Digital Privacy, Cybersecurity, Artificial Intelligence & Automation Day One Policies

Project 2029 Contributors include a former Nokia executive and communications networking industry leader, a U.S. Department of Energy data analyst, and a UN Office for Digital and Emerging Technologies policy consultant. 

Editor’s Note: This brief proposes policies governing digital privacy, cybersecurity, artificial intelligence, and automation that are immediately implementable on ‘Day One’ of a 2029 Presidential administration. 1 These proposals are designed to take immediate steps toward protecting individual rights and freedoms as well as societal security, while ensuring the US leads in critical technology areas. We propose several actionable digital priorities for ‘Day One’ policy within three priority areas: (1) protect digital privacy; (2) address cybersecurity and digital infrastructure threats; and (3) provide safeguards around the rapid development of artificial intelligence (AI).

It is important to note that, as a Day One set of immediately implementable policies and actions, the proposals herein are not meant to exhaustively address the entire regulatory environment around these key topics.  2 States have already enacted a broad range of legislation to address concerns around data privacy, use and development of artificial intelligence (AI), and more. Notably, the state of California enacted the Consumer Privacy Rights Act, with similar legislation passed in Virginia, Colorado, Connecticut, and Utah.  California has also passed the Frontier AI Act (SB53) as well as several other AI laws addressing topics like age assurance, algorithmic pricing, and various regulations on social media.  There are excellent templates that could be expanded nationally, but this should be done through Congress with support from the Executive Branch.  The focus of this brief is strictly on Day One policies that can be implemented by the 2029 Presidential administration’s executive branch, ensuring a new administration delivers immediate results to safeguard the public from the dangers of unregulated AI development, government data collection, foreign and domestic cyber attacks, and the threat of quantum computing.

This paper is structured by identifying key problems in each of the three areas noted above and offering Day One solutions.  

  1. Protect Digital Privacy and Prevent Unnecessary Governmental Surveillance

  2. Address Cybersecurity and Digital Infrastructure Threats

  3. Provide Safeguards Around the Rapid Development of Artificial Intelligence (AI)

Protect Digital Privacy and Prevent Unnecessary Governmental Surveillance

Problem: The Federal government has undermined trust and privacy through secondary data abuse and centralization

Executive Order 14243, which was signed on March 20, 2025, mandated the dismantling of intragovernmental data silos and promoted unfettered intra- and inter-agency access to unclassified government and state-level data, has changed the way data is collected and used by the federal government. This order created new threats to citizens through secondary data abuse and the downsides of centralizing vast quantities of information about individual Americans for surveillance purposes.

In secondary data abuse cases, data collected about an individual for one purpose is then used by that government agency or another agency for a different purpose without the knowledge or consent of the person who provided that information. For example, a taxpayer who shared their personal information with the IRS may now have that information used against them by Immigration and Customs Enforcement. One of the key problems with secondary data abuse is that it breaks down trust in government, potentially making Americans more reluctant to share data and cooperate in processes like filing their taxes, costing America needed revenue and resources. 

While some argue that centralized data increases efficiency, it also creates new privacy risks through both the abuse of available data and security breaches.  A single database represents a single point of failure in the case of a cybersecurity breach, creating a prime target for domestic and foreign hackers.  And from the perspective of citizen trust, a single database containing so much personal information can be easily weaponized against citizens considered to be political enemies by those in power.

The broad scope of Executive Order 14243, coupled with the lack of stringent safeguards, may lead to the erosion of privacy rights and civil liberties, as data collected for one purpose could be repurposed for others without individuals' consent or knowledge. Such surveillance practices stand in clear violation of the Fourth Amendment, which protects “the right of the people to be secure in their persons, houses, papers, and effects, against unreasonable searches and seizures.”

Policy Solution: Deconstruct Mass Surveillance Databases and update the Privacy Act of 1974

A future presidential administration must immediately rescind Executive Order 14243, known as "Stopping Waste, Fraud, and Abuse by Eliminating Information Silos," and dismantle any corresponding infrastructure created by this order. Issued on March 20, 2025, this order mandated the dismantling of data silos and promoted unfettered intra- and inter-agency access to unclassified government and state-level data, raising significant concerns about the legal use of data, particularly with respect to the Privacy Act of 1974, and concerns about the weaponization and security of citizen information. Put simply, the widespread sharing of data across government agencies without the consent of citizens, or without any recourse for citizens to ensure the data is accurate, created enormous potential for the federal government to mishandle intrusive information about every citizen and resident.

