← All company positions
Googleagenda

A Pragmatic Approach to AI Governance in America

Published June 2026 · Printed on the cover page directly above the title; the PDF document title reads "A Pragmatic Approach to AI Governance in America, June 2026". The companion announcement on blog.google prints "Jun 25, 2026".

Not law. This is a company's own public position on AI regulation. It is not law, and it carries no legal force.

What it argues for

Google argues that "the debate over AI governance is stuck in a false choice between over-regulation and no regulation" and proposes a two-track US federal regime that treats frontier AI and everyday AI as different regulatory problems. For frontier models, it proposes a new federally overseen, industry-funded self-regulatory body — a "frontier AI regulatory organization (FARO)" — explicitly modelled on NERC (overseen by FERC), FINRA and the PCAOB (overseen by the SEC), the AMA and state bar associations: private bodies that "write and enforce binding rules on their members, but operate under the supervision (and ultimate veto) of a government agency." The FARO would maintain a repository of scientific benchmarks and safety/security standards for building, testing and deploying frontier systems, require each frontier developer to publish and adhere to its own frontier AI framework, and run an annual independent "procedural" audit regime that would harden into substantive audits once real benchmarks exist. Below the frontier, Google argues the federal government "does not need new regulatory regimes that duplicate or conflict with existing law" and should instead adapt existing statutes to specific real-world harms — child safety, copyright, workforce transition, energy, provenance and privacy — on the principle that "if something is illegal to do without AI, it's illegal to do with AI." The paper is explicitly evidence-based and output-focused: it says regulation should "address outputs, not inputs," accept some uncertainty rather than slow progress, and that "the greatest risk of all would be missing out on AI's life-changing benefits." The framing line Google repeats is that "AI is too important not to regulate, and too important not to regulate well."

Stated positions (13)

  • Create a 'frontier AI regulatory organization (FARO)' — an independent, industry-funded, industry-and-independent-director-governed body operating under a federal agency's supervision and ultimate veto, on the NERC/FINRA/PCAOB model. Oversight 'could be provided by any number of agencies, including the Commerce Department, the Treasury Department, or the Department of Energy.'
  • Two separate regimes, not one AI law: frontier AI is framed as a national-security problem; widely-deployed applications like chatbots are framed as consumer-protection problems that existing law can reach.
  • The federal government 'should ultimately be the lead jurisdiction on issues of importance to national security' — while noting Google 'supported initiatives in various states' and 'have supported U.S. state legislation requiring frontier AI frameworks and other safety measures such as transparency and incident reporting.'
  • Membership threshold: reject FLOPs as the test ('a mere recital of the number of floating point operations (FLOPs) used in training is insufficient and both over- and under-broad'), but accept 10^26 FLOPs as an interim placeholder until NIST or the FARO develops a capability-based standard keyed to facilitating cyberattacks or expert-level CBRN assistance.
  • Every frontier developer publishes its own framework with tiered risk thresholds and mitigations, model-weight security against unauthorized transfer, critical incident response plans, and internal governance — explicitly building on Google DeepMind's Frontier Safety Framework.
  • Audits start as annual independent PROCEDURAL audits by established professional audit firms (did you follow your own framework?), with pre-release attestation to the FARO, moving to substantive audits later. Three protections: standardized document sets, a company right to remediate before the report is final, and confidential submission of all final audit reports to the FARO.
  • International reciprocity: models verified by the FARO would be 'automatically verified in reciprocal jurisdictions', letting the FARO 'set the global benchmark'.
  • The FARO 'would complement – but not supplant' US national security agencies' early access to models with advanced cyber capabilities, referencing the Administration's Executive Order on Promoting Advanced Artificial Intelligence Innovation and Security.
  • Minors: federal law should mandate evidence-backed AI interaction guidelines, disclaimers that chatbots are not sentient, bans on gamified rewards, and 'pause-and-direct' protocols for self-harm-related queries.
  • Copyright: AI training on public data 'is subject to fair use and text-and-data-mining exemptions'; infringing outputs should be handled under established copyright and notice-and-takedown regimes, with industry-developed value exchange for creators.
  • Information integrity: Congress should require watermarking (SynthID named) and tamper-resistant cryptographic provenance (C2PA named) for generative AI services, while warning against 'label fatigue' from over-labelling.
  • Energy: a public-private initiative to scale generation and transmission, with comprehensive federal permitting reform, arguing large AI data centres help amortize fixed legacy grid costs and ultimately lower residential rates.
  • Workforce: gather data before regulating — better economic-impact assessments, employer-driven 'earn-and-learn' upskilling, and 'where warranted, modernization of unemployment insurance.'

