AI Preemption War: Part 5 — The Safety Question
Series: The AI Preemption War | Table42 Research
—
The National Policy Framework for Artificial Intelligence devotes one of its seven pillars to “Child Safety.” It calls for “age assurance, parental control tools, and features that reduce risks of exploitation and self-harm” and warns Congress against “open-ended liability” that could trigger excessive litigation.
This is the framework’s safety section. One pillar, three paragraphs, framed primarily in terms of limiting liability rather than protecting children.
The question Table42 should ask: what safety protections does the framework actually provide, and what happens to the state-level safety regulations that exist today?
What the Framework Says About Safety
The framework identifies child safety as a priority area and lists several objectives:
– Age assurance: Systems should verify user age where appropriate – Parental tools: Parents should have ability to monitor and control children’s AI use – Exploitation prevention: AI systems should reduce risk of exploitation and self-harm
These are legitimate safety goals. The question is whether the framework’s approach achieves them.
The framework does not mandate specific technical requirements. It does not create enforcement mechanisms. It does not establish liability for AI companies whose systems fail to protect children. It calls on Congress to act, but provides no statutory text that would actually require anything.
Compare this to the EU AI Act’s approach. The EU Act classifies AI systems that pose specific risks—real-time biometric surveillance, social scoring, manipulation of vulnerable groups—and prohibits or restricts those systems outright. It establishes conformity assessment procedures that require AI companies to demonstrate safety measures before deployment. It creates enforcement mechanisms with substantial penalties.
The US framework’s safety language is hortatory. It states goals without creating obligations.
What State Safety Laws Would Face
State AI laws often include safety provisions. California’s transparency requirements address AI systems that could manipulate or deceive consumers. Colorado’s algorithmic discrimination framework requires safeguards for AI systems used in healthcare decisions. Illinois’ BIPA, though primarily about data privacy, has been applied to AI systems that collect biometric information. Note: Colorado’s SB 24-205 enforcement was blocked by a federal court on April 28, 2026, with the DOJ joining xAI’s lawsuit challenging the law.
Under the framework’s preemption approach, these laws could be displaced if they are deemed “unduly burdensome.” The child safety provisions—which are framed in terms of preventing harm—might be preserved. But laws addressing other safety concerns could be challenged.
Consider: a state law requires AI companies to implement safeguards against deepfake manipulation of electoral content. Is that “burdensome” to AI developers? The framework doesn’t say. But an AI company facing compliance costs could argue that the requirement is preempted, and the undefined “burdensome” standard provides a hook for litigation.
The Liability Limitation Problem
The framework explicitly warns against “open-ended liability” that could “trigger excessive litigation.” This language reveals the safety framework’s orientation: it is not primarily concerned with protecting people from AI harms, but with limiting AI company exposure to liability claims.
This is a significant inversion. Safety regulation exists because markets don’t adequately protect people from harmful products. Liability for product defects creates incentives for safety; unlimited liability creates stronger incentives than limited liability. When the framework prioritizes liability limitation over safety protection, it shifts the balance from precaution to profit.
The argument for liability limits is that excessive litigation chills innovation—if AI companies face unlimited liability for AI harms, they won’t invest in AI development. This argument has some merit: legal uncertainty does affect investment decisions, and a well-designed liability system provides clear rules that allow companies to plan.
But “limited liability” as a policy priority is different from “appropriate liability.” The framework’s language—warning against “open-ended liability”—suggests the goal is to cap liability rather than to calibrate it. A well-designed safety framework would match liability to actual harm: companies that take reasonable precautions pay less than companies that cut corners. The framework does not propose such a calibration; it proposes limitation.
The Enforcement Gap
The framework does not create a federal AI safety regulator. It explicitly rejects the EU model of a dedicated AI agency. Instead, it proposes sector-specific oversight—existing agencies (FDA, FTC, CFPB) would enforce AI safety within their domains, combined with industry standards and self-regulation.
This creates enforcement gaps. The FDA regulates medical AI; the FTC regulates consumer AI; the CFPB regulates financial AI. But AI systems often span domains. A hiring algorithm might be a consumer product (regulated by FTC), an employment tool (subject to EEOC jurisdiction), and a data collection system (subject to state privacy laws). No single regulator has comprehensive authority.
State attorneys general have been filling this gap. They have brought enforcement actions against AI companies for deceptive practices, discrimination, and privacy violations. They have issued guidance on AI compliance. They have coordinated enforcement across state lines.
Preemption would weaken this enforcement mechanism. Federal minimum standards might not match state enforcement priorities; federal agencies might not have resources to pursue enforcement actions that state AGs have prioritized; federal preemption might create gaps that no one fills.
The Child Safety Test
Consider the specific case the framework highlights: child safety.
Children face AI harms that adults do not: algorithmic amplification of harmful content to vulnerable users, AI-enabled exploitation, manipulation through personalized AI interactions. State laws addressing these harms exist in various forms—consumer protection laws, child safety statutes, data privacy requirements.
