The "AI Kill Switch Act" is one of the latest in a growing wave of U.S. AI legislative proposals. Alongside increasing state-level activity, recent federal measures indicate a more active approach to AI governance, particularly where national security and cybersecurity concerns intersect with frontier AI development.
To help unpack these developments, we asked our good friends at Cravath, Swaine & Moore about the evolving U.S. AI regulatory landscape, where federal and state initiatives are not always aligned.
Q1: There is a view among some in Europe that the approach in the United States is generally anti-regulation when it comes to AI, but we’ve seen from the AI Kill Switch Act and other bills that there is a desire in some corners to pass AI specific laws. So, to what extent is AI now regulated in the United States?
It remains the case that there is no single, comprehensive federal law which governs the use, development, or deployment of AI in the U.S. Instead, we see:
- A growing body of State Legislation: The AI Kill Switch Act is one of more than 1,800 AI-related bills introduced across 46 U.S. state legislatures as of last month (July 2026). Key state enactments include: risk-based AI regulations (Colorado, California, New York, Texas); regulations on AI conversational services (Connecticut, Washington, Idaho, Nebraska, Oregon); regulation of the use of AI for employment and recruitment purposes (Illinois); regulations related to privacy and automation (California, Colorado, Connecticut, Virginia); and ensuring transparent AI use and the regulation of deepfakes (Washington, New York).
- Executive Orders at federal level: In his second term, President Trump has issued several executive orders aimed at strengthening the U.S.’s position in global AI competitiveness and attempting to limit the ability of state lawmakers to enact AI-related legislation. His order signed on 2 June 2026 (Executive Order 14409 “Promoting Advanced Artificial Intelligence Innovation and Security”):
- Establishes US policy to work collaboratively with the private sector to modernise and secure government and private sector information systems, protect American IP from theft and cultivate its advanced AI-enabled capabilities.
- Sets 30 and 60 day deadlines for federal agencies to bolster their cybersecurity measures - for example the Treasury Department will create an “AI cybersecurity clearinghouse” to coordinate vulnerability scanning and patch distribution and a number of federal agencies have issued binding guidance.
- Directs a coalition of government agencies to establish two key mechanisms within 60 days – a classified benchmarking process establishing a threshold for determining when an AI model qualifies as a “covered frontier model” and a voluntary framework which then applies to such models. Alongside other safeguards, the framework contemplates a 30 day pre-release window for government tos access the models before broader release.
Directs the Attorney General to prioritise the enforcement of federal criminal laws against anyone who uses AI to access or damage a computer without authorisation, or who employs AI agents to unlawfully access data for a criminal purpose.
[Note: Since our interview, President Trump has issues a new order to rename AI Super Intelligence (or SI) and launched a new America.gov service to streamline the use of US government websites.]
Q2: We understand that national security concerns may have (at least in part) prompted this latest Executive Order. Can you tell us more about these concerns, and whether they demonstrate a change in the federal government’s position?
Concerns about frontier AI security pre-dated the OpenAI incident you mentioned earlier. Following concerns it was possible to “jailbreak” Anthropic’s latest commercial models (i.e. by-pass its guardrails and safety features), the US government intervened - directing Anthropic to suspend access for foreign nationals to its latest models, Fable 5 and Mythos 5. Citing difficulties around real-time nationality verification, Anthropic responded by suspending access for all users to both models, effective immediately on 12 June 2026. Access to Mythos 5 was then partially restored for 100+ approved US organisations and government agencies on 26 June and the restrictions were officially lifted by the government four days later (although Mythos restrictions remained for non-US organisations).
So does this all indicate a change in the federal government’s position? Both the decision to issue an export control directive and the latest Executive Order are a marked departure from the Trump Administration’s previous approach to AI regulation. They represent a shift from a laissez-faire posture to active federal involvement, driven by emerging national security concerns. However, despite this more active regulatory posture, there remains a strong emphasis on ensuring that federal actions do not undermine America’s ability to remain a global AI leader. The Executive Order itself was nearly issued in May, before being pulled due to concerns that it would serve as a “blocker” to AI innovation and competitiveness. The final version shortened the pre-release review window from 90 to 30 days to address industry concerns, and the Executive Order still does not impose a mandatory federal AI framework: instead providing for voluntary collaboration with no mandatory preclearance for AI models.
Q3: The recent developments have raised concerns among non-US organisations that their access to frontier AI models may be pulled. Are these concerns valid?
The latest Executive Order and export control directive issued to Anthropic have amplified concerns that the U.S. government may cut off foreign nations’ access to leading AI models based on national security determinations. Introducing a classified benchmarking process for designating “covered frontier models” also raises concerns about subjectivity and accountability, as AI developers may have limited visibility into the threshold.
Key departures among White House officials also mean there are questions about whether decision-making in this area is personality-driven and concentrated among a small number of officials. For example, in connection with the export control directive against Anthropic, Treasury Secretary Bessent reportedly served as the point of contact when Amazon raised concerns about Anthropic’s Mythos model, despite not directly overseeing AI testing.
Q4: Given these concerns, what can organisations with US exposure do?
As ever, the implications of these regulatory developments depends upon the role the organisation is playing in the AI value chain.
For organisations developing AI models for US deployment, consideration should be given to whether their models could be designated as a “covered frontier model” and, if so, how participation (or non-participation) in the voluntary framework might affect their operations, customer expectations and broader engagement with government. Today’s voluntary standards may also become future binding obligations and early engagement may offer an opportunity to organisations to influence how any future mandatory regime applies to their business.
Model deployers may also take an interest in whether their providers participate in the framework. Participation may offer additional transparency and reassurance around a model's risk profile and could help reduce the risk of future geopolitical or regulatory disruption, although it is clearly no guarantee against government intervention.
More broadly, recent developments highlight the sovereign and concentration risk to deployers of using US-domiciled models. For example, companies relying on a single U.S. AI provider for critical operations should evaluate concentration risk and develop contingency plans.
With thanks to David J. Kappos and Ryan Wichtowski from Cravath, Swaine & Moore LLP.

/Passle/5badda5844de890788b571ce/SearchServiceImages/2026-09-25-14-41-03-780-6ab687ff84411a806827a297.jpg)
/Passle/5badda5844de890788b571ce/SearchServiceImages/2026-09-22-10-29-33-270-6ab2588d12121dd18e20a97e.jpg)
/Passle/5badda5844de890788b571ce/SearchServiceImages/2026-09-17-15-48-08-572-6aac0bb83163f6587eb93bd6.jpg)
/Passle/5badda5844de890788b571ce/SearchServiceImages/2026-09-11-12-15-18-048-6aa3f0d6aa29502bc9625d76.jpg)