State Laws Affecting Frontier US AI Companies
Bill page: Massachusetts

S.3228 · Transparency in Frontier Artificial Intelligence Act

Senate passed: awaiting passage in the House
A plain-language summary laid over the statute; the margin marks where Massachusetts departs from the California baseline.
Version read
Text the Senate passed
Citation
S.3228
Effective
If enacted: the act starts 1 July 2027 (S.3228 SECTION 355). The audit and evaluation duties in s. 3A run on their own clock: they start 180 days after a developer first crosses the bill's thresholds, and never before 1 January 2027 (SECTIONS 346-347).
Last verified
1 August 2026
Baseline
Cal. SB 53
Cite
Cite this page

Frontier State Law (frontierstatelaw.com), Massachusetts S.3228: Transparency in Frontier Artificial Intelligence Act, verified 1 August 2026. https://frontierstatelaw.com/states/ma.html

@misc{frontierstatelaw-ma,
  author  = {{Frontier State Law}},
  title   = {Massachusetts S.3228: Transparency in Frontier Artificial Intelligence Act},
  year    = {2026},
  url     = {https://frontierstatelaw.com/states/ma.html},
  note    = {Verified 1 August 2026},
}

High-level summary

Ordered by novelty

An SB 53 copy, plus a standing 180-day risk report, plus annual audits, plus independent model evaluations every 120 days (not law yet, in conference).

No CA analogue
Standing 180-day residual-risk report, on a clock rather than on a release.
Binds you if
Binds you if you are a large frontier developer, whether or not you have deployed anything new; the clock runs on the calendar, and it reaches internally deployed models that materially exceed your externally deployed ones.
Effective
180 days after the act takes effect, or 180 days after first qualifying as a large frontier developer, whichever is later S.3228, SECTION 345 ↗
Compared with CA
California has nothing like this. SB 53's transparency report fires once, on release; Massachusetts adds a standing report every 180 days that must compare against the previous one and meet a stricter evidence standard: a reasonable person must be able to reach the same conclusion from the assessment. Added on the Senate floor by amendment 471 (Sen. Rush). One flaw, reproduced as passed: the effective-date section cites the wrong subsection. Not law yet; awaiting the House.
G.L. c. 93M s. 2(c 1/2) (proposed)
Eff. see note
Annual third-party audit of compliance, summary published within 30 days.
Binds you if
Binds you if you are a large frontier developer; the audit covers compliance with section 2, expressly excluding the (c 1/2) risk report, which the separate model evaluation covers instead.
Effective
2027-01-01, or 180 days after first qualifying as a large frontier developer, whichever is later S.3228, SECTION 346 ↗
Compared with CA
California mandates no audit at all. Its nearest text requires only that the developer state the extent to which third-party evaluators were involved, and SB 53 sets no auditor-independence standard. This is structurally the Illinois move (PA 104-0538 Sec. 10(d)), arriving by floor amendment 471, which also struck S.3178's SECTION 153 special commission to merely study third-party audits. One timing tension, as passed: the audit section is dated to 2027-01-01 while c. 93M itself would take effect 2027-07-01 (SECTION 355). Not law yet; awaiting the House.
G.L. c. 93M s. 3A(a) (proposed)
Eff. 1 Jan 2027
Independent third-party evaluation of the models themselves, at least every 120 days.
Binds you if
Binds you if you are a large frontier developer: an outside evaluator must be given your most capable frontier models, per category of catastrophic risk, at least three times a year.
Effective
2027-01-01, or 180 days after first qualifying as a large frontier developer, whichever is later S.3228, SECTION 347 ↗
Compared with CA
No other state text on this map goes this far. Illinois requires an audit of compliance; Massachusetts s. 3A(b) requires evaluation of the models themselves against each category of catastrophic risk, with the evaluator granted access to 'the large frontier developer's most capable frontier models' (s. 3A(b)(3)(A)) and required to state whether it disagrees with the developer's own risk claims (s. 3A(b)(2)(iii)(D)). A first-in-the-nation claim is plausible, but no first marker is shown: the only source found for it is a social-media claim that could not be verified, and a first is marked here only on a verifiable outside source. Not law yet; awaiting the House.
G.L. c. 93M s. 3A(b)(1) (proposed)
Eff. 1 Jan 2027
Independence standard for auditors and evaluators, certified to the Attorney General.
Binds you if
Binds you if you are a large frontier developer engaging an auditor or evaluator, and binds the third party itself, which must certify its independence in writing before accepting the engagement.
Effective
2027-07-01 S.3228, SECTION 355 ↗
G.L. c. 93M s. 3A(c) (proposed)
Eff. 1 Jul 2027
Attorney General must build an independent-evaluator ecosystem.
Binds you if
Binds the Attorney General, not developers: the state, not the industry, is made responsible for there being qualified evaluators to hire.
Effective
the plan is due not later than 1 year after the act takes effect (S.3228 SECTION 348) S.3228, SECTION 348 ↗
G.L. c. 93M s. 3A(d)(1) (proposed)
Eff. see note
Tightens CA
Broader trigger: what counts as a reportable critical safety incident.
Binds you if
Definitional: which events start the 15-day and 24-hour clocks.
Effective
2027-07-01 S.3228, SECTION 355 ↗
Compared with CA
Same definition, widened three ways. Clause (i) adds 'inadvertent release of' to the weights-compromise clause and, unlike SB 53's (d)(1), attaches no 'that results in death or bodily injury' qualifier, so a weights leak is reportable on its own. Clause (iii) reaches loss of control that 'demonstrates materially increased catastrophic risk' as well as loss of control causing death or injury, where SB 53 (d)(3) requires death or bodily injury. More events start the clock in Massachusetts than in California. Not law yet; awaiting the House.
G.L. c. 93M s. 1 (proposed), definition of 'Critical safety incident'
Eff. 1 Jul 2027
Publish a frontier AI framework: 11 topics.
Binds you if
Binds you if you are a large frontier developer: a frontier developer whose revenues, with affiliates, exceed $500M that has trained a model above 10^26 operations. Massachusetts requires each topic described 'in detail'.
Effective
2027-07-01 S.3228, SECTION 355 ↗
Compared with CA
Same framework duty, two changes. Massachusetts requires it to describe 'in detail how the large frontier developer handles' each topic, where SB 53 requires it to describe 'how the large frontier developer approaches' them, and Massachusetts adds an eleventh topic at clause (iv), the ability of the models to automate AI research and development, which has no counterpart in the SB 53 list. Clause (iv) carries a typo, 'challengers to risk monitoring', reproduced as passed. Clause (xi) matches SB 53 (a)(10) on internal use. Not law yet; awaiting the House.
G.L. c. 93M s. 2(a) (proposed)
Eff. 1 Jul 2027
Quarterly internal-use catastrophic-risk summary to the Attorney General.
Binds you if
Binds you if you are a large frontier developer that uses its own frontier models internally; the duty runs on a clock, not on a release.
Effective
2027-07-01 S.3228, SECTION 355 ↗
Compared with CA
Same three-month clock, one tightened parameter and a different recipient. SB 53 lets the developer substitute 'another reasonable schedule specified by the large frontier developer'; Massachusetts requires any alternate schedule to be 'agreed to by the attorney general', so the escape hatch is bilateral rather than unilateral. The report goes to the Massachusetts Attorney General, who enforces, rather than to California's Office of Emergency Services, who does not. Not law yet; awaiting the House.
G.L. c. 93M s. 2(d) (proposed)
Eff. 1 Jul 2027
Civil penalty up to $1M first violation, $3M subsequent, Attorney General only.
Binds you if
Binds you if you are a large frontier developer that fails to publish or transmit a required document, makes a prohibited statement, misses an incident report, or departs from your own framework.
Effective
2027-07-01 S.3228, SECTION 355 ↗
Compared with CA
Higher ceiling for repeat violations, and on one reading a lower floor. Massachusetts caps repeat violations at $3,000,000 against California's flat cap, matching the $1M/$3M structure Illinois and New York use. One parameter runs the other way: SB 53's cap is 'per violation' and is scaled 'in an amount dependent upon the severity of the violation', where the Massachusetts text caps by whether it is a first or later violation, with no per-violation multiplier on its face. A conduct-level reading could be less severe than California for a first offence spanning many documents. Not law yet; awaiting the House.
G.L. c. 93M s. 5 (proposed)
Eff. 1 Jul 2027
Whistleblower protection keyed to danger, on a 'reasonably believes' standard.
Binds you if
Binds you if you are any frontier developer employing covered employees: those responsible for assessing, managing or addressing risk of critical safety incidents.
Effective
2027-07-01 S.3228, SECTION 355 ↗
Compared with CA
Same trigger, a lower mental-state bar. Protection attaches to danger from catastrophic risk even where no law has been broken, as in SB 53. Amendment 471 struck 'has reasonable cause to believe' and inserted 'reasonably believes'. Massachusetts s. 7(b)(ii) also adds a flat anti-discrimination clause, and s. 7(e) adds court costs to the fee award. Not law yet; awaiting the House.
G.L. c. 93M s. 7(a) (proposed)
Eff. 1 Jul 2027
Internal disclosure channel usable anonymously or by name, with monthly status updates.
Binds you if
Binds you if you are a large frontier developer; the internal-channel duty, unlike the anti-retaliation duty, attaches only to large developers.
Effective
2027-07-01 S.3228, SECTION 355 ↗
Compared with CA
Same channel, open to named disclosures too. SB 53's channel is for employees who 'may anonymously disclose'; Massachusetts makes it available 'anonymously or named', so an employee who signs the disclosure gets the same statutory process. Massachusetts also drops SB 53's 'believes in good faith' in favour of 'reasonably believes'. One slip, reproduced as passed: 'disclose information to the large frontier developer of the covered employee reasonably believes', with 'of' where 'if' is plainly meant. Not law yet; awaiting the House.
G.L. c. 93M s. 7(d)(1) (proposed)
Eff. 1 Jul 2027
Matches CA
5 provisions track the California baseline.
Eff. 1 Jul 2027

