Commentary. The United States is regulating artificial intelligence in the least satisfying way possible: rapidly enough to create uncertainty, but unevenly enough to leave major risks unresolved. California and Connecticut are adding obligations for transparency, automated employment decisions and frontier-model developers, while Washington still has no comprehensive federal AI statute. That patchwork is not merely an administrative nuisance. It is becoming a policy choice with consequences for workers, consumers and the companies expected to build the next generation of systems.

Our view is straightforward: the country needs a federal baseline of enforceable safeguards, not a race among states to write incompatible rules. That baseline should focus on demonstrable harms—fraud, discrimination, unsafe autonomous behavior, privacy violations and failures to disclose synthetic content—while leaving room for experimentation in lower-risk applications.

The case for a national floor

Businesses operating across state lines cannot sensibly treat every AI deployment as a separate legal universe. California’s revised transparency requirements and Connecticut’s first wave of AI duties illustrate how obligations are accumulating at the state level, while Colorado continues to develop its own framework.[1] This may produce useful policy experimentation, but it also raises compliance costs and invites strategic loopholes: companies may design to the weakest applicable standard, or avoid smaller markets rather than adapt responsibly.

A federal law could set common minimum requirements without preventing states from going further. It should require risk assessments for high-impact systems, meaningful human oversight, incident reporting and clear explanations when AI materially affects employment, credit, housing, education or access to essential services. Regulators should also have the authority to inspect evidence rather than rely on corporate promises.

“Testing before regulation” is a legitimate principle—but testing must not become an excuse to postpone basic protections indefinitely.

The strongest counterargument

Critics are right to warn that badly designed rules could entrench large incumbents. Extensive documentation and approval procedures may be manageable for technology giants but prohibitive for small firms, universities and public-interest developers. Broad definitions of “frontier” or “high risk” could also sweep in ordinary tools that pose little danger, chilling research and slowing productivity gains.

Those concerns deserve more than ceremonial acknowledgment. Regulation should be proportionate, with simplified duties for small deployers, safe harbors for open research and regularly reviewed thresholds. Liability should follow control: a company deploying an AI system in a consequential decision should bear more responsibility than a developer whose general-purpose tool is used unpredictably by a third party.

Nor should lawmakers pretend that every risk can be solved through model rules. Existing consumer-protection, civil-rights and workplace laws already address many harms. The better approach is to clarify how those laws apply to AI, fund enforcement agencies and require companies to preserve the records needed to investigate failures.

Why delay is also a decision

The policy vacuum is not neutral. The UK’s Department for Science, Innovation and Technology has issued an AI risk-management toolkit for public-sector bodies, while financial regulators are warning that frontier models with cyber capabilities may accelerate vulnerability discovery faster than firms can respond.[2] These developments show that the practical question is no longer whether AI governance will exist. It is whether governance will be coherent, independently enforced and capable of responding before preventable harm becomes systemic.

Congress should therefore establish a floor now, with sunset reviews and evidence-based updates rather than a one-time attempt to predict the technology’s future. The aim should not be to guarantee that no AI system ever fails. That standard would be impossible and would push innovation into less visible channels. The aim should be to ensure that failures are detectable, contestable and costly enough to discourage recklessness.

America does not need a regulatory monument. It needs a dependable building code: basic rules that apply everywhere, inspectors with real authority and room for responsible architects to innovate. A fragmented system may be politically convenient, but it is not a serious answer to a technology already shaping decisions at national scale.

Sources