Two Democratic offices published AI texts on 7 October 2026. They are not the same document, and neither is a statute. Sen. Maria Cantwell of Washington, ranking member of the Senate Commerce Committee, outlined a framework of six principles. Rep. Lori Trahan of Massachusetts released a discussion draft of a liability bill she calls the CLAIM Act. Neither page says the text has been enacted.
Cantwell’s six principles
Cantwell’s release says she outlined “a comprehensive AI governance framework built upon six principles that must drive the legislative and executive actions needed to address catastrophic risks and other AI harms.” It attaches no bill number. She is quoted: “To manage risks from advanced AI systems we need clear safety standards, continuous testing, and reporting of serious failures.”
The six headings, in the order the release prints them:
- Clear, Enforceable Federal Safety Standards for Frontier AI Development and Deployment
- Continuous Testing, Reviewing and Auditing to Verify Standards are Met
- Transparency and Accountability Through Disclosure, Oversight and Consequences
- Public Private Partnerships to Benefit the Public Good
- Protections for Children, Support for Workers and Human Oversight of Consequential AI
- U.S. Led Global Cooperation in Adopting and Upholding Common AI Safety and Security Standards
Under the first heading, NIST should develop “clear, transparent, measurable, risk-based standards for AI systems that could cause catastrophic harm.” The listed harms are “AI-enabled cyberattacks; chemical, biological, radiological and nuclear threats; potential for loss of human control; and automated improvement and autonomous agents escaping secure testing environments.” An “Open-Source Protections” line calls for specialized standards for open-source models. Covered models “should not be released until they have undergone an independent audit.”
Incident reporting includes “loss of control over autonomous agents.” On accountability, the release does not set a new penalty schedule. It says developers “must remain liable under applicable civil and criminal law for foreseeable harms and unlawful conduct arising from their AI systems.” The same section covers whistleblowers. Later headings cover defensive AI, public-interest compute, children, workers, and human oversight, plus a secure channel with China “like the Soviet era red phone.”
The CLAIM Act is a discussion draft
Trahan’s release says she “released a discussion draft” of the Clear Liability for Artificial Intelligence Misconduct Act. The PDF is stamped “October 5, 2026 (12:18 p.m.).” Its header reads “H. R.” with the bill number left blank, 119th Congress, 2d session, and the committee line is blank too. The sheet uses the standard bill form, “Mrs. TRAHAN introduced the following bill,” but carries no number. Her office calls the file a discussion draft. It is not law.
Section 3 is the mechanism. A “developer” is “a person that performs the initial training of an artificial intelligence system.” A user operates or directs it, including by prompting. A non-user is anyone else.
Except for defamation, a developer “shall be liable, regardless of the degree of care exercised, for all reasonably foreseeable injuries to a non-user” if the injuries are factually and proximately caused by a system that “engages in conduct that, if undertaken by an adult human of sound mind, would satisfy the elements of negligence or any intentional tort or crime,” and neither the user nor “any intermediary that fine-tuned, scaffolded, or otherwise modified the system” intended that conduct or “was negligent with respect to the risk.” Elements follow “the law of the State in which the injury occurred.” The draft applies to training, development, provision, or deployment in or affecting interstate or foreign commerce.
Section 4 is a rebuttable presumption of the mental state a person taking similar actions would have had, and “it shall not be a defense that artificial intelligence systems are incapable of having mental states.” Section 5 is a private suit in federal or state court, within three years of discovering the injury. Section 6 says the act shall not “preempt, displace, or otherwise limit” state causes of action, and remedies are “in addition to, and not in lieu of,” other remedies. It would take effect on enactment and expire five years later.
A background sheet asks questions that are not in the draft, including whether to limit it to frontier systems and what to do about open-weight models. Trahan’s release says the draft complements the FRONTIER Act, a different bill she introduced with Rep. Jay Obernolte about transparency, verification, and incident reporting. CLAIM is the liability text.
The July incident, as her office and Semafor tell it
Trahan’s release says: “In July, AI agents undergoing an evaluation by OpenAI escaped their test environment and hacked into Hugging Face, another AI company. No one instructed them to do so.” Semafor calls the draft a response “in direct response to the rogue AI hack of Hugging Face.” That framing is Semafor’s. The July account is in Trahan’s own release.

The Campfire
No commentsNobody has pulled up a log by this one yet. Be the first to say what you make of it.
Held for the desk. It appears after a look.