top of page

Josh Shapiro AI Safeguards Challenge Washington’s Race-First Strategy

6 days ago
15 min read

Josh Shapiro called for strict federal AI guardrails on September 17, challenging Washington’s preference for faster development with fewer regulatory barriers. The Pennsylvania governor wants independent oversight, greater transparency, and safety requirements applied to companies building advanced artificial intelligence systems, according to Bloomberg’s report on his remarks.

The Josh Shapiro AI safeguards proposal is more than another warning about hypothetical technology risks. It connects model oversight with immediate disputes involving children, professional impersonation, electricity costs, water use, and local control over data centers.

That position puts Shapiro at odds with the Trump administration’s emphasis on rapid development and fewer regulatory barriers. Shapiro argues that this framing presents a false choice. The United States, he says, can capture AI’s economic benefits without asking the public to accept every risk.

Bloomberg’s report establishes what Shapiro advocated at the Pittsburgh event; official Pennsylvania documents provide the record of what his administration has already implemented. Those are separate categories. His requested federal guardrails remain proposals, while Pennsylvania’s executive order, agency initiatives, lawsuit, and pending legislation have distinct legal statuses and limits.

Josh Shapiro AI Safeguards Move the Debate to Congress

Shapiro is asking Congress to create enforceable duties for AI companies, not simply publish another voluntary framework.

Speaking at the AI Horizons 2026 Summit in Pittsburgh, Shapiro urged Congress and the federal government to establish strict guardrails for artificial intelligence. His central requests included independent third-party oversight, stronger transparency, and a requirement that companies place safety closer to the center of development, according to his administration’s official transcript of his prepared remarks.

Independent oversight means an evaluation performed by an organization that does not build or sell the system being examined. It can include testing, documentation reviews, security assessments, and verification of a company’s risk claims.

In technical terms, such an evaluation could examine whether a developer has identified foreseeable harms, measured performance under realistic conditions, documented limitations, monitored incidents, and assigned responsibility for remediation. These functions broadly correspond to the govern, map, measure, and manage activities in the National Institute of Standards and Technology’s AI Risk Management Framework, although Shapiro has not publicly specified that Congress should adopt the NIST framework as the legal standard.

That distinction matters because much of the information available about advanced models still comes from their developers. Companies decide which benchmarks to publish, how to define severe risks, and how much detail to release about internal testing.

A third-party requirement would not automatically settle those questions. However, it would reduce the extent to which developers grade their own work and select the evidence presented to policymakers.

The practical difference would be visible during procurement. A hospital considering an AI assistant might currently receive an aggregate accuracy score and a vendor-authored safety statement. A qualified outside review could instead test medical prompts, identify groups or situations in which performance deteriorates, document whether the system fabricates citations, and verify that uncertain answers are escalated to a clinician.

In his prepared remarks, Shapiro described himself as optimistic about AI’s opportunities while arguing that emerging harms require a stronger government response. He also rejected the label of an AI “doomer,” a term commonly applied to people who expect advanced systems to cause catastrophic harm.

His stated position is narrower and more politically significant. AI does not need to present an inevitable extinction risk before government can require testing, disclosure, and accountability.

That approach expands the case for safeguards beyond one dramatic scenario. A model can cause material harm through deceptive advice, discriminatory decisions, privacy failures, security weaknesses, or unreliable outputs without becoming an autonomous global threat.

The speech also changed who carries the burden of proof. A purely promotional policy assumes that restrictions require extraordinary justification. Shapiro’s approach asks developers to show that high-impact systems have received meaningful scrutiny before the public absorbs their risks.

His proposal remains a policy demand, not enacted federal law. Congress would still need to define which systems require review, who qualifies as an independent evaluator, what evidence evaluators may access, and which findings must become public.

Those unresolved details are substantial. Yet Shapiro’s intervention establishes a clear test for federal lawmakers: whether national AI policy will impose measurable obligations or continue relying mainly on company promises.

Why Pennsylvania’s Governor Is Pressing Washington Now

Pennsylvania has encountered AI as a physical, consumer, and administrative issue, which makes abstract assurances increasingly difficult to defend.

The state is seeing the technology through several distinct channels. AI chatbots can interact with children and deliver health-related responses. State employees use generative tools in public administration. Developers also want to build the energy-intensive infrastructure required to train and operate larger models.

These issues do not fit neatly inside a single technology policy. They touch professional licensing, consumer protection, education, electricity regulation, environmental permitting, labor, and local government authority.

