In Three Days, Two AI Bills: The Compliance Calendar Has Started

Here is what happened. In three days, the United States Congress moved on two AI bills. On August 24, the AI Advertising Disclosure Act. On August 27, the Open-Source AI Leadership Act. Both are House bills. Both are early-stage. Neither is law yet. The signal is not the bills. The signal is the pace.

Fast recap of the last 72 hours of federal AI law: disclosure on one track, open-source support on another. They look like opposites. They are not. Both are the same move — turning AI policy from statements into rules.

The disclosure bill, quickly

H.R.10146. Sponsored by Representatives Magaziner and Norton. The core requirement: when an AI tool’s output is shaped by a commercial arrangement, the tool must say so. Sponsorship must be disclosed. A register of commercial arrangements must exist. Users must be able to look it up. Enforcement sits with the FTC. Violations are handled under the FTC Act.

Let me think about what that does in practice. An AI assistant that recommends products — if the recommendation is paid, that is now a sponsorship, on the record. Think of influencer disclosure rules, applied to software. The logic is the same. The consumer has a right to know who is steering the answer.

This matters more than it looks. Most AI advertising today is invisible. The model returns an answer. No tag. No label. No way to know the answer was bought. This bill makes that commercial relationship a legal disclosure. The sponsored answer, in short, stops being a secret.

There is a design detail worth noticing. The bill requires the arrangement register to be user-queryable. That is not a footnote. It means the disclosure is not a one-time press release. It is an ongoing, inspectable record. Anyone — a journalist, a competitor, a regulator — can check who is paying for which AI answers. For an industry built on convenient opacity, that is the most uncomfortable clause in the bill.

The open-source bill, quickly

H.R.10152. Sponsored by Representative Evans. Filed three days later. The core requirement: the Commerce Department must support adoption of qualified open models. It must also assess risks from “foreign adversary models”. And it must publish reports, periodically.

I will admit the phrase “foreign adversary models” catches my attention first. That is a security frame, not a market frame. The bill is doing two jobs at once. One hand helps open models. The other watches foreign ones. In short: support and surveillance, in one package.

Let me walk through what “qualified” might mean, because that single word will decide everything. Qualified open models — qualified by whom, against what standard? The answer is not in the bill’s summary; it will be written in the Commerce rulemaking that follows. That is the quiet pattern of every technology bill: the fight is never in the title, it is in the definition. The definition of “qualified” is where the lobbying will land.

The bigger pattern under the noise

Step back from the two bills. They are not random. They are arriving in sequence, and they are arriving from both chambers.

The FRONTIER Act — H.R.9925 — keeps advancing. That one targets the biggest developers. Federal transparency. Incident reporting. Risk management. Independent evaluations. That is the heavy track, built for frontier-scale systems, and it is the bill most likely to reshape how the largest labs operate.

The Senate Commerce Committee moved more bills out in early August. The Child AI Toy Safety Act. The CHATBOT Act. The Teen AI Privacy Act. Different topics. Same direction. Safety rules for products that touch children and teens — toys that talk, chatbots that converse, platforms that collect adolescent data.

Add them up. Disclosure for advertising. Support and risk-review for open models. Safety for toys. Privacy for teens. Transparency for frontier models. That is not a grab bag. That is a rulebook being assembled, piece by piece, across jurisdictions and across product categories.

Why this week matters

For two years, United States federal AI law was mostly speeches. Committees held hearings. Members gave statements. Little became binding. The industry heard the same word at every conference: principles. The subtext was always the same: watch this space, but don’t change anything yet.

This week changes the texture. Bills with actual enforcement mechanisms are moving. The FTC is named as an enforcer. Registers must be built. Reports must be filed. Definitions must be written. These are not aspirational clauses. They are operational ones, and operational clauses are what turn a policy debate into a compliance budget line.

Let me correct myself on one point before I overclaim. None of these bills are law. Committee passage is not floor passage. Floor passage is not the president’s signature. The legislative runway is long, and every bill can still die quietly in the next session. I am not forecasting the outcome. I am describing the direction of travel.

The direction is clear, though. The center of gravity in AI policy has shifted from “should we regulate” to “how do we write the rule”. That shift is the real news, and it happened inside a ten-day window.

What the compliance clock looks like

Assume for a moment the bills move at the typical pace of federal legislation. That still means two things for companies today. First, the audit starts now: map every place where a commercial arrangement can influence an AI output, because that is exactly the list a future disclosure register will reproduce. Second, the design decisions get made now: the choice between proprietary and open models is about to acquire a regulatory dimension, and that dimension is shaped by how “qualified” and “adversary” end up being defined.

