FRONTIER Act Would Put Major AI Developers Under Federal Oversight

The bill would require risk plans, outside audits and incident reporting, while allowing the Commerce Department to restrict models posing an imminent catastrophic risk.

 

The bipartisan FRONTIER Act would require major AI developers to publish risk-management plans, undergo annual audits and report serious safety incidents to the Commerce Department.

Rep. Jay Obernolte (R-Calif.) introduced H.R. 9925 on July 23 with Reps. Lori Trahan (D-Mass.), Erin Houchin (R-Ind.), Scott Peters (D-Calif.), Scott Franklin (R-Fla.) and Suhas Subramanyam (D-Va.).

The House referred the bill to the Energy and Commerce and Science, Space, and Technology committees.

 

The larger the developer, the more the oversight

The bill would divide covered developers into three tiers. The lowest tier would require model disclosures and safety-incident reporting. A middle tier for larger developers would add public risk plans and annual audits. The highest tier, reserved for the largest developers, would add continuous outside review and reports at least every six months. Developers in each higher tier would also have to meet the requirements of the tiers below it.

All covered developers would disclose model details and report safety incidents

The lowest tier would cover developers of foundation models trained using more than 1026 computational operations. The bill uses that threshold to define a “frontier model,” counting the original training run and later work such as fine-tuning or reinforcement learning.

These developers would have to publish a report before or when releasing a new or substantially modified model. The report would describe the model’s capabilities, intended uses, restrictions, and safety testing.

They would also have to report critical safety incidents to the Commerce Department within 72 hours. Incidents presenting an imminent risk of death or serious injury would have to be reported to law enforcement within 24 hours.

The middle tier adds annual audits

The second tier would apply to developers and their affiliates that generated more than $50 million in gross revenue and spent at least $1 billion on AI development during the previous 36 months.

These companies would have to publish a plan explaining how they test and manage catastrophic risks, protect nonpublic model files, respond to safety incidents, and assess risks before deploying a model externally or using it within the company.

They would have to review the plan at least annually and hire a third party to audit their compliance every year. A summary and redacted version of the audit report would be made public.

These developers would also have to confidentially submit summaries of any assessments that identify catastrophic risks from their internal use of frontier models.

The reports would be due at least once every three months unless the developer and Commerce Department agreed to another schedule.

Large-scale, frontier developers would be subject to ongoing review

The highest tier would cover developers and their affiliates with more than $5 billion in gross revenue and at least $10 billion in AI development spending during the previous 36 months.

In addition to the other requirements, these companies would have to retain a Commerce-licensed outside organization to continuously review their safety plans, governance practices and handling of identified risks.

The outside organization would have access to internal records and assessments. It would have to issue a report at least every six months and could recommend corrective action.

If the reviewer concluded that a model posed an imminent catastrophic risk, it would have to refer the matter to the Commerce Secretary within 72 hours.

The bill generally defines catastrophic risk as a model materially contributing to a single incident causing at least 50 deaths or serious injuries, or at least $1 billion in property damage. Covered scenarios include a model helping create or release a chemical, biological, radiological or nuclear weapon; independently carrying out a cyberattack or conduct amounting to murder, assault, extortion or theft; or escaping the control of its developer or user.

Violations could bring penalties of $1 million per day

Developers that violate the bill’s transparency, audit, or reporting requirements could face civil penalties of up to $1 million for each violation. Each day that a violation continued would count as a separate violation.

Commerce could restrict dangerous models

The Commerce secretary could suspend or restrict the development, release, or internal use of a model found to present an imminent catastrophic risk.

A provisional order could remain in effect for up to 45 days. A final order would last up to 90 days and could be renewed following a new risk determination.

Violating an emergency order could bring civil penalties of up to $10 million per violation for each day it continues. Willful violations could also result in criminal penalties.

Bill would limit overlapping state requirements

The FRONTIER Act would prevent states from imposing separate requirements on AI developers covering catastrophic-risk disclosures, outside audits and safety-incident reporting.

States could continue to enforce generally applicable laws and regulate how businesses and other users deploy AI. The bill would also preserve state rules protecting minors and governing state procurement and use of AI.

 

The bill remains before its two assigned House committees. Committee consideration would be the next step in the legislative process.