AI Policy Wiki
Dashboard

Standards Are the New Legislation (Clearwater, March 2026)

high confidence · updated 2026-06-06

Andrew Clearwater's framework for the simultaneous emergence of three approaches to standards-based US AI governance — incentive (Texas TRAIGA: NIST compliance → safe harbor), mandate (Illinois SB 3312, Washington HB 2157), and transparency (California TFAIA, NY) — plus the litigation channel that always runs.

Author: Andrew Clearwater Source: https://andrewclearwater.substack.com/p/standards-are-the-new-legislation Published: March 24, 2026

"Standards Are the New Legislation" is a March 24, 2026 essay by Andrew Clearwater arguing that voluntary AI standards — the NIST AI RMF, ISO/IEC 42001, and the OECD AI Principles — are being woven into US law, litigation, and liability, and have, in Clearwater's account, become regulatory infrastructure carrying the force of law even as the AI governance community continues to treat them as optional guideposts. The essay's central contribution is a three-lane framework for how state legislation incorporates standards, alongside a litigation-evidence channel that Clearwater argues operates independently of any statute.

Summary of argument

Clearwater's premise is that voluntary AI standards (NIST AI RMF, ISO/IEC 42001, OECD AI Principles) are being woven into the actual fabric of law, litigation, and liability, and that the AI governance community treats them as guideposts when, in his view, they have already become regulatory infrastructure with the force of law.

Three-lane framework

The essay's central contribution is a typology of three ways state legislation incorporates standards. (See full coverage at Three-Lane Standards-Based AI Governance.)

  • Incentive lane (Texas TRAIGA): NIST AI RMF compliance produces an affirmative defense or safe harbor.
  • Mandate lane (Illinois SB 3312, Utah HB 286, Washington HB 2157): standards function as an obligation.
  • Transparency lane (California TFAIA / SB 53, New York): standards function as accountability disclosure.

Clearwater notes that for multi-state operators the same NIST framework carries different legal weight depending on user jurisdiction, and that pending bills borrow freely across the three lanes.

Standards as litigation evidence

The essay argues that standards influence liability independently of statutory adoption. (See full coverage at Standards as Litigation Evidence.) Drawing on decades of product-liability law, in which industry standards set the bar for what counts as negligent, Clearwater applies the same logic to AI: NIST AI RMF compliance becomes presumptive evidence of good faith, while non-adoption becomes presumptive evidence of a failure to exercise reasonable care. He asserts that courts are already using NIST in AI-related cases without statutory direction.

Standards bodies as quasi-legislative actors

Clearwater argues that NIST, ISO, IEEE, and CEN-CENELEC were never designed as quasi-legislative bodies, but that standards-based governance is making them so. He uses the EU as an example of the resulting strain: only 15 of the EU AI Act's harmonized technical standards had been published by late 2025, with roughly half projected to miss the August 2026 deadline. The standards bodies' fast-track response — smaller expert groups pushing delayed standards across the line — drew pushback from original drafters who argued it gutted consensus legitimacy. The European Parliament proposed conditioning the AI Act's high-risk activation timeline on standards availability.

NIST crosswalks

The essay highlights the crosswalk documents NIST published mapping the AI RMF to ISO 42001, the OECD AI Principles, and others, which Clearwater says received almost zero mainstream coverage. He argues the crosswalks let organizations implement one governance program and demonstrate alignment with multiple frameworks simultaneously, because the organizational governance, risk identification, and monitoring layers largely mirror one another across NIST and ISO 42001. In his account the crosswalk is the beginning of a global governance interoperability layer for AI.

Forecasts and prescriptions

The essay advances five forecasts. Clearwater predicts that standards, rather than federal legislation, will become the primary mechanism for US AI governance, citing NIST's bipartisan support and the precedent of the CISA framework. He projects that ISO 42001 certification will become enterprise table stakes by 2027, analogous to SOC 2 and ISO 27001 in security. He expects the standards-as-litigation-evidence trend to accelerate, the NIST crosswalks to function as global governance interoperability infrastructure, and practitioners who treat standards as optional to face a structural disadvantage.

For practitioners, Clearwater prescribes ceasing to treat standards as optional, building for interoperability from day one through a unified governance program that maps controls across NIST, ISO, and applicable jurisdictions, and getting documentation in order before any inquiry rather than after it.

The essay's significance, in its own framing, lies in articulating the three-lane framework as an account of US state-level AI standards-based governance in 2026, surfacing the litigation-evidence channel as a mechanism independent of statutory adoption, naming the position of standards bodies that were not designed as legislatures but are taking on legislative weight, and drawing attention to the NIST crosswalks as an under-covered interoperability development.

Relationships