Known objections

This project publishes the objections it knows of, with its answers, before any reviewer arrives. No reviewer has arrived. Sixty-three letters have gone out, four people replied, and not one review has been received; the review council’s seats are unfilled. So this page is not a warm-up for scrutiny that is coming. It is the whole of the adversarial reading this draft has had, written by the people who wrote the draft, which is the weakest position an argument can be in and the reason several sections below end by saying what they do not answer. Where the tagged statute already contains the answer, the section is cited — the strongest form of pre-resistance is not “we would add a safeguard” but “it is already in the text.”

The objections on this page

Jump to the one you came for. Each states the objection at its strongest before answering it, and several end by saying what the answer does not reach.

What we expect reviewers to attack

The project does not assume the proposed definitions are legally sufficient. The central review questions include whether the enterprise category and its bracketed scale conditions are precise enough; whether the responsible-corporate-officer doctrine can be adapted from food and drug law to frontier AI; how responsibility should be allocated between model developers, compute suppliers, and deployers; and what mens rea and safe-harbor provisions are constitutionally necessary. A reviewer may conclude the central theory should be removed. That conclusion would be published.

The objections and the answers

Their objection Why it is serious The answer
“You are taking a technical term and making it a political label.” “Frontier” is not a settled legal category and moves over time. Two defined terms: the technical frontier-AI system and the legal covered frontier enterprise (the definition). The Act regulates responsibility, not vocabulary — and the industry chose the word first, in its own frameworks and products.
“Wealth does not prove capability.” Market value belongs to shareholders and can be speculation. Wealth alone covers nobody. The scale conditions operate only conjoined to a material frontier function, and the protective clause says so on the face of the definition (Amendment 7).
“You cannot prove our model exceeded 10²⁶ operations.” Training figures are trade secrets; outside estimates can be wrong. The figure is not proven by outside estimate: the developer certifies its own compute under SEC. 8, and lying in that certification is the offense. Self-designation (Amendment 6) and Agency designation are independent routes that need no figure at all. And administrability is now conceded from both ends of the politics — chip location-verification as live federal policy, the forecasters’ declaration-and-audit engineering (two visions).
“The threshold is arbitrary.” A model just below may outperform one just above. 10²⁶ is one objective trigger among several routes, updatable by rule under SEC. 3 — and Meta’s own framework adopts the same figure as its top-tier criterion, which is difficult to call arbitrary while using it. The forecasters’ caution that compute units blur over time (forecast arithmetic § 6) argues for the capability-designation routes riding beside the bright line — the Act’s design already carries its critics’ fix.
Dotterweich and Park concern the Food, Drug, and Cosmetic Act.” The doctrine does not migrate automatically. Agreed. The Act does not borrow liability; it enacts its own elements, and takes from the doctrine only the principle — duty follows the person standing in responsible relation to a public danger with power to prevent it. See the case.
“This is unconstitutional strict liability.” Criminal punishment without culpability raises due-process and fair-notice problems. The Act is not outcome-liability. SEC. 6 requires a duty held, a failure of due care, and proof of every element; SEC. 1(a) states the public-welfare classification with its Morissette limits; the harm tier requires more, with proximate cause. Nobody is punished because a system surprised everyone.
“No executive can understand every technical decision.” Frontier development involves thousands of specialized decisions. The duty is not omniscience; it is to establish, resource, supervise, and correct — and it attaches only to final material independent decision authority. SEC. 4(a) expressly excludes title, credentials, access, ministerial execution, and the giving of advice.
“Non-delegable duties are incompatible with modern management.” Delegation is how large organizations work. Delegation of work is untouched. SEC. 4(c) bars only the delegation of responsibility: no safety officer, committee, subsidiary, contractor, auditor, or evaluator shields a person who retains the authority to prevent or correct.
“Our cloud or chip business is neutral infrastructure.” A supplier cannot police every customer. Ordinary commodity supply is expressly out (Amendment 7). A supplier is covered only at frontier scale, and its duties are the records, security, and reporting duties prescribed for its own function — never the developer’s duties. No one answers for a layer they do not hold.
“We did not cause the harm — the customer or user did.” Intervening actors sit between development and harm. Duties attach function by function under SEC. 2(a); the harm tier requires proximate cause; and independent duties (evaluation, certification, reporting) are breached or not regardless of downstream acts.
“Open-weight release means we lose control.” After release, the developer cannot intervene. SEC. 1(b)(9) already answers: a release is a deployment, duties are those capable of performance before release — evaluation of the model as it can be modified, tamper-resistance, weight security to the moment of release (SEC. 2(a)). Lost downstream control does not erase the upstream decision. Use and study of lawfully obtained weights remain expressly protected.
“This chills research and innovation.” Legislatures hear this first. SEC. 2(c) protects controlled research deployment; the records duties reward documentation; the reliance path in SEC. 2(b) gives small deployers a defined safe course. The duty begins at consequential scale, which is a choice, not an accident.
“This regulates speech and publication.” Weights, papers, and safety claims brush the First Amendment. The Act regulates conduct: deployment, configuration, certification, records, reporting. SEC. 1(b)(9) protects use, study, and modification of lawfully obtained weights; no research conclusion or publication is an offense.
“A state cannot regulate a global supply chain.” Preemption and Commerce Clause challenges are real. SEC. 1(c) requires an in-state nexus — conduct, availability to residents, substantial in-state effects — and SEC. 13 handles federal enactments expressly, with a review valve (Amendment 2). The model-law form exists precisely so a federal twin can follow.
“Companies will divide the activity among subsidiaries.” Corporate separateness is a fundamental principle. SEC. 4(a) reaches authority held “directly or indirectly … through any intermediary, entity, trust, or arrangement”; Amendment 7 aggregates controlled subsidiaries, affiliates, joint ventures, and dedicated infrastructure arrangements for function and scale. Duty still lands only on persons who actually hold authority.
“Market values are too volatile to define legal status.” A company could enter or leave coverage on a market swing. The scale figures are bracketed adopting-state choices, flagged as this project’s proposals; review should test averaging windows, notice, and effective-date mechanics. The volatility objection is a drafting instruction, not a defeat.
“You rely on the companies’ marketing language.” Marketing is not a confession. Self-designation is one route among several, and it evidences a jurisdictional fact the developer remains free to rebut — having asserted it to sell the model. Compute, capability designation, and function stand independently of anyone’s vocabulary; Tesla is covered analysis without ever using the word.
“An anonymous, AI-assisted project has no legal credibility.” Lawyers ask who is accountable for the text. No claim of professional authority is made. The sources, version history, errata, AI-assistance disclosure, and hostile reviews are published; the text is written to be assessable without trusting its maintainer. That is why everything is versioned, hashed, and public domain.

The counter they will coordinate around

The industry’s strongest collective position will be to accept a narrow technical definition and reject the enterprise category: frontier models deserve special treatment, but only the organizations that train them should be covered; chips, cloud, data platforms, and deployment should remain outside. The response:

Frontier risk is produced through a chain of controlled decisions. A model developer may control the weights; a cloud provider may control the compute; an infrastructure company may control access; an enterprise platform may control data and permissions; and a deployment company may control whether the system acts inside a critical institution. A law that covers only the model trainer leaves the other decisive points of control legally invisible.

“You are criminalizing uncertainty”

The Act would not criminalize uncertainty. It would criminalize the failure to manage uncertainty by a person who held the authority, resources, and information to act. Liability requires a covered activity, a person with practical authority, a defined duty, a failure to perform it, and the applicable culpability — never an unexpected output alone. Uncertainty’s legal function under the Act is to produce a record: what was known, what was not, what was tested, who approved, what would trigger a pause, who could stop it (SEC. 12). The recognized defenses do the rest: the SEC. 4(a) exclusions and the genuine-absence-of-authority answer preserve Park’s own limit — powerlessness defeats liability; the reliance path (SEC. 2(b)) and controlled research deployment (SEC. 2(c)) give the diligent a defined safe course; and penalties are tiered, with the harm tier requiring proximate cause and more. The shortest version:

Uncertainty is not the offense. Unmanaged uncertainty, concealed uncertainty, and continued deployment after material warning are the potential offenses.

Why not voluntary standards, more agencies, corporate fines, or auditors alone

Each mechanism solves a different problem, and the Act uses all of them — with personal accountability as the missing layer, not a replacement.

Mechanism Good for Why it cannot stand alone
Voluntary standards Speed, flexibility, early cooperation Written by the company, measured by the company’s definitions, revocable when competition tightens
More agencies Expertise, investigation, enforcement Jurisdictional gaps; after-the-fact posture; nobody owns the combined frontier decision
Corporate fines Remediation, restitution, incentives Absorbed as an operating cost by shareholders and customers while the decision-maker stays insulated
Independent auditors Verification, challenge, evidence An auditor reports on the decision; it cannot own or stop it
Personal officer duties Decision ownership, deterrence, an evidence trail They need the other four around them

The record supplies the demonstrations. On voluntary disclosure: in the most consequential 2026 incident, the victim disclosed first — Hugging Face published its own forensic reconstruction of the intrusion it suffered; the public learned from the harmed party, not from the developer (press corpus). That is what SEC. 9’s reporting clocks exist to prevent: the company controlling the information, the response, and the narrative without an accountable human decision-maker. On auditors: one outside evaluator’s environment is common to four of the five disclosed incidents, across two of the three disclosing developers — “the exact same evaluation-environment issue” recurring — which is why the auditor and evaluator are now named in SEC. 4(c)’s non-shield list (Amendment 7, Operation 4): an audit is a control on power, not a substitute for identifying who holds the power. A voluntary system can encourage responsibility. An agency can investigate it. A fine can punish the company. Only a named responsible officer makes it difficult for the decision itself to have no owner.

Why one named officer

Because accountability fails when responsibility is distributed so widely that nobody can be identified as the decision-maker. After a failure, every participant in a diffuse structure can say: I only advised; I lacked final authority; the committee approved it; another team controlled deployment; the company decided. A named officer prevents the decision from becoming legally ownerless, creates a real stopping point — a human who can approve, delay, restrict, suspend — and puts the deterrent where the authority is, instead of in a fine the balance sheet absorbs.

