State Laws Affecting Frontier US AI Companies
Bill page — Massachusetts

S.3228 · Transparency in Frontier Artificial Intelligence Act

In conference — House non-concurred 7/30; conference committees appointed
A plain-language summary laid over the statute. Every row below opens the text it comes from; the margin marks where Massachusetts departs from the California baseline.
Version read
Senate-engrossed text
Citation
S.3228
Effective
Chapter 93M would take effect 2027-07-01 if enacted (S.3228 SECTION 355); the s. 3A audit and evaluation duties are dated to 2027-01-01 or 180 days after a developer first qualifies, whichever is later (SECTIONS 346-347)
Last verified
1 August 2026
Baseline
Cal. SB 53

High-level summary

Ordered by novelty · open a row for detail · the cite jumps to the text
An SB 53 copy, plus a standing 180-day residual-risk report that runs on the calendar rather than on a release, plus an annual third-party compliance audit, plus — alone among the states — an independent evaluation of the models themselves against each category of catastrophic risk every 120 days, with the evaluator given the developer's most capable models; not law yet, and in conference.
New — no CA analogue
Standing 180-day residual-risk report, on a clock rather than on a release.
Binds you if
Binds you if you are a large frontier developer, whether or not you have deployed anything new — the clock runs on the calendar, and it reaches internally deployed models that materially exceed your externally deployed ones.
Effective
180 days after the act takes effect, or 180 days after first qualifying as a large frontier developer, whichever is later
G.L. c. 93M s. 2(c 1/2) (proposed)
New — no CA analogue
Annual third-party audit of compliance, summary published within 30 days.
Binds you if
Binds you if you are a large frontier developer; the audit covers compliance with section 2, expressly excluding the (c 1/2) risk report, which the separate model evaluation covers instead.
Effective
2027-01-01, or 180 days after first qualifying as a large frontier developer, whichever is later
G.L. c. 93M s. 3A(a) (proposed)
New — no CA analogue
Independent third-party evaluation of the models themselves, at least every 120 days.
Binds you if
Binds you if you are a large frontier developer: an outside evaluator must be given your most capable frontier models, per category of catastrophic risk, at least three times a year.
Effective
2027-01-01, or 180 days after first qualifying as a large frontier developer, whichever is later
G.L. c. 93M s. 3A(b)(1) (proposed)
New — no CA analogue
Independence standard for auditors and evaluators, certified to the Attorney General.
Binds you if
Binds you if you are a large frontier developer engaging an auditor or evaluator, and binds the third party itself, which must certify its independence in writing before accepting the engagement.
Effective
2027-01-01, or 180 days after first qualifying as a large frontier developer, whichever is later
G.L. c. 93M s. 3A(c) (proposed)
New — no CA analogue
Attorney General must build an independent-evaluator ecosystem.
Binds you if
Binds the Attorney General, not developers: the state, not the industry, is made responsible for there being qualified evaluators to hire.
Effective
the plan is due not later than 1 year after the act takes effect (S.3228 SECTION 348)
G.L. c. 93M s. 3A(d)(1) (proposed)
Tightens CA
Catastrophic risk: 50 people or $1B, on the same four limbs — with the threshold inclusive.
Binds you if
Binds you if you are a frontier developer: this definition sets the harm every framework, report, evaluation and incident duty in the chapter is measured against.
Effective
2027-07-01
G.L. c. 93M s. 1 (proposed), definition of 'Catastrophic risk'
Tightens CA
Broader trigger: what counts as a reportable critical safety incident.
Binds you if
Binds you if you are any frontier developer: this definition sets which events start the 15-day and 24-hour clocks.
Effective
2027-07-01
G.L. c. 93M s. 1 (proposed), definition of 'Critical safety incident'
Tightens CA
Published frontier AI framework, 11 required topics, described 'in detail'.
Binds you if
Binds you if you are a large frontier developer — a frontier developer whose group revenue exceeds $500M that has trained a model above 10^26 operations.
Effective
2027-07-01
G.L. c. 93M s. 2(a) (proposed)
Tightens CA
Quarterly internal-use catastrophic-risk summary to the Attorney General.
Binds you if
Binds you if you are a large frontier developer that uses its own frontier models internally — the duty runs on a clock, not on a release.
Effective
2027-07-01
G.L. c. 93M s. 2(d) (proposed)
Tightens CA
15-day critical safety incident report to the Attorney General; 24 hours where risk is imminent.
Binds you if
Binds you if you are any frontier developer — not only a large one — that discovers a critical safety incident involving one of its frontier models.
Effective
2027-07-01
G.L. c. 93M s. 3(c)(1) (proposed)
Tightens CA
Civil penalty up to $1M first violation, $3M subsequent, Attorney General only.
