AI Policy Wiki
Dashboard

Responsible Innovation at the Frontier (ARI, August 2026)

medium confidence · updated 2026-08-11

Americans for Responsible Innovation's blueprint for federal frontier-AI governance, built on three functions — standards, assurance, transparency. Covers developers meeting both a 10^26 FLOP and a $100M annual training-spend threshold; five statutory risk domains; government-conducted assurance with a phased, accreditation-gated role for independent verification organizations; quarterly and four-business-day AI R&D automation disclosures; a 72-hour emergency authority subject to judicial extension; compliance-equivalence preemption; a nine-year sunset.

"Responsible Innovation at the Frontier" is a blueprint for federal frontier-AI legislation published August 10, 2026 by Americans for Responsible Innovation, written by senior policy analyst Iskandar Haykel and Morgan C. Plummer, the group's vice president of policy design and delivery. The companion PDF filename encodes a document date of August 6, 2026; the publication date on ARI's own page and in its page metadata is August 10, 2026.

The blueprint is organized around three governance functions the authors argue any federal proposal should incorporate: standards, under which the federal government holds every covered developer's published safety framework to minimum federal standards defining adequacy; assurance, under which the government verifies compliance with those standards; and transparency, under which the government obtains confidential visibility into internally deployed frontier models and into the automation of AI research and development. The authors frame the proposal against a field they describe as already regulated in an unstructured way — the Trump administration "regularly preventing frontier model releases based on unspecified criteria," three states with enacted frontier safety framework statutes, federal-legislation blueprints published by Anthropic, Google and OpenAI, and a set of measures before Congress.

Scope

Coverage is deliberately narrow and the two thresholds are conjunctive. A covered developer must both have trained or initiated the training of a model using, or intended to use, at least 10^26 floating-point operations of compute, and have spent at least $100 million in the past year on aggregate training of AI models.

The authors treat compute as an imperfect proxy: because algorithmic efficiency gains mean models trained with less compute may eventually match the performance of current frontier models, the regulator must review the compute threshold on a fixed cycle and adjust it as the proxy degrades. They propose that the regulator eventually adopt a capabilities-based definition of a frontier model, with technical assistance from the Center for AI Standards and Innovation (Compute Governance).

The blueprint defines "deployment" to cover internal as well as external use, on the stated ground that there is already evidence dangerous capability thresholds can be reached by internally deployed frontier models before those models are available to the public. Standards and assurance obligations apply to covered models regardless of who is using them or where.

Standards

Each covered developer publishes and maintains a safety framework addressing five risk domains, which the blueprint would codify in statute:

  1. chemical, biological, radiological, nuclear, and explosive threats (CBRNE);
  2. offensive cyber capability;
  3. automated AI R&D;
  4. harmful manipulation, including large-scale influence operations, particularly those directed by foreign states; and
  5. autonomy, including misalignment and loss of control.

Regulators may add new risk domains as new threats emerge but may never summarily remove one, since each is codified. For each domain a framework must state how the risk is evaluated (including capabilities testing and red-teaming) and why those techniques are sufficient; the thresholds at which the developer must respond or enact mitigations, expressed in terms of model behavior or evaluation results; and the point at which the developer notifies federal authorities. Each developer must name an officer responsible for the framework's maintenance and implementation. Frameworks are filed with the regulator, which publishes every one in a public catalog, and for publicly released models evaluation information and results must be published concurrently with release through transparency documents such as system cards.

The standards operate as a ratchet. After the initial filing cycle the regulator periodically reviews and updates minimum standards, drawing on developers' published commitments and research, CAISI technical analysis, independent safety research, and the aggregated findings of assurance examinations. The floor set in each cycle is intended to prevent developers from backsliding on safety commitments or deploying systems exhibiting previously prohibited behavior; the authors state that advances in safety science may permit a relaxation of technical standards but that the public is never exposed to lower safety margins than the previous cycle set. Standards-setting rests with the regulator's independent judgment rather than averaging industry custom, and the authors distinguish developer input from developer authorship: proven feasibility informs the floor but does not cap it, so a developer demonstrating stronger measures can prompt the government to strengthen later requirements.

Emergency authority. Where fixed standards cannot anticipate a danger and the standards-setting process would be too slow, the blueprint gives the government authority to temporarily halt development, internal deployment, or external release, to order specific mitigations, and to recall a deployed model. The authority is designated in statute, granted only to senior federal officials in named offices, and informed by those officials' technical advisers. An emergency order takes effect immediately and lapses after 72 hours unless the government petitions a court for an extension within that window; once an extension is sought the order remains in effect while courts rule on an expedited basis, but lapses after a fixed period without a ruling. Upholding an order requires substantial evidence of present or imminent severe harm, and an affirmative ruling is subject to normal appellate process. The authors expect the authority to be rarely needed, because the conditions for stopping development or deployment must themselves be written into developer frameworks.

