Last Updated on July 7, 2026 by Taya Ziv
Six days ago, Illinois signed what every headline called “America’s strongest AI law.” Mandatory bias audits. Impact assessments before you deploy. Real fines if you screw up. The message was clear: if Washington won’t regulate AI, the states will.
Washington’s response took exactly six days.
On June 4, Representatives Jay Obernolte and Lori Trahan dropped a 269-page bipartisan discussion draft called the Great American Artificial Intelligence Act. It has four pillars, a new federal AI safety center, and a $100 million annual budget. But the provision that matters is a single clause: for the next three years, states cannot pass laws regulating how AI models are developed.
Not how AI is used. How it’s built.
That distinction is everything. And if you’re building a startup right now, the gap between those two words is where your next three years of regulatory reality lives.
The numbers behind the preemption
Here’s the landscape Congress is trying to flatten. In 2025, state lawmakers across all 50 states introduced 1,208 AI-related bills. 145 became law. By March 2026, 45 states had already introduced another 1,561 AI bills, and the legislative session wasn’t even over.
That’s not regulation. That’s a stampede.
California passed a frontier AI transparency law requiring developers to disclose training data summaries. New York enacted the RAISE Act with mandatory safety reporting for models above 10^26 FLOPs. Illinois went further, demanding impact assessments and bias audits for high-risk deployments. Colorado, Texas, and Virginia all had their own versions in progress.
For a startup operating across state lines, each new law meant another compliance stack. Another legal review. Another set of contradictory requirements that no 12-person team could reasonably track.
The Great American AI Act kills that patchwork. For three years. But only on the development side.
The two-tier system nobody’s talking about
Here’s where it gets interesting for founders. The bill explicitly exempts startups.
The preemption and the new federal requirements only apply to “frontier models,” defined as AI systems trained with more than 10^26 floating-point operations. Right now, roughly 30 models on Earth meet that threshold. They belong to maybe 6 companies: OpenAI, Google, Anthropic, Meta, xAI, and a couple of Chinese labs.
If you’re a startup building on top of those models, or training your own smaller model, or fine-tuning an open-source base, the bill doesn’t touch you. The governance deadline that was already looming for AI agent startups gets more complicated, because state deployment rules still apply, but the federal development rules? Not your problem.
This creates a strange two-tier system. The frontier labs face federal oversight: safety incident reporting within 15 days (24 hours if someone might die), mandatory risk assessments, a new Commerce Department watchdog with real teeth, and $1 million per day in fines for non-compliance. Everyone else faces… the states. Or nothing. Depending on where you operate and what you build.
And here’s the part that should make you uncomfortable: the companies that lobbied hardest for this bill are the ones it regulates.
The Amazon minimum wage play
I’ve seen this movie before. In 2018, Amazon raised its minimum wage to $15 per hour. Generous, right? Then it lobbied Congress to make $15 the federal minimum. Not because Amazon cared about warehouse workers in Mississippi. Because Amazon had already absorbed the cost, and forcing every competitor to match it would hurt them more than it hurt Amazon.
The Great American AI Act has the same structure. We wrote last week about how Anthropic and OpenAI actively helped write the Illinois AI law. Now Congress is preempting that law and replacing the 50-state patchwork with a single federal framework that the same companies helped shape.
Think about what that means. The frontier labs can afford a dedicated compliance team for one federal standard. A startup in Austin can’t afford a dedicated compliance team for one federal standard. But the startup didn’t need one, because the bill exempts them from the federal rules. Instead, they get the state rules that the feds just neutered.
The result: the frontier labs get a single, predictable regulatory environment they helped design. Everyone else gets regulatory ambiguity, because the states were building the framework that would eventually create clarity, and Congress just paused it.
What the bill actually does (and doesn’t do)
Let me be specific, because 269 pages is a lot of pages and most of the coverage has been about the preemption clause.
What it does: requires frontier model developers to create and publish an AI safety framework, report critical safety incidents to a new federal center (the Center for AI Standards and Innovation at Commerce), conduct pre-deployment risk assessments, identify and disclose whether their models pose catastrophic risks. It funds workforce impact studies and authorizes $100 million a year for AI safety research.
What it doesn’t do: regulate how AI is deployed. States keep full authority over AI use in hiring, insurance, healthcare, criminal justice, housing, and education. Illinois’s bias audit requirements for employers using AI in hiring decisions? Still valid. Colorado’s algorithmic accountability for insurance? Untouched.
This is the development-vs-deployment split. Congress is saying: we’ll decide who can build the most powerful AI models and under what safety conditions. States can decide how those models get used in people’s lives.
It sounds clean. It isn’t.
The problem with drawing the line at 10^26 FLOPs
The 10^26 FLOPs threshold is a number borrowed from California’s SB 53 and the Biden-era executive order. It was a reasonable line in 2024. In 2026, it’s already becoming arbitrary.
Distillation, synthetic data, and more efficient architectures mean that models trained at 10^25 FLOPs can match the performance of models that cost 10 times more compute two years ago. DeepSeek’s V4 proved that point. So did several open-weight models from Mistral and Alibaba.
The bill’s own projections estimate around 30 models above the threshold today, and over 200 by 2030. But the models just below the line aren’t meaningfully less capable. They’re just cheaper to train.
For founders, this creates a strange incentive. If you’re training a model that’s close to the threshold, staying just below it means you avoid federal oversight entirely. If efficiency improvements push frontier capabilities below 10^26 FLOPs, the cost collapse that companies like DeepSeek are driving could eventually make the entire regulatory framework irrelevant.
The three-year sunset is supposed to address this. Reassess, recalibrate, adjust the threshold. But if history teaches us anything about temporary government measures, it’s that “temporary” is the most permanent word in Washington.
What founders should actually do
The bill is a discussion draft. It hasn’t been formally introduced, hasn’t been through committee, hasn’t been voted on. But the direction is clear, and the bipartisan co-sponsorship means this general shape, if not this specific bill, is coming.
Here’s the practical reality for startups in 2026:
First, the compliance burden just shifted from “where you build” to “what you build.” If your model stays under 10^26 FLOPs, federal rules don’t apply. If you’re deploying in specific states, their deployment laws still do. Map both.
Second, the preemption creates a window. For the next three years (if it passes), state development regulations freeze. That’s three years to build, train, and ship without worrying about whether your training data disclosure in California conflicts with your safety reporting in New York. Use the window. Don’t assume it’ll stay open.
Third, and this is the uncomfortable one: the regulatory moat you might have been counting on just got thinner. If you were building a compliance-heavy AI product and hoping that regulatory complexity would keep smaller competitors out, the simplification of the regulatory landscape removes that advantage. Your moat needs to be product, not paperwork.
The Great American AI Act is the first serious attempt at federal AI governance. It’s 269 pages long and its most consequential provision is the one that stops other people from governing. That tells you everything about where AI regulation is actually headed: not more rules, but fewer rulemakers.
For founders, the signal is simple. The government just told you it’s not going to regulate your AI startup. Whether that’s freedom or a trap depends entirely on what you build with it.