Binds you if
Binds you if you are a large frontier developer that fails to publish or transmit a required document, makes a prohibited statement, misses an incident report, or departs from your own framework.
Effective
2027-07-01
G.L. c. 93M s. 5 (proposed)
Tightens CA
Whistleblower protection keyed to danger, on a 'reasonably believes' standard.
Binds you if
Binds you if you are any frontier developer employing covered employees — those responsible for assessing, managing or addressing risk of critical safety incidents.
Effective
2027-07-01
G.L. c. 93M s. 7(a) (proposed)
Tightens CA
Internal disclosure channel usable anonymously or by name, with monthly status updates.
Binds you if
Binds you if you are a large frontier developer — the internal-channel duty, unlike the anti-retaliation duty, attaches only to large developers.
Effective
2027-07-01
G.L. c. 93M s. 7(d)(1) (proposed)
Matches CA
3 provisions track the California baseline.
G.L. c. 93M s. 1 (proposed), definitions of 'Frontier model' and 'Large frontier developer' +2 more
↑ Summary

The Bill

Senate-engrossed text, verbatim · quoted in statute order
G.L. c. 93M s. 1 (proposed), definition of 'Catastrophic risk'
Tightens CA
Compared →
Catastrophic risk: 50 people or $1B, on the same four limbs — with the threshold inclusive
“Catastrophic risk”, a foreseeable and material risk that a frontier developer’s development, storage, use or deployment of a frontier model [a foundation model trained using more than 10^26 integer or floating-point operations (c. 93M s. 1)] will materially contribute to the death of, or serious injury to, not less than 50 people or not less than $1,000,000,000 in damage to, or loss of, property arising from a single incident involving a frontier model that: (i) provides expert-level assistance in the creation or release of a chemical, biological, radiological or nuclear weapon; (ii) engages in conduct with no meaningful human oversight, intervention or supervision that is either a cyberattack or, if the conduct had been committed by a human, would constitute the crime of murder, assault, extortion or theft, including theft by false pretense; or (iii) evades the control of its frontier developer or user; provided, however, that “catastrophic risk” shall not include a foreseeable and material risk from: (A) information that a frontier model outputs if the information is otherwise publicly accessible in a substantially similar form from a source other than a foundation model; (B) lawful activity of the federal government; or (C) harm caused by a frontier model in combination with other software if the frontier model did not materially contribute to the harm.
Effective
2027-07-01
Binds you if
Binds you if you are a frontier developer: this definition sets the harm every framework, report, evaluation and incident duty in the chapter is measured against.
Goes to
n/a — a definition
Duty
mandatory
Category
thresholds-scoping
G.L. c. 93M s. 1 (proposed), definition of 'Critical safety incident'
Tightens CA
Compared →
Broader trigger: what counts as a reportable critical safety incident
“Critical safety incident”, any: (i) unauthorized access to, modification of, inadvertent release of or exfiltration of, the model weights [the numerical parameters adjusted through training that determine how a model turns inputs into outputs (c. 93M s. 1)] of a frontier model; [a foundation model trained using more than 10^26 integer or floating-point operations (c. 93M s. 1)] (ii) harm resulting from the materialization of a catastrophic risk; (iii) loss of control of a frontier model that causes death or bodily injury or that demonstrates materially increased catastrophic risk; or (iv) instance where a frontier model that uses deceptive techniques against the frontier developer to subvert the controls or monitoring of its frontier developer outside of the context of an evaluation designed to elicit this behavior and in a manner that demonstrates materially increased catastrophic risk.
Effective
2027-07-01
Binds you if
Binds you if you are any frontier developer: this definition sets which events start the 15-day and 24-hour clocks.
Goes to
n/a — a definition; the reporting duty it triggers runs to the Attorney General under s. 3(c)
Duty
mandatory
Category
incident-reporting
G.L. c. 93M s. 1 (proposed), definitions of 'Frontier model' and 'Large frontier developer'
Matches CA
Compared →
10^26 operations for the model, $500M revenue for the developer
“Frontier model”, a foundation model that has been trained using a quantity of computing power greater than 10^26 integer or floating-point operations; provided, however, that the quantity of computing power shall include computing for the original training run and for any subsequent fine-tuning, reinforcement learning or other material modifications the developer applies to a preceding foundation model. “Large frontier developer”, a frontier developer that together with its affiliates collectively has annual gross revenues greater than $500,000,000.
Effective
2027-07-01
Binds you if
Binds you if you trained, or started training, a model above 10^26 operations; the heavier duties attach only above $500M in group annual revenue.
