How AI’s Soft Law Sandcastles Can Become Hard Law Skyscrapers
When the Trump administration took office, it promised to strip back AI oversight and let American innovation run full speed ahead of its international competitors. Over the past year, it has followed through with its commitment by shifting federal focus away from AI safety issues and toward AI security: the Artificial Intelligence Safety Institute (AISI) under NIST was restructured into the Center for AI Standards and Innovation (CAISI), and previous administrations executive orders (EOs) on AI oversight were rescinded. This June, the same administration issued Executive Order 14409, which established the first federal review framework for frontier AI models. The framework, albeit voluntary, signals an important shift in the current trajectory of AI regulation, one that congressional staff weighing in on AI legislation, companies building compliance programs, and state policymakers should read closely.
The review framework asks companies to voluntarily submit unreleased frontier models to the federal government for capability and risk assessment up to 30 days before releasing the models to trusted partners. It explicitly forbids any mandatory licensing or government permitting for AI model development, and the 30 day review window exists on the reasoning that anything longer might slow the pace of American innovation. Flexible, fast, and lacking any direct enforceable power, EO 14409 is a textbook example of soft law. Policymakers built out the silhouette of a shifting sandcastle for AI regulation versus the solid structure of a skyscraper.
Reactions to the EO split two ways. Some industry voices called it a sensible first-try approach that permits innovation to run its course without significant intervention. Others called the decision toothless and an ineffective for-show gesture with no real power over frontier AI. But what’s striking about this EO is less about the policy itself than what it signals for an incoming turn in the track towards AI regulation. Is this the first layer of foundational soft law that will eventually build towards concrete statutes? Or are the sandcastle policies becoming something that the administration intends to leave (shakily) standing indefinitely?
To answer those questions, we need to understand what role soft law plays, what it has failed to do alone, and what makes the sandcastles build into skyscrapers instead of being just washed away.
Soft Law and Hard Law
Soft laws include voluntary frameworks, industry-led codes of conduct, and internal governance boards such as the NIST AI Risk Management Framework, Microsoft’s Responsible AI Principles, and IBM’s Responsible Technology and Governance Framework, all of which are generally fast, flexible, and broadly adopted. These self-imposed structures, which ask companies to behave well without legally requiring it, often excel in their speed of drafting and implementation. The multi-stakeholder process that some soft laws go through also encourages every actor to actively participate in the process of writing the rules that they will be living under, instead of fighting against them.
Soft law is also, notably, optional or constrained in its ability to shape. There is no real legally enforceable punishment that prevents companies from deviating from the EO 14409 voluntary risk assessment framework. Officially, only reputational incentives or public scrutiny can push companies to follow through. Voluntary standards can also offer little transparency in how they are made or in how and whether they are implemented.
That lack of transparency poses a risk to public trust. A February 2026 Pew Research Center report says that 40% of Americans predict that AI’s impact on society over the next 20 years will be negative, and 67% of Americans have little to no confidence in the U.S. government to regulate AI effectively. These statistics raise questions as to whether soft law, which by design casts the government as a policy partner and advisor rather than an enforcer, suffices on its own to reassure the American public.
Hard law, on the other hand, is everything that soft law isn’t. It’s legally binding, enforceable through courts or penalties, and difficult to change once established. But its permanence is also its weakness. AI develops so quickly that legislation can become outdated before it clears committee, and agencies are often too under-resourced or removed from industry to provide the technical expertise that regulating AI demands. Yet, hard law is also capable of generating public trust through casting the government as an enforcing regulator.
The difficulties of establishing hard law are on display in Congress, where federal AI bills are caught in a heated partisan tug-of-war. For instance, the AI Civil Rights Act introduced by Senator Ed Markey (D-MA) in 2024 and re-introduced in December 2025, would mandate a pre-deployment AI risk review structure and transparency around AI use in critical areas such as employment, housing, and medical fields. Yet, it remains sitting in congressional committees and has not received a vote on the floor. As the U.S. lacks a clear federal policy, states have been filling the vacuum, with examples being Colorado SB24-205, California SB 53 (2025), and Virginia Consumer Data Protection Act.