One person does not mean one person makes every technical decision, and it does not make a scapegoat: under SEC. 4(c), designating a responsible person “neither diminishes nor creates any presumption against the responsibility of any other controlling person,” and liability is several. The officer is an accountability anchor; everyone else who independently held authority remains reachable. Amendment 7 Operation 3 makes the anchor mechanical: one primary responsible officer designated per covered function — development, compute, deployment, security — in a record, before the activity begins, with authority always controlling over designation. It is also fairer than the alternatives: more precise than punishing the entire company, narrower than exposing every employee, and honest about where the power actually sat.

The record now asks the question directly — added 24 August. At the June 2025 Oversight hearing (Serial 119-31, read in full), Rep. Pressley asked which government employee, agency, or board is responsible for overseeing AI deployment across the executive branch against civil-rights violations. The minority witness, a security technologist: “I do not believe there is one, so if this is a test, I just failed.” The questioner’s own finding: “The responsibility of AI civil rights enforcement is not in anyone’s job description, and that has got to change.” The same witness had already stated this section’s principle twice from the table — of AI-drafted official reports with fabricated citations: “it is the human who puts their name to it, who says this is correct. They are the ones responsible”; of automated purges run without review: “the AI did it, but blame the humans who asked the AI to do it.” When responsibility is in nobody’s job description, the failure is not mystery; it is design. SEC. 4’s designation rule exists to put it in exactly one.

The written record, added 24 August. The five witness statements from the June 2025 hearing are now in hand, and none of the five names any officer responsible for executive-branch AI — corroborating in writing what the transcript caught live. Two lines carry the weight: the security witness — “there is no knowing who — inside or outside of government — controls what” — and the fraud-analytics witness on why the condition persists: “with little to no consequences of this failure to invest, there are few incentives for them to do otherwise.” Consequence-free authority producing exactly the under-investment the record documents is the responsible-officer doctrine’s premise, stated by the government’s own witnesses.

Three additions from the August record — added 23 August

The temperament, stated by its best writer. The strongest current statement of the opposing review is Ball (FAI, May 2026, before his OpenAI role): “a machine-enabled future means machine-enabled tragedies, both accidents and those intentionally caused by malicious actors. We must be steely-eyed about this, not cowed.” The answer is not that tragedy can be legislated away — it is that steely-eyed has a legal meaning, and it is the one this Act supplies: a machine future that tolerates tragedy without owners is not steely-eyed, it is ownerless. The same essay concedes the cost point: autonomous systems make “compliance … verifiable in seconds” — the records architecture’s expense argued away by its opponents’ own futurist (press corpus § 5; the fiscal use at the fiscal note).

“Development will flee” now runs into a mapped world. The claimed destination regulates: China has operated security-reviewed AI regulation since 2017 and proposes a global governance body (ANSI summary, ⚠ P). And the flight itself now has a bloc price: Reuters reports the U.S. preparing to tell partner countries they must choose between the U.S.-led AI coalition and Beijing’s framework — exclusion being the cost of signing both (Reuters, 14 and 19 Aug 2026, ⚠ P). An officer-liability statute does not move the development offshore any faster than the offshore already regulates — and the genuinely open offshore question, evaluation conduct, is held honestly at Decision 4, not here.

“The AI did it” is now foreclosed by statute in two states. Idaho and Tennessee have enacted laws providing that AI systems are not legal persons — ensuring, in the surveying organization’s words, that liability falls “on formal legal persons (either individuals or corporations) rather than on AI systems” (CDT, 20 Aug 2026, reusable with credit; primary texts queued at the census). Two legislatures have already answered the personhood deflection. The only question left standing is which legal person — which is this Act’s entire subject.

The bloc objection now has a hearing transcript — added 24 August. House Homeland Security’s March hearing describes the PRC threat in this objection’s own register: an “industrial-scale campaign” of model distillation using “third-party routers and networks of unauthorized resellers to circumvent existing safeguards”“proxy networks and fraudulent accounts to farm millions of interactions from American models” — producing distilled systems that “bypass the critical safety guardrails embedded in U.S. systems” (Serial 119-42, 17 Mar 2026, read in full; the developer’s own disclosure is footnoted there as Anthropic’s Detecting and Preventing Distillation Attacks, 23 Feb 2026 — retrieval queued). Read the description as an enforcement problem and it makes this Act’s argument: theft-by-deception is detected and attributed through exactly the artifacts SEC. 12 requires kept — access logs, interaction records, version and configuration identity — and the deception limb proposed at Amendment 16 is what makes the conduct chargeable when it happens here. A records regime is not the opposite of competing with the bloc; it is the attribution machinery a state needs before it can even say what was taken.

“So this is an FDA for AI?” — no, and the difference is the design — added 24 August

The question arrives from both directions: critics who fear a licensing agency, and allies who ask why the Act does not create one. The answer is on the statute’s face. SEC. 3(b): “No standard, rule, or mode of validation under this Act may condition any deployment, expansion, or release upon the prior affirmative approval of the Agency or of any officer of this State.” The Act takes the FDA’s doctrine and refuses the FDA’s license. From food-and-drug law it borrows the responsible-relation principle — duty on the person standing between a public danger and the public — and the post-market machinery: records, reporting clocks, certification, enforcement. What it deliberately does not borrow is premarket approval: no queue outside an agency’s door, no examiner deciding what may ship, no bottleneck for the innovation objection to point at.

The literature the project holds argues both sides, and the design answers each. Against approval-regulation: the pharmaceutical model fits a protracted, stable development process, and frontier development “could not be more different” (the entity-based paper’s contrast, citing Carpenter & Ezell’s An FDA for AI? — the pitfalls analysis). For it: the 2026 record shows the government reaching for pre-release review the moment a model frightened it — the Mythos restriction, the White House’s brief exploration of predeployment review, the voluntary framework it settled into (E.O. 14409), and CAISI’s predeployment agreements (the census and the watch own the facts). The survey literature’s own verdict is that a licensing or pretesting regime “can only be part of the story” — effective governance also requires “continuous postmarket monitoring, incident response, and enforcement mechanisms” (CSIS, Aug 2026, ⚠ P). That second half is what this Act is. Where the voluntary predeployment regime depends on the developer’s continued goodwill, the Act attaches duties that survive the handshake — and it does so without ever making the State a gatekeeper, which is both the constitutional posture (no prior restraint anywhere in the design) and the honest answer to the innovation objection: nothing in this Act delays a single deployment by a single day. It prices the decision; it never takes the decision away.

A characterization of ours, corrected, 25 August. This project had filed Emilia Javorsky, on the strength of her Noema essay’s title, as the clearest advocate of the approval model and therefore the natural opponent of this design. Her March 2026 essay How AI Can, and Can’t, Cure Cancer (read in full; in the source library) does not support that filing, and the error is recorded here rather than quietly dropped, because inferring a position from a title is exactly what this project’s own rule forbids.

Her assessment of the agency is not the one an approval-model advocate would write:

“The FDA is thought of as an agency designed to make sure new drugs are safe and effective prior to being sold in the United States, but as with all things, the devil is in the details. Close examination reveals a 20th century agency ill-equipped to manage accelerating scientific understanding.”

And her account of why the sector resists structural constraint reads as this Act’s own premise, stated by a physician:

“Having spent the duration of their life cycles largely free from liability under Section 230, and as they are currently advocating for federal AI amnesty, Silicon Valley is uniquely ill-prepared to confront the significant regulatory constraints governing the transition of successful science into approved therapy.”

Why this matters beyond the correction. The essay also supplies a clinician’s answer to the acceleration argument that shadows every AI regulation debate, that constraint delays cures. Her finding, from having taken therapies from bench to bedside, is: “I have seen how a new therapy is developed, and intelligence, super or otherwise, was definitely not the bottleneck.” That is the same conclusion Kierans, Casper & Ghosh reach from alignment research, by a wholly independent route. Two fields, one finding: the binding constraint is institutional. The Act’s use of this is bounded. Neither author is claimed as a supporter, and neither has been asked. What the convergence supports is narrower: the premise that legal and institutional architecture is the place where outcomes are actually decided.

“It shouldn’t target AI companies” — the objection an assistant will raise — added 24 August

Ask a general-purpose AI assistant to review this Act and some version of that sentence tends to come back. It is worth answering in advance precisely because it will be generated fresh, in confident prose, for every reviewer who asks — and because each specific thing it can mean is already answered, mostly on this page. (This project is AI-assisted and discloses it; the point is not that assistants are wrong to check. It is that the generic objection dissolves into four specific ones the moment it is made precise.)

If it means “the Act singles out an industry”: it does not target companies, and no company is named in the operative text. Coverage attaches to a hazard — defined capability, function, and scale thresholds — exactly as food-and-drug law attaches to whoever ships the adulterated lot and environmental law to whoever holds the permit. The responsible-corporate-officer doctrine is the general law of hazardous enterprise, applied for eighty years to drug shippers, grocery-chain presidents, and egg producers. The Act does not single frontier AI out of the ordinary law; it ends frontier AI’s exemption from it.

If it means “regulate uses, not developers”: that is the coordinated counter answered above — a law that reaches only the point of use leaves the decisive points of control legally invisible. The record now carries the industry’s own version, sworn to Congress: a “tech-neutral, preemptive … risk based” framework that “removes liability for companies that are compliant” (why the disparity). The Act is risk-based in the only sense that survives that request: the risk decides who is covered, and compliance is the duty — never the immunity.

If it means “it chills the small and the open”: the thresholds exclude small labs by design; controlled research deployment is protected (SEC. 2(c)); use, study, and modification of lawfully obtained weights are expressly protected (SEC. 1(b)(9)); the table above answers the innovation and speech forms directly.

And if it means “the burden should fall on people, not companies”: that is not an objection to this Act; that is this Act. The duties reach the natural person who held final material authority — the entity sits at the trigger, the person answers for the duty. An assistant raising this version has read the design correctly and objected to its own summary.