To prevent further government collection of U.S. persons' information that violates privacy laws and intrudes on the lives of law-abiding citizens, a future administration must immediately issue a sweeping executive order to stop these types of data aggregation, sharing, and surveillance activities. The order shall:

  • Immediately bar inter-agency data-sharing arrangements involving personal or administrative data, including those held by the IRS, the U.S. Census Bureau, DMVs, educational institutions, utilities, and medical databases, unless explicitly authorized under the Privacy Act of 1974, § 552a(b). This includes suspending “matching programs” (§ 552a(o)–(u)), which entail automated comparisons of federal records against other datasets to identify discrepancies or targets, unless compliant with statutory notice, safeguards, and verification requirements. Federal agencies that published internal policies with the intent to subvert these laws must rescind such policies immediately. The Congressional oversight committees, with their full authority, must ensure that contracted companies and federal agencies are in compliance. 

  • Contracts with firms assisting governmental surveillance efforts through data aggregation, including companies such as Palantir Technologies, OpenAI, Anduril, etc., and any or all government contracts that are not aligned with the United States Constitution and in violation of Privacy laws, must be paused or cancelled until an open competition that meets appropriate guidelines is selected. Establish clear wind-down timelines for contracts that cannot be terminated immediately, requiring contractors to comply with safeguards under § 552a(e)(10) during transition periods.

  • To ensure that law enforcement and the Intelligence Community (IC) do not violate the US Constitution and federal laws, for any data that involves US persons and those present in the US, mandate the security tagging of such data. Security tagging is the process of attaching descriptive metadata labels (such as "Public," "Confidential," or "Personally Identifiable Information - PII") to datasets. It serves as a foundational pillar for cybersecurity, automating access controls, data loss prevention (DLP), and zero-trust security policies across an organization that includes US and non-US persons. Immediately rescind all internal policies that circumvent such laws. Ensure all centralized data systems that collect US persons and other legal non-US citizens are consistent with the collection limitation principle (§ 552a(e)(1)) and accuracy/timeliness requirements (§ 552a(e)(5)), which prohibit the indefinite maintenance of irrelevant, unnecessary, or unreliable records.

  • Guarantee individual rights of access and amendment to personal records (§ 552a(d)), including expedited correction processes for erroneous or outdated information. New cabinet members, once confirmed, must rescind any policies that are unlawful, illegal, or violate privacy laws and the US Constitution. 

  • Launch a Privacy Task Force within the Office of Management and Budget (OMB) with the assistance of the federal, state, and local law enforcement community to ensure illegal data-sharing and surveillance operations are in accordance with the US privacy laws and the Civil Liberties Act. This shall include auditing all federal data-sharing and surveillance operations, with authority to:

    • Investigate agency compliance with publication requirements for systems of records (§ 552a(e)(4));

    • Enforce disclosure restrictions (§ 552a(b));

    • Monitor civil remedies available to individuals due to violations (§ 552a(g));

    • Recommend criminal referrals where willful violations are identified (§ 552a(i));

    • Design a privacy-centered replacement framework that sets boundaries between individual agency databases, ensuring compliance with the Privacy Act while protecting civil liberties.

  • Direct the Privacy Task Force to assess gaps in the Electronic Communications Privacy Act (ECPA), which was written prior to the advent of smartphones, connected homes, chatbots, agentic AI 3, etc, and to produce a legislative recommendation to Congress within 180 days. In particular, prioritize the following areas for targeted ECPA updates, and request relevant agencies (including DOJ, Commerce, and OMB) to support the effort with implementation plans and higher internal standards. Focus areas shall include:

    • Warrant standards 4 for stored content

    • Non-disclosure orders

    • geofence/keyword warrants 5

    • Mobile location data

    • Reverse searches

    • CLOUD Act reform, which governs when U.S. law enforcement can compel American tech companies to hand over data stored abroad.

  • To immediately increase protection of civil liberties until Congress updates the ECPA, issue a memorandum directing the DoJ to issue guidance to federal prosecutors and investigators to voluntarily apply warrant standards in cases where the ECPA does not yet require it - e.g., for real-time location data, tower dumps, etc.

Address Cybersecurity and Digital Infrastructure Threats

Problem: The US is under persistent and extensive cyberattacks by foreign agents for multiple purposes

Cyberattacks in various forms threaten critical infrastructure (including communications, water, and energy), undermine election integrity, and expose data on US citizens to bad actors.  AI multiplies these threats considerably.  While the single greatest contributor to breaches was once the human element, within 5-10 years, quantum or hybrid systems will likely be able to fully exploit any infrastructure not hardened with quantum-safe cryptography and automated system configuration. Ongoing training and education are lacking and are becoming even more urgent as AI accelerates and amplifies the problem. 

A few examples of threats:

  1. In 2024, the People’s Republic of China’s (PRC) cyber espionage efforts rose 150% compared to the previous year, according to CrowdStrike. China’s targeted attacks on the financial services, media, manufacturing, and industrial sectors increased by 300%. A Homeland Security Committee report identified that the most unprecedented of these intrusions, Salt Typhoon, compromised at least nine major telecommunications providers in 2024- this included accessing the phones of presidential candidates and potentially gaining access to data from nearly every American.  