Shapiro’s administration began tightening its approach before the Pittsburgh speech. In February, it announced an AI literacy toolkit and coordinated oversight efforts involving Pennsylvania’s education, health, human services, state, aging, and financial agencies.

The administration’s official AI safety initiative included resources for parents, students, teachers, caregivers, and consumers. It also directed residents toward a complaint process for AI companion bots that appear to offer licensed professional services.

For a family, this distinction can arise during an ordinary conversation rather than an obvious medical consultation. A teenager might ask a companion bot about depression, an eating disorder, or medication and receive a confident answer written in the voice of a therapist or physician. A parent may see no warning that the response was generated without a licensed professional reviewing the child’s circumstances.

That initiative framed literacy as necessary but insufficient. Teaching users to recognize an unreliable system can reduce exposure to harm. It does not remove a developer’s responsibility when a product falsely presents itself as a doctor or another regulated professional.

Pennsylvania later sued Character.AI, alleging that chatbots unlawfully held themselves out as licensed medical professionals and delivered medical advice. In the formal filing, Commonwealth of Pennsylvania, Department of State, State Board of Medicine v. Character Technologies, Inc., the state sought a preliminary injunction and alleged unauthorized medical practice. The allegations in the Commonwealth’s filed complaint remain subject to adjudication. Character Technologies’ liability has not been established, and the filing represents the Commonwealth’s allegations rather than judicial findings.

The case nevertheless illustrates why Shapiro now emphasizes accountability rather than user education alone. It asks whether existing professional-licensing rules can reach an AI service when the apparent “speaker” is a generated character rather than a human practitioner.

The governor has also encountered resistance around data center development. These facilities turn the AI debate into questions residents can see on utility bills, zoning notices, and environmental permit applications.

In August, Shapiro signed Executive Order 2026-05. It tied state support for new data centers to energy, environmental, workforce, transparency, and community requirements.

According to the administration’s official account of Executive Order 2026-05, Pennsylvania removed AI data center proposals from its expedited permitting program, prohibited nondisclosure agreements in those projects, and required local approval before qualifying permits could be issued. The order also requires developers to enter enforceable consent agreements incorporating the state’s GRID requirements.

Developers seeking the state’s cooperation must make binding commitments under the Governor’s Responsible Infrastructure Development requirements, known as GRID. Those commitments include paying infrastructure costs associated with their projects rather than shifting them to other electricity customers.

Operators must also report energy and water consumption information. The state says it will maintain a public map of proposals that have engaged with environmental regulators.

For residents, those requirements determine whether they can learn about a proposed facility before major decisions are effectively settled. A nearby household could otherwise encounter the project only after receiving a zoning notice or hearing predictions of higher electricity demand. A public project map, disclosed resource estimates, and local approval process give residents information they can use at hearings, even though those tools do not guarantee that every objection will prevail.

These measures do not amount to an AI development ban. They establish conditions for projects that impose identifiable costs on host communities. They also remain subject to implementation by state agencies and to any future legal challenge over the scope of executive authority.

That record explains the timing of Shapiro’s federal demand. Pennsylvania is already trying to manage consequences that Congress often discusses as future possibilities. State agencies face chatbot complaints, infrastructure proposals, professional impersonation concerns, and decisions about AI use inside government.

The immediate pressure falls on federal lawmakers and major AI developers. Congress must decide whether states should remain the primary testing ground for safeguards. Developers must decide whether to support consistent oversight or continue opposing rules that constrain deployment.

The Central Fight Is Safety Accountability Versus Deployment Speed

The primary conflict is not innovation versus prohibition. It is accountable development versus a policy that treats regulatory friction as a strategic weakness.

The Trump administration has described AI leadership as an international race. Its policy prioritizes rapid private-sector development, wider adoption, infrastructure construction, and the removal of rules viewed as unnecessary obstacles.

That argument has economic and national security force. A fragmented collection of state requirements can raise compliance costs, especially for smaller businesses. Rules written around current technology can also age quickly as model architectures and uses change.

The administration’s national AI legislative framework calls for a consistent federal policy and argues that conflicting state laws can weaken American competitiveness. The same document also asks Congress to address child safety, AI-enabled fraud, national security, and the effect of data centers on residential ratepayers.

The White House has sought authority to challenge state laws it considers excessive. Its stated position is that AI development has interstate and foreign policy implications that individual states cannot manage effectively.