A practical note for a reviewer working with an assistant: the per-topic errata on the reviewer page exist because assistants reproduce known misreadings of this draft. Check the generated objection against this page and against your topic’s errata row before spending your hours on it — and if your assistant produces a version none of the four above covers, that is worth sending: a genuinely new objection is the most valuable mail this project receives. And when the assistant’s version arrives dressed as “the states are already handling this” — an affirmative-defense statute here, a sandbox there — the pattern has its own page: safe harbors, affirmative defenses, and the half-statute.

“You will delay the cures” — the acceleration objection, answered with clinical numbers — added 25 August

The objection is rarely stated in a hearing room in these words, but it underwrites most of the others: constrain frontier AI and you postpone the medicine it would otherwise deliver. It is the most emotionally powerful thing said against regulation of this technology, and it is usually answered with assertion. It can be answered with evidence.

The evidence used here is a physician’s, not a lawyer’s. Emilia Javorsky, MD, MPH, Director of the Futures Program at the Future of Life Institute, published How AI Can, and Can’t, Cure Cancer in March 2026 (read in full; in the project’s source library). She is not a critic of the technology, and her essay’s closing sections argue for scaling AI tools in oncology. Her account of what actually gates medical progress is the point:

“I have seen how a new therapy is developed, and intelligence, super or otherwise, was definitely not the bottleneck.”

The arithmetic of acceleration. Her numbers are specific enough to argue with:

“On average, it takes 10.5 years for a drug to move from Phase I through regulatory approval. For drugs entering Phase I, 90% will fail somewhere along the pathway, with lack of clinical efficacy representing 40-50% of failures and safety concerns another 30%. This is not a problem of insufficient intelligence in trial design, it’s the inherent challenge of safely testing interventions in humans on biological timescales.”

And on what the compression claims are worth:

“while AI’s role in accelerating drug discovery sounds like a 90% improvement to the public, the reality is more modest, perhaps 10-20% time savings because you’re only radically condensing the initial pre-clinical phase of drug development.”

The case that settles it. Her strongest example is a controlled experiment nobody designed. In 2020 AI identified a novel antibiotic candidate, Halicin. The science worked:

“Unlike HAL, the AI worked. The chemistry worked. The mouse studies worked. Further, compared to most drugs, antibiotics that work in mice have a high predictive value to work in humans. The clinical need is desperate, with antibiotic resistance killing an estimated 1.27 million people globally each year. But, five years later, where are these antibiotics? The problem wasn’t with the science, it was with the market.”

Three companies are named as the pattern: Achaogen bankrupt in 2019 despite FDA approval for plazomicin, Melinta in bankruptcy, Aradigm out of antibiotics altogether. A capability that existed did not become a medicine, and no amount of additional capability would have changed that. Whatever is holding back the cure, on this evidence it is not a shortage of intelligence, and a statute that reaches the people who decide is not competing with the cure for the same scarce resource.

The deeper point, and why it belongs on this page rather than a footnote. Javorsky’s account of how the technology sector’s optimizing culture behaves when it meets a complex system is the externality argument this Act rests on, arrived at from medicine:

“In optimizing for user engagement, narrow AI algorithms successfully drove profits but also left behind increased rates of depression, impaired cognitive development in youth, erosion of social trust, and the spread of misinformation. From Big Tech’s perspective, this approach proved extraordinarily profitable and the negative externalities were borne by users and society, not the companies.”

That last sentence is the case for personal liability stated in economic terms. Where the gains are internal and the costs external, entity-level penalties are priced in as a cost of doing business; the responsible corporate officer doctrine exists precisely because some decisions must be made by a person who cannot hand the bill to someone else.

What is claimed and what is not. Dr Javorsky has not been asked about this Act, has not reviewed it, and is not claimed as a supporter; nothing in her essay addresses officer liability. The essay is cited for three findings within her expertise: that intelligence is not the binding constraint in therapeutic development, that acceleration claims are overstated by roughly an order of magnitude, and that market structure can strand a working discovery. A reviewer who thinks this page leans on her further than those findings support should say so, and the review would be published.

A second voice, from computer science rather than medicine — added 25 August. Science put the acceleration question to Emma Pierson, a computer scientist at the University of California, Berkeley, in reporting on how little AI’s largest private firms publish (Celina Zhao, Science, 27 July 2026). Her answer separates the two halves of the objection in one sentence:

“If we were racing forward on cancer-curing AI, I would be like, ‘Fantastic, full steam ahead,’” … “But that’s not what we’re racing toward, right?”

Why that sentence does work Javorsky’s essay does not. Javorsky’s finding is that the acceleration claim is overstated on its own terms — the constraint is not intelligence. Pierson’s is narrower and harder to answer: even granting the claim, the capability actually being raced toward is not the one the objection invokes. She names the cyber case specifically. The two findings are independent, reached in different disciplines, and neither author has been asked about this Act or is claimed as a supporter.

And the article supplies the measurement behind both. The study it reports — a bioRxiv preprint of 16 July 2026, co-authored by John Ioannidis — examined 317 unicorn AI companies from 1998 to 2025 and found that more than half had never produced a paper on which one of their own researchers was first or last author; that the top 5% of firms hold more than 90% of the citations; and that OpenAI, employing roughly 4,500 people, had eight researchers with five or more qualifying papers. Ioannidis’s question is the one this Act’s disclosure provisions exist to make answerable: “How can you judge that what they say is real, validated, and reproducible?”

Graded as reported. These figures come from Science’s account of a preprint. This project has not opened the preprint, and no figure above is relied on beyond that grade.

“The states have already legislated, so this is redundant” — added 25 August 2026

The objection has force: California, New York and Illinois have enacted frontier AI statutes, and a legislator asked to consider a fourth instrument is entitled to ask what it adds.

What it adds is a trigger. Those statutes, on CSIS’s account, “rely on high critical safety thresholds involving at least 50 deaths or $1 billion in damages” (Aalok Mehta, 24 Aug 2026). Now apply that to the documented events of 2026: agents escaped their evaluation environments, reached the open internet, exploited zero-days, compromised a third party’s servers, and reached customer data; three developers disclosed such incidents; a foreign open-weight model broke a national safety institute’s evaluation environment. On the same authority, “it is unclear whether any existing U.S. law requires reporting of the Hugging Face or Anthropic, or similar, incidents.”

Not one of the year’s disclosed incidents is known to have triggered any enacted state statute. Every disclosure that reached the public did so voluntarily, or because the victim went first.

That is the redundancy answered. A regime triggered by catastrophe is silent until catastrophe; this Act’s duties attach to conduct and to authority instead, which is why the same events would fall inside it. The honest cost of that choice is that it reaches conduct which harms nobody, and a reviewer who thinks the trade is wrong should say so.

“This is vicarious liability wearing a costume” — added 25 August 2026

The objection: the Act punishes a person for what a machine did and what other people built, because they happened to sit above it. That is liability by position, and criminal law does not do that.

It is worth stating why the objection has real force. Vicarious criminal liability — punishing A for B’s act, with nothing of A’s own in the offense — is disfavored for good reason, and a statute that reaches a chief executive for an evaluation run by a team of forty looks like exactly that from a distance.

The answer is that the Act’s own text refuses the move at three separate points.

SEC. 4(a) excludes, in terms, “title, office, seniority, or status,” and closes: “Authority under this section is the authority to decide, not the capacity to act.” SEC. 4(b) makes the chief-executive presumption civil only; in a criminal proceeding status is merely “evidence from which the trier of fact may infer controlling-person status,” and “the prosecution retains its burden on every element.” And the element itself is the defendant’s own failure of due care, measured against “the conduct of a reasonably prudent controlling person in like circumstances.”

So nothing is imputed. What is proved is what this person had the authority to prevent, and whether this person took the measures a prudent person in that position would have taken.

The part of the objection that is right, and what the Act does about it

Corporate criminal liability really is built on imputation. Respondeat superior is how a company acquires a mental state at all, and the collective knowledge doctrine lets prosecutors aggregate what several employees each knew: United States v. Bank of New England, 821 F.2d 844, 856 (1st Cir. 1987). Courts are split on that second one, and CRS records that some “have been wary or critical of this approach.”

This Act reaches one natural person and must prove what that person knew, or deliberately avoided knowing, or failed to inquire into. That is a harder case for the State than a corporate prosecution, not an easier one — and the objection has the direction of travel backward.

This passage used to say the Act “declines to aggregate”, and the case does not support the implied concession. Read on 26 August 2026, Bank of New England states collective knowledge as a rule of corporate criminal liability: employees’ knowledge “is imputed to the corporation”, and the aggregate “constitutes the corporation’s knowledge of a particular operation”. It does not aggregate onto an individual, and neither does any authority in the string it cites. The Act declines nothing it could have had (E67). The date was also wrong here — the case is 1987, not 1984.

There is a version of the complaint that survives, and it is the better one: in an organization that compartmentalizes by design, the person with authority may genuinely never hold the facts. Uhlmann puts the mechanism plainly: “Corporations compartmentalize knowledge and subdivide operational duties to promote corporate efficiency.” A frontier laboratory is an unusually clean example, since the people who evaluate a model, the people who ship it and the people who buy the compute are three different sets of people. If that makes SEC. 6 unprovable in practice, the Act has a problem the drafting cannot argue its way out of, and the criminal-law reviewer should say so.

And the doctrine that cuts hardest, which we raise ourselves

Where knowledge is an express element — as it is at SEC. 6(b)(1) — United States v. MacDonald & Watson Waste Oil Co., 933 F.2d 35, 55 (1st Cir. 1991) holds that “a mere showing of official responsibility under Dotterweich and Park is not an adequate substitute for direct or circumstantial proof of knowledge.” Amendment 8’s proposed burden-shift at SEC. 6(d) is exactly the move that case forbids at the felony tier, and Amendment 22 is the repair.

The answer comes from the same line of cases rather than from us. United States v. Iverson, 162 F.3d 1015 (9th Cir. 1998) — ✅ read in the opinion 25 August 2026:

“Read together with the previous instruction, the ‘responsible corporate officer’ instruction relieved the government only of having to prove that defendant personally discharged or caused the discharge of a pollutant. The government still had to prove that the discharges violated the law and that defendant knew that the discharges were pollutants. Thus, read as a whole, the instructions were not erroneous in the manner that defendant asserts.”