  2. Interference in the 2024 and 2016 elections has been widely documented, with Russia being the most active in its disinformation campaign. Russia sought to reduce American support for Ukraine and to influence the Presidential election toward the candidate whom they believed would be more favorable to Russia

  3. In March 2026 alone, a US water facility was hit with more than 1,900 hacking attempts from around the world, principally Iran.  While many of these hacks are less serious, a growing number of attacks target internet-facing operational technology (OT) devices, including programmable logic controllers (PLCs) that can disrupt water supply, endanger water treatment, and more.

Policy Solution: Declare a National Emergency on Foreign Cybersecurity and Digital Infrastructure Threats

To immediately protect Americans from escalating cyber and digital threats posed by foreign actors, the President shall declare a national emergency on foreign cybersecurity and digital infrastructure threats under the International Emergency Economic Powers Act (IEEPA) (50 U.S.C. §§ 1701–1707). This act authorizes the President to regulate commerce, communication, and technological exchanges in response to "unusual and extraordinary threats" originating from abroad that imperil national security, foreign policy, or the economy. The emergency declaration should specifically designate any cyber and digital activities from foreign entities that involve interfering with our national security, foreign policy, or the economy as "unusual and extraordinary threats," including:

  • Malicious cyber activities, such as

    • Malware,

    • Phishing,

    • Denial-of-Service (DoS) and distributed denial of service attacks (DDOS),

    • Operational Technology (OT) attacks targeting the control systems of critical infrastructure,

    • Data breaches,

    • Cybercrime,

    • Cyber espionage,

    • Insider threats,

    • and Supply chain attacks;

  • Digital surveillance;

  • Manipulation of networks, including communication networks;

  • Foreign malign influence operations and disinformation campaigns, including coordinated inauthentic behavior and state-sponsored propaganda networks, along with the financial, technical, and material infrastructure that supports them;

  • Other emergent methods and processes that are not yet in use.

Upon presidential declaration, the Department of the Treasury, acting through the Office of Foreign Assets Control (OFAC), shall be directed to freeze assets, prohibit all financial transactions, and block the import or export of goods, services, and technology involving specifically identified foreign individuals, organizations, or entities responsible for such malicious activity. This shall be done in coordination with the Department of Commerce on export control measures and the Department of Justice on enforcement and prosecution of violations. The General Services Administration and all federal agencies shall be directed to suspend identified entities and any U.S. entities found to be material support providers or affiliates from eligibility for federal contracts, grants, and procurement relationships. These measures shall not extend to a foreign country as a whole unless it is determined that the foreign government itself directed, sponsored, and/or knowingly facilitated the activity in question.

To ensure these designations rest on continuous, credible intelligence rather than an ad hoc case-by-case review, the Director of National Intelligence (DNI) shall rebuild the Foreign Malign Influence Center (FMIC), an Office of the Director of National Intelligence (ODNI) mission center whose staff and functions were folded into other directorates in August 2025. This shall include restoring its statutory role as the intelligence community’s primary body for analyzing and issuing warnings on foreign malign influence campaigns under 50 U.S.C. § 3059. If the Center is formally terminated under the statute’s post-2028 termination authority before the 2029 administration takes office, the Director of National Intelligence shall instead reestablish the Center and its statutory functions within ODNI, consistent with that same statutory authorization. FMIC’s assessments shall serve as the evidentiary basis for Treasury’s designations under this order, extending the model Executive Order 13848 already uses for elections to foreign influence operations more broadly. 

Concurrently, a new administration shall direct the Department of Commerce to block all imports and exports of the designated offenders and prohibit any American business transactions with them, including the blocking of exports, reexports, or in-country transfers of sensitive U.S. technologies. Offending foreign firms, such as telecommunications providers, software developers, and/or hardware manufacturers, shall be placed on the Entity List under the Export Administration Regulations (EAR), restricting their access to U.S. goods, services, and technology.

To further defend domestic systems, the Cybersecurity and Infrastructure Security Agency (CISA) and the Federal Communications Commission (FCC) shall put into effect emergency directives mandating infrastructure protections and allowing full expensing of any and all upgrades. These shall include requiring firms to report cyber breaches, reroute compromised internet traffic, and isolate digital assets vulnerable to foreign surveillance. Additionally, the Department of Homeland Security (DHS) and the National Security Agency (NSA) shall coordinate expanded threat mitigation and surveillance protocols to monitor foreign actors’ digital intrusions, especially in sectors such as energy, transportation, finance, and healthcare. Such action must include clearly defined guardrails to ensure the Fourth Amendment rights of Americans are protected, ensuring these protocols only focus on foreign digital infrastructure threats. Any surveillance and mitigation must be done respecting the rule of law, including relevant search warrants.

CISA funding must be immediately rebuilt and restored to FY2024 levels. In particular, a new administration should restore the Election Security Program to support states in identifying and mitigating cyber threats and risks that threaten election integrity. 

