Trump's AI Framework Is Creating the Patchwork It Was Designed to Prevent
The Trump administration’s National Policy Framework for AI, released March 20, was explicitly engineered to prevent a “patchwork” of state regulations by asserting federal primacy. Six weeks on, it is producing the opposite outcome.
Analysis from the Bloomsbury Intelligence and Security Institute identifies the framework’s structural flaw: it contains no binding obligations and no enforcement mechanisms. Every substantive directive is framed as what “Congress should” do — not what federal law requires. Without enabling legislation, the pre-emption claim has no legal force to back it.
States Are Moving Anyway
The vacuum is being filled at the state level. Several legislatures are accelerating their own AI bills, reading the federal framework as evidence that coherent national action will be slow or incomplete. The irony is sharp: the framework intended to reduce regulatory complexity, but its lack of legal teeth has given states no reason to pause their own processes.
New York’s RAISE Act, finalised earlier this year with 72-hour incident windows and $1 million penalties effective January 2027, was passed before the framework. More state laws are in committee now. The result is the fragmented legal environment the framework was supposed to eliminate — except companies now face it without the clarity of a single federal standard.
The Regulatory Capture Risk
The BISI analysis flags a second concern: regulatory capture. The framework’s emphasis on removing “unnecessary barriers” and industry-led governance, without binding oversight requirements, creates conditions in which large AI developers effectively shape the rules applied to them. The parallel to pre-2008 financial services self-regulation is explicit in the analysis.
The largest AI labs have every incentive to support weak federal pre-emption: a national standard with no teeth keeps states at bay while imposing minimal compliance costs. Smaller developers and downstream deployers bear more of the uncertainty cost, since they lack the legal resources to navigate a contested federal-state landscape.
Practical Implications for Companies
For legal and compliance teams, the core conclusion is blunt: do not assume federal pre-emption. The framework is a policy statement, not a legal shield. Organisations with AI deployments across multiple US states need to track state-level legislation independently, because the federal framework will not pre-empt it until Congress passes binding law — and there is no clear legislative timeline for that.
The conflicts between the framework’s pre-emption intent and active state legislation are likely to be litigated. Outcomes are not predetermined. In the interim, the “patchwork” the framework warned against is already being woven — stitch by stitch, state by state.