United States Capitol building dome against a cloudy sky in Washington DC
Photo via Unsplash

TL;DR: On March 20, 2026, the White House released a “National Policy Framework for Artificial Intelligence”: a legislative blueprint telling Congress how to regulate AI. The centerpiece: federal preemption of state AI laws. States wouldn’t be allowed to regulate AI development. Developers couldn’t be held liable for what third parties do with their models. “Light-touch” federal standards would replace the stronger protections that states like Colorado, Virginia, and Illinois have spent years building. The framework also pushes child safety through age verification (which requires biometric data collection from everyone) while simultaneously weakening the state privacy laws that restrict that collection. It’s not a law yet. But 20+ state privacy frameworks are in the crosshairs.

What the White House Actually Wants

The framework emerged from President Trump’s December 11, 2025 executive order titled “Ensuring A National Policy Framework For Artificial Intelligence.” It lays out seven priority areas for Congress [1]:

  • Child safety: Age verification requirements, parental control tools, safeguards against exploitation
  • Economic growth: Streamlined permits for AI data centers, ratepayer protections for electricity costs
  • Intellectual property: Defer copyright questions to courts, support voluntary licensing, protect against unauthorized digital replicas of voice and likeness
  • Free speech: Bar federal agencies from pressuring platforms to moderate content based on political ideology
  • Innovation: Regulatory sandboxes, rely on existing agencies rather than creating new AI regulators
  • Workforce: AI training integration into education programs
  • Federal preemption: One set of national rules, overriding state AI laws

Seven items. But item seven is doing all the heavy lifting.

The Preemption Play: Kill State Laws, Install Weaker Federal Ones

The framework doesn’t dance around it. States should not be permitted to [2]:

  • Regulate AI development
  • Penalize AI developers for what third parties do with their models
  • Burden the use of AI for activities that would be lawful if done without AI

Read that last one again. If an activity is legal when a human does it, states can’t regulate AI doing the same thing. Sounds reasonable until you think about scale. A human reviewing job applications is legal. An AI rejecting 10,000 applications per hour using biased training data? Also legal, under this framework, and states couldn’t touch it.

The White House calls this avoiding a “fragmented landscape” that “raises costs for companies operating across state lines” and undermines “national economic and security objectives” [3]. Speaker Mike Johnson framed it as needing to “beat China in the global AI race” [3].

States get to keep a few things: zoning authority over data centers, control over their own government’s AI procurement, and the ability to enforce “generally applicable laws.” Everything else (the hard-won consumer protections, the impact assessments, the transparency requirements) goes to the federal level. Where “light-touch” is the guiding philosophy.

What States Would Lose

This isn’t abstract. Specific laws are in the crosshairs:

Colorado’s AI Act was the first comprehensive state AI law in the country. It requires companies deploying “high-risk” AI systems to conduct impact assessments, perform annual reviews, and provide transparency mechanisms. The Trump administration’s December executive order specifically named Colorado’s law as an example of “harmful excessive State regulation” [4]. Colorado already delayed implementation from February to June 2026 under industry pressure. Federal preemption would kill it entirely.

Virginia’s facial recognition ban for law enforcement takes effect July 1, 2026. Under the framework’s logic (that states can’t regulate AI doing things that are legal when humans do them) this ban could be challenged. A police officer looking at someone’s face is legal. An AI matching faces against a database at scale? The framework suggests states can’t distinguish between the two.

New York’s RAISE Act, signed by Governor Hochul on March 27, 2026, requires frontier AI developers to publish safety protocols, file transparency reports, and report AI incidents within 72 hours. Civil penalties start at $1 million [5]. Federal preemption would override these requirements before they take effect in January 2027.

Illinois BIPA (the Biometric Information Privacy Act) lets individuals sue companies that collect biometric data without consent. It’s produced hundreds of millions in settlements: $650 million from Facebook in 2021, $228 million from TikTok in 2024. The framework’s liability shield for AI developers could undercut BIPA’s enforcement model when biometrics are collected through AI systems.

Ropes & Gray, the law firm, noted that the framework recommends states “not be permitted to regulate AI development” or “penalize AI developers for third-party unlawful conduct involving their models” [2]. That’s a direct shot at state liability frameworks.