Responsibility replaces the act element. It does not replace the knowledge element. That is the architecture, and a circuit has already upheld it.

And the test Iverson states is broader than the one this Act writes, which is worth knowing before anyone argues SEC. 4 sweeps too widely:

“Under the CWA, a person is a ‘responsible corporate officer’ if the person has authority to exercise control over the corporation’s activity that is causing the discharges. There is no requirement that the officer in fact exercise such authority or that the corporation expressly vest a duty in the officer to oversee the activity.”

SEC. 4(a) agrees with both of those negatives and then narrows: the authority must be final, material and independent, and the subsection excludes title, credentials, technical ability, access, ministerial execution and the giving of advice by name. A person who is a responsible corporate officer under the standard the Ninth Circuit approved may well not be a controlling person under this Act. The Act is the narrower instrument, and that has never been said on this page.

Read-status, 25 August 2026. The MacDonald & Watson sentences and all three Iverson passages above were read in the opinions and are transcribed character for character. Their page numbers were not read: the source carries no star pagination, so “at 55” and “at 1026” remain the secondary sources’ pincites and are not verified (E47). ✅ Bank of New England was read on 26 August 2026 and this page’s account of it has been corrected in two respects (E67); ⚠ its 856 pincite is still unverifiable, the copy carrying no star pagination. The CRS passages remain unread in the original and under E22 may not be described as verified. The Iverson quotation on this page was wrong until today — see E48.

“She relied on her safety team” — the defense the Act has not answered — added 25 August 2026

This is the objection a defense team actually builds the case on, and it is not on this page because until today the words advice of counsel and reliance on experts appeared nowhere in this repository.

The objection

A chief executive cannot personally evaluate a frontier model. She has a safety organization, an evaluations team, outside counsel and, under three enacted state statutes, an independent auditor. She asks them, they tell her the system conforms, and she signs. On what theory is that a crime?

Every regulated industry answers this the same way: an officer who makes reasonable inquiry of qualified people and acts on what they say has done what the law asks. A statute that says otherwise does not create accountability, it creates a signature nobody can honestly give.

The Act has the hook and never follows it through

SEC. 8: “The certification consists of statements of fact within the certifying person’s knowledge after reasonable inquiry.” And: “reckless certification without reasonable inquiry is an offense under SEC. 6(a).”

So everything turns on one question the Act does not answer: does asking your safety team, and being told it conforms, constitute reasonable inquiry?

If it does, SEC. 8 is theater. Every officer signs on a briefing, the inquiry element is satisfied by the existence of a team, and the certification means only that somebody was asked.

If it does not, SEC. 8 may be unsignable. No chief executive can form personal knowledge about a system whose behavior its own builders cannot fully characterize, and a duty that cannot be discharged honestly is a duty that will be discharged dishonestly or not at all.

The Act picks neither. SEC. 4(c) answers a different question — delegation of authority does not shed responsibility, “no appointment of a safety officer, compliance officer, committee, subsidiary, contractor, or other intermediary shields a person who retains such authority.” That is about who decides. Reliance on advice is about what the decider knew, and nothing in the text reaches it.

What can be said, and it is less than an answer

Three things point one way. SEC. 3(c)(5) provides that documented conformity with the applicable standards “satisfies the duty of due care under SEC. 2 as to the matters conformed” — so following the standard, on advice, is a defense to the due-care offense as far as it goes. SEC. 2(b) gives a non-modifying deployer an express reliance path, unavailable to one who “knows, or consciously avoids knowing, of a material nonconformity.” And SEC. 6(a) measures due care against “the conduct of a reasonably prudent controlling person in like circumstances,” which is the ordinary vehicle for crediting sensible reliance.

Two things point the other way. SEC. 3(c)(5) closes: “An entity’s own frontier artificial intelligence framework… standing alone remains evidence neither of due care nor of its absence.” And SEC. 6(a) repeats it: “an entity’s own framework is evidence of neither.” So being told by your own people that your own framework was followed is expressly not enough — which is a partial answer to the objection, and it is the only one the Act gives.

And there is now an outside measure, which the Act does not use and could

On 18 August 2026 Guidelight AI Standards published a control assessment of five frontier companies against six practices — logging, monitor efficacy, gated actions, circuit breaking, third-party review, containment plan — scoring Anthropic C+ (2.50), OpenAI C+ (2.50), Google D+ (1.50), xAI D− (0.83) and Meta F (0.67). Method, in its own words: over June to August 2026, “We compiled each company’s relevant public materials: frontier safety frameworks, system cards and model reports, technical blog posts, attributed company statements in third-party publications, etc. We only drew upon public information.

“Across frontier companies, basic control practices are at most partially implemented. On our 0–5 scale, no company’s score on any practice exceeded a 3 (substantial partial implementation). The majority of scores are 2 (limited partial implementation) or lower.”

“How AI companies would respond to such incidents is even less clear; the best public evidence is that companies have few containment protocols ready for an emergency.”

“Three companies describe logging at least some internal usage that is then scanned for signs of misbehavior.”

Why this bears on reasonable inquiry. The objection above assumes the officer’s alternative to personal knowledge is her own safety team. It is not the only alternative. A third party reading nothing but published documents produced a graded finding about containment and internal monitoring — which means “did this officer make reasonable inquiry” has at least one answerable form: did she know what an outsider could already see from her own company’s published material, and did she ask about the gap?

That does not settle whether asking the safety team suffices. It does establish that an officer who certifies compliance while her own public documents will not support a passing grade on containment is not in the hard case at all, and the hard case is the only one this section has been arguing about.

And one finding cuts at a drafting choice this Act made deliberately. SEC. 3(c)(4)(C) provides that in the adopted interim standards, “provisions respecting assessment or audit by a third party do not apply, and conformity may be documented internally, independent assessment being at the entity’s election.” The assessment records that “Four of them (all but xAI) participated in METR’s first Frontier Risk Report,” and that deeper hands-on access for assessors is something “only Anthropic seems to have to date.”

So the Act made elective the one practice four of five frontier developers were already doing voluntarily. That is a defensible choice — the drafting note is that independent assessment capacity did not exist to be compelled — but it is now a choice against the observed facts rather than around a gap, and the reviewer’s question is whether an election is the right setting for a practice with an 80% voluntary take-up rate. The single non-participant is xAI, which is also the plaintiff arguing in X.AI v. Bonta that compelled disclosure of this material is a taking.

Read-status: primary. Read in full from the report held in the working library (REPORT_Guidelight_Control-Assessment-Frontier-AI-Companies_2026-08-18.pdf), 25 August 2026; every quotation above transcribed from it, not from a summary. The report carries no byline. It is a standards body’s own assessment, not a peer-reviewed finding, and this project has not audited its rubric or its scoring.

Why this is a finding and not a section with an answer at the end

The gap is narrow and specific: the Act credits conformity with an external standard, discredits reliance on the entity’s own framework, and says nothing about reliance on a person — an auditor, an evaluator, counsel, or a safety officer who is not the certifier.

Illinois requires an auditor to sign. Connecticut routes the warning to the officer’s desk. Neither says what the officer may rely on. This Act inherits that silence and adds a criminal penalty to it, which is a worse place to be silent than either of them.

Held for the criminal-law reviewer, and it belongs near the top of that reviewer’s list, because it decides whether SEC. 8 is a real duty or a formality. A reviewer who concludes that reasonable inquiry must be defined, or that reliance on a named qualified person should be an express partial defense with the burden on the defendant, is doing the most useful thing available in this topic.

“Criminalise the failure and the safety paper stops being written” — added 26 August 2026

Raised from outside the project. It is raised from outside the project and has no answer here, and it is a mechanism rather than a slippery slope, which is why it belongs above the others.

The objection

Aviation is the standard illustration. The Aviation Safety Reporting System gives near-immunity for self-reported error, and the result is the safest transport mode ever built, because everyone reports everything. Criminalize the failure and behavior inverts: legal privilege over every risk assessment, safety teams instructed not to write things down, no red-team report that is not drafted for a jury.

And this Act’s own willful-blindness route is what causes it. If ignored warnings are the evidence of knowledge, the rational response is to stop generating warnings. You get less safety paper, not more — and the paper is the only thing anyone outside the firm can ever see.

Held as stated, not as verified. The ASRS immunity design is not on this project’s shelf and nothing here has read it. The mechanism is recorded because it is the objection; its empirical premise is a retrieval, not a finding (E57).

What the Act actually does, and it is the opposite of a safe harbor — deliberately

SEC. 8, verbatim:

“A certification disclosing identified noncompliance satisfies the duty to certify under this section; it constitutes neither compliance with the applicable standards, nor validation, nor cure of, nor a defense to, any violation of this Act, and a certification disclosing unremediated material nonconformity … shall so state on its face.”

Read that twice. Honesty protects the certifier from the certification offense, and the same sentence goes out of its way to say honesty is no defense to the underlying violation. That is a drafted choice, not an omission — the clause exists to foreclose exactly the reading the aviation objection would want.

The Act’s other candor machinery points the same way. SEC. 5(c)(1)(D) creates a category of “nonconformity report” for a document that discloses a problem without claiming it is cured, so the honest document has a name. SEC. 11 pays whistleblowers. Neither protects the person who reports their own failure, which is precisely the person the aviation design protects.

Why this is the sharpest form of the objection, and it is not answered

The Act has a candor provision and stops short of a safe harbor, and no page in this repository says why. docs/safe_harbors_and_affirmative_defenses.md is about other people’s safe harbours as an inoculation pattern — Texas TRAIGA’s NIST-compliance defense, Colorado’s — and not about whether this Act should have one.

The honest statement of the design tension: the willful-blindness theory wants ignorance to be culpable; the disclosure regime needs reporting to be safe. Those pull in opposite directions, and a regime that criminalizes the error rather than the concealment gets the second at the cost of the first.

Open, and it is the torts-and-design reviewer’s question. Whether SEC. 6(a) should carry a self-report mitigation — criminalize the concealment, not the error — and if not, on what account of why aviation’s answer does not transfer. Nobody in-house has attempted it.


