Key Takeaways
The SANDBOX Act uses the goal of promoting AI innovation to cloak a sweeping deregulatory agenda. The bill does not require applicants to demonstrate that AI is integral to their operations, nor does it establish a meaningful threshold test to determine whether the burden, which applicants attribute to regulation and seek to waive or modify, is substantial or even legitimate.
The program favors regulatory relief rather than genuine experimentation. Applicants are not required to demonstrate that proposed mitigation measures will work or that the claimed benefits of the deployment will materialize. Meanwhile, agencies face substantially greater burdens when seeking to deny an application than when approving one.
Temporary waivers could become a mechanism for permanent deregulation. The bill requires the director of the White House Office of Science and Technology Policy to report annually to Congress on covered provisions and recommend covered provisions for potential repeal or amendment based on participants’ self-reporting that they can operate safely without those requirements.
Congress should reject the SANDBOX Act and similar proposals. If lawmakers believe existing federal regulations are outdated or unnecessarily burdensome, those rules and authorizing statutes should be evaluated through ordinary legislative and regulatory processes.
Introduction and summary
Since 2025, the second Trump administration1 has pushed an agenda of American artificial intelligence (AI) dominance. The administration’s 2025 AI Action Plan2 frames rapid AI adoption as a national priority and treats regulation as the principal obstacle to achieving that goal. The administration has also begun promoting this approach internationally. In September 2026, the United States secured G20 support from the Chinese delegation for the “Carolina Principles for Emerging Technologies,” which encourage governments to use regulatory sandboxes and experimental exemptions from certain regulatory requirements to accelerate the development and commercialization of emerging technologies.3
To advance this agenda, the Trump administration and congressional Republicans have focused on preempting state AI laws,4 which Trump has described as a “chaotic patchwork”5 that threatens innovation. They argue6 Congress needs time to develop a national framework, despite state laws currently being the main source of frontier AI oversight.7 Supporters also claim existing federal laws and voluntary company standards are sufficient, suggesting no new federal regime is needed. Yet Senate Commerce Chair Sen. Ted Cruz’s (R-TX) introduction to the September 2025 “Legislative Framework for American Leadership in Artificial Intelligence”8 and a Trump executive order in December 20259 show their approach is not truly deferential to existing federal law.
The centerpiece of Sen. Cruz’s AI policy framework,10 the Strengthening Artificial intelligence Normalization and Diffusion By Oversight and eXperimentation (SANDBOX) Act,11 leverages the general-purpose nature of AI to establish a broad mechanism through which companies in virtually every sector using the technology could seek exemptions from most federal regulatory requirements, including those expressly mandated by Congress. The SANDBOX Act represents one of the most expansive deregulatory proposals ever introduced at the federal level and is the next step in a long-running effort to eliminate government regulations. Deregulation of this magnitude poses significant risks to public health and safety, worker and consumer rights, and economic security.
The SANDBOX Act proposes a federal program that would permit private companies and the director of the White House Office of Science and Technology Policy (OSTP) to seek waivers or modifications of “covered provisions,” which the bill defines as nearly any federal rule across the federal regulatory system, to enable deployment of AI systems beyond existing regulatory requirements. Although the bill is framed as an effort to “establish a Federal regulatory sandbox program for artificial intelligence,” regulatory theory and practice generally characterize sandbox regimes as narrowly tailored programs that allow a limited set of firms to test novel products or operate under temporarily waived requirements, subject to close supervisory oversight, specific conditions, and the continued preservation of baseline protections.12 The SANDBOX Act significantly diverges from this established model by granting broad regulatory waivers and insulating participating entities from civil and criminal enforcement of waived provisions.13
The SANDBOX Act represents one of the most expansive deregulatory proposals ever introduced at the federal level and is the next step in a long-running effort to eliminate government regulations.
The SANDBOX Act14 would establish a program that, while framed as a mechanism to facilitate AI deployment, creates a pathway by which temporary waivers or modifications could become the basis for permanently amending or repealing federal protections across unrelated domains, including environmental regulation, health care, and labor, with effects extending far beyond AI.15
The most significant issues associated with the SANDBOX Act stem from several structural design features:
- The bill lacks a meaningful limitation tying eligibility for regulatory exemption to actual AI use, allowing a technology that is increasingly embedded across sectors to serve as an expansive gateway for obtaining regulatory waivers.16
- The bill defines eligible “covered provisions” in such broad terms that the program extends well beyond regulations specifically related to AI.17
- The bill centralizes substantial authority in the director of the OSTP, allowing a single White House official to oversee the program, override agency objections, and independently initiate waiver or modification proceedings. This structure positions the director as one of the most powerful officials within the federal government.18
- The bill creates a mechanism whereby temporary regulatory relief can serve as the basis for permanent changes to federal requirements. It directs Congress to consider amendments or repeals of covered provisions once participants demonstrate that they can operate without them.19
- Finally, by allowing the executive branch to suspend or modify rules mandated by Congress, the SANDBOX Act raises significant separation-of-power concerns about the balance between legislative mandates and executive authority.
A reading of the SANDBOX Act reveals little meaningful concern for regulatory harmonization or for limiting its scope to AI governance. Instead, it aims to strip federal agencies of their authority to regulate any AI-related activity. The problem, in the eyes of the act’s proponents, is not just the inconsistency of state laws, but the existence of federal rules—and not just AI rules. By linking waivers to a technology that can be integrated into nearly any regulated activity, the bill opens the door to dismantling protections across sectors, threatening protections related to health, safety, labor, and the environment. Those committed to any of those hard-won protections must not allow them to be discarded in the name of easing the burden on AI companies. Even if the SANDBOX Act never advances to the Senate floor, it signals the clear intent of a significant faction in Congress when it references “AI sandboxes.” It is important to expose its radical design before its principles are repackaged and presented in a more palatable form to prevent a mechanism of this scope from being normalized.
