The White House AI Framework Says Exactly What Big Tech Wanted to Hear

The White House AI Framework Says Exactly What Big Tech Wanted to Hear
Legal scales and government building silhouette on dark navy background representing White House AI policy framework

AI Policy — March 27, 2026

The White House AI Framework Says Exactly
What Big Tech Wanted to Hear.

Seven pillars. One clear message: no new federal regulator, ask Congress to preempt state AI laws, let courts decide copyright. Here is what the framework actually says, what it deliberately avoids, and what it means for builders and publishers.

7
Policy Pillars
Child safety, community safeguards, copyright, government censorship, federal regulation, workforce, state preemption.
No
New Regulator
Explicitly rejects a dedicated federal AI regulator. Existing agencies handle their domains.
State
Law Preemption
Calls on Congress to preempt state AI laws it deems unduly burdensome. Nonbinding until legislation passes.
Courts
Decide Copyright
Training data copyright deferred to litigation. No legislative clarity. Publishers bear the risk.

Sources: White House National AI Policy Framework (March 20, 2026); EFF analysis; CDT policy brief; Electronic Frontier Foundation; March 2026.

The White House released its National Policy Framework for Artificial Intelligence on March 20, 2026, a four-page document with language designed to sound like regulation while functioning as a permission structure. It asks Congress to preempt state AI laws, rejects a new federal AI regulator, defers the training-data copyright question to the courts, and recommends shielding AI developers from liability when third parties misuse their systems. The five companies that control AI infrastructure (OpenAI, Google DeepMind, Anthropic, Meta, Microsoft) got exactly what they wanted: the appearance of governance without the constraint of regulation.

The framework’s legal status reveals its function. It is not an executive order and not a rule. It is a set of legislative recommendations, fulfilling a December 11, 2025 executive order that directed White House science adviser Michael Kratsios and AI and crypto adviser David Sacks to draft a national AI policy to replace the state-by-state approach. Nothing in the framework binds anyone. Its power is agenda-setting: it tells Congress what the administration wants codified, and it tells agencies and courts how the administration reads existing law. The December order separately created an AI Litigation Task Force to challenge state AI laws on constitutional grounds, so the preemption campaign runs on two tracks at once, persuasion in Congress and pressure in the courts.

What the Framework Actually Says

The framework lays out seven priorities for Congress to codify. Child safety comes first: AI services must protect children and give parents control over their children’s digital environment, building on the recently enacted Take It Down Act and existing child privacy law. Community safeguards come second, covering fraud, unauthorized use of name, image, and likeness, and other harms where the framework preserves state police powers of general applicability.

On copyright, the framework encourages Congress to let courts resolve whether training on copyrighted works infringes intellectual property law. That is a deliberate non-answer. Publishers and artists suing AI companies get no legislative clarity, and model developers get to keep training while litigation runs its multi-year course. The framework also warns against indirect government censorship of AI outputs, language aimed at jawboning over model behavior rather than at any existing statute.

On federal regulation, the framework explicitly rejects a new centralized AI regulator. Existing sector-specific agencies handle their own domains, supplemented by industry-led standards. It asks Congress to expand the study of AI-driven job trends and to fund training and reskilling, but it mandates no worker protections. It calls for streamlined permitting for data centers and for regulatory sandboxes that exempt AI systems from existing federal rules.

The seventh priority is the connective thread: broad federal preemption of state AI laws that impose what the administration calls undue burdens. The framework states that states should not be permitted to regulate AI model development at all, on the theory that development is an inherently interstate activity with national security implications. It carves out state laws of general applicability that protect children, prevent fraud, and safeguard consumers, plus state authority over data center permitting and state government procurement of AI. Everything else, including state algorithmic discrimination and transparency laws, would be on the table. None of this is law today. Congress declined to enact blanket AI preemption twice in 2025, in the One Big Beautiful Bill Act and the National Defense Authorization Act, and the framework is a formal request that it reconsider.

