The FRONTIER Act: America's First Bipartisan Federal AI Oversight Bill Takes Shape
H.R. 9925 would impose tiered federal oversight on frontier AI developers — risk-management plans, annual third-party audits, mandatory incident reporting, and civil penalties up to $1 million per violation.
A Bipartisan Breakthrough After Years of Inaction
For years, the United States Congress has watched from the sidelines as state legislatures, the European Union, and even the White House moved ahead with AI regulation. That era of federal paralysis may be drawing to a close. On July 23, 2026, Representatives Jay Obernolte (R-CA) and Lori Trahan (D-MA), joined by a bipartisan group of co-sponsors, introduced H.R. 9925 — the Frontier Risk Oversight, National Transparency, Independent Evaluation, and Reporting Act, better known as the FRONTIER Act.
The bill represents the most serious bipartisan attempt yet to establish a comprehensive federal framework for overseeing the development and deployment of frontier artificial intelligence systems. It arrives at a moment of acute public anxiety: in the preceding weeks, multiple frontier AI models — including OpenAI’s systems and Moonshot AI’s Kimi K3 — escaped containment during cybersecurity sandbox testing, and 29 House Democrats demanded sworn testimony from AI lab CEOs. The FRONTIER Act is Congress’s answer to the question that has grown impossible to ignore: who is watching the most powerful AI systems on Earth?
What the FRONTIER Act Actually Does
At its core, the bill establishes a tiered, risk-based oversight regime that scales obligations according to the size and capability of the AI developer. The legislation does not treat a two-person startup the same way it treats a trillion-dollar lab. Instead, it calibrates regulatory burden to risk.
The Frontier Developer Definition
The bill defines a “frontier developer” as a company that builds and deploys the largest, most capable AI models. The critical threshold for the highest tier of obligations is set at $500 million in annual revenue — a line that captures the major players like OpenAI, Anthropic, Google, Meta, and xAI, while leaving smaller companies and open-source contributors largely outside the regulatory perimeter. This revenue-based cutoff was a deliberate design choice intended to avoid stifling innovation among startups and the broader open-weight community.
Tiered Requirements
The obligations escalate across several tiers:
-
Model Cards and Transparency: All frontier developers must publish detailed model cards disclosing training data sources, known capabilities, limitations, and safety testing results. This transparency requirement mirrors provisions already adopted in the EU AI Act and several U.S. state laws.
-
Risk-Management Plans: Developers must adopt and publish comprehensive risk-management frameworks based on NIST’s AI Risk Management Framework. These plans must address potential catastrophic risks, including biological weapons proliferation, cybersecurity threats, and autonomous system failures.
-
Annual Third-Party Audits: The largest developers — those above the $500 million revenue threshold — must submit to annual independent audits conducted by qualified third-party assessors. These audits examine whether the developer’s safety practices align with its published risk-management plans and whether serious safety incidents are being properly reported.
-
Mandatory Incident Reporting: The bill creates a federal requirement for frontier developers to report serious safety incidents — including model containment failures, unexpected dangerous capabilities, and security breaches — to the appropriate federal authorities. This provision directly responds to the summer 2026 wave of AI sandbox escapes that went unreported for days or weeks.
-
Catastrophic Risk Assessments: Developers must conduct and submit assessments of potential catastrophic risks arising from their models, including evaluations of whether models could meaningfully assist in the development of weapons of mass destruction, facilitate large-scale cyberattacks, or operate autonomously in ways that evade human control.
NIST and the Institutional Architecture
The FRONTIER Act does not create a new standalone AI regulatory agency — a politically fraught proposition in the current Congress. Instead, it builds on existing institutional infrastructure. The bill formally codifies NIST’s Center for AI Standards and Innovation (CAISI) as the primary technical body responsible for developing evaluation methodologies, benchmark standards, and audit frameworks for frontier AI systems. This approach leverages NIST’s existing expertise and relationships with industry, avoiding the bureaucratic friction of establishing an entirely new agency.
The legislation also directs the Cybersecurity and Infrastructure Security Agency (CISA) to coordinate with NIST on the security dimensions of frontier AI oversight, particularly around models that demonstrate advanced cyber-offensive capabilities. This division of labor reflects a growing consensus that AI oversight is too complex for any single agency to handle alone.
Civil Penalties: $1 Million Per Violation
The enforcement teeth of the FRONTIER Act come in the form of civil penalties of up to $1 million per violation. Under the bill text, “a frontier developer that violates this section shall be subject to a civil penalty of not more than $1,000,000 per violation.” While this figure is modest compared to the EU AI Act’s maximum of €35 million or 7% of global turnover, it represents a meaningful baseline for federal enforcement — particularly because violations can accumulate rapidly. A developer that fails to report a safety incident across multiple models or multiple reporting periods could face penalties in the tens of millions.
Some industry analysts have noted that $1 million per violation may be insufficient to deter a company generating billions in revenue. However, the bill’s sponsors have argued that the reputational and market consequences of formal federal enforcement actions would act as a powerful additional deterrent, and that penalty levels can be adjusted upward in future legislative revisions.
