Recently: AI safety on the political agenda
In May 2026, the CAIS newsletter argued AI safety had “entered the political mainstream.” That means Washington and summit circuits are seriously discussing guardrails — not that federal law has passed:
- 2023-11 — Bletchley AI Safety Summit; 26-country declaration
- 2026-04-29 — Sanders convenes US–China researchers on Capitol Hill on existential risk and coordination
- 2026-05 — Trump–Xi Beijing summit discusses AI guardrails; China confirms restart of government dialogue
- 2026-05 — White House pushes CAISI voluntary testing agreements with frontier labs (DeepMind, Microsoft, xAI, etc.)
- 2026-04–05 — Mythos and GPT-5.5-Cyber cyber capabilities push national-security reassessment
- 2026-06 — Trump EO: optional 30-day federal frontier review (not mandatory licensing)
- 2026-06 — G7 France: Altman urges governments not to “cede responsibilities” to labs
Movement side: grassroots action started years ago
The push to slow or govern frontier AI did not start from zero — headcount is small and federal hard law is still missing:
Open letters. 2023-03 FLI pause letter, 30,000+ signers, no lab paused; 2023-05 CAIS extinction-risk statement; 2026-03 FLI superintelligence prohibition — still no federal pause.
Street. PauseAI chapters worldwide; 2024-02-12 first protest at OpenAI SF HQ; 2025-09 Trazzi hunger strike outside DeepMind London; 2026-03-21 Stop The AI Race SF march (~200 people, Anthropic→OpenAI→xAI); 2026-04 PauseCon DC Capitol Hill demonstration; 2025-02 protests outside Paris AI Action Summit. Bay Area hub: Berkeley AI Risk series, recurring small rallies outside labs.
Whistleblowers. 2024-04 Kokotajlo refuses non-disparagement; 2024-05 Leike resignation tweet; 2024-06 Saunders testifies to Congress; 2024-11 Balaji death controversy — still no federal training licenses or compute caps.
Legislative side: wins and losses
Encode helped pass California SB 53 and New York RAISE at state level. 2025-07 Senate stripped Cruz’s 10-year state AI ban 99–1. 2026 NY-12 primary: industry PACs spent ~$7M to keep a pro-regulation assemblyman out of Congress.
Put it together: the warning window is wide, the political agenda and movements are real, federal hard law is nearly absent. The bottleneck is not “one more Nobel-signed letter.” It is translation — survey concern into votes, bills, and enforcement.
The short answer: governments rarely act because they finally understand a risk. They act when inaction becomes politically expensive. Letters don’t pause labs, but state shelf bills, election fights, and constituent lobbying do move the game — below, the political-science playbook for why, and what to do proactively.
The real puzzle: it’s not that the public is unaware
The problem was never that the public doesn’t see the risk — they already do:
| Finding | Source |
|---|---|
| 70–84% say AI needs regulation | KPMG 2025, Eurobarometer 2024 |
| 81% support government testing before AI deployment | PPC/UMD 2024 (bipartisan) |
| 84% support banning deepfakes in political ads | PPC/UMD 2024 |
| 50% of US adults more concerned than excited about AI | Pew 2025 |
The May 2023 CAIS extinction-risk statement was signed by Hinton, Bengio, Altman, Hassabis, and Amodei. “AI is dangerous and needs governance” is no longer fringe political speech — the Overton window (the range of policy ideas politicians and media treat as sayable and actionable) on warning is already wide.
The bottleneck is translation: concern in surveys does not become votes, bills, or enforcement. That gap has a name in political science — and a playbook for closing it.
Why governments sit still: five mechanisms
1. Collective action (Olson)
Mancur Olson’s Logic of Collective Action (1965): small groups with high stakes organize; large diffuse groups free-ride.
In AI today: Industry coordinates ruthlessly — Leading the Future spent ~$7M in NY-12 to block one pro-regulation assemblyman; preemption lobbying alone hit ~$8.5M in Q1 2026 (The AI Lobby). The public side is diffuse — the FLI pause letter gathered 30,000+ signatures with zero policy effect; global AI safety/governance spending is ~$200–400M/year against labs and investors with billions at stake. Attempts to beat Olson: Encode mobilizing voters for state bills; PauseAI US reporting 192 lawmaker meetings — still tiny next to industry.
2. Regulatory capture (Stigler)
George Stigler (1971): regulation is often sought by industry to create moats, not imposed on unwilling firms.
In AI today: The 2026 industry priority is federal preemption — one weak national standard replacing California SB 53 and New York RAISE. The GAAIA discussion draft bundles mandatory audits with three-year state preemption; OpenAI’s policy lead pushes “reverse federalism” — proactively pass “industry-livable” state laws in CA, NY, and IL to set a de facto national floor. Industry fought hard against SB 1047 (vetoed); Anthropic publicly backed the softer SB 53. Capture often looks like “yes to regulation, but on our terms.”