What Big Tech Wanted

The Regulatory Capture Checklist
No licensing requirements: The framework does not require AI companies to obtain licenses or certifications before deploying frontier models. Any company can build and deploy any model with any capability. The EU AI Act, by contrast, classifies AI systems by risk level and imposes mandatory requirements on high-risk applications.
A liability shield: The framework goes beyond silence on liability. It asks Congress to preclude states from imposing liability on AI developers for unlawful conduct by third parties using their systems. When an AI system contributes to harm (a hallucinated medical answer, a biased hiring decision), the deployer and the end user hold the risk. Liability ambiguity plus an explicit developer shield benefits the companies with the most lawyers.
No data rights: The framework does not address training data rights, opt-out mechanisms, or compensation for creators whose work trains AI models. Handing the copyright question to the courts benefits every company that trained on internet-scale data without permission.
Self-regulation language: Phrases like “minimally burdensome national standard” and “industry-led standards” place the compliance burden on the companies themselves. Self-regulation has failed to constrain behavior in every previous technology cycle (social media content moderation, cryptocurrency fraud prevention, adtech privacy). There is no reason to expect a different outcome for AI.

The Comparison That Matters

The EU AI Act, which entered enforcement in 2025, classifies AI systems into risk categories (unacceptable, high, limited, minimal) and imposes mandatory requirements on each. High-risk AI systems (used in hiring, credit scoring, medical devices, law enforcement) must meet specific accuracy, transparency, and oversight requirements before deployment. Non-compliance carries fines of up to 7% of global annual revenue. The EU approach regulates AI applications. The U.S. approach does not regulate anything.

The practical consequence: AI companies that operate globally must comply with the EU AI Act regardless of the U.S. framework. The U.S. framework provides no additional protection for American citizens beyond what EU law already requires of companies operating in European markets. The companies that lobbied for a permissive U.S. framework are already complying with stricter EU requirements for their European users. The gap in protection is borne entirely by American users who interact with AI systems that have no mandatory safety, accuracy, or transparency requirements under U.S. law.

Why the Framework Exists at All

The framework serves a political function, not a regulatory one. It allows the administration to claim it has addressed AI governance without alienating the technology companies that fund campaigns, employ voters, and drive stock market performance. It provides a reference document for federal agencies that need guidance on AI procurement and deployment. It establishes vocabulary and categories that future legislation can build on, if Congress ever acts.

The likelihood of binding AI legislation from Congress in 2026 is low. The technology sector spent over $100 million on AI-related lobbying in 2025 (OpenSecrets data). Bipartisan disagreement exists on whether AI regulation should focus on safety (Democratic priority), competition (bipartisan but vague), or avoiding regulation that hampers innovation (Republican priority). The framework splits the difference by doing nothing enforceable while sounding definitive.

For the AI industry, the framework is a green light. Build what you want. Deploy how you want. If something goes wrong, there is no federal enforcement mechanism. For the public, the framework is a press release dressed as policy. The protections it describes do not exist as enforceable rights. The gap between what the framework says and what it does is the gap between marketing and governance. In 2026, that gap is the entire width of U.S. AI policy.

Sources: White House National Policy Framework for Artificial Intelligence and companion legislative recommendations (March 20, 2026); executive order Ensuring a National Policy Framework for Artificial Intelligence (December 11, 2025); EU AI Act enforcement timeline; OpenSecrets (AI lobbying expenditures 2025); Congressional Research Service (AI legislation tracker); Brookings Institution (AI governance analysis). Updated 2026-08-18: This article originally described a four-pillar structure (safety, innovation, worker protections, government use) that does not match the released document, and a summary card stated the framework preempts state law. The framework contains seven legislative priorities and recommends rather than enacts preemption, which requires an act of Congress. The section above was rebuilt against the March 20 text and contemporaneous legal analyses, and the card was corrected.

The most telling detail is what the framework omits. It does not mention the DOJ antitrust case against Google. It does not mention the FTC’s investigations into AI company practices. It acknowledges the copyright fight only to hand it to the courts, which leaves every pending lawsuit from artists, writers, and publishers unresolved by design. It does not mention the concentration of compute resources in three cloud providers and one hardware company. These are the structural issues that determine who benefits from AI and who bears the costs. The framework addresses none of them. A governance document that ignores the power structure it is supposed to govern is not a governance document. It is an endorsement of the status quo.

The European approach is not perfect. The EU AI Act has been criticized for being too prescriptive, too slow, and potentially stifling innovation. But it is a law with penalties. The U.S. framework is a suggestion with no penalties. When the next major AI incident occurs (a deepfake that influences an election, an autonomous system that causes physical harm, a model that leaks private data at scale), the U.S. will discover that nonbinding frameworks are worth exactly what they cost to enforce: nothing.

Discover more from My Written Word

Subscribe now to keep reading and get access to the full archive.

Continue reading