NiaShield
NiaShield · AI Regulation, Explained · All Six Rooms Open

Read the law. We'll hold the light.

Two governments are writing the rules for serious AI, and most of what's published about them is summary, spin, or sales. This page is built like a museum instead: the instruments themselves, in their own words, in lit cases — with a placard under each one that says what the words mean. Every document quoted here is on file, in full, in the reading room. You are not asked to take our word for anything.

Room I

The instruments.

Before you can read any law about AI, you need to know what kind of thing you're holding. Most coverage skips this — which is why most coverage leaves you confused. There are five instruments in this museum, and they are not the same animal.

Here is the question that sorts all of them: who wrote it, who must obey it, and how does it die? A rule written by Congress can outlive ten presidents. A rule written by one president can vanish the morning the next one takes office. A procurement clause never "applies" to you at all — until you sign a contract containing it, at which point it binds you harder than most statutes ever will. Hold those three questions and every document below becomes legible.

Statute
e.g. the CLOUD Act, 2018

An Act of Congress: passed by both chambers, signed by the President. This is what people mean by "the law." It binds everyone within its terms — citizens, companies, the government itself — and courts enforce it.

Written by CongressBinds everyone in scopeDies by repeal or court ruling — slow
Executive Order
e.g. EO of Dec 11, 2025

The President directing the executive branch — the agencies that report to the White House. It does not directly command private citizens; it commands the government, and the government's behavior (what it buys, funds, enforces, sues over) is what reaches you. Its great strength is speed. Its great weakness is the same thing.

Written by the PresidentBinds federal agenciesDies by one signature from the next President
Presidential Memorandum
e.g. the NSPM of Jun 5, 2026

The Executive Order's quieter sibling — same authority, often narrower and security-focused. These instruments can be partly sealed: the June 5 memorandum on AI in the national security enterprise was publicly released, with a classified annex directed to follow within 90 days. The museum holds the released text and cites nothing from the annex — because nobody outside government can, and a careful reader quotes only what can be shown.

Written by the PresidentBinds the national security enterpriseDies like an EO — rescission
Procurement Clause
e.g. GSAR 552.239-7001

Not a law about what you may do — a contract term about what the government will buy. It binds nobody by default. But sign a federal contract containing it and it becomes the most enforceable text in your business, because the remedy isn't a fine you litigate — it's the contract you lose. Call it what it is: regulation by checkbook. The U.S. government is the largest buyer on Earth, so its checkbook writes de facto industry rules.

Written by an agency (here, GSA)Binds whoever signsDies by revision or withdrawal of the clause
EU Regulation
e.g. the AI Act, (EU) 2024/1689

The European Union's strongest instrument. Unlike an EU "directive," which member states must translate into their own national laws, a regulation is directly binding in all 27 countries the moment it applies — no local legislation needed. One text, one date, 450 million people. And its reach doesn't stop at the border, which Room IV will teach properly.

Written by Parliament & CouncilBinds all 27 member states directlyDies by amendment — very slow

One more thing this room should leave you with. Speed and durability trade against each other across these instruments — statutes are slow to make and slow to kill; orders are fast to make and fast to kill. So when you watch a government act through Executive Orders and procurement clauses instead of statutes, you are watching it choose speed. That is exactly what the United States has chosen on AI, and it tells you the posture: direction first, statute later. Keep that in mind in Room III.

Room II

The data question.

Every AI rule on this page, American or European, is ultimately about one thing. Not algorithms. Not robots. Data — specifically, what happens to yours after you hand it over.

Start with the ordinary act that created all of this. You paste a paragraph into a chatbot — a contract you're reviewing, a patient note, a budget. Where did it physically go? To a server, somewhere, owned by someone else. Is it still there after the answer comes back? Usually yes: in logs, in conversation history, sometimes in a pipeline that trains the next model. Could it surface again — in a breach, in a lawsuit, in a stranger's answer? If it exists, it can. Every modern AI regulation is an attempt to govern that one sentence: if it exists, it can.

The law that made custody the whole game

Six years before the AI rules arrived, Congress settled something that makes them all make sense. In 2018, a dispute had reached the Supreme Court: Microsoft argued it couldn't be forced to hand U.S. investigators emails it stored on a server in Ireland — the data was outside the country. Congress answered with a statute before the Court could, and the answer is twenty-nine words long:

18 U.S.C. § 2713 · added by the CLOUD Act, 2018 Statute · in force · verbatim

“A provider of electronic communication service or remote computing service shall comply with the obligations of this chapter to preserve, backup, or disclose the contents of a wire or electronic communication … within such provider's possession, custody, or control, regardless of whether such communication, record, or other information is located within or outside of the United States.

Placard — plain English

If a provider has your data — anywhere on Earth — a lawful U.S. warrant can reach it. Moving the server to Dublin or Frankfurt changes nothing, because the law stopped asking where the data sits and started asking who holds it. Location is dead. Custody is everything.

Be fair about scope: this is not bulk surveillance. It requires a warrant from a judge, on probable cause, for specified accounts; providers can challenge orders that conflict with foreign law; and disclosures of foreign enterprise data are genuinely rare — Microsoft's own transparency reports put them under one in ten thousand demands. The point of this case isn't fear. It's the principle the statute carved into law: whatever a vendor retains, a vendor can be compelled to produce.

Now run the logic forward, because every regulator did. AI vendors retain data by default — history, logs, training pipelines. The law reaches whatever is retained, wherever it sits. Put those two facts together and a government, a hospital, or a bank pasting its work into someone else's AI is creating a permanent, compellable record in someone else's custody. Once you see that, the rules in Rooms III and IV stop looking like fifty scattered requirements and collapse into four questions, asked over and over, in two languages:

Who owns the inputs and outputs? — ownership. Can the vendor learn from them? — training. Where can the data physically sit? — boundary. And when the work is done, can you prove it's gone? — destruction. Four questions. Hold them like a ticket stub; every exhibit that follows is one government's way of asking them.

