Discussion drafts
Two proposed bills—one federal and one for Minnesota—designed to protect lawful access to computation, advanced AI, and open-weight models while limiting government-imposed capability restrictions.
The argument #
Governments have started regulating artificial intelligence by how capable a system is rather than by what anyone did with it.
Executive Order 14110 set a reporting threshold at 10<sup>26</sup> training operations before it was revoked in January 2025. The 2025 AI Diffusion Framework controlled model weights directly, though as an export control it is one of the things these drafts expressly leave alone. California and New York now use frontier-model and compute criteria to decide which developers fall under additional safety, transparency and incident-reporting duties. Every one of them picks out its subject by capacity rather than by what anyone did.
What a capability rule reliably does is sort people. Agencies and large institutions keep access, because they can absorb compliance. Individuals, small businesses, researchers and local governments get a degraded version, because they cannot. The gap is already real and nobody is required to measure it.
These drafts take the opposite approach. Government keeps every power it has to punish what people actually do. Fraud, intrusion, weapons development and harm to children stay illegal, and stay illegal whether or not an AI system was involved. What government loses is the power to restrict a tool because of how capable the tool is.
That prohibition is categorical rather than a balancing test. An earlier draft let government impose a capability restriction if it could show a compelling interest and narrow tailoring. That concedes the question: it accepts that the right can be weighed away whenever the stated worry is serious enough. These drafts withhold the authority instead. No interest, no degree of tailoring and no emergency makes a capability restriction valid.
What the bills do #
- RightA statutory right to acquire, possess, develop, share, access and operate computational resources and AI systems for lawful purposes.
- StandardFor any other burden on the right, compelling interest and least restrictive means, modeled on the Religious Freedom Restoration Act framework with added requirements. That test is unavailable for a capability restriction, which is void no matter what showing is made.
- No ceilingsGovernment may not restrict a system because of how capable it is. Not through compute thresholds, parameter counts, benchmarks, autonomy or any other proxy. This one is categorical: the bill withholds the authority rather than making it hard to use.
- Back doorNo leaning on cloud providers, chipmakers, app stores or payment processors to do what government cannot do directly, and notice to the person who got cut off.
- ParityIf an agency runs a nonclassified civilian capability, it may not forbid citizens a comparable one — and it has to publish annually what it is running.
- KnowledgeNo federally mandated refusal lists. Government may not require a system to withhold from an adult what that adult could read in a public library.
- Open weightsPublishing, receiving and redistributing model weights is protected expression. No prior approval, no licensing, no restriction because a model is open or modifiable — and no duty to police who downloads it.
- ExpiryCovered executive and administrative restrictions expire after three years unless re-justified on current facts. The Minnesota draft expressly leaves statutes alone. Anyone covered may petition to repeal a restriction, and anything missing from the annual inventory is unenforceable.
- ConductEverything illegal today stays illegal, and the named worries — chemical, biological, radiological and nuclear weapons, attacks on infrastructure, harm to minors — are answered by prosecuting the conduct, never by capping what anyone may possess.
- DutyAnyone running AI that controls critical infrastructure must keep a written risk policy and guarantee a human can halt it at any time. Businesses under 50 employees are exempt unless they serve more than 10,000 customers.
What they do not do
- They do not require any developer to release, sell or license a model, or to disclose model weights, training data, source code or trade secrets. There is no mandated release and no forced service. They do impose three private duties: a risk policy for AI controlling critical infrastructure, data portability on user request, and notice to someone cut off because of government pressure.
- They do not touch export controls, sanctions or classified information.
- They do not legalize conduct. Fraud, intrusion, weapons development, child exploitation and every other prohibition survive, whatever tool was used. There is one deliberate change: someone who lawfully publishes model weights is not liable for another person’s independently unlawful use of them, and has no duty to police downloads.
- They do not tie government’s hands on catastrophic risk. Preventing chemical, biological, radiological and nuclear weapons, critical-infrastructure intrusion and harm to minors are all named in the text, and government keeps every power to prohibit, investigate and punish that conduct. What it may not do is answer those risks by limiting how capable a tool an ordinary person is allowed to have.
Precedent #
Montana enacted the first Right to Compute Act in 2025, pairing broad protection for computational resources with a risk-management duty for AI-controlled critical infrastructure. It passed the Senate unanimously and the House 61 to 38. Similar bills have since moved in Ohio, New Hampshire and South Carolina.
These drafts build on that model and depart from it in one respect: Montana subjects a restriction to a compelling-interest and narrow-tailoring test, while these drafts withhold the authority to impose a capability restriction rather than subjecting it to a test. They also add the parity, knowledge-access and sunset provisions the existing state bills lack.
Read the drafts #
Both bills are published in full. The federal bill runs 38 sections across three titles; the Minnesota bill runs 38 sections across two articles. Article 2 and Title II — the public access programs — are drafted to be severable, so a sponsor can strip them without touching the rights.
What a bill like this can and cannot do #
A statute can withhold authority, and these drafts do. What no statute can do is bind the legislature that comes next. Both bills use the strongest device available for that: a later law does not override them unless it says so by specific reference. That creates a strong presumption against implied displacement and makes an accidental or silent override much harder. It is not absolute — the Supreme Court held in Dorsey v. United States (2012) that a later Congress can override an express-reference requirement by implication. It does not guarantee a separate vote, and it does not stop a legislature that means to repeal it.
Putting the right fully beyond legislative reach is a constitutional question rather than a drafting one. That is worth saying plainly rather than implying these drafts do more than they do.
Getting it introduced #
Nothing here has a sponsor yet, and a sponsor is the first step toward formal introduction. The sponsoring office and its legislative counsel would revise the text before introduction, after which the normal referral procedures apply. The text is in the public domain, so any legislative office can take it, amend it and introduce it under its own name without asking.
Support this #
Leave your email and we’ll tell you when the drafts change, when a sponsor picks them up, and when there is something concrete to do. Your state matters more than you’d think: legislators count constituents, not signatures.