Where the bill stands

Recorded actions · malegislature.gov
8 Jul 2026
House
Passed to be engrossed - 148 YEAS to 2 NAYSH.5576 is the House’s economic-development bill; the text the House passed contains no frontier-AI sections.
H.5576
13 Jul 2026
Senate
Read; and referred to the committee on Senate Ways and Means
H.5576
16 Jul 2026
Senate
Committee recommended ought to pass with an amendment striking out all after the enacting clause and inserting in place thereof the text of S3178S.3178 is the Ways and Means text. Its SECTION 106 is where the proposed chapter 93M first appears.
H.5576
23 Jul 2026
Senate
Amendment #471 (Rush) adoptedThe frontier-AI floor amendment: it adds section 3A (annual audit and independent evaluations) to the proposed chapter 93M. Its text is printed as S.3224.
S.3178
24 Jul 2026
Senate
Amended by striking out all after the enacting clause and inserting in place thereof the text of S3178The Senate takes the Ways and Means text, as amended on the floor, as its version of H.5576.
H.5576
24 Jul 2026
Senate
Reprinted, as amended, see S3228S.3228 is that reprinted Senate text, and the version this page quotes.
H.5576
24 Jul 2026
Senate
Read third and passed to be engrossedThe Senate’s floor vote on its version.
H.5576
30 Jul 2026
House
House NON-concurred in the Senate amendmentThe House declines the Senate text rather than voting it up or down section by section.
H.5576
30 Jul 2026
House
Committee of conference appointed - (Michlewitz-Fiola-Soter)
H.5576
30 Jul 2026
Senate
Committee of conference appointed (Finegold-Rodrigues-Durant), in concurrence
H.5576
Now: both chambers are negotiating one text. No action later than 30 July 2026 appears in the bill’s recorded history, last checked 1 August 2026. The proposed chapter 93M binds no one unless the bill is enacted; the Senate text would date the chapter to 1 July 2027 (S.3228, SECTION 355).
↑ Summary

