Congress should require independent evidence for AI models through the procurement process.
President Donald J. Trump postponed a planned artificial intelligence (AI) executive order on May 21, and signed one on June 2. The order that emerged declined to create the licensing regime that OpenAI’s Sam Altman had urged the Senate in 2023 to create—a federal agency empowered to license powerful models before release—and that Gary Marcus, testifying beside him, wanted modeled on the Food and Drug Administration. It chose a voluntary federal review of advanced AI models before public release instead. The useful lesson is about instrument choice. National Economic Council director Kevin Hassett framed the Administration’s thinking about AI as akin to releasing models “in the wild after they’ve been proven safe, just like an FDA drug.” Pre-market approval is the wrong tool. A procurement condition is the right one.
The pharmaceutical analogy fails for two reasons. The first is technical. A drug is a fixed compound tested within a defined population before approval. A “frontier model”—a cutting-edege, general-purpose AI model—however, is not fixed. Its capabilities shift with fine-tuning and updates, its attack surface, or the set of points an attacker can reach, expands when it is connected to external tools and agents, and its hazards vary with the user and the deployment context. A one-time regulatory clearance would be a certification of a system that looks altogether different by the time of use.
The second reason that the analogy fails is constitutional. Conditioning the public release of a general-purpose AI system that generates text and code on prior government clearance implicates the prior restraint doctrine, which calls for a heavy presumption against the validity of ex ante government restrictions on expression. Drug licensing raises no comparable problem because a pill is not a form of expression. An approval regime for AI models would have to survive constitutional scrutiny that a licensing regime for drugs never faces.
There is an existing alternative that avoids both problems. The Federal Risk and Authorization Management Program (FedRAMP), codified in 2022, conditions the awarding of federal agency contracts on an independent assessment of security controls against a defined baseline. A vendor without an authorization is not barred from the commercial market, but it is excluded from the federal one until it passes that assessment. I lead FedRAMP compliance strategy for a managed services platform. The model works because the government acts as a purchaser rather than a regulator of primary conduct. A vendor stays free to sell commercially without an authorization and is ineligible only for federal contracts, until its product is approved, so the condition does not restrict public release or commercial sale and avoids the constitutional problem that licensing creates.
The authorization also benefits from being continuous, rather than a one-time approval. FedRAMP requires continuous monitoring: monthly vulnerability scans and plan-of-action reporting, an annual independent assessment, and re-authorization when a system makes a significant change. The standard tracks a system as it evolves—appropriate for a frontier model’s needs, since its capabilities shift after release. FedRAMP tests whether a cloud system is secure. It does not test whether the model inside that system is dangerous. A service hosting a frontier model may need FedRAMP authorization today, yet that authorization does not ask whether the model can materially assist a cyberattack, the synthesis of a pathogen, or another high-consequence misuse. The proposal borrows FedRAMP’s mechanism and aims it at that gap: independent evidence about the safety of the model, not only the security of the system.
That structure transfers to frontier AI. The U.S. Congress should condition the federal acquisition of high-risk AI models on independent evidence of the model’s safety. Public release would remain a company decision, governed by the consumer protection, privacy, security, and tort law that already applies. Federal adoption, however would require more. Federal agencies and defense contractors should not use a model that can materially assist autonomous cyber operations, biological or chemical weapons development, large-scale fraud, or military targeting based on a company’s own representations, alone.
A procurement condition is an exercise of the spending power, and the relevant limit is the unconstitutional-conditions doctrine. In Rust v. Sullivan, the U.S. Supreme Court distinguished procurement conditions that merely define a federal program from conditions that leverage federal funds to control conduct outside of that program. A condition requiring an independent safety assessment would stay on the program-defining side if it were drafted with discipline. It must test whether a model that the government would adopt has been independently evaluated for the capabilities relevant to that use, and it must not reach the developer’s unrelated speech, corporate structure, or commercial conduct. Drafted in this way, it would regulate the federal purchasing relationship, not the expressive act of releasing a model.
Procurement conditions are implemented through the Federal Acquisition Regulation, which means that the substantive rule would proceed through notice-and-comment rulemaking than bypassing it. The contours of “covered models”—the high-capability systems Congress would designate by capability threshold as eligible for government contracts—the evidentiary standard, and any waiver process by which an agency could procure a model that lacks full authorization, would be built on a public record and remain reviewable. That is a feature of the procurement route, not an evasion of administrative law.
The statutes that empower federal agencies matter more after the Supreme Court’s decision in Loper Bright Enterprises v. Raimondo, under which courts will no longer defer to an agency’s reasonable reading of an ambiguous statute. Congress would therefore need to specify the elements of a federal procurement condition for covered AI systems: define what models the regulation covers based on capability thresholds, state what information an AI developer must address in the evidence provided for federal use, place the Center for AI Standards and Innovation, the National Institute of Standards and Technology body that already runs voluntary frontier-model evaluations, in statute as a national-security test range directed to publish its evaluation methodology, test categories, and evidentiary criteria, so that the public record shows what the government tests for and how, and instruct the Federal Acquisition Regulation Council to implement the proposed procurement condition. Specificity would protect this proposed scheme from concerns that an agency is encroaching upon Congress’s legislative authority.
A co-founder of the defense software company Palantir, Joe Lonsdale, warned that an FDA-style regime would entrench dominant companies able to absorb the costs of bespoke review for each new AI model. The procurement model resists that outcome only if the statute requires the Center to publish its methodology for review, mandates no-cost evaluation options for small developers and open-weight projects, whose trained model parameters are published for anyone to download and run, and bars the creation of review channels available only to the largest firms.
The need for such a program is not hypothetical. The U.S. Department of Defense designated the AI developer Anthropic a supply chain risk this year, a label once reserved for foreign adversaries, after negotiations over its safety guardrails collapsed. The Center for AI Standards and Innovation has completed more than 40 frontier-model evaluations but under voluntary agreements, and the new order sets the threshold for a covered model through a classified process the public cannot see. Federal trust in frontier AI developers is currently granted and withdrawn by discretion. A statutory release-evidence condition would replace that discretion with a reviewable, evidence-based standard. The signed order chose voluntary review over a license. That instinct was right, but the mechanism was wrong. A framework that a developer can decline, with no criteria yet for who qualifies as a trusted partner, leaves federal trust in the gift of whoever holds office. The instrument that fixes that should be procurement, not an honor system.

Aashis Luitel leads a federal compliance program for a managed services platform.