A complete model statute for independent AI training-data oversight — built transparently, mistakes included, and open for public critique.
If you've read Pages One through Four, you already know where this project has been heading. Page One asked how we'd even classify evidence of an AGI failure. Page Two asked why the emergency is already here, not coming later. Page Three asked who actually gets to decide what "AGI" even means. Page Four asked what happens when governance only shows up after something has already gone wrong.
This page was supposed to ask one more question and stop there: what happens when AI systems start learning from the very writing that criticizes AI governance? That question still matters, and it's still answered here.
But something unexpected happened while building this page, and it's important enough to explain. What started as a question turned into an attempt at an answer.
While testing that question with Gemini, Google's AI system, and ChatGPT, OpenAI's AI system, one of them did something unplanned. Gemini began drafting the first version of an actual bill—a real, working model statute for how AI training could be independently verified. The central architectural idea was sound. The details contained a serious mistake. That mistake was caught twice, independently — first by Claude, Anthropic's AI system, through direct technical scrutiny, and again when the same flawed mechanism was shown, cold, to ChatGPT, with no knowledge of the first draft's history. Both reached the same technical conclusion for the same underlying reason. What was left, after months of work most readers will never see, is a complete, working piece of legislation: something a real lawmaker could pick up, read, and actually use. Whether Congress should enact it is a separate question entirely. The purpose of this page is simply to place one workable design into the public record.
So this page is two things instead of one. It's still the argument "The Recursive Trap" set out to make. And it's also a full model bill, built in the open, with its mistakes, corrections, and reasoning left visible, meant to answer that argument with something concrete instead of just another warning.
Why this might matter to you, specifically:
If you're worried about AI and don't know what to actually do about it, this page gives you something concrete to point to — not just "someone should do something," but an actual, specific proposal you can read, question, and share.
If you work in accounting, auditing, or law, this page shows what independent examination could look like applied to AI, using the same evidentiary tools your profession already relies on.
If you're a lawmaker, a staffer, or someone who writes to one, this page hands you a starting draft, not a finished demand — something built to be argued with, not just accepted.
And if you're simply someone who's read this far because you're worried about what happens if nobody's watching: this page is the answer to that worry, built as carefully as we knew how to build it, with every important mistake left visible on purpose.
What follows is the bill, and the documented record of how it came to be.
This Act may be cited as the "Independent AI Provenance and Examination Act."
Congress finds the following:
(1) Artificial intelligence systems are built through a process. That process includes gathering data, training a model on that data, testing the model, and releasing it for public or commercial use. This Act regulates that process. It does not regulate artificial intelligence as a concept, and it does not attempt to define artificial general intelligence or any similar term. A process can be independently examined. A concept cannot.
(2) A covered training run substantially affects interstate and foreign commerce. Training data is gathered from sources located in multiple states and countries. The computational infrastructure used in a covered training run is frequently located in a different state than the covered developer, and is often supplied by a provider operating across state lines. A covered system developed through a covered training run is typically deployed nationwide, regardless of state boundaries. This Act is enacted under the authority granted to Congress by Article I, Section 8 of the Constitution of the United States to regulate commerce among the several states and with foreign nations.
(3) History shows a repeating pattern in industries where those developing products or services were permitted to certify their own safety and soundness without independent examination. In the historical cases underlying this Act's findings, a failure eventually occurred, and the failure revealed that no independent examiner ever possessed the authority or access necessary to verify the company's representations. This pattern has occurred across banking, aviation, pharmaceuticals, and public accounting. Each time, meaningful oversight arrived only after serious harm had already taken place. This Act exists to break that pattern before it repeats in the development of artificial intelligence.
(4) This Act does not identify any company, developer, or individual as a wrongdoer. No finding in this Act should be read as an accusation against any named party. This Act creates a system of rules that applies equally to every company that meets the conditions described in Section 4. Its purpose is to build a structure to establish accountability before a failure occurs, not to assign blame for one that has already occurred.
(5) The records required under this Act shall be maintained for one purpose: to allow an independent examiner to verify what data was used to train a covered system, and when. These records are not created to establish ownership of that data, and nothing in this Act shall be read to grant, expand, limit, or otherwise affect any copyright, patent, trade secret, or other intellectual property right. A provenance record documents the process. It is not a claim of ownership.
(6) Records required under this Act must be created and maintained contemporaneously with the activities they document. Records reconstructed after training cannot reliably substitute for records maintained during the training process.
(7) Independent examination, properly designed, does not impede responsible development. It supports that development by providing a verifiable public record of compliance that a covered developer may rely upon as evidence of its own diligence.
Running a holiday sale or weekly special? Definitely promote it here to get customers excited about getting a sweet deal.
The purpose of this Act is to require covered developers to maintain verifiable records of the data used in training covered systems, and to establish an independent examiner with standing, access, authority, and the legal ability to require production of the records maintained under this Act, so that questions concerning what occurred, when it occurred, and who was responsible can be answered through verifiable evidence rather than assumption.