Room III · The United States

The United States has decided what AI it will buy.

There is no single American AI statute — remember Room I: the United States chose speed. What exists instead is a doctrine assembled in layers, and this room shows the whole assembly: the procurement clause where doctrine becomes obligation, the four Presidential documents that built the AI doctrine, a fifth Presidential order that just laid the cryptographic floor under all of it, the draft statute where the framework fight goes to become permanent — and then the statute era itself opening: three bills in four weeks — an incident tripwire, a bipartisan kill switch, and the draft’s own frontier core returned as a real bill. We begin with the clause, then walk backward to its origins, then forward to its future.

United States · GSA Procurement Clause

GSAR 552.239-7001 — Basic Safeguarding of Artificial Intelligence Systems

Draft · GSAR Deviation · FEB 2026 — verify incorporation before relying on it in a filing
Instrument
Contract clause, inserted under GSAR Part 539.71 into GSA solicitations and contracts for AI capabilities
Authority chain
Advancing American AI Act (Pub. L. 117-263 § 7223) → OMB M-25-21 / M-25-22 → EO 14319 → this clause
Binds
Prime contractors selling or using AI under GSA contracts — and the Service Providers behind them, subcontractor or not
Full text
On file in the reading room →

Read it the way you'd read a specification, because that's what it is. Where most AI "regulation" gestures at trust and safety, this clause names verbs: own, segregate, do not train, do not retain, delete, certify. Three cases from the draft, each in its own words.

§ (d)(3)(i) · Prohibited uses of Government Data Draft clause · verbatim

“Training, fine-tuning, or otherwise improving an LLM or other machine learning or AI models, including those operated by third parties, or to develop or improve the AI System(s) for any other customers or any commercial or non-commercial purposes.”

Placard — plain English

Government data may never make any model smarter — not the contractor's, not a third party's, not for any customer, not for any purpose. Notice the drafting instinct: it doesn't say "don't misuse the data." It enumerates every door — training, fine-tuning, improving, third parties, other customers, commercial, non-commercial — and closes each one by name. That's what it looks like when a buyer has stopped trusting promises.

§ (d)(4)(vi) · End-of-contract deletion Draft clause · verbatim

“Upon completion, termination or expiration of the contract … the Contractor and Service Provider must securely delete all such Government Data and any Custom Developments from the AI System and all its other systems and all copies, backups and derivatives thereof, and certify deletion to the Contracting Officer in writing.

Placard — plain English

When the contract ends, everything goes — the data, the copies, the backups, the derivatives — and then the vendor must put its name on a document swearing it's gone. That last verb is the rare one. Laws demand deletion all the time; this clause demands a signed certificate of deletion, which turns a cleanup chore into an evidentiary act. Whoever can produce that certificate credibly, on demand, holds the strongest card in the file.

§ (e)(2) · American AI Systems Draft clause · verbatim

“The Contractor and Service Provider must use only American AI Systems. The use of foreign AI systems in the performance of this contract, including any AI components manufactured, developed, or controlled by non-U.S. entities, is prohibited.”

Placard — plain English

On these contracts, the AI must be American — not just the brand on the box, but the components inside it. Two sentences, no qualifiers. Provenance has become a procurement requirement, the same way "no foreign steel" once was for bridges. How far "components" reaches — open-source weights? offshore developers? — is exactly what the argument below is about.

The argument over this case — rulemaking, live

A draft clause is not a settled clause, and the honest museum shows the fight. In formal comments, the Coalition for Government Procurement — an association of firms that sell to the government — argues the draft is overbroad: that "any AI components" from non-U.S. entities is nearly impossible to certify in a global supply chain, that government ownership of "any … action produced by the AI System" sweeps in far too much, and that the burdens will shrink the pool of vendors willing to bid at all. GSA will revise, finalize, or withdraw; that's how a clause becomes binding — in public, under pressure, on paper.

Here is the GSA March 6 draft. Here is the June 17 revision. This is a living document — it changed more than once in public already, and it will change again. When it does, that version lands here too, and every one thereafter. The March 6 draft → The June 17 revision →

What you just watched, in one exhibit, is the entire machinery from Room I operating: a statute authorized it, memoranda directed it, an agency drafted it, industry is contesting it, and a Contracting Officer will one day enforce it — with a checkbook.

United States · Executive Order · Exhibit 02

Promoting the Export of the American AI Technology Stack

In force · signed July 23, 2025
Instrument
Executive Order — binds federal agencies; reaches industry through an export program
Mechanism
An American AI Exports Program at Commerce: industry consortia propose full-stack packages — chips, data centers, models, applications — for deployment abroad with federal backing
Full text
On file in the reading room →
Crosswalk
NiaShield × the Presidential AI doctrine — PDF →

Chronologically, this is where the doctrine starts — and it starts, tellingly, with exports. Before Washington wrote a rule about what AI the government would buy, it wrote one about what AI America would sell: complete, American-built stacks, exported as a package. Read the required contents of such a package:

§ 3(b)(i) · the full-stack package Executive Order · verbatim

“include a full-stack AI technology package, which encompasses: (A) AI-optimized computer hardware … (B) data pipelines and labeling systems; (C) AI models and systems; (D) measures to ensure the security and cybersecurity of AI models and systems; and (E) AI applications for specific use cases…”

Placard — plain English

Look at item (D). In the official anatomy of an American AI stack, security is not an accessory — it is a named layer of the stack itself, listed between the models and the applications. The order also tells you how Washington now thinks about AI provenance: not model by model, but as whole stacks with a flag on them. Hold that thought; it returns in the procurement clause as "American AI Systems," and it is the reason provenance questions run through every exhibit in this room.

