The Federal AI Bill Isn't About Your Business - And That's the Problem

Based on the House discussion draft introduced June 2, 2026. This analysis reflects the draft text; final legislation may differ.

---

The Great American AI Act is primarily a frontier model governance bill. Its core regulatory framework targets a small group of companies that trained large AI foundation models using extraordinary compute and cleared a $50 million revenue threshold. If your company isn't in that group, Title I has limited direct application to you.

Two provisions in the bill do apply broadly to any employer using AI. The bill's preemption structure also has real consequences for how businesses think about state law compliance. Those are the parts worth understanding.

Who the bill actually regulates

The bill defines a "frontier model" as a foundation model trained using more than 10^26 integer or floating-point operations -- cumulative across the original training run plus any subsequent fine-tuning or substantial modification. That is an extraordinarily high compute threshold. The models that clear it today come from the largest AI labs.

A "frontier developer" is an entity that trained or initiated training of a frontier model and had more than $50 million in gross revenue (with affiliates) in the prior year. A "large frontier developer" clears the same compute bar with $500 million or more in revenue.

California's SB 53, which uses an identical threshold, identified roughly 5 to 8 companies currently qualifying. That number will grow as models scale, but it's a narrow group today.

Title I obligations for large frontier developers include publishing a frontier AI framework covering catastrophic risk assessment and mitigation, submitting to independent third-party audits by licensed verification organizations, reporting critical safety incidents, and publishing transparency reports before deploying new models or material updates. These are substantive compliance obligations. They're also calibrated to entities with the engineering resources and organizational infrastructure to carry them out.

If your company licenses AI from a provider, deploys AI applications built on a foundation model, or uses AI in internal operations, you're downstream of that framework. You're a deployer. Title I is not your regulatory framework.

The preemption provision and what it does for deployers

The bill's preemption provision (Sec. 121) has drawn significant attention. Read carefully, it's narrower than it appears.

The bill preempts state laws "specifically regulating the development of any artificial intelligence model." Development, as defined in the bill, covers training, fine-tuning, substantial weight modification, and pre-deployment safety evaluation. This provision addresses the concern that a patchwork of state-by-state training-phase mandates would fragment AI development oversight. It's a win for frontier labs. It's not a win for businesses deploying AI.

The bill explicitly preserves state authority over:

"activities occurring upon or after the deployment of an artificial intelligence model, including any law or regulation governing the implementation, deployment, distribution, offering, or use of any artificial intelligence system, product, or service that incorporates or is derived from an artificial intelligence model."

That's the deployer side of the ledger, preserved in full.

The bill also separately preserves "any State law or regulation of general applicability." State anti-discrimination laws, consumer protection statutes, employment law, biometric privacy laws, and common law tort claims -- none of those are preempted. The preemption scope is limited to state laws specifically targeting AI model development.

A business deploying AI cannot use the GAAIA as a preemption argument against state law obligations. The bill's text says it doesn't cover that ground.

One additional constraint: the preemption provision has a 3-year sunset. Without reauthorization, it expires. Even the narrow development-phase preemption is temporary.

The state law compliance picture

The practical result of the preemption structure is that every active state deployer obligation remains fully in force.

Illinois HB 3773 took effect January 1, 2026. It prohibits use of AI in employment decisions that discriminate based on protected characteristics, and the Illinois Department of Human Rights issued draft rules requiring notice to employees and applicants when AI is used to influence a hiring, promotion, or termination decision.

California finalized FEHA regulations governing employer use of automated decision systems (ADS), effective October 1, 2025. The regulations apply to any computational tool used in employment decisions, cover employers with 5 or more employees, and require 4-year retention of AI-related records including dataset descriptions, scoring outputs, and audit findings. Courts and agencies may consider the absence of bias testing as evidence in discrimination cases, which effectively creates a practical incentive for audits.

New York City Local Law 144 requires independent bias audits for automated employment decision tools, public posting of audit results, and advance notice to candidates before use. After a December 2025 comptroller's audit found enforcement had been largely ineffective, the city committed to significantly stricter enforcement in 2026.

