
Regulating AI: Is the Rule of Law Possible?
Though Congress needs to act quickly to resolve the uncertainty that pervades the United States’ current approach to AI governance, it should not rush and settle for a law that may not provide the requisite clarity or necessary constraints on executive action.
Congress must address two pressing AI governance questions: who should have access to the most advanced AI, and, among those permitted access, when should that access be granted?
Answers to those questions have so far been determined by the Trump Administration in an ad hoc, vague manner. Hence, the need for congressional action. US leadership in a global AI race hinges on stakeholders knowing which laws will apply to which models and what the ramifications will be. Absent such clarity, it’s highly likely that companies and other entities looking to adopt the latest AI tools will instead opt for increasingly capable open-source Chinese models.
Absent Congress developing its own framework, it remains unclear how exactly the federal government will answer these questions. Under a recently announced executive order, labs may voluntarily work with the Administration to ensure their most advanced models are released only to “select trusted partners” before a general release. The order omits details on how individuals and entities will be assessed for that status. There’s also no guidance on which models may qualify for that pre-deployment check, and none is forthcoming because the order directs the National Security Administration to oversee that effort.
As the Administration develops that framework—partially behind classified doors—it relied on contested authority under the Export Control Reform Act (ECRA) in the interim to prevent Anthropic from making its Mythos 5 and Fable 5 models available to the public until the lab instituted additional safeguards. Commerce Secretary Howard Lutnick sent the company an “Is Informed” letter, notifying Anthropic that it would need a license to allow any foreign national to access the model. This amounted to the Department stretching ECRA and the Export Administration Regulations (EAR), which implement ECRA, to cover remote, API-based access to a model. OpenAI was likewise directed by the Administration to delay public access to its latest model, albeit with less specificity about the legal basis for that mandate. Note that the Administration has subsequently permitted a broader release of those models, though it did so with minimal explanation.
This approach is untenable for many reasons. ECRA was not enacted with frontier AI in mind. Section 4817(b)(1) of the ECRA permits the Commerce Department to enforce interim controls on emerging or foundational technologies with national security significance. Section 744.22(b) of the EAR allows Commerce’s Bureau of Industry and Security (BIS) to inform a person that a license is required for exports of an item governed by the EAR if there’s an unacceptable risk of the item facilitating “military intelligence end use” in designated countries of concern. Up to this point, Commerce has not treated access to a model as a controlled item. For example, the AI Diffusion Rule promulgated by the Biden Administration and then effectively rescinded by the Trump Administration applied controls to model weights, not general model access.
Congress can and should clarify whether ECRA should reach remote access to a model and, more generally, access to items subject to the EAR via the cloud. It’s contemplating legislation to do just that—the Remote Access Security Act (RASA). However, the legislation has structural issues that require redress.
As several Advisory Opinions issued by BIS made clear, it has generally been understood that merely allowing internet users to access software does not qualify as an export. RASA would attempt to close the so-called Cloud Loophole by amending the Act to cover “access on a purposeful, knowing, reckless, or negligent basis to an item subject to the jurisdiction of the United States under this Act by a foreign person through a network connection, including the internet or a cloud computing service, from a location other than where the item is physically located if the Secretary determines that the use of the item could pose a serious risk to the national security or foreign policy of the United States.”
Considering recent AI governance developments, it’s important to see if this law goes further than necessary to answer the two pressing questions of who should access AI models and when.
The problem is that RASA—if passed in its present form—would still result in tremendous ambiguity. Under the amended ECRA, the President would have the authority to control exports, including remote access to items subject to the EAR, and the ability to devise a licensing program for such access. Yet, the Act stops short of detailing which items should be subject to remote access restrictions and how any such licensing program should be developed and imposed. Those critical inquiries would instead fall to the BIS. In theory, BIS could promulgate far-reaching regulations under RASA that may go further than Congress intends. Of course, those regulations could be challenged, but given the fast-moving nature of the global AI race, the harm that results from impeding access to US models and, by extension, driving AI stakeholders to Chinese models would already be done.
The US has alternative tools to keep America’s most advanced AI systems out of the hands of our adversaries. Development and implementation of hardware-based verification technology, imposition of Treasury sanctions, updates to the Commerce Department’s Entity List, and other national security authorities can significantly reduce the likelihood of bad actors and organizations harnessing US AI for ill. RASA, as proposed, may impose sweeping restrictions that risk making American AI less accessible to allies, partners, and legitimate businesses around the world.
While Congress needs to act quickly to resolve the uncertainty that pervades the United States’ current approach to AI governance, it should not rush and settle for a law that may not provide the requisite clarity or necessary constraints on executive action. The stakes of the AI race are too high to enact a framework rife with pitfalls that will inevitably result in legal challenges and political disputes, outcomes that do little other than assist our adversaries.
Professor Kevin Frazier leads the AI Innovation and Law Program at the University of Texas School of Law and is a Senior Fellow at the Abundance Institute.

Regulating AI: Is the Rule of Law Possible?
The stakes of the AI race are too high to enact a framework rife with pitfalls that will inevitably result in legal challenges and political disputes, outcomes that do little other than assist our adversaries.

What a Packed Court Could Have Done in One Year
Thanks to the principled thought and dedicated efforts of former Attorney General Edwin Meese III, Justice Antonin Scalia, the Federalist Society, and many others, originalism has become the dominant interpretative theory on the Supreme Court.
.jpg)
The Best Escape from the U.S. Attorney Mess
The process for appointing U.S. Attorneys is sputtering, but there is a way out of this mess.
Get the Civitas Outlook daily digest, plus new research and events.




