On June 4, a bipartisan group of U.S. House lawmakers released a 269-page discussion draft of the Great American Artificial Intelligence Act of 2026, a proposal that would do something legal teams have been anticipating for months: move AI governance from a patchwork of state experiments toward a federal framework built around transparency, audits, incident reporting, and limited preemption. Reuters described the draft as legislation that would prohibit states from regulating AI model development, while preserving room for states to regulate how AI systems are used after deployment.1 Roll Call reported that the draft would create a three-year preemption period for state laws specifically regulating AI development, while imposing federal requirements on large frontier AI developers.2
For lawyers and corporate legal departments, the most important point is not whether this particular draft becomes law in its current form. Discussion drafts change. Committees rewrite definitions. Preemption fights become politically complicated. The important point is that the center of gravity in AI law is shifting. Legal AI is no longer merely a procurement question about whether a team should buy a faster research assistant. It is becoming a governance question about how AI systems are documented, tested, verified, supervised, and defended when their outputs affect legal rights, business risk, and institutional accountability.
The draft arrives only days after the White House issued an executive order on advanced AI innovation and security. That order directed federal agencies to develop voluntary processes for evaluating certain frontier models before release, with an emphasis on cybersecurity, critical infrastructure, and national security.3 The House draft goes further in legislative form. It would formally establish the Center for AI Standards and Innovation, or CAISI, within the Department of Commerce; authorize $100 million per year for fiscal years 2027 through 2029; and create a licensing regime for independent verification organizations that would audit large frontier developers.2
| Governance signal | What it means for legal teams |
|---|---|
| Federal preemption of some model-development rules | Legal teams still need to manage downstream use, deployment, procurement, and sector-specific compliance. |
| Independent verification for frontier developers | Vendor diligence will increasingly focus on auditability, logs, controls, and evidence of review. |
| Incident reporting and whistleblower protection | AI mistakes should be treated as legal operations events with clear escalation paths. |
| Preservation of use-based and generally applicable laws | Employment, privacy, IP, consumer protection, civil rights, and professional duties remain central. |
That architecture matters because it reflects a policy judgment that AI risk cannot be managed by assurances alone. The draft’s model is not simply “trust the developer.” It is closer to “publish the framework, retain an independent verifier, report serious incidents, protect whistleblowers, and allow enforcement.” According to the FAQ released by Rep. Lori Trahan’s office, large frontier developers would be required to publish and follow plans to address catastrophic risks, report safety incidents to federal and state regulators, submit to third-party audits, and face civil penalties or injunctions if they fail to comply.4
The preemption provision is the political flashpoint. The draft would preempt state laws that specifically regulate AI model development for three years. Reuters reported that the bill would prevent states from requiring certain pre-release testing of AI models, but would not bar states from regulating AI use.1 The Trahan FAQ states that the draft would preserve state laws governing activities after deployment, including implementation, distribution, offering, or use of AI systems or products that incorporate AI models. It also says common-law remedies and generally applicable laws covering civil rights, labor protections, copyright, child sexual abuse material, and consumer privacy would remain available.4
That distinction between model development and AI use is where corporate counsel should focus. Many legal departments will not be frontier model developers. They will be buyers, deployers, integrators, and supervisors of AI-enabled workflows. A bank using AI to triage consumer complaints, a retailer using AI to monitor counterfeit listings, a law firm using AI to draft deposition outlines, or a software company using AI to review customer contracts may not be training frontier models. But they will still be responsible for how AI is used in decisions, documents, communications, evidence packages, and enforcement actions.
In other words, even if federal preemption temporarily narrows state authority over model development, it does not eliminate the governance burden for legal teams. It may actually sharpen it. If development rules become more federalized while use-case rules remain distributed across privacy, employment, consumer protection, IP, civil rights, professional responsibility, and sector-specific regimes, legal teams will need a clearer map of where each AI system sits in the organization’s risk stack. They will need to know whether a tool is a general legal assistant, a contract-review system, a decision-support tool, an enforcement automation layer, a customer-facing chatbot, or a model embedded in a regulated operational process.
The draft also signals the rise of the audit as a central governance object. Roll Call reported that large frontier developers would be required to retain CAISI-licensed independent verification organizations to perform semiannual assessments of compliance with safety requirements and the adequacy of frontier AI frameworks. The draft includes potential penalties of up to $1 million per day for certain violations.2 The statutory targets are frontier developers, not ordinary corporate legal departments. But procurement norms tend to flow downstream. Once lawmakers, regulators, insurers, and enterprise customers start treating AI governance as something that should be independently verifiable, legal buyers will begin asking similar questions of every AI vendor they use.
Those questions will be concrete. What data does the system process? What sources does it rely on? How are outputs logged? Can a reviewer see the prompt, context, citations, and final answer? Does the workflow separate machine suggestions from human legal judgment? Can privileged material be segregated? Can the organization reconstruct why a notice, draft, filing, clause edit, or escalation was generated? If a customer, judge, regulator, adversary, insurer, or board committee asks how an AI-supported legal action was produced, can the team answer without reverse-engineering the process from Slack messages and screenshots?
