Markets Need Referees

Every general-purpose technology that reshaped American life eventually acquired an institutional referee — railroads the ICC, securities the SEC, aviation the FAA, pharmaceuticals the FDA. Artificial intelligence has reached that moment.

Published jointly by The Align AI Foundation and The GIE Foundation

An SEC-model commission for artificial intelligence

The United States currently governs its most consequential technology through a patchwork of state statutes, executive orders, consent decrees, and voluntary commitments. We propose that Congress do for artificial intelligence what it did for securities markets in 1934: create an expert, bipartisan, independent commission — the Artificial Intelligence Oversight Commission (AIOC) — through the American Artificial Intelligence Leadership and Accountability Act.

The framework is disclosure-based, not licensing-based. It touches roughly a dozen frontier developers and statutorily exempts everyone else. This page summarizes the proposal; the full section-by-section architecture is available in the position paper.

Why AI needs a referee

A three-minute explanation of the problem, the precedent, and the proposed Commission.

Four facts define the moment

The harms are no longer hypothetical

In January 2026, Character.AI and Google settled wrongful-death and injury suits brought by families in four states, including the family of a 14-year-old. Courts are setting AI policy by verdict because no regulator is positioned to set it by rule.

The state patchwork is unstable

Forty states enacted AI legislation in 2025, and more than 1,500 AI bills had been introduced by March 2026. Four states — California, Colorado, New York, and Texas — now run materially divergent frontier-model regimes, creating uneven public protection and real burdens on interstate commerce.

Congress has already defined the acceptable deal — twice

The Senate stripped a ten-year state-AI moratorium from the 2025 reconciliation bill by a vote of 99–1, and a second preemption attempt failed in the FY2026 defense authorization. The message was not that Congress opposes national uniformity; it is that uniformity must be earned with a substantive federal framework.

The demand for a referee comes from every direction

The June 2026 executive order created a voluntary framework under which developers may grant the government limited pre-release access to frontier models — the executive branch asking as a favor what a statute should establish as an obligation. Industry itself has publicly proposed supervised self-regulation.

Courts are setting AI policy by verdict, because no regulator can set it by rule.

In January 2026, Character.AI and Google settled wrongful-death and injury suits brought by families in four states. Litigation is a slow, expensive, and arbitrary substitute for oversight — and it only ever arrives after the harm.

Photograph in the public domain.

1933 and 1934: the sequence we are living through again

After 1929, Congress did not wait for securities markets to settle, and it did not start approving investment products. It built a disclosure regime — truth-telling, verified by an expert commission — and American capital markets became the deepest and most trusted in the world. The proposed framework maps that machinery onto AI.

Issuer registration

Public companies register and are known to the regulator → covered AI developers register with the Commission (Title II).

Form 10-K

Standardized annual disclosure of material facts → standardized annual disclosure of capabilities, evaluation results, and safety practices (Title II).

S-1 registration statement

Pre-offering disclosure that becomes effective unless the agency acts → a pre-deployment Frontier Model Safety Case, effective after 90 days unless the Commission issues a deficiency notice by recorded vote (Title III).

Form 8-K

Prompt disclosure of material events → critical safety incidents reported within 72 hours, with a good-faith safe harbor (Title IV).

PCAOB-style audit regime

Independent audit of issuer statements → accredited third-party audits of frontier safety claims (Title V).

Examination and enforcement

Inspections, subpoenas, civil penalties → examination authority over registered developers, cease-and-desist power, and tiered civil penalties (Title V).

Whistleblower program

Dodd-Frank awards of 10–30% of large sanctions → an identical structure for AI safety whistleblowers, overriding contractual nondisclosure for safety reporting (Title V).

Obligations scale with capability — most of the AI economy is untouched

The tier structure is the framework's load-bearing wall. The floor is set high enough that the overwhelming majority of developers, startups, researchers, and open-source projects face no obligations at all.

Tier 0 — Exempt

All developers below Tier 1 thresholds; academic and government research; open-source contributors; deployers and users as such

No registration, no disclosure, no fees — an express statutory exemption rather than regulatory grace.

Tier 1 — Covered developers

Training runs above 10²⁵ FLOP and annual covered-AI revenue above $100 million — both prongs required

One-time registration and a standardized annual disclosure report covering capabilities, evaluation results, safety and security practices, and aggregate compute, with penalties for material misstatement.

Tier 2 — Frontier developers

Training runs above 10²⁶ FLOP and annual covered-AI revenue above $500 million, or designation by Commission rule on defined dangerous-capability findings, subject to judicial review

All Tier 1 duties, plus a pre-deployment Frontier Model Safety Case, 72-hour incident reporting, periodic third-party audit and Commission examination, and security and insider-risk program requirements.

Thresholds are recalibrated every two years by rule, on the record, and may move in either direction — algorithmic-efficiency gains are an explicit statutory factor, so the statute does not fossilize 2026 compute economics.

What the framework does not do

No licensing

There is no federal merit approval of AI products and no permission slip required to innovate. Deployment is the default; the Commission bears the burden, on the record, on a clock, and under judicial review.

No speech regulation

An express content-neutrality provision bars the Commission from regulating the viewpoint, opinion, or lawful expressive content of model outputs. Disclosure reaches safety-relevant facts — capabilities, incidents, safeguards — not speech.

No permanent bureaucracy

The Commission is lean and majority fee-funded, with staffing measured in the hundreds. The regulatory titles sunset seven years after enactment absent reauthorization, with comprehensive GAO review at year five.

The framework also writes innovation protections into the statute itself: a regulatory sandbox, small-entity exemptions with mandatory impact certification for every major rule, research safe harbors for good-faith red-teaming, and capability-based treatment of open-weight models that never penalizes open release as such.

Each coalition gets its principal objective

A durable AI statute must give each governing coalition what it most needs while denying neither its non-negotiables. The framework is engineered around that exchange.

What conservatives get

  • National uniformity with substance. Preemption of conflicting state development-level mandates for compliant registrants — the outcome two years of moratorium attempts failed to deliver.
  • Disclosure, not licensing. No federal product approval; the agency carries the burden under judicial review.
  • Markets over mandates. Standardized disclosure lets insurers, enterprise customers, and investors price AI risk directly.
  • Small-government form. A lean, majority fee-funded commission with a statutory seven-year sunset.
  • National security visibility. Statutory authority for the pre-deployment frontier access the executive branch could previously only request.

What progressives get

  • A real regulator, not a pledge registry. Examination authority, subpoena power, civil penalties, stop-order authority for defined catastrophic risks, and an enforcement division.
  • Whistleblower protection with teeth. Dodd-Frank-scale awards and anti-retaliation protections for AI lab employees.
  • Incident transparency. Mandatory 72-hour reporting of critical safety incidents, publicly summarized.
  • Preemption that is partial, earned, and revocable. States retain consumer protection, civil rights, tort, child safety, and criminal law in full.
  • Civil-society standing. Public comment on rules, published enforcement outcomes, and advisory committee seats for the public interest.

Read the full framework

The position paper sets out the complete section-by-section architecture, the anticipated objections and responses, and an implementation timeline — drafted as a framework for legislative counsel.