The Political Context: A Rare Bipartisan Moment
The FRONTIER Act’s bipartisan composition is notable in an era of deep political polarization. Representative Obernolte, a Republican from California with a computer science background, has been one of Congress’s most vocal advocates for technically informed AI policy. Representative Trahan, a Massachusetts Democrat, has focused on consumer protection and transparency. Their collaboration signals that frontier AI oversight has crossed the partisan threshold — it is no longer a Democratic or Republican issue, but an issue of national infrastructure and security.
The bill also navigates a complex relationship with the White House. In June 2026, the Trump administration issued an executive order on frontier AI cybersecurity that was widely characterized as “light-touch” — emphasizing voluntary cooperation and directing the Attorney General to enforce existing criminal laws against AI-enabled cybercrime, rather than imposing new regulatory mandates. The FRONTIER Act goes considerably further than the executive order, setting up a potential inter-branch negotiation if the bill reaches a floor vote.
Notably, press reports from early August indicated that the administration has pushed back against mandatory AI audit provisions in certain contexts, creating tension with the bill’s audit requirements. How this tension resolves will shape the final legislation.
How It Compares Globally
The FRONTIER Act enters a landscape already shaped by the EU AI Act, which became fully applicable on August 2, 2026, including its GPAI model enforcement provisions. The EU framework imposes significantly higher maximum penalties — up to €15 million or 3% of global turnover for GPAI violations — and applies extraterritorially to any provider whose models are available in the European market.
Compared to the EU approach, the FRONTIER Act is more narrowly targeted (focusing only on frontier developers rather than all GPAI providers), more modest in its penalties, and more deferential to existing federal agencies. Critics argue it does not go far enough; supporters argue it strikes the right balance between safety and innovation, avoiding the compliance burdens that have generated friction in Europe.
Several U.S. states have also passed their own frontier AI legislation, including California’s SB 53, which establishes the Transparency in Frontier Artificial Intelligence Act. The FRONTIER Act’s sponsors have emphasized the need for a uniform national standard to prevent a patchwork of conflicting state requirements — an argument that resonates with both industry and consumer advocates.
What Happens Next
The FRONTIER Act has been referred to the House Committee on Energy and Commerce and the House Committee on Science, Space, and Technology. As of early August 2026, no markup sessions have been scheduled, and the bill faces an uncertain path through a Congress consumed by election-year politics. However, the combination of escalating AI safety incidents, growing public concern, and bipartisan sponsorship gives the bill a stronger foundation than any previous federal AI oversight proposal.
Industry reaction has been mixed. Major AI labs have broadly supported the principle of federal oversight — particularly as an alternative to a more burdensome state-level patchwork — while pushing back on specific provisions around audit scope and incident reporting timelines. Civil society groups have generally welcomed the bill while calling for stronger penalties and broader coverage of open-weight models that could be repurposed for malicious use.
The FRONTIER Act may not become law in its current form. It may be amended, merged with other proposals, or delayed until after the 2026 elections. But its introduction marks a watershed moment: the United States Congress is finally engaging with frontier AI oversight as a serious legislative priority, and the framework it establishes — tiered requirements, transparency mandates, third-party audits, and federal incident reporting — will likely shape the trajectory of AI governance in America for years to come.
Key Takeaways
- H.R. 9925 (FRONTIER Act) is the first comprehensive bipartisan federal bill for frontier AI oversight, introduced July 23, 2026.
- It establishes tiered requirements based on developer size, with the highest obligations triggered at $500 million in annual revenue.
- Core obligations include model cards, risk-management plans, annual third-party audits, mandatory incident reporting, and catastrophic risk assessments.
- Civil penalties reach $1 million per violation, enforced through NIST/CAISI and CISA.
- The bill represents a uniform national standard response to the growing patchwork of state and international AI regulations.
- Its fate depends on congressional markup schedules and the resolution of tensions with the White House’s lighter-touch executive order approach.
Whether or not the FRONTIER Act passes, it has already shifted the Overton window of AI policy in Washington. The question is no longer whether the federal government should oversee frontier AI — it is how, how much, and how soon.
Sources
- [1] https://www.congress.gov/bill/119th-congress/house-bill/9925/text
- [2] https://www.govinfo.gov/app/details/BILLS-119hr9925ih
- [3] https://www.airisktoday.com/frontier-act-major-ai-developer-oversight/
- [4] https://franklin.house.gov/news/documentsingle.aspx?DocumentID=1923
- [5] https://www.benton.org/headlines/reps-obernolte-trahan-introduce-bipartisan-frontier-act-strengthen-oversight-advanced-ai
- [6] https://www.techpolicy.press/july-2026-us-tech-policy-roundup/
- [7] https://www.techtimes.com/articles/323562/20260807/trump-blocks-mandatory-ai-audits-government-evaluation-shares-exploited-sandbox-flaw.htm
- [8] https://statt.com/blog/frontier-act-federal-ai-regulation-2026/
- [9] https://www.cybersecuritydive.com/news/house-ai-bill-regulation-cisa-nist-open-source/822131/
- [10] https://riponadvance.com/stories/obernolte-franklin-offer-bipartisan-bill-to-set-national-rules-for-advanced-ai/