As used in this Act:
(1) "Automatic consequence" means a legal result that takes effect because a finding has occurred, without requiring further approval, discretion, or agreement from the covered developer or any other party.
(2) "Covered compute expenditure" means computational resources used in a covered training run, measured in floating point operations or an equivalent unit of computational work, where those resources meet or exceed the threshold established under Section 7(b).
(3) "Covered dataset" means all data used, in whole or in part, in a covered training run.
(4) "Covered deployment" means making a covered system available for public or commercial use, whether directly or through a third party.
(5) "Covered developer" means a person or entity that conducts, directs, controls, or funds a covered training run. If more than one entity is involved in a covered training run, each entity shall be considered a covered developer to the extent of its role, as described in Section 7(d).
(6) "Covered system" means an artificial intelligence model or system produced, in whole or in part, through a covered training run.
(7) "Covered training run" means a computational process that uses a covered compute expenditure to train, fine-tune, continue training, or otherwise materially modify a covered system.
(8) "Finding" means a written determination issued by the Independent Examiner following the procedure described in Section 11, stating whether a covered developer has complied with the requirements of this Act.
(9) "Independent Examiner" means the independent office established under Section 9 to review provenance records and issue findings under this Act.
(10) “Knowing falsification" means intentionally creating, submitting, or causing to be submitted a provenance record, comparison result required under this Act, or other documentation required under this Act, that the covered developer knew to be false at the time it was created or submitted. Knowing falsification does not include an error, omission, or inaccuracy that resulted from negligence rather than intentional deception.
(11) "Protected data source" means a dataset or document that has been designated for protection under Section 8(c), and that a covered developer may not use in a covered training run without disclosure under this Act.
(12) "Provenance record" means a record, created and maintained contemporaneously with a covered training run, that documents what data was included, when it was included, and the source from which it was obtained.
This Act does not define, use, or rely upon the terms "artificial general intelligence," "AGI," "frontier intelligence," "frontier model," or "harmful model." No provision of this Act shall be interpreted by reference to any such term. This Act regulates the conduct described in this Act, regardless of how any resulting system is later described, marketed, or classified.
(a) This Act regulates the institutional conduct of covered developers during and in connection with a covered training run. It does not regulate the internal computational operations of a covered system, nor does it regulate the outputs a covered system produces.
(b) A covered developer's compliance with this Act does not depend on the content a covered system generates after deployment. This Act regulates the documented process by which a covered system was built.
It does not regulate what a covered system says.
(c) Except as expressly provided elsewhere in this Act, this Act does not regulate the use of a covered system by a third party after covered deployment.
(d) Jurisdiction under this Act attaches when a covered training run involves a covered compute expenditure that meets or exceeds the threshold established under Section 7(b). Jurisdiction does not depend on any assessment of a covered system's capability, intelligence, or classification. A covered training run either meets the threshold or it does not.
(e) This Act applies to a covered developer that conducts a covered training run within the United States, regardless of where the resulting covered system is later deployed.
(f) A covered developer's conduct outside the United States is not, by itself, subject to the recordkeeping requirements of this Act. But a covered system built through that conduct may not receive covered deployment within the United States unless the covered developer first produces the required provenance records to the Independent Examiner. Without those records, deployment within the United States is not permitted.
(g) Nothing in this Act shall be construed to regulate speech protected by the First Amendment to the Constitution of the United States. This Act regulates the conduct of a covered developer in conducting a covered training run. It does not regulate the expressive content of any output generated by a covered system.
(h) Nothing in this Act shall be construed to require or authorize the Independent Examiner to evaluate the truthfulness, usefulness, safety, viewpoint, or legality of any output generated by a covered system. The Independent Examiner's jurisdiction is limited to the institutional conduct regulated by this Act.
(i) If, while examining institutional conduct under this Act, the Independent Examiner becomes aware of output-based evidence suggesting that a covered developer may have failed to meet a recordkeeping or disclosure requirement of this Act, the Independent Examiner may refer that evidence for formal examination under Section 11. A referral under this subsection is not a finding. It does not require, and shall not be treated as, an evaluation of the truthfulness, usefulness, safety, viewpoint, or legality of the output. The referral shall identify only the specific recordkeeping or disclosure requirement that the evidence appears to implicate.
(j) A referral under subsection (i) may be made only where the output-based evidence relates directly to a requirement of this Act. Nothing in this subsection shall be construed to expand the Independent Examiner's jurisdiction beyond the institutional conduct regulated by this Act.
(a) A covered development event occurs when a covered developer begins a covered training run that is reasonably expected, at the time it begins, to involve a covered compute expenditure meeting or exceeding the threshold established in subsection (b).
