A decades-old law built to mobilize American factories during the Korean War could become one of Washington’s primary tools for controlling artificial intelligence if a frontier AI system is ever judged a national security threat.
The Defense Production Act (DPA), enacted in 1950, has traditionally been used to expand military production, prioritize government contracts and respond to national emergencies. National security and legal experts who spoke with Fox News Digital say those same authorities could give the executive branch leverage over AI developers if a system posed catastrophic risks — though exactly how remains largely untested.
Most of the DPA’s authorities were set to expire on September 30 but were recently extended by Congress through December 11, 2026, setting up another reauthorization fight later this year, just before a potential shift in the balance of power in Congress after the midterms.
What the Law Could Actually Do
James Lewis, director of the Strategic Technologies Program at the Center for Strategic and International Studies, said the government could likely piece together a response using existing law even without a purpose-built AI statute.
“The authorities could be a little clearer,” Lewis told Fox News Digital. “But you could probably cobble together a solution using the legal authorities we have now.”
One of the most immediate applications wouldn’t wait for a crisis at all — it would compel companies to disclose what they’re building before anything goes wrong. James E. Baker, a former chief judge of the U.S. Court of Appeals for the Armed Forces and past legal adviser to the National Security Council, pointed to the DPA’s broad information-gathering powers.
“What you could use the DPA for is to require reporting, and that’s the first step to making sound policy,” Baker said. “You can have a debate about whether there should be regulation and what the regulation should look like. But you really can’t argue against knowing what’s happening.”
The Law’s Limits
Paul Rosenzweig, a lawyer and former deputy assistant secretary for policy at the Department of Homeland Security, cautioned that the DPA was designed mainly to compel production for government use — not to stop private companies from building things.
“The Defense Production Act is more about mandating the production of things for the United States rather than preventing the production for the general public,” Rosenzweig said, though he agreed its information-demanding power is its strongest feature for AI oversight.
Beyond the DPA, other existing tools could come into play: export controls to keep sensitive technology from adversaries, conditions attached to federal contracts, and ordinary criminal law. A June executive order directed the attorney general to prioritize enforcement of existing federal criminal statutes against people who use AI to illegally access or damage computer systems.
Rosenzweig noted there is no blanket legal exemption for AI companies. Both federal and state governments already have tort liability, privacy, consumer protection and criminal statutes that could apply — but none of it has been tested against a true AI emergency.
Building a Framework
The same June executive order directed agencies including the NSA and CISA to establish classified benchmarks for advanced cyber capabilities and to determine when a system should be labeled a “covered frontier model.” It also proposes a voluntary framework allowing developers to give the government early access to such models — while explicitly avoiding mandatory federal licensing or pre-clearance.
Lewis said the cyber threat landscape has shifted quickly, with AI compressing the time needed to find and exploit vulnerabilities from months to hours, and helping attackers chain smaller weaknesses into larger attacks.
“The threat itself is not new,” Lewis said. “We’ve known about this for a while, but people weren’t taking it seriously.” AI, he added, has “changed the landscape dramatically.”
The debate arrives as executives at major AI companies issued warnings this week about the growing capability of their own systems and called for slowing development to let safety measures catch up. Trump responded by saying his administration already has “tremendous criminal and regulatory power” over AI firms, pushing back on calls for new guardrails.
Rosenzweig said liability questions would be especially difficult if an AI system caused harm autonomously — for instance, hacking a hospital or critical infrastructure network — since courts would have to sort out negligence, whether stricter product-liability standards apply, and whether the damage can even be traced to a specific system.
“I tend to think that liability is going to be difficult to establish early on,” Rosenzweig said. “Right now, that’s not where I would base my deterrence model.”
For now, the country’s legal defenses against a dangerous AI system rest on a patchwork of laws written for other purposes — untested against a technology moving faster than the legal system built to constrain it.
