Legislative Framework Development
State Senator Carla Whitmore chaired a technology committee that had never passed a major bill. When constituents began demanding rules for the AI systems their agencies were buying, she drafted what she thought was a clean, tough law: it banned "the use of artificial intelligence in any government decision affecting a person's rights." Within a week, the state's own benefits agency pointed out the bill would outlaw the spam filter on their email and the routing software in their call center. The agriculture department noted it would ban the satellite-imagery tool that allocated drought relief. The bill that was supposed to protect people would have frozen the government. Whitmore pulled it before the first hearing and started over, this time asking a different question: not "how do we ban AI," but "which decisions need which safeguards."
Writing law for a fast-moving technology is one of the hardest things a public leader does. Write too broadly and you freeze useful tools. Write too narrowly and the technology outruns you before the ink dries. This lesson is about drafting AI legislation that protects people, survives contact with reality, and can actually pass.
The Central Tension: Specificity Against Durability
Every AI law faces one tension. The more specific the rules, the faster they become obsolete. A statute that names a particular technique or model size will be irrelevant in two years. But the more general the rules, the harder they are to enforce; "AI must be fair" is a sentiment, not a law. A sentiment gives an agency nothing to comply with, gives an enforcer nothing to measure, and gives an affected person nothing to point at when they are harmed.
The resolution that durable technology law uses is to regulate by risk and outcome, not by technique. Do not write rules about neural networks or large language models; those terms will age badly. Write rules about what an AI system does to a person and how much harm it could cause. A system that decides who gets a benefit is regulated tightly regardless of the technique inside it. A system that sorts internal email is regulated lightly. This is the structural insight behind the most influential modern AI laws, including the European Union's risk-tiered approach, and it is the one Whitmore's rewrite adopted. Regulate what the system decides, not how it computes. The technique will change; the stakes for citizens will not.
There is a second reason this framing wins, and it is about who has to read the statute. A rule written around technical characteristics can only be applied by someone who understands the technology, which in most agencies means a small team that is already overloaded. A rule written around consequence can be applied by the programme manager who owns the decision, the counsel who reviews it and the auditor who examines it later, none of whom need to know what is inside the model. Legislation that only experts can interpret produces compliance only where experts happen to be sitting.
Defining Scope Without Freezing the Government
Whitmore's first draft failed on a single word. "Any government decision affecting a person's rights" sounds narrow when you picture a benefits denial and turns out to be enormous when the people who run the government read it literally, because a spam filter affects which correspondence reaches a caseworker and a call routing system affects who reaches a human at all. Broad prohibitions written by people who do not operate the systems reliably catch things nobody intended, and the agencies discover it in the week before a hearing rather than the month after enactment.
Her rewrite covered "systems that make or substantially inform decisions about a person's eligibility, rights, or safety," which captures the high-stakes uses without banning the spam filter. Two things did the work. The scope is defined by the function the system performs rather than the technology inside it, and it is defined by the consequence to a person rather than by the department deploying it. The practical test for any scope clause you draft is to hand it to the three agencies most likely to be caught by it and ask them to list everything they own that it covers. If the list surprises you, the clause is not finished.
The Five Building Blocks of an AI Statute
A workable government-AI law is built from five components. Miss one and the law has a hole that implementation will fall through, usually in the direction of nothing happening at all.
- Scope and definitions. What counts as an "automated decision system," and which uses are covered. Define by function, not technology.
- Risk tiers. A small number of categories, from minimal to high risk, with obligations that scale up. Most laws use three or four tiers. The key is that the obligations are proportionate; nobody fills out an impact assessment for a chatbot that answers parking-hours questions.
- Obligations per tier. The concrete duties. For high-risk systems: a pre-deployment impact assessment, bias testing, a human alternative or appeal, public disclosure that the system is in use, and ongoing monitoring. These mirror what federal guidance already requires of agencies, so a state law that tracks them reduces the number of different tests an agency has to satisfy rather than multiplying them.
- Governance and accountability. Who enforces the law, who reports to whom, and what happens when an agency fails to comply. A law with no enforcer is a press release.