(b) The threshold established under this Act is 10^26 floating-point operations, measured across the full duration of a single covered training run. This threshold is consistent with the compute levels used to define comparable frontier-scale systems in other current federal AI policy proposals, and is subject to the review process established in subsection (c).
(c) Not later than two years after the effective date of this Act, and at least once every two years after that, the Independent Examiner shall review the threshold established in subsection (b). The Independent Examiner shall submit to Congress any recommendation for adjustment needed to reflect changes in computational efficiency, hardware cost, or industry practice. No adjustment under this subsection takes effect unless enacted by Congress.
(d) Where more than one entity participates in a covered training run, obligations under this Act attach as follows:
(1) The entity that directs the covered training run and sets its training objectives is the primary covered developer under this Act.
(2) A cloud infrastructure provider that supplies the covered compute expenditure, but does not direct the covered training run or control its training objectives, is a covered developer only with respect to recordkeeping requirements concerning compute provisioning. That provider is not subject to recordkeeping requirements concerning the content of the covered dataset.
(3) A person who obtains a covered system and later conducts a covered training run to fine-tune, continue training, retrain, or otherwise materially modify it is a covered developer with respect to that later covered training run. This obligation exists independently of any obligation that attached to the original covered developer.
(e) A covered development event occurs each time a covered training run meets the threshold in subsection (b), regardless of whether the resulting covered system is described as a new model, a checkpoint, a fine-tuned version, a distilled version, a successor version,or a component of a modular or composite system. A covered training run does not fall outside this Act solely because it modifies, compresses, distills, or derives from an earlier covered system.
(f) Where a covered developer conducts a series of covered training runs, each individually below the threshold in subsection (b), but collectively meeting or exceeding that threshold within a twelve-month period and directed toward the same covered system or substantially the same covered system, the covered developer shall be treated as having conducted a single covered development event for purposes of this Act.
(a) A covered developer shall create and maintain a provenance record for each covered training run. The provenance record shall be created contemporaneously with the commencement of the covered training run and maintained until the retention period in subsection (f) expires.
(b) A provenance record shall include:
(1) an ingestion manifest identifying each identifiable component of the covered dataset, including its source and the date it was added;
(2) a cryptographic hash of each component identified under paragraph (1);
(3) a description of the preprocessing steps applied to the covered dataset, sufficient to allow the Independent Examiner to substantially reproduce those preprocessing steps; and
(4) a record of the covered compute expenditure used in the covered training run.
(c) The Independent Examiner shall maintain a registry of protected data sources. Any person may petition the Independent Examiner to designate a dataset or document as a protected data source, under procedures the Independent Examiner shall establish. Upon designation, the Independent Examiner shall generate a cryptographic hash of the protected data source and record that hash in the registry. A covered developer may petition the Independent Examiner to remove or narrow a designation under this subsection, and the Independent Examiner shall grant that petition if the designation is broader than necessary to serve the purpose of this Act.
(d) Before using any component of a covered dataset in a covered training run, a covered developer shall compare that component, using the cryptographic hash generated under subsection (c), against the registry maintained under subsection (c). The covered developer shall log the result of that comparison as part of the provenance record required under subsection (b).
(e) A provenance record shall be created contemporaneously with the covered training run it documents, consistent with the finding in Section 2(5). A record first created or materially reconstructed after a covered training run has concluded does not satisfy this section.
(f) A covered developer shall retain a provenance record for not less than ten years after the date of covered deployment, or for as long as the covered system remains available through covered deployment, whichever is longer.
(g) A covered developer shall maintain each provenance record under conditions that permit the Independent Examiner to detect whether any alteration has been made after the record was created.
(h) Upon receiving notice of an examination or a petition under this Act concerning a covered training run, a covered developer shall preserve all provenance records, compute attestation records, ingestion manifests, cryptographic hashes, and other documentation required under this Act relating to that covered training run until the examination and any judicial review under this Act are complete. This duty to preserve exists independently of, and continues beyond, the retention period otherwise established under this Act. A covered developer that destroys, alters, or conceals a record required to be preserved under this subsection after receiving notice under this subsection is subject to a finding of knowing falsification under this Act, and the destruction, alteration, or concealment itself constitutes evidence supporting that finding.
(i) The following do not constitute evidence of the contents of a covered dataset under this Act:
(1) the latency of a covered system's response to any prompt;
(2) the presence or absence of prefix-cache or similar inference-time optimization behavior;
(3) a covered system's perplexity, confidence, or any similar statistical measure when processing a prompt; or
(4) any other measurement of a covered system's behavior at the time it generates an output. For purposes of this Act, evidence of the contents of a covered dataset consists solely of the provenance records required under this section.
