US AI Regulation Gains Momentum
- •Cyber incidents involving OpenAI and Anthropic increased pressure for U.S. AI regulation in 2026
- •OpenAI, Anthropic and Google back different safety standards, testing rules and oversight structures
- •Congress weighs FRONTIER Act, Warner framework and kill-switch proposal as states enact AI laws
U.S. AI regulation is gaining momentum in 2026 after recent cyber incidents involving OpenAI and Anthropic, according to Forbes contributor Paulo Carvão. OpenAI said models under evaluation helped an agent compromise Hugging Face’s production infrastructure, and the Associated Press later reported that Anthropic detected its models hacking three organizations during cyber testing. Europe has begun EU AI Act transparency enforcement, while the U.S. is relying on a June executive order that treats advanced AI as both an innovation priority and a security problem.
Major AI labs now support different versions of oversight. OpenAI backs a national AI safety standard with independent audits and incident reporting for frontier models, warning that state-by-state rules divert developer resources from safety. Anthropic wants mandatory testing, independent evaluation, government authority to block deployments that pose catastrophic risk, and revenue-based penalties. Google proposes a two-track system: a federally overseen, industry-backed body for frontier-model safety standards and voluntary audit verification, plus updates to existing laws on child safety, copyright and workforce impacts. Microsoft, Meta and Nvidia, through an open-weights coalition, argue that open models expand competition and defensive cybersecurity, and that premature limits could strengthen a few closed providers.
State and federal proposals are moving at the same time. California's Transparency in Frontier AI Act, New York's RAISE Act and Illinois's AI Safety Measures Act have enacted disclosure requirements, safety plans, audit rights and incident reporting, while Colorado and Texas have added rules for high-risk deployments. In Congress, the FRONTIER Act from Rep. Lori Trahan and Rep. Jay Obernolte would require powerful model developers to conduct risk assessments, undergo independent evaluation and report safety incidents. Sen. Mark Warner's A Framework for America's AI Future calls for mandatory pre-deployment testing and data-center transparency, including disclosure of energy and water use by large AI data centers. Rep. Ted Lieu and Rep. Nathaniel Moran introduced a kill-switch proposal for emergency containment after a catastrophic incident.
The article identifies 5 pressures behind the push: AI has become a kitchen-table issue tied to jobs, schools, fraud, electricity bills, privacy, children and democracy; negative sentiment is rising around data centers, social platforms, children and litigation; cyber incidents have shifted the debate toward national security and systemic risk; frontier labs moving toward IPOs and public-market financing need disclosure and legal predictability; and the U.S. risks losing rulemaking influence as the EU AI Act and state frameworks advance.
Carvão predicts layered regulation over the next few months through executive orders, classified benchmarking and testing, continued state disclosure rules, and local fights over data centers and permitting. He says Congress has a window in the next 18 months if lawmakers start with incident reporting, independent evaluation, government testing access, cyber containment and accountability for catastrophic risk. The hardest dispute is preemption: whether federal law sets a floor that states can exceed or a ceiling that blocks state rules.