TL;DR: June 4, 2026 bipartisan discussion draft. "Large frontier developer" = $500M+ revenue + trained a frontier model. Key provisions: mandatory third-party audits, whistleblower protections, critical safety incident reporting, 3-year preemption of state AI development laws. Not yet formally introduced. Worth tracking closely.
On June 4, 2026, Representative Jay Obernolte (R-CA) and Representative Lori Trahan (D-MA) released a bipartisan discussion draft of the Great American AI Act. It is the most detailed bipartisan attempt at a federal AI framework to emerge from Congress in 2026, and in several ways, it splits the difference between tech industry preferences (federal preemption of state law) and AI safety advocates' priorities (mandatory audits, whistleblower protections, incident reporting).
The bill is not law. It hasn't been formally introduced. But its bipartisan sponsorship, level of detail, and the specific compromises it makes signal where consensus on federal AI governance may be converging.
What the draft covers
The Great American AI Act discussion draft has four main titles:
Title I, Frontier AI Governance. Establishes requirements for "large frontier developers," defined as companies with $500M+ in annual revenue that have trained a frontier AI model. Requirements include: pre-deployment third-party audits, reporting of critical safety incidents to a designated federal agency, and annual transparency disclosures about model capabilities and limitations.
Title II, Workforce. Addresses AI's impact on the labor market, including obligations to disclose AI tools used in employment decisions and requirements to notify workers 90 days before AI automation displaces positions. This title overlaps significantly with proposals being advanced in parallel by Senators Sanders and others.
Title III, Cybersecurity. Requires large frontier developers to maintain AI model security programs, including protections against model theft, training data poisoning, and adversarial attacks. Mandates reporting of AI-specific cybersecurity incidents.
Title IV, Research and International Competitiveness. Creates a federal AI research program and frames AI safety as a national security and economic competitiveness issue.
The frontier developer definition
The $500M revenue threshold is the detail most relevant to compliance planning. It is not tied to training compute alone, a company must exceed $500M in annual revenue AND have trained a model at or above a specified frontier compute threshold.
This threshold has two significant design implications:
It captures today's major AI developers. Companies like Anthropic, Google DeepMind, Meta AI, and OpenAI all meet the revenue threshold. It excludes most startups and academic institutions, regardless of how large their models are.
It excludes most enterprise AI users. Companies that use AI tools but do not train frontier models, which describes most enterprises, are not "large frontier developers" under this definition. Title I's most burdensome requirements (third-party audits, incident reporting) apply to developers, not users.
This distinction matters for enterprise compliance planning. If your organization uses AI tools from large frontier developers, you face disclosure and notice obligations under the draft but not the development-stage audit requirements.
Third-party audits
Title I requires that large frontier developers submit their frontier models to third-party safety audits before deployment. The audits must be conducted by organizations that are: (1) independent of the developer, (2) technically capable of evaluating frontier model risks, and (3) certified by the designated federal agency.
The draft does not specify what the audits must cover in detail, that is left to rulemaking. But the legislative text references: capability evaluations for specified dangerous capabilities (biological, chemical, nuclear, radiological, cyberoffense), alignment evaluations, and systemic risk assessments.
This is a significant departure from the current voluntary framework, under which major AI developers conduct their own safety evaluations or submit voluntarily to external evaluators like METR or Apollo Research. Making third-party audits mandatory before deployment would change the economics of frontier AI development and create a new professional services market in AI safety evaluation.
For enterprise procurement teams, the audit requirement creates a new due diligence data point: if the federal framework passes, frontier model providers will be required to publish audit summaries, providing standardized safety documentation that current voluntary frameworks do not guarantee.
Whistleblower protections
Title I creates explicit federal whistleblower protections for employees of large frontier developers who report AI safety concerns. Protected disclosures include:
- Concerns about a model's dangerous capabilities that the developer did not disclose in its pre-deployment audit
- Failures to meet incident reporting requirements
- Violations of the bill's other provisions
- Concerns about the adequacy of the audit process
Retaliation, including termination, demotion, or threats, is prohibited. The bill provides a private right of action in federal court, meaning employees can sue their employer directly for retaliation without going through an administrative process first.
The whistleblower provisions reflect a specific lesson from 2024-2025: the most credible information about frontier AI risks came from employees of frontier AI companies, and those employees had no legal protection for raising those concerns. The Anthropic letter-signers, the OpenAI departures, and the various internal safety team concerns that became public all happened in a legal void. This bill fills it.
State law preemption
The draft proposes a 3-year moratorium on state laws that regulate the development of frontier AI models. This is the provision most likely to be contentious in the legislative process.
What is preempted: State laws imposing development-stage requirements on frontier models, training procedures, safety testing before training, compute reporting, and similar obligations.
What is NOT preempted: State laws governing the deployment and use of AI, including employment discrimination laws, consumer protection laws, and data privacy laws. NYC Local Law 144, Colorado SB 26-189, and similar deployment-stage laws would not be affected.
The 3-year window is explicitly framed as time for Congress to develop a comprehensive federal framework. At the end of 3 years, if Congress has not passed permanent preemption, state authority would resume.
This framing reflects a real tension in current AI law. Sixteen states have enacted AI-related legislation, and the compliance burden for AI developers operating across states has become significant. Industry has argued for federal preemption; state advocates have resisted. The 3-year moratorium is a compromise position.
For enterprises, the preemption question matters less than it does for AI developers, enterprises aren't training frontier models. But the preemption outcome shapes what patchwork of state laws enterprises will face in the medium term.