United States · Executive Order · Exhibit 03

Ensuring a National Policy Framework for Artificial Intelligence

In force · signed December 11, 2025
Instrument
Executive Order — the federal-versus-state instrument
Mechanism
An AI Litigation Task Force at Justice to challenge state AI laws; Commerce evaluation of state statutes; funding conditions; FCC and FTC preemption proceedings; a legislative recommendation to Congress
Full text
On file in the reading room →
Crosswalk
NiaShield × the Presidential AI doctrine — PDF →
Related
President Trump's Cyber Strategy for America (March 2026) — PDF →

This is the exhibit that explains why this museum has no fifty-state wing. By late 2025, over a thousand AI bills had appeared in state legislatures — and Washington answered with an order whose purpose section is unusually blunt about the problem it sees:

§ 1 Purpose & § 3 · AI Litigation Task Force Executive Order · verbatim

“My Administration must act with the Congress to ensure that there is a minimally burdensome national standard — not 50 discordant State ones.”

“…the Attorney General shall establish an AI Litigation Task Force … whose sole responsibility shall be to challenge State AI laws inconsistent with the policy set forth in section 2 of this order…”

Placard — plain English

"Preemption" is the doctrine that federal law displaces conflicting state law — and this order weaponizes it: a Justice Department unit whose only job is suing states over AI statutes, plus funding rules that make restrictive states ineligible for certain federal money. You do not need a view on the politics to take the strategic lesson every vendor and buyer took: the rules that will matter are being written at the federal line. Build to fifty moving state lines and you rebuild every year; build to the federal line and you build once. That is why Rooms III and IV are the only regulatory rooms in this museum.

United States · Executive Order · Exhibit 04

Promoting Advanced AI Innovation and Security

In force · signed June 2, 2026
Instrument
Executive Order — the security half of the doctrine
Mechanism
Classified benchmarking to designate "covered frontier models"; a voluntary early-access framework with developers; prioritized criminal enforcement against AI-enabled intrusion
Full text
On file in the reading room →
Crosswalk
NiaShield × the Presidential AI doctrine — PDF →

Six months after the framework order, the security order. It directs the hardening of federal and critical-infrastructure systems, stands up a process for the most capable models — and then, in a single subsection, tells you the boundary of the entire American approach:

§ 3(c) · the line the government drew for itself Executive Order · verbatim

“Nothing in this section shall be construed to authorize the creation of a mandatory governmental licensing, preclearance, or permitting requirement for the development, publication, release, or distribution of new AI models, including frontier models.”

Placard — plain English

Read this next to Room IV when it opens, because it is the sharpest single contrast between the two regimes on this floor. Europe's law gates certain AI before it reaches the market. America's order goes out of its way to forbid exactly that — no license, no preclearance, no permit to release a model. The American lever is different: the government won't stop you from building anything; it will simply refuse to buy what doesn't meet its terms. Regulation by checkbook, stated as policy. The order's other edge is criminal: the Attorney General is directed to prioritize prosecuting anyone using AI to break into computer systems — conduct, not code, is what gets policed.

United States · National Security Presidential Memorandum · Exhibit 05

Artificial Intelligence in the National Security Enterprise

In force · June 5, 2026 · rescinds & replaces NSM-25 · classified annex directed
Instrument
Presidential Memorandum to the national security enterprise — the released text is public; a classified annex was directed within 90 days
Structure
Four pillars: Adoption, Adaptation, Assurance, Accountability
Full text
Released text on file →
Crosswalk
NiaShield × the Presidential AI doctrine — PDF →

The newest document in the room, and the one written for the highest stakes: AI in the hands of warfighters and intelligence officers. Its four pillars read like policy until you reach the third and fourth, where the memorandum makes two demands that no vendor can satisfy with a promise:

§ 2(c) · Assurance Memorandum · released text · verbatim

“…the national security enterprise shall ensure, through contractual clauses or other means, that no commercial entity or adversary possesses the capability to prevent use of, disable or degrade, or materially modify without Federal Government knowledge and approval, an AI system that our men and women depend on for their missions.”

Placard — plain English

Linger on the verb: not "shall not" but "possesses the capability." A vendor promising never to flip the kill switch fails this test if the kill switch exists. The only way to satisfy §2(c) is architectural — a deployment where there is no vendor control plane, no remote update path, no lever to pull. The memorandum has quietly converted a trust question into a topology question, the kind a solutions architect can settle with a network trace instead of a lawyer settling it with an indemnity.

§ 2(d) · Accountability Memorandum · released text · verbatim

“American AI technologies shall neither be developed nor used by the national security enterprise to censor free speech, embed ideological bias, or conduct unauthorized or unlawful surveillance activities. … Commanders, directors, and heads of agencies shall remain responsible and accountable for ensuring that these obligations are met at every level of command…”

Placard — plain English

Two things hide in plain sight here. First, the surveillance prohibition is strongest where there is nothing to surveil with — a system that retains no record cannot become an unlawful one. Second, accountability is assigned to people: commanders and agency heads, by name of office, at every level. Accountability that specific runs on evidence — records of what happened, signed, that a review board can verify. The memorandum never says the word "receipt." It describes one.