There’s a trade-off between the two types of laws. Soft law sandcastles are quick to make and forgiving, but they don’t hold up forever. Hard law skyscrapers are durable, but expensive and inflexible. The solution to our AI regulation problem, then, isn’t to rely on only one type of infrastructure. There is a testing-ground logic that underlines the whole process. We sketch out the silhouettes before we put ink to paper. We draft out our writing before we send it to the publisher. Similarly, policy leaders, experts, and advocates can lay out flexible, lower-cost soft law before they consolidate it into enforceable legislation. We need to build a hybrid approach that allows for flexibility and testing different policies in response to an emerging technology but with a deliberate build towards enforcing compliance.
The NIST Cybersecurity Framework Case Study
The soft-to-hard law pipeline method has been proven to work in the past. Similar to AI, cybersecurity was a fast moving innovative technology. By the early 2010s, issues like major data breaches, IP theft, and a private sector without a consistent regulatory environment reached a peak. With no legislation fast and flexible enough to address the problem, the government issued EO 13636 in 2013 that directed NIST to create its own Cybersecurity Framework (CSF) in 2014. This framework started off as a sandcastle much like today’s EO: voluntary guidance for private sector infrastructure that arrived at a consensus on technical vocabulary and a flexible risk-management structure.
Later, the Cybersecurity Enhancement Act of 2014 established NIST’s role in overseeing the framework while still keeping the standards themselves explicitly voluntary. Meanwhile, the crucial actors that would enable a smooth remapping of the CSF onto existing governance structures already existed under FISMA. Each agency had its Chief Information Officer (CIO) who was held responsible for their agency’s security program and ran annual audits by its Inspector General (IG).
Therefore, when the annual Inspector General audit metrics were mapped onto the CSF five central functions in 2016, agencies didn’t need to acquire additional funding or restructure roles to identify an individual to lead the effort. There was no new law or new executive order to mandate this shift, OMB and DHS simply reorganized the previous audit metrics to work with the CSF evaluation vocabulary. This action subtly oriented each agency around CSF a year before any mandate came along to require them to use it.
Finally, in 2017, EO 13800 and OMB Memo M-17-25 gave agencies 90 days to submit a risk assessment to OMB and DHS describing how they were mitigating cybersecurity risks and implementing the CSF. The transformation relied on budgetary gatekeeping as the forcing mechanism. When this report reached OMB, agencies that poorly adhered to these standards risked OMB flagging or cutting their IT budget requests. As EO 13800 stressed, agency heads would take personal responsibility for non-adherence to cyber risk management. This incentive was a major drive behind agencies adopting the new framework. Mapping onto pre-existing structures allowed the transfer to happen with low friction and without putting administrative and resource burden on agencies to start something from scratch.
EOs and OMB memos sit somewhere on the spectrum between the soft law of voluntary industry standards and the hard laws of statutes, as they are easily canceled with a signature. Yet these mechanisms that have no legal authority proved capable of shaping the market when given incentives and consequences within the control of executive branch agencies. Although the main effects of EO 13800 and OMB Memo M-17-25 were contained within the bureaucratic structures of the federal government, they slowly diffused outward toward the market through government contracts. The private sector began to adopt the CSF framework as its default approach for addressing cybersecurity risks because the government’s audits and budgets orbited around CSF standards. State legislatures hardened the framework further by incorporating CSF into state safe harbor statutes (in Ohio, Iowa, Connecticut, Utah, and others) that grant organizations an affirmative defense against data breach lawsuits if their security programs are aligned with safe industry standards, such as the CSF. Through these methods, the CSF soft-to-hard-law pipeline bypassed the traditional flaws of legislation, forgoing the expensive and slow pathway to becoming a bill by mapping onto existing bureaucratic designs.
The Consumer Privacy Bill of Rights
On the other hand, there are cautionary tales where soft regulations were laid down with plans of becoming enforceable law, but never came to be. The Obama’s administration’s Consumer Privacy Bill of Rights (CPBR) is one such example.
The initiative started off in 2012 as a blueprint similar to the NIST Cybersecurity Framework. It laid out a voluntary framework projected to give consumers control over seven central rights over their data privacy. While the Bill of Rights itself was designed as a voluntary code of conduct, the administration had clear intentions to codify the infrastructure later down the line. While introducing the bill, Obama explicitly stated that “my Administration will work to advance these principles and work with Congress to put them into law.”
