
The regulatory debate over AI is moving from control at the model-building stage to the allocation of responsibility. In the US House, Republican Rep. Jay Obernolte and Democratic Rep. Lori Trahan released a 269-page draft AI bill on June 4 local time, and a day later, on the 5th, the Trump administration's Executive Order on Promoting Advanced AI Innovation and Security and OpenAI's white paper "Democratic Governance of Frontier AI: A Blueprint for a Federal Framework" were each made public. The three documents aim at different points, but together they ask how far the responsibility of developers and the government, and of the states and the federal government, extends.
The House draft would require companies building the most advanced models to establish and carry out risk response plans, and have independent third-party auditors verify that they do so. It designates CAISI, under the Department of Commerce, as the oversight body. The design pins down in law an organization that had been running on an executive order, and attaches $300 million (about 460 billion won) over three years.
The administration's approach has a different grain. The executive order states flatly that it does not impose mandatory licensing or prior approval on the development and deployment of new models. Instead it calls for a voluntary framework under which developers grant the government early access for up to 30 days before release, and the NSA takes a central role in the classified benchmarking that identifies which frontier models fall under regulation. Cyber capability assessments are built around the NSA and CISA.
OpenAI's white paper also drew a line against a permit system. It would require safety evaluations and risk mitigation procedures before release only for top-tier frontier models, while opposing giving the government authority to approve or block a release. At the same time it proposed building CAISI into a permanent hub handling safety evaluation, the setting of testing standards, accreditation of independent evaluators, and coordination with international partners. All three documents point to the same agency, but they differ on what to hand that agency.
The sharpest clash is between the federal government and the states. The House draft would bar state governments from writing rules aimed at AI model development itself, while leaving open state rules that address how AI is used, such as fraud, discrimination and consumer harm. The restriction carries a sunset provision under which it automatically lapses after three years. The White House, in the AI policy blueprint it submitted to Congress in March, also called for federal legislation limiting state regulation of development.
Reactions were split. Brad Carson, president of Americans for Responsible Innovation (ARI), said the minimum safeguards in state AI legislation could instead become a ceiling. Technology industry groups including ITI welcomed the draft, citing the unification of regulatory standards. It is a divide over which layer regulation attaches to rather than how strict it is.
The same question comes up in different language in Korea's financial sector. Yeon Tae-hoon, senior research fellow at the Korea Institute of Finance, in his report "Building a Regulatory Framework for AI Use in the Financial Sector," divided regulatory types into controlling side effects through legislation, inducing self-regulation based on industry guidelines, and extending the existing model risk management (MRM) framework to AI. Model risk management refers to the management procedure in which financial companies catalog and grade the various forecasting and assessment models they use, then verify and monitor them. The report judged that the third of these offers the most workable control process in terms of feasibility.
The specific elements listed are model identification and assessment, risk grading, documentation, testing before actual use, continuous monitoring and auditing, and the establishment of a dedicated risk management unit. Added to these was an explanation covering independent-unit validation and internal approval, third-party management, and a three lines of defense structure. The idea is to broaden the scope of the control procedures financial firms have long operated rather than write a new law.
Other countries are on that path. The UK Prudential Regulation Authority introduced model risk management principles in 2023, Canada's Office of the Superintendent of Financial Institutions issued related guidelines last year, and the United States revised and released its guidance this year. Korea has no model risk management guidelines that apply across the financial sector. Regulation is taking shape as the AI Framework Act takes effect this year, but the tools that address the layer of financial models remain empty.
The report expects AI in finance to spread to effectively every line of business, apart from some areas where verifying regulatory compliance is difficult. At the same time it forecast that traditional mathematical and statistical models and AI models will be used together for a considerable period. So it added a recommendation that a management framework covering non-AI models as well, rather than carving out AI alone, be introduced in parallel to reduce blind spots. If only one side is tightened, work flows to the side where management is looser.
Regulation that reaches into the stage where models are built carries heavy political friction and struggles to keep pace with technological change. Regulation that requires a record of who verified and who approved when that model is used to screen loans, price insurance and filter job applicants operates on top of existing procedures.
Someone denied a loan at a bank counter is not curious about which model was built with how many parameters. They want to know what procedure the decision went through, and whom they can hold to account if it was wrong. The House draft in Washington still faces committee deliberation, and it will take more time for Korea's supervisory regulations to be put in order.