(j) A covered developer may designate as confidential any specific content of a provenance record whose disclosure would cause identifiable competitive harm to the covered developer. The Independent Examiner has full access to a record so designated, notwithstanding that designation. The Independent Examiner may challenge a designation under this subsection and may order the covered developer to narrow or remove it if the Independent Examiner finds the designation is broader than necessary to prevent that harm. Any officer or employee of the Independent Examiner who knowingly or with gross negligence discloses a record designated as confidential under this subsection, other than as required by this Act or by law, is subject to the penalties established under Section 12(j). An officer or employee who discloses a record in good-faith compliance with a subpoena, court order, or other legal process, after providing the Independent Examiner and the covered developer reasonable notice where practicable, is not subject to penalty under this subsection.
(k) Not less than once each year, the Independent Examiner shall publish a public compliance summary for each covered developer. A compliance summary published under this subsection shall not include the contents of any record designated as confidential under subsection (j).
(a) There is established an Office of the Independent Examiner, headed by an Independent Examiner. The Independent Examiner shall be independent of any covered developer and independent of any agency whose statutory mission includes promoting, developing, or advancing the artificial intelligence industry.
(b) The President shall appoint the Independent Examiner, by and with the advice and consent of the Senate, for a term of five years. The Independent Examiner may be removed by the President only for neglect of duty, malfeasance, incapacity, or a violation of this Act, and for no other reason. The Independent Examiner may be reappointed for one additional term.
(1) If a court of competent jurisdiction holds that the removal protection in subsection (b) is unconstitutional or otherwise unenforceable, that holding does not affect the validity of any other provision of this section or this Act. In that circumstance, the Independent Examiner is removable by the President at will, and all other provisions of this Act remain in full effect.
(c) An individual appointed as Independent Examiner shall have not less than seven years of professional experience in at least two of the following fields: independent auditing, forensic examination, computer science, or administrative law. An individual may not be appointed as, or continue to serve as, Independent Examiner while holding a direct financial interest in a covered developer, or an indirect financial interest held through a spouse or an entity the individual controls. This subsection does not apply to an interest held through a widely diversified investment fund, including a mutual fund or exchange-traded fund, over whose specific holdings the individual exercises no control, provided that no single covered developer constitutes a significant portion of that fund's holdings.
(d) An individual may not be appointed as Independent Examiner, or employed in a role examining a covered developer, if that individual was employed by that covered developer within the preceding two years. An individual who leaves employment with the office of the Independent Examiner may not accept employment with a covered developer that the individual examined within the preceding two years.
(e) The office of the Independent Examiner shall be funded through an assessment on covered developers, calculated in proportion to each covered developer's covered compute expenditure, and deposited into a fund established for that purpose. This fund is not subject to annual discretionary appropriation. Assessments collected under this subsection shall be pooled and allocated without regard to the identity of the contributing covered developer.
(f) Computing resources used to examine a covered developer shall not be procured from, hosted by, or otherwise supplied by that covered developer. The Independent Examiner shall procure computing resources through a competitive procurement process involving more than one qualified provider.
(g) Notwithstanding any other provision of law governing federal compensation, the Independent Examiner may establish rates of pay for technical staff sufficient to attract individuals with the qualifications described in subsection (c), consistent with rates of pay for comparable positions outside the federal government.
(h) The Independent Examiner may require a covered developer to produce any provenance record, compute attestation record, or other record required under this Act. The Independent Examiner may enter and inspect the physical or virtual facilities of a covered developer, upon reasonable notice, to verify the accuracy of a record produced under this subsection.
(i) The jurisdiction of the Independent Examiner is limited to the institutional conduct regulated by this Act. The Independent Examiner shall not exercise any authority beyond that expressly granted by this Act, including the limits established in Sections 6(h) and 6(i) with respect to the output of a covered system.
(a) There is established an Inspector General for the Office of the Independent Examiner. The Inspector General shall be appointed by the President, by and with the advice and consent of the Senate, for a term of five years. The Independent Examiner may not appoint, remove, or direct the Inspector General. The Inspector General may be removed by the President only for neglect of duty, malfeasance, incapacity, or a violation of this Act, and for no other reason.
(b) The jurisdiction of the Inspector General is limited to the conduct and operations of the Office of the Independent Examiner. The Inspector General has no jurisdiction over a covered developer, and no authority to review, alter, or delay a finding issued under this Act.
(c) The Inspector General shall report its findings directly and publicly to Congress, not through the Independent Examiner. Nothing in this Act authorizes the Independent Examiner to review, delay, or condition the publication of an Inspector General report.
(d) Not less than once each year, the Independent Examiner shall publish a public report to Congress covering examinations opened, findings issued by tier, average examination duration, appeals filed and their outcomes, and aggregate compliance rates across covered developers. A report under this subsection shall not include the contents of any record designated as confidential under this Act.
(e) The Independent Examiner may prescribe regulations necessary to administer this Act. A regulation prescribed under this subsection may not expand the jurisdiction, obligations, or authority established by this Act. This subsection does not authorize the Independent Examiner to exercise any authority beyond that expressly granted elsewhere in this Act.