- Transparency and review. Public reporting of where AI is used, and a built-in schedule to revisit the law. A sunset and review clause that forces reexamination on a fixed cycle is how you keep a statute from rotting.
The block drafters skip most often is the fourth, and the reason is political rather than technical. Naming an enforcer means naming who loses discretion, funding a function nobody currently performs, and accepting that some agency in your own state will eventually be found in violation. It is far more comfortable to write a strong duty and leave the question of who checks it for a later bill that never comes. Notice that four of the five blocks describe what agencies must do, and only one describes what happens if they do not. That single block is what separates a statute from a statement.
The third block deserves unpacking, because "obligations per tier" is where a bill either becomes operational or stays abstract. A pre-deployment impact assessment means the agency writes down what the system does, what it could get wrong and who bears the cost, before anyone is affected by it. Bias testing means measuring performance separately by group and retaining the result, which is a different activity from measuring accuracy overall. A human alternative or appeal means an affected person can get out of the automated path and reach someone with authority to change the answer.
The remaining two are the ones that make the first three checkable. Public disclosure that a system is in use gives oversight, the press and affected people something to ask about, and without it nobody outside the agency can tell whether the other obligations were met. Ongoing monitoring means the duties do not expire at launch, which matters because a model retrained on new data is not the system that was assessed. Write each obligation so that a person outside the agency could tell whether it happened. If the only evidence of compliance is the agency's own assurance, the tier is decorative.
Rights Are Only as Strong as Their Remedy
The most common defect in AI bills is not weakness of language. It is a right stated without a path. A bill declares that people affected by high-risk systems have a right to disclosure and a human appeal, and everyone in the room hears a guarantee. What was actually created is a duty on agencies with no answer to three questions: who does an affected person complain to, what can that body order, and what happens if the agency does nothing. If the bill does not answer all three, the right exists on paper and the person is in exactly the position they were in before.
Draft the remedy alongside the right, in the same section, in concrete terms. Name the body that receives complaints. State what it can require: production of records, suspension of use, correction of the individual decision. State the reporting that makes non-compliance visible, because a duty nobody can observe is a duty nobody enforces. This is unglamorous drafting and it is the difference between a law that changes agency behaviour and a law that agencies read once and file.
Committee Structure: Where Bills Live or Die
A good bill dies in the wrong committee. AI cuts across technology, privacy, civil rights, procurement, and budget, so jurisdiction is genuinely contested. Whitmore learned that the technology committee alone could not carry the bill; the civil rights members wanted bias provisions, and the budget committee controlled whether agencies got money to comply. Neither of those was an obstacle to route around. Each was a constituency whose absence would have produced a law that could not function.
The practical move is to map committee jurisdiction early and build the coalition the bill needs to survive each stop. Identify which committees must approve the bill, who chairs them, and what each cares about. Then shape the bill so that each committee sees its priority reflected. Done well this is not dilution; it is the difference between a bill that clears one committee and one that becomes law. Done carelessly it is exactly dilution, which is why you decide in advance which provisions are the floor you will not trade. For most AI bills that floor is the scope clause, the enforcement block, and the appeal right, because a law that loses any of the three stops doing anything.
The budget committee is the stop drafters most often treat as a formality, and it is the one that decides whether the law functions. Compliance costs money in a form that is easy to overlook: staff time to inventory systems, testing that small agencies cannot perform in house, a support office, and an enforcer's operating budget. A bill that arrives at that committee with duties fully specified and costs unestimated invites the committee to solve the problem by weakening the duties. Arriving with a costed implementation plan converts the same conversation into a negotiation about phasing, which is a conversation you can win.
Building Bipartisan Support
AI legislation has an unusual advantage: the core concerns are shared across the political spectrum, even when the language differs. One side frames it as protecting civil rights and preventing discrimination. The other frames it as preventing government overreach and protecting individual liberty from unaccountable systems. These are the same safeguards described in different vocabularies, and a drafter who hears them as two different demands will build two different bills and pass neither.
