AI News HubLIVE
In-site rewrite5 min read

The U.S. has 1,200 AI bills and no good test for any of them

The U.S. has introduced over 1,200 AI-related bills in 2025, but lacks a unified evaluation standard. The article analyzes the fragmented policy landscape and proposes a three-stage test framework to determine which regulations are truly necessary.

SourceHacker News AIAuthor: Brajeshwar

Commentaryregulation

The U.S. has 1,200 AI bills and no good test for any of them

By

Jeffrey Sonnenfeld

Jeffrey Sonnenfeld,

Gary Marcus

Gary Marcus, and

Stephen Henriques

Stephen Henriques

By

Jeffrey Sonnenfeld

Jeffrey Sonnenfeld,

Gary Marcus

Gary Marcus, and

Stephen Henriques

Stephen Henriques

May 15, 2026, 5:00 AM ET

FBI Director Kash Patel (R) speaks next to Micron CEO Sanjay Mehrotra (2nd L) and IBM CEO Arvind Krishna (2nd R) at a Diwali celebration with US President Donald Trump and Indian American leaders in the Oval Office of the White House in Washington, DC, on October 21, 2025. ANDREW CABALLERO-REYNOLDS/AFP via Getty Images

In an interview this week on Fox Business, IBM Chairman and CEO Arvind Krishna pressed Washington on the central question facing AI policy: “The balance between too many regulations, it’s terrible; too few, we may not love the outcome, so we got to find the Goldilocks middle.” Krishna extended his warning to the international landscape: “If it turns into a bloated bureaucracy, that would not be so good for us to win the AI race.”

The balance Krishna identifies extends well beyond federal policy. It runs downward into a state-by-state patchwork of legislation now reshaping how American companies build and deploy AI, and upward into a global contest where technological competitiveness underwrites both economic prominence and national security. No clear path forward has emerged at any level. In our conversations with CEOs and political leaders, that lack of clarity is the common refrain.

In the past nine months, the United States has produced more AI legislation than in the prior decade, and on three different theories of what AI policy is supposed to do. California’s SB 53 focuses on transparency from frontier developers. New York’s Responsible AI Safety and Education (RAISE) Act mandates stricter incident reporting and a new oversight office inside the Department of Financial Services. The Texas Responsible Artificial Intelligence Governance Act (TRAIGA) prohibits specific intentional misuses and establishes a 36-month regulatory sandbox. Connecticut joined two weeks ago, when both chambers passed Senate Bill 5 (SB5) by lopsided margins after years of failed attempts.

Meanwhile, federal policy has lurched in opposite directions. President Trump’s December 11 executive order directed the Department of Justice to challenge state AI laws and conditioned broadband funding on alignment with a “minimally burdensome” national standard. The 2026 National Defense Authorization Act (NDAA), signed the day before, excluded preemption language entirely. In April, Anthropic’s disclosure of Mythos Preview, a model withheld from public release due to its autonomous cyber capabilities, introduced a new category of risk into a federal conversation unprepared to absorb such capabilities. The scare has reportedly prompted the White House to consider an executive order establishing an FDA-like pre-release vetting system for advanced AI models—an idea proposed by the second author to the U.S. Senate in 2023.

All this unfolds against a sharper international backdrop. The EU is implementing the AI Act, and China is deploying frontier capability under state direction, while the line between commercial AI and national-security capability is collapsing—raising the cost of incoherent U.S. policy.

By one count, state legislatures introduced over 1,200 AI-related bills in 2025 and enacted just under 150, with the pace accelerating since. Beneath the volume lies a more fundamental problem. Policymakers at every level are working without a shared test to determine whether their legislative efforts constitute good policy.

Why the Current Debate is Stuck

Too often, the debate has been framed as a binary choice between sweeping regulation and unrestricted operation, as though there were no middle ground, and with too little attention given to how proposals might conflict with existing law. Both sides talk past each other because neither has a clear test for which specific regulation, aimed at which actor, addresses which gap, and at what cost to whom, is actually necessary.

At the state level, most bills attempt to regulate “AI” as a category even though many uses sit cleanly within existing consumer protection, civil rights, intellectual property, and data privacy law. Colorado and Utah passed omnibus statutes “with reservations” in 2024, attaching sunset clauses and delayed effective dates that signaled their drafters’ uncertainty, and both states are now visibly retreating.

Colorado passed a “repeal and reenact” maneuver in its final session weeks to roll back onerous audit mandates in favor of targeted transparency. Utah narrowed its disclosure rules, extended the sunset to 2027, and swapped additional omnibus attempts for nine surgical bills targeting chatbot medical advice, AI-generated defamation, and child protection. In Connecticut, a broad 2025 bill died in the House amid a gubernatorial veto threat, while the narrower Connecticut Artificial Intelligence Responsibility and Transparency Act (SB 5) passed in its place two weeks ago, replacing mandatory developer audits with consumer transparency measures.

Yet these narrower successors still impose new compliance burdens beyond those imposed by existing civil rights and consumer protection law. Across statehouses, the same pattern is recurring. Well-intentioned legislation that, read carefully, replicates existing protections at the cost of substantial new compliance burdens.