To reduce the threat of human error, a new administration shall instruct CISA to launch a task force to work with commercial sectors as well as universities to identify and consistently deploy threat-countering solutions across executive branch agencies that do not rely upon reliable human performance (e.g., mandatory two-factor authentication, no passwords, quantum-safe cryptography).   

The President shall also appoint a senior civilian official in the Office of the President to manage and direct the execution of the state of emergency in order to ensure civilian primacy over the domestic cyber environment, which is central to the economy and protection of civil liberties and privacy.  CISA, other elements of DHS, and the Department of Commerce should have leading roles and be provided the resources to execute these roles. National security agencies should have a supporting role as well. 

Problem: The rapid development of quantum technologies combined with Artificial Intelligence (AI) threatens everything from global banking systems to critical infrastructure.

In March 2026, Anthropic determined that its latest version of Claude Mythos was too dangerous to release publicly due to its ability not only to identify undiscovered software vulnerabilities but also to weaponize them. In fact, Mythos found previously undiscovered vulnerabilities in every major operating system and web browser. Instead, Anthropic launched an initiative, “Project Glasswing,” a coalition of leading software, hardware, and cybersecurity organizations working together with a restricted-access version of Claude Mythos to identify and patch vulnerabilities in critical systems before models with similar capabilities become widely available.  

In early 2026, two separate studies found methods to reduce the requirements (number of qubits 6 ) needed for quantum computing to be able to break current encryption systems, effectively bringing forward the date when today’s cryptography, especially one of the oldest and most widespread public-key cryptosystems - Rivest-Shamir-Adleman (RSA) -  will likely be ineffective.  This has broad potential ramifications: everything from cryptocurrency collapse to mass privacy invasion to infrastructure attacks.  While the need for quantum-resistant algorithms has been understood and work to replace RSA with those is ongoing, the transition to a new encryption typically takes 10+ years.  

Policy Solution: Reinvest in US scientific research.

Direct the National Science Foundation (NSF) to review requirements for working with industry and the scientific community, and present within 120 days to the President and to Congress what they believe is needed to restore basic AI and quantum research funding to support US leadership in research and development (R&D).

Policy Solution: Strengthen Cybersecurity Standards

Direct the Department of Commerce to immediately update the National Institute of Standards and Technology (NIST) Cybersecurity Framework (CSF 2.0) and, in particular, to provide mandates with accountability and penalties for non-compliance. Direct the Department of Commerce to also determine the funding and approach needed to support effective compliance monitoring. The EU NIS2 Directive (Network and Information Systems) provides an example of what could be proposed, including the introduction of mandatory requirements rather than recommendations only for key sectors, incident reporting deadlines, management liability for compliance failures, and supply chain audits.  CISA and relevant national security agencies should support this effort actively with relevant insights, particularly as threats evolve rapidly over the coming months and years.

NIST CSF updates should provide a mandate for all critical government sectors and recommendations for the private sector to implement Post-Quantum Cryptography (PQC) to counter future “harvest now, decrypt later” threats.

Provide Safeguards Around the Rapid Development of Artificial Intelligence (AI)

In this section, we identify several major issues related to the rapid development of AI. 

Problem: AI is a critical set of technologies for the future, but it is evolving rapidly and poses significant risks.  

Investment in AI technologies exceeded $200B in the US in 2025, and spending just for data centers worldwide is projected to be $2.9 trillion from 2025 to 2028. Responsible development and application of the growing set of technologies known as AI has the potential to help solve urgent and complex challenges, including mitigating the effects of climate change and pandemics, while helping to make our world safer, more productive, and more innovative. But ensuring AI realizes its full potential requires accounting for a significant and ever-changing set of risks. Those risks range from near-term societal disruptions to existential threats to Americans and the planet.  Near-term disruptions include the amplification of bias and widespread misinformation via deepfakes, massive job displacement, and autonomous weapons development. Advanced AI systems could lead to catastrophic risks if control is lost.

Given the very high potential positive and negative impact of AI, and the rapid speed of its development, it is urgent and necessary for the Federal Government to establish policies, principles, laws, and regulations to advance and govern the development and use of AI.  Moreover, given the existential threat that AI poses, the US must join other countries to define global agreements and alignment.  Something akin to a nuclear non-proliferation treaty for AI is just not realistic.  While nuclear weapons have negative connotations across the international community, nuclear technology has provided a positive impact on other global resources, such as electricity, medical applications, and powering our global infrastructure. However, the use of nuclear weapons against other countries, such as the use of "nuclear-laden bombs," clearly violates bilateral agreements between countries. 

The current NATO AI strategy and the Association of Southeast Asian Nations (ASEAN) AI & Governance guide provide an expansive AI strategy across our allied partners. However, the US lacks a federal commission on AI. Effective immediately, Executive Order 14110 of October 30, 2023, known as “Safe, Secure, and Trustworthy Development and Use of Artificial Intelligence," must be reinstated by the new administration.  But our nation can insist on forming a group analogous to the World Health Organization (WHO). Just as the World Health Organization tracks and responds to threats that move easily across borders and shares relevant information to mitigate them, so too is a global Cyberthreat organization needed to alert and mitigate existential threats from AI and quantum in particular.  A new administration should appoint a task force to work with other countries through the UN to develop such an organization and set of agreements.