The Bill

Text the Senate passed, verbatim · quoted in statute order
G.L. c. 93M s. 1 (proposed), definition of 'Catastrophic risk'
Matches CA
Click to compare
Catastrophic risk: 50 people or $1B, on the same four parts, with the threshold inclusive§
“Catastrophic risk”, a foreseeable and material risk that a frontier developer’s development, storage, use or deployment of a frontier model [a foundation model trained using more than 10^26 integer or floating-point operations (c. 93M s. 1)] will materially contribute to the death of, or serious injury to, not less than 50 people or not less than $1,000,000,000 in damage to, or loss of, property arising from a single incident involving a frontier model that: (i) provides expert-level assistance in the creation or release of a chemical, biological, radiological or nuclear weapon; (ii) engages in conduct with no meaningful human oversight, intervention or supervision that is either a cyberattack or, if the conduct had been committed by a human, would constitute the crime of murder, assault, extortion or theft, including theft by false pretense; or (iii) evades the control of its frontier developer or user; provided, however, that “catastrophic risk” shall not include a foreseeable and material risk from: (A) information that a frontier model outputs if the information is otherwise publicly accessible in a substantially similar form from a source other than a foundation model; (B) lawful activity of the federal government; or (C) harm caused by a frontier model in combination with other software if the frontier model did not materially contribute to the harm.
Effective
2027-07-01 S.3228, SECTION 355 ↗
Binds you if
Definitional: the harm every framework, report, evaluation and incident duty in the chapter is measured against.
Goes to
n/a: definitional.
Compared with CA
Substantively the same as SB 53. Same four parts, same three carve-outs; only the threshold's boundary word differs ('not less than' for California's 'more than'). Not law yet; awaiting the House.
G.L. c. 93M s. 1 (proposed), definition of 'Critical safety incident'
Tightens CA
Click to compare
Broader trigger: what counts as a reportable critical safety incident§
“Critical safety incident”, any: (i) unauthorized access to, modification of, inadvertent release of or exfiltration of, the model weights [the numerical parameters adjusted through training that determine how a model turns inputs into outputs (c. 93M s. 1)] of a frontier model; [a foundation model trained using more than 10^26 integer or floating-point operations (c. 93M s. 1)] (ii) harm resulting from the materialization of a catastrophic risk; (iii) loss of control of a frontier model that causes death or bodily injury or that demonstrates materially increased catastrophic risk; or (iv) instance where a frontier model that uses deceptive techniques against the frontier developer to subvert the controls or monitoring of its frontier developer outside of the context of an evaluation designed to elicit this behavior and in a manner that demonstrates materially increased catastrophic risk.
Effective
2027-07-01 S.3228, SECTION 355 ↗
Binds you if
Definitional: which events start the 15-day and 24-hour clocks.
Goes to
n/a: definitional; the reporting duty it triggers runs to the Attorney General under s. 3(c).
Compared with CA
Same definition, widened three ways. Clause (i) adds 'inadvertent release of' to the weights-compromise clause and, unlike SB 53's (d)(1), attaches no 'that results in death or bodily injury' qualifier, so a weights leak is reportable on its own. Clause (iii) reaches loss of control that 'demonstrates materially increased catastrophic risk' as well as loss of control causing death or injury, where SB 53 (d)(3) requires death or bodily injury. More events start the clock in Massachusetts than in California. Not law yet; awaiting the House.
G.L. c. 93M s. 1 (proposed), definitions of 'Frontier model' and 'Large frontier developer'
Matches CA
Click to compare
Who is covered: 10^26 operations for the model, $500M revenue for the developer§
“Frontier model”, a foundation model that has been trained using a quantity of computing power greater than 10^26 integer or floating-point operations; provided, however, that the quantity of computing power shall include computing for the original training run and for any subsequent fine-tuning, reinforcement learning or other material modifications the developer applies to a preceding foundation model. “Large frontier developer”, a frontier developer that together with its affiliates collectively has annual gross revenues greater than $500,000,000.
Effective
2027-07-01 S.3228, SECTION 355 ↗
Binds you if
Definitional: a model above 10^26 operations makes you a frontier developer; the heavier duties attach only above $500M in annual gross revenues, affiliates included.
Goes to
n/a: definitional.
Compared with CA
The same pair of numbers every frontier state has landed on. One drafting difference: SB 53 measures revenue 'in the preceding calendar year', where the Massachusetts text says only 'together with its affiliates collectively has annual gross revenues greater than $500,000,000', leaving the measuring year unstated. Massachusetts s. 4 gives the Attorney General the same annual definition-review duty SB 53 gives the Department of Technology. Not law yet; awaiting the House.
G.L. c. 93M s. 2(a) (proposed)
Tightens CA
Click to compare
Publish a frontier AI framework: 11 topics§
Section 2. (a) A large frontier developer [a frontier developer whose revenues with affiliates exceed $500,000,000 (c. 93M s. 1)] shall write, implement, comply with and clearly and conspicuously publish on its internet website a frontier AI framework that applies to the large frontier developer’s frontier models and describes in detail how the large frontier developer handles: (i) incorporating national standards, international standards and industry-consensus best practices into its frontier AI framework; (ii) defining and assessing thresholds used by the large frontier developer to identify and assess whether a frontier model [a foundation model trained using more than 10^26 integer or floating-point operations (c. 93M s. 1)] has capabilities that could pose a catastrophic risk, which may include multiple-tiered thresholds; (iii) applying mitigations to address the potential for catastrophic risks based on the results of assessments undertaken pursuant to clause (ii); (iv) assessing the ability of the large frontier developer’s frontier models to automate artificial intelligence research and development and any increased potential for catastrophic risks or challengers to risk monitoring, assessment or mitigation resulting from such ability;
Effective
2027-07-01 S.3228, SECTION 355 ↗
Binds you if
Binds you if you are a large frontier developer: a frontier developer whose revenues, with affiliates, exceed $500M that has trained a model above 10^26 operations. Massachusetts requires each topic described 'in detail'.
Goes to
The public: published on the developer's own internet website; no filing with any state office
Compared with CA
Same framework duty, two changes. Massachusetts requires it to describe 'in detail how the large frontier developer handles' each topic, where SB 53 requires it to describe 'how the large frontier developer approaches' them, and Massachusetts adds an eleventh topic at clause (iv), the ability of the models to automate AI research and development, which has no counterpart in the SB 53 list. Clause (iv) carries a typo, 'challengers to risk monitoring', reproduced as passed. Clause (xi) matches SB 53 (a)(10) on internal use. Not law yet; awaiting the House.