3. Punctuated equilibrium (Baumgartner & Jones)
Most policy areas sit in long equilibrium — incremental tweaks, industry-friendly defaults — until a focusing event breaks the monopoly and produces rapid change.
| Domain | Decades of stasis | Trigger | Outcome |
|---|---|---|---|
| Tobacco | Industry-dominated policy image | Surgeon General report, 1964 | 1990s regulatory wave |
| Environment | Business-led agencies | NEPA 1969, Three Mile Island | EPA, Clean Air Act |
| Banking | Basel I voluntary standards | 2008 financial crisis | Basel III binding rules |
In AI today: Chatham House argued in 2026 that binding governance may need a crisis — same pattern as finance. Proactive side builds shelf: Scott Wiener pivoted from vetoed SB 1047 to SB 53; the EU AI Act took seven years, with ChatGPT forcing a mid-process GPAI chapter. Shocks don’t always produce law — after FTX collapsed, the US still has no federal crypto statute (case studies). Mythos / GPT-5.5-Cyber shifted national-security discourse but landed as CAISI voluntary testing — shock ≠ punctuation unless the shelf is ready.
4. Multiple streams (Kingdon)
John Kingdon’s framework: agenda change needs three streams ripe at once — problem, policy, politics — plus a policy entrepreneur to couple them during a policy window.
In AI today (US frontier safety, 2026):
| Stream | Status | Examples |
|---|---|---|
| Problem | Weak on x-risk (no Chernobyl); stronger on near-term harm | GUARD Act (child chatbots), deepfakes (84% support a ban), jobs |
| Policy | Moderate | EU AI Act, SB 53, Anthropic RSP as legislative template |
| Politics | Unfavorable federally | AI = competitiveness, race with China; Trump EO deregulatory, optional review |
| Entrepreneurs | Active in states, not coupled federally | Wiener (SB 53), Bores (RAISE), Sanders S.4214 (data-center moratorium) |
GDPR succeeded because entrepreneurs kept a fourth stream (technology harmonization) aligned while industry stalled. US frontier safety: streams not coupled → no federal law.
5. Salience and the say-do gap (Slovic)
Politicians follow issues that are salient and electorally costly, not issues that poll well in the abstract. AI is high-consensus, low-salience: Pew 2025 shows more concern than excitement, but AI rarely ranks in voters’ top five.
In AI today: People say they’re worried and do keep using ChatGPT — KPMG 2025 found only 46% trust AI globally but 66% use it regularly, a 20-point gap. Slovic’s affect heuristic: like a product, underestimate its risk. Contrast: election deepfakes (84% support a ban) are far more salient than “deceptive alignment”; NY-12 spent $7M in PAC money to force frontier regulation into salience — but the salience was electoral warfare, not x-risk itself.
What actually works (before a crisis)
The strategic goal is not to make politicians “believe” in x-risk. It is to make not regulating cost more votes and money than regulating. Seven levers, ordered by empirical plausibility.
1. Anchor to salient harms — build coalitions, not monocultures
X-risk alone is politically weak. Bridge groups with different motives:
| Partner | Cares about | Policy vehicle |
|---|---|---|
| Labor | Jobs | Training transparency, impact reports |
| Parents | Kids | GUARD Act, child-safety vetting |
| Populist right | Anti-elite, anti-Big Tech | Oppose blanket federal preemption |
| Creative industries | Deepfakes, copyright | Labeling, liability |
| Natsec moderates | Unauditable systems | Mandatory testing — not pause |
Tobacco regulation didn’t break through on distant lung-cancer statistics alone. Secondhand smoke made harm immediate and personal. For AI, the analogues are deepfakes in elections (84% support a ban), chatbots harming minors, and electricity bills from data centers — not “deceptive alignment.”
The sellable federal frame: “FAA for AI” — pre-deployment government testing. 81% support, bipartisan.
2. Electoral fear beats open letters
A legislator’s utility function is simple: keep the seat. What moves them is anything that touches re-election — votes, primary challengers, donors, local anger. The political-science name is the electoral connection (Mayhew 1974): member behavior is almost fully explained by the drive to get re-elected.
That’s exactly why open letters fail. A signature is costless — signing it loses you no votes and no money. So it conveys zero information to a legislator: a room full of Nobel laureates’ names changes nobody’s next vote. This is costly signaling: only signals that carry a price are credible.