Policy Solution: Rescind Executive Order 14365 “Ensuring a National Policy Framework for Artificial Intelligence”  and Restore Executive Order EO14110 "Safe, Secure, and Trustworthy Development and Use of Artificial Intelligence".

To responsibly govern the advent of Artificial Intelligence (AI) technologies currently permeating American society, a future president should swiftly restore the recently rescinded Executive Order 14110, known as “Safe, Secure, and Trustworthy Development and Use of Artificial Intelligence.” This order, originally signed on October 30, 2023, established a comprehensive federal framework to guide the development and deployment of AI technologies, emphasizing safety, security, equity, and innovation. 

The order mandated that developers of powerful AI systems share, before system release, safety test results with the federal government and directed the National Institute of Standards and Technology (NIST) to develop rigorous safety and security standards for AI tools. The order also implemented guidelines to prevent AI-related discrimination in areas such as housing, healthcare, and employment, and required transparency measures like labeling AI-generated content to inform users. If necessary, the EO should be updated to ensure it addresses Agentic AI. 3

Furthermore, EO 14110 launched programs to train AI professionals and authorized the creation of a job portal at AI.gov to attract AI talent to federal agencies. It also utilized the Defense Production Act to require developers of powerful AI systems to disclose information about model training and cybersecurity practices to the Department of Commerce and other designated federal agencies responsible for national security and technology oversight. Lastly, the order directed the Department of Energy to assess AI-related risks, such as potential contributions to biological or chemical threats.

As a prerequisite, a future president must rescind Executive Order 14365, which was largely designed to enable the federal government to override state-level AI safety laws, and in particular the transparency and safety requirements that California had established in SB53, the Transparency in Frontier Artificial Intelligence Act.  SB53 targets, for example, large AI models, requiring developers to report safety protocols, prevent "catastrophic risks" (chemical, biological, or nuclear weapons), and report critical incidents to the State Office of Emergency Services. It also imposes strict transparency requirements, including public disclosure of safety frameworks and mandated labeling for "predatory" chatbots.

Problem: AI is projected to replace between 6 and 14% of the US workforce by 2030. 

One of the key challenges presented by AI is the potential for significant labor market reshaping. In particular, a large number of job losses, especially in entry-level roles, will disproportionately affect young and low-income Americans. Across global businesses, AI is fueling record investment and usage. U.S. private AI investment climbed to $109.1 billion in 2024, nearly twelve times China's $9.3 billion and twenty-four times the U.K.'s $4.5 billion, per Stanford's 2025 AI Index Report. The AI momentum, globally, continues to expand funding and investment, from governments to private investment. Rapid use of AI across the global workforce continues to create an assumption that AI will replace their jobs. 

The distribution of income and wealth has worsened persistently in the US since the 1970s.  According to an Oxfam study in 2025, the richest 1% of households in the United States have accumulated almost 1,000 times more wealth than the poorest 20% over the last three and a half decades, and economic inequality reflects ongoing disparities of race, ethnicity, and gender.  As of 2022, the average wealth of a household headed by a White man was 16 times higher than that of households headed by a Black or Latina woman (see above Oxfam study).  While there are many contributing factors to this, one is certainly the erosion of workers’ rights.  AI has the potential to contribute to even more rampant inequality.  

While job loss is the top-of-mind labor issue related to AI, a larger and more pervasive topic is how AI is integrated into work and management.  In the European Union’s AI Act, for example, human resource systems' use of AI in recruitment and selection, worker management, and performance monitoring is classified as high risk and therefore is required to meet strict obligations, including mandatory human oversight, high-quality data, and transparency, as these systems require rigorous risk assessment and technical documentation.  And some activities, e.g., social scoring and analyzing employee emotions at work, are simply prohibited by the Act.  Some similar protections are beginning to appear in some US state legislation, but a national framework is urgently needed

Policy Solution: Strengthen workers’ rights, including gig workers and independent contractors 

A future administration shall issue a presidential memorandum directing the Office of Information and Regulatory Affairs (OIRA) to use its regulatory review process to promote workforce protection to help mitigate the impact of AI displacement. This memorandum should direct OIRA to revise cost-benefit tests to promote regulatory policies that reflect new labor developments and ensure that new regulations do not accelerate the displacement of employees due to AI technologies. The memorandum shall also require OIRA to play a more proactive role in partnering with federal agencies to explore, promote, and undertake regulatory initiatives that are likely to yield significant protections for American workers against the threat of AI displacement.

