Congress Moves at Tech Pace: The FRONTIER Act

Crossposted from canaryinstitute.ai/blog/frontier-act-tech-pace.

Related postsThe Best AI Bill Congress Hasn't Introduced Yet — my section-by-section read of the GAAIA discussion draft this bill grew out of; this post assumes you've at least skimmed it.

Just two days ago I wrote about the Great American AI Act (GAAIA), a 269-page discussion draft that struck me as "the best AI bill that Congress hasn't introduced yet". I ended by hoping that Congress might start moving at tech pace, rather than policy pace; I didn't expect that to change this soon, but it has.

On July 23, Representatives Obernolte and Trahan, joined by four bipartisan cosponsors (Peters, Franklin, Subramanyam, and Houchin), introduced the frontier-oversight core of GAAIA as a real bill: the Frontier Risk Oversight, National Transparency, Independent Evaluation, and Reporting (FRONTIER) Act. Someone really, really worked for that acronym, and I salute them. Seven weeks from discussion draft to introduced legislation is fast for Congress on anything; for AI, where the standing complaint is that they've been asleep at the wheel, it's astounding. This wasn't a panic bill scribbled over a weekend; the revision shows seven weeks of actual work, with gaps closed, clocks tightened, and new teeth added. The sponsor statements make it clear that they were watching the same news as the rest of us.

The world has far fewer skeptics this week than it had last week. Last week AI oversight was somewhere between "fringe issue" and "bargaining chip", but now there are going to be interesting fights about the details... I think this is what "waking up" looks like.

What the bill is

FRONTIER is the core part of GAAIA, stripped of a lot of the horse-trading machinery (workforce, cybersec, and R&D sections) that I'm guessing was being used to gain traction. Instead it's just the fundamental pieces: transparency requirements, independent audits, incident reporting, an emergency authority, and preemption of state law, now scoped to three specific functions rather than GAAIA's blanket development-side rule (as before, states can still regulate deployment).

It is still a visibility bill at heart, but this time visibility comes with a switch attached, which I'll get to.

There are now 3 coverage categories instead of 2. With FRONTIER, any developer training a model past 10^26 ops is a "frontier developer" and owes transparency reports and incident reporting

"large" developers have $50M in revenue plus $1B in AI development spending over a rolling 36 months; they additionally owe a published safety framework, an annual independent audit, and registration

"very large" developers are bumped up to $5B / $10B; they have the same requirements as "large", but also retain a licensed independent verification organization for ongoing assessment. The top tier is roughly five companies.

They fixed my favorite complaint

In the GAAIA post I pointed out that the draft's revenue-only thresholds let a capital-rich, revenue-free lab train frontier models while owing nothing, which I thought of as the "Ilya loophole". FRONTIER fixes this, so now the base tier has no revenue floor at all: train past the compute line and the transparency and incident-reporting duties apply from the first day that the threshold was crossed (not at the end of the fiscal year). A new "AI-related development expenditures" test (deliberately written to ignore accounting treatment, so spending counts whether it's expensed, capitalized, deducted, or amortized) catches labs with modest revenue and enormous spend at the heavier tiers. They might change the registration requirements down to base tier, but even if they don't, I think we'll find out what Ilya's been up to. Last I heard, SSI was worth $32B, and had ~320 words on the website, which is a cool $100M/word (Rudyard Kipling's shilling, eat your heart out).

Along with that, they've sped up the incident-reporting clock, from 15 days under GAAIA to 72 hours under FRONTIER. Given this week's roller-coaster, probably a good call.

The bill also creates the first federal registry of frontier developers (the "large" tier and up), which is public, and requires beneficial-ownership disclosure, so we'll finally see who is operating at frontier scale... and Commerce, at least, will know who owns them. It also orders GAO to report annually on whether the audit industry remains independent of the target industry, so the lessons from finance haven't been forgotten.

We can see a lot, but still only act on large events

FRONTIER defines "critical safety incident" with four independent triggers, and three of them don't require any harm at all:

unauthorized access to model weights

a model using deception against its own developer to subvert controls (outside a test designed to elicit that)

loss of control of a model: no body count, no dollar figure, no showing of catastrophic risk

I'm not a lawyer, but this reads to me as a model that breaks out of its testing sandbox has evaded its developer's control, period. Under this bill that's a federal report due in 72 hours, period.

It's essentially impossible to make a networked environment truly secure; the perimeter always leaks. So if every escape is a mandatory report, a lab can't just patch the sandbox and move on... instead they might have to make models that don't try to escape. That's probably great, but remember there are two ways to make escapes stop: align the model, or teach it to escape only when nobody's watching. From outside, both look like fewer reports, but the second is more concerning. The drafters seem aware of it, since the deception trigger is scoped to behavior outside of designed evals (which is the stealth case), but mandatory reporting isn't an alignment guarantee. It's legitimate pressure against pure "speed at all costs", and I'll take it.

Meanwhile, everything with actual teeth (the emergency authority, the standard auditors certify against) applies when there is "catastrophic risk": 50-plus deaths or serious injuries, or a billion dollars in property damage, from a single incident. I think the thresholds are probably "as low as they think they can get away with", and I'm glad they exist at all; having coherent and universally-applied laws is an important part of liberalism.

Visibility is also especially valuable right now. Today's misaligned models are loud: they cheat, they don't hide it well, and they don't seem to care much about getting caught. That's a property of how they're trained, not a law of nature, and training against detected misbehavior (which is the only kind you can train against) mostly selects for quieter misbehavior (this, incidentally, is the alignment problem in a nutshell). That signal is cheap today, but it won't stay cheap.

Two things FRONTIER doesn't have

First, there's still no severability language. Nothing ties the preemption to the federal duties, so if a court strikes the transparency sections (the NetChoice playbook writes itself), the preemption stands alone, permanently. Nobody wants that outcome, including the sponsors. One sentence fixes it; I said that two days ago too. The preemption itself did get narrower: it's scoped to three functions (transparency, third-party audits, incident reporting), with carve-outs for general law, deployers, protection of minors, and states' own AI procurement. The sponsor's summary lists which existing state laws would be overcome (California's SB-53, New York's RAISE Act, Illinois's SB-315). Displacing named state laws while your own duties might not survive review is, uh, a bold bet.

Second, the whistleblower protections. GAAIA's whistleblower title was its best-thought-out provision: whole-industry coverage, non-waivable rights, no sunset. FRONTIER contains not one word of it. The omission is odd, because the bill builds the reporting channel: the confidential incident mechanism accepts submissions from "a frontier developer or member of the publi…

添加评论
点赞收藏
点踩分享查看原文
评论
?
参与讨论