At the federal level, three live propositions each flop on different grounds. Broad state preemption, in the form of presidential executive authority and the failed congressional moratorium, trades real protection against demonstrable harms, such as deepfake-generated child sexual abuse material (CSAM), AI-driven election fraud, and automated hiring discrimination, for the illusion of federal uniformity. Mandatory frontier-model approval, as currently floated, is poorly targeted and creates an incumbent moat that locks in the largest developers; however, perhaps a better version could be formulated. Capability-specific oversight of frontier models that can autonomously generate cyber exploits or Chemical, Biological, Radiological, and Nuclear (CBRN)-relevant content—the one area where federal action is genuinely needed—is where the federal conversation is not productively focused.

International approaches sharpen the contrast. The EU AI Act applies a tiered, risk-based regime with prescriptive compliance requirements scaled to system risk. China pairs state-directed deployment with detailed sectoral rules—algorithmic recommendation, generative AI, and deep synthesis—under national security review. Singapore and the UK have positioned themselves as governance hubs through voluntary frameworks, model sandboxes, and active industry partnerships. Each is a different bet on the same underlying tradeoff between innovation pace, harm reduction, and national security. The U.S. is currently betting without clearly identifying which bet it has placed.

The common failure is the lack of a structured method for determining whether a proposed rule effectively addresses the gap. A three-stage test offers a clear solution.

The Framework: A Three-Stage Test

Stage 1: The Target Specificity Question

Before evaluating any tradeoffs, a single test should be applied: if “AI” were replaced with “technology” or “software” in the bill text, would existing law already address the harm?

The specificity test is not hypothetical. Connecticut Attorney General William Tong issued an advisory memorandum on February 25, 2026, outlining how Connecticut’s existing civil rights, privacy, data security, competition, and consumer protection laws already apply to a substantial share of AI-related conduct. Massachusetts Attorney General Andrea Joy Campbell issued a similar advisory earlier. Both demonstrate that an attorney general can act on AI deployments without new legislation. Auditability of automated decisions, due process protections, and transparency in government use are already addressed by existing anti-discrimination and consumer protection laws. State bills creating new accountability rights for automated hiring often duplicate protections already enforceable under Title VII and the Americans with Disabilities Act.

The rule, then, is that when existing law adequately addresses the harm, the appropriate instrument is interpretive guidance from the relevant agency. New legislation imposes compliance costs, whereas simple interpretive guidance provides clarity. Many state AI bills do not survive this stage, and the first test is the most efficient single-discipline a state house can adopt.

Stage 2: Four Dimensions of Cost-Benefit Analysis

When existing law does not adequately address the harm, the question becomes whether the proposed rule’s benefits exceed its costs. Every AI policy choice sits along a single axis: a higher degree of regulation generally delivers stronger protections but reduces economic competitiveness, while a lower degree of regulation, beyond basic protections, preserves competitiveness but accepts greater downside risk. The framework’s purpose is not to resolve this tradeoff in the abstract but to make it explicit for each specific proposal.

Four dimensions warrant consideration: harm reduction, national security and critical-infrastructure resilience, innovation environment, and competitive concentration. The first two yield near-clear benefits when targeted well, with cost caveats that must still be weighed. The second two entail genuine tradeoffs.

Harm reduction is the strongest test case. The question is whether the harm is demonstrable, measurable, and unaddressed by existing law. AI-generated child sexual abuse material, election deepfakes, and discriminatory automated hiring decisions pass cleanly. Algorithmic harm framed in the abstract does not. A targeted state law addressing a specific harm produces measurable protection at a reasonable cost. A 50-state patchwork addressing the same harm multiplies compliance costs without proportional improvement.

National security and critical-infrastructure resilience addresses the category Anthropic’s Mythos brought into sharp focus, where risks are too systemic for any state law to address alone. The federal Center for AI Standards and Innovation (CAISI) framework provides a voluntary pre-deployment evaluation of frontier models in classified environments and was recently expanded to include Google DeepMind, Microsoft, and xAI, alongside the original agreements with Anthropic and OpenAI. But the cost caveat is significant. National-security framings can impose capability ceilings on legitimate research, crowd out commercial deployment, and place the U.S. at a technological disadvantage to international competitors. The challenge is calibrating oversight narrow enough to preserve commercial activity but broad enough to address the systemic risks Mythos illustrated.

Innovation environment carries a genuine tradeoff. Higher regulation can anchor durable adoption of AI. Rules compelling basic disclosure or human-in-the-loop oversight in high-stakes contexts can reinforce the trust that sustains adoption over time. Poorly designed governance has the opposite effect. For example, Consumer Financial Protection Bureau (CFPB) complaint volumes nearly doubled between the launch of ChatGPT and 2024, with complaints concentrated among high-adoption firms that scaled deployment without adequate guardrails.

Higher regulation can also push innovation out. Palantir relocated its principal executive office to more business-friendly Miami in February 2026, Elon Musk explicitly cited California law in moving SpaceX and X to Texas, and OpenAI signaled it would exit California amid state attorney general investigations into its proposed for-profit tr

[truncated for AI cost control]