Productivity increases should equally benefit management and workers (by way of either increased pay or reduced work hours for the same pay). As a result, a new administration shall issue an Executive Order directing the SEC to mandate that companies disclose how this has been accomplished in quarterly and annual financial reporting.

A future administration shall also appoint a National Labor Relations Board (NLRB) General Counsel who is committed to aggressively protecting the right of private employees to organize in order to improve their working conditions and protection against AI displacement. This General Counsel shall be committed to investigating and penalizing unfair AI labor practices by issuing complaints against employers before the NLRB’s Administrative Law Judges. If the ALJ or Board finds violations, the NLRB can order remedies such as reinstatement of employees, back pay, cease and desist orders, and posting notices about workers’ rights

Similarly, a future administration shall appoint a Secretary of Labor who is committed to publicly advocating against right-to-work laws that hurt union organizing efforts, which may indirectly inhibit efforts to protect employees from AI displacement. 

Problem: Federal workers have been the subject of politically motivated purges in the name of productivity

Policy Solution: Protect Federal Workers from AI Displacement and Politically Motivated Purges

The federal government employs over 2.4 million Americans, making it one of the largest employers nationwide. Its size, therefore, necessitates protections for federal employees against AI displacement. A future presidential administration shall work to restore and expand employment protections from recently rescinded Executive Orders 14003 (“Protecting the Federal Workforce”) and 14055 (“Nondisplacement of Qualified Workers Under Service Contracts”) to enhance protections for career civil servants and federal contractors against AI displacement and politically motivated purges. A new executive order must strengthen protections from these original orders by:

  • Mandating that productivity increases should equally benefit management and workers (by way of either increased pay or reduced work hours for the same pay).

  • Ensuring collective bargaining rights that allow career civil servants to advocate for protection against AI displacement and politically motivated purges. This action should include rescinding Executive Order 14251 ("Exclusions from Federal Labor-Management Relations Programs”), which stripped thousands of federal employees of the ability to unionize, negotiate working conditions, or engage in grievance proceedings. 

  • Directing federal agencies to engage in good-faith bargaining with labor unions over “permissive subjects” of bargaining, such as staffing patterns and technology use.

  • Requiring that when a federal service contract expires, and a new contract is awarded for the same or similar services at the same location, the successor contractor must offer employment to the non-managerial employees of the predecessor contractor. This will protect against new contractors replacing previous contractors with AI technology, while also reducing disruption in federal services, maintaining workforce continuity, and protecting experienced workers from job loss due to contract transitions, thereby reducing training costs associated with onboarding new employees.

Problem: Key AI technologies are being developed by a small number of companies in an already oligopolistic technology industry.  

There are three key inputs to AI systems and applications that are particularly vulnerable to anticompetitive behavior.  These are: 

  1. The graphics processing units (GPUs) used to train AI models (NVIDIA currently controls 80% of the world’s AI chip market). 

  2. Generative AI foundation models such as GPT (developed by OpenAI with significant investment from Microsoft) and Google’s Gemini are trained on massive unlabeled datasets, some of which include copyright-protected data that has drawn multiple lawsuits, to handle a wide variety of tasks, from translating text to analyzing medical images. 

  3. Data is the life force of AI — Google, Amazon, Microsoft, Meta, and Apple have captured not only vast amounts in raw form, but through their various services and algorithms, they also have the tremendous ability to make connections between data sources. Google search alone has 4 billion active users and handles more than 10 billion searches per day.

Policy Solution: Direct the FTC to apply the full force of federal antitrust statutes to govern AI competition

To preserve fair competition in the evolving digital economy, a future administration shall issue an Executive Order directing the Federal Trade Commission (FTC) to apply the full force of federal antitrust statutes, including the Sherman Antitrust Act (15 U.S.C. §§ 1–2), the Clayton Antitrust Act (15 U.S.C. §§ 12–27), and the Federal Trade Commission Act (15 U.S.C. §§ 41–58), to address emerging forms of anti-competitive behavior stemming from the deployment and consolidation of artificial intelligence technologies. Where necessary, the Hart–Scott–Rodino Antitrust Improvements Act (15 U.S.C. § 18a) should also be invoked to scrutinize AI-related mergers and acquisitions that threaten competition.

As dominant firms increasingly integrate proprietary AI systems into their core operations, there is growing concern that such technologies are being used not merely to enhance productivity but to entrench monopoly power, suppress labor competition, and foreclose opportunities for new entrants. The FTC, consistent with its statutory authority, shall be instructed to expand its enforcement framework to investigate and, where warranted, prosecute AI-related conduct that violates these statutes.