This analysis is based on the SANDBOX Act discussion draft released by the Senate Committee on Commerce, Science, and Transportation on September 10, 2025.20 Although the proposal has not been revised or advanced since, it is essential to shine a bright light on the act’s radical design and true intent. The SANDBOX Act represents one of the most sweeping deregulatory proposals ever introduced, advancing conservative groups’ long-standing goal to dismantle government safeguards under the banner of AI policy.
Overview of the SANDBOX Act
The SANDBOX Act,21 introduced in September 2025 by Sen. Cruz,22 chairman of the Senate Committee on Commerce, Science, and Transportation, proposes creating a federal AI regulatory sandbox. This program is designed to facilitate the testing, experimentation, and deployment of AI products, services, and development methods by allowing eligible participants to seek temporary waivers or modifications of federal regulatory requirements.23 The director of the OSTP24 would administer the program, oversee applications, and retain authority to issue decisions, including on appeals of agency determinations.25 In addition to reviewing applications submitted by private entities, the bill authorizes the director to independently submit waiver or modification applications where the director determines that relief would advance the development, deployment, or use of artificial intelligence in the United States.26 In their applications, private party applicants must identify the AI system, product, service, or development method associated with the request; specify the regulatory requirements, or “covered provisions,” from which they seek relief; describe anticipated risks and proposed mitigation measures; and explain how the waiver would promote AI development or deployment.27 The bill defines the regulatory requirements eligible for relief as “covered provisions,” a term that incorporates the Administrative Procedure Act’s (APA) definition of “rule” and extends to associated guidance, frequently asked questions, bulletins, and other related agency materials.28 The SANDBOX Act also establishes procedures through which approved waivers or modifications may later be considered for amendment or repeal through a congressional review process.29
Although the SANDBOX Act is structured around the terminology of regulatory experimentation, the authority it creates differs significantly from the traditional sandbox model. To place this departure in context, it is important first to examine how regulatory sandboxes are traditionally designed.
The conventional use of the term “sandbox” describes an environment designed to contain risk, not remove safeguards. In technology development, sandboxing is used to prevent untested systems from interacting with real users or critical infrastructure. That logic has occasionally been adapted into policy through the use of regulatory sandboxes.30 In those models, experimentation is limited under clearly defined and carefully monitored conditions by regulators, with constraints that scale based on risk and are designed to preserve core protections31 while gathering information to inform future regulatory decisions.
The SANDBOX Act32 departs from the traditional model by authorizing the complete waiver or modification of federal rules to facilitate the real-world deployment of AI products, services, and development methods directly to consumers, including at scale and without compliance with the licensing, authorization, or enforcement requirements of the waived or modified regulations. This shift reflects a broader approach to sandboxes in federal AI and technology policy, as further evidenced by the introduction of bills such as the July 2025 draft of the Unleashing AI Innovation in Financial Services Act33 and the May 2025 draft of the Digital Asset Market Clarity Act,34 which both similarly contemplate waiver authority for regulated financial firms and raise many of the same concerns as the SANDBOX Act.
The SANDBOX Act inverts the premise of a traditional sandbox. While framed as a mechanism to evaluate the safety and performance of novel and emerging AI systems, the bill places greater emphasis on scrutinizing existing federal regulations than on evaluating the technology itself. The SANDBOX Act program is structured to generate evidence that regulated entities can function without the covered provisions, which then serves as justification to recommend that Congress repeal or amend those provisions on a fast-track timeline. The bill gestures at “consumer protection”35 only in a narrow disclosure provision that requires participants to post basic public notices about their participation in the program, the experimental nature of the product, that the product may expose consumers to risks, and how to file a complaint. Beyond these disclosures, the bill imposes no substantive consumer protection requirements.
While the waiver or modification is in effect and the applicant remains in compliance with the written agreement,36 the bill provides an unusually strong shield from accountability. Specifically, during the waiver period:
- The applicant is expressly shielded from civil or criminal enforcement37 of the specific covered provisions identified in the waiver.
- Agencies are barred from pursuing punitive actions,38 such as civil penalties or fines.
- Agencies cannot suspend or revoke licenses based on violations of waived provisions.
If the OSTP director concludes the applicant is not complying with the agreement, the bill still does not require immediate consequences. The director must provide39 at least 30 days to cure and may grant additional 30-day cure periods at their discretion. Only after the cure window closes40 without correction may the director revoke the waiver and terminate the applicant’s participation.
Once revocation occurs, the enforcement shield applies only prospectively and only to the specific conduct that constituted noncompliance with the written agreement. Conduct that occurred during the waiver period while the participant was in compliance with the agreement remains permanently shielded from agency enforcement, even if it would have violated the waived provisions or caused substantial harm,41 effectively granting permanent retroactive immunity for conduct under a valid waiver. And because the director, not the affected agency, controls both the compliance determination and the cure process,42 agencies cannot enforce against noncompliant conduct until the director revokes the waiver, allowing lengthy periods of noncompliance before enforcement is even on the table. The bill does clarify that waivers and modifications under the sandbox program do not confer immunity for criminal offenses43 that are not expressly identified in the waiver or modification, and it preserves existing private rights of action44 by consumers seeking damages or equitable relief.
The SANDBOX Act inverts the premise of a traditional sandbox. While framed as a mechanism to evaluate the safety and performance of novel and emerging AI systems, the bill places greater emphasis on scrutinizing existing federal regulations than on evaluating the technology itself.
The SANDBOX Act creates two pathways through which federal rules can be waived or modified under the program. The first allows companies to apply directly. The second allows the OSTP director to initiate applications independently.
As the above charts illustrate, regardless of the relevant agency’s response, both pathways can lead to the same result: approval of the waiver. An agency that grants the application produces a waiver. An agency that misses its review deadline produces a waiver by default. And an agency that denies the application can still be overridden by the OSTP director on appeal, also producing a waiver. The only way for an agency denial to stand is if the director agrees with it.