Assurance

The blueprint distinguishes two forms of continuous examination across each risk domain. Compliance assurance assesses whether a developer is adhering to its published framework; it is a technical determination against a fixed and published standard, and may be conducted by the government or by a delegated authority. Adequacy assurance assesses whether the framework meets the minimum federal standards in force; because that judgment bears directly on future rulemaking, the blueprint never delegates it, irrespective of how mature a market in independent verification organizations (IVOs) becomes.

Since no IVO market exists today, both functions begin with the government, which the blueprint would give dedicated funding and hiring authority. The functions could sit in a single entity — the authors give the example of a national lab using special hiring and pay authorities — or be spread across agencies, led by the Department of Commerce and supplemented by others. Federal evaluation teams would test frontier systems against the standards in force and against the capability thresholds in each developer's framework, while a dedicated oversight team, which the authors model on the Federal Reserve's standing supervision of the largest banking institutions, examines each developer's safety practices. The authors argue both are required: model evaluations can show that capability thresholds were crossed without corresponding developer action, and examinations can show that evaluations were not conducted at all.

Scheduled review is the principal mechanism but not the only one. Covered developers must promptly report safety incidents, whistleblowers who disclose violations are protected in statute, and either channel can prompt a for-cause examination. Examiners must immediately report any imminent risk of severe harm that neither the standards in force nor the developer's framework addresses; such findings can supply the basis for the emergency authority.

The three-phase shift. The authors identify volume rather than competence as the constraint most likely to require augmenting government assurance. If compliance-assurance responsibility shifts, it does so in three phases, and only in domains where the regulator certifies against fixed criteria that sufficient accredited capacity exists:

  • Phase One: the government conducts all assurance examinations; there is no second channel.
  • Phase Two: each developer is examined by the government and by one accredited IVO, selected by the developer, for each covered risk domain.
  • Phase Three: each developer selects an accredited IVO for each risk domain and the government assigns the other.

In every domain, cycle and phase the government conducts a share of the total examinations. The authors call this a capability floor, and describe federal capacity as a permanent core capability rather than a bridging function that sunsets as the IVO market emerges; the floor is intended to keep federal examiners abreast of the frontier, preserve the regulator's ability to reproduce IVO work, and provide a basis for assessing IVO findings. Even in a mature market the government permanently retains audits of compliance examinations, adjudication of examiner discrepancies, development of standards for novel and contested capability domains, continuous inspection of IVO work, for-cause examination capacity, and adequacy assurance in every domain.

Accreditation is granted by domain and rests with the government alone, so a developer may need several IVOs to cover every risk domain. The authors model the regulator's supervision of IVOs on the Public Company Accounting Oversight Board's supervision of public-company auditors. Certification that initial IVO capacity exists would come from a statutorily designated official, for which the authors give the example of the Secretary of Commerce.

On liability, the blueprint proposes that IVO liability track the verification burden: limited protection may help catalyze the market and may be relaxed where the government examines the same domain, but protection diminishes once IVO examinations are load-bearing, on the argument that "there could be nothing worse for frontier AI safety than a robust IVO market that enjoys immunity from its own negligent conduct." For developers, no examination outcome — government or IVO — ever creates immunity, safe harbor, or a presumption against liability.

Market safeguards include examination fees paid by developers and distributed to IVOs through a regulator-administered fund; a cap on the share of revenue an IVO may receive from any single developer, calibrated to market size; mandated periodic rotation of IVOs and government examination teams; and revolving-door restrictions on personnel movement between examiners and the developers they examine. Any marked difference between two examination assessments draws scrutiny, may trigger a for-cause examination, and may affect the accreditation of the IVO involved where a bad-faith determination was made. The authors distinguish the arrangement from self-regulation on the grounds that IVOs are accredited contractors under government supervision with no rulemaking authority, no role in setting or interpreting standards, and no separate governance body of their own, and that the government issues every binding consequence (Who Verifies the Frontier: Competing Architectures for Third-Party AI Assessment).