The Liability Shield: Can’t Sue the Tool Maker

The framework recommends “restricting developer liability for unlawful conduct by third parties using their systems” [1]. In plain English: if someone uses an AI model to discriminate, surveil, or harass, you can’t sue the company that built the model.

Brad Carson of Americans for Responsible Innovation didn’t mince words: the framework offers “another chance for tech companies to launch harmful products with no accountability” [3].

This matters for surveillance because AI-powered tracking, facial recognition, and predictive policing systems are built on foundation models. If a city deploys a facial recognition system that produces wrongful arrests (and we’ve documented at least 14 cases) the framework suggests the model developer bears no responsibility. Only the deployer. Good luck suing a municipal police department with qualified immunity.

The Age Verification Paradox (Again)

The framework’s child safety section calls for “commercially reasonable, privacy protective, age assurance requirements” [1]. Sounds careful. But here’s what “age assurance” means in practice: scanning faces, checking government IDs, or analyzing behavioral data to guess someone’s age.

The framework pushes this while simultaneously recommending the preemption of state biometric privacy laws that regulate exactly this kind of collection. Illinois BIPA requires informed consent before collecting facial geometry. Several states require data minimization for biometric processing. The framework’s preemption language could override all of it.

We’ve seen this pattern before. The FTC did the same thing with COPPA: new rules taking effect tomorrow protect children’s biometric data while the FTC’s own age verification guidance encourages companies to collect biometric data from everyone to figure out who the children are.

The framework takes it further. By preempting state laws that restrict biometric collection, it removes the legal barriers that currently make companies think twice before building age verification databases. The “commercially reasonable” standard is whatever the industry says it is.

What the Framework Doesn’t Do

Look at what’s missing:

  • No federal privacy law. The framework calls for preempting state AI laws but doesn’t propose replacing them with comprehensive federal privacy protections. There’s no federal equivalent of Illinois BIPA, Colorado’s AI impact assessments, or Virginia’s facial recognition restrictions.
  • No new regulatory agency. Rather than creating an AI regulator (like the EU’s approach), the framework relies on existing sector-specific agencies (the FTC, SEC, FDA) that are already stretched thin.
  • No expanded data privacy for children. Despite the child safety framing, the framework “affirms” existing COPPA protections rather than expanding them. No new protections for teens 13-17. No new restrictions on data collection.
  • No warrant requirements for AI surveillance. Nothing about law enforcement use of AI for surveillance, predictive policing, or social media monitoring.

The framework preempts what states built. It doesn’t replace what it tears down.

Where This Goes From Here

This is a legislative recommendation, not a law. Congress has to act on it. But the groundwork is already being laid:

  • The Justice Department was ordered to create an AI Litigation Task Force within 30 days of the December executive order, specifically to sue states over their AI laws [4].
  • The Commerce Department had 90 days to identify “onerous” state regulations, with Colorado’s AI Act explicitly named [4].
  • Senator Marsha Blackburn is working to “develop legislation that can garner bipartisan support and accomplish the president’s goals” [3].
  • The tech industry’s AI lobbying spend has shattered records in 2025 and 2026.

The EU went the opposite direction. The EU AI Act, with full enforcement starting August 2, 2026, imposes strict requirements on high-risk AI systems, bans certain AI practices outright, and holds developers liable. The White House framework is an explicit rejection of that approach. Reed Smith described it as favoring “light-touch regulation and industry standards” over the EU’s “rigid approach” [6].

For Americans, the question is simple: do you want AI regulation that protects companies from state accountability, or AI regulation that protects people from companies? The White House has made its choice. Congress gets the next one.

References

  1. Sullivan & Cromwell: White House Releases National Policy Framework for AI (March 2026)
  2. Ropes & Gray: Federal Preemption of State AI Laws (March 2026)
  3. Governing: White House AI Framework Pushes for Broad Preemption of State Laws
  4. Clark Hill: What Does Trump’s AI Executive Order Mean for Colorado’s AI Act?
  5. Governor Hochul: Signs RAISE Act for Frontier AI Models (March 27, 2026)
  6. Reed Smith: Decoding the 2026 White House AI Blueprint
  7. Holland & Knight: White House Releases National AI Policy Framework (March 2026)