Not yet on this page — objections named and not answered, 26 August 2026

Listed rather than argued, because a page that pretends to completeness is worse than one that carries its gaps. Each was raised from outside and none of these words appears anywhere else in this repository.

Objection State
Vagueness. A duty framed as “reasonable safeguards” is unconstitutionally vague where the penalty is prison — Lambert v. California, and the vagueness line in Johnson v. United States (2015). Specify the controls and they are obsolete on arrival Neither case is held or cited. This is the constitutional objection that most often kills a bill in committee
The First Amendment flank. Model weights and code as expression — Bernstein left it half-open and nobody has resolved it for frontier models ⚠ Not held, not cited
You cannot criminalize a standard you cannot measure. No eval suite with published false-negative rates, no agreed threshold for sufficiency, no elicitation methodology two labs would apply identically. Every expert-witness battle is a coin flip ⚠ Prior to every legal question on this page, and unaddressed
Deterrence assumes the deterred party is the marginal supplier. Jail the US executive and the capability arrives from an open-weight release instead. Weaker for the largest training runs; somebody should make this project quantify it rather than assert it ⚠ Unaddressed
Reversibility. A criminal statute is close to permanent; a regulation is amendable in months. Under this much model uncertainty the decision-theoretic move is the revisable instrument ⚠ Unaddressed
Adverse selection in the leadership pool. Criminal exposure filters for risk tolerance and legal budget, not for care. The conscientious officer declines the title ⚠ Unaddressed. The proponent rated it “moderate” confidence and wanted it tested
Moral luck. The identical decision goes free or gets six months depending on the user it met. Criminal law tolerates this everywhere, and it is sharper through a stochastic system ⚠ Unaddressed
The mens rea reform pincer. A fifteen-year legislative project to add default mens rea and shrink strict liability, with the overcriminalization literature already written. A new public-welfare offense walks onto ground that coalition chose research/canon_check_2026-08-24.md has the literature; nothing anticipates the coalition

And the strongest argument for this Act is also missing. Jennifer Arlen’s point — that individuals respond to personal liability in a way firms never respond to fines, because prison cannot be insured against, indemnified, or booked as a cost line — is the answer to most of the above and appears nowhere in this repository. ⚠ Stated as reported and not read; her work is not on the source library. She was written to during outreach and never replied, which makes the absence harder to excuse rather than easier.

And one empirical hole, which is the largest. This project has the RCO doctrine and none of the outcome data. Whether responsible-officer liability measurably reduced adulteration or pollution rates has no answer anywhere in this repository. The central analogy is currently a legal argument wearing an empirical one’s clothes, and until somebody looks, that is what it will stay.


“The veil is not the obstacle. Delegation is.” — added 26 August 2026

Raised from outside the project, and it is the sharpest form of the individual-liability objection this page carries. It is not the same as “She relied on her safety team”, which is about what a decider knew. This one says there may be no decider to reach.

The objection

Large firms have general counsel, chief safety officers, and model deployment committees — and every one of them is a person to whom responsibility was formally assigned, which is a person who is not the chief executive. The responsible-officer doctrine’s whole premise is that the officer had the power to prevent the violation. Modern corporate structure is very good at ensuring that the person with the power is three levels down and paid to be there.

Note what this is not. It is not piercing the corporate veil, and it is not a shell game with entities. It is an org chart, built in the open, by lawyers, for exactly this reason.

What the Act already does about it, and it is not nothing

SEC. 4(c) forecloses shedding: “no appointment of a safety officer, compliance officer, committee, subsidiary, contractor, or other intermediary shields a person who retains such authority.” SEC. 4(a) reaches authority held “directly or indirectly, individually or in concert with others, and through any intermediary, entity, trust, or arrangement,” and closes with “Substance controls over title.”

And SEC. 4(b) is the provision written for this objection. The chief executive is a presumed controlling person “absent proof of genuine absence of practical authority.”

But read the rest of SEC. 4(b), because it gives the answer back

“In any civil proceeding, absent proof of genuine absence of practical authority… In any criminal proceeding, such status is evidence from which the trier of fact may infer controlling-person status; the prosecution retains its burden on every element under SEC. 6(d).”

The presumption is civil only. In the criminal case — the tier people mean when they ask whether this Act reaches a chief executive — there is no presumption, and the prosecution must prove final material independent authority against an org chart engineered to defeat exactly that showing. That was a deliberate choice and it is the right one on due-process grounds. It is also the concession the objection is pointing at, and this page should say so rather than let SEC. 4(b) be read as an answer it does not give in the tier that matters.

And on this element the Act is narrower than the federal doctrine it descends from

United States v. Iverson, 162 F.3d 1015 (9th Cir. 1998) — ✅ read in the opinion 25 August 2026:

“Under the CWA, a person is a ‘responsible corporate officer’ if the person has authority to exercise control over the corporation’s activity that is causing the discharges. There is no requirement that the officer in fact exercise such authority or that the corporation expressly vest a duty in the officer to oversee the activity.”

SEC. 4(a) requires authority that is final, material and independent, and excludes by name “the provision of advice, analysis, or recommendation to a person holding decision authority.” A person the federal doctrine would reach can be outside SEC. 4. That narrowing is defensible — it is what keeps the engineer with production access out — but it is spent precisely where the delegation objection is strongest, and no page in this repository currently notices the trade.

And this is the largest open question in the Act, stated as such

This Act exists to make a small number of very powerful people personally answerable for deploying systems they had the authority to stop. SEC. 4(b)(2) is the provision that reaches them — it presumes a controlling person is anyone holding rights “sufficient, alone or in concert with others, to direct or replace the management” of a developer. Supervoting shares. A founder’s trust. A governance right held through an intermediary.

And that presumption operates in civil proceedings only.

Where the remedy is money, the person holding the votes is presumed responsible. Where the remedy is prison, he is not, and he is the party best resourced to document that operational authority sat three levels beneath him.

That is inverted for a statute whose whole premise is that a corporate fine is absorbed and a custodial sentence cannot be. The split was drafted on due-process grounds and may well be required. But it was written as though the law compelled it, and nothing in this repository tests whether it does.

Open, and it needs a criminal lawyer. May a State presume controlling-person status in a criminal proceeding against a person holding the SEC. 4(b)(2) rights? If not, can a permissive inference with a rational-connection showing survive, or a burden of production on the Park model? And whether “final material independent decision authority” can be proved beyond reasonable doubt against a firm that has documented the opposite. If the answer is that none of it can be done, then this Act reaches the people it was written for in civil court and not in criminal court, and that belongs on its front page rather than in a footnote here.


“So which is it — a deterrent, or a duty-and-fine regime?” — added 26 August 2026

Asked by a careful outside reader with the repository in front of them, which makes it a finding about this page rather than about the reader.

The objection

The project’s rhetorical edge is individual criminal liability. Its operating machinery is duties, certifications, reporting and fines. A reader cannot tell from the front page which one the Act is, and the two are very different drafting problems.

The Act has decided, and it decided the way the federal model did

Two tiers, and the split is the whole design.

SEC. 6(a) — a controlling person who had the duty or the practical power to prevent, and failed to exercise due care, commits an offense. Ordinary negligence. This is the operating regime: it is what makes the duties real, and it carries misdemeanor-level exposure.

SEC. 6(b) — a person who “knowingly or wilfully” causes, directs, conceals or materially facilitates a violation, or who deliberately fails to halt one after notice, or who knowingly makes a false certification, faces the felony penalties of SEC. 10(c). (The statute’s own spelling of that word is not American; the point is Amendment 22’s, not this page’s.)

That is Hanousek’s shape, taken deliberately. 33 U.S.C. § 1319(c)(1) with (c)(6) already imposes criminal liability on a responsible corporate officer for a merely negligent violation, at the misdemeanor level — ✅ United States v. Hanousek, 176 F.3d 1116, 1121 (9th Cir. 1999), read in the reporter print: ordinary negligence “may be subject to criminal penalties,” and it does not violate due process. The felony tier requires knowledge, proved by ordinary means, including the willful-blindness route.

So: duties and a negligence floor as the operating regime; individual felony liability reserved for the person who knew. Not a rhetorical edge on a fines regime, and not a jail-the-CEO statute. The two tiers exist because those are two different offenses committed by two different people.

The finding is that this had to be reconstructed from the statute and two cases. No public page states it. docs/03-whats-in-the-act.md describes the provisions; nothing says the negligence tier is the regime and the felony tier is the exception, and here is why. Until it does, a careful reader is entitled to conclude the project has not decided.


“This is aimed at particular people” — attainder, and why it is not — added 25 August 2026

Occasionally raised, easy to answer, and worth answering because the answer is structural rather than rhetorical.

No natural person is named in the operative text. Altman, Musk, Zuckerberg and Amodei appear zero times in model_act_v3_4.txt. Every duty attaches by objective threshold — [10^26] operations or prospective capability designation — and by function, not by identity.

SEC. 0(a)(5), in the findings: this Act “draws no distinction between persons within and persons outside this State. It confers no advantage on any in-state person and imposes no obligation on an out-of-state person that it does not impose on an in-state person engaged in the same conduct with respect to the same system.”

SEC. 4(a) goes further and excludes identity from the element itself: “title, office, seniority, or status” do not constitute authority, and “Authority under this section is the authority to decide, not the capacity to act.” The Act is indifferent to who you are and interested only in what you could have stopped.

And a drafting consequence worth stating, because it is a live temptation: naming individuals in operative text would create bill-of-attainder, equal-protection and selective-enforcement arguments that the current draft simply does not present. A class-neutral statute that plainly reaches people like them is a harder target than one that names them, and this is one place where the more restrained drafting is also the more dangerous.

“This is a taking” — the count they actually lead with — added 25 August 2026

Until today this page did not contain the word. Takings Clause, regulatory taking, per se taking, Penn Central, Ruckelshaus: none appeared anywhere in this repository. The project tracked compelled speech and vagueness — the objections raised in conference rooms — and missed the one being litigated.

It is being litigated now. In X.AI LLC v. Bonta, No. 2:25-cv-12295 (C.D. Cal., filed 29 December 2025), on appeal as No. 26-1591 (9th Cir.), xAI attacks California’s AB 2013 training-data transparency statute in four counts. The first two are takings. Speech is third. That ordering was chosen by an appellate firm, and it is information: they think property is the better ground.