Transparency

Automated AI R&D is a covered risk domain like any other but is also the single domain receiving a dedicated disclosure program. The authors give three reasons: automation of the research pipeline can accelerate advances in every other covered domain and could in the long run outrun the standards-setting and assurance cycles; human oversight diminishes precisely as automation grows, so the window for establishing structured disclosure narrows as the need rises; and disclosure supplies evidence bearing on the dispute over recursive self-improvement, where the evidence indicating whether automating AI R&D produces runaway acceleration or a stalling loop currently sits in internal deployments that developers are incentivized to keep private (Recursive Self-Improvement (RSI)).

The program adapts the Securities and Exchange Commission's 10-Q and 8-K regime to the research pipeline. Each covered developer files quarterly disclosures on the automation of its AI R&D activities, plus a material-change filing within four business days after discovery of a material shift in AI R&D automation between quarterly filings. Broad categories are set in statute while subcategories, measurement rules and filing deadlines are delegated to rulemaking. Disclosures anchor on auditable measures, including the share of compute devoted to autonomous work in each category, with developer-estimated figures such as researcher-equivalent hours serving only as a supplement. Each filing must report the state of human review against a predefined test of meaningful oversight, paired with auditable review-sampling rates such as the share of autonomous outputs examined by a human. The blueprint defines meaningful human oversight by four conditions: whether humans can and do intervene in a system's outputs or actions before they are integrated into broader R&D workflows; whether a supervisor faces a volume and velocity of outputs that still permits substantive assessment of each distinct automated action; whether the supervisor has sufficient information and resources to verify the system's safety; and whether review protocols ensure material human control over autonomous decision-making.

Filings are confidential, held under security controls commensurate with their sensitivity, with trade secrets and proprietary information protected by Freedom of Information Act exemptions. Public summaries are required only in the safety, evaluation and oversight category, which the authors describe as less commercially sensitive and more useful to the public. Developers must maintain internal records, which the government incorporates into periodic aggregated reports on the state of automated AI R&D, and the regulator may examine a developer or contract an accredited IVO to do so under government authority where a filing warrants it. Knowingly false statements or failure to retain mandated records draw penalties; a developer that identifies and corrects its own filing errors in good faith is protected, and the authors state that no developer is ever penalized for a truthful disclosure alone.

Bounds on the regime

The three functions may be consolidated in a single authority, for which the authors give the example of the Department of Commerce, or divided among several federal bodies; in either case the authority to penalize a developer that fails to adequately evaluate and address frontier risks is conferred by statute.

  • Preemption by compliance equivalence. Federal compliance satisfies a state requirement only where the federal obligation covers the same conduct and is at least as protective; other state laws remain untouched. The authors present this as an alternative to broad displacement of state law (EO — Trump Federal Preemption of State AI Laws (Dec 11, 2025)).
  • No immunity. Compliance creates no immunity, safe harbor, or presumption against liability under otherwise applicable state law.
  • State authority. States remain free to legislate above the federal floor.
  • Sunset. The regime sunsets nine years after enactment unless Congress reauthorizes it, with function-specific efficacy reviews staggered through the later years of implementation — including a review of shifts in compliance-assurance responsibility — and a Government Accountability Office review of each function before sunset.

The authors close by describing the blueprint as a statement of legislative intent rather than statutory language, noting that "specific statutory language will always matter and determine ARI's position on any final legislative proposals."

Relation to other proposals

The blueprint's central claim — that assurance must rest with the government, with private verifiers admitted only after the regulator certifies capacity and never for adequacy determinations — sets it against the industry-funded self-regulatory model proposed by Demis Hassabis, under which an industry-funded standards body modelled on FINRA would run capability assessments (A Framework for Frontier AI and the Dawning of a New Age (Hassabis, July 2026)). It aligns with the argument that developers should not select and pay their own evaluators (Don't Let AI Developers Hire Their Own Referees (Weil, July 2026)), though ARI's proposal admits an accredited private-verification market on the government's terms rather than excluding one.

On automated AI R&D the blueprint and the IFP report published four days earlier identify the same gap — that evidence about recursive self-improvement sits in internal deployments the government cannot see — and address it differently: ARI through a mandatory quarterly and material-change filing regime, IFP through preparatory state capacity, verification technology and voluntary disclosure backed by narrower legislated transparency.

Relationships

Provenance

Single source: the report as published on ARI's own site, with a companion PDF. Confidence is medium — the text is unambiguous, but this is an advocacy organization's legislative proposal rather than an empirical finding, no part of it has been introduced as legislation, and no independent assessment of it had been published at the time of ingest. The two dates on the document (August 10 publication, August 6 encoded in the PDF filename) are recorded rather than reconciled to one.