With new AI models continuing to push the technological frontier ever further, and with data center investments growing ever larger, recent public discussions have pondered how to preserve safety and national security amid the rapid developments. Looking ahead to the future of managing the industry in the United States, new ideas have recently emerged from the industry itself, the Executive Branch, and the U.S. Congress.
On July 21, 2026, Senator Mark Warner (D-VA) unveiled “A Framework for America’s AI Future,” a package of legislative proposals addressing AI infrastructure, competition and safety, workforce issues, and national security.
Two proposals in the package are outlined below. Together, they would impose the first federal mandate for pre-release access to frontier AI models and a new tax, disclosure, and enforcement regime for the data centers that support AI development. Both proposals carry compliance and contractual consequences for developers, data center operators, utilities, lenders, and federal contractors.
Broader Considerations Underway
The Warner package arrives at a moment of increased policy focus on AI governance. In early June, the White House issued Executive Order 14409, Promoting Advanced Artificial Intelligence Innovation and Security, establishing voluntary pre-release testing arrangements with frontier AI developers, inviting companies to provide covered models for cybersecurity review ahead of public release. On the House side, Representatives Lori Trahan (D-MA) and Jay Obernolte (R-CA) have advanced bipartisan proposals focused on AI transparency and safety standards. Industry participants have also weighed in, with leading AI companies proposing the creation of a self-regulatory organization modeled on the Financial Industry Regulatory Authority (“FINRA”) that would oversee safety standards for frontier AI development. Reports indicate that Treasury Secretary Scott Bessent has engaged with industry stakeholders on the FINRA-style model, suggesting the Executive Branch is actively considering self-regulatory approaches alongside its current voluntary framework. Against this backdrop, the Warner package is a legislative effort that would impose mandatory federal oversight of frontier AI models and the data center infrastructure that supports them.
Mandatory Access to Frontier Models
The package’s central governance proposal may be the Secure Artificial Intelligence Development Act of 2026 (“Secure AI Act”), S.5061, which would require providers of covered “frontier artificial intelligence models” to give the National Security Agency (“NSA”) access at least 21 calendar days before introducing a model into interstate or foreign commerce. That requirement contrasts with the White House’s Executive Order 14409, which established a voluntary framework under which companies may provide covered frontier models for cybersecurity testing up to 30 days before planned release. It is possible, however, that the Executive Branch may in the future impose some form of pre-launch review.
Warner’s Secure AI Act would mandate federal access to covered frontier models but would not require government approval before release or compel a provider to implement mitigations identified through testing. Instead, the NSA Director would “share relevant guidance” to “inform voluntary vendor actions” addressing potential security threats—creating, in effect, a mandatory checkpoint without a formal licensing regime.
The bill defines a frontier model by capability rather than a fixed compute threshold: a model, or system combining models, would be covered if it “exhibits or could be modified to exhibit” high performance on tasks posing serious risks to national security, national economic security, or public health or safety. A National Institute of Standards and Technology (“NIST”)-based Artificial Intelligence Risk Board (“Board”) would develop and periodically reassess the technical evaluations used to apply that standard.
Providers of covered models would have to make available the model weights, configuration files, runtimes, and software libraries needed to operate the model. The bill does not make release contingent on completion of NSA testing, specify what happens if testing is not completed within the 21-day period, establish a process for resolving disagreements over test results, or explain how submitting companies would participate in any classified review.
Separately, the bill would require NIST to establish a public registry of frontier models, with providers required to register before introducing a covered model into commerce. Failure to provide NSA the required access could result in a fine of not less than $100,000 per day while the model remains available without the guidance generated through the testing process. As the bill is currently drafted, before commencing enforcement, the Attorney General would have to provide notice and a seven-day window to come into compliance.
Data Centers: Tax Eligibility, Public Disclosure, and Enforcement
Turning to infrastructure, the Data Center Tax Accountability and Disclosure Act of 2026 (the “Data Center Act”), S.5054, would impose disclosure requirements and targets tax breaks for certain data centers.
First, the bill would impose disclosure requirements on “covered data centers”—defined as facilities with power demand of 25 megawatts or more, regardless of whether they are used for AI—to disclose key operational information to the Department of Energy (“DOE”) and the Environmental Protection Agency (“EPA”). New covered facilities would submit estimates of water usage, electricity usage, backup power, and property setback1Section (3)(c)(1)-(4) prescribes the initial disclosures required including: total number of gallons of water withdrawn or consumed each month, source of the water, annual average water usage effectiveness, water rights or permits, total electricity contracted for or consumed, whether the data center uses behind-the-meter power generation, total greenhouse gas emissions, annual average power usage effectiveness, long-term power purchase agreements, types of backup power maintained, backup capacity, fuel stored on-site, hours of backup power used, backup power emissions, and property setback requirements. no later than 180 days before operations; existing facilities would make an initial disclosure within 180 days of enactment and then submit annual reports covering water and electricity usage, power and water arrangements, backup generation, and certain land-use information, which DOE and EPA would be required to publish annually on their respective websites. This means that detailed operational information of large data centers would become a matter of public record.