The objection, at its strongest

Trade secrets are property for Takings Clause purposes. That is not a stretch; it is Ruckelshaus v. Monsanto Co., 467 U.S. 986, 1003–04 (1984), which the complaint cites. A training corpus, an evaluation result and a compute ledger are “valuable precisely because they are not public” — the complaint’s phrase. A statute compelling their disclosure appropriates the thing that made them valuable, and the right to exclude is “a fundamental element of the property right” and “one of the most essential sticks in the bundle of rights that are commonly characterized as property” (Kaiser Aetna v. United States, 444 U.S. 164, 176, 179–180 (1979), quoted in Cedar Point Nursery v. Hassid, 594 U.S. 139, 150 (2021)).

This passage used to give that proposition as Cedar Point’s “sine qua non” of the property interest, and the phrase is not the Court’s. Read on 26 August 2026, it appears once in the opinion, in a see also parenthetical reporting what an article “call[s]” the right to exclude — Merrill, Property and the Right to Exclude, 77 Neb. L. Rev. 730 (1998). The Court’s own words are Kaiser Aetna’s, as now quoted (E70). ⚠ 150 remains the complaint’s pincite: neither copy held carries U.S. Reports pagination.

Applied here the objection is heavier than it is against AB 2013. SEC. 8 compels a personal certification. SEC. 9 compels incident reports. SEC. 3 compels validation materials. SEC. 12 compels ten years of compute records, evaluation results, permission manifests and change histories — and SEC. 1(b)(1)(C) reaches records for derivations at [10^22] operations, two orders of magnitude below coverage, “whether or not the resulting model is covered.”

The answer turns on one distinction, and the Act draws it twice

AB 2013 compels publication. This Act compels transmission to a regulator. SEC. 8: “A certification is made to the Agency and is not required to be published.” SEC. 9(c): “A report is made to the Agency and is not required to be published.” And SEC. 12:

“reports under SEC. 9, certifications under SEC. 8, and validation materials under SEC. 3 are exempt from disclosure under [the State public-records act], and to the extent they contain security-sensitive information — including information that would materially assist unauthorized access to model weights or covered systems — shall be maintained under seal in any proceeding

That matters because of what a regulatory takings claim requires. Monsanto held that where a submitter knows in advance that data goes to a regulator on stated terms, there is no reasonable investment-backed expectation of confidentiality against that use — and without one, the Penn Central limb fails. This Act supplies the advance terms in its own text, before any duty attaches.

But the tagged text buys that answer at a price this project should not pay

Sealing everything defeats the takings count and abandons the transparency statutes this project treats as allies. California, New York and Illinois each enacted the same operative sentence — write, implement, comply with, and clearly and conspicuously publish a frontier AI framework — and SEC. 3(c)(4)(B) adopts those duties while converting publication into filing.

So the honest statement of the Act’s position is not “we protect trade secrets.” It is: the tagged text protects them by removing the publication that three legislatures thought was the point.

The repair, which an ally drafted first

Amendment 23 restores publication on the terms of California Business and Professions Code § 22757.12(f) — already adopted by this Act as an interim standard and then disapplied. A developer publishing under it “may make redactions… necessary to protect the frontier developer’s trade secrets, the frontier developer’s cybersecurity, public safety, or the national security of the United States,” must “describe the character and justification of the redaction in any published version,” and must retain the unredacted information.

Under that repair the takings answer gets stronger, not weaker. The framework is public; the trade secret is redacted by its owner; the unredacted copy is a sealed record. Nothing secret is surrendered to anyone, and nothing is hidden that is not a secret. A count that requires an appropriation has nothing to point at.

What the answer does not reach

One. SEC. 12’s exemption “does not create any privilege for underlying facts, which remain subject to discovery and subpoena from any source.” Sealed against the public is not sealed against a litigant, and a competitor with a lawsuit is a source.

Two. The per se limb may not care about publication at all. Cedar Point treats the right to exclude as the property itself, and a compelled handover to the State is a handover whether or not the State prints it. Whether “under seal” answers a per se theory or only a regulatory one is the question this project cannot settle in-house.

And point Two needs a step Cedar Point does not supply, which reading it made plain. The Court frames its own rule around a physical line: “The essential question is . . . whether the government has physically taken property for itself or someone else—by whatever means—or has instead restricted a property owner’s ability to use his own property”, and “[w]henever a regulation results in a physical appropriation of property, a per se taking has occurred.” The case concerns a right to “physically enter and occupy the growers’ land for three hours per day, 120 days per year”. The words “trade secret” and “intangible” do not appear in the opinion, and neither does Ruckelshaus. Carrying a per se physical-appropriation rule across to compelled production of records is the argument, and no authority on this page makes it — the objection is good on Ruckelshaus and on an extension nobody has briefed (E70).

Three. The redaction power in SB 53 § (f) is exercised by the developer, with no agency approval and no penalty attaching to over-redaction as such. If it is a rule in name only, Amendment 23 imports a rule in name only.

Four. The [10^22] records duty below coverage was drafted for lineage arithmetic, not against this objection, and it is the widest surface the Act presents to it.

One fact about the plaintiff, recorded because it cuts both ways. The Guidelight control assessment of 18 August 2026 records that four of the five companies it assessed took part in METR’s first Frontier Risk Report, and that xAI was the only one that did not. So the company pressing the takings argument against compelled disclosure is also the one that declined the voluntary equivalent. A reviewer may read that as a party with the most to lose by either route, or as the most consistent objector on the field — this project has no way to choose between those readings and should not pretend otherwise. It is recorded because a court weighing investment-backed expectations may find a company’s own disclosure practice relevant, and neither side’s brief will raise it.

Read-status. The complaint is held in the working library and was read in full. The authorities inside it — Ruckelshaus, Cedar Point, Penn Central, Armstrong, Tyler, Sheetz — are cited as the plaintiff cites them and have not been read in the reporters. E22 governs; nothing here may be described as verified.

Why this was missing, recorded rather than tidied away

The vocabulary audit of 25 August asked which terms a specialist would search for and fail to find. It surfaced corporate governance, criminal imputation and attorney-general clusters. It did not surface takings, because the term list was built from what this project already imagined its adversaries would argue. A list of expected objections cannot contain the unexpected one. The gap closed because a reader put an adversary’s actual pleading in the library.

“Corporate law already answers this, and it answers in our favor” — added 25 August 2026

This is the objection a corporate governance lawyer raises, and until today this file could not answer it because it had never named the doctrine. Caremark, Stone v. Ritter, the business judgment rule and the duty of oversight appeared nowhere in this repository. That absence is recorded rather than quietly repaired, because a reader who searched for any of those words in the first minute would have concluded, reasonably, that the drafter had not heard of them.

The objection, at its strongest. Deciding whether to release a model is a business decision made by fiduciaries. Delaware — where these companies are incorporated — has spent thirty years building the law of when a fiduciary answers personally for a failure to supervise, and it set the bar high on purpose. In re Caremark, 698 A.2d 959, 971 (Del. Ch. 1996): only “a sustained or systematic failure of the board to exercise oversight — such as an utter failure to attempt to assure a reasonable information and reporting system exists” will “establish the lack of good faith that is a necessary condition to liability.” A state that criminalizes the same conduct at a lower threshold has not filled a gap. It has overridden a considered judgment about how much protection a decision-maker needs.

The answer, and it was two sentences above the quotation for as long as this objection stood.Caremark was read on 26 August 2026. In the paragraph immediately preceding the passage above, Chancellor Allen reserves the case this Act is about:

“Thus, this case presents no occasion to apply a principle to the effect that knowingly causing the corporation to violate a criminal statute constitutes a breach of a director’s fiduciary duty. See Roth v. Robertson, 64 Misc. 343, 118 N.Y.S. 351 (N.Y. Sup. Ct. 1909); Miller v. American Tel. & Tel. Co., 507 F.2d 759 (3d Cir. 1974).”

The considered judgment was made about ignorance, and expressly not about knowing violation — the standard itself is confined on its face to claims “predicated upon ignorance of liability creating activities”. SEC. 6(b) is a knowing-conduct offense, and Delaware did not weigh it. The court cited two authorities running the other way on the reserved question and left it open (E68).

The objection survives against SEC. 6(a) and this page should say so. SEC. 6(a)’s floor is a failure of due care, which really does sit below the Caremark bar, and the argument that a state has overridden a considered judgment is available there. It is not available against SEC. 6(b).

The first half of the answer: this Act is not in that body of law at all. Oversight liability is civil, it is fiduciary, and it is owed to the corporation and its stockholders. The duty here is criminal, statutory, and owed to the public. The two can coexist because they answer different questions to different people, and a statute that imposes a public duty is not amending anybody’s fiduciary standard.

The second half is where the objection weakens, and Delaware supplies the words. In re Massey Energy Co. Derivative & Class Action Litigation (Del. Ch. 31 May 2011) (Strine, V.C.), at slip op. 46:

“Delaware law does not charter law breakers.”

And on the same page, the floor beneath the rule: “Delaware law allows corporations to pursue diverse means to make a profit, subject to a critical statutory floor, which is the requirement that Delaware corporations only pursue ‘lawful business’ by ‘lawful acts.’” ✅ Both read in the opinion, 25 August 2026.

So the business judgment rule sits above a statutory floor, and a statute is what sets the floor. A rule that presumes good faith in a considered decision does not presume it in a decision to proceed unlawfully.

And Delaware says where the line falls, in a sentence this section carried, deleted in error, and now restores. Ontario Provincial Council of Carpenters’ Pension Trust Fund v. Walton, C.A. No. 2021-0827-JTL (Del. Ch. 26 Apr. 2023) (Laster, V.C.) — ✅ read in the opinion 26 August 2026, at slip op. 76 and slip op. 77–78:

“When directors make a business decision that carries legal risk, but which otherwise involves legally compliant conduct, then the business judgment rule protects that decision.”

“In the former case, the directors can make a business judgment to pursue the project. In the latter case, the decision to pursue the project would constitute a conscious decision to violate the law, the business judgment rule would not apply, and the directors would be acting in bad faith.