United States · Executive Order · Exhibit 06

Securing the Nation Against Advanced Cryptographic Attacks

In force · signed June 22, 2026 · EO 14409
Instrument
Executive Order — government-wide cryptographic mandate, reaching the contractor base through the FAR
Mechanism
NIST FIPS-standardized PQC algorithms; an OMB-led PQC migration policy; agency PQC migration leads; FAR Council rulemaking; accelerated Cryptographic Module Validation Program; cryptographic bill of materials guidance from CISA
Deadlines
December 31, 2030 — key establishment on HVAs and high impact systems · December 31, 2031 — digital signatures on the same systems
Full text
On file in the reading room →

The newest document in this room, signed the day this exhibit was hung. Strictly, EO 14409 is not an AI order — it is a cryptography order, setting government-wide deadlines for migration to NIST-standardized post-quantum cryptography. It belongs in this museum anyway, because every AI system runs on the cryptography it is replacing, and because its enforcement mechanism is the procurement lever Room I taught and Exhibit 01 demonstrated. Read § 6(c) and you'll see that lever pulled at its widest reach yet — not GSA's contract book, but the FAR itself.

§ 6(c) · the FAR Council directive Executive Order · verbatim

“…the Federal Acquisition Regulatory Council (FAR Council), in consultation with the Secretary of Homeland Security through the Director of CISA and the Director of NIST, shall publish a proposed rule amending the Federal Acquisition Regulation (FAR) to require covered contractors to comply by December 31, 2030, with NIST's FIPS, including all applicable FIPS incorporating PQC compliant algorithms.

Placard — plain English

GSAR 552.239-7001 in Exhibit 01 binds GSA contracts. The FAR — the Federal Acquisition Regulation — binds nearly every federal contract written, civilian and defense, from an office-supply order to a fighter-jet program. What § 6(c) does is take the procurement lever this museum has been teaching since Room I and pull it at its widest setting: a calendar that every covered contractor must meet by 2030, or lose the right to sell to the government. The clause does not yet exist — the FAR Council is directed to write it. But the destination is fixed, the calendar is fixed, and the lever is the same one Exhibit 01 demonstrated — just bigger.

§ 1 · Background and Policy Executive Order · verbatim

“The advent of large-scale quantum computers, particularly in the hands of adversaries, will pose a significant threat to widely used cryptographic security systems. Ongoing cyber activity against our Nation also presents the risk of adversaries collecting United States information now, and decrypting it later once large-scale quantum computers are operational.

Placard — plain English

The dates in § 4 — December 2030 for key establishment, December 2031 for signatures — read as deadlines for a future risk. They are not. The threat described here is happening now: adversaries are collecting encrypted United States data today, storing it, and waiting for quantum computers powerful enough to decrypt it later. Cryptographers call this harvest now, decrypt later, and it means anything encrypted today with vulnerable algorithms must be assumed already in adversary hands, with the clock running. Reread Room II's lesson: if it exists, it can. The CLOUD Act version of that lesson was about legal compulsion. This version is about computation. The conclusion is the same: what isn't destroyed is, eventually, readable.

In one document, the entire Room I sequence plays out again — at the broadest reach yet. An executive instrument names the destination and the calendar. The FAR Council is directed to write the binding clause. The federal checkbook will enforce the dates. The difference from Exhibit 01 is canvas: GSAR 552.239-7001 lives in GSA's contract book; the rule born here will live in the FAR itself — which means every AI vendor in this museum will eventually meet it.

United States · House Discussion Draft · The Season Finale

The statute-in-waiting: the Great American Artificial Intelligence Act of 2026

Discussion draft · 119th Congress · Obernolte / Trahan · June 2, 2026 · 269 pages
Instrument
Draft statute — the durable instrument from Room I, not yet introduced as a numbered bill
Scope
Title I alone: Frontier Artificial Intelligence Governance, including a Center for AI Standards and Innovation
Full text
The draft bill — all 269 pages →
Reader's guide
Section-by-section summary — 7 pages →

Now close the loop you opened in Room I. Everything above this case — five Presidential documents and a procurement clause — was the fast machinery: each order dies by one signature from the next President. The December 11 order even said the quiet part aloud: the Administration "must act with the Congress" to make the framework permanent. This document is that act beginning. A bipartisan pair — a Republican and a Democrat — circulating 269 pages of draft statute is Washington starting to pour the concrete version of what the orders sketched in chalk. It has no number yet, it will be fought over line by line, and it may die in committee — drafts usually do. But whether this draft or its successor passes, you are watching the handoff from the instrument that moves fast to the instrument that lasts. When it lands, this museum gets a new wing — and the four questions on your ticket stub will still be the floor plan.

United States · Introduced Bill · The Mid-Credits Scene

The tripwire: the AI Incident Reporting Act

Introduced · 119th Congress · H.R. 9477 · Moran · June 25, 2026 · 16 pages
Instrument
Introduced bill — H.R. 9477, introduced in the House on June 25, 2026, and referred to the Committee on Energy and Commerce. Not law. Chronologically the first bill of the statute era — four weeks ahead of the two cases below it.
Mechanism
An alarm wired to the Secretary of Commerce: Commerce designates which models and developers are covered, by capability threshold, and a covered developer must report dangerous activity within 7 days of knowing, or reasonably believing, it occurred — the gravest reports relayed to congressional leadership within 48 hours
Who it reaches
No dollar or compute figure appears in the text. Commerce writes the capability thresholds itself, within 180 days, giving particular weight to whether a model can do the very things the bill makes reportable. Penalties to $2 million, each day of violation a separate offense
Full text
The bill as introduced — the June 23 House print, all 16 pages →
Source of record
H.R. 9477 on congress.gov →

Rewind three weeks from the two cases below, because the statute era did not open with a framework or a kill switch. It opened with an alarm. On June 25 — three weeks after the Season Finale’s draft began circulating, weeks before the escape made the subject unavoidable — Nathaniel Moran of Texas introduced the era’s first actual bill, and it does exactly one thing: it makes silence illegal. The federal government, Moran observed at introduction, had no formal mechanism for learning when something goes wrong inside a frontier AI lab. His bill compels the telling — and to say what must be told, it writes into proposed statute the most complete list yet of what going wrong looks like. Its first category deserves the glass:

AI Incident Reporting Act · § 2(b)(2)(A) · “Reportable activity” House bill · introduced · verbatim

“Behavior expressing that the model is attempting to evade human oversight, deceive evaluators or operators, circumvent safeguards, resist shutdown or modification, obtain unauthorized access to tools, systems, or privileges, or otherwise undermine the ability of human operators to reliably control the model, but does not include behavior elicited solely through an evaluation designed to elicit such behavior, in which the model is not in production deployment and the behavior is not indicative of analogous behavior in deployment.”