The associated enforcement provisions would carry substantial penalties: negligent reporting failures could result in penalties of up to $50,000 per day, while knowing failures or materially misleading reports could reach $100,000 per day. The bill also would void nondisclosure and confidentiality provisions restricting required disclosures, render conflicting clauses unenforceable, and preempt contrary state contract law—provisions that could affect utilities, water authorities, landlords, and other counterparties possessing information required for reporting.
The current draft of the bill leaves the federal enforcement authority unspecified. It allows states to elect to receive companies’ disclosures directly, to issue related information requests, and to impose fines and other enforcement measures themselves, consistent with state law. But it does not identify a particular federal regulator that would assess or collect the civil penalties in states that do not elect to undertake this enforcement authority themselves. If states become the primary enforcers of the bill’s reporting requirements, data center operators could face varying state-level regulatory approaches, as state attorneys general may differ in how strictly they enforce the bill’s provisions.
Second, to incentivize sustainable construction, the bill addresses the economics of AI data center development by conditioning bonus depreciation on green-building certification. While the disclosure provisions apply broadly to large data centers generally, the bill’s tax provisions focus on AI facilities specifically. The bill would generally deny bonus tax-purposes depreciation for property used in an “AI data center” unless the facility obtained LEED Gold or Platinum certification, or else met an approved equivalent standard. Bonus depreciation allows businesses to immediately deduct a large portion of the cost of certain qualifying assets in the year they are placed in service, rather than spreading those deductions over many years. Denying this accelerated tax write-off would increase the up-front cost of building or equipping such facilities. An AI data center would include a qualifying facility with at least one graphics processing unit if at least 20 percent of the facility is used to develop or operate AI. The bill does not define the calculation of this 20 percent figure. It provides only that an “AI data center” is a qualifying structure or group of structures “at least 20 percent of which is used for developing or operating artificial intelligence.” This may leave developers and operators of data centers uncertain about the methodology for calculating the percentage of a facility used for AI, impacting the application of the bill’s bonus depreciation exception.
Potential Downstream Implications
Even though Warner’s bills have just been introduced and only a few months remain in the current Congress, there are points that companies may consider from this framework, which appears intended to drive momentum on these key issues.
Frontier-model release planning. Developers approaching the frontier-model threshold may want to start to build in the concept of a federal-access period to the process of pre-launch check. Should such a review requirement come into force, companies will need to be ready to document the basis for coverage determinations and be prepared for secure transfer of sensitive model assets. Because the NIST Board’s capability evaluations could change over time and the classified-review process remains undefined, developers may benefit from treating technical assessment, legal classification, and federal engagement as a coordinated, iterative process rather than a one-time pre-release step.
Data center development and contracting. Developers and operators may wish to analyze separately whether a facility falls within the tax provision, the disclosure regime, or both. The proposed reporting calendar would move compliance into the development phase, requiring parties to identify who controls the relevant utility, water, backup-generation, and land-use data and to allocate reporting responsibilities in project agreements. LEED certification could become a material project-tax assumption, and public reporting combined with the limits on confidentiality may warrant express disclosure carveouts in utility agreements, leases, development agreements, and financing documents.
The reporting regime also carries substantial penalty exposure. Because civil penalties accrue per day of noncompliance, a single missed or defective disclosure could generate substantial exposure before it is cured. The negligence standard is notable given that the initial disclosure requires forward-looking estimates of first-year water, electricity, emissions, and related information, and that both tiers cover reports that are “materially misleading” as well as inaccurate.
Conclusion
Warner’s bills remain legislative proposals and would likely be subject to significant debate and potential revision before moving through Congress. And with just a few months remaining in the current Congress, the bills are unlikely to be passed in their current form before the end of this session.
Still, the package represents a shift. The Administration has so far pursued voluntary pre-release engagement, while Warner’s bills would require federal access to new frontier models. The bills also propose imposing new tax, disclosure, and contracting requirements for data centers—issues that may carry over as a focus for Congress in 2027. Companies developing advanced models, operating or financing data centers, or supplying AI-related products and services to the federal government may wish to assess the potential effects on future model releases and data center investments. We will continue to monitor related developments.