All Articles

Security Clearance

Federal vs. State AI Regulation: What Executive Order 14365 Means for Defense Contractors and the Cleared Workforce

11 min readJuly 2026Attorney Advertising
By Russell Roby, Esq.Last updated July 2026

Executive Order 14365 seeks to establish a national framework for artificial intelligence while challenging conflicting state AI laws. At the same time, separate federal directives are accelerating AI adoption and cybersecurity requirements across the defense and intelligence enterprise. For defense contractors and security-cleared organizations, understanding both developments is essential, because AI increasingly affects hiring, insider-threat programs, personnel monitoring, and national security systems.

In Short

Executive Order 14365 (Dec. 11, 2025) sets a federal policy for a "minimally burdensome" national AI framework and directs a DOJ task force to challenge conflicting state laws. An executive order does not preempt state law on its own — preemption ordinarily requires a federal statute, though executive action implementing valid statutory authority can carry preemptive effect. Existing state AI laws remain enforceable while the challenges proceed. The federal posture has a second front: the June 2, 2026 order hardening National Security Systems and defense systems with AI-enabled cyber defenses, plus a June 5 memorandum on AI across the defense and intelligence enterprise. A light touch on the states; hands-on on national security. For the cleared community, the fight lands where AI meets hiring, insider-threat monitoring, and personnel screening — the same tools states are regulating and federal security rules already govern. The durable move is governance that survives either outcome, not a bet on which sovereign wins.

The Order, in Plain Terms

On December 11, 2025, President Trump signed Executive Order 14365, titled Ensuring a National Policy Framework for Artificial Intelligence. Its stated aim is to sustain American AI leadership through a single, "minimally burdensome" national framework and to reduce what the Administration characterizes as a costly patchwork of divergent state laws. To that end, the order directs several coordinated federal actions:

  • An AI Litigation Task Force at the Department of Justice, to be established within 30 days, charged with challenging state AI laws deemed inconsistent with federal policy — on theories including interference with interstate commerce, conflict with existing federal regulation, and First Amendment concerns;
  • A Commerce Department evaluation, within 90 days, to identify "onerous" state AI laws; and
  • Funding leverage, conditioning certain federal broadband dollars on states' willingness to pause enforcement of AI statutes the Administration views as conflicting.

The order follows a familiar legislative trajectory. A proposed ten-year moratorium on state AI enforcement was stripped from the budget reconciliation package after the Senate voted 99–1 to remove it, and preemption language likewise failed to make it into the FY2026 National Defense Authorization Act. The EO is the executive-branch route to a goal Congress declined to enact.

Why an Executive Order Cannot End the Argument

Here is the point most coverage rushes past: an executive order does not, by itself, preempt state law. Under our constitutional structure, preemption ordinarily flows from federal statutes enacted by Congress, although executive action may carry preemptive effect when implementing valid statutory authority. EO 14365 can direct litigation, marshal agency evaluations, and attach conditions to federal funds — but standing alone, it cannot wave state statutes out of existence.

The practical consequence is a period of contested authority. A coalition of state attorneys general has already signaled resistance to federal efforts to constrain state AI regulation, and the Task Force's suits will raise significant questions of federalism, the spending power, and the limits of executive action. Colorado, for its part, repealed and replaced its comprehensive AI Act with a narrower automated-decision statute effective in 2027, illustrating that the state regulatory landscape continues to evolve even without federal intervention. Until courts resolve these challenges, existing state AI laws remain in force, and regulated parties remain subject to them. Betting on preemption before a court has ruled is not a compliance strategy.

The Other Federal Front: National Security Systems and Defense AI

Read alone, EO 14365 suggests an administration that simply wants less AI regulation. That is only half the picture — and for the cleared community, the less familiar half. Where national security is at stake, the same administration is moving assertively.

