The Great American AI Act: What businesses need to know
On June 4, 2026, Representatives Jay Obernolte (R-CA) and Lori Trahan (D-MA) released a discussion draft of the Great American Artificial Intelligence Act of 2026 (GAAIA). This bipartisan legislation would create the first comprehensive federal framework for governing AI in the United States. The nearly 270-page draft is intended to solicit feedback from stakeholders, experts and the public before the bill is formally introduced to Congress. The bill contains four major titles: (i) Frontier AI Governance; (2) Workforce; (3) Cybersecurity; and (4) Research, Development, and International Cooperation.
Transparency and auditing requirements
The legislation requires front AI model developers to disclose information about those models, obtain third-party audits through designated Independent Verification Organizations (IVOs), and refrain from retaliating against whistleblowers. These requirements draw heavily from recently enacted frontier model laws in California, New York, and Illinois. Privacy professionals should note that the bill’s transparency requirements for frontier models may create new disclosure obligations that intersect with existing data governance framework.
Federal preemption of state laws
Perhaps the most consequential element of the draft is its three-year preemption of state laws “specifically regulating the development of” any AI model. The draft broadly defines “development” as “acts performed or directed by a developer prior to its deployment.” Notably, the preemption does not apply post- development and does not preempt state laws of “general applicability.” This means that many existing state privacy and consumer protection laws, such as the California Consumer Privacy Act (CCPA) and Virginia’s Consumer Data Protection Act, would remain unaffected.
While the preemption provision is limited to AI model “development,” the precise boundary between development-stage and deployment-stage practices (particularly regarding training data collection and processing) will require businesses to analyze the bill carefully as it evolves.
Codification of the Center for AI Standards and Innovation
The bill would formally authorize the Center for AI Standards and Innovation (CAISI) within the Commerce Department, allocating $100 million per fiscal year for fiscal years 2027 through 2029. The Center would develop voluntary guidelines, best practices, and standards for AI security, in addition to evaluating AI systems and monitoring AI progress.
Cybersecurity provisions
The legislation would also extend the Cybersecurity Information Sharing Act of 2015 through fiscal 2035, allowing companies to share cyber threat information without incurring antitrust liability.
What’s next?
The GAAIA remains a draft, and its sponsors are seeking feedback. The House Democratic Commission on AI has already framed itself in opposition hours after the draft’s release, leaving the bill’s path to formal introduction or even passage filled with uncertainty. Nevertheless, the draft signals a bipartisan effort to move beyond the current patchwork of state-level AI regulation. Businesses should be prepared to engage with the draft’s evolving provisions.
Stay tuned! McDonald Hopkins will continue to monitor developments as this legislation progresses through the feedback process and even towards potential formal introduction.