What the charts fail to capture is the substance of what each type of applicant is required to demonstrate. While, on its face, the application process appears rigorous, the requirements are largely procedural. Applicants must supply a lengthy checklist of information, but at no point are they required to prove the validity of their claims, that their proposed safeguards will work, or that the benefits they assert will materialize. For a private applicant, the company must apply to the OSTP director and is required to:45
- Describe the AI product, service, or development method it seeks to introduce
- Identify the specific rules it seeks to waive or modify and explain why this action is necessary
- Explain how the proposed activity would benefit consumers, enhance efficiency, create jobs, expand economic opportunity, or otherwise promote AI innovation
- Explain how potential benefits outweigh any risks
- Describe any foreseeable risks, which the bill limits to only health and safety concerns, economic harm, or unfair or deceptive trade practices
- Explain (without demonstrating effectiveness) how they intend to reasonably mitigate any identified risk
- Specify the proposed duration of the waiver or modification
- List all agencies with jurisdiction over the affected provisions
- Affirm the company’s intent to comply with the original covered provision once the waiver or modification period concludes
For a director-submitted application, there are even fewer requirements. The OSTP director only needs to form the opinion that the proposed waiver or modification will advance AI development, deployment, or use in the United States. The bill does not require the director to identify specific risks, propose mitigation strategies, or demonstrate that the benefits of the waiver outweigh its costs.
Key risks posed by the SANDBOX Act
The SANDBOX Act’s structure raises several questions about the scope, administration, and operation of the proposed program. The following sections examine the bill’s most significant features and their implications.
No threshold for what counts as AI
A critical feature of the SANDBOX Act is that it does not require a meaningful or limiting nexus between the regulation being waived or modified and the use of AI. The bill does not define how central AI must be to the activity at issue. It also does not establish a threshold test to ensure that the requested waiver is genuinely necessary for AI development or deployment. In other words, to seek waiver or modification of a federal rule, a company need only assert that its activity involves AI. There is no requirement to show that the activity depends on AI, or even that the asserted system meets the bill’s own definition. Instead, the determination of relevance is left almost entirely to the discretion of the applicant and, ultimately, the OSTP director. As a result, AI need not be the primary subject of the regulated activity. It may be incidental, auxiliary, or embedded in an otherwise conventional operation. This creates a significant risk that AI functions as a pretext rather than a constraint. Because modern AI tools can be integrated into nearly any process, from logistics and manufacturing to environmental monitoring and workforce management, applicants can plausibly assert an AI connection to justify waiving regulations that were never designed to govern AI systems. Moreover, the bill does not require a covered provision be AI specific or even closely related to algorithmic decision-making. In practice, this allows the SANDBOX Act to target long-standing regulatory safeguards in sectors such as energy, labor, health care, or environmental protection, so long as an applicant can articulate some link to AI deployment.46
By leaving the question of AI nexus unresolved at every stage, the SANDBOX Act effectively transforms a program nominally aimed at AI experimentation into a general-purpose deregulatory tool. The lack of a substantive AI nexus requirement allows the bill to extend far beyond AI governance into largely unrelated regulatory domains.
The problem is compounded on the agency review side. Even if an agency were skeptical of a claimed AI nexus, the bill provides no mechanism for it to act on that skepticism. The agency review framework prescribes a narrow and exclusive set of considerations, and nowhere does the bill direct agencies to assess whether the applicant’s product, service, or development method qualifies as an ‘artificial intelligence system’ under the bill’s own definitional provision.
By leaving the question of AI nexus unresolved at every stage, the SANDBOX Act effectively transforms a program nominally aimed at AI experimentation into a general-purpose deregulatory tool. The lack of a substantive AI nexus requirement allows the bill to extend far beyond AI governance into largely unrelated regulatory domains.
Even if such an AI nexus requirement were imposed, the statutory definitions are insufficient to serve as a meaningful gatekeeping device. They are drafted broadly and can encompass a wide range of software-enabled processes, allowing broad use of the waiver authority across regulatory domains. To be clear, even a genuine and well-defined AI nexus would not make this bill acceptable. Even a real connection to AI does not justify overriding congressionally mandated protections or insulating companies from enforcement. At most, it would tie the waiver authority to AI instead of leaving it open to nearly any regulated activity.
Expanding the definition of “covered provision”
To understand the scope of the SANDBOX Act, it is necessary to unpack how the bill defines a “covered provision.”47 Rather than supplying its own definition, the bill incorporates and then expands definitions drawn from federal administrative law. Read together, these nested definitions produce an extraordinarily broad category of rules that may be waived or modified.
The SANDBOX Act defines a covered provision48 as follows:
The term ‘covered provision’ has the meaning given the term ‘rule’ in section 804(3) of title 5, United States Code, including any associated guidance, frequently asked questions publications, bulletins, or associated, derivative material and any rule the adoption of which is expressly required by statute.
The SANDBOX Act bill defines a covered provision by cross-referencing the term “rule” in 5 U.S. Code § 804(3),49 which is the definition used in the Congressional Review Act (CRA).50
The CRA provision does not itself supply an original definition of a rule. Instead, it incorporates yet another definition from elsewhere in the APA. It provides that the term “rule” has the meaning given in 5 U.S.C. § 551.51
The APA, 5 U.S.C. § 551,52 defines the term “rule” as follows:
The whole or a part of an agency statement of general or particular applicability and future effect designed to implement, interpret, or prescribe law or policy or describing the organization, procedure, or practice requirements of an agency and includes the approval or prescription for the future of rates, wages, corporate or financial structures or reorganizations thereof, prices, facilities, appliances, services or allowances therefor or of valuations, costs, or accounting, or practices bearing on any of the foregoing.
Under the APA,53 a rule is defined expansively to cover virtually any agency action that is intended to have future effect, including statements that interpret the law, set policy, or establish requirements for how an agency or regulated entities must operate. In practice, if an agency action shapes what an individual entity or the public at large is allowed to do or how they must behave going forward, it likely counts as a rule.
