Safe harbors, affirmative defenses, and the half-statute: the inoculation pattern in AI law

A pattern is now visible across enacted and proposed AI legislation, and this page names it before it is used against this project: the half-statute — a law that adopts the form of frontier-AI accountability (risk frameworks, disclosures, reporting, even this Act’s own public-domain vocabulary) while omitting its central element, and then functions in debate as the reason no fuller statute is needed. “We already have an AI law.”

The mechanism has three working parts, and each now has enacted or introduced examples. The primary texts are queued for the shelf under the census’s verify-first rule; until they land, every row below is carried on the cited reporting and official summaries, graded accordingly.

Compliance as a defense — the framework safe harbor

Texas — TRAIGA (H.B. 149, effective 1 January 2026). ⚠ Per TechPolicy.Press’s analysis, the act gives developers and deployers an affirmative defense for having “substantially complied” with the NIST AI Risk Management Framework “or a similarly recognized risk-management framework”; a 60-day cure period before enforcement; a further defense where the violation was “discovered through various mechanisms, like user feedback”; a regulatory sandbox; and exclusive attorney-general enforcement. No provision reaches an individual officer.

Colorado — SB 24-205 (approved 17 May 2024; core duties delayed to **30 June 2026 by SB 25B-004, signed — the delay bill and its fiscal note now in hand).** ⚠ (the defense description below remains per the official bill summary) Per the General Assembly’s official bill summary: an affirmative defense for compliance with “a nationally or internationally recognized risk management framework” the act or the attorney general designates; exclusive attorney-general enforcement; violations are civil deceptive-trade practices. Obligations attach to developers, deployers, and entities — not to any individual natural person or officer.

Now put those beside the ask made to Congress under oath in September 2025: a “tech-neutral, preemptive … risk based” federal framework that “removes liability for companies that are compliant” (why the disparity). The framework-safe-harbor design is that ask, enacted at state scale: the duty is converted into the immunity. Follow the checklist and the checklist answers for you.

This Act’s position, stated so it can be attacked — and stated precisely, because the Act makes a version of this design choice itself. Under its standards section, documented conformity with the standards applicable at the time — three enacted state frontier-duty statutes adopted as frozen interim standards, then Agency-promulgated ones — satisfies the duty of due care as to the matters conformed. That is deliberate: fair notice requires that a person who did what the published standard required be able to prove it. The difference from the framework affirmative defense is everything around that sentence. The measuring stick is chosen by the enacting state and frozen — not “a similarly recognized risk-management framework” of the defendant’s own selection. The satisfaction is scoped to the matters conformed — the certification, incident-reporting, and records duties stand untouched. And the defendant’s own framework, “standing alone,” is by the Act’s express terms “evidence neither of due care nor of its absence.” Park is the precedent for the residue: the question was never whether Acme Markets had a sanitation program on paper; it was whether the man with authority used it. The difference between a defense and a duty is who chose the stick and what it measures — a statute that lets the defendant choose, and makes the paper conclusive of everything, has repealed the question.

The waiver route — sandboxes

The federal SANDBOX Act (Sen. Cruz, introduced 10 September 2025). ⚠ Per TechPolicy.Press: AI developers may seek waivers of federal regulations to “test, experiment with, or temporarily offer” AI products — two years per waiver, renewable four times, a possible decade of waiver, administered through OSTP. And yet note what its own framing concedes: participants “are not immune to civil or criminal liability,” and “people creating or using AI still have to follow the same laws as everyone else.”

Utah’s AI Policy Act (2024, since narrowed). ⚠ The first-mover state framework: disclosure duties plus a learning laboratory in which participants can negotiate regulatory mitigation — reduced exposure in exchange for supervised testing. Primary text on the retrieval list; characterization held to the reporting until it lands.

