If Congress held hearings the way IT shops open tickets, AI would have a thousand “in progress” items and one closed change: a narrow law about nonconsensual intimate imagery. Everything else is still in committee, which is Capitol Hill’s version of “awaiting CAB approval.”
As of mid-September 2026, with midterms weeks away, that is still the picture. Dramatic testimony. Sparse statute.
What actually became law
Give credit where it is due. The TAKE IT DOWN Act became Public Law 119-12 on May 19, 2025. It criminalizes intentional disclosure of nonconsensual intimate visual depictions—including AI-generated digital forgeries—and requires covered platforms to remove them promptly after notice. That is real, targeted, and enforceable.
It is also not a comprehensive AI safety regime. It does not set training-data rules, model-release gates, energy reporting for training clusters, or liability baselines for frontier systems.
See:
- [Congress.gov: S.146 TAKE IT DOWN Act](https://www.congress.gov/bill/119th-congress/senate-bill/146)
- [GovInfo compiled text of Public Law 119-12](https://www.govinfo.gov/content/pkg/COMPS-18158/pdf/COMPS-18158.pdf)
What is still theater
Reporting in September 2026 describes a familiar deadlock: Senate negotiators discussing risk-mitigation duties and possible federal preemption of some state AI rules; House members pushing bills such as a Frontier Act for audits and catastrophic-risk pauses; leadership eyeing the calendar more than the text. NBC, Reuters, and BBC coverage converge on the same punchline—action before Election Day is unlikely.
- [NBC News: warnings shock Congress, action unlikely before election](https://www.nbcnews.com/politics/congress/warnings-ai-danger-congress-action-unlikely-election-rcna597230)
- [Reuters: Senate negotiators consider major-risk mitigation rules](https://www.reuters.com/legal/litigation/us-senate-negotiators-consider-requiring-ai-firms-mitigate-known-major-risks-2026-09-11/)
- [BBC: AI regulation faces deadlock](https://www.bbc.com/news/articles/ck20989806e9o)
From a systems view, that delay is not neutral. States keep writing their own rules. Enterprises keep guessing which standard will matter in 18 months. Hyperscalers keep expanding GPU campuses under a patchwork of executive orders, export controls, and voluntary commitments. The control plane is fragmented on purpose—or at least by habit.
Election-year physics
I used to tell executives that you cannot freeze production every time someone shouts “risk” in a meeting. You also cannot ignore repeated, documented failure modes. Congress has perfected the worst of both: maximal rhetoric, minimal change control.
Midterm calendars compress voting weeks. Consensus on AI does not exist across parties—or even within them. Some want industrial policy and U.S. lead-at-all-costs. Others want brakes, audits, and liability. Preemption fights pit state attorneys general against federal baseline fans. Add White House executive-order strategies that prefer agency guidance over statutes, and you get hearings as content, not legislation as product.
What IT and security teams should do while Washington stalls
- **Inventory model use like software.** Who uses which foundation models, with what data, under what contracts.
- **Assume multi-jurisdiction rules.** California, Colorado, EU AI Act-style obligations, and sector rules (health, finance, kids) will hit you before a grand federal bargain does.
- **Treat deepfake and abuse reporting as ops.** TAKE IT DOWN is a reminder that content-response SLAs are becoming legal SLAs.
- **Separate safety theater from engineering controls.** Eval suites, red-team results, and access logging beat a PDF of principles.
The dry joke, then the point
Watching CEOs warn about existential risk and then lobby against anything with teeth is like a vendor presenting a disaster-recovery slide while refusing to fund a second site. I have sat through that meeting. The coffee was better than the follow-through.
Voters get soundbites. Operators get uncertainty. Uncertainty has a price: duplicated compliance work, delayed deployments, and brittle ad-hoc controls that fail the week a model jumps a capability notch.
What “delay” costs outside the Beltway
In Mason, Ohio, nobody is waiting on a Senate white paper to decide whether to let ChatGPT draft a status report. They are waiting on clearer rules for:
- whether customer recordings can train a vendor model;
- how long to retain AI-assisted decision logs for audits;
- what counts as acceptable deepfake handling after TAKE IT DOWN;
- whether a “high-risk” label will suddenly apply to a tool already in production.
Every month without a federal baseline pushes that work onto counsel, insurers, and state AGs. That is not agile. That is cost-plus compliance.
I am not romantic about perfect legislation. I am romantic about boring predictability—the same reason change-advisory boards exist. Tell operators the rules, give them a runway, enforce them evenly. Hearings without votes are just expensive stand-ups with better cameras.
Bottom line
Congress can keep booking the apocalypse on C-SPAN. Until it ships a baseline—transparency, incident reporting, liability clarity, or even a narrow high-risk regime—the United States will keep regulating AI the way poorly run shops manage shadow IT: one exception at a time, after the outage.
TAKE IT DOWN proves they can pass something specific when the harm is vivid and the coalition is wide. Comprehensive AI rules need the same clarity of scope. Until then, treat federal AI policy as a backlog item with no sprint date.
Steve Miller — Mason, Ohio. Still waiting for Congress to merge the PR branch into main.