On June 2, 2026, the President signed a separate Executive Order, Promoting Advanced Artificial Intelligence Innovation and Security — the third major AI order of the term, and a marked shift toward operational security. It directs federal agencies on aggressive 30- and 60-day timelines to harden their systems with AI-enabled cyber defenses. Notably, within 30 days the Committee on National Security Systems was directed to prioritize the cyber defense of National Security Systems (as defined in 44 U.S.C. § 3552(b)(6)(A)), and the Secretary of War (the order's own terminology, following the 2025 redesignation of the Department of Defense as the Department of War) to do the same for defense information systems, while CISA issues binding operational directives for civilian federal systems. The order also stands up an AI cybersecurity clearinghouse (Treasury, with NSA and CISA) to find and fix software vulnerabilities, and builds a voluntary framework under which frontier-model developers may give the government early, pre-release access to covered models. Importantly, it expressly disclaims any mandatory licensing, preclearance, or permitting requirement.

Three days later, on June 5, 2026, the President issued a National Security Presidential Memorandum on Artificial Intelligence in the National Security Enterprise, framing AI procurement and use for defense and intelligence around four pillars — Adoption, Adaptation, Assurance, and Accountability.

Put the two fronts together and the federal position resolves into something more coherent than "deregulation": a light touch toward commercial AI regulation at the state level, and a hands-on approach toward AI inside the national-security enterprise. For a defense contractor, that is the operative reality — fewer external state constraints on commercial tools, but accelerating federal expectations on the systems and models that touch classified missions.

Where This Reaches the Cleared and Defense Community

For most readers of national-security commentary, AI regulation can feel like a consumer-tech story. It is not. Cleared employers and defense contractors deploy artificial intelligence squarely inside the functions states are now regulating — and inside functions federal security law already governs. Three intersections deserve attention.

Automated hiring and screening

State automated-decision and AI-transparency laws increasingly reach employment tools: bias audits, candidate notice, human-review requirements, and recordkeeping. A cleared contractor using an AI screening system to build a candidate pipeline may sit under a state employment-AI statute while simultaneously managing federal suitability and eligibility obligations. The federal framework the EO envisions would, if it holds, change which rules control — but today both can apply at once.

Insider-threat behavioral analytics

Insider-threat programs under 32 CFR Part 117 increasingly rely on user and entity behavior analytics (UEBA) and AI-driven risk scoring to detect anomalies. That behavioral analytics layer implicates state transparency and automated-decision rules, employee-privacy considerations, and the accuracy concerns that follow any high-false-positive system. A defense contractor's Insider Threat Program Senior Official (ITPSO) can find the program caught between a federal security mandate to monitor and a state regime demanding disclosure and governance around exactly that monitoring. Cleared facilities building out that written program can start with our Insider Threat Program Starter Templates.

Personnel monitoring and consequential decisions

Where AI materially influences a decision about someone's employment, access, or standing, the "consequential decision" frameworks emerging at the state level become applicable — and the interplay with federal continuous-vetting and clearance processes is unsettled. The direction of EO 14365 is toward a single federal answer; the reality on the ground is overlapping obligations.

What to Do Now

  • Comply with state law as it stands. It remains enforceable until a court rules otherwise. A pending federal challenge is not a defense to present non-compliance.
  • Inventory your AI decision points. Map where AI drives or materially influences consequential decisions in hiring, insider-threat, and personnel functions.
  • Document data provenance, model governance, and meaningful human review. Maintain records of training-data provenance, model use, and the point at which a human exercises judgment — the three concepts appearing repeatedly across AI frameworks.
  • Reconcile the security-and-transparency tension. Align insider-threat and screening tools so they satisfy federal security obligations under 32 CFR Part 117 and applicable state transparency and governance rules.
  • Prepare for the national-security clock. If you support National Security Systems or defense information systems, anticipate accelerated AI-enabled cyber-defense requirements flowing from the June 2, 2026 order and the June 5 memorandum, on 30- and 60-day agency timelines.
  • Watch the mechanisms. Track the DOJ AI Litigation Task Force, the Commerce evaluation of state laws, the CISA directives and AI cybersecurity clearinghouse, and state-level responses; the compliance floor may shift with each.