The sandbox is the honest half-statute: it says openly that the regulator will stand back. What it cannot do — what the SANDBOX Act’s own sponsors say it does not do — is waive the general criminal law. Which is the second time the deregulatory side has made that concession on the record: asked to explain the proposed ten-year state moratorium at the June 2025 Oversight hearing, its defending witness testified that “laws of general applicability are not to be covered by this, also criminal activity not covered” (Serial 119-31, read in full; the dossier’s federalism file). The lane this Act occupies — a state criminal public-welfare statute of general form — is the lane the inoculating instruments themselves keep leaving open.

The ceiling variant — preemption with a federal half-statute

The pattern’s maximal form runs through Washington, and its instruments arrived in sequence: the sworn ask (a “preemptive” framework that “removes liability for companies that are compliant” — September 2025, why the disparity); the ten-year state moratorium (fought and rejected — the fight recorded from inside the majority at dossier § 5.3); the executive order of 11 December 2025 (“Ensuring a National Policy Framework for Artificial Intelligence” ⚠ — a litigation task force against state AI laws, federal broadband funding conditioned on states avoiding “onerous” AI statutes; the order whose litigation the watch already tracks); the TRUMP AMERICA AI Act (Sen. Blackburn ⚠ — federal preemption of state frontier catastrophic-risk law in exchange for an FTC-enforced duty of care, DHS reporting, and even private litigation, while its § 24, per the section-by-section summary now in hand: “The Act does not preempt any generally applicable law, including a body of common law”); and the Great American AI Act discussion draft (Obernolte–Trahan, 4 June 2026 ⚠ — a three-year preemption of state regulation of frontier development only, deployment expressly left to the states, with third-party “Independent Verification Organizations” — the certify-the-inspector instinct the census already documents).

Read the sequence as a negotiation and its direction is unmistakable: ten years shrank to three; everything shrank to development-only; and every ceiling instrument writes the same exemption. The moratorium’s own defending witness: “laws of general applicability are not to be covered by this, also criminal activity not covered.” The SANDBOX framing: “people creating or using AI still have to follow the same laws as everyone else.” The Blackburn bill, its § 24, per the section-by-section summary now in hand: “The Act does not preempt any generally applicable law, including a body of common law”. Three instruments, three drafting teams, one carve-out — and a state criminal public-welfare statute of general form is precisely what sits inside it. The executive’s own roadmap now writes a fourth reservation from its side of the government: the Action Plan arms a funding lever against “burdensome” state AI law in the same paragraph that says the federal government “should also not interfere with states’ rights to pass prudent laws that are not unduly restrictive to innovation” (two visions, which owns the quotes). The ceiling keeps being built around this Act’s lane, never over it.

Hardening note (24 Aug, evening — the primaries arrived): EO 14365, signed 11 December 2025, in hand — § 3 establishes the task force “whose sole responsibility shall be to challenge State AI laws,” § 5(a) makes “onerous” states “ineligible for non-deployment funds”; the SANDBOX text in hand — § 702(i): two-year waivers renewable to ten, § 702(k)(1): “No existing right of action of a consumer … may be waived”; the Blackburn section-by-section in hand (its § 24 as conformed above; bill text queued); the GAAIA draft in hand — §§ 121(b)–(d) as the census now quotes, and every Title I signature the draft requires is the IVO audit partner’s (§ 112(e)(8)). The ⚠ marks in this section retire wherever the primary now speaks.

The counter-example a state has enacted — Connecticut inverts the pattern

The inoculation pattern is a choice, and it may be that one legislature has made the opposite one.

This paragraph rested on a bill that did not become law, and the argument in it is withdrawn pending retrieval of the enacted text. It asserted that Connecticut’s P.A. 26-15 had been “read in full” and cited two provisions — § 33(e) and § 13(b)(1) — for the proposition that Connecticut legislated against the framework defense. The enacted 2026 act is not held by this project, and those section numbers were taken from 2025’s S.B. 2, a bill that did not pass. So the pincites cannot be relied on. Where the quoted words themselves came from is unestablished — they may be from the enacted act carrying wrong section numbers, from the failed bill, or from a summary of either, and this project has not opened the document that would settle it. Nothing here should be read as a finding that Connecticut did or did not legislate against the framework defense. See FACT-15 and DOC-9 in the worklist.