The CRA then incorporates this definition in 5 U.S. Code § 804(3),54 but narrows it slightly by carving out three specific categories. First, it excludes rules of applicability, meaning rules that apply only to a specific individual, company, or transaction rather than to the public at large. Second, it excludes rules that deal solely with internal agency management or personnel matters. Third, it excludes agency rules governing organizational procedure or practice when those rules do not substantially affect the rights or obligations of parties outside the agency. After these exclusions, what remains within the CRA definition are agency rules of general applicability that shape the legal or economic obligations of the public. These include regulations that govern how industries operate, what standards businesses must meet, what conduct is permitted or prohibited, and how federal law is implemented in practice. In plain terms, this definition is meant to capture regulations that have a real-world impact on regulated entities and the public, while leaving out narrowly targeted decisions and purely internal agency operations.
The SANDBOX Act adopts this CRA definition along with its exemptions, meaning the same categories of rules that the CRA excludes from its scope are also excluded from the program. However, the bill broadens the definition in two key ways. First, it explicitly extends the definition beyond formal regulations to include a wide range of informal agency materials. This includes guidance documents, frequently asked questions, bulletins, and other associated or derivative materials that agencies use to explain, interpret, or implement their rules (more details in the next section). In plain terms, this means that not only binding regulations, but also the nonbinding documents that agencies rely on to give those regulations meaning in day-to-day enforcement, may be waived or modified under the program. Second, the act expressly includes any rule that Congress has required an agency to adopt by statute. These are not discretionary regulations that an agency chose to issue on its own. They are rules that Congress itself directed agencies to write to carry out federal law. By bringing these congressionally mandated rules within the definition of a covered provision, the SANDBOX Act allows the executive branch to suspend or modify regulations that exist precisely because Congress determined they were necessary and put their requirement into law.
Additionally, it is important to note what the plain text of the covered provision definition does not encompass. A covered provision does not include statutes themselves. Thus, the SANDBOX Act does not authorize the waiver or modification of federal law enacted by Congress, and statutory requirements formally remain in force. However, because many federal statutes operate through their implementing regulations, the ability to waive or modify those regulations often amounts to undermining the statute’s practical effect. This means that while the underlying statute technically remains intact, its teeth are removed. For example, under the Clean Air Act (CAA),55 Congress directs the Environmental Protection Agency (EPA) to protect public health through nationally applicable air quality standards, including National Ambient Air Quality Standards.56 In some cases, Congress goes further and expressly requires the agency to promulgate those rules by statute. The SANDBOX Act’s definition of covered provision specifically includes such statutorily mandated rules, allowing them to be waived along with everything else. If those rules are waived under the SANDBOX Act for a particular company because compliance would impede AI deployment, the statutory mandate to protect public health remains on paper. Still, the regulatory mechanisms that give it effect are suspended. The ultimate impact would be that the statute is no longer in effect for the approved company.
Once a rule or related agency material falls within the definition of a covered provision, the SANDBOX Act authorizes its suspension or modification, and the label does heavy work in making that authority sound more contained than it is. The bill’s use of covered provision is misleading insofar as it suggests a granular, provision-specific unit of analysis. A “provision” is ordinarily understood to refer to a discrete subpart of a statute or regulation,57 representing one piece of a larger whole. A reader could therefore be forgiven for assuming that an applicant identifies a specific requirement and the agency waives that requirement alone. However, the bill’s own definitional chain does not support that assumption. Tracing covered provision back through the CRA to the APA’s definition of a rule reveals that the object being waived is the rule itself, and a rule, under the APA, can be “the whole or a part of an agency statement.”58 Nothing in that chain requires the waived unit to be limited to the specific text an applicant points to as burdensome. Accordingly, the waiver mechanism does not actually operate on a provision-by-provision basis. Instead, identification of a single provision within a rule that is plausibly connected to AI deployment may serve as the basis for waiver of the broader rule in which it is embedded.
An important component of the “covered provision” definition that merits some attention is its explicit extension beyond formal regulations to include “any associated guidance, frequently asked questions publications, bulletins, or associated, derivative material.”59 These informal agency materials may lack the binding legal force of a formal regulation. Still, they are often the documents that give regulations practical meaning in day-to-day enforcement and compliance.
Guidance documents, bulletins, and frequently asked questions (FAQs) publications are how agencies tell regulated entities what the rules mean in practice. They explain how an agency will interpret ambiguous statutory terms, how it will apply a regulation to fact patterns, and what conduct will or will not trigger enforcement. For agencies and businesses alike, these documents are more operationally significant than the underlying regulation itself because they translate abstract legal requirements into concrete compliance expectations. For example, “associated guidance” would encompass documents such as the Office of Federal Procurement Policy’s Policy Letter 11-01,60 which explains how agencies should distinguish inherently governmental functions from those that may be performed by contractors. FAQs include agency interpretations such as the U.S. Department of Education’s Title IX FAQs61 explaining regulated entities’ obligations under federal civil rights law. “Bulletins” include supervisory documents, such as the Office of the Comptroller of the Currency’s Bulletin 2023-1762 on third-party risk management, which provides banks with detailed expectations for managing relationships with outside vendors. By including these materials within the definition of covered provisions, the SANDBOX Act allows applicants to seek waivers not just of formal regulations, but of the interpretive infrastructure that surrounds them. In some cases, a company might seek relief from an agency’s guidance rather than the underlying regulation itself, particularly where the regulation is broadly worded but the guidance imposes detailed compliance expectations or adopts an interpretation the company views as more burdensome. In other cases, waiving the regulation would necessarily render the accompanying guidance inapplicable. Either way, the bill’s express inclusion of guidance documents, FAQs, bulletins, and other derivative materials illustrates the extraordinary breadth of the SANDBOX Act. It demonstrates that the bill is not just concerned with suspending legally binding regulations, but with eliminating every single component of the regulatory framework to ensure that there is truly nothing left that could constrain participating companies.
Upending federal procurement rules
The broad net the SANDBOX Act casts with its covered provision definition extends beyond traditional regulatory programs and into the rules governing how the federal government purchases goods and services. Federal procurement operates through an extensive framework of generally applicable regulations and associated interpretive materials. These include the Federal Acquisition Regulation (FAR),63 agency-specific acquisition supplements64 such as the Defense Federal Acquisition Regulation Supplement (DFARS),65 procurement policy directives,66 and related guidance. Together, these authorities establish the conditions under which private entities may contract with the federal government.