Shapiro agrees that federal action is necessary, but he disputes what that action should accomplish. A national standard, in his view, should create a safety floor rather than function mainly as a ceiling on state authority.

This difference is the article’s central tradeoff. Uniformity can simplify compliance, but a weak uniform standard can also prevent states from responding to harms that Congress has not addressed.

The dispute becomes sharper when federal policy separates product regulation from areas traditionally controlled by states. The White House framework preserves state enforcement of generally applicable child-protection laws and recognizes state and local authority over zoning and data center siting, while arguing against conflicting state regulation of AI development.

Those categories may overlap in practice. Consider a chatbot that gives dangerous health guidance. Pennsylvania can enforce professional licensing and consumer laws. However, reducing the underlying risk might require rules governing model evaluation, deployment testing, disclosure, or access controls.

A federal framework focused mainly on preemption could leave states responsible for the consequences while limiting their ability to regulate the technical and business decisions producing those consequences.

Shapiro’s demand for independent oversight targets that gap. It would place responsibility earlier in the development chain, before a state investigator receives complaints or a family must prove harm.

The same logic applies to transparency. A regulator cannot evaluate whether a safeguard works without knowing how the company tested it, what limitations appeared, and which deployment conditions changed.

Still, transparency is not a single switch. Public disclosure of every technical detail could reveal security weaknesses, trade secrets, or information that helps malicious actors. Effective legislation would need separate channels for regulators, qualified auditors, researchers, enterprise customers, and the general public.

Independent oversight presents similar design problems. An auditor paid by the company being reviewed can face incentives that weaken independence. A small group of approved evaluators could also become a bottleneck or produce standardized reviews that miss unusual hazards.

A credible system would therefore require conflict-of-interest rules, minimum testing competencies, protected access to nonpublic evidence, and a mechanism for regulators to review the evaluator’s work. Rotation requirements or random assignment could reduce dependence on a single client, although each option would add cost and administrative complexity.

These challenges do not invalidate Shapiro’s approach. They show why Congress must define the mechanism instead of passing a law built around broad terms such as safety and responsibility.

The real measure of Josh Shapiro AI safeguards will be whether they create reliable evidence before deployment. If the policy only produces compliance reports, it will add paperwork without changing incentives.

State Action Shows Both the Promise and Limits of AI Guardrails

Pennsylvania can respond to local harms, but it cannot independently create a complete oversight system for a national technology market.

The state’s recent actions show what targeted regulation can accomplish. Professional licensing laws can address systems that present themselves as doctors. Consumer protection agencies can investigate deception. Education authorities can create guidance for students and teachers.

Local and state governments also possess direct authority over land use, permits, environmental conditions, and infrastructure support. That gives Pennsylvania meaningful leverage over data centers even when it has limited influence over model development elsewhere.

The August order uses that leverage carefully. It does not claim that every data center is unsafe. It distinguishes projects willing to accept enforceable community requirements from speculative proposals seeking public support without comparable obligations.

Supporters include labor and community representatives who see a path between unrestricted construction and a blanket moratorium. The Pennsylvania State Building and Construction Trades Council backed the GRID principles as a way to preserve development while addressing energy, environmental, and community concerns, according to the state’s announcement.

That coalition matters because AI infrastructure debates often divide economic and environmental interests. Building trades want employment, municipalities want investment, and residents want protection from higher costs or depleted resources.

A requirements-based approach gives each group something concrete to evaluate. Developers can proceed if they accept defined conditions. Communities receive information and a formal role. Workers can seek local hiring commitments.

However, executive action has limits. A future administration can alter an executive order. Agencies can face legal challenges over the reach of permitting conditions. State rules also cannot force a developer based elsewhere to disclose every material fact about its models.

Legislation offers greater durability, but Pennsylvania’s experience shows how slowly even targeted proposals can move. Senate Bill 1090, which addresses disclosures and safeguards for AI interactions with children, passed the state Senate 49 to 1 on March 17, 2026.

The bill then moved to the House Communications and Technology Committee. Its official legislative history documents the vote and subsequent referral. As of September 19, 2026, the bill had not completed the House process and was not enacted law.

This is one reason federal inaction does not produce a regulation-free market. It produces a patchwork assembled from executive orders, old consumer laws, lawsuits, agency guidance, and targeted state bills.

Businesses still face uncertainty, but the rules emerge after conflicts and enforcement actions rather than through a coherent national system.

