One bill, assembled verbatim from enacted state law — the strictest enacted version of each obligation, in the statutes’ own words. Click any section: the source bill opens at right with the identical text highlighted.
4 enacted acts read · sections drawn from CA, NY, IL
Sources
Official state texts only
AN ACT governing frontier artificial intelligence development, as it already binds a developer operating in every state.
Assembled verbatim from: Cal. SB 53 (2025) · N.Y. RAISE Act (2026) · Ill. PA 104-0538 (2026)
Sec. 1
CAIn force
Source →
Frontier AI framework.A large frontier developer [a frontier developer whose group revenue topped $500 million last year — § 22757.11(j)] shall write, implement, comply with, and clearly and conspicuously publish on its internet website a frontier AI framework that applies to the large frontier developer’s frontier models and describes how the large frontier developer approaches all of the following: (1) Incorporating national standards, international standards, and industry-consensus best practices into its frontier AI framework. …
Sec. 2
CAIn force
Source →
Transparency reports.Before, or concurrently with, deploying a new frontier model or a substantially modified version of an existing frontier model, a frontier developer shall clearly and conspicuously publish on its internet website a transparency report containing all of the following: (A) The internet website of the frontier developer. (B) A mechanism that enables a natural person to communicate with the frontier developer. (C) The release date of the frontier model. (D) The languages supported by the frontier model. …
Sec. 3
ILEff. 1 Jan 2027
Source →
Machine-readable summaries.All summaries required under paragraph (2) shall be provided in a machine-readable format to facilitate verification of model claims.
Sec. 4
ILEff. 1 Jan 2027
Source →
Critical-incident reporting.A frontier developer [anyone who trains, or starts training, a model above the 10^26-operation compute line] shall report any critical safety incident pertaining to one or more of its frontier models to the Agency [the Illinois Emergency Management Agency and Office of Homeland Security] and the Attorney General within 72 hours of the frontier developer learning facts sufficient to establish a reasonable belief that a critical safety incident has occurred. …
Sec. 5
CAIn force
Source →
Whistleblower protection.A frontier developer shall not make, adopt, enforce, or enter into a rule, regulation, policy, or contract that prevents a covered employee from disclosing, or retaliates against a covered employee for disclosing, information to the Attorney General, a federal authority, a person with authority over the covered employee, or another covered employee who has authority to investigate, discover, or correct the reported issue, if the covered employee has reasonable cause to believe that the information discloses either…
Sec. 6
ILEff. 1 Jan 2028
Source →
Independent verification.Beginning on January 1, 2028 or 90 days after a developer first qualifies as a large frontier developer, [anyone who trains, or starts training, a model above the 10^26-operation compute line] whichever is later, a large frontier developer shall annually retain a third party to perform an independent audit of compliance with the requirements of this Section. The third party shall conduct audits consistent with generally accepted auditing standards and best practices and shall possess demonstrated competence to perform the audit, including experience employing or contracting with individuals who…
Sec. 7
ILEff. 1 Jan 2027
Source →
Enforcement.A large frontier developer that fails to publish or transmit a compliant document required to be published or transmitted under this Act, makes a statement in violation of subsection (f) of Section 10, fails to have a third party perform an independent audit of compliance as required by subsection (d) of Section 10, fails to report a critical safety incident as required by Section 15, or fails to comply with its own frontier AI framework shall be subject to a civil penalty in an amount dependent upon the severity…
Sec. 8
NYEff. 1 Jan 2027
Source →
Registration.Except as otherwise provided in this section, no large frontier developer may develop, deploy, or operate a frontier model, in whole or in part in New York state, without having a current disclosure statement filed with the office and paying the required share. 2. The disclosure statement shall be filed in the form and the manner prescribed by the office and shall contain all the information required by the office. …
Sec. 9
CAIn force
Source →
Scope and thresholds.“Frontier developer” means a person who has trained, or initiated the training of, a frontier model, with respect to which the person has used, or intends to use, at least as much computing power to train the frontier model as would meet the technical specifications found in subdivision (i). (i) (1) “Frontier model” means a foundation model that was trained using a quantity of computing power greater than 10^26 integer or floating-point operations. …
Sec. 10
CAIn force
Source →
Internal-use risk.A large frontier developer [a frontier developer whose group revenue topped $500 million last year — § 22757.11(j)] shall transmit to the Office of Emergency Services [the California Governor's Office of Emergency Services (Cal OES)] a summary of any assessment of catastrophic risk resulting from internal use of its frontier models every three months or pursuant to another reasonable schedule specified by the large frontier developer and communicated in writing to the Office of Emergency Services with written updates, as appropriate.
