The fight over a three-year freeze on state AI laws has moved from a June discussion draft into a live House bill, and founders shouldn't treat the state patchwork as gone.
Congress's AI bill fight didn't fade over the summer. It got narrower, more concrete, and more useful to read. On July 23, Reps. Lori Trahan and Jay Obernolte introduced the FRONTIER Act, the frontier-model oversight piece developed from their broader Great American AI Act framework. That's the current story now, not only the 269-page draft released on June 4.
The first draft mattered because it put a serious federal AI rulebook on paper. It would have required large frontier AI developers to publish risk frameworks, undergo semi-annual independent audits, report serious safety incidents, and work through the Center for AI Standards and Innovation. It also carried the line that started the real fight: a three-year bar on state laws specifically regulating how AI models are developed.
That line is still the pressure point. You can support federal audits and still object to Congress freezing state law before a federal system has proved it can work. Frankly, that is the sane position. A national baseline is overdue. A national ceiling is something else.
The June draft started a state revolt
According to the official June 4 release from Trahan's and Obernolte's offices, the Great American AI Act was meant to solicit feedback before formal introduction. The sponsors said it would create a federal framework for AI governance and invited public comments at [email protected]. That was not a quiet request. Within hours, labor groups, consumer advocates, and Democratic lawmakers were arguing that the preemption clause traded away state authority too cheaply.
The House Commission on AI and the Innovation Economy said on June 4 that the draft did not meet the moment and could not serve as the basis for productive dialogue in its current form. The AFL-CIO also opposed preemption that same day, saying any attempt to tie the hands of states trying to protect working people was not acceptable. Those are not obscure objections. They go to the structure of the bill.
Then came the state lawmakers. Americans for Responsible Innovation published a June 16 letter signed by more than 200 lawmakers from 42 states, led by Massachusetts Sen. Michael Moore and Ohio Sen. Louis Blessing. The letter warned that the draft's preemption language could reach state measures on AI models trained on copyrighted works or child abuse content, rules meant to prevent discriminatory development affecting workers and homebuyers, and privacy bills that cover model building. That is specific. It is also why the fight won't be settled by saying AI crosses state lines.
Public Citizen joined more than 130 organizations in a separate opposition letter, along with groups including AFSCME, the American Federation of Teachers, the National Consumer Law Center, SEIU Local 1021, and the Writers Guild of America West. Their argument was blunt: Congress can fund standards, training, and transparency without handing the AI industry a federal ban on state regulation.
Colorado shows why the details matter
Colorado is the example you should watch because it has already rewritten its own AI law once. The original Colorado AI Act passed in 2024 and was set to take effect on June 30, 2026. Governor Jared Polis signed Senate Bill 26-189 on May 14, 2026, replacing that framework with a narrower automated decision-making technology law that Mayer Brown says will take effect on January 1, 2027.
That matters for startups because most companies are not OpenAI, Anthropic, Google DeepMind, or xAI. They are using models, fine-tuning them, embedding them in hiring tools, lending workflows, insurance reviews, health products, customer support systems, you name it. A federal bill aimed at the largest frontier developers may not erase the state obligations those companies face when AI is used on people.
As Future of Privacy Forum noted in its June analysis, the Great American AI Act draft was broad, but many of its most important provisions focused on frontier model regulation. Legal analysts at Subject to Inquiry made the same practical point: most companies using AI in daily operations would not fall directly under the frontier developer rules, while state laws on employment, privacy, consumer protection, healthcare, financial services, and common-law claims could still matter.
The July 23 FRONTIER Act sharpens that split. Trahan's office said the introduced bill would create tiered requirements for frontier AI developers, including model cards, risk-management frameworks, independent audits, incident reporting, and ongoing assessments. Bloomberg Law reported the same day that the measure would subject developers such as OpenAI and Anthropic to transparency and audit requirements aimed at catastrophic risks.
Good. Those companies need federal scrutiny. You don't want fifty different legislatures trying to inspect a frontier model's catastrophic risk plan. But the bill's preemption language still deserves hard reading, because states have been the only governments moving quickly on AI harms while Congress argues over the map.
For founders, the practical answer is dull but important: keep tracking both layers. The FRONTIER Act is not law. Colorado's replacement statute has a January 1, 2027 start date. California, Illinois, New York, and other states are still moving on AI rules that touch deployment, consumer disclosures, workplace decisions, privacy, and child safety. If you stop state compliance work because a House bill has a federal preemption clause, you're betting your legal budget on a bill that has not crossed Congress.
The federal bill may become the foundation of American AI oversight. It may also get rewritten again before it moves. Until then, the only honest rulebook is the messy one companies already have: follow the live state laws, watch the federal text, and assume the preemption fight is not over.
Also read: Amazon and Microsoft are spending $400 billion on AI this year and investors want to know when it pays off • Google Gemini has 900 million users and barely any of them chose it • LG Electronics wins Korea's first Nvidia liquid cooling certification as AI data centers hit a heat wall