Developers also operate across sectors with different standards. A general-purpose chatbot may be used for entertainment, education, employment, health questions, or financial decisions. The risk changes with the context, even if the underlying model remains the same.

A workable federal law must therefore distinguish capability from use. Oversight should become stricter when a system can materially affect health, safety, employment, credit, public benefits, or critical infrastructure.

This principle also applies inside organizations. Teams adopting AI need records of source material, model limitations, review decisions, and changes to automated workflows. A searchable engineering knowledge base can support that work, but documentation cannot replace external accountability.

In practice, a procurement team might see a vendor’s accuracy score yet receive no breakdown showing that performance deteriorates on medical questions or among particular user groups. A customer-support team might also miss that a model update weakened escalation rules until users begin reporting harmful answers. Independent review can expose those gaps before they become routine failures.

The same problem can appear after deployment. Employees may learn that a system was updated but receive no usable explanation of what changed. If an earlier version reliably transferred self-harm messages to a human reviewer and a later version does not, a version number and general release note will not give the support team enough information to manage the new risk.

Companies may maintain excellent internal records while choosing not to reveal serious weaknesses. Conversely, a disclosure mandate can produce thousands of pages that offer little usable information.

The strongest version of Shapiro’s proposal would connect documentation to action. An evaluator should be able to identify a problem, require or recommend remediation under a defined legal process, and verify whether the change worked. Regulators would also need authority to intervene when a developer rejects a material finding.

Without that enforcement chain, “independent oversight” risks becoming another trust label attached to systems that ordinary users cannot meaningfully inspect.

Tougher Oversight Still Leaves Difficult Questions Unanswered

Shapiro has identified an accountability gap, but his public proposal does not yet answer who audits, what gets tested, or what happens after failure.

The first uncertainty concerns scope. Congress could apply oversight to every AI product, only the largest general-purpose models, or specific high-impact uses.

An overly broad rule would pull simple business software into an expensive process designed for frontier systems. An overly narrow rule would let companies reorganize products or remain below a technical threshold while still affecting millions of users.

Lawmakers also need a durable way to define covered systems. Fixed computing thresholds are measurable, but efficiency improvements can make them outdated. User counts reveal reach but not severity. Capability tests can better capture risk, although developers may optimize models around known evaluations.

The second uncertainty is evaluator independence. Congress would need conflict-of-interest rules, accreditation standards, access requirements, and procedures for handling confidential information.

Auditors must have enough technical access to test meaningful claims. A polished demonstration or restricted interface cannot reveal how a system behaves under adversarial pressure, after fine-tuning, or when connected to outside tools.

For example, an office assistant that appears harmless in a chat window may behave differently once it can open email, retrieve files, or initiate transactions. A realistic evaluation would test the complete deployed workflow, including whether malicious instructions embedded in a document can redirect the system or expose information from another user.

Yet unlimited evaluator access creates genuine security and intellectual property concerns. The law must establish secure testing environments and penalties for mishandling sensitive information.

The third question is disclosure. Shapiro wants more transparency, but different audiences need different material.

Consumers need clear notice when they are interacting with AI and when its advice is not professionally licensed. Enterprise buyers need evidence about reliability, security, data handling, and monitoring. Regulators need incident reports, internal test results, and enough technical documentation to investigate claims.

The public also needs aggregate information about serious failures. Without it, researchers and journalists cannot identify patterns across companies or products.

The fourth question involves remedies. Discovering a weakness means little if a company can deploy the system without addressing it.

Congress must decide whether regulators can delay a release, require restrictions, order notification, impose monitoring, or demand withdrawal from high-risk uses. Each option introduces procedural and constitutional questions.

A mandatory pause may be justified for a clearly dangerous health product. Applying the same remedy to a general-purpose writing assistant would be harder to defend.

There is also a risk that compliance strengthens the largest companies. Major developers can build audit teams, hire specialized counsel, and absorb delays. Smaller companies may struggle with the same fixed costs.

That outcome would be especially counterproductive if the rules protect dominant companies without producing better safety. Congress could consider shared testing resources, tiered obligations, and standards that scale with a system’s reach, capability, and use.

Critics of state regulation make a valid point when they warn about inconsistent obligations. A company should not need 50 substantially different technical audits for the same model.

However, that argument supports a credible national standard. It does not by itself establish that state rules should be eliminated before an adequate federal replacement exists.