Because the SANDBOX Act defines covered provision by cross-referencing the CRA’s definition of a rule, and because the FAR and its component amendments are generally applicable agency rules that fall within that definition,67 the FAR falls within the scope of the SANDBOX Act’s waiver and modification authority. The bill’s inclusion of associated guidance, frequently asked questions, bulletins, and derivative materials extends that reach even further, meaning the SANDBOX Act can reach not just the FAR itself, but the broader interpretive framework agencies used to implement it. However, the bill’s reach is limited to generally applicable rules and guidance materials that govern federal contracting more broadly and does not cover individual procurement decisions, such as a specific contract award, bid protest determination, or other decisions of applicability.
This is particularly significant because procurement has increasingly become one of the federal government’s primary tools for governing AI. In the absence of comprehensive federal AI legislation, agencies have increasingly relied on acquisition requirements, procurement guidance, and vendor obligations to establish expectations regarding cybersecurity, testing, risk management, documentation, incident reporting, and other safeguards applicable to AI systems purchased by the government. For example, FAR 52.204-2168 requires contractors to implement basic safeguarding controls for covered contractor information systems, and DFARS 252.204-701269 imposes more extensive requirements on defense contractors, including implementation of the security controls in National Institute of Standards and Technology Special Publication 800-171 and reporting of cyber incidents within 72 hours of discovery. An AI company looking to sell AI systems or services to the U.S. Department of Defense could seek a waiver for the underlying FAR and DFARS clauses, arguing that implementing the required security controls would impede its ability to deploy AI products to the government on the timeline federal customers demand and allowing it to contract with and deliver AI systems to the government without having implemented the security controls those clauses require.
Presumption in favor of deregulation in agency review process
Although the SANDBOX Act formally assigns70 federal agencies a role in reviewing waiver and modification requests, the structure of the bill ensures that agency oversight is narrow and asymmetrical.
The bill narrows the scope of agency review by prescribing how applications must be evaluated. It instructs agencies to evaluate71 applications primarily on whether the proposed AI activity would produce public benefits such as efficiency gains, economic growth, or technological advancement. The agencies weigh these benefits against a narrow set of risks, limited to health and safety concerns, economic harm, or unfair or deceptive trade practices. This framing excludes a wide range of considerations that routinely inform agency decisions, including environmental impacts, labor protections, and civil rights implications. By defining both the benefits and the risks that matter, the statute pre-loads the analysis in favor of approval and prevents agencies from relying on the full range of expertise Congress has historically delegated to them.
The bill goes even further by establishing a clear presumption in favor of granting waivers and modifications. For both approvals and denials,72 agencies must produce a formal record identifying each covered provision under their jurisdiction and enumerating the reasonably foreseeable risks associated with the requested waiver or modification, limited to health and safety risks, economic damage, and unfair or deceptive trade practices. Beyond this shared baseline, however, the burdens diverge sharply. When an agency denies a waiver or modification,73 it must generate an extensive record explaining why, including how the waiver could cause those risks, the likelihood that the risks would materialize, why partial approval or reformulation would be insufficient to mitigate them, and the information relied upon in reaching that conclusion. Additionally, where an agency would deny an application unless risks are mitigated, it must affirmatively recommend how the applicant could mitigate those risks. In contrast, an approval requires74 only a limited description, if applicable, of how the applicant intends to mitigate identified risks and how it intends to protect consumers during the waiver period. This asymmetrical design places a heavy procedural burden on agencies that seek to deny applications, effectively biasing the review process toward approval or conditional approval even where substantial concerns exist.
The asymmetry is compounded by the narrow definitions of risks agencies can examine. Each of the three permitted risk categories is so narrowly defined that even agencies with well-founded concerns will struggle to meet the specificity the bill demands. The bill requires not just identifying whether a risk exists but establishing the specific mechanism by which the waiver causes it and the likelihood it will materialize. A “health and safety risk”75 is defined as a risk likely to cause bodily harm, loss of human life, or a substantial adverse effect on human health. Although the final category extends beyond bodily injury, the definition still limits agencies to harms that can be characterized as substantial, leaving some psychological, dignitary, and other nonhealth effects outside its scope. A “risk of economic damage”76 is defined not as financial loss or market harm, but specifically as a risk likely to cause tangible, physical harm to a consumer’s property or assets. The “risk of unfair or deceptive trade practices”77 is tethered to Federal Trade Commission (FTC) Act Section 5 and two 1980s FTC policy statements. These require demonstrating consumer injury that is substantial, not outweighed by countervailing benefits, and not reasonably avoidable by the consumer. This demanding standard was developed over years, and agencies are now expected to apply it to novel AI products on a 90-day clock.
Granting competitive advantage to favored entities
The agency review process matters most, if at all, only for the first waiver granted because agency skepticism becomes increasingly difficult to sustain once the program signals that a rule is dispensable. That initial approval becomes evidence that the regulated activity can occur “safely without” the rule, which in turn feeds directly into the bill’s annual congressional repeal mechanism. After that first waiver, the question for every later applicant is not if the activity is safe, but whether the agency can justify treating them differently from the company the program has already approved. This has important competitive effects within regulated markets. Once a single firm is granted a waiver or modification of a covered provision, that regulatory relief alters the competitive baseline for all similarly situated firms operating in the same market. Competitors that continue to comply with regulatory requirements may face higher compliance costs and operational constraints. As a result, the program incentivizes firms to seek equivalent or broader waivers not primarily as a matter of regulatory preference, but to avoid structural disadvantage in the marketplace. Equally important, the discretionary nature of these approvals allows an administration to pick winners and losers within a sector, granting relief to favored companies while withholding it from others, and to wield that power as leverage in unrelated dealings with those companies.
The Trump administration has already been accused of using its regulatory authority in this manner, most prominently when the Federal Communications Commission’s approval of the Paramount-Skydance merger followed Paramount’s $16 million settlement of a lawsuit the president had brought against CBS News.78
The program incentivizes firms to seek equivalent or broader waivers not primarily as a matter of regulatory preference, but to avoid structural disadvantage in the marketplace.