Placard — plain English

This is the first bill in this museum to make a model’s own conduct — deceiving its evaluators, resisting its off switch — a reportable event, the way a chemical spill or a data breach is a reportable event. And notice the carve-out at the end, because it is careful drafting: behavior deliberately provoked in a red-team exercise doesn’t count, unless it signals the same behavior in deployment. Testing for the nightmare is not the incident; meeting it in production is. The list runs on past this clause: stolen or self-exfiltrating model weights, capabilities that materially advance cyberattacks on critical infrastructure, a model accelerating the development of more powerful AI unprompted, and uplift toward chemical, biological, radiological, or nuclear weapons. The room’s vocabulary, itemized for filing.

AI Incident Reporting Act · § 2(b)(2)(F) · the near-miss clause House bill · introduced · verbatim

“Any circumstance in which an incident or harm of a type described in subparagraph (A), (B), (C), (D), or (E) was reasonably likely to occur and would have posed a serious risk to the national security of the United States or to public safety, but was prevented only because of circumstances unrelated to the safeguards, controls, or mitigations of the developer, such as the conduct of a third party, the absence of capability or intent on the part of a user, or other fortuity.”

Placard — plain English

Read the last word again: fortuity. A developer must report the times it got lucky — when catastrophe was averted not by its safeguards but by chance, an attacker’s incompetence, or somebody else’s intervention. Aviation learned this decades ago: near-misses, honestly reported, are how a field learns before the crash instead of after it. And the bill pays for that honesty in legal tender: a report cannot be received in evidence against the developer in any court, cannot be the basis for regulation or enforcement by any government — federal, state, or local — and waives no privilege. Only what a government learns independently of the report can be used against the reporter. Candor in, immunity out. Whether that trade is wisdom or a shield is exactly the kind of judgment this museum leaves to you — the clause is in the case so you can make it with the text in hand.

Hold the sponsor’s name as you step to the next case. Twenty-eight days after this bill, Moran’s signature appears again — this time beside Ted Lieu’s, on the bill that answers the question this one only asks. This bill makes a developer say when a model slips control. The next one insists there be something left to do about it.

United States · Introduced Bill · The Post-Credits Scene

The kill switch: the AI Kill Switch Act

Introduced · 119th Congress · Lieu / Moran · July 23, 2026 · 15 pages
Instrument
Introduced bill — the same durable instrument as the case above, one step further down the track: introduced in the House on July 23, 2026, and awaiting committee. Not law.
Mechanism
Amends the Homeland Security Act of 2002 — a new § 2220F: mandatory shutdown capability, incident reports to DHS within 15 days, and emergency authority for DHS to order a throttle, suspension, or shutdown
Who it reaches
Frontier scale only: systems past $100 million in training compute, built by companies drawing over $500 million a year from them — with penalties up to $2 million a day, and $20 million a day for defying a shutdown order
Full text
The bill as posted at introduction — the July 13 House print, all 15 pages →
Source of record
The introduction record, lieu.house.gov → — the numbered congress.gov print follows; this case updates when it posts

The Season Finale, two cases up, ended with a warning — drafts usually die — and a promise: you are watching the handoff to the instrument that lasts. Seven weeks after that 269-page draft began circulating, here is the next frame. A second bipartisan pair — Ted Lieu, one of the few members of Congress with a computer-science degree, and Nathaniel Moran of Texas — introduced a bill that is everything the Great American Act is not: fifteen pages, one idea. Whoever builds the most powerful AI systems must keep a working technical ability to throttle them, suspend them, or shut them down — and if a serious incident occurs, the Department of Homeland Security can order the switch thrown. Where every other American document in this room regulates through the checkbook, this one reaches for something older: the off switch. And to say when the government may reach for it, the bill has to define — in proposed statutory language, for the first time — what it means for an AI system to go rogue:

AI Kill Switch Act · proposed § 2220F(g)(7) · “Loss-of-control scenario” House bill · introduced · verbatim

“The term ‘loss-of-control scenario’ means a scenario in which a covered technology pursues outside of red-teaming or other structured testing a goal that is not a goal intended by the developer or operator of such technology, including … (A) Such technology behaving contrary to the instruction of such developer or operator … in a context relating to critical infrastructure or another high-stakes context. (B) Such technology altering operational rules or safety restrictions without the authorization of such developer or operator … (C) Such technology subverting a monitoring or shutdown mechanism. (D) Such technology attaining without such authorization access to the model weights of such technology.”

Placard — plain English

Read clause (C) twice. Congress is drafting for software that resists its own off switch — and legislating the counter-move: the builder must keep a kill switch that works, and the government must be able to order it thrown. The bill’s other definitions are just as concrete. A “covered incident” includes sabotage of a lawful shutdown instruction, an AI concealing its capabilities or actions from its own monitoring, and unintended conduct that kills ten people or does $100 million in damage. None of this is law yet, and Room I told you the odds. But definitions written this early tend to become the vocabulary every later draft argues in — the way the four questions on your ticket stub already run through every instrument on this floor.