Compare three real cases:
| Tactic | Cost / credibility | Result |
|---|---|---|
| FLI pause letter, March 2023 (1,000+ signers) | Costless signatures | Zero policy effect — no lab paused, no law passed |
| Industry ~$7M anti-Bores primary | Real money + electoral threat | Blocked Bores from Congress; the stated goal was a chilling effect — make other politicians run from AI regulation |
| Cruz federal moratorium on state AI laws | Bipartisan voters + governor pressure | Stripped 99–1, July 2025 — a rare proof that organized voter pressure can beat concentrated industry lobbying |
Note the asymmetry in the last two rows: industry uses money and electoral threats to successfully block a person (Bores), but when the other side also makes the pressure electoral — governors, state AGs, child-safety groups pushing together — concentrated lobbying loses too (Cruz, 99–1). The lesson isn’t “money always wins.” It’s whoever turns the issue into a re-election risk for the legislator wins.
Operational takeaway for advocates: stop collecting signatures. Spend on actions that change the re-election calculus —
- Make a legislator pay a price (even just a bad news cycle) in a primary/general for voting against AI regulation
- Translate x-risk into issues with a local constituency (data-center electricity bills, kids and chatbots, deepfakes) so “doing nothing” carries a vote cost
- Watch specific actions: whether a federal preemption clause makes it into a reconciliation bill, whether a committee marks up mandatory testing — not another op-ed about AGI
3. States first, then nationalize (the Encode playbook)
The most realistic US path:
California / New York pass frontier transparency ([SB 53](https://leginfo.legislature.ca.gov/faces/billNavClient.xhtml?bill_id=202520260SB53), [RAISE](https://www.nysenate.gov/newsroom/press-releases/2025/andrew-gounardes/landmark-ai-safety-bill-signed-law))
→ Labs adapt to largest markets → de facto national standard
→ Block federal preemption ([GAAIA](https://trahan.house.gov/news/documentsingle.aspx?DocumentID=3783)-style bills)
→ State champions reach Congress ([Wiener](https://www.scottwiener.com/), etc.)
→ Federal floor codifies the state template
The environmental movement used the same structure: lose in agencies → win in Congress → NEPA → EPA.
The critical defensive fight: federal preemption of state AI law. If industry wins preemption, state wins get wiped out. That is the highest-negative-risk lever in US AI politics right now.
4. Shelf-ready policy before the window opens
Basel banking rules were voluntary for years; 2008 made them binding. Today:
- Draft training-compute registration and licensing statutes
- Turn METR/CAISI eval protocols into mandatory release requirements
- Incident reporting + whistleblower protection
- Product liability that internalizes risk in corporate P&L
Voluntary commitment → legislative template. Anthropic’s RSP (Responsible Scaling Policy — a self-imposed “at capability level X, apply safety measures Y” rule) has no enforcement: they can change it, ignore it, and face no penalty. But it translates “training frontier models responsibly” into concrete, drafting-ready clauses (capability thresholds, eval triggers, release gates). Banking went the same way — Basel’s capital-adequacy ratios existed as a voluntary standard for years, then after 2008 became mandatory Basel III almost verbatim. The RSP is playing “voluntary version before Basel III”: when a crisis opens the window, legislators don’t draft from scratch — they take the ready-made template and add enforcement.
But statutes are just paper. What determines whether implementation takes six months or six years after the window opens is whether measurement and enforcement plumbing was built in advance. Three categories of infrastructure you can start now and plug in when law passes:
A. Compute monitoring and training verification (the GPU-monitor problem)
Anthropic Institute (2026) says that if credible systems existed to verify other frontier labs had actually stopped/slowed training — and no one could defect in secret under cover of a coordinated pause — Anthropic expects it would slow down too. Not a binding pledge, but it names the bottleneck: without verification, pause rhetoric is empty.
| Horizon | Build now | What law enables | Status |
|---|---|---|---|
| Now–2027 | Cloud training registration API spec (job metadata, GPU-hours, cluster ID); public energy/throughput baselines; third-party eval standard output format (draft before METR protocols become statute) | SB 53 / RAISE-class transparency → mandatory disclosure + independent audit | Voluntary side: CAISI testing; clouds have billing telemetry, no unified schema, no independent verification |
| 2027–2030 | HEM / FlexHEG hardware attestation pilots: NIC/rack-level signed telemetry proving cluster-scale training | Export-control / VEU datacenter mandatory attestation; multilateral pause treaty verification | No commercial product yet; engineering blueprints in R&D |
| Post-crisis | Chip-level licensing, proof-of-training, international inspection agency | Full pause / compute caps | 3–5+ years; consumer GPU stockpiles remain a bypass |
Near-term engineering (don’t wait for FlexHEG shipping): (1) open-source reference implementation for “training job declaration + independent reconciliation” (cloud APIs + energy fingerprints; imperfect but deployable); (2) align eval output formats with METR / AISI network so state-mandated “published safety assessments” are machine-readable. Post-Chernobyl nuclear law wasn’t written from zero — IAEA inspection protocols, incident scales, and radiation monitoring existed before the accident; the gap was political will, not instruments.