This is why the legal AI debate is moving beyond hallucination headlines. Hallucinated citations remain a serious professional responsibility problem, but they are only one visible symptom of a broader issue: ungoverned AI work leaves weak records. Lawyers and legal operations leaders need systems that make verification routine rather than heroic. A legal team should not have to choose between speed and defensibility. The more AI becomes embedded in everyday legal work, the more legal departments will need operational evidence that human review, source checking, privilege controls, and escalation rules actually happened.
The House draft’s incident-reporting language points in the same direction. The proposal would require developers to report critical safety incidents and imminent catastrophic risks on specific timelines.2 For corporate legal teams, the analogous lesson is that AI governance needs defined triggers. Not every AI mistake is a crisis. But certain events should automatically escalate: a tool produces unsupported legal authority; an automated enforcement campaign risks targeting a legitimate reseller; a contract assistant changes an indemnity clause beyond approved playbooks; a litigation workflow mixes privileged and non-privileged material; an AI system interacts with a government platform or marketplace in a way that creates a record. These are not merely technical bugs. They are legal operations events.
The opposition to the draft also matters. The ACLU criticized the proposal as an effort that could block states from enforcing existing protections or enacting new ones, arguing that AI affects employment, healthcare, lending, education, and many other areas where state lawmakers have tried to act.5 Public Citizen, according to Reuters, warned that the bill could leave oversight largely to a federal government that has struggled to pass meaningful AI protections.1 Supporters, including technology industry groups, argue that a national standard would reduce fragmentation and support responsible AI adoption.1
Corporate counsel should not read this debate as a simple binary between innovation and regulation. The practical reality is that both sides are describing real risks. Fragmented rules can create compliance drag, especially for companies operating across fifty states and global markets. But a single national rule that is too weak can leave affected people, customers, employees, and counterparties without meaningful protection. The legal team’s job is not to predict the final politics perfectly. It is to build AI workflows that can survive either outcome: a more unified federal regime, a continued state-by-state patchwork, or a hybrid model of federal standards plus state enforcement and private litigation.
That means legal departments should begin with an inventory of AI-assisted legal work. The inventory should identify the tool, owner, business purpose, data categories, human reviewers, output types, approval thresholds, and records retained. It should distinguish between low-risk productivity uses and high-impact legal workflows. Drafting a first-pass internal memo is not the same as generating an external cease-and-desist package, triaging employment claims, ranking litigation exposure, or preparing marketplace takedown submissions. The governance burden should follow the consequence of the output.
Second, legal teams should convert policies into workflows. Many organizations now have AI acceptable-use policies, but policies alone do not create evidence. A governed workflow defines who may initiate a task, what context may be supplied, which sources are permitted, what the AI may and may not generate, when human review is required, and what audit trail is retained. In the legal function, this workflow approach is especially important because confidentiality, privilege, conflicts, citation accuracy, and client authorization are not optional controls. They are part of the professional and institutional duty of care.
Third, vendor diligence should become more specific. It is no longer enough to ask whether a vendor “uses AI responsibly.” Legal teams should ask whether the product supports matter-level permissions, source traceability, reviewer attribution, exportable logs, data retention controls, and defensible evidence packaging. They should ask how the vendor evaluates model changes, handles incident reporting, and separates customer data. They should also ask whether the system is designed for legal review or merely wraps a general-purpose model in a legal-looking interface.
For law firms, the message is similar. Clients are increasingly likely to demand not only efficiency gains but also transparency about how AI was used. A firm that can say “we used an AI tool” will sound less credible than a firm that can say “we used an approved workflow, limited the data scope, verified authorities, preserved the review trail, and documented partner sign-off.” As AI changes pricing and staffing assumptions, defensible process will become a competitive asset. Lawyers who can combine speed with reviewable judgment will be more valuable than lawyers who merely use faster tools.
For corporate legal teams, the draft is a reminder that the future of legal AI is not a chat box sitting beside the real work. The future is governed execution: tasks, evidence, approvals, monitoring, exceptions, and audit trails built into the work itself. Whether Congress ultimately passes the Great American Artificial Intelligence Act, modifies it, or abandons it, the direction of travel is visible. AI systems that influence legal work will be expected to show their work.
That is the operating philosophy behind CourtifyAI. AI Copilot is built for lawyers and legal teams that want an AI legal assistant embedded in reviewable legal workflows, not an unstructured shortcut that creates new risk. Auto Pilot extends the same principle to automated IP enforcement, helping teams monitor infringement, organize evidence, prepare enforcement actions, and scale marketplace protection without losing operational control. As AI regulation moves toward audits, verification, and accountable deployment, legal teams should choose tools that make governance part of the workflow from the beginning.