Colorado repealed and replaced its original AI Act (SB 24-205) with SB 26-189, signed May 14, 2026 and effective January 1, 2027. The new law scales back significantly, eliminating mandatory impact assessments and risk management programs in favor of a disclosure-based framework with targeted healthcare provisions. The compliance burden dropped, but the law remains.

Texas HB 149, effective January 1, 2026, prohibits use of AI systems that intentionally discriminate against members of a protected class. The intent standard is higher than California's or Illinois's, making it more employer-friendly, but the obligation is real.

Layer existing federal law on top: FCRA adverse action requirements for AI-driven credit and employment decisions, ECOA model explainability obligations for AI-assisted lending, FHA restrictions on AI-driven tenant screening and advertising, and EEOC disparate impact analysis applied to AI hiring tools. None of that is new to the GAAIA. AI deployment in regulated contexts just gives those frameworks more places to apply.

Two things the GAAIA did change for average businesses

Whistleblower protection (Sec. 113)

This provision covers any employer engaged in commerce. Its scope is not limited to frontier developers.

An "AI violation" means any violation of federal law related to the development, deployment, or operation of AI. The protected individual includes current and former employees and current and former independent contractors. Protected activity includes reporting to a supervisor, not just to external regulators or government agencies. The employer doesn't need to know the employee actually violated any law -- the employee only needs a reasonable belief that a violation occurred.

The bill imports the Air Carrier Whistleblower burden of proof standard (49 U.S.C. 42121(b)). Under that standard, the employee must show that protected activity was a contributing factor in the adverse action. That's a lower bar than but-for causation. The burden then shifts to the employer, who must prove by clear and convincing evidence that it would have taken the same action regardless of the protected activity. That's a high bar to clear.

Mandatory arbitration clauses are void for these claims. Jury trial is available in federal district court. The statute of limitations runs 6 years from the violation or 3 years from discovery, with a 10-year outer limit. Relief includes reinstatement, 2x back pay with interest, compensatory damages, expert fees, and attorney fees.

Any internal complaint about an AI system -- raised to a manager, an HR officer, or a compliance team member -- is now a protected compliance complaint. The same response protocol that governs internal discrimination complaints applies: route through legal and HR, preserve records, separate the decision-makers from the complaint, and document the investigation. The employment law exposure is structurally similar to what employers already manage for harassment and discrimination complaints.

WARN Act disclosure (Sec. 251)

When AI was a substantial factor in a mass layoff that already requires WARN notice, the notice must now include a statement that AI contributed, identify the type and usage of the AI involved, estimate the percentage of job losses attributable to AI, and describe any upskilling or retraining steps taken before the layoff. A good-faith compliance standard applies.

The provision requires documentation most organizations don't currently maintain. If AI is part of workforce planning, the record needs to exist before any reduction is announced: what tools were used, in what context, for which decisions, and with what human oversight. A reduction in force involving AI is no longer just a communications and severance exercise. It's also a documentation obligation.

The practical takeaway

The GAAIA discussion draft confirms what the state law landscape has been signaling for two years: AI governance is moving from voluntary principles to documented accountability. The bill adds federal evidence of that shift without changing the operational compliance picture for most businesses.

If your organization can't explain where it uses AI, what laws apply to those uses, who owns the risk when something goes wrong, and how employees can safely raise concerns without retaliation, the problem isn't the GAAIA. The gap between where most organizations are and where the law expects them to be is the work -- and it predates this bill.

The right project isn't a GAAIA compliance program. It's an AI use inventory mapped to current state law obligations, an internal complaint process that routes AI concerns through legal and HR, layoff documentation that accounts for AI's role in workforce decisions, and vendor diligence that reflects what accountability now looks like. The federal bill didn't create those obligations. It made clear they're not optional.

---

Jeremy Harris is a privacy, cybersecurity, and AI governance advisor. JHarris Advisory helps organizations build AI and privacy governance programs from operations, not theory. This article reflects general analysis of publicly available legislative text and does not constitute legal advice.

Previous
Previous

HIPAA Series: Risk Analysis - OCR's Most-Cited Deficiency - And Most Entities Are Still Failing It

Next
Next

HIPAA Series: “We'll Get to It" Just Expired - Encryption is here