State Laws Affecting Frontier US AI Companies

The Combined State Frontier Law

US state frontier-AI law, in the statutes’ own words. The bill below is assembled verbatim from the strictest version of each obligation in force as of 6 August 2026.
No legislature has passed this combined text.
Bills tracked (open any one)
Cal. SB 53·N.Y. RAISE Act·Ill. PA 104-0538·Conn. PA 26-15·Mass. S.3228 (passed the Senate, not the House)
Viewing
Enacted·In force today
Last verified
1 August 2026
Jurisdictions
4 acts read · sections in force today all come from CA
Sources
Official state texts only
Cite
Cite this page

Frontier State Law (frontierstatelaw.com), The Combined State Frontier Law: in force today, verified 1 August 2026. https://frontierstatelaw.com/in-force.html

@misc{frontierstatelaw-composite-in-force,
  author  = {{Frontier State Law}},
  title   = {The Combined State Frontier Law: in force today},
  year    = {2026},
  url     = {https://frontierstatelaw.com/in-force.html},
  note    = {Verified 1 August 2026},
}
Start here·How to read this page

The bill below is assembled from enacted state law: for each obligation, the strictest enacted version, quoted verbatim.

Click any section This panel opens the source bill with the identical text highlighted.

The citation line Names the section of the source law the printed text came from; its link goes to the official page.

“Why [state]” Explains why we think this is the strictest version among similar provisions in enacted state frontier-AI laws. If several states have the strictest version, we print the one enacted first.

AN ACT governing frontier artificial intelligence development,
as it already binds a developer operating in every state.
Assembled verbatim from: Cal. SB 53 (2025)
Sec. 1
(CA·In force)
Frontier AI framework.§ A large frontier developer [a frontier developer whose revenues with affiliates topped $500M last year, § 22757.11(j)] shall write, implement, comply with, and clearly and conspicuously publish on its internet website a frontier AI framework that applies to the large frontier developer’s frontier models and describes how the large frontier developer approaches all of the following: (1) Incorporating national standards, international standards, and industry-consensus best practices into its frontier AI framework. (2) Defining and assessing thresholds used by the large frontier developer to identify and assess whether a frontier model has capabilities that could pose a catastrophic risk, which may include multiple-tiered thresholds. (3) Applying mitigations to address the potential for catastrophic risks based on the results of assessments undertaken pursuant to paragraph (2). (4) Reviewing assessments and adequacy of mitigations as part of the decision to deploy a frontier model or use it extensively internally. (5) Using third parties to assess the potential for catastrophic risks and the effectiveness of mitigations of catastrophic risks. (6) Revisiting and updating the frontier AI framework, including any criteria that trigger updates and how the large frontier developer determines when its frontier models are substantially modified enough to require disclosures pursuant to subdivision (c). (7) Cybersecurity practices to secure unreleased model weights from unauthorized modification or transfer by internal or external parties. (8) Identifying and responding to critical safety incidents. (9) Instituting internal governance practices to ensure implementation of these processes. (10) Assessing and managing catastrophic risk resulting from the internal use of its frontier models, including risks resulting from a frontier model circumventing oversight mechanisms.
Sec. 2
(CA·In force)
Transparency reports.§ Before, or concurrently with, deploying a new frontier model or a substantially modified version of an existing frontier model, a frontier developer shall clearly and conspicuously publish on its internet website a transparency report containing all of the following: (A) The internet website of the frontier developer. (B) A mechanism that enables a natural person to communicate with the frontier developer. (C) The release date of the frontier model. (D) The languages supported by the frontier model. (E) The modalities of output supported by the frontier model. (F) The intended uses of the frontier model. (G) Any generally applicable restrictions or conditions on uses of the frontier model.
Sec. 3
(CA·In force)
Critical-incident reporting.§ Subject to paragraph (2), a frontier developer shall report any critical safety incident pertaining to one or more of its frontier models to the Office of Emergency Services [the California Governor's Office of Emergency Services] within 15 days of discovering the critical safety incident.
Sec. 4
(CA·In force)
Critical-incident reporting: imminent risk.§ If a frontier developer discovers that a critical safety incident poses an imminent risk of death or serious physical injury, the frontier developer shall disclose that incident within 24 hours to an authority, including any law enforcement agency or public safety agency with jurisdiction, that is appropriate based on the nature of that incident and as required by law.
Sec. 5
(CA·In force)
Whistleblower protection.§ A frontier developer shall not make, adopt, enforce, or enter into a rule, regulation, policy, or contract that prevents a covered employee from disclosing, or retaliates against a covered employee for disclosing, information to the Attorney General, a federal authority, a person with authority over the covered employee, or another covered employee who has authority to investigate, discover, or correct the reported issue, if the covered employee has reasonable cause to believe that the information discloses either of the following: (1) The frontier developer’s activities pose a specific and substantial danger to the public health or safety resulting from a catastrophic risk. (2) The frontier developer has violated Chapter 25.1 (commencing with Section 22757.10) of Division 8 of the Business and Professions Code.
Sec. 6
(CA·In force)
Independent verification.§ The extent to which third-party evaluators were involved.
Sec. 7
(CA·In force)
Enforcement.§ A large frontier developer [a frontier developer whose revenues with affiliates topped $500M last year, § 22757.11(j)] that fails to publish or transmit a compliant document required to be published or transmitted under this chapter, makes a statement in violation of subdivision (e) of Section 22757.12, fails to report an incident as required by Section 22757.13, or fails to comply with its own frontier AI framework shall be subject to a civil penalty in an amount dependent upon the severity of the violation that does not exceed one million dollars ($1,000,000) per violation. (b) A civil penalty described in this section shall be recovered in a civil action brought only by the Attorney General.
Sec. 8
(CA·In force)
Scope and thresholds.§ “Frontier developer” means a person who has trained, or initiated the training of, a frontier model, with respect to which the person has used, or intends to use, at least as much computing power to train the frontier model as would meet the technical specifications found in subdivision (i). (i) (1) “Frontier model” means a foundation model that was trained using a quantity of computing power greater than 10^26 integer or floating-point operations. (2) The quantity of computing power described in paragraph (1) shall include computing for the original training run and for any subsequent fine-tuning, reinforcement learning, or other material modifications the developer applies to a preceding foundation model. (j) “Large frontier developer” means a frontier developer that together with its affiliates collectively had annual gross revenues in excess of five hundred million dollars ($500,000,000) in the preceding calendar year.
Sec. 9
(CA·In force)
Internal-use risk.§ A large frontier developer [a frontier developer whose revenues with affiliates topped $500M last year, § 22757.11(j)] shall transmit to the Office of Emergency Services [the California Governor's Office of Emergency Services] a summary of any assessment of catastrophic risk resulting from internal use of its frontier models every three months or pursuant to another reasonable schedule specified by the large frontier developer and communicated in writing to the Office of Emergency Services with written updates, as appropriate.
Sec. 10
(CA·In force)
Minimum-bar standards.§ A frontier developer shall not make a materially false or misleading statement about catastrophic risk from its frontier models or its management of catastrophic risk. (B) A large frontier developer [a frontier developer whose revenues with affiliates topped $500M last year, § 22757.11(j)] shall not make a materially false or misleading statement about its implementation of, or compliance with, its frontier AI framework. (2) This subdivision does not apply to a statement that was made in good faith and was reasonable under the circumstances.
Scope

Each section binds only whom its own state’s text reaches: every act here starts at a model trained above 10^26 computational operations, and the heavier duties add a $500 million revenue test, counted across the developer and its affiliates together, for a “large frontier developer”; so a section keeps its source state’s scope and its source state’s definitions, not a national one.