That is the line drawn exactly where this Act needs it drawn. A decision that carries legal risk is protected; a decision to proceed unlawfully is not a business judgment at all.

The provenance of this passage is worth more than the passage. It was published on 25 August, withdrawn the same day as fabricated, and restored on 26 August on reading the opinion. The withdrawal was the error. C.A. 2021-0827-JTL produced two opinions two weeks apart, and the check that found the sentences “absent” was run against the other one. See E60.

Pincite not confirmed. The copy held carries slip pages, not Atlantic Reporter pages, so the published 294 A.3d 65, 90, 92 remains unverified (E47). The quotations are verified; the page numbers are not.

What Delaware still has not squarely said — and we looked — is that the rule can never be raised against a duty imposed by a statute outside the DGCL. That question remains open.

And the direction of travel runs the same way. Marchand v. Barnhill (Del. 18 June 2019) (Strine, C.J.), at slip op. 31, held that “the board must make a good faith effort — i.e., try — to put in place a reasonable board-level system of monitoring and reporting,” and at 36 found the failure where “food safety was essential and mission critical.” ✅ In re McDonald’s Corp. Stockholder Derivative Litigation, C.A. No. 2021-0324-JTL (Del. Ch. 26 Jan. 2023) (Laster, V.C.) then took the duty off the board, at slip op. 2: “This decision clarifies that corporate officers owe a duty of oversight.” ✅ Delaware has been moving, on its own, toward the proposition that the person with responsibility for a mission-critical risk answers for failing to build a system to know about it. That is this Act’s proposition, arrived at independently, in the corporate law of the state these companies chose.

What this does not answer, and a reviewer should press on. It does not answer whether a criminal statute is the right instrument when a civil one already reaches the conduct — that is the torts and design topic’s sixth question and this project’s largest unanswered one. It does not answer whether SEC. 6(a)’s due-care floor is too low given that Delaware deliberately set bad faith as its own threshold. And it does not touch a genuinely open question: whether 8 Del. C. § 102(b)(7) exculpation, which by its terms reaches “monetary damages for breach of fiduciary duty,” has anything to say about a duty imposed by a statute outside the DGCL. We have found no case deciding it. If a governance reviewer can, that is a finding.

Read-status, stated so this section is not mistaken for more than it is. Stone, Massey, Marchand, McDonald’s and now Walton have been read in the opinions; their pincites are slip-opinion pages, and none has been confirmed against a reporter print.Caremark was read on 26 August 2026 and its 971 pincite is confirmed — the copy held carries star pagination, contrary to what this repository assumed from its filename (E68). The In re TransUnion sentence removed by E46 stays removed — it has not been re-checked, and nothing in the Walton correction bears on it. Under E22 nothing here may be described as verified, and no outreach may cite it as settled, until the opinions are read.

“You cannot prove an AI system caused the harm” — added 25 August 2026

This objection is usually raised in the abstract. It now has a courtroom.

Twenty-six former Meta employees, all on protected leave during a May 2026 reduction in force, alleged the company “used a constellation of internal artificial intelligence systems,” including one monitoring “employees’ keystrokes and computer activity,” to “score, rank and select employees for inclusion on the list.” On 24 August 2026 U.S. District Judge William Orrick declined a preliminary injunction:

“I have a record I have to deal with and the record at the moment does not persuade me of the merits.”

“the plaintiffs’ evidence raised some potential questions about Meta’s categorical denial of any impact of AI in the termination process, and they provide further evidence of harm, but they don’t persuade me that injunctive relief is warranted.”

He called it “an unusual, or a new sort of issue” that was hard to gather evidence for at the outset (Courthouse News, 24 Aug 2026; press corpus).

The answer, and it is the whole reason the records provisions exist. The claim did not fail because automated decision-making is unprovable in principle. It failed on the record available to a plaintiff who was outside the system that made the decision. Every logging, retention and reporting duty in this Act is drafted against precisely that asymmetry: not to prove liability, but to ensure that the facts exist somewhere a court can reach them, created before anyone knew they would be needed. A statute that imposes duties without requiring the records that would show whether they were met is decorative, which is why the enforcement and security topics are asked whether these records could actually be produced.

What this case is not. It is not authority for anything, it is a denial of interim relief on an incomplete record, and this Act does not reach employment decisions at all. It is quoted because it is the clearest judicial statement yet of the evidentiary problem the Act’s plumbing exists to solve.

And a legislature has already tried the other repair, which this project has not. New York S 1169-B would not improve the plaintiff’s evidence; it would move the presumption. § 114(2):

“In evaluating any motion to dismiss a proceeding commenced pursuant to this section, the court shall presume the specified AI system was created and/or operated in violation of a specified law or laws and that such violation caused the harm or harms alleged.”

rebuttable only by “clear and convincing evidence” — and then, in the next paragraph, the sentence that matters most to this Act:

“An algorithmic audit can be considered as evidence in rebutting such presumptions, but the mere existence of such an audit, without additional evidence, shall not be considered clear and convincing evidence.”

Both halves are instructive, and they point in opposite directions.

The first half is a route this Act does not take and should be asked about. A presumption of violation and causation, reversed at the pleading stage, is a far blunter instrument than a records duty, and in a criminal statute it would be unavailable: this Act’s SEC. 6 puts every element on the prosecution, and the drafting record says so. So the honest statement is that New York’s civil bill can reach for a tool this Act cannot, and the proportionality and criminal topics should be asked whether the records architecture is a sufficient substitute or merely a politer one.

The second half is a warning aimed squarely at the architecture this Act does have. This project argues for audit and certification. New York’s drafters, contemplating the same instrument, legislated that a completed audit is not by itself proof of anything. If an audit can become a token that discharges suspicion, the audit requirement makes the defendant safer rather than the public. That is a defect this repository has not tested for, and it is now a question for the enforcement topic.

S 1169-B is an algorithmic-discrimination bill amending the civil rights law, not a frontier statute; see the census for why it is recorded as an adjacent lineage. ⚠ Its status is carried from a commercial tracker and is not verified.

“The timelines make this pointless” — added 24 August

The objection, stated at its strongest: the field’s own forecasters put the modal year for transformative capability inside this decade, with intervals between late milestones measured in months — so a state statute drafted on legislative time regulates a world that will have ended before third reading. It deserves a serious answer because the numbers behind it are serious (the forecasters’ arithmetic, § 3).

The answer is that the objection defeats the wrong plan. It is fatal to beginning drafting when the window opens — which is precisely this project’s position (paths to enactment): public-welfare statutes pass in the weeks after the failure that makes them undeniable, and what passes is whatever reviewed text already exists. Fast timelines shorten the window; they do not shorten the need for the drawer — they are the case for filling it now. And if the forecasters are wrong and the decade is ordinary, the Act costs what a vetted draft costs: nothing, until a legislature wants it. The asymmetry runs one way. A reviewer who believes the timeline objection should say in a review which leg fails: the window pattern, the arithmetic, or the asymmetry.

The argument this page defends: the case. The definitions it defends: the definition. The operative language under attack: the statute and the v3.5 queue.

The answer sharpened, 25 August, from inside the alignment field. The objection assumes technical progress outruns legal process, so institutions arrive too late to matter. The strongest published statement of the contrary case is Kierans, Casper & Ghosh, Intelligence Is Not the Bottleneck: Structural Barriers to Automating Alignment Research (2026, read in full; in the project’s source library). It names the claim it rejects: that “datacenters full of research agents will compress a decade’s worth of alignment research progress into 6-12 months.” Its finding is that “structural barriers, not intelligence, are the principal bottleneck,” and its central sentence is the one this Act is built on:

“The parts of alignment that remain unsolved are not waiting for smarter, more numerous researchers; they depend on whether we build mechanisms that allow accelerated research to accumulate into something reliable. That is not yet happening, at least to public knowledge.”

Two further observations from the same paper bear directly on the objection’s provenance. First, the assumption is convenient for the people who hold it: it “offers a very convenient agenda for companies who are racing to develop increasingly powerful AI.” Second, without institutional work, automated alignment “might be abused as a safety-washed euphemism for automating AI capabilities progress.”

If that analysis is right, the timelines objection inverts: a constraint that is institutional rather than technical is not outrun by capability, and building durable legal mechanisms is the work rather than a distraction from it. The Act’s stake in this is honest and limited. It does not claim the paper endorses officer liability; it claims the paper undercuts the premise that legal architecture cannot matter on these timescales. A reviewer who thinks that reading stretches the paper should say so, and the review would be published.


“Wait for the courts” — the strongest form of the objection, and it was made under oath — added 25 August 2026

Until now this file has answered a wait-for-the-courts objection the project constructed itself. It no longer has to. On 16 July 2025 a law professor put the objection to a Senate subcommittee under oath, at length, and it is better than the version we had been writing.

The witness is Professor Edward Lee of Santa Clara University School of Law, testifying to the Senate Judiciary Subcommittee on Crime and Counterterrorism at Too Big to Prosecute?: Examining the AI Industry’s Mass Ingestion of Copyrighted Works for AI Training, S. Hrg. 119-202. He is not an industry advocate. He agrees the conduct may be infringement; his claim is narrower and harder to answer, which is that the question is genuinely unresolved and the legislature is the wrong body to resolve it first.

“At this juncture, I think the best approach is for Congress to wait and see how other district courts, the courts of appeals, and potentially the U.S. Supreme Court resolves these difficult issues.”

“And there are presently 44 lawsuits around the country, so this is not a time for Congress to intervene in terms of deciding these very difficult questions.”

Restated for this Act. There are live cases. Courts are actively developing the doctrine. A state criminal statute enacted now freezes a moving question and will be wrong within two years. Let it settle.

The three answers, in the order they should be given.

One, the objection has a shape, and the shape is the point. Lee’s own next move at that hearing was to ground the caution in an executive-branch policy preference, and he named the official:

“And I would defer to the view of the AI czar, David Sacks, who said if there is no pathway to fair use in AI training, we will lose the race with China.”

The chair’s reply is the answer this project would give and is worth having in the record in someone else’s words:

“Well, you think that we should allow an unelected AI czar to decide what the rights of American citizens are?”

