The proposal would require covered companies to meet federal safety standards, undergo government reviews, and report how they automate AI research.
Key Takeaways
- The proposal would require AI developers that meet both training thresholds to follow federal safety standards, undergo government examinations, and file reports.
- Developers would be covered only if they have trained, or started training, a model using at least 1026 computing operations and spent at least $100 million on AI model training during the previous year.
- Senior federal officials could temporarily halt dangerous AI development or deployment, subject to expedited court review.
Americans for Responsible Innovation (ARI), a nonprofit AI policy group, proposed federal AI safety rules that would require the largest developers to follow government-set safety requirements and prove that they are meeting them.
The proposal is not legislation and would not create immediate obligations for AI companies. ARI released it as a model for federal lawmakers developing AI policy.
The plan combines three forms of oversight: federal safety standards, government examinations of developers, and confidential reports about companies using AI to automate their own research.
Proposal targets a small group of developers
ARI’s Responsible Innovation at the Frontier report would apply only to developers that meet two thresholds.
A covered developer must have trained, or started training, an AI model using at least (10^{26}) computing operations. This is a technical measure of how much computing work is used to train a model, and the report says only the largest training projects currently reach that level.
The developer must also have spent at least $100 million on AI model training during the previous year.
Both requirements would have to be met. ARI said this would initially limit the rules to a handful of well-funded developers.
The federal regulator would periodically review the computing threshold because improvements could allow companies to produce equally capable AI systems with less computing power.
Federal standards would govern company safety plans
Covered developers would have to publish safety plans that meet minimum federal standards. The plans would explain how companies test their AI models, which results require safeguards, and when they must notify federal authorities.
The plans would have to address how AI could enable major physical attacks or cyberattacks. They would also cover risks from automated AI research, large-scale manipulation, and systems operating beyond human control.
Each developer would have to name an officer responsible for maintaining and carrying out its safety plan. The federal regulator would publish the plans in a public catalog.
The government would periodically update the minimum standards using company practices, federal technical reviews, independent research, and examinations of developers. Later updates could change technical requirements, but they could not reduce the overall level of protection or allow model behavior that earlier standards prohibited.
Government would examine models and safety practices
The proposal would initially place responsibility for examining covered developers with the federal government.
Federal teams would test AI models and inspect company practices to determine whether a developer follows its published safety plan and whether that plan meets federal requirements.
Accredited private examiners could later assist if the government determined that enough qualified organizations were available. The government would continue conducting some examinations, supervising private examiners, and deciding whether a company had violated the rules.
Developers would report automated AI research
Covered developers would file confidential quarterly reports describing how they use AI systems to perform parts of their AI research and development.
The reports would measure how much of that work AI performs independently and how much receives human review.
A developer would also have to report a major increase in AI-performed research within four business days of discovering it.
The government would publish combined reports about the overall use of automated AI research without releasing protected trade secrets. Companies could face penalties for knowingly making false statements or failing to keep required records, but not for making a truthful disclosure.
Emergency orders could halt dangerous work
The proposal would give designated senior federal officials authority to temporarily stop AI development, internal use, or public release of an AI model when existing standards fail to address an immediate danger.
Officials could also order specific safeguards or recall a deployed model if it risks causing, or has caused, severe harm.
An emergency order would take effect immediately but expire after 72 hours unless the government asked a court to extend it. A court would need substantial evidence of present or imminent severe harm to uphold the order.
States could impose stronger requirements
Following a federal rule would also satisfy a state rule only when both address the same activity and the federal rule is at least as strict.
States could keep other AI laws and adopt stricter rules. Developers that meet the federal requirements could still be sued under state law.
The proposed federal rules would end after nine years unless Congress renewed them.
ARI said it wants lawmakers to translate the proposal into legislation. The specific requirements, agencies, penalties, and enforcement powers would ultimately depend on any bill introduced and passed by Congress.