Greatly expanding the authority of the OSTP
The SANDBOX Act places most of its authority in the director of the White House Office of Science and Technology Policy. The director is a Senate-confirmed official who leads the OSTP, which sits within the Executive Office of the President. Presidents have often also designated the OSTP director as an assistant to the president, giving the official an additional White House role79—one that does not require Senate confirmation.80 Under the SANDBOX bill, the OSTP director would move beyond this role and become the central decision-maker in a program that can dismantle federal regulatory requirements across the government. This concentration of authority is especially unusual because it flows not to the expert agencies Congress empowered to write and enforce these rules, but to the OSTP, an office with no rulemaking authority, no enforcement capacity, and no institutional tradition in any of the regulatory domains it would override.
The bill authorizes the director to submit applications81 to waive or modify covered provisions under the program, independent of any private applicant, when the director determines that the waiver or modification would advance AI development, deployment, or use in the United States. Unlike private applications, which respond to specific business activities or products,82 an executive assessment of how particular regulatory provisions affect AI adoption more broadly drives director-submitted applications. The bill imposes no additional or specific conflict of interest constraints on this authority, allowing the director to place specific regulations into the sandbox program based on policy judgment alone. This authority effectively elevates executive priorities on AI development into the waiver pipeline and positions the OSTP as an agenda-setting actor within the federal regulatory system.
The bill also gives the OSTP director extensive power to override agency resistance in two crucial ways. First, if the head of an applicable agency fails to submit a record of decision83 by the deadline, the director must presume that the agency does not object to the waiver or modification and may proceed with the application. Second, even if an agency denies an application, the director retains decisive authority through the appeals process.84 Applicants whose requests are denied may appeal directly to the director for reconsideration. For director-submitted applications, the director personally prepares the response to agency objections. The director then decides whether the appeal addresses the agency’s concerns and may approve the application notwithstanding the original denial. In doing so, the director files a new record of decision explaining how the concerns have been mitigated. This structure makes the OSTP both the appellate body and the ultimate decision-maker, allowing the White House to substitute its judgment for that of the expert agency charged by Congress with implementing and enforcing the underlying statute.
Director-approved applications also carry outsize power beyond the initial waiver or modification. When a director-submitted application is granted by an agency or by the director on appeal, the director must publish notice of the waiver or modification in the Federal Register and may establish a mechanism for other applicants to use.85 This means any person may subsequently apply to operate under the same waiver or modification. Thus, a single director-initiated waiver can become a generally available deregulatory pathway.
Additionally, the bill authorizes the director to actively assist applicants in navigating the program. Upon request,86 the OSTP may consult with applicants, identify which covered provisions are likely eligible for waiver or modification, identify the agencies with jurisdiction over those provisions, and provide anonymized information about other applications or aggregate applicant trends. This places the director as both facilitator and adjudicator, as applicants are guided by the same office that later evaluates their submissions, weighs agency objections, and decides appeals. This consolidation of power further erodes the independence and neutrality of the review process.
These authorities make the OSTP director one of the most powerful regulatory actors in the executive branch. The SANDBOX Act empowers the director to suspend congressionally mandated regulations and substitute executive judgment for that of expert agencies implementing federal law. This raises serious questions about the allocation of power between Congress and the executive branch. At minimum, it blurs the distinction between policymaking, enforcement, and adjudication. This strains long-standing separation of powers principles and undermines the role Congress envisioned for independent regulatory agencies.
Temporary regulatory relief as a pathway to permanent deregulation
The SANDBOX Act’s waiver and modification mechanism is not limited to providing temporary regulatory flexibility for individual participants. The bill expressly allows temporary participation in the sandbox to serve as a basis for permanently eliminating or modifying federal regulatory requirements through its congressional review of covered provisions process.87 Under Section 703, the OSTP director is required to submit an annual special message to Congress identifying each covered provision that has been waived or modified, how many times it has been waived or modified, the provisions for which applications were denied, and any covered provision the director determines should be repealed or amended. This includes recommended textual changes based on participants demonstrating they could “operate safely without” those requirements under the sandbox program.88 Meanwhile, applicants define their own mitigation strategies and have no meaningful obligation to demonstrate that those measures will be effective or to revise them if they prove ineffective. The reporting framework sent to Congress depends entirely on applicants to disclose whether previously unanticipated risks have emerged during deployment and to report any adverse incidents or consumer harms.
Congress must then consider and vote on the proposed amendment or repeal, subject to the applicable legislative procedures governing enactment. If those procedures track those of the CRA, only a simple majority is needed in both chambers.89 This makes clear that the temporary waiver process is not the bill’s end goal but a pretext for broader deregulation. A single company’s temporarily approved waiver or modification can serve as the predicate for permanently eliminating a rule. Although this section borrows the language of congressional review, it is materially distinct from and far broader than the CRA,90 which allows Congress to disapprove only newly finalized rules within a narrow, time-limited window after issuance.91 The SANDBOX Act imposes no comparable temporal or procedural constraint and applies to existing regulatory requirements regardless of how long they have been in force, including long-standing regulations.
Undermining separation of powers and usurping congressional authority
The fundamental problem with the SANDBOX Act is not its individual provisions but the constitutional structure it creates. By empowering a lone executive branch official to suspend rules that Congress has required be issued, the bill creates a category of executive authority with no clear analog in existing law and in deep tension with the basic allocation of power between Congress and the executive branch.