The cost side is worth stating plainly. Every disclosure register needs a system behind it. Every definition needs a compliance team to interpret it. Every periodic report needs an owner. None of that is catastrophic, but all of it is overhead that did not exist a year ago. For large labs, the FRONTIER Act’s independent-evaluation requirement is the biggest line item. For mid-size AI vendors, the disclosure machinery is the one that bites first. No time to linger if you want to be ready when the definitions land.

Let me give you the concrete picture, because it is the one I keep coming back to. It is an office with a server rack in the corner, and a compliance officer is building a spreadsheet — not of customers, but of every commercial arrangement that can tilt an AI answer. Rows for sponsored results, rows for paid rankings, a column for which tool they touch. A year ago that spreadsheet would have been a curiosity. If the disclosure bill keeps moving, it becomes the company’s register, and the officer’s job is suddenly regulated. That spreadsheet is the shape the compliance calendar takes when it stops being a headline.

I keep circling back to one observation. These bills are not radical. They are normal. Disclosure, safety, transparency, privacy — these are standard categories in every regulated industry on the planet. Financial firms disclose conflicts. Toymakers meet safety standards. Platforms answer for minors’ data. The surprise is not that AI is getting these rules. The surprise is that it took this long, and that the rules are arriving as a coordinated wave rather than a single law.

One more point on the shape of the wave, because it affects how companies should read it. The bills come from different sponsors, different committees and different chambers, but they share a vocabulary: disclosure, safety, transparency, privacy, evaluation. A shared vocabulary is not an accident. It is the sign of settled direction — the pieces may move at different speeds, but they are moving along the same line. For anyone tracking AI policy, that line is the one to watch, not the individual bills.

What this means for the marketing chain

The disclosure bill is aimed at the whole chain that sits between a brand and a consumer’s screen. Think of the layers. A brand pays an agency. The agency briefs a model provider. The provider tunes the model, or wires in sponsored content, or adjusts ranking. The consumer asks a question and gets an answer that has been quietly commercialized at any of three layers. Under the current system, that answer arrives with no visible trace of the money.

Let me trace the chain in plain terms. The bill makes each layer think twice. The brand must know whether its payment influences output. The agency must document the arrangement. The provider must register it and make it queryable. The consumer must be able to find it. None of that is technically hard. All of it is administratively new. For every company in the chain, the question stops being “could this be read as sponsored” and becomes “how do we record the sponsorship we already have”.

I will add a note on enforcement, because the FTC angle changes the stakes. The FTC already polices disclosure in advertising. It knows how to audit. It knows how to issue penalties. Naming the FTC as the enforcer for AI disclosure is not a symbolic choice — it puts the new rules into an agency that has a track record of actually looking.

The FRONTIER Act, in concrete terms

The open-source and disclosure bills get the headlines. The FRONTIER Act is the one doing the heavy engineering. Federal transparency requirements mean the largest labs would have to open their operations to structured reporting. Incident reporting means a defined obligation to disclose failures, not a discretionary press release. Risk management means documented processes that regulators can inspect. Independent evaluations mean third parties get access — a provision that, if it survives, will change how capability claims are verified.

Let me think about why this one moves slowly. It targets the few players who hold frontier capability. Those players are few enough to fight hard. Every clause in the bill is a negotiation over a specific operational cost, and the cost is concentrated, which means the resistance is concentrated too. The child-safety and privacy bills face lighter resistance because their costs are spread across many smaller companies and because the political optics are harder to oppose. That asymmetry in resistance explains the sequencing: the easy ones move first, the consequential one grinds.

From a compliance standpoint, the lesson is to build for the whole stack now. A company that designs its systems as if disclosure, incident reporting and evaluation are all coming will be ready whichever bill lands first. A company that waits for the text will be rebuilding while its competitors are already compliant.

What’s next

Watch three things. First, committee markups of H.R.10146 and H.R.10152 — that is where the definitions get written, and where the real shape of the rules becomes visible. Second, the Senate’s calendar for the child-safety and teen-privacy bills, which move on a faster track because children’s products attract less political resistance. Third, the FRONTIER Act’s next stop; it is the biggest of the group, it moves the slowest, and it is the one that will determine how the largest developers are governed.

One more signal, and it is the one I keep returning to. The calendar is no longer empty. In ten days, the United States federal government went from discussing AI to filing, advancing and sequencing actual rules. The era of AI policy as a press release is ending. The era of AI policy as a compliance calendar is beginning. What’s next matters more than the headline — and what’s next is the rulebook, not the speeches.