DEV Community

Auton AI News
Auton AI News

Posted on Originally published at autonainews.com

US AI Security Laws Take Center Stage in 2026

Key Takeaways

  • President Trump’s Executive Order 14409 (June 2, 2026) created a voluntary framework for frontier AI developers to engage with federal agencies on national security assessments, explicitly ruling out mandatory pre-deployment licensing.
  • The Commerce Department’s June 2026 Is-Informed Letter to Anthropic, requiring export licenses for its Mythos and Fable models after researchers found bypassable safety guardrails, marks the first time the US has applied export controls directly to AI model weights.
  • The American AI Security Act, introduced September 18, 2026, would require mandatory NSA review of powerful AI models before release, putting Congress on a direct collision course with the administration’s voluntary approach. Congress and the White House are pulling US AI policy in opposite directions. On September 18, 2026, Representative Josh Gottheimer, co-chair of the House AI Commission, introduced the bipartisan American AI Security Act with Representative Mike Lawler (R-NY), proposing mandatory national security reviews for the most powerful AI models before deployment. The bill sits in direct tension with President Trump’s Executive Order 14409 from June 2, 2026, which built a voluntary framework around industry collaboration and explicitly ruled out mandatory pre-deployment licensing.

Security Mandates Take Shape

Executive Order 14409, titled “Promoting Advanced Artificial Intelligence Innovation and Security,” put national security at the centre of federal AI policy. The order directed the Department of the Treasury, the NSA and the Cybersecurity and Infrastructure Security Agency to develop a classified benchmarking process for assessing the advanced cyber capabilities of frontier models and defining what qualifies as a “covered frontier model.” It also called for an AI-cybersecurity clearinghouse within 30 days to coordinate vulnerability scanning, validation and patch distribution, and provided for secure early access for trusted partners. The order was explicit, however, that none of this authorises mandatory licensing or preclearance requirements for AI development. That voluntary posture has become harder to defend as model capabilities advance.

Export Controls Reach AI Model Weights

The Commerce Department’s June 12, 2026 Is-Informed Letter to Anthropic was a significant departure from existing export control practice, which had focused on hardware. The letter required Anthropic to obtain a licence before exporting, re-exporting or transferring its Mythos and Fable models, including to foreign nationals employed by Anthropic inside the United States. The trigger was a reported method for bypassing the models’ safety guardrails in ways that could expose unrestricted cybersecurity capabilities, including identification of zero-day vulnerabilities and generation of exploit code. Anthropic temporarily disabled both models globally, citing the technical difficulty of restricting access only for foreign persons on short notice. On June 26, Commerce issued a follow-up letter exempting Mythos 5 access for roughly 100 trusted companies and federal agencies, though Fable 5 remained restricted. On June 30, the Department fully lifted export controls on both models, and Anthropic restored global access to Fable 5 on July 1, continuing to expand Mythos 5 access through its Glasswing program. The episode established that the federal government is prepared to regulate model deployment directly on national security grounds and to reverse course quickly once negotiated safeguards are in place.

Congress Pushes for Mandatory Reviews

Gottheimer, co-chair of the House AI Commission, framed his American AI Security Act as a direct response to the administration’s voluntary approach. The bill would require developers to grant the NSA full access to evaluate models before release, specifically for their potential use in cyberattacks or in facilitating the development of chemical, biological or radiological weapons. Alongside it, Gottheimer introduced the China FIREWALL Act, which would bar federal agencies from procuring or using Chinese-developed open-weight AI models on government systems, a separate front in the same national security argument. Earlier legislative proposals in 2026 include Senator Marsha Blackburn’s TRUMP America AI Act from March, which proposed new liability standards and mandatory third-party audits, and the bipartisan Great American Artificial Intelligence Act of 2026 discussion draft from Representatives Jay Obernolte and Lori Trahan, seeking a comprehensive federal framework. None of these has advanced to a floor vote.

State Rules Fill the Federal Vacuum

With no comprehensive federal AI law in place, states have continued legislating independently, and the picture is neither uniform nor converging. Trump’s December 2025 Executive Order 14365 created an AI Litigation Task Force to challenge state laws deemed onerous and threatened to withhold federal funding from states whose AI rules conflicted with federal objectives, but the order carved out child safety, AI compute infrastructure and state procurement, implicitly acknowledging that federal preemption has limits. As of March 2026, lawmakers in 45 states had introduced 1,561 AI-related bills, a volume that reflects the scale of the gap Washington has left open.

The resulting patchwork is uneven. California’s Transparency in Frontier AI Act (SB 53), effective January 1, 2026, requires developers of large frontier models trained with over 10^26 FLOPS to publish risk frameworks and report safety incidents, with penalties up to $1 million per violation. Governor Newsom compounded this on September 18, 2026, with an executive order advancing independent oversight and directing exploration of an AI kill switch, a measure that has drawn attention from other observers of state-level AI governance. Colorado moved in the opposite direction: it repealed its earlier comprehensive AI Act in May 2026 and replaced it with a narrower statute (SB 26-189), effective January 1, 2027, focused on automated decision-making in consequential decisions and dropping earlier risk management program requirements. Illinois enacted its Artificial Intelligence Safety Measures Act in July 2026, imposing transparency and catastrophic-risk management obligations for frontier developers; disclosure requirements take effect January 1, 2027, with the framework-publication and third-party audit requirements following in January 2028. The fragmentation this creates for multi-state operators is real and, for now, unresolved and it sits alongside a separate, unrelated trend of some AI products, like ByteDance’s Dola, opting out of the US market entirely for reasons that go well beyond AI-specific state law.

NIST Standards Under Pressure

The National Institute of Standards and Technology has kept pace with the legislative activity, though its output remains voluntary. On July 29, 2026, NIST released an initial public draft of guidance and templates for public-facing AI documentation, seeking input on an approach it described as an AI standards “zero draft.” On April 7, it released a concept note for an AI Risk Management Framework profile on trustworthy AI in critical infrastructure, aimed at guiding operators managing AI-enabled risks. The existing NIST AI RMF 1.0, while technically voluntary, has become operationally mandatory for federal agencies and contractors through Executive Order 14110 and procurement requirements. The most recent addition, SP 1353, published August 19, is a quick-start guide for using generative AI in Cybersecurity Framework compliance. It offers structured prompts for CSF analysis and reporting but introduces a concern that NIST itself flags: organisations following the guide risk exposing sensitive internal policies and audit findings to the AI systems processing them. Public comment on SP 1353 closes October 15, 2026. The divergence between US and UK approaches to AI security standards adds further context to where NIST’s voluntary framework sits internationally.


Originally published at https://autonainews.com/us-ai-security-laws-take-center-stage-in-2026/

Top comments (0)