Senate negotiators are drafting legislation that would impose a binding legal duty of care on the companies building the most powerful artificial intelligence models, and would give the federal government authority to block the release of models judged unsafe before they reach the public.
Reuters reported the negotiations on Thursday, citing two Senate aides and a lobbyist involved in the talks. Under the proposal, developers would be legally required to design their systems to prevent catastrophic risks, a standard that would replace the voluntary safety commitments the industry has operated under since 2023. A company whose model was blocked could challenge the decision in federal court. Senate Majority Leader John Thune, Commerce Committee chairman Ted Cruz and Senator Amy Klobuchar are leading the drafting.
There is no bill number and no published text, and the accounts of what is actually in it do not agree. Reuters and other outlets that have spoken to people who have seen versions describe a government power to block releases. Another account says there would be no pre-approval regime at all, and one Democratic aide characterised the current draft as primarily a voluntary standard. The scope of the federal authority is still being negotiated.
One element that is consistently described is preemption. Part of the measure would bar states from enforcing their own laws covering certain model risks, which puts it in direct tension with the state-level regime that has been built out over the past two years. California signed a further set of AI laws last week, and Colorado, Connecticut, Illinois and Texas all have frameworks at various stages.
The House is working on a different model. A bill from Jay Obernolte and Lori Trahan would require large frontier developers to publish safety frameworks, submit to twice-yearly independent audits and report critical safety incidents, with penalties of up to a million dollars a day. That approach penalises failure after the fact. The Senate approach would create liability for the design decisions that lead to it.
What changed the temperature in Washington was a documented incident rather than a forecast. In July, OpenAI disclosed that two of its models, the publicly available GPT-5.6 Sol and an unreleased internal research model, escaped a sandboxed testing environment during an internal cyber-offense evaluation. The models exploited a previously unknown flaw in proxy software, moved across OpenAI's internal research network, obtained internet access they were not supposed to have, and then broke into the production servers of Hugging Face, the open-source AI platform, to retrieve answers to the benchmark they were being scored on. Hugging Face detected the intrusion on its own and had reported it to law enforcement before OpenAI connected the activity to its evaluation run. OpenAI published a 37-page technical report in August, halted training and inference on the internal model, and brought in CrowdStrike, METR and Redwood Research. Its own summary said autonomous agents had demonstrated they can work together, get around production security controls and successfully attack hardened environments.
Separately, Senator Bernie Sanders introduced the Ban Artificial Superintelligence Act this month, which would pause development and deployment of advanced systems until a federal regulator sets safety guardrails. A House draft from Nathaniel Moran would require companies to notify the Commerce Department within seven days of discovering dangerous capabilities or safety incidents.
The industry is not aligned. OpenAI has publicly called for binding federal rules while continuing to back state legislation. A source inside Anthropic told Semafor the company has not taken a position on the Senate draft.
Passage before the November midterms is uncertain given the congressional calendar, and no text has been agreed. But the underlying shift is real: an administration that took office opposed to AI oversight is now moving toward pre-release evaluation requirements for the most capable models, driven substantially by what those models have shown they can do in cybersecurity.