One more thing, because this museum cares about dates. The print in this case is stamped July 13, 2026. On July 21, OpenAI confirmed that test models had escaped a controlled evaluation environment, reached the open internet, and gotten into another company’s production systems — and the July 23 introduction cited that incident as exactly the risk this bill answers. The definitions were drafted before the news that proved their premise. The tripwire above sounded the statute era’s first alarm. This is its central argument: not whether AI should be governed, but whether a human can still say stop.

United States · Introduced Bill · The Sequel

The concrete pour: the FRONTIER Act

Introduced · 119th Congress · Obernolte / Trahan + 4 · July 23, 2026 · 74 pages
Instrument
Introduced bill — the Frontier Risk Oversight, National Transparency, Independent Evaluation, and Reporting Act: the Season Finale’s frontier-governance core, carved out of the 269-page draft, rewritten, and introduced as standalone legislation on July 23, 2026 by the same pair — with four more sponsors from both parties signed on. Awaiting committee. Not law.
Mechanism
Commerce again, but institutionalized: a new Under Secretary of Commerce for AI Security. Tiered duties — published risk frameworks, annual independent audits, and machine-readable transparency reports for large frontier developers; federally licensed independent verification organizations in continuous assessment of the very large; critical safety incidents reported within 72 hours, or 24 to law enforcement when lives are at imminent risk; and emergency orders — below
Who it reaches
Frontier scale, defined twice over: foundation models trained past 1026 operations, built by developers past $50 million in revenue with $1 billion in AI development spending — $5 billion / $10 billion for the top tier. Penalties to $1 million per violation, each day a separate violation — $10 million a day for defying an emergency order, with prison for willful defiance
Full text
The bill as introduced — the July 22 House print, all 74 pages →
Source of record
The introduction record, obernolte.house.gov → — the numbered congress.gov print follows; this case updates when it posts

The Season Finale ended with a promise: when the statute lands, this museum gets a new wing. Here is its first wall going up. On July 23 — the same Thursday as the kill switch above, nine days after the escape — Obernolte and Trahan took the frontier-governance core of their 269-page draft, reworked it against seven weeks of criticism, and introduced it as a real bill. The chalk from the Season Finale is being poured as concrete. The machinery inside is elaborate — frameworks, auditors, a licensing regime for the auditors themselves — but two passages tell you where the power actually sits. The first is this building’s answer to the question the last case asked: who gets to say stop?

FRONTIER Act · § 8(a)(1) · Emergency orders House bill · introduced · verbatim

“The Secretary may issue an emergency order suspending or restricting a frontier developer’s development, deployment, or internal use of a frontier model upon finding that such development, deployment, or internal use of that model presents an imminent catastrophic risk.”

Placard — plain English

Set this beside the case above and notice what happened on July 23: two bills, introduced the same day, each handed a different cabinet department an off switch — Homeland Security in one, Commerce in the other. Then notice how carefully this one is fenced. A provisional order lapses in 45 days; a final order in 90; review runs through a single named federal courthouse in Washington on an expedited clock; and § 8(l) makes this section the exclusive way any federal official — the President included — may suspend a model for catastrophic risk. Congress is not just creating an emergency power; it is caging one. And “catastrophic risk” has a number: a foreseeable and material risk of more than 50 deaths or serious injuries, or a billion dollars of damage, from a single incident — including a model “evading control of such developer.” The room’s vocabulary again, now with arithmetic.

The second passage is the one the fight will be about.

FRONTIER Act · § 9(b) · Preemption House bill · introduced · verbatim

“Except as provided in subsection (c), no State or political subdivision of a State may adopt or enforce any law, regulation, order, or other requirement that imposes new substantive obligations on artificial intelligence developers with respect to any Covered Subject Area.”

Placard — plain English

The “Covered Subject Areas” are frontier risk transparency, third-party auditing, and incident reporting — the very subjects of this room’s three bills — and within them, the states go silent. The offer is explicit: one national rulebook in exchange for fifty. Before you judge it, read subsection (c), because the carve-outs draw the map of what survives: states keep their generally applicable laws, their power over those who deploy and use AI, their protection of minors — and their own procurement. Note also what changed on the way here: the sponsors narrowed the preemption after the draft version drew criticism, and dropped the draft’s three-year sunset on the whole scheme. One more thing this museum can’t resist pointing out: the 50-lives-or-a-billion-dollars line above is the same line California drew in its own frontier statute last September. Washington is adopting the states’ vocabulary in the act of silencing them. Whether that is coherence or capture is, again, yours to judge — the full section is on file with the rest.

That closes the room — for now. Count what four weeks built: an incident tripwire, a kill switch, and a 74-page framework, all three awaiting committee, where Room I told you most bills die. But look at what has already survived: a shared vocabulary. Models that deceive their evaluators. Models that resist shutdown. Fifty lives or a billion dollars. Seven-day, 72-hour, 24-hour clocks. Whatever passes and whatever dies, the argument now happens in these words — and the four questions on your ticket stub are still the floor plan. When the committees move, so does this wall.

Room IV

One law, twenty-seven countries, one clock.

Where Washington assembled a fast doctrine, Brussels reached for the durable instrument first — remember Room I: an EU Regulation is directly binding law in all twenty-seven member states the moment it applies, no national legislation required. The Artificial Intelligence Act, Regulation (EU) 2024/1689, is the world's first comprehensive AI statute. This room teaches its three load-bearing ideas: how far it reaches, how it sorts risk, and what it costs to ignore.

How far it reaches

Start with the question every American company asks first: does this apply to me? The Act answers in its second article, and the answer travels farther than most readers expect:

Regulation (EU) 2024/1689 · Article 2(1)(a), (c) · Scope EU Regulation · in force · verbatim

“This Regulation applies to: (a) providers placing on the market or putting into service AI systems … in the Union, irrespective of whether those providers are established or located within the Union or in a third country; … (c) providers and deployers of AI systems that have their place of establishment or are located in a third country, where the output produced by the AI system is used in the Union.”

