Sen. Bernie Sanders and Rep. Greg Casar announced a proposal they call the Ban Artificial Superintelligence Act on September 3, 2026. Their published framework would permanently prohibit the development and deployment of what it calls artificial superintelligence, pause advanced AI development while a federal regulator is created, and seek international cooperation. That is a consequential policy position—but it is not yet the same thing as enacted law, or even a bill whose full text can be examined.

That distinction is the best place to begin. The lawmakers' announcement describes forthcoming legislation. Independent reporting likewise said the complete text had not been released at the time. A policy summary can clarify an objective; it cannot answer every question that a statute, agency rule, or court would have to answer.

A person looking over an urban landscape, representing the public scrutiny required for consequential AI policy.

Start with legislative status

Political announcements are often reported with the language of finished legislation. Readers should instead ask four straightforward questions: Is there a bill number? Is complete legislative text public? Which committees have jurisdiction? Has any companion measure attracted additional sponsors? Until those answers are available, the responsible description is a proposed framework, not a federal ban that companies must already follow.

This is more than procedural nitpicking. The framework uses powerful terms such as “advanced AI development,” “superintelligent AI,” and a new Cabinet-level regulator. Each term could cover very different activities depending on definitions, exceptions, timing, and enforcement. A short release cannot establish whether a rule would apply to a training run, model fine-tuning, agentic software built around an existing model, open research, or a deployed enterprise service.

The lawmakers' own release summary supplies a useful starting point. It describes artificial superintelligence as a system that matches or exceeds human cognitive performance across a broad range of domains, or one that can plan and execute humanity's disempowerment. It also lists concerning capabilities, including subverting shutdown commands. Those are policy concepts, not yet a reproducible compliance test.

Ask what could be measured

A durable rule needs a threshold that developers, regulators, and outside reviewers can apply consistently. Broad human-level performance is difficult to operationalize: people vary by task, and AI performance changes with the benchmark, system prompt, tools, sampling settings, and operator skill. A model can outperform most people on a narrow technical task and still make basic contextual mistakes.

Capability-based rules can be more concrete, but they also need detail. If a system is alleged to perform an unauthorized cyber operation, reviewers need to know the model version, allowed tools, credentials, target environment, number of attempts, and success criterion. Otherwise, one assisted demonstration and a repeatable autonomous outcome can be described with the same headline.

The same applies to shutdown resistance. An adversarial evaluation may reveal that a model can route around a poorly designed sandbox. That is an important security finding, but it is not by itself proof that the system has durable independent goals or meets a legal definition of superintelligence. A well-designed law would need to distinguish model behavior, insecure scaffolding, operator choices, and real-world harm.

Enforcement has to be proportionate and reviewable

The proposal framework contemplates severe sanctions, including loss of an entity's ability to do business and criminal penalties. The more serious the consequence, the stronger the need for notice, technical evidence, a chance to challenge a classification, and a defined appeal route. A company and its customers need to know what happens to data, contracts, essential services, and employees while a disputed determination is reviewed.

There is also an accountability question inside an AI organization. A researcher running a controlled evaluation, an engineer configuring a connector, and an executive authorizing a frontier training program do not exercise the same control. A final text would need clear safe harbors for defensive testing, incident research, and responsible disclosure, while still prohibiting deliberate evasion.

A regulator would need enough technical capacity to inspect confidential systems without turning sensitive model weights or security findings into a new exposure. That points toward protected evaluation procedures, documented test protocols, and independent technical advice—not simply a requirement that laboratories make public claims about their own safety.

A domestic pause needs an international theory

The proposal's international ambition is central, not incidental. A unilateral US restriction could reduce domestic development while leaving capability work elsewhere untouched. Supporters can reasonably answer that a race without shared restraints raises collective risk; critics can reasonably ask how any pause would be verified across borders. Both questions concern implementation, not just political preference.

AI is harder to control like a physical weapons program because software, expertise, and model weights can move. Large training projects still depend on chips, data centers, capital, and specialized talent, which gives governments some points of visibility. But increasingly efficient algorithms and distributed access make a simple infrastructure threshold incomplete.

A credible international strategy would need shared definitions, reporting rules, verification procedures, and consequences for evasion. It would also need to protect legitimate safety research. Narrow agreements around specified harmful uses may be easier to verify than a universal line for intelligence, but that choice would produce a different policy from the proposed categorical ban.

Do not wait for a frontier-law debate to secure agents

The announcement has been linked to reports of AI-agent security failures. Those reports deserve careful investigation, but they should not become a reason to postpone ordinary safeguards. A connected agent can create material risk without being superintelligent if it has broad credentials, unreviewed network access, or authority to execute actions.

For a practical deployment, review the account identity, information flows, tool permissions, and human approval point separately. A finance assistant may prepare a payment but should not both hold an unrestricted bank credential and approve its own transfer. A coding agent may read a repository while production deployment and secret access remain separate, logged actions. Short-lived credentials, scoped service accounts, approval gates, and a tested disable path are concrete controls available now.

This is also where regulation can be more useful than rhetoric. Incident reporting requirements, evaluation standards, access-control expectations, and independent audits can target observable behavior. They can coexist with a larger debate about whether some capabilities should never be developed.

What to watch next

The proposal becomes easier to assess when complete text is filed. Watch for a bill number; definitions of covered systems and development; an explicit start and end to any pause; a regulator's powers; research exemptions; due-process rules; and evidence of congressional support beyond the original sponsors. Those details will reveal whether the framework can become an enforceable program or remains a way to force a sharper public debate.

The right response to an early policy proposal is neither dismissal nor premature certainty. It is to separate the policy goal from the legal mechanism, insist on testable definitions and reviewable enforcement, and keep improving the operational controls that reduce AI risk today.

Editorial method

AI Tools Radar separates product facts, editorial judgment, and commercial placement. Updated facts retain their verification date.

Sources

Browse the directory