Whitmore's bill found bipartisan footing on three planks that both sides could claim as their own: a person's right to know when an automated system was used on them, a right to a human appeal, and a requirement that government be able to explain its own decisions. Framed as transparency and accountability rather than as "regulating AI," the bill drew co-sponsors from both parties. The lesson is to lead with the safeguards everyone wants and let each side describe them in its own terms. It also helps that all three planks are about what government owes the governed, which is a far easier argument in a legislature than one about what technology should be permitted to exist.
Those three planks are durable for a reason worth naming, because it tells you what else will hold. Each of them is a duty the government already owes when a human makes the same decision. Telling a person a decision was made about them, letting them appeal it to someone with authority, and being able to state the reason are not new obligations invented for AI; they are existing expectations of government restated for a case where the technology made them easy to skip. Provisions framed that way are hard to argue against without arguing that automation should carry fewer obligations than a clerk.
Implementation Planning: The Part Most Bills Forget
A law that agencies cannot implement is worse than no law; it breeds quiet noncompliance that erodes the rule of law. Whitmore's first draft would have taken effect in ninety days, which was impossible. Agencies did not yet know what systems they had, let alone whether those systems met obligations nobody had written procedures for. A deadline that cannot be met teaches every agency in the state that this statute's deadlines are decorative, and that lesson is very hard to unteach in the next bill.
The rewrite phased it. Definitions and disclosure came first, impact assessments for new systems next, and existing systems within two years. It also funded a central support office to help small agencies that had no AI expertise, and it required agencies to inventory their existing systems before any deadline applied, because an obligation to assess systems you have not yet identified is an obligation to guess. An unfunded mandate with an impossible deadline is how good intentions become dead letters, and the cost of the support office is nearly always smaller than the cost of a statewide compliance failure that arrives two years later as a scandal.
Sequencing is the underrated craft here. Every obligation in an AI statute depends on something else being true first, and a bill that ignores those dependencies produces deadlines that cannot be met in the order they are written. You cannot assess systems you have not identified, so the inventory precedes assessment. You cannot test for disparate impact without deciding what data you are permitted to use to do it, so that question is resolved before the testing duty bites. You cannot appeal to a human in an office that has not been funded. Lay the obligations out as a dependency chain and the phasing writes itself.
Phasing also gives you something politically useful: an early deliverable that is visible and cheap. Disclosure and the inventory can land in the first phase because they require agencies to describe what they already do rather than to change it. That produces a public artifact within the first cycle, which sustains support for the harder obligations that follow. A statute whose first visible result arrives three years after enactment will spend those three years being described as having accomplished nothing, and in a legislature that description eventually becomes the fact.
AI Legislation Drafting Checklist
Use this checklist to pressure-test any AI bill before it goes to committee. Each item that is missing or weak is a place the law will fail in the field. A bill that passes every item is a bill worth advancing; it is not yet a bill that works, because that is decided by how agencies and the enforcer behave once it is in force.
- Defined by function, not technique. Scope language describes what systems do, so it survives the next wave of technology.
- Proportionate risk tiers. Obligations scale with potential harm; low-risk uses are not buried in paperwork.
- Human alternative with a route to enforce it. People affected by high-risk systems have a right to disclosure and a human appeal, and the bill names who hears the complaint and what they can order.
- Explainability required. Agencies must be able to state the reason for a consequential automated decision in plain language.
- Bias testing mandated. High-risk systems require pre-deployment and recurring testing for disparate impact, with retained results.
- Named enforcer with teeth. The law specifies who enforces it and what the consequences of noncompliance are.
- Aligned with federal guidance. Obligations track existing federal frameworks so agencies face one coherent set of duties, and the bill states plainly what happens where the two diverge.
- Phased, funded implementation. Realistic timelines, funding for compliance, and support for under-resourced agencies.
- Public AI inventory. Agencies must publish where they use covered systems, so oversight has something to look at.
- Sunset and review clause. The law is scheduled for reexamination on a fixed cycle so it can keep pace with the technology.
Anti-Patterns to Avoid
- The ban that freezes the government. A prohibition drafted without operators in the room catches the spam filter, the call router and the imagery tool. Before any scope clause is final, have the agencies most affected list what it covers.