About this document

A 21-page illustrated PDF policy paper published on publicpolicy.google in June 2026, authored corporately by Google (no named signatory; it speaks as "we") and carrying no footnoted citations, bill numbers or docket reference — it is a positioning paper aimed at federal policymakers rather than a formal submission. It is organised into five numbered sections: 01 Executive Summary, 02 Introduction, 03 Standard-Setting for Frontier AI, 04 Policies for Widely-Deployed AI, and 05 Conclusion. The executive summary is laid out as callout tiles (Shape the Future of Work, Protect Minors, Promote Copyright and Creativity, Develop Energy Infrastructure, Protect Privacy, Ensure Information Integrity). Section 03 develops a single institutional proposal — a "frontier AI regulatory organization" (FARO), an independent industry-funded body supervised by a federal agency such as Commerce, Treasury or Energy, explicitly modelled on NERC/FERC, FINRA, the PCAOB, the AMA and state bar associations — with sub-sections on benchmarks and standards and on transparency and annual audits. Section 04 runs six sub-sections: workforce, kids and families, energy and data centres, provenance, copyright, and privacy. Alongside asks of government it records Google's own commitments: the Ratepayer Protection Pledge, nearly 35 GW of contracted power, water replenishment by 2030, training over 300,000 workers and all six million US educators, publisher grounding-partnership pilots, and the Google-Extended robots.txt control. It names 10^26 FLOPs, NIST, ANSI, ISO, the Frontier Model Forum, SynthID, C2PA and the Collingridge Dilemma.

How this sits against AI law

Each stance compared with what EU and US instruments actually require. Where no instrument addresses a theme, that gap is shown rather than hidden.

Federal leadership over a state patchwork

Because of its role, capabilities and access to intelligence, the federal government should be the lead jurisdiction on frontier AI, with one national framework for safety, security, incident reporting and transparency instead of state-by-state rules.

European UnionAligned

The AI Act delivers exactly this single-jurisdiction outcome: one directly-applicable regulation across all 27 Member States, with supervision of general-purpose AI models reserved exclusively to the Commission's AI Office under Article 88.

United StatesContradicts

California already binds large frontier developers directly by state law, and no federal statute preempts it — the paper argues that this venue, not its substance, is the mistake, while conceding Google has supported such state bills.

An industry-funded frontier regulator (FARO)

Congress should create a federally overseen but independent, industry-funded frontier AI regulatory organization that sets standards, verifies safety practices before release and runs an annual independent procedural audit regime, with audit reports filed confidentially.

European UnionContradicts

The AI Act vests enforcement over general-purpose models in a public authority — the Commission acting through the AI Office, with power to demand documentation and run its own evaluations (Art 92) — not in an industry-funded self-regulatory body, and it mandates no annual third-party audit.

United StatesNo equivalent law

No US instrument establishes any frontier AI regulator: EO 14179 revoked the prior AI executive order and directed an action plan, imposing no obligations on developers and creating no supervisory body.

Published frontier safety frameworks and incident reporting

Every frontier developer should publish and adhere to a framework with tiered risk thresholds, mitigations, cybersecurity for unreleased model weights, incident response plans and internal governance, and attest to adherence before releasing a materially new model.

European UnionAligned

Article 55 already requires providers of models presumed to carry systemic risk (above 10^25 training FLOPs under Art 51) to evaluate and adversarially test, mitigate systemic risk, secure the model and its physical infrastructure, and report serious incidents to the AI Office without undue delay.

United StatesAligned

SB 53 requires large frontier developers to publish a frontier AI framework covering catastrophic-risk thresholds, weights security and incident response, and to report critical safety incidents to the Office of Emergency Services within 15 days.

