewed them.

ARI said it wants lawmakers to translate the proposal into legislation. The specific requirements, agencies, penalties, and enforcement powers would ultimately depend on any bill introduced and passed by Congress.

Clayton Rifkind

Clayton Rifkind is the Founder and Senior Editor of AI Risk Today. He also advises on business development for ESG Today, a leading source of ESG investment news and research for institutional investors and corporate leaders. He has 20+ years of experience in B2B technology, leading strategy and execution of go-to-market plans across software, enterprise platforms, and mobile applications. He founded two consultancies advising startups and Fortune 1000 companies, including Autodesk, Intel, and Microsoft. He began his career in the San Francisco advertising scene working with brands such as Hewlett-Packard, Intel, Microsoft, Symantec, and Wells Fargo. Clayton launched AI Risk Today in 2025 after two decades of watching enterprises adopt transformative technologies, and seeing how often risk, governance, and compliance considerations lagged behind. His reporting draws on primary sources including regulatory filings, court documents, and official announcements, with a focus on what AI developments mean for the executives accountable for managing them. Reach him at Reach him at [email protected] or on LinkedIn.

Essential AI Risk Intelligence

Daily insights on AI governance, regulation, and enterprise risk management. Trusted by Chief Risk Officers and compliance leaders globally.

By subscribing, you agree to receive our daily newsletter. Unsubscribe anytime.

Advertise with AI RIsk Today, Today!