Specifically, the FTC shall prioritize investigations into AI practices that:

  • Violate Sherman Act § 1 (15 U.S.C. § 1) by facilitating unlawful collusion among competitors, such as coordinated use of shared AI vendors, predictive algorithms, or pricing models to suppress wages, eliminate labor demand, or fix prices;

  • Violate Sherman Act § 2 (15 U.S.C. § 2) by reinforcing monopolies through exclusionary conduct, such as leveraging proprietary AI systems as barriers to entry in critical markets, including digital advertising, e-commerce, finance, and logistics;

  • Violate Clayton Act § 7 (15 U.S.C. § 18) by using mergers and acquisitions in the AI sector to consolidate control over essential infrastructure, including compute resources, large-scale training data, or cloud access, thereby stifling innovation and limiting downstream competition;

  • Violate the FTC Act § 5 (15 U.S.C. § 45) by engaging in “unfair methods of competition” through vertical integration of AI supply chains, where control of infrastructure is exploited to dominate adjacent or dependent markets.

The FTC shall also issue updated policy guidance clarifying how existing antitrust laws apply to AI-related practices, including algorithmic coordination, predictive pricing, labor market displacement, and vertical integration of AI infrastructure. Such guidance would provide notice to industry and workers alike, reinforcing that innovation cannot lawfully be weaponized to erode competition or disempower the American workforce.

Problem: AI has a bias problem, which reflects societal biases built into the data we train it on.  

AI is only as useful as the data it is trained on.  Biases in hiring, health care, facial recognition, and more have all been widely documented. As in real life, these biases disadvantage women and people of color, people with disabilities, as well as older workers.

Policy Solution: Rescind EO 14310 (“Preventing Woke AI in the Federal Government”), which barred federal funding for AI models trained on diversity, equity, and inclusion (DEI) methods.

A future administration must issue a directive rescinding Executive Order 14319 (“Preventing Woke AI in the Federal Government”), which barred federal funding for AI models trained on diversity, equity, and inclusion (DEI) methods. This directive undermined necessary DEI integration aimed at combating bias and promoting fairness within AI models.

Problem:  Data Centers are being built at a tremendous pace in the US, putting enormous strains on energy, water, and land use, as well as driving up carbon emissions.

A mid-sized data center consumes as much water as a small town, while larger ones require up to 5 million gallons of water every day—as much as a city of 50,000 people. Moreover, a conventional data center handling cloud storage for work documents or streaming videos draws as much electricity as 10,000 to 25,000 households, according to the International Energy Agency. Newer AI data centers can use as much power as 100,000 homes combined. And of course, most of that energy today is driving up carbon emissions.

Policy Solution: Restore safeguards and protections against the significant environmental harms posed by large computing facilities.

A future administration must first rescind Executive Order 14318 (“Accelerating Federal Permitting of Data Center Infrastructure”), which weakened environmental protections for data centers. This directive stripped away safeguards against the significant environmental harms posed by large computing facilities. Additional action must include a sweeping executive order to restore environmental and community benefit protections for data centers and embed them directly into AI procurement and oversight. The order must:

  • Mandate environmental review and community benefits agreements for data center projects while integrating environmental justice considerations. A future administration must direct the Environmental Protection Agency (EPA), in coordination with the Department of Energy (DOE) and the OMB, to reinstate full National Environmental Policy Act (NEPA) requirements (42 U.S.C. §§ 4321–4370h) for all federally funded, permitted, or federally sited data center projects. Agencies shall, where feasible, suspend approvals issued under Executive Order 14318 and require Environmental Assessments (EAs) or full Environmental Impact Statements (EISs) before proceeding.

As part of the NEPA review and any federal siting approvals, data center operators shall be required to:

  • Prioritize siting away from overburdened communities, using cumulative environmental and demographic data;

  • Avoid environmentally protected lands, including wetlands, critical habitats, and conservation areas;

  • Conduct a cumulative impact and Environmental Justice assessment for any proposed site, submitting findings to the Environmental Protection Agency (EPA) and the Department of Energy (DOE) for review prior to approval;

  • Incorporate mitigation measures where unavoidable impacts on disadvantaged communities or sensitive ecosystems occur, including community benefit programs or environmental offsets.

  • Direct the Secretary of Energy to immediately reinstate and strengthen internal guidance re-establishing the Department of Energy’s (DOE) Community Benefits Plan requirement, which the current administration suspended in January 2025. New guidance shall extend to the DOE’s own AI data center land leases and Title 17 loan guarantee-backed power projects, including the four federal sites already opened to private development (Idaho National Laboratory, the Oak Ridge Reservation, the Paducah Site, and the Savannah River Site). 

  • Direct the EPA and DOE to require developers and financial backers of any federally funded, financed, or sited data center project to execute a binding Community Benefit Agreement with affected local and Tribal governments. Such agreements must cover disruption-minimizing site and technology commitments, such as advanced cooling and noise abatement, along with direct compensatory measures, including infrastructure investments and workforce agreements. Compliance with these requirements shall, where possible, be a condition of federal approval, funding, or permitting. The EPA and DOE shall jointly enforce this directive through permit modification, denial, or referral to the DOJ for failure to comply. 