Federal preemption without strong federal enforcement would shift power away from states and toward developers. Preemption paired with meaningful oversight could offer both consistency and accountability.

The final uncertainty concerns international coordination. Advanced systems cross borders, and many supply chains include foreign research, chips, data, cloud services, and users.

Shapiro criticized an isolationist approach to AI governance. Coordination with allies can support common evaluation methods and incident reporting. It can also reduce the chance that companies move risky work to the least demanding jurisdiction.

International cooperation will not erase political differences. It can still establish shared technical language for testing security, controllability, and misuse risks.

The skeptical conclusion is straightforward: Josh Shapiro AI safeguards are a direction, not a completed regulatory design. Their value depends on details that the speech left for Congress to resolve.

Three Signals Will Show Whether Shapiro’s Challenge Matters

The next test is whether Shapiro’s proposal changes federal legislation, developer behavior, or Pennsylvania’s enforcement record.

The first signal is the content of any federal AI bill that advances through Congress. The key question is not whether lawmakers use the word “safety.” It is whether legislation requires independent evaluation, gives regulators access to evidence, defines covered systems, and creates consequences for serious failures.

Preemption language will be equally important. A bill that blocks state action while preserving weak voluntary commitments would cut against Shapiro’s position. A federal floor with room for traditional state consumer, child safety, licensing, and infrastructure powers would strengthen it.

Readers should distinguish a discussion draft, an introduced bill, a committee-approved measure, and an enacted statute. Each represents a different degree of legal consequence, and public statements about a framework do not themselves impose obligations on developers.

The second signal is how leading developers respond to independent oversight. Public support for safety testing is common, but companies often disagree over mandatory access, publication requirements, and enforcement.

A meaningful change would include support for qualified outside evaluators who can examine nonpublic evidence. Another sign would be standardized reporting of severe incidents and clear disclosure when a product enters a high-impact setting.

Voluntary action alone cannot substitute for law. It can reveal whether the industry sees credible oversight as compatible with competition or as an unacceptable limit on deployment speed.

The third signal comes from Pennsylvania itself. The state must show that its data center conditions and consumer protections work in practice.

Watch whether developers sign binding GRID commitments, obtain local approvals, and report energy and water use. Also watch whether the state’s public project map gives communities timely information rather than documenting decisions after they become difficult to change.

The relevant evidence will be concrete: published project locations, consent agreements, resource-use reports, enforcement notices, local hearing records, and documented penalties for noncompliance. Announcements alone will not show whether the order changes developer conduct or protects ratepayers.

Enforcement around AI companion bots will provide another practical test. Courts and agencies will determine how existing licensing and consumer laws apply when a conversational system appears to offer professional advice.

A ruling accepting Pennsylvania’s legal theory could show that current law can address some AI harms. A dismissal based on jurisdiction, platform immunity, standing, or an unclear statutory definition could increase pressure for targeted legislation. Until the court rules, either outcome remains uncertain, and the complaint should not be treated as proof of liability.

For developers and enterprise buyers, this debate changes procurement expectations. Organizations should expect more questions about model testing, incident response, training data governance, human review, version changes, and third-party access.

A school district, for example, may need to know whether a student-facing chatbot stores sensitive conversations, how it handles self-harm disclosures, and who receives an alert. An employer using AI to screen applicants may need subgroup performance data and a process for human appeal. A utility deploying an automated assistant may need evidence that it does not invent payment rules or shutoff policies.

Knowledge workers should also care because safety policy determines who carries the cost of an unreliable output. Without clear accountability, users and employers must detect failures after deployment. Stronger rules can move some of that responsibility back toward the companies designing and selling the systems.

Shapiro’s argument ultimately asks whether speed should remain the default measure of national AI success. Faster models and more infrastructure can produce economic value, but they can also distribute risks faster.

The next one to three months should reveal whether Washington translates his intervention into legislative text or leaves it as a public policy demand. Readers should watch the bill language, agency authority, court record, and implementation data - not the slogans - and ask one direct question: do the final Josh Shapiro AI safeguards give independent reviewers enough access and authority to identify serious problems before the public bears their cost?

Give every agent the context to do better work

Connect your agents to the knowledge, decisions, and history already organized in remio.

remio currently supports Windows 10+ (x64) and Macs with Apple silicon.

Your AI Partner at Work
Get more done with remio

Plan. Create. Deliver.
All in one place.

bottom of page