The "Securing and Establishing Consumer Uniform Rights and Enforcement" (SECURE) Data Act is a comprehensive federal consumer privacy bill released on April 30, 2026 by the data privacy working group of the U.S. House Committee on Energy and Commerce's Republican members. It was anticipated as the Republican counterpart to the various Democratic drafts reviving the American Data Privacy and Protection Act (ADPPA). The bill is principally a privacy measure, but its federal-preemption framing and its treatment of automated decision-making bear on state-level AI governance.
Status and legislative history
The House Energy and Commerce Republican working group released the bill text for introduction on April 30, 2026 (Source: d1dth6e84htgma.cloudfront.net). The Future of Privacy Forum (FPF) published a contextual analysis of the draft the same day (Source: fpf.org).
Reporting dated June 2, 2026 indicated that the House Energy and Commerce Committee was set to take up the bill during the week of June 2, 2026. According to that reporting, the bill touches on AI but largely sidesteps the most contested AI-policy questions, framed as an attempt to break the long-running impasse over a uniform federal privacy standard; the narrowing — a privacy framework first, with contentious AI-governance questions such as automated decision-making technology (ADMT) and bias audits set aside — was described as a step intended to make federal preemption more passable (Source: insideaipolicy.com).
The bill received its first hearing on June 3, 2026, where the House Energy and Commerce innovation subcommittee split along party lines, with Democrats criticizing the preemption of nearly all state privacy laws (Source: iapp.org; statescoop.com).
Scope and core provisions
The bill text was released April 30, 2026 for introduction; its detailed structure follows the Republican working group's prior drafts. As described, the bill establishes a federal floor with preemption of state privacy laws; consumer rights of access, correction, deletion, and portability; data minimization and purpose-limitation obligations on covered entities; a sensitive data category with heightened protection; and enforcement through the Federal Trade Commission and state attorneys general.
The bill's specific AI-related provisions — automated decision-making transparency, model-output disclosure, and bias-audit safe harbors — are the open question for its AI-governance impact.
Interaction with state AI governance
The federal-preemption framing connects the bill to state-level AI governance. If preemption holds, state-level AI privacy and bias-audit obligations may be partially or wholly displaced depending on the bill's coverage. Examples cited include the Colorado AI Act disparate-impact testing requirement, the CCPA AI provisions, New York transparency obligations, and state-level model-card requirements.
IAPP analysis published April 30, 2026 noted that California and New York have passed AI transparency and accountability obligations for AI developers, with deployers facing distinct compliance challenges — the regulatory layer the SECURE Data Act's preemption clause would touch (Source: info.iapp.org). U.S. states issued more than $3.4 billion in fines for alleged violations of state privacy laws in 2025, more than regulators had issued in the previous five years combined, a figure cited as context for the timing of the federal preemption push.
Reactions
At the June 3, 2026 hearing, Democrats on the innovation subcommittee criticized the bill for preempting nearly all state privacy laws (Source: iapp.org; statescoop.com).
On June 4, 2026, sponsors defended the bill as a "consensus" of the 22 existing state privacy laws it would preempt, arguing that the federal floor codifies rather than weakens prevailing state protections. Critics countered that preempting nearly all state privacy laws sacrifices stronger state regimes to a lowest-common-denominator federal standard (Source: route-fifty.com).
Related
- California CCPA/CPRA Regulations — Automated Decision-Making Technology (ADMT) — state floor that would be preempted.
- Colorado AI Act (SB 24-205) — algorithmic-discrimination law with a preemption interaction.
- Three Privacy Problems AI Creates and AI Compliance Industry / Regulatory Fragmentation.
- IAPP US State AI Governance Legislation Tracker — parallel state activity.
Relationships
- regulated-by: Federal — enforcement through the FTC and state attorneys general.
- related: AI Compliance Industry / Regulatory Fragmentation, Three Privacy Problems AI Creates, Colorado AI Act (SB 24-205), California CCPA/CPRA Regulations — Automated Decision-Making Technology (ADMT), International Association of Privacy Professionals (IAPP).