Goes to
n/a — scoping definitions
Duty
mandatory
Category
thresholds-scoping
G.L. c. 93M s. 2(a) (proposed)
Tightens CA
Compared →
Published frontier AI framework, 11 required topics, described 'in detail'
Section 2. (a) A large frontier developer [a frontier developer whose group annual gross revenues exceed $500,000,000 (c. 93M s. 1)] shall write, implement, comply with and clearly and conspicuously publish on its internet website a frontier AI framework that applies to the large frontier developer’s frontier models and describes in detail how the large frontier developer handles: (i) incorporating national standards, international standards and industry-consensus best practices into its frontier AI framework; (ii) defining and assessing thresholds used by the large frontier developer to identify and assess whether a frontier model [a foundation model trained using more than 10^26 integer or floating-point operations (c. 93M s. 1)] has capabilities that could pose a catastrophic risk, which may include multiple-tiered thresholds; (iii) applying mitigations to address the potential for catastrophic risks based on the results of assessments undertaken pursuant to clause (ii); (iv) assessing the ability of the large frontier developer’s frontier models to automate artificial intelligence research and development and any increased potential for catastrophic risks or challengers to risk monitoring, assessment or mitigation resulting from such ability;
Effective
2027-07-01
Binds you if
Binds you if you are a large frontier developer — a frontier developer whose group revenue exceeds $500M that has trained a model above 10^26 operations.
Goes to
the public: published on the developer's own internet website; no filing with any state office
Duty
mandatory
Category
frontier-ai-framework
G.L. c. 93M s. 2(c)(2) (proposed)
Matches CA
Compared →
Deployment-triggered transparency report with catastrophic-risk assessment summaries
(2) Before, or concurrently with, deploying a new frontier model or a substantially modified version of an existing frontier model, a large frontier developer [a frontier developer whose group annual gross revenues exceed $500,000,000 (c. 93M s. 1)] shall include in the transparency report required by paragraph (1) summaries of: (i) assessments of catastrophic risks from the frontier model conducted pursuant to the large frontier developer’s frontier AI framework; (ii) the results of such assessments; (iii) the extent to which third-party evaluators were involved; and (iv) any other steps taken to fulfill the requirements of the frontier AI framework with respect to the frontier model.
Effective
2027-07-01
Binds you if
Binds you if you are a large frontier developer deploying a new or substantially modified frontier model.
Goes to
the public: published on the developer's website; may be folded into a system card or model card
Duty
mandatory
Category
transparency-reports
G.L. c. 93M s. 2(c 1/2) (proposed)
New — no CA analogue
No CA analogue
Compared →
Standing 180-day residual-risk report, on a clock rather than on a release
(c 1/2)(1) A large frontier developer [a frontier developer whose group annual gross revenues exceed $500,000,000 (c. 93M s. 1)] shall clearly and conspicuously publish on its internet website a risk report that provides an overall assessment of the catastrophic risks posed by: (i) any frontier models the large frontier developer deploys externally; and (ii) any internally deployed frontier models with capabilities that materially exceed those of any frontier model [a foundation model trained using more than 10^26 integer or floating-point operations (c. 93M s. 1)] that frontier developer has externally deployed. (2) A risk report that is required by paragraph (1) shall include, but not be limited to: (i) a summary of assessments of capabilities of the frontier models relevant to catastrophic risk, which shall address each type of catastrophic risk and describe any material changes to the capabilities of the frontier models relevant to each type of catastrophic risk since the most recently published risk report; (ii) a description of the key threat models the large frontier developer tracks to identify potential catastrophic risks, how observed capabilities of those frontier models relate to each threat model and key mitigations that the large frontier developer has put in place to mitigate any such identified risks; and (iii) an assessment of the residual level of each type of catastrophic risk posed by the frontier models after accounting for the mitigations implemented pursuant to clause (ii); provided, however, that the assessment shall provide sufficient information to demonstrate the evidence and reasoning behind the risk assessment and such information shall be sufficient to allow a reasonable person to reach a similar conclusion to that which the large frontier developer would reach in analyzing the level of risk posed by its frontier model. (3) A large frontier developer shall renew and update the risk report required by paragraph (1) not less than every 180 days and include in each update a comparison of the assessed level of each type of catastrophic risk to the level assessed in the previously published risk report.
Effective
180 days after the act takes effect, or 180 days after first qualifying as a large frontier developer, whichever is later
Binds you if
Binds you if you are a large frontier developer, whether or not you have deployed anything new — the clock runs on the calendar, and it reaches internally deployed models that materially exceed your externally deployed ones.
Goes to
the public: published on the developer's internet website
Duty
mandatory
Category
transparency-reports
G.L. c. 93M s. 2(d) (proposed)
Tightens CA
Compared →
Quarterly internal-use catastrophic-risk summary to the Attorney General
(d) A large frontier developer [a frontier developer whose group annual gross revenues exceed $500,000,000 (c. 93M s. 1)] shall transmit to the attorney general [the Massachusetts Attorney General, the sole enforcer of proposed c. 93M] a summary of any assessment of catastrophic risk resulting from internal use of its frontier models every 3 months or pursuant to another reasonable schedule as agreed to by the attorney general and large frontier developer.