B. Biorisk: physical chokepoint + model eval in parallel
Bio sells better than x-risk because both parties have a physical-layer consensus: BMIA (S.3741) targets synthesis screening chokepoints, not training pauses.
| Layer | Build now | What law enables | Gap |
|---|---|---|---|
| Model eval | WMDP / RefusalBench-class CBRN benchmarks; sandbagging detection protocols | RAISE / RSP statutory conversion → mandatory bioweapons-class eval before release | No unified “HarmBench for biology FMs”; Evo-class open weights face no mandatory review |
| Synthesis screening | Deploy IBBIS Common Mechanism; function-based screening prototypes (NIST/Science 2025 direction) | BMIA → mandatory nucleic-acid order screening + recordkeeping | Covers physical orders only, not in silico design; non-IGSC vendors, offshore arbitrage |
| Wet lab / defense | Order-pattern anomaly detection; metagenomic surveillance interfaces | Federal procurement chain → compliant synthesis providers only | Red Queen Bio-class closed-loop defense still early |
(1) Run CBRN evals as a repeatable third-party service (voluntary today; tomorrow one SB 53 clause — “tested by independent body to WMDP-class standard” — plugs in); (2) push BMIA without letting IGSC voluntary protocols substitute for function-based screening — sequence homology is broken by attacks like GeneBreaker.
C. Cross-cutting: eval, incidents, liability
Risk-agnostic infrastructure every frontier-AI statute will reference:
- Mandatory eval publication: METR/CAISI protocols as statute-citable appendices (thresholds, methods, public fields)
- Incident report schema: standardized when/which-model/what-harm — whistleblower and media cycles need legible formats (AIWI path)
- Product liability case templates: internalize harm in corporate P&L without requiring regulators to “believe in x-risk” first
Stock the shelf with things you can measure, not things you can only debate. Election deepfakes, child chatbot harms, synthetic DNA orders — all have deployable detectors or screeners; “is the model conscious” does not. When the political window opens, the former can go live in six months; the latter spends six years in committee.
5. Reframe the policy image
Industry maintains a monopoly on how AI is pictured: innovation, jobs, beat China. Counter-frames with polling behind them:
- Unregulated deployment = untested drugs on the market
- “Losing to China” = China already has pre-market review; the US has less governance, not more freedom
- Self-regulation = race to the bottom under competitive pressure
- Auditing ≠ pausing (natsec hawks can support testing without supporting a moratorium)
Venue shopping matters: state AGs, courts, EU extraterritorial reach, congressional committees that weren’t captured first.
6. Exploit routine windows
Not every opening requires a disaster. Elections, budget cycles, EU AI Act full enforcement (August 2026), and spillover from data-center energy fights are predictable windows. Prepare the bill; wait for the calendar.
7. What not to waste energy on
| Strategy | Why it fails |
|---|---|
| More Nobel open letters | Costless signals |
| Pure x-risk / TESCREAL framing | Culturally coded “weird”; inoculates policymakers |
| Demanding permanent pause | Natsec and Global South oppose; 55% oppose a regulation moratorium |
| Treaty-first multilateralism | CoE Convention unratified; US–China dialogue stuck on guardrails |
| Industry self-regulation alone | RSP has no enforcement; competition dominates |
Realistic timeline
| Phase | When | What’s achievable |
|---|---|---|
| 0 | Now–2027 | State transparency/licensing; block preemption; coalitions; shelf bills |
| 1 | 2027–2030 | De facto standards via CA/EU market size; liability case law |
| 2 | Crisis-dependent | Enforceable federal law (penalties, licensing, mandatory audits); binding treaty |
Before a crisis hits, the strongest push line is transparency → licensing → mandatory eval — force labs to publish safety frameworks, require a license to train/deploy, and impose mandatory evals. A full frontier pause needs a multilateral compute treaty, hardware verification, and US–China alignment — not on the table in 2026. Don’t expect to stop the frontier pre-crisis; “transparency + licensing + mandatory eval” is still far more than today’s near-nothing.
If you want to help
From my practical guide to AI safety participation, filtered through political strategy:
- One issue, consistently — e.g. oppose federal preemption + support state training transparency
- Encode AI alerts — tied to specific bill sections, not vague “stop AI”
- Bridge coalitions — labor + deepfake + natsec on the same legislative package
- Research → legible policy briefs — engineering evidence that lawyers can paste into statute language
- Support candidates who can win on regulation — not movement theater
The signal to watch is not “another warning.” It is SB 53 surviving preemption, a committee marking up mandatory testing, a senator flipping on GAAIA.
Governments will care when caring is cheaper than not caring. The work before the crisis is to make that true — and to have the bills already written when the window opens.
For what that pre-crisis period actually looks like in history — shelf bills, failed shocks (FTX), EU AI Act’s seven-year march — see What happens before policy changes.
Further reading