A Missing Word Makes a Big Difference

Can We Model Better Disagreements about AI Preemption?

Read this post on Neil’s Substack: Getting Out of Control.

Should Congress or the states establish the U.S. framework for AI governance? It is strange to me that this is even a question. “Preemption” has become a litmus test; some seem content to let the states effectively set federal policy on AI.

But recent White House actions to opaquely and unpredictably block frontier AI model releases are spurring bipartisan interest in a more assertive congressional role. As a result, I believe there is right now more room than ever for congressional dealmaking on governance of AI model development.

Making a deal in Congress is always difficult, but it’s even harder when stakeholders don’t agree on what deal is being offered.

I am worried that preemption is becoming such an issue. Consider a recent long analysis of Reps. Obernalte and Trahan’s Great American AI Act (“GAAIA”). The analyst, Charlie Bullock, spends much of the post defending GAAIA from critics.

Yet he also criticizes the bill’s federal preemption of state laws as “sweeping,” while I see it as extremely narrow. Bullock has written a lot about federal preemption, and I’ve generally found he tries to understand other points of view. So I have been trying to work through his analysis to identify the gap between our interpretations.

It all comes down to a missing word.

A Misstated Bargain

Bullock frames GAAIA as a negotiated bargain, but he repeatedly misstates one of the terms of that bargain. He says “state laws will be preempted if they are deemed to ‘specifically regulate’ development.” He describes GAAIA as a strong federal framework purchased at the “steep price” of “broad preemption of all state laws regulating AI development.“ He then predicts that courts will apply a functional test to laws that have “the effect of regulating AI development,“ so that any law that “functions primarily to regulate development,” or that can be complied with only by “altering development practices,” will likely be preempted.

In short, Bullock repeatedly refers to “AI developmentas the relevant regulated activity.

But he’s leaving out a critically important word: model!

Anyone with a passing familiarity with modern AI technology knows there is a difference between an “AI developer” and an “AI model developer.” AI models are the expensively-trained engines of AI applications. Cutting-edge frontier models cost hundreds of millions of dollars to develop. Only a few companies do this. The number of significant new frontier models that come out every year depends on what you consider significant, but it is in the dozens.

By contrast, building AI systems is an activity engaged in by everyone from large multinational companies (including companies that develop models) to solo hobbyists. Hundreds of thousands, likely millions of AI systems are developed every year. Any application that uses an AI model falls into this much larger and sweeping category of AI development.

  • Thus, “AI development” is a much broader category of activity than “AI model development.”
  • And therefore regulation of “AI development” is a much broader category of regulation than regulation of “AI model development.”
  • And therefore preemption of “regulation of AI development” is a much broader preemption than preemption of “regulation of AI model development.”

Bullock’s conclusion that GAAIA has “broad preemption” depends on the fact that he ignores the word “model,” which appears throughout the legislation. Section 121, the preemption section, is titled “Federalization of State Laws Regulating Artificial Intelligence Model Development.” (emphasis added) Its findings state its purpose: “to preempt State regulation specifically targeting artificial intelligence model development” and to allow federal oversight frameworks for “artificial intelligence models.” Its operative preemption clause then bars states from enforcing any law “specifically regulating the development of any artificial intelligence model.”

GAAIA’s definitions further preclude Bullock’s overly broad characterization. The bill defines “artificial intelligence model” narrowly as “the set of parameter values or weights” that define a mathematical function learned through machine learning on training data. The bill also distinguishes “AI model” from “artificial intelligence,” which it defines as a “system.” Thus, GAAIA’s definitions distinguish AI models from AI systems, products, services, chatbots, employment-screening tools, consumer interfaces, recommender applications, and every other form of downstream deployment.

GAAIA’s definition of “development” for the purposes of preemption reinforces the point. Bullock says this definition is “quite broad,” but the language is entirely focused on AI model development. It seems silly to quote this language, because Bullock’s own article did so, but here it is, with emphasis added:

“The term ‘development’ means the acts performed or directed by a developer with respect to an artificial intelligence model prior to its deployment, including determining training or fine-tuning objectives; training, fine-tuning, or otherwise substantially modifying the weights or other parameters of an artificial intelligence model; and evaluating and deciding, prior to deployment, whether an artificial intelligence model satisfies applicable safety or capability thresholds for deployment.”

Every time the word “artificial intelligence” appears in the definition it is immediately followed by “model.” So too for the definition of “developer.” Accordingly, GAAIA then defines “deploy” as making an “artificial intelligence model” available “for use, copying, or combination with other software.”

Confusing GAAIA with State Laws

GAAIA’s development / deployment dichotomy could be confusing if one has looked at state AI legislation. Such bills also often divide the AI ecosystem into “developers” and “deployers.” (See Colorado’s 26-189, for example.) But those laws are splitting up something different than GAAIA. They are distinguishing between the parties that build AI software and the parties that use and operate such software every day. Under such laws, “AI development” is a broad category of activity that covers both model development and application development.

The end result is that there is a large swath of activity that that state laws would label “development” but which GAAIA defines as “deployment.”