Effective
2027-07-01
Binds you if
Binds you if you are a large frontier developer that uses its own frontier models internally — the duty runs on a clock, not on a release.
Goes to
the Attorney General, confidentially (s. 3(b)); exempt from the public-records law under s. 3(f)
Duty
mandatory
Category
internal-use-risk
G.L. c. 93M s. 2(e) (proposed)
Matches CA
Compared →
No deployment bar and no quality standard: the prohibitions run to statements, not to shipping
(e)(1) A frontier developer shall not make a materially false or misleading statement about catastrophic risk from its frontier models or its management of catastrophic risk. (2) A large frontier developer [a frontier developer whose group annual gross revenues exceed $500,000,000 (c. 93M s. 1)] shall not make a materially false or misleading statement about its implementation of, or compliance with, its frontier AI framework. (3) This subsection shall not apply to a statement that was made in good faith and was reasonable under the circumstances.
Effective
2027-07-01
Binds you if
Binds you if you are a frontier developer making public claims about catastrophic risk; nothing in the chapter bars you from deploying a model you have assessed as dangerous.
Goes to
n/a — a prohibition, enforced by the Attorney General under s. 5
Duty
mandatory
Category
minimum-bar-standards
G.L. c. 93M s. 3(c)(1) (proposed)
Tightens CA
Compared →
15-day critical safety incident report to the Attorney General; 24 hours where risk is imminent
(c)(1) A frontier developer shall report any critical safety incident pertaining to 1 or more of its frontier models to the attorney general [the Massachusetts Attorney General, the sole enforcer of proposed c. 93M] within 15 days of discovering the critical safety incident; provided, however, that if a frontier developer discovers that a critical safety incident poses an imminent risk of death or serious physical injury, the frontier developer shall disclose that incident within 24 hours to an authority, including any law enforcement agency or public safety agency with jurisdiction, that is appropriate based on the nature of that incident and as required by law.
Effective
2027-07-01
Binds you if
Binds you if you are any frontier developer — not only a large one — that discovers a critical safety incident involving one of its frontier models.
Goes to
the Attorney General within 15 days; within 24 hours, any authority with jurisdiction (including law enforcement or a public safety agency) where the incident poses an imminent risk of death or serious physical injury
Duty
mandatory
Category
incident-reporting
G.L. c. 93M s. 3A(a) (proposed)
New — no CA analogue
No CA analogue
Compared →
Annual third-party audit of compliance, summary published within 30 days
Section 3A. (a) A large frontier developer [a frontier developer whose group annual gross revenues exceed $500,000,000 (c. 93M s. 1)] shall annually retain a third party to perform an independent audit of compliance with the requirements of section 2 except for subsection (c 1/2) of said section 2. The third party shall conduct audits consistent with generally accepted auditing standards and best practices and shall possess demonstrated competence to perform the audit, including experience employing or contracting with individuals who possess technical expertise in the safety of frontier models.
Effective
2027-01-01, or 180 days after first qualifying as a large frontier developer, whichever is later
Binds you if
Binds you if you are a large frontier developer; the audit covers compliance with section 2, expressly excluding the (c 1/2) risk report, which the separate model evaluation covers instead.
Goes to
the developer, which must publish a high-level summary plus the redacted report within 30 days and transmit the redacted report to the attorney general (s. 3A(a)(4): "Not later than 30 days after receiving the audit report, the large frontier developer shall conspicuously publish on its website a high-level summary of the audit findings and a copy of the third party’s report with redactions as provided in subsection (f) of section 2 and transmit a copy of the redacted report to the attorney general.")
Duty
mandatory
Category
independent-verification
G.L. c. 93M s. 3A(b)(1) (proposed)
New — no CA analogue
No CA analogue
Compared →
Independent third-party evaluation of the models themselves, at least every 120 days
(b)(1) A large frontier developer [a frontier developer whose group annual gross revenues exceed $500,000,000 (c. 93M s. 1)] shall engage at least 1 third party to conduct an independent evaluation of the developer’s frontier models with respect to each category of catastrophic risk. A large frontier developer shall engage a third party to conduct its evaluation not more than 30 days after publishing each risk report under subsection (c 1/2) of section 2 and in any event shall conduct an independent evaluation not less than once every 120 days.
Effective
2027-01-01, or 180 days after first qualifying as a large frontier developer, whichever is later
Binds you if
Binds you if you are a large frontier developer: an outside evaluator must be given your most capable frontier models, per category of catastrophic risk, at least three times a year.