What is confirmed is the fate of the earlier bill: 2025’s S.B. 2, which carried a true NIST-framework affirmative defense on the TRAIGA pattern, died in chamber — confirmed against the General Assembly’s own bill history. That much stands, and it is the only part of this paragraph that does. The pattern this page documents is a drafting choice, not an inevitability — and CURE 20 is this Act’s version of Connecticut’s answer.

The occupancy argument — “this field is taken”

The finished form of the pattern is rhetorical, not doctrinal: once a framework-defense statute exists, every fuller bill is answered with already regulated. California’s SB 53 and New York’s RAISE Act — transparency architectures, civil penalties, entity duties, no officer reach (the census, both read in full) — already do this work in debate, cited as proof the frontier is governed. The census exists to make that argument checkable, and its tally is the answer: of every frontier bill read to date, the number reaching a natural person as an officer of a developer is zero.

The precedent the safe harbor forgets — certified systems, false accusations

Every compliance-as-defense design assumes the certified system is the safe one. The record the June 2025 Oversight hearing assembled points the other way (Serial 119-31, read in full; all three examples below are cited as they were given from the witness table and the dais). The UK’s Horizon software “flagged hundreds of instances of fraud that was not real, costing people their jobs. There were suicides.” Michigan’s unemployment system produced fraud findings so wrong the state “had to refund $21 million to residents who were wrongfully accused.” A tenant- screening system “was accused of violating the Fair Housing Act because their AI algorithm disproportionately scored Black and Hispanic renters lower.” In each case the institution held the paper — process, vendor assurances, an audited system — and the paper was wrong at machine pace. As the hearing’s witness put it: humans make these mistakes too, “we just make them slower.”

A framework affirmative defense, applied to that record, would have armoured the accuser, not the accused. The Act’s design takes the opposite lesson twice over: the record duties (SEC. 12) exist so that the system’s state can contradict the institution’s narrative, and the duty sits on a person precisely so that “the human who puts their name to it” — the hearing’s phrase — answers when the certified system was certified wrongly.

The officer test — how to read any AI law in five minutes

Run the census’s word test on any statute or bill offered as the reason nothing more is needed. Search the text for: natural person · individual · officer · director · personally · certify · imprisonment · misdemeanor · felony. Then ask three questions. Who, by name or by office, owed the duty? Can that duty be delegated away? What happens to that person — not the entity — when it is breached? A statute that answers nobody, yes, and nothing is a half-statute, whatever its title says. The method, with completed worked examples: the frontier bill census.

The affirmative frame — personal liability as trust infrastructure

The half-statute is usually sold as pro-industry. Here is what the industry actually needs, on its own record. The June 2025 hearing’s industry-side witness: careless AI use “does not just imperil the goals of the AI project, it undermines the trust in the technology itself.” The dais, same day: “If we want the public to trust the Federal Government, then we must have transparency.” And the summer’s defining incident taught the public exactly what a trust vacuum looks like: the victim disclosed first, while the developer said nothing (known objections). Meanwhile the one company that held safety terms at real cost was punished for it by its largest customer — proof that under current arrangements a safety commitment is a bargainable contract term, revocable under pressure (the dossier).

Every earlier industry that faced this problem bought its way out with the same purchase: a named human being, personally answerable. Food and drug law did it in 1943 and the public eats without testing its own groceries. Financial reporting did it in 2002 — a chief executive’s personal certification on pain of felony, 18 U.S.C. § 1350 — and capital markets resumed believing audited statements. SEC. 8 of this Act is built expressly on that § 1350 structure: the certification is the trust instrument, and the person signing it is the reason it works. Personal liability is not the industry’s punishment. It is the industry’s missing trust infrastructure — the mechanism that converts “trust us” from a request into a system, makes a safety commitment non-bargainable because it is a legal floor, and gives every honest officer something no framework badge can give: a reason for the public to believe them that does not depend on taking their word for it. The half-statute offers the industry immunity it will pay for in permanent suspicion. The whole statute offers it the only commodity it cannot manufacture: a public entitled to believe what it is told.