Bullock’s analysis confuses GAAIA’s definition of AI model development with state laws’ AI system development. For example, he refers to GAAIA as preempting Texas TRAIGA’s “development-focused regulations” such as those “prohibit[ing] developing an AI system that impersonates a child while describing sexual conduct or developing an AI system with the intention of producing child sexual abuse material or illegal deepfakes.”1

Yet because GAAIA focuses on AI model development, it expressly preserves this kind of state law. Its rule of construction preserves from preemption “any State law or regulation applicable to activities occurring upon or after the deployment of an artificial intelligence model, including any law or regulation governing the implementation, deployment, distribution, offering, or use of any artificial intelligence system, product, or service that incorporates or is derived from an artificial intelligence model.”2 Bullock mentions this exemption once, waving it off as “somewhat opaque.” But, provided one doesn’t ignore the word “model,” GAAIA’s definitions of “development” and “deploy” make clear this exemption’s meaning: state law that regulates AI systems generally survives GAAIA.

And this is most state AI law! States regulate automated decision tools, chatbot operators, deployers, services, and consumer-facing applications. When states use the word “developer,” they typicaly define it to cover those creating AI systems or services, not those pre-training or fine-tuning AI models.

Consider Bullock’s other examples of laws he argues are preempted by GAAIA. Colorado’s SB 189 regulates the use of automated decision-making technology (ADMT) in consequential decisions. It defines ADMT as technology that processes personal data and generates outputs used to make, guide, or assist decisions about individuals. It imposes obligations on developers, but defines them developers of ADMTs or developers of components intended to be used as a covered ADMT. Perhaps some of the latter group are AI model developers that would be protected from SB 189 by GAAIA, but most developers affected by SB 189 are not model developers. Thus, saying GAAIA “almost certainly” preempts the entirety of SB 189 is almost certainly wrong.

The child-safety discussion has a different flaw. Bullock describes such state child safety chatbot laws as “purport[ing] to regulate deployers or ‘operators’ of AI systems.” Such laws would appear to fall outside of GAAIA’s preemption even under Bullock’s mistaken substitution of “AI development” for “AI model development.”

What if child safety advocates weren’t worried about preemption? Bullock gets creative here, saying such laws still might be preempted because they “could realistically be satisfied only via interventions implemented during training or fine-tuning.”

It’s an interesting question: are there laws that require AI system deployers or users to do something that can only really be accomplished during model pre-training and fine-tuning?

More on that in a second — but first, it’s clear that Bullock’s example of Idaho’s Conversational AI Safety Act isn’t such a law. This law defines an operator as a person who makes a conversational AI service available to the public. It imposes operator duties: disclosures, suicidal-ideation protocols, minor-safety measures, and account and privacy tools. None of these mandate or require AI model changes or fine-tuning. A chatbot operator can comply with such child-safety rules at the system layer, through product design, interface disclosures, account settings, age-aware experiences, classifier layers, refusal policies, system prompts, output filters, crisis-routing protocols, parental controls, and human review. Many chatbot builders don’t even develop their own AI models. Finally note that Idaho’s law expressly provides that the chapter “shall not create liability for the developer of an AI model for any violation of this chapter…” by a third party conversational AI operator.3 That is the opposite of a model-development statute.

Preemption Precedent Doesn’t Change The Result

Would GAAIA preempt any state law that could only be complied with by changing model development? It is not obvious — would a court really find that a state law that claims to regulates AI systems but necessitates model changes thereby “specifically” regulates AI model development? But Bullock spends a couple of paragraphs explaining how under some precedent courts might “impose a functional test under which state laws would be preempted if they had the effect of regulating AI development, as defined.”

This analysis could be entirely correct and still not matter much — because “as defined” is an important phrase! Despite Bullock leaving out the word “model” here again, I hope I’ve clarified by now that GAAIA defines development as “artificial intelligence model development.”

This matters because the number of state AI laws that have the effect of regulating model development is very small. Bullocked noted in his piece that I have previously pointed to a few state-level frontier AI safety laws. A few of his other examples also probably qualify: Some CCPA automated-decisionmaking regulations, such as § 7153, which addresses businesses that process personal information to train ADMT; and the portions of California’s AB 2013 that require documentation of the data used to train models. These laws arguably regulate AI model development.

However, the vast majority of state AI regulations can be complied with in other layers of the AI stack — which is good, because most companies building AI systems are not training their own models.

Bullock explains that courts won’t look kindly on state laws that seek to cleverly wordsmith their way around preemption. He’s correct. But writing a law to clearly fit in the stated scheme of GAAIA by regulating AI model deployment and use orather than AI model development isn’t clever wordsmithing, it is following the express design of the legislation.

A Fair Hearing and a Fair Bargain

Bullock really wants a fair hearing for the parts of GAAIA he likes. I think that should hold for the preemption section as well. I hope explaining my view in some detail helps.

More broadly, preemption debates about AI are not over. AI has important national and international policy implications. Congress must lead. Stakeholders involved will need to propose and assess compromises and offers. Yet it will be impossible to strike a bargain on these important issues if the parties involved misunderstand the terms offered by the other side. I hope careful analysis by all sides and continued dialogue between them can help us move toward good federal AI policy.


[1] To drive the point home, TRAIGA’s enforcement provision bars the attorney general from bringing a civil-penalty action “for an artificial intelligence system that has not been deployed.” In other words, TRAIGA specifically prohibits any enforcement against AI model development.

[2] GAAIA Sec. 121(c)(2).

[3] Senate Bill No. 1297, Sec. 48-2105(3).