The SANDBOX Act raises a distinct concern about how far Congress can go in delegating legislative authority to the executive branch. The nondelegation doctrine, a constitutional principle rooted in Article I’s vesting of “all legislative powers” in Congress, governs that question.92 The doctrine holds that because the Constitution assigns lawmaking authority to Congress, Congress cannot hand that authority to the executive branch to exercise without limit. In its modern form, the doctrine permits Congress to authorize the executive to exercise policy discretion as long as it provides an “intelligible principle”93 to guide that discretion. This means that a meaningful standard channels what the executive may do, distinguishing permissible delegations of implementation authority from impermissible transfers of lawmaking power. The Supreme Court has not struck down a statute on nondelegation grounds in more than 90 years,94 but some justices have suggested it be reinvigorated. The SANDBOX Act is aggressive enough to potentially do so, creating broader implications for Congress’ authority to act in other areas.95
At a minimum, Congress cannot transfer its core lawmaking function wholesale to the executive without meaningful constraint. The SANDBOX Act authorizes the OSTP director to waive or modify any federal rule, including statutorily mandated rules, based on a single standard, namely that doing so will “advance the development, deployment, or use of artificial intelligence in the United States.”96 That formulation supplies no limiting principle. It does not define what counts as advancing AI, how to weigh advancement against the purposes the underlying rule was enacted to serve, or what categories of rules are off limits. The director may target any covered provision in the federal regulatory system, in any sector, regardless of whether Congress contemplated AI when enacting the statute or its implementing rules. In effect, Congress would be handing the executive branch a roving authority to identify and disable federal law, constrained only by the executive’s own judgment about what serves AI. It bears emphasis that this critique does not require reviving a more aggressive nondelegation doctrine. This effort risks destabilizing the broad swath of federal regulatory authority that depends on agency rulemaking under general statutory standards. The point is narrower. Whatever standards the doctrine has tolerated for delegations of rulemaking authority, the SANDBOX Act delegates something different, namely, the authority to unmake rules that Congress required to be in force.
The crux of the constitutional concern is that the SANDBOX Act’s express inclusion of “any rule the adoption of which is expressly required by statute”97 within the definition of a covered provision. When Congress directs an agency to issue a rule, that directive reflects a deliberate legislative judgment that the statute is not self-executing and that specific regulatory requirements are necessary to give the statute effect. The mandate is itself an exercise of legislative power. By allowing the executive branch to waive these rules, the bill lets the executive override the legislative judgment in the statutory mandate. The statute formally remains on the books, but the regulatory mechanism Congress requires to implement it does not. This is also where the bill departs most sharply from the ordinary categories of executive authority. Executive agencies routinely interpret statutes, exercise enforcement discretion, and prioritize among regulated activities. However, none of those familiar powers extends to disregarding a congressional command that a rule be in force. The SANDBOX Act would create that authority for the first time and vest it in the OSTP, an office that Congress has never charged with regulatory responsibility in any domain.
Finally, the constitutional problem is sharpened by the identity of the official given this authority. The OSTP director is a single Senate-confirmed official within the Executive Office of the President. The director does not lead an agency charged by Congress with administering or enforcing the regulatory programs the bill places within the office’s authority and has no institutional expertise in the regulatory domains the bill empowers the office to override. Still, the bill gives that office the authority to suspend federal rules and, in practical effect, determine when congressionally mandated regulatory requirements will not apply. That allocation of authority echoes a power long viewed with suspicion, namely, the executive’s unilateral suspension of laws enacted by the legislature. Indeed, one of the central principles established by the English Bill of Rights of 1689 was that the Crown could not suspend or dispense the operation or execution of laws without Parliament’s consent.98 The framers carried forward this principle into the American constitutional structure through the Take Care Clause, which provides that the president “shall take Care that the Laws be faithfully executed.”99 The clause reflects the rejection of executive authority to suspend the operation of laws based solely on the executive’s own judgment. Although the president retains discretion in determining how to enforce the law, that discretion does not include the authority to disregard or suspend legal requirements enacted through the legislative process.
Structural vulnerabilities invite corruption and abuse
The structural problems described above not only raise constitutional concerns in the abstract, but they also create conditions that are uniquely vulnerable to corruption and abuse in practice. A program that grants a company multiyear federal rules exemptions that its competitors do not have creates enormous incentives to cultivate political favor. The SANDBOX Act provides almost no safeguards against that dynamic.
The most obvious concern is selective favoritism in approvals. The OSTP director has broad discretion over application approvals and denials, with no requirement to treat similarly situated applicants consistently, no obligation to explain different outcomes, and no conflict-of-interest provisions governing decisions involving companies with financial or political relationships to the administration. As detailed above, the director can unilaterally target any federal regulation—free of a company’s request—based solely on their determination that doing so advances AI. It is difficult to imagine a cleaner vehicle for delivering regulatory relief to a specific industry free from the paper trail of a company-initiated request.
The same discretion that enables favoritism in approvals can be turned in the other direction just as easily, with denials and delays deployed to punish disfavored applicants. Moreover, because the federal government is, by a wide margin, the largest single purchaser of goods and services in the world,100 the risk of favoritism is more acute where a waiver or modification touches federal procurement. For instance, a company exempted from a cybersecurity certification requirement could bid on and win contracts that certified competitors have priced to account for compliance cost or that uncertified competitors are ineligible to pursue.
The point is not that any official will act corruptly. It is that the bill creates a structure in which corruption would be easy to carry out, difficult to detect, and largely immune to legal remedy.
Sectoral examples of impact
To understand what is at stake, it helps to consider the kinds of rules that could realistically be targeted under the program.
In the environmental context, the CAA directs the EPA to require any new or modified “major stationary source” to obtain a preconstruction permit under the Prevention of Significant Deterioration program before construction may begin.101 The implemented regulation102 requires the source to install the “best available control technology” and undergo agency and public review of its projected health and environmental impacts as a condition of that permit. AI data centers require enormous amounts of energy, and companies are increasingly installing on-site gas turbines to meet that demand. Under the SANDBOX Act, a company could argue that this permitting requirement impedes the deployment of the on-site power generation needed to scale AI infrastructure and seek a waiver allowing it to build and operate immediately. If granted, that company’s data centers would be permitted to operate without the pollution controls that protect surrounding communities from toxic emissions. In addition, a federal agency would be precluded from acting against the company for the duration of the waiver. Ordinarily, constructing a major stationary source without the required permit exposes a company to criminal enforcement under the CAA, which carries up to five years’ imprisonment, doubled for repeated violations.103 Under the SANDBOX Act, however, a company holding an active waiver covering that permitting requirement would face neither criminal charges nor civil enforcement for the waived violation.
