Sen. Maria Cantwell of Washington has introduced a comprehensive framework under which the most powerful artificial intelligence systems would not be allowed on the market without federal standards, independent evaluation and mandatory reporting of serious failures. It is not yet a bill, but rather an attempt to set a benchmark for Congress in the final weeks before the November elections, when lawmakers agree on only one thing: technology is advancing faster than the rules governing it.
Cantwell’s proposal is not focused on familiar chatbots that help write an email or choose a recipe, but on so-called frontier models — systems capable of carrying out complex autonomous tasks and potentially useful for cyberattacks or for creating hazardous chemical, biological, radiological or nuclear materials. The senator proposes that the National Institute of Standards and Technology, or NIST, along with other federal agencies, develop clear, measurable and mandatory requirements for such models.
The central principle of her framework is simple and highly unusual for the U.S. technology sector: a developer should not be the sole judge of the safety of its own product. Cantwell proposes ongoing stress testing of models by government officials and independent experts, as well as external audits comparable to the financial reviews required of publicly traded companies. Before a system covered by the new risk criteria is released, independent evaluators would have to confirm that its safeguards actually work.
A separate section addresses what usually remains behind the closed doors of laboratories: incidents. Under the plan, companies would have to promptly report losses of control over autonomous agents, the emergence of dangerous cyber capabilities, the bypassing of safety barriers and failures related to models’ self-improvement. Cantwell also proposes protecting employees and contractors who report violations from dismissal and other forms of retaliation. Developers would remain civilly and criminally liable for foreseeable harm resulting from design, deployment or inadequate safety measures.
The formula echoes a long-running debate over who can assess technological risk more reliably: the industry itself or the government. In September, it was reported that Cantwell had diverged from Sens. Ted Cruz, John Thune and Amy Klobuchar over a draft of future legislation. According to sources familiar with the negotiations, she insisted that models undergo mandatory reviews by federal entities, including national laboratories and relevant agencies, while the alternative approach relied more heavily on assessments conducted by the companies themselves.
For Cantwell, this is not a sudden shift. In 2024, when she chaired the Senate Committee on Commerce, Science and Transportation, the committee approved a package of bipartisan initiatives: the Future of Artificial Intelligence Innovation Act, the TEST AI Act, a bill on AI testing for national-security purposes, and the VET AI Act, which addressed standards for evaluating and validating systems. The committee’s work did not become a comprehensive federal regulatory regime. Cantwell now argues that the country has lost time as model capabilities and concerns about their autonomy have grown.
Cantwell’s current framework extends well beyond national security. It calls for protecting children from addictive and harmful AI products, retraining and apprenticeship programs for workers, and the right for people to learn how an algorithm influenced a decision about employment, credit or medical care — and to seek a review of that decision by a qualified professional. The document specifically mentions the WISeR system used in Medicare, which has raised questions about whether automation is delaying medically necessary care.
For Washington state, the debate hits particularly close to home: Microsoft, Amazon and a significant share of the cloud infrastructure supporting the current computing boom are located there. Cantwell is not proposing to slow the American technology race, but to tie leadership to trust — by creating common standards with allies, sharing information about dangerous incidents and even establishing a secure communications channel with China in case of a major failure. Yet a wide political gap remains between principles and legislation. Congress still must decide whether these requirements will be mandatory, who exactly will conduct the reviews and whether the technology industry will accept oversight before the next model is already in the hands of millions of users.
Based on: Cantwell unveils AI safety framework as Congress stalls ahead of election