Goes to
the public: the third party publishes its own report within 30 days of delivering it, and the developer must link to it (s. 3A(b)(4))
Duty
mandatory
Category
independent-verification
G.L. c. 93M s. 3A(c) (proposed)
New — no CA analogue
No CA analogue
Source →
Independence standard for auditors and evaluators, certified to the Attorney General
(c)(1)(A) A third party engaged under this section shall have no financial, operational or management dependence on the large frontier developer [a frontier developer whose group annual gross revenues exceed $500,000,000 (c. 93M s. 1)] or any of the large frontier developer's affiliates and shall be otherwise free from the large frontier developer's control in reaching conclusions or making recommendations, including through contractual safeguards and conflict of interest policies. (B) If no other source of funding has been established pursuant to clause (iii) of paragraph (1) of subsection (d), a large frontier developer may compensate the third party at reasonable market rates and shall not condition any payment or the amount of any payment on the results of the third party’s audit or evaluation. (2) Prior to accepting any engagement under this section, the third party shall certify in writing to the large frontier developer and the attorney general [the Massachusetts Attorney General, the sole enforcer of proposed c. 93M] that the third party satisfies the independence requirements of this subsection. The certification shall include the third party’s sources of funding and remuneration for the engagement, any other current or recent engagements with the large frontier developer or its affiliates and any other facts that could reasonably be expected to bear on the third party’s independence.
Effective
2027-01-01, or 180 days after first qualifying as a large frontier developer, whichever is later
Binds you if
Binds you if you are a large frontier developer engaging an auditor or evaluator, and binds the third party itself, which must certify its independence in writing before accepting the engagement.
Goes to
the large frontier developer and the Attorney General both receive the written independence certification
Duty
mandatory
Category
independent-verification
G.L. c. 93M s. 3A(d)(1) (proposed)
New — no CA analogue
No CA analogue
Source →
Attorney General must build an independent-evaluator ecosystem
(d)(1) The attorney general, [the Massachusetts Attorney General, the sole enforcer of proposed c. 93M] in consultation with academic institutions, nonprofit organizations and industry stakeholders, shall implement an independent evaluation ecosystem plan by: (i) developing and publishing standards for the qualification of qualified independent third party evaluators; (ii) exploring a licensing system to qualify third party evaluators; (iii) subject to government appropriation, providing government funding or arranging pooled funding to supplement other sources of evaluator funding;
Effective
the plan is due not later than 1 year after the act takes effect (S.3228 SECTION 348)
Binds you if
Binds the Attorney General, not developers: the state, not the industry, is made responsible for there being qualified evaluators to hire.
Goes to
the public, via published qualification standards; findings on licensing go to the joint committee on advanced information technology, the internet and cybersecurity and the joint committee on economic development
Duty
rulemaking
Category
independent-verification
G.L. c. 93M s. 5 (proposed)
Tightens CA
Compared →
Civil penalty up to $1M first violation, $3M subsequent, Attorney General only
Section 5. (a) A large frontier developer [a frontier developer whose group annual gross revenues exceed $500,000,000 (c. 93M s. 1)] that fails to publish or transmit a compliant document required to be published or transmitted under this chapter, makes a statement in violation of this chapter, fails to report an incident as required by this chapter, or fails to comply with its own frontier AI framework shall be subject to a civil penalty of not more than $1,000,000 for a first violation and not more than $3,000,000 for subsequent violations. (b) A civil penalty described in this section may only be recovered in a civil action brought by the attorney general. [the Massachusetts Attorney General, the sole enforcer of proposed c. 93M]
Effective
2027-07-01
Binds you if
Binds you if you are a large frontier developer that fails to publish or transmit a required document, makes a prohibited statement, misses an incident report, or departs from your own framework.
Goes to
the Attorney General, exclusively — no private right of action appears anywhere in the chapter
Duty
mandatory
Category
enforcement
G.L. c. 93M s. 7(a) (proposed)
Tightens CA
Compared →
Whistleblower protection keyed to danger, on a 'reasonably believes' standard
Section 7. (a) A frontier developer shall not make, adopt, enforce, or enter into a rule, regulation, policy or contract that prevents a covered employee [an employee responsible for assessing, managing or addressing risk of critical safety incidents (c. 93M s. 1)] from disclosing or retaliates against a covered employee for disclosing, information to the attorney general, [the Massachusetts Attorney General, the sole enforcer of proposed c. 93M] a federal authority, a person with authority over the covered employee or another covered employee who has authority to investigate, discover or correct the reported issue, if the covered employee reasonably believes that the information discloses either: (i) the frontier developer’s activities pose a specific and substantial danger to the public health or safety resulting from a catastrophic risk; or (ii) the frontier developer has violated this chapter.
Effective
2027-07-01
Binds you if
Binds you if you are any frontier developer employing covered employees — those responsible for assessing, managing or addressing risk of critical safety incidents.
