State Laws Affecting Frontier US AI Companies
Composite view

The Combined State Frontier Law

One bill, assembled verbatim from enacted state law — the strictest enacted version of each obligation, in the statutes’ own words. Click any section: the source bill opens at right with the identical text highlighted.
Bills tracked — open any one
Cal. SB 53·N.Y. RAISE Act·Ill. PA 104-0538·Conn. PA 26-15·Mass. S.3228 (in conference)
Last verified
1 August 2026
Jurisdictions
4 enacted acts read · sections drawn from CA, NY, IL
Sources
Official state texts only
AN ACT governing frontier artificial intelligence development,
as it already binds a developer operating in every state.
Assembled verbatim from: Cal. SB 53 (2025) · N.Y. RAISE Act (2026) · Ill. PA 104-0538 (2026)
Sec. 1
CAIn force
Source →
Frontier AI framework. A large frontier developer [a frontier developer whose group revenue topped $500 million last year — § 22757.11(j)] shall write, implement, comply with, and clearly and conspicuously publish on its internet website a frontier AI framework that applies to the large frontier developer’s frontier models and describes how the large frontier developer approaches all of the following: (1) Incorporating national standards, international standards, and industry-consensus best practices into its frontier AI framework. (2) Defining and assessing thresholds used by the large frontier developer to identify and assess whether a frontier model has capabilities that could pose a catastrophic risk, which may include multiple-tiered thresholds. (3) Applying mitigations to address the potential for catastrophic risks based on the results of assessments undertaken pursuant to paragraph (2). (4) Reviewing assessments and adequacy of mitigations as part of the decision to deploy a frontier model or use it extensively internally. (5) Using third parties to assess the potential for catastrophic risks and the effectiveness of mitigations of catastrophic risks. (6) Revisiting and updating the frontier AI framework, including any criteria that trigger updates and how the large frontier developer determines when its frontier models are substantially modified enough to require disclosures pursuant to subdivision (c). (7) Cybersecurity practices to secure unreleased model weights from unauthorized modification or transfer by internal or external parties. (8) Identifying and responding to critical safety incidents. (9) Instituting internal governance practices to ensure implementation of these processes. (10) Assessing and managing catastrophic risk resulting from the internal use of its frontier models, including risks resulting from a frontier model circumventing oversight mechanisms.
Sec. 2
CAIn force
Source →
Transparency reports. Before, or concurrently with, deploying a new frontier model or a substantially modified version of an existing frontier model, a frontier developer shall clearly and conspicuously publish on its internet website a transparency report containing all of the following: (A) The internet website of the frontier developer. (B) A mechanism that enables a natural person to communicate with the frontier developer. (C) The release date of the frontier model. (D) The languages supported by the frontier model. (E) The modalities of output supported by the frontier model. (F) The intended uses of the frontier model. (G) Any generally applicable restrictions or conditions on uses of the frontier model.
Sec. 3
ILEff. 1 Jan 2027
Source →
Machine-readable summaries. All summaries required under paragraph (2) shall be provided in a machine-readable format to facilitate verification of model claims.
Sec. 4
ILEff. 1 Jan 2027
Source →
Critical-incident reporting. A frontier developer [anyone who trains, or starts training, a model above the 10^26-operation compute line] shall report any critical safety incident pertaining to one or more of its frontier models to the Agency [the Illinois Emergency Management Agency and Office of Homeland Security] and the Attorney General within 72 hours of the frontier developer learning facts sufficient to establish a reasonable belief that a critical safety incident has occurred. The disclosure shall include: (i) the date of the critical safety incident; (ii) the reasons the incident qualifies as a critical safety incident as defined in this Act; and (iii) a short and plain statement describing the critical safety incident.
Sec. 5
CAIn force
Source →
Whistleblower protection. A frontier developer shall not make, adopt, enforce, or enter into a rule, regulation, policy, or contract that prevents a covered employee from disclosing, or retaliates against a covered employee for disclosing, information to the Attorney General, a federal authority, a person with authority over the covered employee, or another covered employee who has authority to investigate, discover, or correct the reported issue, if the covered employee has reasonable cause to believe that the information discloses either of the following: (1) The frontier developer’s activities pose a specific and substantial danger to the public health or safety resulting from a catastrophic risk. (2) The frontier developer has violated Chapter 25.1 (commencing with Section 22757.10) of Division 8 of the Business and Professions Code.
Sec. 6
ILEff. 1 Jan 2028
Source →