The federal-versus-state contest over AI will not be settled by a single order or a single lawsuit. For organizations that hold clearances and hold data, the durable competitive advantage is not predicting which sovereign ultimately prevails — it is building AI governance capable of surviving either outcome.

Frequently Asked Questions

Does Executive Order 14365 preempt state AI laws?

No — not by itself. Preemption ordinarily requires a federal statute, though executive action implementing valid statutory authority can carry preemptive effect. EO 14365 directs litigation and agency action, but existing state AI laws remain enforceable until a court rules otherwise.

Can I stop complying with my state's AI law while the DOJ challenges proceed?

No. State AI laws remain in force during the litigation, and a pending federal challenge is not a defense to present non-compliance. Regulated parties should comply with state law as it stands while monitoring the challenges.

How does this affect insider-threat programs under 32 CFR Part 117?

Insider-threat programs increasingly use behavioral analytics and AI-driven risk scoring. Those tools can sit under both a federal security mandate to monitor and state transparency and automated-decision rules demanding disclosure and governance around that monitoring. Programs should be aligned to satisfy both until the preemption fight resolves.

What are the June 2026 national-security AI directives?

On June 2, 2026, a separate executive order directed agencies — on 30- and 60-day timelines — to harden National Security Systems, defense information systems, and civilian federal systems with AI-enabled cyber defenses, and created an AI cybersecurity clearinghouse. On June 5, 2026, a National Security Presidential Memorandum framed AI in the defense and intelligence enterprise around four pillars: Adoption, Adaptation, Assurance, and Accountability.

What should a cleared contractor do right now?

Inventory where AI drives or materially influences consequential decisions in hiring, insider-threat, and personnel functions; document data provenance, model governance, and meaningful human review; and reconcile federal security obligations with applicable state transparency rules. Build governance that survives either outcome of the preemption fight.

Primary Sources

Exec. Order No. 14365, Ensuring a National Policy Framework for Artificial Intelligence (Dec. 11, 2025); Exec. Order, Promoting Advanced Artificial Intelligence Innovation and Security (June 2, 2026); National Security Systems as defined at 44 U.S.C. § 3552(b)(6)(A); National Security Presidential Memorandum on Artificial Intelligence in the National Security Enterprise (June 5, 2026); Exec. Order No. 14179, Removing Barriers to American Leadership in Artificial Intelligence (Jan. 23, 2025); NIST AI Risk Management Framework 1.0 (NIST AI 100-1); America's AI Action Plan (July 23, 2025); 32 C.F.R. Part 117 (National Industrial Security Program Operating Manual), Insider Threat Program requirements; Colorado SB 24-205 (repealed and replaced by SB 26-189, eff. Jan. 1, 2027); National Defense Authorization Act for FY2026 (AI preemption provision omitted). Last reviewed July 19, 2026 — AI-governance law is in active transition at both the federal and state level; confirm the current status before relying on it.

Related reading: on how workplace processes intersect with clearance eligibility, see Can an HR Investigation Affect Your Security Clearance? and what SEAD 3 actually requires you to report. For contractors, the other recurring federal compliance certification with legal teeth is the CMMC affirmation — see The CMMC Affirmation Trap. And for what AI-assisted screening means for individual clearance holders, see When an Algorithm Flags Your Clearance.

Building AI governance in a cleared environment? My office advises defense contractors and cleared organizations on the intersection of insider-threat obligations, personnel security, and emerging AI-governance requirements. Schedule a consultation to discuss your organization's situation. This article is attorney advertising and is provided for general informational purposes only. It does not constitute legal advice, does not address the facts of any specific matter, and does not create an attorney-client relationship. Russ Roby is admitted to practice in the State of Maryland; his practice before federal agencies is limited to matters governed by federal law and applicable agency rules. AI-governance obligations are jurisdiction-specific and rapidly evolving — consult a qualified attorney about your organization's particular circumstances before acting.

Have Questions About Your Situation?

A 30-minute consultation can save you years of headaches — and keep your family out of legal trouble.

Free Consultation

Responds within ~1 business day