G.L. c. 93M s. 2(c)(2) (proposed)
Matches CA
Click to compare
Deployment-triggered transparency report with catastrophic-risk assessment summaries§
(2) Before, or concurrently with, deploying a new frontier model or a substantially modified version of an existing frontier model, a large frontier developer [a frontier developer whose revenues with affiliates exceed $500,000,000 (c. 93M s. 1)] shall include in the transparency report required by paragraph (1) summaries of: (i) assessments of catastrophic risks from the frontier model conducted pursuant to the large frontier developer’s frontier AI framework; (ii) the results of such assessments; (iii) the extent to which third-party evaluators were involved; and (iv) any other steps taken to fulfill the requirements of the frontier AI framework with respect to the frontier model.
Effective
2027-07-01 S.3228, SECTION 355 ↗
Binds you if
Binds you if you are a large frontier developer deploying a new or substantially modified frontier model.
Goes to
The public: published on the developer's website; may be folded into a system card or model card
Compared with CA
Clause-for-clause the SB 53 transparency report, reordered from lettered to roman subclauses. Massachusetts s. 2(c)(4) drops SB 53's 'encouraged, but not required' framing for best-practice disclosures in favour of 'may make disclosures', with no change in obligation. Not law yet; awaiting the House.
G.L. c. 93M s. 2(c 1/2) (proposed)
No CA analogue
Click to compare
Standing 180-day residual-risk report, on a clock rather than on a release§
(c 1/2)(1) A large frontier developer [a frontier developer whose revenues with affiliates exceed $500,000,000 (c. 93M s. 1)] shall clearly and conspicuously publish on its internet website a risk report that provides an overall assessment of the catastrophic risks posed by: (i) any frontier models the large frontier developer deploys externally; and (ii) any internally deployed frontier models with capabilities that materially exceed those of any frontier model [a foundation model trained using more than 10^26 integer or floating-point operations (c. 93M s. 1)] that frontier developer has externally deployed. (2) A risk report that is required by paragraph (1) shall include, but not be limited to: (i) a summary of assessments of capabilities of the frontier models relevant to catastrophic risk, which shall address each type of catastrophic risk and describe any material changes to the capabilities of the frontier models relevant to each type of catastrophic risk since the most recently published risk report; (ii) a description of the key threat models the large frontier developer tracks to identify potential catastrophic risks, how observed capabilities of those frontier models relate to each threat model and key mitigations that the large frontier developer has put in place to mitigate any such identified risks; and (iii) an assessment of the residual level of each type of catastrophic risk posed by the frontier models after accounting for the mitigations implemented pursuant to clause (ii); provided, however, that the assessment shall provide sufficient information to demonstrate the evidence and reasoning behind the risk assessment and such information shall be sufficient to allow a reasonable person to reach a similar conclusion to that which the large frontier developer would reach in analyzing the level of risk posed by its frontier model. (3) A large frontier developer shall renew and update the risk report required by paragraph (1) not less than every 180 days and include in each update a comparison of the assessed level of each type of catastrophic risk to the level assessed in the previously published risk report.
Effective
180 days after the act takes effect, or 180 days after first qualifying as a large frontier developer, whichever is later S.3228, SECTION 345 ↗
Binds you if
Binds you if you are a large frontier developer, whether or not you have deployed anything new; the clock runs on the calendar, and it reaches internally deployed models that materially exceed your externally deployed ones.
Goes to
The public: published on the developer's internet website
Compared with CA
California has nothing like this. SB 53's transparency report fires once, on release; Massachusetts adds a standing report every 180 days that must compare against the previous one and meet a stricter evidence standard: a reasonable person must be able to reach the same conclusion from the assessment. Added on the Senate floor by amendment 471 (Sen. Rush). One flaw, reproduced as passed: the effective-date section cites the wrong subsection. Not law yet; awaiting the House.
G.L. c. 93M s. 2(d) (proposed)
Tightens CA
Click to compare
Quarterly internal-use catastrophic-risk summary to the Attorney General§
(d) A large frontier developer [a frontier developer whose revenues with affiliates exceed $500,000,000 (c. 93M s. 1)] shall transmit to the attorney general [the Massachusetts Attorney General, the sole enforcer of proposed c. 93M] a summary of any assessment of catastrophic risk resulting from internal use of its frontier models every 3 months or pursuant to another reasonable schedule as agreed to by the attorney general and large frontier developer.
Effective
2027-07-01 S.3228, SECTION 355 ↗
Binds you if
Binds you if you are a large frontier developer that uses its own frontier models internally; the duty runs on a clock, not on a release.
Goes to
The Attorney General, confidentially (s. 3(b)); exempt from the public-records law under s. 3(f)
Compared with CA
Same three-month clock, one tightened parameter and a different recipient. SB 53 lets the developer substitute 'another reasonable schedule specified by the large frontier developer'; Massachusetts requires any alternate schedule to be 'agreed to by the attorney general', so the escape hatch is bilateral rather than unilateral. The report goes to the Massachusetts Attorney General, who enforces, rather than to California's Office of Emergency Services, who does not. Not law yet; awaiting the House.
G.L. c. 93M s. 2(e) (proposed)
Matches CA
Click to compare
No materially false or misleading statements about catastrophic risk or framework compliance§
(e)(1) A frontier developer shall not make a materially false or misleading statement about catastrophic risk from its frontier models or its management of catastrophic risk. (2) A large frontier developer [a frontier developer whose revenues with affiliates exceed $500,000,000 (c. 93M s. 1)] shall not make a materially false or misleading statement about its implementation of, or compliance with, its frontier AI framework. (3) This subsection shall not apply to a statement that was made in good faith and was reasonable under the circumstances.
Effective
2027-07-01 S.3228, SECTION 355 ↗
Binds you if
Binds you if you are a frontier developer making public claims about catastrophic risk; the framework-compliance clause binds large frontier developers only. The prohibitions run to statements, not to shipping: the chapter sets no deployment bar and no quality standard.
Goes to
n/a: a prohibition, enforced by the Attorney General under s. 5
Compared with CA
No state on this map sets a minimum bar, Massachusetts included. The only 'shall not' aimed at developer conduct is a truthfulness rule about statements, which is what the quote shows. Across the chapter text, 'unreasonable risk', 'shall not deploy', 'critical harm' and 'private right' appear zero times. Section 3A moves closer than any other text here, letting an outside evaluator say on the record that it disagrees with the developer's risk assessment, but no consequence attaches to that disagreement. Not law yet; awaiting the House.