Goes to
the Attorney General, a federal authority, a person with authority over the employee, or another covered employee with authority to investigate
Duty
mandatory
Category
whistleblower
G.L. c. 93M s. 7(d)(1) (proposed)
Tightens CA
Compared →
Internal disclosure channel usable anonymously or by name, with monthly status updates
(d)(1) A large frontier developer [a frontier developer whose group annual gross revenues exceed $500,000,000 (c. 93M s. 1)] shall provide a reasonable internal process through which a covered employee may, anonymously or named, disclose information to the large frontier developer of the covered employee reasonably believes that the information indicates that the large frontier developer’s activities present a specific and substantial danger to the public health or safety resulting from a catastrophic risk or that the large frontier developer violated this chapter, which shall include a monthly update to a person who makes a disclosure under this chapter on the status of the large frontier developer’s investigation of such disclosure and the actions taken by the large frontier developer in response to such disclosure.
Effective
2027-07-01
Binds you if
Binds you if you are a large frontier developer — the internal-channel duty, unlike the anti-retaliation duty, attaches only to large developers.
Goes to
the developer itself, internally; disclosures and responses go to officers and directors quarterly under s. 7(d)(2)
Duty
mandatory
Category
whistleblower
S.3228 SECTION 345 (offered as SECTION 166 of amendment 471 / S.3224)
New — no CA analogue
Drafting note
Source →
Effective-date section for the risk report cites the wrong subsection
SECTION 345. Not more than 180 days after the effective date of this act or 180 days after the date on which a frontier developer first qualifies as a large frontier developer, [a frontier developer whose group annual gross revenues exceed $500,000,000 (c. 93M s. 1)] whichever is later, a large frontier developer shall post its risk report required under subsection (c) of section 2 of chapter 93M of the General Laws.
Effective
180 days after the act takes effect, or 180 days after first qualifying, whichever is later
Binds you if
Binds you if you are a large frontier developer subject to the risk report; this is the timing section for that report.
Goes to
n/a — a timing section, not an obligation to a receiver
Duty
mandatory
Category
transparency-reports
Full text ↗

Every quotation above is machine-checked against the archived official text before this page is built. Passages of the act outside the frontier-model duties this site tracks are not quoted here — read the whole the bill on malegislature.gov ↗.

CACompared with — G.L. c. 93M s. 1 (proposed), definition of 'Catastrophic risk'
Cal. SB 53
Cal. Bus. & Prof. Code s. 22757.11(c)·leginfo.legislature.ca.gov, official text ↗
(c) (1) “Catastrophic risk” means a foreseeable and material risk that a frontier developer’s development, storage, use, or deployment of a frontier model will materially contribute to the death of, or serious injury to, more than 50 people or more than one billion dollars ($1,000,000,000) in damage to, or loss of, property arising from a single incident involving a frontier model doing any of the following: (A) Providing expert-level assistance in the creation or release of a chemical, biological, radiological, or nuclear weapon. (B) Engaging in conduct with no meaningful human oversight, intervention, or supervision that is either a cyberattack or, if the conduct had been committed by a human, would constitute the crime of murder, assault, extortion, or theft, including theft by false pretense. (C) Evading the control of its frontier developer or user. (2) “Catastrophic risk” does not include a foreseeable and material risk from any of the following: (A) Information that a frontier model outputs if the information is otherwise publicly accessible in a substantially similar form from a source other than a foundation model. (B) Lawful activity of the federal government.

Continue on leginfo.legislature.ca.gov ↗

CACompared with — G.L. c. 93M s. 1 (proposed), definition of 'Critical safety incident'
Cal. SB 53
Cal. Bus. & Prof. Code s. 22757.11(d)·leginfo.legislature.ca.gov, official text ↗
(d) “Critical safety incident” means any of the following: (1) Unauthorized access to, modification of, or exfiltration of, the model weights of a frontier model that results in death or bodily injury. (2) Harm resulting from the materialization of a catastrophic risk. (3) Loss of control of a frontier model causing death or bodily injury. (4) A frontier model that uses deceptive techniques against the frontier developer to subvert the controls or monitoring of its frontier developer outside of the context of an evaluation designed to elicit this behavior and in a manner that demonstrates materially increased catastrophic risk.
CACompared with — G.L. c. 93M s. 1 (proposed), definitions of 'Frontier model' and 'Large frontier developer'
Cal. SB 53
Cal. Bus. & Prof. Code s. 22757.11(i)-(j)·leginfo.legislature.ca.gov, official text ↗
(i) (1) “Frontier model” means a foundation model that was trained using a quantity of computing power greater than 10^26 integer or floating-point operations. (2) The quantity of computing power described in paragraph (1) shall include computing for the original training run and for any subsequent fine-tuning, reinforcement learning, or other material modifications the developer applies to a preceding foundation model. (j) “Large frontier developer” means a frontier developer that together with its affiliates collectively had annual gross revenues in excess of five hundred million dollars ($500,000,000) in the preceding calendar year.