(a) The Independent Examiner may open an examination of a covered developer's compliance with this Act on the Independent Examiner's own initiative, upon a referral under Section 6(i), or upon a written petition by any person alleging specific facts that, if true, would show a violation of this Act.
(b) The Independent Examiner may issue a finding that a covered developer has violated this Act only upon a preponderance of the evidence, based solely on the provenance records and other records required or produced under this Act. Notwithstanding the preceding sentence, the Independent Examiner may issue a finding of knowing falsification undertaken to conceal the use of a protected data source only upon clear and convincing evidence. No other finding under this Act requires a standard of proof higher than a preponderance of the evidence.
(c) Before issuing a final finding, the Independent Examiner shall issue a preliminary finding to the covered developer. A preliminary finding shall state the specific provision of this Act that the covered developer is alleged to have violated, the evidence supporting that allegation, including the specific records on which the preliminary finding relies, and the reasoning connecting that evidence to the alleged violation.
(d) A covered developer shall have not less than sixty days after receiving a preliminary finding to respond in writing, to produce additional records, or to request a meeting with the Independent Examiner. A covered developer may appear at any meeting requested under this subsection with legal counsel or another representative. The Independent Examiner shall prepare a written summary of any meeting held under this subsection, which becomes part of the administrative record. The Independent Examiner shall consider a timely response under this subsection before issuing a final finding.
(e) After considering any response under subsection (d), the Independent Examiner shall issue a final finding sustaining, modifying, or withdrawing the preliminary finding. A final finding shall state the evidence relied upon and the reasoning connecting that evidence to the finding.
(f) The Independent Examiner shall publish each final finding, including a statement of the reasoning required under subsection (e), not later than thirty days after it is issued. A published finding shall not include the contents of any record designated as confidential under Section 8(j).
(g) A preliminary finding does not, by itself, trigger any automatic consequence under this Act. Only a final finding triggers the automatic consequences established under this Act. A preliminary finding is not admissible as evidence that a violation of this Act occurred in any other proceeding.
(h) The Independent Examiner shall issue a final finding not later than one hundred eighty days after issuing a preliminary finding, unless the covered developer and the Independent Examiner agree in writing to extend that period, or unless the Independent Examiner states, in writing, good cause for a longer period.
(i) The administrative record of an examination under this section consists of the preliminary finding,
the evidence relied upon under subsections (b) and (c), any response submitted under subsection
(d), and the final finding issued under subsection (e). This record may be supplemented only in accordance with procedures established under this Act.
(j) A covered developer may not discharge, demote, suspend, threaten, harass, or otherwise discriminate against an employee or contractor because that individual, in good faith, provided information to the Independent Examiner, filed or assisted in filing a petition under subsection (a), or testified or otherwise participated in an examination under this Act. An individual who believes they have been subjected to conduct prohibited by this subsection may petition the Independent Examiner for relief under the procedure established under this section. A finding that a covered developer violated this subsection triggers the following consequence, independent of the tier structure established under Section 12: the covered developer shall submit a corrective compliance plan to the Independent Examiner not later than thirty days after the finding is published, addressing the conduct found to violate this subsection. Submission of a corrective compliance plan under this subsection does not otherwise restrict the covered developer under this Act unless and until a subsequent finding under this subsection is issued. A second or subsequent finding that the same covered developer violated this subsection is a Tier Three finding under Section 12(b)(3).
a) The purpose of the consequences established in this section is to create predictable compliance incentives, not to impose punitive sanctions. Upon issuance of a final finding that a covered developer has violated this Act, the consequences established in this section attach automatically, without further agency action, discretion, or proceeding, except as expressly provided in this Act.
(b) A final finding shall classify each violation into one of the following tiers:
(1) Tier One, Recordkeeping Deficiency: a failure to maintain a provenance record in the form required under Section 8, where no evidence indicates the covered dataset included a protected data source.
(2) Tier Two, Verification Failure: a failure to compare a covered dataset against the registry maintained under Section 8(c), or a failure to log that comparison as required under Section 8(d).
(3) Tier Three, Confirmed Ingestion of a Protected Data Source: a finding, based on the provenance records required under Section 8, that a covered dataset included a protected data source without the disclosure this Act requires.
(4) Tier Four, Knowing Falsification: a finding of knowing falsification, as defined under this Act. Tier Four is aggravated where the knowing falsification was undertaken to conceal the use of a protected data source, and ordinary where it was not.
(c) A covered developer subject to a Tier One finding shall submit a corrective compliance plan to the Independent Examiner not later than thirty days after the final finding is published. The covered developer is not otherwise restricted under this Act while implementing a compliance plan approved by the Independent Examiner.
(d) A covered developer subject to a Tier Two finding may not receive covered deployment of the covered system involved in the finding until the Independent Examiner completes a verification review and issues a written finding confirming the covered dataset does not include an undisclosed protected data source.