G.L. c. 93M s. 3(c)(1) (proposed)
Matches CA
Click to compare
15-day critical safety incident report to the Attorney General; 24 hours where risk is imminent§
(c)(1) A frontier developer shall report any critical safety incident pertaining to 1 or more of its frontier models to the attorney general [the Massachusetts Attorney General, the sole enforcer of proposed c. 93M] within 15 days of discovering the critical safety incident; provided, however, that if a frontier developer discovers that a critical safety incident poses an imminent risk of death or serious physical injury, the frontier developer shall disclose that incident within 24 hours to an authority, including any law enforcement agency or public safety agency with jurisdiction, that is appropriate based on the nature of that incident and as required by law.
Effective
2027-07-01 S.3228, SECTION 355 ↗
Binds you if
Binds you if you are any frontier developer (not only a large one) that discovers a critical safety incident involving one of its frontier models.
Goes to
The Attorney General within 15 days; within 24 hours, any authority with jurisdiction (including law enforcement or a public safety agency) where the incident poses an imminent risk of death or serious physical injury
Compared with CA
Same clocks, a different recipient. The clocks are identical to SB 53, 15 days ordinarily and 24 hours on imminent risk, with the same 'authority with jurisdiction' routing in the 24-hour case. The ordinary report goes directly to the enforcing authority, the Attorney General, where California's goes to the Office of Emergency Services and reaches the enforcer, if at all, secondhand. A reader who weighs the clock only will fairly read this as a match. The incident definition is broadened too, in its own row. Not law yet; awaiting the House.
G.L. c. 93M s. 3A(a) (proposed)
No CA analogue
Click to compare
Annual third-party audit of compliance, summary published within 30 days§
Section 3A. (a) A large frontier developer [a frontier developer whose revenues with affiliates exceed $500,000,000 (c. 93M s. 1)] shall annually retain a third party to perform an independent audit of compliance with the requirements of section 2 except for subsection (c 1/2) of said section 2. The third party shall conduct audits consistent with generally accepted auditing standards and best practices and shall possess demonstrated competence to perform the audit, including experience employing or contracting with individuals who possess technical expertise in the safety of frontier models.
Effective
2027-01-01, or 180 days after first qualifying as a large frontier developer, whichever is later S.3228, SECTION 346 ↗
Binds you if
Binds you if you are a large frontier developer; the audit covers compliance with section 2, expressly excluding the (c 1/2) risk report, which the separate model evaluation covers instead.
Goes to
The developer, which must publish a high-level summary plus the redacted report within 30 days and transmit the redacted report to the Attorney General (s. 3A(a)(4))
Compared with CA
California mandates no audit at all. Its nearest text requires only that the developer state the extent to which third-party evaluators were involved, and SB 53 sets no auditor-independence standard. This is structurally the Illinois move (PA 104-0538 Sec. 10(d)), arriving by floor amendment 471, which also struck S.3178's SECTION 153 special commission to merely study third-party audits. One timing tension, as passed: the audit section is dated to 2027-01-01 while c. 93M itself would take effect 2027-07-01 (SECTION 355). Not law yet; awaiting the House.
G.L. c. 93M s. 3A(b)(1) (proposed)
No CA analogue
Click to compare
Independent third-party evaluation of the models themselves, at least every 120 days§
(b)(1) A large frontier developer shall engage at least 1 third party to conduct an independent evaluation of the developer’s frontier models with respect to each category of catastrophic risk. A large frontier developer [a frontier developer whose revenues with affiliates exceed $500,000,000 (c. 93M s. 1)] shall engage a third party to conduct its evaluation not more than 30 days after publishing each risk report under subsection (c 1/2) of section 2 and in any event shall conduct an independent evaluation not less than once every 120 days.
Effective
2027-01-01, or 180 days after first qualifying as a large frontier developer, whichever is later S.3228, SECTION 347 ↗
Binds you if
Binds you if you are a large frontier developer: an outside evaluator must be given your most capable frontier models, per category of catastrophic risk, at least three times a year.
Goes to
The public: the third party publishes its own report within 30 days of delivering it, and the developer must link to it (s. 3A(b)(4))
Compared with CA
No other state text on this map goes this far. Illinois requires an audit of compliance; Massachusetts s. 3A(b) requires evaluation of the models themselves against each category of catastrophic risk, with the evaluator granted access to 'the large frontier developer's most capable frontier models' (s. 3A(b)(3)(A)) and required to state whether it disagrees with the developer's own risk claims (s. 3A(b)(2)(iii)(D)). A first-in-the-nation claim is plausible, but no first marker is shown: the only source found for it is a social-media claim that could not be verified, and a first is marked here only on a verifiable outside source. Not law yet; awaiting the House.
G.L. c. 93M s. 3A(c) (proposed)
No CA analogue
Source →
Independence standard for auditors and evaluators, certified to the Attorney General§
(c)(1)(A) A third party engaged under this section shall have no financial, operational or management dependence on the large frontier developer or any of the large frontier developer's affiliates and shall be otherwise free from the large frontier developer's control in reaching conclusions or making recommendations, including through contractual safeguards and conflict of interest policies. (B) If no other source of funding has been established pursuant to clause (iii) of paragraph (1) of subsection (d), a large frontier developer [a frontier developer whose revenues with affiliates exceed $500,000,000 (c. 93M s. 1)] may compensate the third party at reasonable market rates and shall not condition any payment or the amount of any payment on the results of the third party’s audit or evaluation. (2) Prior to accepting any engagement under this section, the third party shall certify in writing to the large frontier developer and the attorney general [the Massachusetts Attorney General, the sole enforcer of proposed c. 93M] that the third party satisfies the independence requirements of this subsection. The certification shall include the third party’s sources of funding and remuneration for the engagement, any other current or recent engagements with the large frontier developer or its affiliates and any other facts that could reasonably be expected to bear on the third party’s independence.
Effective
2027-07-01 S.3228, SECTION 355 ↗
Binds you if
Binds you if you are a large frontier developer engaging an auditor or evaluator, and binds the third party itself, which must certify its independence in writing before accepting the engagement.
Goes to
The large frontier developer and the Attorney General both receive the written independence certification
G.L. c. 93M s. 3A(d)(1) (proposed)
