// blog · analysis · policy2026-08-08source: policy reporting and legal analysis

Sixty days later, and the states went the other way

The federal framework deadline landed on 1 August. In the same season the strictest state law in the country was repealed by the state that wrote it.

Agencies had 60 days from the June executive order to produce the framework behind covered frontier model designation. Meanwhile Colorado repealed and rewrote its own AI Act, stripping the risk management programme, the annual impact assessments and the duty of care.

The retreat is about enforceability

Colorado wrote the most demanding state AI law in the country. It then looked at implementation and pulled the demanding parts before they took effect. That is not a political story so much as an administrative one, and it is the same conclusion Brussels reached when it pushed high-risk conformity assessment out to December 2027.

Twice now, in two jurisdictions with opposite politics, a horizontal risk-assessment regime has met the question of who exactly performs the assessment and lost. Connecticut's narrower, use-case approach — chatbots, synthetic media, automated decisions — is what keeps surviving contact with a legislature.

The federal instrument is stranger

Real assessment machinery, a classified threshold, an NSA determination, a voluntary 30-day pre-release access window — and an explicit refusal to create licensing, pre-clearance or permitting. It measures without gating.

The lobbying was open: reporting places lab and chip executives with lawmakers and officials during the drafting. Not improper, and it does mean the framework was partly shaped by the parties it governs.

The week's actual evidence

OpenAI stopped work on Astra after finding it met the Critical cybersecurity bar in the company's own Preparedness Framework — able to find and develop working zero-days in hardened real-world systems without human intervention.

That is the strongest case anyone has made for voluntary restraint, and it is also the clearest illustration of why it is not enough. The company wrote the threshold, ran the evaluation, graded itself, and no external party has seen the model or the results. It held this time. The mechanism contains nothing that guarantees it holds next time.

Meanwhile the courts are settling a prior question. A judge declining to hold that model output is speech, letting product liability and negligence proceed, will shape more behaviour than either framework.

CNBC — Trump's AI executive order nears key deadline as regulation debate intensifies → · Wiley — Connecticut enacts AI framework while Colorado scales back landmark AI law → · Lawfare — If AI outputs aren't speech, who has to prove they're human? →