- The right with no remedy. Declaring that people have a right to appeal, without naming who hears the appeal, what they can order and what follows non-compliance, creates a duty that nobody can invoke. Draft the remedy in the same section as the right.
- Naming the technology. A statute that regulates a named technique dates on the day a different technique does the same job. Regulate the decision and the consequence.
- The unfunded mandate. Obligations with no money and no support office produce quiet noncompliance, which is more corrosive than open opposition because nobody has to defend it.
- The impossible first deadline. A date agencies demonstrably cannot meet trains everyone that this statute's dates are decorative, and the lesson carries to the next bill.
- Assuming alignment equals equivalence. Tracking federal language reduces duplicated effort. It does not merge two legal regimes, and a bill that leaves the divergence unaddressed hands the question to whoever is least equipped to answer it.
- Trading the floor for the vote. Shaping a bill so each committee sees its priority is coalition-building. Conceding the scope clause, the enforcement block or the appeal right is not, because a law missing any of the three has stopped doing anything.
Practice Prompts
- Take a scope clause from a real or draft AI bill and hand it to the three agencies most likely to be covered. Ask each to list every system it captures. Compare the lists to what the drafter intended.
- Write the enforcement block for a bill that currently has none. Name the body, the powers it holds, the reporting that makes non-compliance visible, and what happens when an agency ignores it.
- Rewrite a technology-specific provision so that it regulates the decision and the consequence instead. Then check whether the rewrite still covers the case the original was aimed at.
- Map the committee path for an AI bill in your own legislature. For each stop, name the chair and the one provision that committee will care most about.
- Draft the three planks you would lead with to build support across the aisle, and write each one twice, once in the vocabulary of civil rights and once in the vocabulary of limiting government power.
- Build a phased implementation schedule for a bill you support, starting from the inventory that has to exist before any assessment obligation makes sense. Cost the support office.
Reflection
Think about a law in your jurisdiction that agencies technically comply with and nobody believes in. What is missing from it? In most cases the answer is not the strength of the duty but the absence of a consequence, a budget or a body whose job it is to notice. Ask whether the AI bill you are working on has the same shape, and be honest about whether that is an oversight or a compromise somebody made deliberately.
Then consider the timing question, which is the hardest one in technology law. Legislating early risks writing rules for a technology you do not yet understand. Legislating late means the practices harden first and the statute ratifies them. There is no correct answer, only a choice about which risk you would rather explain afterwards. What would make you comfortable moving now, and what would you build into the bill so that being wrong is recoverable?
Glossary
- Automated decision system. The functional term legislation uses for a system that makes or substantially informs a decision about a person, defined by what it does rather than by the technology inside it.
- Risk tier. A category in a statute that groups covered uses by potential harm, with obligations that scale up as the tier rises.
- Proportionality. The drafting principle that obligations should match the stakes, so that high-risk uses carry heavy duties and trivial ones carry almost none.
- Human alternative. A right belonging to an affected person to decline the automated path and have a person handle the matter.
- Sunset and review clause. A provision scheduling a statute for reexamination on a fixed cycle so it can be updated as the technology moves.
- Unfunded mandate. An obligation imposed without the resources to meet it, which typically produces quiet noncompliance rather than open refusal.
- Committee jurisdiction. The set of committees entitled to consider a bill, which determines the path it must survive and the constituencies it must satisfy.
- Enforcement block. The part of a statute naming who enforces it, what powers they hold, and what follows non-compliance.
Related Lessons
- AI Regulatory Design covers the regulatory architecture that sits underneath a statute once it passes.
- Writing Policy Papers and Legislative Proposals covers the drafting and advocacy craft in detail.
- Multi-Level Government AI Governance covers how federal, state and local obligations interact.
- State and Local Government AI Policy covers the subnational policy landscape a state bill enters.
- AI Policy Monitoring and Enforcement covers making the enforcement block work after enactment.
- Judicial and Legal Implications covers how courts test the systems your statute governs.
- Public Consultation on AI Policy covers bringing affected people into the drafting rather than the hearing.