No CA analogue
Source →
Attorney General must build an independent-evaluator ecosystem§
(d)(1) The attorney general, [the Massachusetts Attorney General, the sole enforcer of proposed c. 93M] in consultation with academic institutions, nonprofit organizations and industry stakeholders, shall implement an independent evaluation ecosystem plan by: (i) developing and publishing standards for the qualification of qualified independent third party evaluators; (ii) exploring a licensing system to qualify third party evaluators; (iii) subject to government appropriation, providing government funding or arranging pooled funding to supplement other sources of evaluator funding;
Effective
the plan is due not later than 1 year after the act takes effect (S.3228 SECTION 348) S.3228, SECTION 348 ↗
Binds you if
Binds the Attorney General, not developers: the state, not the industry, is made responsible for there being qualified evaluators to hire.
Goes to
The public, via published qualification standards; findings on licensing go to the joint committee on advanced information technology, the internet and cybersecurity and the joint committee on economic development
Duty
rulemaking
G.L. c. 93M s. 5 (proposed)
Tightens CA
Click to compare
Civil penalty up to $1M first violation, $3M subsequent, Attorney General only§
Section 5. (a) A large frontier developer [a frontier developer whose revenues with affiliates exceed $500,000,000 (c. 93M s. 1)] that fails to publish or transmit a compliant document required to be published or transmitted under this chapter, makes a statement in violation of this chapter, fails to report an incident as required by this chapter, or fails to comply with its own frontier AI framework shall be subject to a civil penalty of not more than $1,000,000 for a first violation and not more than $3,000,000 for subsequent violations. (b) A civil penalty described in this section may only be recovered in a civil action brought by the attorney general. [the Massachusetts Attorney General, the sole enforcer of proposed c. 93M]
Effective
2027-07-01 S.3228, SECTION 355 ↗
Binds you if
Binds you if you are a large frontier developer that fails to publish or transmit a required document, makes a prohibited statement, misses an incident report, or departs from your own framework.
Goes to
The Attorney General, exclusively; no private right of action appears anywhere in the chapter
Compared with CA
Higher ceiling for repeat violations, and on one reading a lower floor. Massachusetts caps repeat violations at $3,000,000 against California's flat cap, matching the $1M/$3M structure Illinois and New York use. One parameter runs the other way: SB 53's cap is 'per violation' and is scaled 'in an amount dependent upon the severity of the violation', where the Massachusetts text caps by whether it is a first or later violation, with no per-violation multiplier on its face. A conduct-level reading could be less severe than California for a first offence spanning many documents. Not law yet; awaiting the House.
G.L. c. 93M s. 7(a) (proposed)
Tightens CA
Click to compare
Whistleblower protection keyed to danger, on a 'reasonably believes' standard§
Section 7. (a) A frontier developer shall not make, adopt, enforce, or enter into a rule, regulation, policy or contract that prevents a covered employee [an employee responsible for assessing, managing or addressing risk of critical safety incidents (c. 93M s. 1)] from disclosing or retaliates against a covered employee for disclosing, information to the attorney general, [the Massachusetts Attorney General, the sole enforcer of proposed c. 93M] a federal authority, a person with authority over the covered employee or another covered employee who has authority to investigate, discover or correct the reported issue, if the covered employee reasonably believes that the information discloses either: (i) the frontier developer’s activities pose a specific and substantial danger to the public health or safety resulting from a catastrophic risk; or (ii) the frontier developer has violated this chapter.
Effective
2027-07-01 S.3228, SECTION 355 ↗
Binds you if
Binds you if you are any frontier developer employing covered employees: those responsible for assessing, managing or addressing risk of critical safety incidents.
Goes to
The Attorney General, a federal authority, a person with authority over the employee, or another covered employee with authority to investigate
Compared with CA
Same trigger, a lower mental-state bar. Protection attaches to danger from catastrophic risk even where no law has been broken, as in SB 53. Amendment 471 struck 'has reasonable cause to believe' and inserted 'reasonably believes'. Massachusetts s. 7(b)(ii) also adds a flat anti-discrimination clause, and s. 7(e) adds court costs to the fee award. Not law yet; awaiting the House.
G.L. c. 93M s. 7(d)(1) (proposed)
Tightens CA
Click to compare
Internal disclosure channel usable anonymously or by name, with monthly status updates§
(d)(1) A large frontier developer [a frontier developer whose revenues with affiliates exceed $500,000,000 (c. 93M s. 1)] shall provide a reasonable internal process through which a covered employee may, anonymously or named, disclose information to the large frontier developer of the covered employee reasonably believes that the information indicates that the large frontier developer’s activities present a specific and substantial danger to the public health or safety resulting from a catastrophic risk or that the large frontier developer violated this chapter, which shall include a monthly update to a person who makes a disclosure under this chapter on the status of the large frontier developer’s investigation of such disclosure and the actions taken by the large frontier developer in response to such disclosure.
Effective
2027-07-01 S.3228, SECTION 355 ↗
Binds you if
Binds you if you are a large frontier developer; the internal-channel duty, unlike the anti-retaliation duty, attaches only to large developers.
Goes to
The developer itself, internally; disclosures and responses go to officers and directors quarterly under s. 7(d)(2)
Compared with CA
Same channel, open to named disclosures too. SB 53's channel is for employees who 'may anonymously disclose'; Massachusetts makes it available 'anonymously or named', so an employee who signs the disclosure gets the same statutory process. Massachusetts also drops SB 53's 'believes in good faith' in favour of 'reasonably believes'. One slip, reproduced as passed: 'disclose information to the large frontier developer of the covered employee reasonably believes', with 'of' where 'if' is plainly meant. Not law yet; awaiting the House.
S.3228 SECTION 345 (offered as SECTION 166 of amendment 471 / S.3224)
No CA analogue
Drafting note
Source →
Effective-date section cites subsection (c), not (c 1/2)§
SECTION 345. Not more than 180 days after the effective date of this act or 180 days after the date on which a frontier developer first qualifies as a large frontier developer, whichever is later, a large frontier developer [a frontier developer whose revenues with affiliates exceed $500,000,000 (c. 93M s. 1)] shall post its risk report required under subsection (c) of section 2 of chapter 93M of the General Laws.
Effective
180 days after the act takes effect, or 180 days after first qualifying, whichever is later S.3228, SECTION 345 ↗
Binds you if
Binds you if you are a large frontier developer subject to the risk report; this is the timing section for that report.
Goes to
n/a: a timing section, not an obligation to a receiver
Full text ↗

