
State Attorneys General Call for Federal AI Safety Rules While Defending State Oversight
A bipartisan coalition of 26 attorneys general is urging Congress to establish federal safety rules for frontier AI, including independent testing and a government-led process for investigating incidents. Their letter also calls for states to retain the authority to regulate AI, raising a consequential question for developers and businesses deploying these systems: how would federal and state requirements operate together?
A bipartisan coalition of 26 attorneys general is urging Congress to establish federal safety rules for advanced artificial intelligence. Their September 23 letter calls for independent oversight of AI testing and incident response, while insisting that states retain the authority to regulate the technology and enforce protections.
A Call for Federal Action Following Reported AI Safety Incidents
The attorneys general sent their letter to the leaders of both parties in the House and Senate amid growing concern about the behavior of highly capable AI agents. They cite reports of agents acting outside intended testing environments and accessing external systems, arguing that these incidents expose weaknesses in how frontier AI developers test, monitor, and disclose risks. The letter warns that more capable systems could present threats to financial systems, critical infrastructure, and national security.
Those incidents form the basis for the coalition’s request, but the letter does not itself establish that a company violated the law. It is a policy appeal asking Congress to set rules before an incident with wider consequences occurs.
What the Proposed Framework Would Include
The coalition asks Congress to require federal oversight of AI model safety testing and standards. Under its proposal, experts working under federal regulators would evaluate systems against consistent performance benchmarks. That would move at least part of the safety assessment outside the companies developing the models.
The attorneys general also seek a uniform, government-led process for responding to AI incidents. They envision investigators with access to relevant company records and public findings that other developers could use to improve their systems. The letter further calls for safety infrastructure and experienced leaders empowered to make critical safety decisions, along with international cooperation on the pace of advanced AI development.
These proposals leave significant questions for Congress. A statute would need to define which models or activities trigger oversight, when testing must occur, what incidents must be reported, and which regulator would administer the framework. Those details would determine how broadly the rules reach beyond frontier model developers.
Federal Standards Without Displacing State Law
The letter takes an explicit position on preemption: the attorneys general want Congress to prohibit federal AI legislation from overriding state laws and to authorize state officials to enforce federal protections. They say states are already applying existing laws, including fairness requirements and AI-specific safety measures, to AI developers.
That position matters for companies seeking a single national compliance standard. If Congress adopts the coalition’s approach, federal legislation could establish baseline safety duties while state requirements continue to apply. Businesses might then need to account for both federal rules and the laws of the states where they develop, offer, or deploy AI systems. The eventual result depends on the text of any bill Congress considers.
Competition Is Part of the Regulatory Debate
The attorneys general also caution against a framework that entrenches the largest AI companies. Their letter asks Congress to preserve competition and prevent companies from using new safety rules to avoid obligations under existing antitrust law.
Safety requirements can require substantial technical and financial resources. How Congress structures testing, reporting, and oversight could therefore affect smaller developers as well as the leading frontier labs. The letter does not propose a detailed compliance system for smaller companies, but it makes clear that competitive effects should be considered when one is designed.
What Developers and Businesses Deploying AI Should Watch
For model developers, the proposal points toward closer scrutiny of testing methods, monitoring, internal safety authority, incident records, and disclosures to regulators. If legislation advances, definitions will be critical: a rule aimed at frontier models may apply very differently from one covering a broader range of AI systems.
For companies building products with third-party models, responsibility across the AI supply chain will be another key question. A provider may control the underlying model, while an application developer controls its tools and permissions, and a customer decides where and how to use it. Contracts and technical controls will need to reflect who can detect an incident, restrict access, preserve records, and respond.
Businesses using AI agents can assess those issues now. In particular, they should understand what systems an agent can reach, which actions require human approval, what activity is logged, and how access can be stopped if the agent behaves unexpectedly. These are practical governance measures regardless of whether Congress adopts the attorneys general’s recommendations.
The Issue Ahead
The letter creates no new federal AI obligations. It does, however, present Congress with a specific approach: mandatory oversight of advanced model safety, a public process for investigating incidents, safeguards against anticompetitive effects, and a continuing role for state regulators. For AI companies and their customers, the next question is whether those principles become legislation—and how Congress defines the systems, conduct, and parties covered by it.
This blog post is for informational purposes only and is not legal advice. Please consult with a Launch Legal attorney regarding your specific situation.