Sec. 11
CAIn force
Source →
Minimum-bar standards.A frontier developer shall not make a materially false or misleading statement about catastrophic risk from its frontier models or its management of catastrophic risk. (B) A large frontier developer [a frontier developer whose group revenue topped $500 million last year — § 22757.11(j)] shall not make a materially false or misleading statement about its implementation of, or compliance with, its frontier AI framework. (2) This subdivision does not apply to a statement that was made in good faith and was reasonable under the circumstances.
Scope
Each section binds only whom its own state’s text reaches: every act here starts at a model trained above 10^26 computational operations, and the heavier duties add a $500 million group-revenue test for a “large frontier developer” — so a section keeps its source state’s scope and its source state’s definitions, not a national one.
22757.12. (a) A large frontier developer shall write, implement, comply with, and clearly and conspicuously publish on its internet website a frontier AI framework that applies to…
All three frontier states require a published framework on materially the same 10-topic template. Illinois is named strongest on this row in states.json, but its text is tagged MATCHES against SB 53, so the composite prints the California baseline (R4).
First in the nation
SB 53 was the first enacted state statute aimed specifically at frontier-AI transparency; every later state framework requirement is measured against this text. fpf.org ↗
(c) (1) Before, or concurrently with, deploying a new frontier model or a substantially modified version of an existing frontier model, a frontier developer shall clearly and conspicuously publish on its internet website a transparency report containing all of the following: (A) The internet website of the frontier developer. …
(3) All summaries required under paragraph (2) shall be provided in a machine-readable format to facilitate verification of model claims. (4) A frontier developer that publishes the information described in paragraph (1) or (2) as part of a larger…
Why Illinois holds this section
Illinois has no California analogue for this duty, so it is carried as its own section rather than folded into transparency reports (incl. pre-deployment catastrophic-risk assessments) (R5).
(c) A frontier developer shall report any critical safety incident pertaining to one or more of its frontier models to the Agency and the Attorney General within 72 hours of the frontier developer learning facts sufficient to establish a reasonable belief that a critical safety incident has occurred. The disclosure shall include: (i) the date of the critical safety incident; (ii) the reasons the incident…
Why Illinois holds this section
Illinois and New York both run a 72-hour clock against California's 15 days.
1107.1. (a) A frontier developer shall not make, adopt, enforce, or enter into a rule, regulation, policy, or contract that prevents a covered employee from disclosing, or retaliates against a covered employee for disclosing, information to the Attorney General, a federal authority, a person with authority over the covered employee, or another covered employee who has authority to investigate, discover, or…
California protects disclosure of evidence of catastrophic-risk danger even where no law has been broken — the protection is keyed to the danger, not to a legal violation, which is the case that matters most for frontier risk.
(d) Beginning on January 1, 2028 or 90 days after a developer first qualifies as a large frontier developer, whichever is later, a large frontier developer shall annually retain a…
Illinois is the first state to require annual independent third-party audits of frontier-AI transparency compliance.
First in the nation
California only requires disclosing whether third-party evaluators were involved; Illinois makes someone independent actually check, every year. skadden.com ↗
Section 25. Civil penalty. (a) A large frontier developer that fails to publish or transmit a compliant document required to be published or transmitted under this Act, makes a statement in violation of subsection (f) of Section 10, fails to have a third party perform an independent audit of compliance as required by subsection (d) of Section 10, fails to report a critical safety incident as required by…
Large frontier developer disclosure. 1. Except as otherwise provided in this section, no large frontier developer may develop, deploy, or operate a frontier model, in whole or in part in New York state, without having a current disclosure statement filed with the office and paying the required share. 2. …
(h) “Frontier developer” means a person who has trained, or initiated the training of, a frontier model, with respect to which the person has used, or intends to use, at least as much computing power to train the frontier model as would meet the technical specifications found in subdivision (i). …
(d) A large frontier developer shall transmit to the Office of Emergency Services a summary of any assessment of catastrophic risk resulting from internal use of its frontier models every three months or pursuant to another reasonable schedule specified by the large frontier developer and communicated in writing to the Office of Emergency Services with written updates, as appropriate. (e) (1) (A) A frontier…
Why California holds this section
California is strongest because its internal-use duty runs on a clock rather than on a release: § 22757.12(d) requires a large frontier developer to summarize its assessment of catastrophic risk from its own internal use of frontier models and transmit that summary to the Office of Emergency Services every three months.
(e) (1) (A) A frontier developer shall not make a materially false or misleading statement about catastrophic risk from its frontier models or its management of catastrophic risk. (B) A large frontier developer shall not make a materially false or misleading statement about its implementation of, or compliance with, its frontier AI framework. …
Every enacted frontier AI law in the United States is disclosure-and-process: it governs what a developer must write down, publish, and report, not how good its safety practices must actually be.