CACompared with — G.L. c. 93M s. 2(a) (proposed)
Cal. SB 53
Cal. Bus. & Prof. Code s. 22757.12(a)·leginfo.legislature.ca.gov, official text ↗
(a) A large frontier developer shall write, implement, comply with, and clearly and conspicuously publish on its internet website a frontier AI framework that applies to the large frontier developer’s frontier models and describes how the large frontier developer approaches all of the following: (1) Incorporating national standards, international standards, and industry-consensus best practices into its frontier AI framework. (2) Defining and assessing thresholds used by the large frontier developer to identify and assess whether a frontier model has capabilities that could pose a catastrophic risk, which may include multiple-tiered thresholds. (3) Applying mitigations to address the potential for catastrophic risks based on the results of assessments undertaken pursuant to paragraph (2).
CACompared with — G.L. c. 93M s. 2(c)(2) (proposed)
Cal. SB 53
Cal. Bus. & Prof. Code s. 22757.12(c)(2)·leginfo.legislature.ca.gov, official text ↗
(2) Before, or concurrently with, deploying a new frontier model or a substantially modified version of an existing frontier model, a large frontier developer shall include in the transparency report required by paragraph (1) summaries of all of the following: (A) Assessments of catastrophic risks from the frontier model conducted pursuant to the large frontier developer’s frontier AI framework. (B) The results of those assessments. (C) The extent to which third-party evaluators were involved. (D) Other steps taken to fulfill the requirements of the frontier AI framework with respect to the frontier model.
CACompared with — G.L. c. 93M s. 2(c 1/2) (proposed)
Cal. SB 53
Cal. Bus. & Prof. Code s. 22757.12(c)(2) (nearest miss: deployment-triggered summaries, not a standing report)·leginfo.legislature.ca.gov, official text ↗
(2) Before, or concurrently with, deploying a new frontier model or a substantially modified version of an existing frontier model, a large frontier developer shall include in the transparency report required by paragraph (1) summaries of all of the following: (A) Assessments of catastrophic risks from the frontier model conducted pursuant to the large frontier developer’s frontier AI framework. (B) The results of those assessments. (C) The extent to which third-party evaluators were involved. (D) Other steps taken to fulfill the requirements of the frontier AI framework with respect to the frontier model.
CACompared with — G.L. c. 93M s. 2(d) (proposed)
Cal. SB 53
Cal. Bus. & Prof. Code s. 22757.12(d)·leginfo.legislature.ca.gov, official text ↗
(d) A large frontier developer shall transmit to the Office of Emergency Services a summary of any assessment of catastrophic risk resulting from internal use of its frontier models every three months or pursuant to another reasonable schedule specified by the large frontier developer and communicated in writing to the Office of Emergency Services with written updates, as appropriate.
CACompared with — G.L. c. 93M s. 2(e) (proposed)
Cal. SB 53
Cal. Bus. & Prof. Code s. 22757.12(e)·leginfo.legislature.ca.gov, official text ↗
(e) (1) (A) A frontier developer shall not make a materially false or misleading statement about catastrophic risk from its frontier models or its management of catastrophic risk. (B) A large frontier developer shall not make a materially false or misleading statement about its implementation of, or compliance with, its frontier AI framework. (2) This subdivision does not apply to a statement that was made in good faith and was reasonable under the circumstances.
CACompared with — G.L. c. 93M s. 3(c)(1) (proposed)
Cal. SB 53
Cal. Bus. & Prof. Code s. 22757.13(c)(1)-(2)·leginfo.legislature.ca.gov, official text ↗
(c) (1) Subject to paragraph (2), a frontier developer shall report any critical safety incident pertaining to one or more of its frontier models to the Office of Emergency Services within 15 days of discovering the critical safety incident. (2) If a frontier developer discovers that a critical safety incident poses an imminent risk of death or serious physical injury, the frontier developer shall disclose that incident within 24 hours to an authority, including any law enforcement agency or public safety agency with jurisdiction, that is appropriate based on the nature of that incident and as required by law.
CACompared with — G.L. c. 93M s. 3A(a) (proposed)
Cal. SB 53
Cal. Bus. & Prof. Code s. 22757.12(c)(2)(C) (nearest miss: disclose third-party involvement, no audit)·leginfo.legislature.ca.gov, official text ↗
(2) Before, or concurrently with, deploying a new frontier model or a substantially modified version of an existing frontier model, a large frontier developer shall include in the transparency report required by paragraph (1) summaries of all of the following: (A) Assessments of catastrophic risks from the frontier model conducted pursuant to the large frontier developer’s frontier AI framework. (B) The results of those assessments. (C) The extent to which third-party evaluators were involved.