No new horizontal regime for widely-deployed AI

Below the frontier the federal government should not build new regulatory regimes that duplicate existing law: regulate outputs and specific harms through existing agencies and time-tested rules rather than creating AI versions of laws that already apply.

European UnionContradicts

The AI Act is precisely the cross-sectoral regime Google argues against — Annex III designates AI as high-risk by use case (biometrics, education, employment, creditworthiness, essential public services) and attaches binding ex-ante duties on top of existing sectoral law.

United StatesContradicts

Colorado's act imposed an AI-specific duty of reasonable care, impact assessments, consumer notices and 90-day attorney-general reporting on developers and deployers of AI used in consequential decisions, exempting some already-regulated sectors. It is the clearest US counter-example to Google's position — and it did not survive: SB24-205 was repealed on 14 May 2026, and its successor SB 26-189 has not yet taken effect, so Colorado has no operative AI statute today. The horizontal regime Google argues against was enacted in one state and then withdrawn.

RAI-US-CO-CSCPAXX-2024Repealed — not binding law today. Superseded by RAI-US-CO-SB26189-2026.

Training data, copyright and creator value exchange

Training on publicly available web data is a transformative, non-expressive use protected by fair use and by text-and-data-mining exceptions abroad; control should come from voluntary machine-readable opt-outs such as Google-Extended, commercial partnerships, and notice-and-takedown for infringing outputs.

European UnionAsks for less

Article 53(1)(c)-(d) makes it binding rather than voluntary: every general-purpose model provider must run a copyright policy that identifies and honours rights reservations under Article 4(3) of Directive 2019/790 and must publish a sufficiently detailed summary of its training content.

United StatesNo equivalent law

No US instrument addresses AI training on copyrighted works; the question is being settled in fair-use litigation, which is why Google's ask here is for the status quo to hold rather than for legislation.

Mandated chatbot safeguards for minors

Federal law should mandate evidence-backed AI interaction guidelines for minors: persistent disclaimers that the chatbot is not a person, filtering of sexually explicit or romantic content, bans on gamified engagement rewards, and pause-and-direct crisis protocols for self-harm queries.

European UnionAsks for more

The AI Act requires only that people be told they are interacting with an AI (Art 50(1)) and prohibits exploiting age-related vulnerabilities to cause significant harm (Art 5(1)(b)); it sets no design rules for chatbots, engagement mechanics or self-harm handling.

United StatesNo equivalent law

No federal instrument addresses chatbot design, companion behaviour or self-harm protocols for minors, so this is an area where Google is asking Congress for obligations that do not exist.

Energy, permitting and data-centre build-out

Policymakers should pass comprehensive federal permitting reform and launch a public-private initiative to scale generation and transmission — an "Eisenhower Highway Program" for the grid — with ratepayer protections written into federal law so data-centre growth lowers, not raises, residential rates.

European UnionNo equivalent law

No EU AI instrument addresses energy infrastructure, grid build-out or data-centre siting; the AI Act touches energy only as a documentation item for general-purpose model providers.

United StatesAligned

Pillar II of the Action Plan is built on the same premise, calling for streamlined permitting for data centres and energy infrastructure and a grid that matches the pace of AI, though it carries no ratepayer-protection commitment.

On substance Google is closer to EU law than its framing suggests: the frontier half of the paper asks the US for roughly what the EU AI Act already imposes on systemic-risk models — published frameworks, weights security, incident reporting, synthetic-content marking — and on audits and child safety it asks for more than either jurisdiction requires. The sharp divergence is structural and institutional: Google wants an industry-funded body under agency supervision where the EU built a public regulator with exclusive enforcement powers, and it rejects for below-frontier AI exactly the horizontal, use-case-based regime that Annex III of the AI Act embodies. Against current US law the paper mostly argues for a level that does not exist yet, while running against the one binding regime that does — California's frontier statute, whose substance Google says it supported but whose venue it wants replaced.

Source

https://publicpolicy.google/resources/a-pragmatic-approach-to-ai-governance-in-america.pdf
Date on the page:
June 2026
Source checked:
opened and confirmed on 2026-09-18