State Laws Affecting Frontier US AI Companies

Frontier AI law, state by state

This site carries every enacted state frontier-AI law, whole and in the statutes' own words, and is checked against the official texts every day.
Last verified
1 August 2026

The map

Massachusetts: open the bill page Minnesota Montana North Dakota Hawaii Idaho Washington Arizona California: open the bill page Colorado SB 26-189: AI use, not frontier development Nevada New Mexico Oregon Utah SB 149: AI use, not frontier development Wyoming Arkansas Iowa Kansas Missouri Nebraska Oklahoma South Dakota Louisiana Texas HB 149: AI use, not frontier development Connecticut: open the bill page New Hampshire Rhode Island Vermont Alabama Florida Georgia Mississippi South Carolina Illinois: open the bill page Indiana Kentucky North Carolina Ohio Tennessee Virginia Wisconsin West Virginia Delaware District of Columbia Maryland New Jersey New York: open the bill page Pennsylvania Maine Michigan Alaska
Color follows what is on the books, not how strict it is · enacted text only, as of 1 August 2026
Enacted frontier-AI statutes: California · New York · Illinois, and Connecticut in part. No other state has one; other AI laws may apply.
Mass. S.3228In conference

What the colors mean

Frontier AI law enacted
California · New York · Illinois
Partial: some frontier duties
Connecticut
Bill moving
Massachusetts: S.3228, in conference
AI law, different scope
Colorado · Texas · Utah
No frontier-AI statute; other AI laws may apply
Everything else

Bill pages

Law Who it covers Covered harms Key obligations Status and timeline
CA SB 53: Transparency in Frontier Artificial Intelligence Act
California SB 53 is the baseline every other state is measured against.
  • Frontier developer: trains a model above 10^26 integer or floating-point operations.
  • Large frontier developer: that, plus annual gross revenues above $500,000,000 with affiliates.
  • Catastrophic risk: more than 50 deaths or serious injuries, or more than $1,000,000,000 in property damage, from a single incident of:
  • expert-level assistance in creating or releasing a chemical, biological, radiological or nuclear weapon;
  • conduct with no meaningful human oversight that is a cyberattack, or would be the crime of murder, assault, extortion or theft;
  • a model evading the control of its developer or user.
  • Publish a frontier AI framework. First.
  • Transparency report at every deployment.
  • Critical safety incident reported to the Office of Emergency Services in 15 days.
  • 24 hours where risk of death or serious injury is imminent.
  • Quarterly internal-use catastrophic-risk summaries.
  • Whistleblower protection.
In force since 1 January 2026.
NY RAISE Act, as amended by S8828: Gen. Bus. Law art. 44-B
An SB 53 copy, plus a registration regime run by the state's financial regulator, plus a 72-hour incident clock, minus whistleblower protections.
  • Frontier model: trained above 10^26 integer or floating-point operations.
  • Large frontier developer: a frontier developer that, with its affiliates, had annual gross revenues above $500,000,000 in the preceding calendar year.
  • Catastrophic risk: more than fifty deaths or serious injuries, or more than one billion dollars ($1,000,000,000) in property damage, from a single incident of:
  • expert-level assistance in creating or releasing a chemical, biological, radiological or nuclear weapon;
  • conduct with no meaningful human oversight that is a cyberattack, or would be the crime of murder, assault, extortion or theft;
  • a model evading the control of its developer or user.
  • Publish a frontier AI framework.
  • Transparency report at deployment.
  • Critical safety incident reported to the office in 72 hours.
  • Quarterly internal-use catastrophic-risk summaries.
  • Register a disclosure statement with the Department of Financial Services before developing or deploying.
  • Pay assessments that fund the regulator.
Enacted; effective 1 January 2027.
IL Public Act 104-0538 (SB 315): Artificial Intelligence Safety Measures Act
An SB 53 copy, plus first-in-the-nation annual independent audits, plus a 72-hour incident clock.
  • Frontier developer: trains a model above 10^26 integer or floating-point operations.
  • Large frontier developer: that, plus annual gross revenues above $500,000,000 with affiliates, in the preceding calendar year.
  • Catastrophic risk: 50+ deaths or serious injuries, or $1B+ in property damage, in a single incident.
  • A reportable critical safety incident is any of:
  • weight theft causing death or injury;
  • realized catastrophic risk;
  • loss of control causing death or injury;
  • a model deceiving its developer to subvert controls.
  • Publish a frontier AI framework.
  • Machine-readable transparency summaries.
  • Critical safety incident reported to the Agency and the Attorney General in 72 hours.
  • Annual independent third-party audit. First.
  • Public audit summary within 30 days.
  • Registration before a frontier model is developed, deployed or operated.
Enacted; effective 1 January 2027. Framework and audit duties begin 1 January 2028.
MA S.3228: Senate-engrossed frontier AI text (proposed G.L. c. 93M)
An SB 53 copy, plus a standing 180-day risk report, plus annual audits, plus independent model evaluations every 120 days (not law yet, in conference).
  • Frontier model: trained above 10^26 integer or floating-point operations.
  • Large frontier developer: a frontier developer with annual gross revenues, counting affiliates, greater than $500,000,000.
  • Catastrophic risk: not less than 50 deaths or serious injuries, or not less than $1,000,000,000 in property damage, from a single incident of:
  • expert-level assistance in creating or releasing a chemical, biological, radiological or nuclear weapon;
  • conduct with no meaningful human oversight that is a cyberattack, or would be the crime of murder, assault, extortion or theft;
  • a model that evades the control of its developer or user.
  • Would require: a frontier AI framework on eleven topics;
  • a standing residual-risk report every 180 days;
  • an annual third-party audit;
  • independent evaluation of the models themselves at least every 120 days;
  • critical safety incidents to the Attorney General in 15 days.
Not law. House non-concurred 30 July 2026; conference committees appointed in both branches. Chapter 93M would take effect 1 July 2027 if enacted.
CT Public Act 26-15 (SB 5): An Act Concerning Online Safety
SB 53's whistleblower chapter only, with the penalty cut from $1,000,000 to $1,000 per violation.
No retaliation for a safety report; an anonymous internal channel; reports escalated to officers and directors at least quarterly; notice of rights. Enacted; in force 1 October 2026; internal channel due 1 January 2027.

Also on the books

These laws regulate using AI, not building it. That is why this site does not track them.
Decisions about people
Colorado SB 26-189: Automated Decision-Making Technology Takes effect 1 January 2027. When a company uses AI to help decide a person's job, loan, housing, insurance, school admission, health care, or government benefits, it must say so, and after a bad decision the person can ask for a human review and get errors corrected.
Official text
AI use, not development
Texas HB 149: Responsible Artificial Intelligence Governance Act In force since 1 January 2026. Limits specific uses of AI, sets rules for government use, and lets companies test AI products under lighter rules for three years.
Official text
Must say it's AI
Utah SB 149: Artificial Intelligence Policy Act (as amended 2025) In force since 1 May 2024, expires 1 July 2027. Businesses and licensed professionals must tell you when you are talking to an AI.
Official text