Advanced AI models would have to pass an independent safety audit before release under a framework Sen. Maria Cantwell issued on October 7, 2026. The Senate Commerce Committee’s top Democrat is calling for federal standards and continuing outside scrutiny. Her six-point proposal is a policy blueprint, not binding rules.
A release gate, followed by continuing checks
Cantwell would put the National Institute of Standards and Technology, or NIST, in charge of developing measurable, risk-based standards with other federal agencies. Covered models would need an independent audit confirming compliance before release. Those standards would be updated regularly as AI evolves.
The proposed standards target catastrophic risks: AI-enabled cyberattacks; chemical, biological, radiological and nuclear threats; loss of human control; and autonomous agents escaping secure testing environments. Systems with dangerous capabilities or the ability to improve themselves while bypassing safeguards would face heightened review. Open-source models would receive specialized standards intended to reduce misuse while giving developers clear guidance.
Passing an initial audit would not end scrutiny. Government and independent experts would continually stress-test covered models. Tests would check that systems stop self-modification that bypasses safety controls, monitoring or human oversight. Separate audit firms would examine developers comprehensively, much as outside auditors examine financial statements.
The framework identifies a particular role for government and independent experts when testing requires specialized knowledge, sensitive information or secure facilities. Their work would extend beyond checking documented policies: developers would need to give testers and auditors enough access to verify that safety and security safeguards actually function as intended.
To manage risks from advanced AI systems we need clear safety standards, continuous testing, and reporting of serious failures.
Sen. Maria Cantwell, in her October 7 statement
Access, disclosure and legal responsibility
Developers would provide qualified independent testers with the access and information needed to assess risks and investigate serious incidents. They would also publish plain-language disclosures of material safety and security risks and mitigation measures, modeled on the disclosures public companies provide investors.
The framework calls for prompt reporting of material incidents, including loss of control over autonomous agents, dangerous cyber capabilities and failures of critical safeguards. Developers would remain liable under applicable civil and criminal law for foreseeable harms and unlawful conduct to which they materially contribute. Employees and contractors reporting safety or compliance concerns would receive protection from retaliation.
Human appeals and shared defenses
The blueprint also reaches beyond model safety. People whose employment, health care, credit or other essential services are materially affected by AI should be able to challenge the outcome and receive timely review by a qualified human. Cantwell also calls for child-safety protections and AI-company funding for apprenticeships, education and worker training.
For products used by children, the proposal specifically targets addictive design, harmful content and data exploitation. Its worker provisions pair training support with guardrails protecting human creativity and incentives for employers to improve jobs rather than eliminate them. Consequential AI decisions would also need to be transparent and fair, with meaningful human oversight.
- Shared defenses: Leading AI companies should contribute computing resources, expertise and defensive tools for smaller businesses, infrastructure operators and public institutions.
- Public-interest access: Government and industry should expand access to advanced computing and AI tools for universities, researchers and projects serving national priorities.
Internationally, Cantwell proposes common standards with allies and a secure U.S.–China crisis channel for significant AI incidents or system-control failures. Allies would share sensitive information about serious incidents, emerging catastrophic capabilities, testing methods and effective safeguards. Export controls would restrict access to America’s most advanced AI technologies to countries protecting against diversion and misuse and upholding U.S.-led standards.
The legislative backdrop remains unsettled: the Denver Gazette reported that Commerce Committee chair Ted Cruz has repeatedly delayed a planned review of AI bills amid a lack of bipartisan agreement.
Reader comments
Newest comments first. Replies stay oldest first.