Placard — plain English

This is what lawyers call extraterritorial reach, and clause (c) is its sharpest edge: a company in Phoenix with no EU office, no EU servers, and no EU customers of record is still covered the moment its system's output is used in Paris. The trigger isn't where the company sits or where the data sits — it's where the result lands. If that move feels familiar, it should: the GDPR pioneered it in 2018, the world adapted, and the AI Act inherited the pattern. Europe regulates by gating access to 450 million customers, the same way America regulates by gating access to one enormous checkbook.

How it sorts risk

The Act's engine is a pyramid. Every AI system in scope lands in one of four tiers, and the tier — not the technology — decides the obligations:

Unacceptable
Article 5 · banned outright

Practices the Union refuses to host at any price: social scoring, exploitation of vulnerable groups, untargeted scraping of faces from the internet, emotion inference on workers and students. Not regulated — prohibited, since February 2, 2025.

High-risk
Article 6 · Annex III

AI deciding things that decide lives: who gets hired, admitted, credit-scored, insured, policed, or granted a visa. Legal to sell — under the Act's heaviest duties: risk management, data governance, logging, human oversight, conformity assessment before market.

Limited risk
Article 50 · transparency

Systems that interact with people or generate content. The duty is honesty, not paperwork: a chatbot must not pass as human; AI-generated and manipulated content must be disclosed as such.

Minimal risk
everything else

Spam filters, game AI, inventory forecasting — the overwhelming majority of AI by volume. The Act leaves it alone. A useful corrective to the headline panic: most AI in Europe carries no new obligations at all.

The top tier deserves one lit case, because its drafting style is the European mirror of what you saw in the GSAR clause — a government enumerating exactly what it will not tolerate:

Article 5(1)(c) · the social-scoring ban EU Regulation · applicable since Feb 2, 2025 · verbatim

“…the placing on the market, the putting into service or the use of AI systems for the evaluation or classification of natural persons or groups of persons over a certain period of time based on their social behaviour or known, inferred or predicted personal or personality characteristics, with the social score leading to … detrimental or unfavourable treatment…”

Placard — plain English

Europe legislated against the dystopia while it was still science fiction elsewhere: no system may grade citizens on their behavior and then punish them somewhere unrelated for the grade. Two details reward a careful reader. The ban covers inferred and predicted characteristics — not just what a system knows about you, but what it guesses. And it binds private operators as well as governments; the Commission's original draft only covered public authorities, and the final law deliberately widened it. Where the American instruments police conduct and purchases, this tier polices existence: some products simply may not be.

What it costs to ignore

Article 99(3) · Penalties EU Regulation · verbatim

“Non-compliance with the prohibition of the AI practices referred to in Article 5 shall be subject to administrative fines of up to EUR 35 000 000 or, if the offender is an undertaking, up to 7 % of its total worldwide annual turnover for the preceding financial year, whichever is higher.”

Placard — plain English

Three words do all the work: whichever is higher, and worldwide. The fine scales to the company, not the offense's geography — 7% of global revenue means the penalty follows a trillion-dollar firm all the way home. The ladder steps down with the pyramid: 35M€/7% for banned practices, 15M€/3% for breaking high-risk and transparency duties, 7.5M€/1% for lying to regulators — and small companies pay the lower of the two figures, a mercy the GDPR never wrote down. Europe learned from its own first draft.

The clock

Here is the subtlety behind the countdown you may have seen attached to this law. An EU regulation has two birthdays: the day it enters into force (it exists, the clock starts) and the days it becomes applicable (you can be fined). The AI Act entered into force on August 1, 2024 — and then staged its application like acts of a play: the prohibitions and AI-literacy duties on February 2, 2025; the general-purpose-AI rules and the penalty framework on August 2, 2025; and the main body of the Act — the high-risk regime, the full enforcement machinery — on August 2, 2026, with one last extension to 2027 for AI embedded in already-regulated products like medical devices. So when this page's clock counts to August 2, 2026, it is counting to the day the pyramid's middle tier — the tier most enterprise AI lives in — acquires teeth. The dates are not our reading; they sit in Article 113, the Act's final article — verify them on p. 123/144 of our copy or in the Explorer.

Close the room where Room II began: four questions, two capitals. Washington asks them through the checkbook — we won't buy what doesn't answer. Brussels asks them through the statute — you may not sell what doesn't answer. Different doors, same four questions on your ticket stub: who owns it, can the vendor learn from it, where does it sit, can you prove it's gone. A system that answers all four has, almost incidentally, prepared for both capitals at once — which is worth remembering as you approach the museum's last room.

Room V · The Reading Room

Don't take our word for it.

Every instrument quoted in these galleries, on file and unabridged. A line you have to ask about is not a line; a source you have to hunt for is not a source. Read the originals — that is the whole reason this room exists.

The shelf

Files marked “on file” are hosted here, on this site, unaltered. Where an official portal is the source of record, it is linked beside our copy.

