At a recent G7 summit in Évian, France, the heads of state of the world’s leading democratic economies sat down alongside the chief executives of a handful of private artificial intelligence (AI) companies whose market valuations rival the GDP of most nations on Earth. This marked a profound shift in the traditional G7 agenda, which is usually dominated by trade agreements, macroeconomic stability, and pressing global conflicts. Yet at Évian, the true philosophical anchor of the summit shifted to the governance of AI—a question as consequential to the next century as the Peace of Westphalia was to the last 400 years of state sovereignty. Westphalia settled who could claim sovereign authority over territory; Évian may come to be remembered as the first international attempt by the democratic West to settle who claims sovereign authority over intelligence itself.
The path to governance
The age of AI has left political leaders switching between awe at the promise of economic progress and fear of biological weapons, cybersecurity breaches, and the loss of human autonomy. These leaders—and their industry counterparts—toggle back and forth between active government promotion of the technology and exclusively industry-led self-regulation or strict pre-market approvals before powerful new AI systems can be widely deployed.
There is a better path for AI governance based on tools adopted by advanced economies in response to previous inflection points. First, any set of rules should aspire to be international in scope. Second, the preservation of human-centered decisionmaking is central to accountability. Third, the process of formulating new rules should include representation from civil society and elevate the voices of creators, users, and those affected by AI. Finally, policymakers can learn from governance models in other sectors of the economy, including finance and accounting.
Efforts at AI governance to date have been well-intentioned but flawed. In a rush to prevent harm, initial efforts in Europe and the U.S.—such as the EU AI Act and parts of the former Biden administration’s executive order on AI—created arbitrary regulatory thresholds based purely on computing power metrics rather than actual risks. Equally, notions of exclusive industry self-regulation bordered somewhere between naïveté and hubris. Sadly, international agreements here seem years away. Thus, Congress must act first.
Congress should seek to deter bad actors by using responsible parties to set standards (created by both industry and civil society), requiring audits from certified independent, external groups, and providing for serious criminal and civil penalties for material non-compliance.
The emerging consensus: Audits and licensing
Governance must move beyond voluntary frameworks. The bipartisan Great American AI Act, a discussion draft unveiled by Reps. Jay Obernolte (R-Calif.) and Lori Trahan (D-Mass.), correctly identifies that mandatory third-party audits are the baseline for responsible frontier AI development. This requirement is rapidly becoming the state-level standard: Illinois, following the legislative models of California and New York, has enacted the first mandatory annual third-party auditing requirement for large-scale AI models.
Under this emerging regime, all frontier AI models would need a license issued by a designated government entity. This process must be predicated on mandatory audits performed by approved, independent auditing agencies based on standards established by a neutral technical agency, such as the National Institute of Standards and Technology (NIST), with robust input from all industry stakeholders, academic experts, and civil society groups. These audits should be timely and, once submitted, deemed approved after a set time (such as the scheme used in antitrust review under the Hart-Scott-Rodino Act).
Defining ‘material’ risk
The regulatory net should focus at least initially on significant “material” risks that can be clearly articulated and measured. These are defined as matters of such size, scope, replicability, or nature that they could disrupt human health, financial markets, or global health, or otherwise pose threats that cannot be easily corrected. Specifically, standardization for risk reduction should be strictly limited to:
- Cybersecurity: Risks of AI-facilitated automated cyberwarfare, critical infrastructure disruption, or large-scale data breaches.
- Biological risks: The synthesis of novel viral pathogens or misuse in bioweapon design.
- Loss of control: The risk of AI systems taking harmful autonomous action without meaningful human oversight or intervention capability.
The export control dilemma
None of these domestic regulatory advances matter, however, if the current administration retains the unfettered, opaque export control authority it used to impose a “kill switch” in the Mythos-Fable situation. If the executive branch is permitted to bypass statutory law to issue arbitrary enforcement letters, it will inevitably ignore the new federal framework to pursue its own short-term objectives.
To ensure the success of a new federal AI governance law, Congress must mandate specific modifications to the application of export controls. Export control authority should not be a “black box” that operates in parallel to AI governance; it should be reconciled with it. Without statutory guardrails that bind the executive branch’s export directives to the same standards as the broader AI regulatory regime, the industry will remain in a state of perpetual instability.
Resolving the developer-deployer distinction
The current House draft relies on a “developer vs. deployer” distinction, partly to mitigate preemption conflicts. However, such rigid statutory categories fail to capture the economic reality of modern tech firms, where the entity developing the model is frequently the exact same entity deploying it to the public. Furthermore, the difference between the core language model and the software harnesses that control access to it can be hard even for experts to disentangle.
The developer-deployer distinction is a structural loophole that invites regulatory evasion. OpenAI, Anthropic, and Google act as both developers and deployers. Rather than forcing a choice between these roles, the federal statute should simply dictate that whoever provides the AI model to the public is covered by the federal framework. This eliminates the loophole of passing accountability between entities and aligns the law with the operational reality of the AI industry.
Enacting clear rules and targeted preemption
The ultimate objective must be the rejection of volatile, ad hoc, executive-led decisionmaking in favor of clear, congressionally enacted laws. Rather than attempting a sweeping, all-or-nothing approach to federal preemption—which has previously stalled critical legislation—Congress should pursue a highly-targeted, preemption strategy.
Effective governance requires the federal government to occupy the field exclusively where national security is paramount, while leaving traditional legal frameworks and state consumer protection laws intact until Congress fully addresses federal preemption. This approach would enact absolute federal preemption over existential risks from biological weapons and cybersecurity, ensuring a unified national posture. However, it would leave the rest of the preemption debate untouched, preserving traditional state authority over consumer protection, local data privacy, and state tort laws. By trading administrative volatility for targeted legislative clarity, the administration can insulate its national security goals from operational overreach and give American tech structural certainty.
Building the coalition for reform
A predictable, public, and accountable regulatory framework serves all major stakeholders better than the administration’s current secretive, ad hoc licensing system. Enterprise leaders desire mechanisms that hold frontier AI providers liable for cybersecurity or autonomy lapses that harm customers, while premier AI companies like OpenAI and Anthropic have already shown a willingness to support structured frameworks by endorsing the recent Illinois audit law. Civil society, while still pushing for broader privacy protections, will gain a workable baseline of accountability that places clear, enforceable duties on AI model providers.
AI industry support for an improved regulatory scheme has begun coalescing around directionally similar ideas. And the administration appears ready to move forward with something like it. The singular distinction with this framework is that we believe Congress must set the policy with active participation of civil society and executive branch arbitrary actions constrained.
In today’s fractured political environment, Americans do not trust AI. Only swift legislative action by Congress can restore that trust and allow American technology to flourish.
-
Acknowledgements and disclosures
Google is a general, unrestricted donor to the Brookings Institution. The findings, interpretations, and conclusions posted in this piece are solely those of the authors and are not influenced by any donation.
The Brookings Institution is committed to quality, independence, and impact.
We are supported by a diverse array of funders. In line with our values and policies, each Brookings publication represents the sole views of its author(s).
Commentary
Congress must pass a new federal law on AI governance
July 29, 2026