CACompared with — G.L. c. 93M s. 3A(b)(1) (proposed)
Cal. SB 53
Cal. Bus. & Prof. Code s. 22757.12(c)(2)(C) (nearest miss: disclose third-party involvement, no evaluation duty)·leginfo.legislature.ca.gov, official text ↗
(2) Before, or concurrently with, deploying a new frontier model or a substantially modified version of an existing frontier model, a large frontier developer shall include in the transparency report required by paragraph (1) summaries of all of the following: (A) Assessments of catastrophic risks from the frontier model conducted pursuant to the large frontier developer’s frontier AI framework. (B) The results of those assessments. (C) The extent to which third-party evaluators were involved.
MASource text — G.L. c. 93M s. 3A(c) (proposed)
Massachusetts S.3228
G.L. c. 93M s. 3A(c) (proposed)·malegislature.gov, official text ↗
(c)(1)(A) A third party engaged under this section shall have no financial, operational or management dependence on the large frontier developer or any of the large frontier developer's affiliates and shall be otherwise free from the large frontier developer's control in reaching conclusions or making recommendations, including through contractual safeguards and conflict of interest policies. (B) If no other source of funding has been established pursuant to clause (iii) of paragraph (1) of subsection (d), a large frontier developer may compensate the third party at reasonable market rates and shall not condition any payment or the amount of any payment on the results of the third party’s audit or evaluation. (2) Prior to accepting any engagement under this section, the third party shall certify in writing to the large frontier developer and the attorney general that the third party satisfies the independence requirements of this subsection.

Continue on malegislature.gov ↗

MASource text — G.L. c. 93M s. 3A(d)(1) (proposed)
Massachusetts S.3228
G.L. c. 93M s. 3A(d)(1) (proposed)·malegislature.gov, official text ↗
(d)(1) The attorney general, in consultation with academic institutions, nonprofit organizations and industry stakeholders, shall implement an independent evaluation ecosystem plan by: (i) developing and publishing standards for the qualification of qualified independent third party evaluators; (ii) exploring a licensing system to qualify third party evaluators; (iii) subject to government appropriation, providing government funding or arranging pooled funding to supplement other sources of evaluator funding;
CACompared with — G.L. c. 93M s. 5 (proposed)
Cal. SB 53
Cal. Bus. & Prof. Code s. 22757.15·leginfo.legislature.ca.gov, official text ↗
(a) A large frontier developer that fails to publish or transmit a compliant document required to be published or transmitted under this chapter, makes a statement in violation of subdivision (e) of Section 22757.12, fails to report an incident as required by Section 22757.13, or fails to comply with its own frontier AI framework shall be subject to a civil penalty in an amount dependent upon the severity of the violation that does not exceed one million dollars ($1,000,000) per violation. (b) A civil penalty described in this section shall be recovered in a civil action brought only by the Attorney General.
CACompared with — G.L. c. 93M s. 7(a) (proposed)
Cal. SB 53
(a) A frontier developer shall not make, adopt, enforce, or enter into a rule, regulation, policy, or contract that prevents a covered employee from disclosing, or retaliates against a covered employee for disclosing, information to the Attorney General, a federal authority, a person with authority over the covered employee, or another covered employee who has authority to investigate, discover, or correct the reported issue, if the covered employee has reasonable cause to believe that the information discloses either of the following: (1) The frontier developer’s activities pose a specific and substantial danger to the public health or safety resulting from a catastrophic risk. (2) The frontier developer has violated Chapter 25.1 (commencing with Section 22757.10) of Division 8 of the Business and Professions Code.
CACompared with — G.L. c. 93M s. 7(d)(1) (proposed)
Cal. SB 53
Cal. Lab. Code s. 1107.1(e)(1)·leginfo.legislature.ca.gov, official text ↗
(e) (1) A large frontier developer shall provide a reasonable internal process through which a covered employee may anonymously disclose information to the large frontier developer if the covered employee believes in good faith that the information indicates that the large frontier developer’s activities present a specific and substantial danger to the public health or safety resulting from a catastrophic risk or that the large frontier developer violated Chapter 25.1 (commencing with Section 22757.10) of Division 8 of the Business and Professions Code, including a monthly update to the person who made the disclosure regarding the status of the large frontier developer’s investigation of the disclosure and the actions taken by the large frontier developer in response to the disclosure.
MASource text — S.3228 SECTION 345 (offered as SECTION 166 of amendment 471 / S.3224)
Massachusetts S.3228
S.3228 SECTION 345 (offered as SECTION 166 of amendment 471 / S.3224)·malegislature.gov, official text ↗
SECTION 345. Not more than 180 days after the effective date of this act or 180 days after the date on which a frontier developer first qualifies as a large frontier developer, whichever is later, a large frontier developer shall post its risk report required under subsection (c) of section 2 of chapter 93M of the General Laws.