  • Direct the EPA to require the cumulative impact of all data centers, including those with on-site fossil generation and those that trigger increased local peaker plant (plants that run only under extra demand) reliance, to meet the Clean Air Act National Ambient Air Quality Standards. For any datacenter exceeding National Ambient Air Quality Standards due to on-site fossil generation or increased local peaker plant reliance, the EPA shall, within 180 days of the determination, require the datacenter operator or facility owner to secure verifiable emissions offsets and/or establish a community mitigation fund to remediate environmental and public health impacts.

  • Enforce water- and energy-use limits for all datacenters by directing the DOE, in coordination with the EPA, to:

  • Establish maximum allowable water consumption per megawatt of IT load;

  • Prohibit evaporative cooling in water-stressed basins;

  • Require renewable or low-carbon electricity supply contracts consistent with guidelines outlined in the since-revoked Executive Order 14057 (“Catalyzing Clean Energy Industries and Jobs Through Federal Sustainability”).

Direct the Department of Justice (DOJ) to prosecute violations of these regulations under applicable statutes, including:

  • DOE and EPA regulations, as well as NEPA conditions;

  • Clean Water Act (33 U.S.C. §§ 1251, 1311, 1319) for violations involving water pollution, discharge limits, or failure to report effluent accurately;

  • Safe Drinking Water Act (42 U.S.C. §§ 300h, 300i) for violations affecting public water systems, contamination reporting, or failure to comply with administrative orders;

  • Clean Air Act (42 U.S.C. §§ 7413) for emissions or energy-use noncompliance that contributes to exceeding National Ambient Air Quality Standards;

  • 18 U.S.C. § 1001 for knowingly providing false or misleading data in compliance filings or water/energy reporting;

  • State or local water-use permit violations where federally regulated data centers exceed legally authorized withdrawal limits, with the DOJ empowered to assist in enforcing laws through coordination with state authorities.

  • Invoke Title III of the Defense Production Act (50 U.S.C. §§ 45314534) to incentivize domestic manufacturing of energy-efficient servers, advanced cooling systems, and grid-interactive storage. Agencies shall be directed to prioritize contracts with vendors deploying these technologies.

  • Direct the Treasury Secretary, the Financial Stability Oversight Council (FSOC), and the Securities and Exchange Commission (SEC) to require data center operators to disclose climate and water-use risks as material information under securities law. These disclosures shall cover exposure to emissions, water consumption, and climate-related operational risks, ensuring that investors, federal agencies, and other stakeholders can assess financial and regulatory vulnerabilities consistent with requirements in the since-revoked Executive Order 14030 (“Climate-Related Financial Risk”). The SEC shall also monitor and enforce compliance in the secondary financial markets, imposing penalties such as civil fines, injunctions, or rescission of misleading disclosures for failures to report, misstatements, or omissions of material climate and water-use risks.

  • Direct the OMB and General Services Administration (GSA) to require vendors bidding on federal AI or data center contracts to disclose lifecycle carbon emissions, water consumption, and cooling technologies, while giving preference to vendors using 24/7 carbon-free electricity or on-site renewable integration. Under 41 U.S.C. §§ 3301 and 3307, OMB and GSA shall update FAR templates to:

  • Add a “Sustainability & Environmental Performance” section;

  • Incorporate environmental criteria as technical evaluation factors under FAR Part 15;

  • Include enforceable FAR Part 52 clauses requiring annual reporting and verification.

Violations shall trigger contract remedies, including termination, withholding of payments, or penalties under the False Claims Act.

Footnotes

  1.  See Explainer: What are Project 2029 Day One Policies

  2. See our Brief Day One and Beyond: Federal Education Policy Actions for 2029 for recommendations on AI in schools

  3. Agentic AI refers to decision-making systems that act autonomously with limited human interaction to achieve sets of goals. Agentic AI coordinates multiple AI agents and manages communication, data sharing, task distribution, etc. among them.  Agentic AI can use multiple tools and consult multiple databases and even call on other IT systems via Application Programming Interfaces (APIs) without human involvement.  This creates new opportunities for efficiency and accuracy but also creates new opportunities risks, especially to digital privacy, bias, and decision transparency. 

  4. Warrant standards refer to meeting the requirements for a search warrant.  The Fourth Amendment of the Constitution prohibits unreasonable searches and seizures.  Thus, to obtain a search warrant, law enforcement must establish probable cause that the materials sought are contraband, evidence that will “aid in a particular apprehension or conviction,” or otherwise “seizable by virtue of being connected with criminal activity.” Law enforcement must also demonstrate “a fair probability” that these materials “will be found in a particular place.” Source: https://www.congress.gov/crs_external_products/IF/PDF/IF13169/IF13169.1.pdf

  5.  A geofence warrant or a reverse location warrant is a search warrant issued by a court to allow law enforcement to search a database to find all active mobile devices within a particular geofence area.

  6. In quantum computing, a qubit (/ˈkjuːbɪt/) or quantum bit is a basic unit of quantum information, the quantum version of the classic binary bit.