Every quote above is checked against the archived official text. This page covers the frontier-model duties only: read the whole bill on malegislature.gov ↗.

CACompared with: G.L. c. 93M s. 1 (proposed), definition of 'Catastrophic risk'
Cal. SB 53
Cal. Bus. & Prof. Code s. 22757.11(c)
(c) (1) “Catastrophic risk” means a foreseeable and material risk that a frontier developer’s development, storage, use, or deployment of a frontier model will materially contribute to the death of, or serious injury to, more than 50 people or more than one billion dollars ($1,000,000,000) in damage to, or loss of, property arising from a single incident involving a frontier model doing any of the following: (A) Providing expert-level assistance in the creation or release of a chemical, biological, radiological, or nuclear weapon. (B) Engaging in conduct with no meaningful human oversight, intervention, or supervision that is either a cyberattack or, if the conduct had been committed by a human, would constitute the crime of murder, assault, extortion, or theft, including theft by false pretense. (C) Evading the control of its frontier developer or user. (2) “Catastrophic risk” does not include a foreseeable and material risk from any of the following: (A) Information that a frontier model outputs if the information is otherwise publicly accessible in a substantially similar form from a source other than a foundation model. (B) Lawful activity of the federal government.

Continue on leginfo.legislature.ca.gov ↗

CACompared with: G.L. c. 93M s. 1 (proposed), definition of 'Critical safety incident'
Cal. SB 53
Cal. Bus. & Prof. Code s. 22757.11(d)·leginfo.legislature.ca.gov, official text ↗
(d) “Critical safety incident” means any of the following: (1) Unauthorized access to, modification of, or exfiltration of, the model weights of a frontier model that results in death or bodily injury. (2) Harm resulting from the materialization of a catastrophic risk. (3) Loss of control of a frontier model causing death or bodily injury. (4) A frontier model that uses deceptive techniques against the frontier developer to subvert the controls or monitoring of its frontier developer outside of the context of an evaluation designed to elicit this behavior and in a manner that demonstrates materially increased catastrophic risk.
CACompared with: G.L. c. 93M s. 1 (proposed), definitions of 'Frontier model' and 'Large frontier developer'
Cal. SB 53
Cal. Bus. & Prof. Code s. 22757.11(i)-(j)·leginfo.legislature.ca.gov, official text ↗
(i) (1) “Frontier model” means a foundation model that was trained using a quantity of computing power greater than 10^26 integer or floating-point operations. (2) The quantity of computing power described in paragraph (1) shall include computing for the original training run and for any subsequent fine-tuning, reinforcement learning, or other material modifications the developer applies to a preceding foundation model. (j) “Large frontier developer” means a frontier developer that together with its affiliates collectively had annual gross revenues in excess of five hundred million dollars ($500,000,000) in the preceding calendar year.
CACompared with: G.L. c. 93M s. 2(a) (proposed)
Cal. SB 53
Cal. Bus. & Prof. Code s. 22757.12(a)·leginfo.legislature.ca.gov, official text ↗
(a) A large frontier developer shall write, implement, comply with, and clearly and conspicuously publish on its internet website a frontier AI framework that applies to the large frontier developer’s frontier models and describes how the large frontier developer approaches all of the following: (1) Incorporating national standards, international standards, and industry-consensus best practices into its frontier AI framework. (2) Defining and assessing thresholds used by the large frontier developer to identify and assess whether a frontier model has capabilities that could pose a catastrophic risk, which may include multiple-tiered thresholds. (3) Applying mitigations to address the potential for catastrophic risks based on the results of assessments undertaken pursuant to paragraph (2).
CACompared with: G.L. c. 93M s. 2(c)(2) (proposed)
Cal. SB 53
Cal. Bus. & Prof. Code s. 22757.12(c)(2)·leginfo.legislature.ca.gov, official text ↗
(2) Before, or concurrently with, deploying a new frontier model or a substantially modified version of an existing frontier model, a large frontier developer shall include in the transparency report required by paragraph (1) summaries of all of the following: (A) Assessments of catastrophic risks from the frontier model conducted pursuant to the large frontier developer’s frontier AI framework. (B) The results of those assessments. (C) The extent to which third-party evaluators were involved. (D) Other steps taken to fulfill the requirements of the frontier AI framework with respect to the frontier model.
CACompared with: G.L. c. 93M s. 2(c 1/2) (proposed)
Cal. SB 53
Cal. Bus. & Prof. Code s. 22757.12(c)(2) (nearest miss: deployment-triggered summaries, not a standing report)·leginfo.legislature.ca.gov, official text ↗
(2) Before, or concurrently with, deploying a new frontier model or a substantially modified version of an existing frontier model, a large frontier developer shall include in the transparency report required by paragraph (1) summaries of all of the following: (A) Assessments of catastrophic risks from the frontier model conducted pursuant to the large frontier developer’s frontier AI framework. (B) The results of those assessments. (C) The extent to which third-party evaluators were involved. (D) Other steps taken to fulfill the requirements of the frontier AI framework with respect to the frontier model.
CACompared with: G.L. c. 93M s. 2(d) (proposed)
Cal. SB 53
Cal. Bus. & Prof. Code s. 22757.12(d)·leginfo.legislature.ca.gov, official text ↗
(d) A large frontier developer shall transmit to the Office of Emergency Services a summary of any assessment of catastrophic risk resulting from internal use of its frontier models every three months or pursuant to another reasonable schedule specified by the large frontier developer and communicated in writing to the Office of Emergency Services with written updates, as appropriate.
CACompared with: G.L. c. 93M s. 2(e) (proposed)
Cal. SB 53
Cal. Bus. & Prof. Code s. 22757.12(e)·leginfo.legislature.ca.gov, official text ↗
(e) (1) (A) A frontier developer shall not make a materially false or misleading statement about catastrophic risk from its frontier models or its management of catastrophic risk. (B) A large frontier developer shall not make a materially false or misleading statement about its implementation of, or compliance with, its frontier AI framework. (2) This subdivision does not apply to a statement that was made in good faith and was reasonable under the circumstances.
CACompared with: G.L. c. 93M s. 3(c)(1) (proposed)
Cal. SB 53
Cal. Bus. & Prof. Code s. 22757.13(c)(1)-(2)·leginfo.legislature.ca.gov, official text ↗
(c) (1) Subject to paragraph (2), a frontier developer shall report any critical safety incident pertaining to one or more of its frontier models to the Office of Emergency Services within 15 days of discovering the critical safety incident. (2) If a frontier developer discovers that a critical safety incident poses an imminent risk of death or serious physical injury, the frontier developer shall disclose that incident within 24 hours to an authority, including any law enforcement agency or public safety agency with jurisdiction, that is appropriate based on the nature of that incident and as required by law.
CACompared with: G.L. c. 93M s. 3A(a) (proposed)
Cal. SB 53
Cal. Bus. & Prof. Code s. 22757.12(c)(2)(C) (nearest miss: disclose third-party involvement, no audit)·leginfo.legislature.ca.gov, official text ↗
(2) Before, or concurrently with, deploying a new frontier model or a substantially modified version of an existing frontier model, a large frontier developer shall include in the transparency report required by paragraph (1) summaries of all of the following: (A) Assessments of catastrophic risks from the frontier model conducted pursuant to the large frontier developer’s frontier AI framework. (B) The results of those assessments. (C) The extent to which third-party evaluators were involved.
CACompared with: G.L. c. 93M s. 3A(b)(1) (proposed)
Cal. SB 53
Cal. Bus. & Prof. Code s. 22757.12(c)(2)(C) (nearest miss: disclose third-party involvement, no evaluation duty)·leginfo.legislature.ca.gov, official text ↗
(2) Before, or concurrently with, deploying a new frontier model or a substantially modified version of an existing frontier model, a large frontier developer shall include in the transparency report required by paragraph (1) summaries of all of the following: (A) Assessments of catastrophic risks from the frontier model conducted pursuant to the large frontier developer’s frontier AI framework. (B) The results of those assessments. (C) The extent to which third-party evaluators were involved.
MASource text: G.L. c. 93M s. 3A(c) (proposed)
Massachusetts S.3228
G.L. c. 93M s. 3A(c) (proposed)
(c)(1)(A) A third party engaged under this section shall have no financial, operational or management dependence on the large frontier developer or any of the large frontier developer's affiliates and shall be otherwise free from the large frontier developer's control in reaching conclusions or making recommendations, including through contractual safeguards and conflict of interest policies. (B) If no other source of funding has been established pursuant to clause (iii) of paragraph (1) of subsection (d), a large frontier developer may compensate the third party at reasonable market rates and shall not condition any payment or the amount of any payment on the results of the third party’s audit or evaluation. (2) Prior to accepting any engagement under this section, the third party shall certify in writing to the large frontier developer and the attorney general that the third party satisfies the independence requirements of this subsection.