In one line each

Does the Colorado AI Act create individual liability? No — its duties attach to developers, deployers, and entities, not to any natural person, and enforcement is civil and exclusive to the attorney general (⚠ official summary; primary queued). Does Texas TRAIGA have a safe harbor? An affirmative defense for substantial compliance with NIST’s framework or a similar one, plus a 60-day cure period and a sandbox (⚠ reporting; primary queued). Does any enacted American AI law reach a company officer personally? None found to date — the census tally of bills read in full stands at zero. Is regulatory compliance a defense to a public-welfare crime? Traditionally it is evidence of care, weighed — not an immunity that extinguishes the duty; that allocation is Park’s, and it is this Act’s.

If a legislature enacts part of this Act

This text is public domain under CC0. Anything here may be taken, in whole or in part, without permission or attribution — including by a drafter who wants the vocabulary without the duty. That is the license working as intended, and partial adoption honestly labeled would be progress. What this page pre-empts is the claim that the part is the whole. The central elements, published in advance so any borrowing can be measured against them:

  1. A natural person with final material authority, identified before the activity begins (SEC. 4) — not an entity, not a committee, not a compliance function.
  2. Non-delegation (SEC. 4(c)) — no officer, auditor, subsidiary, or framework shields the person who retained authority.
  3. The criminal floor — a due-care public-welfare offense (SEC. 6), not a civil schedule the balance sheet absorbs.
  4. Certification by a person (SEC. 8) — a name on the record, on the Park model, with lying in the certification as the offense.
  5. Records that outlive the narrative (SEC. 12) — kept because attribution, enforcement, and history all run on them.

A bill that adopts this Act’s definitions, thresholds, reporting clocks, and framework language while omitting these five has not enacted a version of this Act. It has enacted an exhibit for the census — and this page is the pre-filed answer to the argument it will one day be used to make.


The sworn version of the ask this page answers: why the disparity. The tally that keeps the score: the census. The objections register, including the one your AI assistant will raise: known objections. Primary texts of TRAIGA, SB 24-205 (and its delay amendment), the SANDBOX Act, Utah’s learning laboratory, the TRUMP AMERICA AI Act, the Great American AI Act discussion draft, and the Federal Register text of the 11 December 2025 order (number to be confirmed against the register): on the retrieval list; rows harden when they land.


Addendum, 25 August 2026 — the same campaign, conducted as trade policy ⚠

The ceiling instruments catalogued above are domestic. The Lancet reports the same pressure applied to a foreign legislature that had already legislated (Paul Webster, “Europe’s medical AI reforms,” 2026; in the project’s source library, read in full). The escalation is dated precisely:

“in November, 2025, when US Commerce Secretary Howard Lutnick tied US steel tariffs to a ‘recalibration’ by the EU of the bloc’s digital regulations, the issue reached a crisis level.”

A quoted health-law academic describes the consequence for medical AI systems, that they would “no longer be subject to meaningful high-risk obligations,” creating “a serious regulatory gap with real risks for patients.” The European Commission’s answer is quoted in the same report: “the EU’s legislation is not up for negotiation. This remains absolutely unchanged.”

What this is and is not evidence of. It has no bearing on United States preemption doctrine, and nothing in this section’s federalism analysis rests on it. What it is evidence of is the campaign’s character and reach: the instruments described elsewhere on this page are one jurisdiction’s expression of a strategy that has also been pursued through tariffs against a jurisdiction that had already enacted. A reader assessing how durable the general-applicability carve-out is should weigh that. Graded ⚠: this is named-source reporting in a journal of record, and the underlying trade and legislative instruments are not in the project’s hands.


Back to top

This page was built . The repository is the authoritative record; if this page and the repository differ, the repository is right.

Visits are counted with GoatCounter: no cookies, no personal data, nothing shared. The count is private to the maintainer.

This site uses Just the Docs, a documentation theme for Jekyll.