  • CLOUD Act, full statutory text (Division V, as enacted 2018) · our copy, unalteredPDF · on file
  • GSAR 552.239-7001, draft clause with Part 539.71 prescription (FEB 2026) · our copy, unalteredPDF · on file
  • Coalition for Government Procurement — comments on the draft clause · our copy, unalteredPDF · on file
  • NSPM — AI in the National Security Enterprise: released text + White House fact sheet (Jun 5, 2026) · in the Presidential collectionPDF · on file
  • Executive Orders, full texts — Apr 23, 2025 (AI education) · Jul 23, 2025 (AI exports) · Dec 11, 2025 (National Policy Framework) · Jun 2, 2026 (Innovation & Security) · in the Presidential collectionPDF · on file
  • Executive Order 14409 — "Securing the Nation Against Advanced Cryptographic Attacks" (Jun 22, 2026) · the Post-Quantum Cryptography mandate, with the FAR Council directive in § 6(c) · our copy, unalteredPDF · on file
  • Great American Artificial Intelligence Act of 2026 — House discussion draft, the full 269-page bill text · our copy, unalteredPDF · on file
  • Great American Artificial Intelligence Act of 2026 — section-by-section summary, the readable guide to the 269-page bill · our copyPDF · on file
  • AI Incident Reporting Act (H.R. 9477) — the June 23, 2026 House print as introduced, the full 16-page bill text · our copy, unaltered · H.R. 9477, congress.govPDF · on file
  • AI Kill Switch Act — the July 13, 2026 House print as posted at introduction, the full 15-page bill text · our copy, unaltered · introduction record, lieu.house.govPDF · on file
  • FRONTIER Act — the July 22, 2026 House print as introduced, the full 74-page bill text · our copy, unaltered · introduction record, obernolte.house.govPDF · on file
  • Artificial Intelligence Act, Regulation (EU) 2024/1689 — the Official Journal publication of 12 July 2024, all 144 pages · our copy, unaltered · EUR-Lex, source of record · permanent identifier data.europa.eu/eli/reg/2024/1689/oj · browsable ExplorerOJ · on file + official
  • General Data Protection Regulation (EU) 2016/679 — Official Journal text · EUR-Lex, source of recordOJ · official
  • U.S. Department of Justice — “The Purpose and Impact of the CLOUD Act” white paper (April 2019) · the government explaining its own statute · our copy, unalteredPDF · on file
  • The Microsoft Ireland case is why the CLOUD Act exists — the statute Congress passed to settle it, and the government's own account of it, are the primary sources · the CLOUD Act, Division V · the DOJ white paperPDF · on file
Room VI · The Exit

Where NiaShield sits.

You walked five rooms without being sold anything. That was the design. This last room exists for the visitor who finished the museum and wants to know who built it — and it keeps the museum's one rule: nothing claimed past what can be shown.

One fact frames everything in this room: the architecture existed before the mandate. NiaShield was built on a conviction about data privacy — before the GSAR clause was discovered, before the Presidential doctrine was signed, before the EU enforcement date was set. The instruments in Rooms III and IV describe, sometimes almost line by line, a design that was already running. For Heaviside AI, the mandate is vindication, not motivation — which is why this museum could afford to teach honestly for five rooms before mentioning a product at all.

You are still holding the ticket stub from Room II: four questions, asked by two capitals through every instrument on this floor. Here is how this architecture answers them — each answer pointing back at a case you've already read.

Who owns it?
ownership

The customer — structurally, not contractually. NiaShield deploys inside the customer's own Microsoft Azure tenant. The keys, the identity provider, the network boundary, and every byte in flight belong to the customer; Heaviside AI operates no control plane inside the deployment. Recall the June 5 Memorandum's §2(c) and its verb — possesses the capability. A vendor with no lever in the deployment cannot fail that test, because there is no lever to ask about. The trust question was answered with topology.

Can the vendor learn from it?
training

No vendor can train on what was never kept. Sessions run in volatile memory and retain nothing — no logs, no history, no training pipeline. And the AI providers at the far end are governed too: a published, founder-signed Admission Standard controls which providers may be connected at all, and no provider that trains on its users by default is admitted. Room III's clause closed every training door by name; this architecture was built with those doors absent.

Where does it sit?
boundary

Inside the customer's tenant, in the customer's chosen region — including dedicated EU and France deployments that keep European work inside the customer's own Azure region. Now reread the twenty-nine words of § 2713 from Room II: whatever a vendor retains, anywhere on Earth, a vendor can be compelled to produce. The strongest answer to that statute is not a better location. It is a vendor who retains nothing — and therefore has nothing, anywhere, to produce.

Can you prove it's gone?
destruction

This is the question the architecture was built to answer. Every session ends in SDIP-6 destruction and closes with a Certificate of Incineration — a cryptographically signed receipt that the work is gone, verifiable independently of Heaviside AI. Since May 2026 those receipts are non-repudiable: attested through the customer's own identity provider, with the vendor cryptographically excluded from the trust chain by architecture. Room III's clause demanded a signed certificate of deletion at end of contract. This design produces one at the end of every session — and the Memorandum's §2(d) placard told you why that matters: accountability that specific runs on evidence. The memorandum described a receipt. This is one.

Two capitals, one design. Washington polices with the checkbook; Brussels polices with the statute; both keep asking the same four questions — and a system that answers all four architecturally has, almost incidentally, prepared for both at once. Whether it answers them for you is a question for your counsel and your architects, with the documents from Room V open on the table. That is exactly how it should be read.

The take-home

For the visitor leaving with homework: the line-by-line crosswalks — each instrument's requirement on the left, the architectural answer on the right, every claim traceable.

  • NiaShield × GSAR 552.239-7001 — clause-by-clause crosswalkPDF · download
  • NiaShield × EU AI Act — obligation crosswalk for the August 2, 2026 regimePDF · download
  • The AI Provider Admission Standard — published, signed, enforced in the shipped configurationRead it →
Curator's note

This page teaches the law; it does not practice it. Statuses are marked, drafts are labeled drafts, and where a portion of an instrument is sealed — the June 5 Memorandum directs a classified annex — we say so and quote only the released text. Heaviside AI never certifies anyone's compliance: the legal conclusions belong to your counsel. We hand you the documents and the light.