In 2015 came the opportunity to have these voluntary standards transition into hard law as a piece of legislation. The proposal of a formal Consumer Privacy Bill of Rights Act was drafted that would’ve made the voluntary principles enforceable by the FTC. But the discussion draft was met with heavy criticism by both the industry, calling it an excessive blockade for innovation, and advocacy organizations like CDT and Consumer Watchdog, pointing out that it was full of loopholes and preempted stronger state laws. In the end, the bill failed to find congressional sponsors and was never formally introduced.
The overlap between this case study and today’s AI policy landscape is hard to miss. For one, the CPBR leaned on a multi-stakeholder process to write the code of conduct that was criticized for being toothless. AI regulation faces the same debate today, with ongoing fights over whether federal or state legislation should take priority, running parallel to the same ones presented in data privacy.
How Can We Apply These Lessons to AI policy?
Therefore, to interpret what the 2026 June EO 14409 is and what it suggests, we should look at these two case studies in order to learn from our mistakes and successes, and then look ahead to predict what this means for the future of AI regulation. The distinction between the NIST CSF’s success and the CPBR’s failure to transition into hard law, aside from differences in subject matter, was how the structures of each industry determined what policy lever it relied on to make it happen.
The NIST CSF was able to make its transition smoothly because it became mandatory only for entities the executive branch already controls. Federal agencies were incentivized to adhere to the CSF via FISMA and budget authority, and government contractors were required to follow in line via procurement regulations. For the private critical infrastructure industry as a whole, the CSF is still voluntary today. CPBR attempts to address private companies across the whole economy. The government isn’t Facebook’s customer and doesn’t fund Google’s IT budget, so there was no bureaucratic or procurement lever to pull. Calling for legislation to make CPBR enforceable brought back all the primary flaws of hard law. The process became slow, expensive, and stuck in political gridlock, exacerbated by the fact that privacy is a politically divisive issue.
What the implications of these case studies hold for AI regulation are significant. The federal government is already a major player in AI procurement, so the pipeline in which the government serves both as the customer and market is fully available for recreating the CSF playbook. AI companies are motivated to establish contracts with the federal government because government adoption carries significant reputational value that ripples out to state, local, and private AI technology adoption. Which means that the government has leverage over market regulation through internal governance mechanisms that it had over cybersecurity but didn’t for consumer privacy.
Voluntary frameworks like EO 14409 may be only the first move in a long process towards developing established statutes, and a way to quickly lay out groundwork while a technology is still changing rapidly and legislation lacks the resources and time to be passed in response. And the tell that EO 14409 should be the first stage of AI regulation and not a finished one is that, immediately after its issue, policy actors called on Congress to codify the order and make the review structure mandatory. That response points to what the AI policy community needs to focus on next: designing a pipeline that goes from soft law to hard law, transforming flexible, tested regulations into something enforceable. The EO is a good place to start, but it is a poor place to stop.
Soft law was never meant to be a permanent solution. Treating it as one, and letting the sandcastle stand in for the skyscraper indefinitely, is how we end up with a decade of voluntary commitments and no enforceable accountability to show for it. Soft law fosters industry cooperation, builds technical capacity among regulators, and creates the policy windows from which hard laws eventually emerge and hold actors responsible. But soft law is meant to be the foundation that eventually builds up to hard law, and this transition doesn’t happen naturally. The switch only works if the pipeline is built with the intention of bridging the two forms of regulation in mind, and the triggering mechanism of internal government policy levers is carefully designed and pulled.
Soft law was never meant to be a permanent solution. Treating it as one, and letting the sandcastle stand in for the skyscraper indefinitely, is how we end up with a decade of voluntary commitments and no enforceable accountability to show for it.
Jobseekers, employees at smaller organizations, and local public workers need more than a weekend crash course in AI. They need practice choosing useful tasks, protecting data, testing outputs, and explaining where human judgment remains necessary.
“What excites me is that it’s very tempting to be very discouraged, and say, ‘Oh, we’ve got these archaic institutions that are calcified and you could never change them.’ But I think we’re in the middle of a technological revolution that will upend lots of things, and does provide a window.”
As Congress considers broader packages to advance critical minerals production and supply chain resilience, science diplomacy vehicles must be part of that conversation, not as an afterthought, but as an intentional and foundational pillar of any strategy.