- International Standards: EU AI Act and OECD covers the risk-tiered models that influenced this approach.
Closing
Whitmore's second bill was less dramatic than her first and considerably more useful. It did not ban anything. It defined which decisions carried enough weight to deserve safeguards, attached proportionate duties to those, named who would enforce them, funded the agencies expected to comply, and scheduled its own reexamination. None of that makes a good headline. All of it makes a law that still works in five years.
That is the trade a legislator makes in this field. The bill that sounds toughest on the day it is filed is usually the one that gets pulled, amended into nothing, or passed and then ignored. The bill that survives is the one written with the operators, the enforcer and the next legislature all in mind. Write for the world in which your law has to function, not for the press release announcing it.
Key Takeaways
- Regulate the decision, not the technique. Laws that name technologies age out fast; laws that govern what a system does to a person endure.
- Build from the five blocks. Scope, risk tiers, tiered obligations, governance, and transparency with review; a missing block is a hole implementation falls through.
- Test your scope clause against real operators. A prohibition that reads narrowly to a drafter can catch the spam filter, the call router and the imagery tool that allocates drought relief.
- A right without a remedy is not a right. Name who hears the complaint, what they can order, and what follows non-compliance, in the same section that creates the duty.
- Proportionality keeps a law alive. Tight rules for high-stakes systems and light rules for trivial ones prevent both citizen harm and government paralysis.
- Committee jurisdiction is strategy. Map which committees must clear the bill and reflect each one's priority, while deciding in advance which provisions are the floor you will not trade.
- Lead with shared safeguards. The right to know, the right to a human appeal, and the duty to explain draw support across the aisle when framed as transparency and accountability.
- Implementation is part of the law. Phased timelines, funding, an inventory before any assessment deadline, and support for small agencies turn intentions into compliance.
- Build in your own expiration date. A sunset and review clause forces the law to keep pace with a technology that will not hold still.
Frequently Asked Questions
How many risk tiers should a bill have?
Most laws use three or four, and the number matters far less than whether the boundaries are legible to the people who must apply them. A tier structure works when an agency programme manager can read the statute and place their own system without calling counsel. If placement is genuinely contested for common cases, you have either too many tiers or definitions that describe technology instead of consequence.
Should a state law simply copy federal guidance?
Tracking federal obligations is usually right, because it means agencies face one coherent set of duties rather than two overlapping ones, and it lets state agencies reuse federal templates. But alignment is not equivalence. Federal guidance can change without your legislature acting, and the two regimes will diverge somewhere. Say in the bill what happens when they do, rather than leaving the question to whoever is least equipped to answer it.
What if we cannot get an enforcement provision through?
Then be clear internally about what you have passed. A bill with duties and no enforcer creates obligations that conscientious agencies will meet and others will not, with no mechanism to tell the difference. That is sometimes still worth doing as a first step, particularly if it establishes the inventory and the definitions. What it is not is a law that protects anyone, and describing it that way in public makes the follow-up bill harder to argue for.
How do we keep the law from being obsolete in two years?
Two provisions do most of the work. Defining scope by function and consequence rather than by technique means a new technology doing the same job is already covered. A sunset and review clause forces the legislature to look again on a schedule instead of waiting for a failure to force it. Neither eliminates the problem; together they make being wrong recoverable rather than permanent.
Is a public AI inventory worth the burden it creates?
It is usually the highest-value provision per page in the bill, because everything else depends on it. Impact assessments, bias testing and enforcement all presuppose that someone knows which systems exist, and in most jurisdictions nobody currently does. Requiring the inventory first, before any assessment deadline applies, converts an impossible obligation into a sequenced one and gives oversight something concrete to examine.
How long should implementation take?
Longer than the first draft assumes. Whitmore's ninety days were impossible because agencies did not yet know what they owned. Her rewrite put definitions and disclosure first, then impact assessments for new systems, then existing systems within two years. Whatever schedule you choose, sequence it so that each obligation lands after the thing it depends on exists, and fund the support that under-resourced agencies will need to meet it.
Skill.re