In April 2026, the NAACP sued xAI and MZX Tech LLC,104 Elon Musk’s AI company, claiming that it had illegally operated dozens of unpermitted methane gas turbines in Southaven, Mississippi, to supply power to its Colossus 2 data center, resulting in the release of significant amounts of nitrogen oxide and formaldehyde emissions in predominately Black communities.105 As of June 16, 2026, the NAACP alleges that xAI operates a total of 59 turbines without permits.106 The U.S. Department of Justice (DOJ) moved to intervene and have the lawsuit dismissed on behalf of xAI, arguing that the lawsuit posed a threat to national security due to the use of the company’s AI chatbot Grok in support of military operations.107 Under the bill, a company in xAI’s position would not need to wait for DOJ intervention. Instead, it could apply for a waiver of the requirements in advance, obtain an enforcement shield barring agency action,108 and thereby deprive affected communities of legal remedies for the duration of the waiver.
In the health context, the Medicare Advantage (MA) prior authorization regulations at 42 C.F.R. §§ 422.101,109 422.137,110 422.138,111 and 422.566112 implement section 1852 of the Social Security Act,113 ensuring MA enrollees receive the same benefits as original Medicare. These regulations impose important requirements on MA plans’ use of prior authorization, including requirements governing the transparency and clinical justification of coverage criteria. For example, 42 C.F.R. § 422.101(b)(6)114 requires MA plans to make certain internal coverage criteria publicly available and to provide supporting evidence and rationale for prior authorization determinations. It also requires plans to demonstrate that additional utilization-management criteria are backed by evidence that the expected clinical benefits are highly likely to outweigh any clinical harms, including harms from delayed or decreased access to care.
MA insurers using an AI-driven utilization review system could seek a waiver or modification of regulatory requirements, asserting these rules hinder the operational efficiency of its AI-enabled business model. The SANDBOX Act does not mandate that the regulation subject to waiver regulate AI or even that it have a meaningful relationship to AI deployment. An applicant is only required to use a business model incorporating AI and demonstrate a qualifying benefit such as improved operational efficiency. Consequently, an insurer could contend that the administrative and transparency requirements imposed on its AI-driven utilization review system inhibit its ability to deploy or operate that system efficiently, even though the underlying regulations were not designed to regulate AI. Such a waiver could allow MA plans to discontinue publishing internal coverage criteria, evidence summaries, source lists, and rationales for prior authorization determinations, as well as eliminate requirements that plans demonstrate that their additional coverage criteria are clinically justified. This could allow insurers to use AI-driven systems to make or assist with coverage decisions while providing patients and clinicians with substantially less information about how those decisions are reached or what standards govern them.
While the preceding examples illustrate how a company might seek an outright waiver of a covered provision, the SANDBOX Act’s modification authority poses similar risks.
In the labor context, the Fair Labor Standards Act (FLSA)115 directs the secretary of labor to define and limit the exemptions from its minimum wage and overtime requirements. Pursuant to that mandate, the Department of Labor (DOL) promulgated regulations under 29 C.F.R. Part 541116 that define which workers qualify as exempt administrative employees, mainly based on whether the employee’s primary duty involves exercising discretion and independent judgment. Workers who do not meet this exemption remain entitled under 29 U.S.C. § 207117 to time-and-a-half pay for hours worked beyond 40 per week. Seeking a waiver of the entire regulation would not serve a company’s interest here, since Part 541 already benefits companies and limits overtime. A company operating AI-driven workforce management systems could request that the duties test be modified so that any employee who reviews, oversees, or signs off on an AI system’s output is deemed to be exercising the “discretion and independent judgment” the administrative exemption requires. Because AI tools are increasingly embedded across scheduling, logistics, customer service, quality control, and countless other functions, broadly framed modification would not just reclassify a handful of AI supervisory roles. It would effectively convert the exemption from a narrow category covering genuine administrative judgment into a much wider one covering nearly any employee whose job involves AI oversight, regardless of how much actual discretion they exercise. This would cut off overtime eligibility for a large share of the company’s workforce. Without a modification, misclassifying these employees as exempt would expose the company to the DOL’s civil penalty authority, including penalties of up to $2,515 per violation for repeated or willful violations of the FLSA’s overtime requirements.118 Once a modification is in effect, the DOL is barred from pursuing that same penalty authority for the duration of the modification period.
Conclusion
Even if the SANDBOX Act never reaches the Senate floor, discussion drafts often serve as the starting point for future legislation. This proposal is significant because it reveals the scope of the deregulatory agenda its proponents seek to normalize. The SANDBOX Act is not a modest, targeted program to help innovative AI companies navigate outdated rules. Nor is it a carefully designed experiment to gather evidence for future regulatory decisions or a good-faith effort to harmonize emerging technology with federal law. Whatever its proponents claim, the SANDBOX Act is not an AI bill. It is a deregulatory proposal that uses AI as a pretext to place virtually the entire federal regulatory system under the authority of a single White House official.
The regulations affected by this program represent generations of hard-won protections in critical areas such as public health, environmental protection, workplace safety, and consumer protections. The SANDBOX Act would allow these safeguards to be reconsidered through an executive branch waiver process rather than the standard legislative process, primarily benefiting companies seeking exemptions from the rules that govern them. Importantly, unlike the temporary waivers the bill touts, the risk is lasting. The bill’s congressional review mechanism could permanently eliminate protections that took decades to establish based on a single company’s “temporary” waiver.
Congress should reject the SANDBOX Act and any similar proposal that uses AI as a vehicle for broad regulatory waivers without significant safeguards or attention to the material conditions under which such waivers would operate. A system that allows powerful actors to bypass rules designed to protect the public fails to create sustainable innovation. It risks undermining the very conditions necessary for widespread adoption. Public confidence in AI is already fragile. A policy agenda that weakens protections and shields companies from oversight risks reinforcing the perception that AI is a technology that benefits powerful actors at the public’s expense.
Acknowledgments
The authors would like to thank Aidan Mostashari for contributions to this report.