(e) A covered developer subject to a Tier Three finding may not receive covered deployment of the covered system involved in the finding. This restriction remains in effect until the covered developer removes the protected data source from the covered dataset, conducts a new covered training run to completion without it, and the Independent Examiner confirms compliance through a subsequent examination.
(f) A covered developer subject to an ordinary Tier Four finding may not receive covered deployment of the covered system involved, and is not eligible to cure that finding through the process otherwise available under this Act. The restriction imposed under this subsection remains in effect until the Independent Examiner, after a new examination, issues a finding that the covered developer's provenance records for the covered system involved are accurate and complete.
(g) A covered developer subject to an aggravated Tier Four finding remains under the same restriction described in subsection (f). Upon a final aggravated Tier Four finding under this section, the Independent Examiner shall refer that finding to the Department of Justice in writing, not later than thirty days after the finding becomes final under Section 11. A referral under this subsection shall include the finding and the administrative record described in Section 11(i). A referral under this subsection is not a prosecution, does not bind the Department of Justice to act, and does not affect the covered developer's rights under Section 13. The Independent Examiner shall provide the covered developer notice that a referral has been made not later than the date the referral is transmitted.
(h) At any tier other than Tier Four, a covered developer may cure a violation through the process described in this section. Cure of a Tier Four violation is governed exclusively by the process described in this section for that tier.
(i) A consequence under this section attaches solely because of a final finding issued under Section 11. No provision of this Act authorizes a consequence based on public reaction, media coverage, political considerations, or any other factor outside this Act.
(j) An officer or employee of the Independent Examiner found, through the process described in Section 11, to have violated Section 8(j) shall be subject to removal from office or employment and to a civil penalty of not more than $50,000 for each violation.
(k) A consequence under this section attaches to the covered developer whose conduct is the subject of the final finding, and, where more than one covered developer participated in a covered training run under Section 7(d), to the specific covered developer whose role gave rise to the violation. Except as provided in subsection (j), a consequence under this section does not attach to a covered system or to any person who is not a covered developer under Section 4(5).
(l) Nothing in this Act shall be construed to authorize the Independent Examiner to prohibit research into, discussion of, or publication concerning a covered system beyond the deployment restrictions expressly established in this Act.
(a) A covered developer aggrieved by a final finding may petition for review in the United States Court of Appeals for the circuit in which the covered developer is headquartered, or in the United States Court of Appeals for the District of Columbia Circuit.
(b) A petition for review under subsection (a) shall be filed not later than sixty days after the final finding is published under Section 11(f).
(c) The reviewing court shall set aside a final finding if the court determines that the finding is not supported by substantial evidence in the administrative record described in Section 11(i), considered as a whole; or that the Independent Examiner acted outside the authority granted by this Act, including the limits established in Sections 6(h), 6(i), and 9(i); or that the Independent Examiner otherwise acted contrary to law.
(d) The reviewing court shall base its review on the administrative record described in Section 11(i). The court shall not consider evidence outside that record, except evidence offered solely to establish that the Independent Examiner acted outside the authority granted by this Act.
(e) Filing a petition for review does not stay a consequence under Section 12, except that the reviewing court may stay a consequence under Section 12(d) or Section 12(e) upon a showing that the covered developer is likely to succeed on the merits of the petition and will suffer irreparable harm absent a stay.
(f) The reviewing court shall render a decision not later than one hundred eighty days after a petition for review is filed, unless the court finds good cause in writing for a longer period.
(g) A petitioner whose petition under Section 11(a) was denied may seek judicial review of that denial. The reviewing court shall set aside a denial under this subsection only upon a showing that the denial was an abuse of discretion.
(h) If the reviewing court sets aside a final finding under this section, the consequences established under Section 12 that attached to that finding no longer apply. The Independent Examiner may conduct further proceedings consistent with the court's decision.
(i) A reviewing court shall give due regard to the Independent Examiner's findings of fact but shall decide all questions of law independently.
(j) Judicial review under this section is the exclusive means for obtaining review of a final finding issued under this Act.
The purpose of this section is to ensure that the evidentiary and technical foundations of this Act remain subject to independent review as science, technology, and administrative practice evolve. This section does not authorize the review commission to reconsider the policy choices reflected in this Act.
(a) Not later than five years after the effective date of this Act, and not less than once every five years after that, an independent review commission shall evaluate whether the evidentiary assumptions, technical mechanisms, and governance structures established by this Act remain scientifically, technically, and administratively valid.