Continue on malegislature.gov ↗

MASource text: G.L. c. 93M s. 3A(d)(1) (proposed)
Massachusetts S.3228
G.L. c. 93M s. 3A(d)(1) (proposed)·malegislature.gov, official text ↗
(d)(1) The attorney general, in consultation with academic institutions, nonprofit organizations and industry stakeholders, shall implement an independent evaluation ecosystem plan by: (i) developing and publishing standards for the qualification of qualified independent third party evaluators; (ii) exploring a licensing system to qualify third party evaluators; (iii) subject to government appropriation, providing government funding or arranging pooled funding to supplement other sources of evaluator funding;
CACompared with: G.L. c. 93M s. 5 (proposed)
Cal. SB 53
Cal. Bus. & Prof. Code s. 22757.15·leginfo.legislature.ca.gov, official text ↗
(a) A large frontier developer that fails to publish or transmit a compliant document required to be published or transmitted under this chapter, makes a statement in violation of subdivision (e) of Section 22757.12, fails to report an incident as required by Section 22757.13, or fails to comply with its own frontier AI framework shall be subject to a civil penalty in an amount dependent upon the severity of the violation that does not exceed one million dollars ($1,000,000) per violation. (b) A civil penalty described in this section shall be recovered in a civil action brought only by the Attorney General.
CACompared with: G.L. c. 93M s. 7(a) (proposed)
Cal. SB 53
(a) A frontier developer shall not make, adopt, enforce, or enter into a rule, regulation, policy, or contract that prevents a covered employee from disclosing, or retaliates against a covered employee for disclosing, information to the Attorney General, a federal authority, a person with authority over the covered employee, or another covered employee who has authority to investigate, discover, or correct the reported issue, if the covered employee has reasonable cause to believe that the information discloses either of the following: (1) The frontier developer’s activities pose a specific and substantial danger to the public health or safety resulting from a catastrophic risk. (2) The frontier developer has violated Chapter 25.1 (commencing with Section 22757.10) of Division 8 of the Business and Professions Code.
CACompared with: G.L. c. 93M s. 7(d)(1) (proposed)
Cal. SB 53
Cal. Lab. Code s. 1107.1(e)(1)·leginfo.legislature.ca.gov, official text ↗
(e) (1) A large frontier developer shall provide a reasonable internal process through which a covered employee may anonymously disclose information to the large frontier developer if the covered employee believes in good faith that the information indicates that the large frontier developer’s activities present a specific and substantial danger to the public health or safety resulting from a catastrophic risk or that the large frontier developer violated Chapter 25.1 (commencing with Section 22757.10) of Division 8 of the Business and Professions Code, including a monthly update to the person who made the disclosure regarding the status of the large frontier developer’s investigation of the disclosure and the actions taken by the large frontier developer in response to the disclosure.
MASource text: S.3228 SECTION 345 (offered as SECTION 166 of amendment 471 / S.3224)
Massachusetts S.3228
S.3228 SECTION 345 (offered as SECTION 166 of amendment 471 / S.3224)·malegislature.gov, official text ↗
SECTION 345. Not more than 180 days after the effective date of this act or 180 days after the date on which a frontier developer first qualifies as a large frontier developer, whichever is later, a large frontier developer shall post its risk report required under subsection (c) of section 2 of chapter 93M of the General Laws.