The White House is moving closer to a voluntary framework under which AI companies would submit their most advanced models to the federal government before public release. The White House’s Office of the National Cyber Director reportedly circulated the draft framework by to OpenAI, Anthropic, and Google, and those companies jointly submitted edits. Although the review process details are not yet public, the continued federal interest in pre-release review of frontier AI models follows earlier discussion of a possible FINRA-like watchdog for advanced AI systems. 

For businesses, the key takeaway is that voluntary AI governance is increasingly becoming a practical expectation, even where formal legal mandates remain unsettled. Companies developing, deploying, or procuring AI tools should be prepared to document model governance, risk assessment, testing, security controls, data provenance, privacy considerations, and human oversight in a way that can stand up to regulator, customer, investor, and board scrutiny. Even if the initial federal framework applies most directly to major AI model developers, downstream users should expect those norms to flow through vendor diligence, contract terms, audit rights, procurement questionnaires, and enterprise AI policies.

Business clients should use this moment to get their AI governance house in order: inventory AI systems and vendors, classify higher-risk use cases, update privacy and security reviews for AI-enabled tools, and build clear internal approval processes before rolling out new tools . For companies buying AI products, contracts should address testing, transparency, cybersecurity, data use restrictions, confidentiality, model training rights, regulatory cooperation, incident notice, and responsibility allocation if the tool produces harmful or noncompliant outputs. The practical step now is not to wait for a final federal rule, but to establish a defensible governance record that reflects a thoughtful assessment of risks, sound decision-making processes, and clear oversight and explanations of AI system management.

Photo of Kathryn Rattigan Kathryn Rattigan

Kathryn Rattigan is a member of the Business Litigation Group and the Data Privacy+ Cybersecurity Team. She concentrates her practice on privacy and security compliance under both state and federal regulations and advising clients on website and mobile app privacy and security…

Kathryn Rattigan is a member of the Business Litigation Group and the Data Privacy+ Cybersecurity Team. She concentrates her practice on privacy and security compliance under both state and federal regulations and advising clients on website and mobile app privacy and security compliance. Kathryn helps clients review, revise and implement necessary policies and procedures under the Health Insurance Portability and Accountability Act (HIPAA). She also provides clients with the information needed to effectively and efficiently handle potential and confirmed data breaches while providing insight into federal regulations and requirements for notification and an assessment under state breach notification laws. Prior to joining the firm, Kathryn was an associate at Nixon Peabody. She earned her J.D., cum laude, from Roger Williams University School of Law and her B.A., magna cum laude, from Stonehill College. She is admitted to practice law in Massachusetts and Rhode Island. Read her full rc.com bio here.