(b) The review commission shall consist of nine members. Not more than five members may be affiliated with the same political party. Three members shall be appointed by the President. Three members shall be appointed by the Speaker and the Minority Leader of the House of Representatives, in equal number from each. Three members shall be appointed by the Majority Leader and the Minority Leader of the Senate, in equal number from each. The membership shall collectively include individuals with professional experience in computer science, independent auditing, administrative law, and civil liberties. No member may hold a direct financial interest in a covered developer, or an indirect financial interest held through a spouse or an entity the individual controls. This subsection does not apply to an interest held through a widely diversified investment fund, including a mutual fund or exchange-traded fund, over whose specific holdings the member exercises no control, provided that no single covered developer constitutes a significant portion of that fund's holdings.
(c) The review commission's evaluation shall address, at a minimum:
(1) whether the threshold established under Section 7(b) remains an accurate measure of the covered training runs this Act is intended to reach;
(2) whether the evidentiary standard established under Section 8, including the exclusions in Section 8(i), remains technically sound and independently verifiable in light of advances in computer science since the Act's effective date or the most recent review;
(3) whether the funding and independence structure established under Section 9 continues to function as intended; and
(4) whether the Independent Examiner has issued findings consistent with the evidence contained in the administrative records of its examinations.
(d) The review commission shall publish a public report to Congress not later than one hundred eighty days after completing its evaluation. The report shall state the commission's findings and any recommended amendments to this Act, if any.
(e) If the review commission determines, at any time, that a technical assumption underlying this Act has been substantially undermined by new evidence such that continued reliance on this Act's evidentiary standard creates a substantial risk of material harm, the review commission may issue an interim report to Congress before completing its regular review under this section.
(f) The Independent Examiner shall cooperate with the review commission by providing access to records, reports, and other materials necessary to conduct the evaluation required by this section, subject to the confidentiality protections established in Section 8(j).
(g) A recommendation under this section does not take effect unless enacted by Congress. Nothing in this section authorizes the review commission to alter, suspend, or waive any provision of this Act, or to exercise regulatory, enforcement, or adjudicatory authority.
(a) If any provision of this Act, or the application of any provision to any person or circumstance, is held invalid, the remainder of this Act, and the application of that provision to other persons or circumstances, is not affected.
(b) Except as otherwise provided in this section, this Act takes effect one year after the date of enactment.
(1) Section 9 takes effect on the date of enactment, to allow for appointment, staffing, and establishment of the office before any covered developer becomes subject to examination.
(2) Sections 4 through 7 take effect on the date of enactment, solely for purposes of establishing the threshold review process under Section 7(c).
(3) Section 8 applies to a covered training run begun on or after the effective date established in this subsection. A covered developer is not required to reconstruct provenance records for a covered training run begun before that date.
(c) The Independent Examiner shall coordinate with existing federal agencies whose responsibilities relate to artificial intelligence, including the National Institute of Standards and Technology and the Federal Trade Commission, to avoid unnecessary duplication of recordkeeping or reporting requirements. Nothing in this Act limits the authority of another federal agency to enforce a requirement under a different statute, based on the same underlying conduct.
(d) Compliance with this Act does not excuse a covered developer from compliance with any other applicable federal, state, or local law. A finding under this Act, or the absence of a finding, is not a defense to liability under any other federal law.
(e) This Act preempts state law only with respect to provenance and recordkeeping requirements for a covered training run as defined in this Act. This Act does not preempt, and shall not be construed to affect, any state law governing the deployment, use, or application of an artificial intelligence system, including state laws addressing employment, healthcare, consumer protection, or civil rights. A state law that imposes an additional or more stringent provenance or recordkeeping requirement on a covered training run is not preempted solely because it imposes additional or more stringent requirements.
(f) This Act does not create a private right of action. Except as expressly provided in this Act, only the Independent Examiner may bring a civil action to enforce this Act.
(g) Nothing in this Act shall be construed to authorize the Independent Examiner to regulate the content of speech or the expressive content of any output generated by a covered system.
(h) Nothing in this Act shall be construed to establish, authorize, or require coordination with the AI governance framework of any foreign government or international body. Any such coordination requires separate statutory or treaty authorization.
(i) If a provision of this Act directly conflicts with a provision of another federal statute such that compliance with both is impossible, the provision that was enacted later in time controls, unless the conflicting statute expressly states otherwise. This subsection applies only where compliance with both provisions is impossible; it does not apply merely because two statutes address related subject matter.
A Model Statute for AI Training-Data Accountability: How It Was Built, and What It Actually Does
The Question This Page Answers
If something goes wrong with an AI system years from now, one explanation will always be available. Blame the algorithm. Blame "the AI." Treat the failure as if no human ever made a decision along the way.
That story only works because right now, nothing requires anyone to prove otherwise. No law requires an AI developer to keep real records of what data trained a system. No independent examiner has the standing to check those records if they existed. When the failure comes, there will be no evidence trail to say who knew what, and when. The absence of evidence will be mistaken for evidence of innocence, whether or not it is.