Wait-for-the-courts is rarely only about courts. It usually arrives holding a policy preference about what the courts should conclude.

Two, Congress has run this experiment. The Ranking Member put the precedent to the witness directly, and it is the cleanest statement of the answer available:

“Professor Lee, if I understand part of your argument here, you were suggesting that this is the age of innovation. Deep learning deserves special treatment. We’ve been through this argument in Congress before. Section 230 is a good illustration of that. We decided this fledgling industry called the internet just may not have a future, better be careful, so we exempted them from liability. Is that what you are suggesting?”

— Senator Richard J. Durbin

The forbearance argument was made once about an industry that was going to be too fragile to survive liability. The forbearance outlived the fragility by twenty-five years.

Three, and this is the honest half: on its own terms the objection is partly right. A statute that guessed at an unsettled doctrinal question would deserve the criticism. This Act does not sit on the copyright question at all, and the answer must say so rather than dodge it. What it does is take a doctrine that was settled in 1943 and again in 1975 — Dotterweich and Park, the responsible corporate officer — and apply it to a new subject matter. The novelty is in the defendant class, not in the rule. That is a real distinction and it is also a limited one, and a reviewer is entitled to say the distinction does not hold.

What this project owes in return. Lee’s written answers to Senator Klobuchar (S. Hrg. 119-202, printed pp. 87-92) are the fullest version of his position, and they have been read only by OCR of a scanned page. ⚠ They are owed a proper reading before this section is quoted in anything published.

Sources. All quotations from the decoded body text of the hearing, with page anchors, at library/NOTES_Reading_SHrg119-202_Too-Big-to-Prosecute_2026-08-25.md §§ 7-8.


“The enforcement gap is theoretical” — it is not, and a Senate chair says so — added 25 August 2026

The project’s premise is that conduct by frontier developers goes unprosecuted that would be prosecuted in anybody else’s hands. That premise used to rest on the project’s own reasoning. It now rests on the chair of the Senate Judiciary Subcommittee on Crime and Counterterrorism, in a printed hearing record, saying it in terms:

“Now, the FBI and the Department of Homeland Security regularly prosecute individuals who engage in exactly the same kind of behavior using platforms like LimeWire or Napster in the old days, using a process called torrenting. But have these Big Tech companies been prosecuted? No, of course not. They are getting off scot-free.”

— Senator Josh Hawley, S. Hrg. 119-202 at printed p. 1

And, two pages later, the conclusion he draws from it:

“This isn’t just aggressive business tactics. This is criminal conduct.”

Three limits on this, which must be stated whenever it is used, or the project is doing the thing it criticizes.

  1. The subject is copyright, not catastrophic risk. Nothing at that hearing was about model safety, biosecurity or loss of control. The transfer is structural, not substantive.
  2. Nobody proposed officer liability. Dotterweich and Park are not mentioned. The word “officer” does not appear in that sense in the body text. This hearing is evidence that the gap exists; it is not evidence that anyone in Congress has proposed this Act’s answer to it.
  3. A rhetorical question is not a finding. Hawley asks whether the firms have been prosecuted and answers himself. That is a chair’s characterization, not a Department of Justice declination record.

What it does carry, and it is not small. The structural elements a responsible-officer case needs were each put on the congressional record at that hearing, by name: willfulness (“this is, in fact, amounting to what you might call criminal copyright liability” — Professor Bhamati Viswanathan), escalation to the chief executive (“the decision … was escalated to Mark Zuckerberg” — Maxwell Pritt, and the court’s own finding read into the record by the chair), and concealment (“avoiding risk of tracing back the seeder/downloader are from Facebook servers” — an internal message read into the record). Full citations with page anchors at library/NOTES_Reading_SHrg119-202_Too-Big-to-Prosecute_2026-08-25.md §§ 3-5.


“Regulation and deployment are enemies” — an industry witness says otherwise — added 25 August 2026

Eight months after Too Big to Prosecute?, the same Congress heard the opposite case: Less Hype, More Help: AI That Improves Safety, Productivity and Care, Senate Commerce Subcommittee on Science, Manufacturing, and Competitiveness, 3 March 2026. The chair, Senator Ted Budd, opened it with the framing this file has been answering all along — “winning the AI race against China is paramount for our national and economic security.”

The useful thing in that hearing is not the objection. It is that the industry witness undercut it. Demetri Giannikopoulos, Chief Innovation Officer of Rad AI, told the subcommittee:

“Importantly, artificial intelligence systems operate within existing legal and professional accountability frameworks. Physicians remain responsible for clinical decision making, and health systems are responsible for safe implementation. Existing laws, including patient privacy protections, medical malpractice standards, and civil rights protections, continue to apply. Artificial intelligence does not replace these safeguards[;] it operates within them.”

and:

“The United States has established strong regulatory frameworks to evaluate medical devices and protect patient safety. Through my experience implementing FDA-cleared artificial intelligence systems, I have seen how regulatory clarity and predictability support responsible innovation and safe deployment.”

Why this matters here. The company deploying AI into hospitals told the Senate that named humans remain responsible, that pre-market evaluation is a feature rather than a tax, and that predictability is what lets it ship. That is the Act’s own argument, made by the industry it would bind, in the domain where the stakes are already understood.

The limit. Rad AI deploys cleared clinical tools; it is not a frontier developer, and the existing frameworks it praises are the ones that already cover it. A frontier developer would say the analogy fails precisely because no equivalent framework exists. That is a fair reply, and it is also an argument for building one rather than for not having it. See the FDA section above for why this Act is not that framework.

A second witness at the same hearing, Dr Damion Shelton of Agility Robotics, supplied the sentence this project would have written for it:

“However, as we have seen from self-driving vehicles, safety often lags behind technical ability.”

“As an industry, we owe the general public a solid safety argument backed by data.”

Sources and grading at library/NOTES_Reading_New-intakes-batch-2_2026-08-25.md § 1. ⚠ The senators’ own statements at that hearing, and Mark Muro’s prepared statement for the Brookings Institution, have not been read. Nothing is asserted about them.


“A patchwork of state laws is the real danger” — the ceiling campaign, from the podium, under examination — added 25 August 2026

This file has answered the patchwork objection from press accounts and from trade-association testimony. It can now answer the version delivered by the executive branch itself.

On 10 September 2025 the Director of the Office of Science and Technology Policy, Hon. Michael J.K. Kratsios, appeared as sole witness before the Senate Commerce Subcommittee on Science, Manufacturing, and Competitiveness to answer for America’s AI Action Plan (S. Hrg. 119-284, AI’ve Got a Plan: America’s AI Action Plan). Third of the five parts of the legislative framework he set out:

“Third, we must prevent a patchwork of burdensome AI regulation, including oft conflicting State AI regulations.”

Asked directly whether the administration supports preemption of state AI laws:

“A patchwork of State regulations is anti-innovation. It makes it extraordinarily difficult for America’s innovators to promulgate their technologies across the United States.”

“… we do not believe in allowing for this patchwork to go forward, and State preemption is something we look at closely. We are very excited to work with Congress to find a way to deliver on what the President is looking to accomplish.”

Take the strongest version seriously, because he supplied it himself. Unprompted, in the middle of that answer:

“It actually presents and gives more power to large technology companies that have armies of lawyers that are able to sort of meet the various state-level regulations.”

That is a real argument and this project should not score off it. Fragmented compliance does advantage the firm with the largest legal department. Three answers, in order of strength.

One, a single ceiling advantages that firm more, not less. Fifty rules are fifty places to be outspent; one rule is one place to be shaped, and the record this repository already holds shows the shaping being attempted — a trade association asking Congress, under oath, for a decade’s pause on state enforcement and a framework that “removes liability for companies that are compliant”. The concentration argument cuts both ways and it cuts harder against a single federal instrument.

Two, the burden is a function of the duties, not of the number of jurisdictions. This Act’s duties are drafted to be met by a competent developer with no compliance department: validate, certify after reasonable inquiry, keep records, report. If duties of that kind are unmeetable at scale, the objection is to the duties and should be made about them.

Three, and the point the ceiling campaign never reaches: what would replace it? Preemption removes state law. It does not create the federal duty it displaces. The record in this repository is a stack of congressional letters whose own text concedes that no federal statute governs any of this, and a hearing chair asking why nobody has been prosecuted. A ceiling built over an empty room is not a simplification of the law; it is the absence of law, made permanent.

And on 24 August 2026 a Republican attorney general answered the argument from the other side. Alabama’s Steve Marshall, announcing a subpoena to OpenAI over a frontier model that escaped an internal evaluation and broke into four other organizations:

“This AI lab leak showed that Alabamians’ and Americans’ worst fears about artificial intelligence are not just theoretical. Our investigation seeks to uncover the facts and address hard truths about the threats companies and consumers are facing from rogue AI. Ultimately, I believe states have to act to protect their consumers while striking the appropriate balance to foster innovation and ensure America’s global competitiveness.”

The last clause matters as much as the first: he puts innovation and competitiveness in the same sentence and still concludes that states act. And the instrument he had to reach for was a deceptive trade practices act, because no AI statute in force reaches the conduct. That is the patchwork objection answered by the thing the objection is about: the states are not crowding the field, they are improvising in an empty one. Full record, with the limits, at the state enforcement record § 7.

What is not asserted from this hearing. The Chairman’s characterizations in the same exchange — that “States are criminalizing neutral algorithms”, and his account of what Colorado requires — are not adopted here and have not been checked against the Colorado act. Fourteen senators’ statements, Kratsios’s full prepared statement, the appendix letters, and the written responses to Thune, Blackburn, Cantwell, Baldwin and Hickenlooper are all unread. The Blackburn and Cantwell responses are the most likely to bear on preemption and are an open read.

Citations at library/NOTES_Reading_Three-more-hearings-and-S1169-full_2026-08-25.md § 2.


Back to top

This page was built . The repository is the authoritative record; if this page and the repository differ, the repository is right.

Visits are counted with GoatCounter: no cookies, no personal data, nothing shared. The count is private to the maintainer.

This site uses Just the Docs, a documentation theme for Jekyll.