Independent verification. Beginning on January 1, 2028 or 90 days after a developer first qualifies as a large frontier developer, [anyone who trains, or starts training, a model above the 10^26-operation compute line] whichever is later, a large frontier developer shall annually retain a third party to perform an independent audit of compliance with the requirements of this Section. The third party shall conduct audits consistent with generally accepted auditing standards and best practices and shall possess demonstrated competence to perform the audit, including experience employing or contracting with individuals who possess technical expertise in the safety of frontier models. A large frontier developer shall not retain a third party if either the large frontier developer or the third party has a financial interest in the other party. A large frontier developer may compensate a third party for its services but shall not condition any payment or the amount of any payment on the results of the third party's audit.
Sec. 7
ILEff. 1 Jan 2027
Source →
Enforcement. A large frontier developer that fails to publish or transmit a compliant document required to be published or transmitted under this Act, makes a statement in violation of subsection (f) of Section 10, fails to have a third party perform an independent audit of compliance as required by subsection (d) of Section 10, fails to report a critical safety incident as required by Section 15, or fails to comply with its own frontier AI framework shall be subject to a civil penalty in an amount dependent upon the severity of the violation that does not exceed $1,000,000 for the first violation. For a subsequent violation, the civil penalty may not exceed $3,000,000 per violation.
Sec. 8
NYEff. 1 Jan 2027
Source →
Registration. Except as otherwise provided in this section, no large frontier developer may develop, deploy, or operate a frontier model, in whole or in part in New York state, without having a current disclosure statement filed with the office and paying the required share. 2. The disclosure statement shall be filed in the form and the manner prescribed by the office and shall contain all the information required by the office. It shall be renewed every two years, whenever ownership of the frontier model is transferred or whenever there is a material change to the information reported in the previously filed disclosure statement, whichever occurs earlier.
Sec. 9
CAIn force
Source →
Scope and thresholds. “Frontier developer” means a person who has trained, or initiated the training of, a frontier model, with respect to which the person has used, or intends to use, at least as much computing power to train the frontier model as would meet the technical specifications found in subdivision (i). (i) (1) “Frontier model” means a foundation model that was trained using a quantity of computing power greater than 10^26 integer or floating-point operations. (2) The quantity of computing power described in paragraph (1) shall include computing for the original training run and for any subsequent fine-tuning, reinforcement learning, or other material modifications the developer applies to a preceding foundation model. (j) “Large frontier developer” means a frontier developer that together with its affiliates collectively had annual gross revenues in excess of five hundred million dollars ($500,000,000) in the preceding calendar year.
Sec. 10
CAIn force
Source →
Internal-use risk. A large frontier developer [a frontier developer whose group revenue topped $500 million last year — § 22757.11(j)] shall transmit to the Office of Emergency Services [the California Governor's Office of Emergency Services (Cal OES)] a summary of any assessment of catastrophic risk resulting from internal use of its frontier models every three months or pursuant to another reasonable schedule specified by the large frontier developer and communicated in writing to the Office of Emergency Services with written updates, as appropriate.
Sec. 11
CAIn force
Source →
Minimum-bar standards. A frontier developer shall not make a materially false or misleading statement about catastrophic risk from its frontier models or its management of catastrophic risk. (B) A large frontier developer [a frontier developer whose group revenue topped $500 million last year — § 22757.11(j)] shall not make a materially false or misleading statement about its implementation of, or compliance with, its frontier AI framework. (2) This subdivision does not apply to a statement that was made in good faith and was reasonable under the circumstances.
Scope

Each section binds only whom its own state’s text reaches: every act here starts at a model trained above 10^26 computational operations, and the heavier duties add a $500 million group-revenue test for a “large frontier developer” — so a section keeps its source state’s scope and its source state’s definitions, not a national one.

CASource — Section 1
California SB 53
Cal. Bus. & Prof. Code § 22757.12(a)·leginfo.legislature.ca.gov, official text ↗
22757.12. (a) A large frontier developer shall write, implement, comply with, and clearly and conspicuously publish on its internet website a frontier AI framework that applies to

Continue on leginfo.legislature.ca.gov ↗

Why California holds this section

All three frontier states require a published framework on materially the same 10-topic template. Illinois is named strongest on this row in states.json, but its text is tagged MATCHES against SB 53, so the composite prints the California baseline (R4).

First in the nation

SB 53 was the first enacted state statute aimed specifically at frontier-AI transparency; every later state framework requirement is measured against this text. fpf.org ↗