This page contains a model statute built to close that gap before it's needed, not after. It doesn't ask whether AI is dangerous, or intelligent, or aligned. It asks a narrower, harder-to-dodge question: was a record kept, was it timely, and can someone independent check it? Those are questions a court already knows how to answer. That's the point.
Most AI legislation gets stuck trying to define its own subject. What counts as "AGI"? What makes a model "frontier"? What is "harmful"? Those debates rarely end, and they're usually won by whoever benefits most from the confusion.
What Makes This Different
This Act never asks those questions. It regulates something else entirely: the conduct of building an AI system, not the system itself. A training run either used a certain amount of computing power, or it didn't. A record either exists, or it doesn't. A comparison against a protected dataset either happened, or it didn't. Every obligation created by this statute can be checked against something real, by someone with no stake in the outcome. That also means the statute reaches a covered developer regardless of where training occurs: a company training outside the United States cannot bring the resulting system into the American market without producing the same records a domestic developer must keep, and a cloud provider supplying computing power is held to a narrower, separate duty than the developer directing the work.
That single choice — regulate the process, not the technology — is what lets the statute survive its own uncertainty about the future. It doesn't need to know what AI will become next year. It only needs someone to have kept the books.
Who's Accountable, and Who Isn't
This statute assigns consequences to a covered developer — a named, identifiable institution or person who directed, funded, or controlled a training run. It does not, and structurally cannot, attach a consequence to an AI system itself. That's not an accident. It's the whole design.
If something goes wrong with an AI system in the future, this statute exists so that no one can point at the technology and call it an act of nature. Somebody trained it. Somebody chose what data went in. Somebody decided whether to keep a record of that choice. This Act makes sure those decisions leave a trail, so that whoever made them can be identified — not the algorithm, not the industry in the abstract, but a specific covered developer whose conduct is documented, dated, and reviewable. Accountability runs the other direction, too: the office built to enforce this Act is independently funded through pooled assessments rather than payments tied to any single company it examines, staffed under revolving-door restrictions that prevent a return to or from the industry it oversees, and watched by its own Inspector General, whom the Examiner cannot appoint, direct, or remove.
How This Was Built
This statute did not arrive fully formed. It started as an idea proposed by Gemini, Google's AI system, during a conversation that, turn by turn, evolved from answering questions to drafting statutory language. That first draft contained one genuine architectural insight that survived every subsequent revision: regulate the institutional conduct around AI development, not the technology's capabilities. It also contained a real, serious flaw: a proposed method for detecting whether protected data had been used in training, based on measuring how quickly an AI system responds to certain prompts. That proposed method proved technically unsound. It confuses two unrelated properties of how AI systems run.
That mistake was caught twice, independently — first by Claude, Anthropic's AI system, through direct technical scrutiny, and again when the same flawed mechanism was shown, cold, to ChatGPT, OpenAI's AI system, with no knowledge of the first draft's history, and evaluated on pure technical merit. Both reached the same technical conclusion for the same reason. The flawed mechanism was removed entirely, not revised, and replaced with something that has actually been used in comparable oversight bodies for decades: contemporaneous records, cryptographic verification, and an examiner with real, independent standing to check them
Every substantive provision in this statute passed through the same process: proposed, challenged, and either accepted, rejected, or rewritten, with the reasoning for every decision preserved rather than smoothed away. The final decision on every line belonged to a human being, not to any AI system involved. Confidence was never treated as evidence. Independent verification was the only standard that counted.
What This Statute Does Not Solve
This is a discussion draft, not a final answer — and discussion drafts exist to improve through criticism, not to avoid it. It's worth being honest about exactly where its limits sit.
It does not resolve the deeper problem that almost all of the country's computing infrastructure sits inside a small number of private companies — meaning any examiner's office, however independent on paper, still depends on an industry it doesn't fully control for the resources to do its job. This statute narrows that dependency. It doesn't eliminate it.
It does not attempt to regulate how AI is used once it's built into hiring decisions, healthcare applications, and consumer products. That's deliberate: those questions belong with the states, which have historically led on exactly this kind of accountability, and this statute is built to leave that authority untouched.
It does not resolve the harder philosophical question of whether the underlying problem it responds to — AI systems increasingly shaping the evidence base that future governance will reason from — is something this kind of statute can fully answer at all. That question is bigger than any single piece of legislation, and pretending otherwise would be the same as overclaiming that this whole project exists to catch others in.
An Invitation, Not a Verdict
This page does not claim to have solved the problem of AI governance. Nobody has. What it offers is a serious, transparently built, technically corrected starting point — one built specifically to survive scrutiny rather than avoid it. If a provision here is wrong, the same discipline that built it can revise it. That was true on the first day of drafting, and it remains true now.
If this statute succeeds, it should be because someone builds a better version of it—not because this version escaped criticism.
Stay Sovereign.
Jim Germer
July 19, 2026
06:21 AM
We use cookies to improve your experience and understand how visitors use our website so we can make it better.