Which state laws survive GAAIA preemption
The distinction between development-layer and deployment-layer laws determines which state obligations remain intact. Most state AI laws passed since 2024 sit on the deployment side and are explicitly preserved under the draft:
| State Law | What It Regulates | Layer | GAAIA Impact |
|---|---|---|---|
| Colorado SB 26-189 (eff. Jan 1, 2027) | ADMT in consequential decisions; employer obligations | Deployment | Survives, deployment law explicitly preserved |
| Illinois AI Video Interview Act | Employer consent for AI video analysis | Deployment | Survives |
| NYC Local Law 144 | Bias audit for automated employment tools | Deployment | Survives |
| Texas TRAIGA | Mostly government AI; limited private sector bans | Deployment | Survives |
| California AB 2013 | AI training data transparency (developers must disclose) | Development | Contested, may be preempted if GAAIA passes |
Compliance teams should not change their current roadmap based on this draft. Colorado SB 26-189's January 1, 2027 deadline has not moved. Illinois AIVR consent requirements are in force now. NYC LL 144 bias audit obligations are unchanged. If California AB 2013 is in your compliance stack, monitor how Congress defines the development versus deployment line as the bill advances.
Critical safety incident reporting
Large frontier developers would be required to report "critical safety incidents" to a designated federal agency within 72 hours of discovery. The draft defines a critical safety incident as an incident involving:
- A model being used to cause or materially assist in causing physical harm to people
- Unauthorized access to model weights or training data
- Evidence that a model is operating outside its intended purpose in ways that create significant risk
- A model exhibiting unexpected behavior that exceeds its tested capability boundaries
The 72-hour reporting window mirrors the reporting requirements in the EU AI Act for serious incidents, and the cybersecurity incident reporting requirements under the SEC's 2023 cybersecurity disclosure rules.
For enterprise governance, critical safety incident reporting creates a disclosure audit trail. Enterprises using frontier AI models can request their vendors' incident history as part of due diligence. A vendor with no disclosed incidents may simply have incidents it has not reported, the bill creates legal risk for that. See the AI vendor due diligence guide for a procurement checklist that incorporates incident reporting history.
What enterprise governance teams should watch
This draft's status matters more than its content right now. The bill is a discussion draft. Key indicators of whether it moves forward:
- Whether it gets formally introduced (scheduled markup in a House committee)
- Whether the Senate produces a companion bill
- Whether the preemption provision survives, it has industry support and state opposition
- Whether the audit provision is narrowed or expanded in negotiation
Timing. The discussion draft emerged in June 2026. Given the legislative calendar and the political complexity, a 2026 passage is unlikely. A 2027 framework is more plausible if political conditions remain favorable.
The workforce title is independent. Even if the frontier governance provisions stall, Title II's workforce provisions, 90-day notice for AI-driven displacement, may move separately or be absorbed into other labor legislation.
For the parallel legislative developments on AI taxation and workforce displacement, see Anthropic's UBI proposal and the Sanders sovereign wealth fund bill. For the current patchwork of state AI laws the preemption would affect, multi-state AI compliance 2026 maps the obligations by jurisdiction.
How the draft compares to other 2026 AI frameworks
Enterprise compliance teams managing multiple AI governance frameworks will find it useful to situate the Great American AI Act discussion draft within the broader landscape of AI regulations in force or under development:
vs. EU AI Act. The EU AI Act uses a risk-tiered approach, imposing obligations based on the application's risk level rather than the developer's revenue. The Great American AI Act focuses on the developer and training process. A company that develops a frontier AI model faces obligations under the US draft at the development stage; the same model faces EU obligations at the deployment stage. These are complementary, not conflicting, but the compliance touchpoints are different.
vs. One Big Beautiful Bill preemption. The OBBB's AI preemption provision, which the Senate stripped 99-1, would have imposed a 10-year freeze on all state AI development laws. The Great American AI Act's 3-year moratorium is narrower, targeting development-stage regulation specifically, and is structured as a compromise rather than a unilateral federal override. If the GAAI Act advances, it represents a more durable preemption approach because it has bipartisan support.
vs. NIST AI RMF. The NIST AI Risk Management Framework is voluntary. The Great American AI Act would make third-party audits mandatory for large frontier developers. If the bill passes, the NIST RMF's voluntary practices for governing AI risk could become the baseline against which third-party auditors measure compliance, making voluntary adoption now a form of pre-compliance preparation.
vs. White House AI Executive Orders. The Trump administration's AI executive order framework emphasizes voluntary commitments and reducing regulatory burden. The Great American AI Act's mandatory audit requirements are partially in tension with this approach. The bipartisan nature of the bill is its insulation against administrative opposition, but the White House's posture toward mandatory audits will be a key factor in whether the bill advances.
For enterprise teams, the practical question is whether to treat the GAAI Act as a compliance planning input now. The answer depends on how quickly the bill moves and how close to the $500M frontier developer threshold your organization is. Most enterprise AI users, not developers, fall outside the bill's primary obligations even if it passes as drafted.
Related Reading
- Anthropic AI tax proposal and Sanders sovereign wealth fund bill 2026
- Pentagon Grok AI and human oversight: Gillibrand Act explained
- One Big Beautiful Bill: what the Senate AI preemption vote means
- Multi-state AI compliance: which laws apply to your business
- AI governance checklist 2026
- AI vendor due diligence in 30 minutes
- AI workforce displacement and the WARN Act: what HR teams need to know in 2026