If preemption displaces these laws, children lose protection without receiving equivalent federal coverage. The framework’s child safety language provides no enforceable rights, no specific requirements, no private right of action. A parent whose child is harmed by an AI system has no framework-generated remedy—only whatever federal enforcement the relevant agency chooses to pursue.
This is not a hypothetical. The framework’s child safety section does not require AI companies to implement specific safeguards, does not create liability for companies that fail to protect children, and does not give parents any mechanism to enforce safety requirements. It calls on Congress to act—eventually—and meanwhile preemption eliminates state protections.
Primary Sources
Federal Framework
1. National Policy Framework for Artificial Intelligence (March 20, 2026): Safety language, liability limitation, child safety pillar
2. Executive Order 14365 (December 11, 2025): Foundation for national AI policy framework
3. Senator Marsha Blackburn’s TRUMP AMERICA AI Act (discussion draft, March 2026): 291-page alternative with safety provisions
EU AI Act — Safety Architecture
4. EU AI Act (Regulation 2024/1689): Article 5 — prohibited AI practices (manipulation, exploitation, social scoring)
5. EU AI Act Article 6: Classification of high-risk AI systems
6. EU AI Act Articles 8-15: Requirements for high-risk AI systems — risk management, data governance, transparency
7. EU AI Act Article 14: Human oversight requirements for high-risk systems
8. EU AI Act Article 15: Accuracy, robustness, and cybersecurity requirements
9. EU AI Act Article 16: Conformity assessment obligations
10. EU AI Act Articles 70-77: Enforcement and penalties — up to €35M or 7% global turnover
11. European AI Office: Implementation and coordination body
US Child Safety Frameworks
12. Children’s Online Privacy Protection Act (COPPA), 15 U.S.C. §§ 6501-6506: Parental consent for data collection from children under 13
13. Children’s Internet Protection Act (CIPA), 20 U.S.C. § 9134: School/library filtering requirements
14. Kids Online Safety Act (KOSA) (proposed): Duty of care for platforms serving minors
15. California Age-Appropriate Design Code Act (AB 2273, 2022): Data protection for children
16. UK Age Appropriate Design Code: International model for child data protection
Federal Agency AI Safety Oversight
17. Federal Trade Commission Act § 5, 15 U.S.C. § 45: Unfair and deceptive practices authority — AI enforcement
18. FTC: “Aimless AI: Consumer Protection Guidance” (2024)
19. FTC: Enforcement action against AI deception cases (2023-2025)
20. Food and Drug Administration (FDA): Guidance on AI/ML-based Software as a Medical Device (2024)
21. FDA: Predetermined change control plans for AI medical devices (2024)
22. Consumer Financial Protection Bureau (CFPB): AI in credit decisioning guidance (2024)
23. Equal Employment Opportunity Commission (EEOC): AI and algorithmic fairness in hiring (2023)
24. Department of Justice Civil Rights Division: AI discrimination enforcement (2024)
25. National Highway Traffic Safety Administration (NHTSA): Autonomous vehicle safety standards
State Safety Laws
26. California AB 2013 (2024): AI transparency — disclosure of AI-generated content affecting consumers
27. Colorado SB 24-205 (2024): High-risk AI systems — healthcare, employment safeguards
28. Illinois BIPA, 740 ILCS 14/1 et seq. (2008): Biometric data consent — facial recognition safety
29. New York Local Law 144 (2023): Bias audit requirements for employment AI
30. Washington HB 2031 (2023): Deepfake disclosure — electoral and consumer safety
31. Maryland HB 276 (2022): Facial recognition limits for law enforcement
32. Virginia HB 2034 (2022): Consumer data protection with AI provisions
State Attorney General Enforcement
33. California Attorney General: AI enforcement guidance and actions (2024-2025)
34. New York Attorney General: AI deception and discrimination enforcement (2024)
35. Illinois Attorney General: BIPA enforcement actions (2023-2025)
36. Texas Attorney General: AI consumer protection guidance (2024)
37. National Association of Attorneys General (NAAG): AI enforcement coordination (2025)
Liability and Safety Scholarship
38. Restatement (Third) of Torts: Products Liability (1998): Defect standards for software
39. Winter v. G.P. Putnam’s Sons, 938 F.2d 1035 (9th Cir. 1991): Information product liability limits
40. American Law Institute: AI and liability project (ongoing)
41. National Academies of Sciences: “AI Safety: Technical and Policy Challenges” (2024)
42. AI Safety Institute (UK): Safety testing and evaluation framework
43. National Institute of Standards and Technology (NIST): AI Risk Management Framework (2023)
44. Center for AI Safety: “Statement on AI Risk” — safety prioritization (2023)
45. Partnership on AI: Responsible practices for AI safety (2024)
—
Status: Draft | Citation count: 45 | Next: Part 6 — The International Context