State Laws Affecting Frontier US AI Companies

Frontier AI law, state by state

This site carries every enacted state frontier-AI law, whole and in the statutes' own words, and is checked against the official texts every day.
Last verified
1 August 2026

The map

Massachusetts: open the bill page Minnesota Montana North Dakota Hawaii Idaho Washington Arizona California: open the bill page Colorado SB 26-189: AI use, not frontier development Nevada New Mexico Oregon Utah SB 149: AI use, not frontier development Wyoming Arkansas Iowa Kansas Missouri Nebraska Oklahoma South Dakota Louisiana Texas HB 149: AI use, not frontier development Connecticut: open the bill page New Hampshire Rhode Island Vermont Alabama Florida Georgia Mississippi South Carolina Illinois: open the bill page Indiana Kentucky North Carolina Ohio Tennessee Virginia Wisconsin West Virginia Delaware District of Columbia Maryland New Jersey New York: open the bill page Pennsylvania Maine Michigan Alaska
Color follows what is on the books, not how strict it is · enacted text only, as of 1 August 2026
Enacted frontier-AI statutes: California · New York · Illinois, and Connecticut in part. No other state has one; other AI laws may apply.
Mass. S.3228In conference

What the colors mean

Frontier AI law enacted
California · New York · Illinois
Partial: some frontier duties
Connecticut
Bill moving
Massachusetts: S.3228, in conference
AI law, different scope
Colorado · Texas · Utah
No frontier-AI statute; other AI laws may apply
Everything else

Bill pages

Law Who it covers Covered harms Key obligations Status and timeline
CA SB 53: Transparency in Frontier Artificial Intelligence Act
California SB 53 is the baseline every other state is measured against.
  • Frontier developer: trains a model above 10^26 integer or floating-point operations.
  • Large frontier developer: that, plus annual gross revenues above $500,000,000 with affiliates.
  • Catastrophic risk: more than 50 deaths or serious injuries, or more than $1,000,000,000 in property damage, from a single incident of:
  • expert-level assistance in creating or releasing a chemical, biological, radiological or nuclear weapon;
  • conduct with no meaningful human oversight that is a cyberattack, or would be the crime of murder, assault, extortion or theft;
  • a model evading the control of its developer or user.
  • Publish a frontier AI framework. First.
  • Transparency report at every deployment.
  • Critical safety incident reported to the Office of Emergency Services in 15 days.
  • 24 hours where risk of death or serious injury is imminent.
  • Quarterly internal-use catastrophic-risk summaries.
  • Whistleblower protection.
In force since 1 January 2026.
NY RAISE Act, as amended by S8828: Gen. Bus. Law art. 44-B
An SB 53 copy, plus a registration regime run by the state's financial regulator, plus a 72-hour incident clock, minus whistleblower protections.
  • Frontier model: trained above 10^26 integer or floating-point operations.
  • Large frontier developer: a frontier developer that, with its affiliates, had annual gross revenues above $500,000,000 in the preceding calendar year.
  • Catastrophic risk: more than fifty deaths or serious injuries, or more than one billion dollars ($1,000,000,000) in property damage, from a single incident of:
  • expert-level assistance in creating or releasing a chemical, biological, radiological or nuclear weapon;
  • conduct with no meaningful human oversight that is a cyberattack, or would be the crime of murder, assault, extortion or theft;
  • a model evading the control of its developer or user.
  • Publish a frontier AI framework.
  • Transparency report at deployment.
  • Critical safety incident reported to the office in 72 hours.
  • Quarterly internal-use catastrophic-risk summaries.
  • Register a disclosure statement with the Department of Financial Services before developing or deploying.
  • Pay assessments that fund the regulator.
Enacted; effective 1 January 2027.
IL Public Act 104-0538 (SB 315): Artificial Intelligence Safety Measures Act
An SB 53 copy, plus first-in-the-nation annual independent audits, plus a 72-hour incident clock.
  • Frontier developer: trains a model above 10^26 integer or floating-point operations.
  • Large frontier developer: that, plus annual gross revenues above $500,000,000 with affiliates, in the preceding calendar year.
  • Catastrophic risk: 50+ deaths or serious injuries, or $1B+ in property damage, in a single incident.
  • A reportable critical safety incident is any of:
  • weight theft causing death or injury;
  • realized catastrophic risk;
  • loss of control causing death or injury;
  • a model deceiving its developer to subvert controls.
  • Publish a frontier AI framework.
  • Machine-readable transparency summaries.
  • Critical safety incident reported to the Agency and the Attorney General in 72 hours.
  • Annual independent third-party audit. First.
  • Public audit summary within 30 days.
  • Registration before a frontier model is developed, deployed or operated.
Enacted; effective 1 January 2027. Framework and audit duties begin 1 January 2028.
MA S.3228: Senate-engrossed frontier AI text (proposed G.L. c. 93M)
An SB 53 copy, plus a standing 180-day risk report, plus annual audits, plus independent model evaluations every 120 days (not law yet, in conference).
  • Frontier model: trained above 10^26 integer or floating-point operations.
  • Large frontier developer: a frontier developer with annual gross revenues, counting affiliates, greater than $500,000,000.
  • Catastrophic risk: not less than 50 deaths or serious injuries, or not less than $1,000,000,000 in property damage, from a single incident of:
  • expert-level assistance in creating or releasing a chemical, biological, radiological or nuclear weapon;
  • conduct with no meaningful human oversight that is a cyberattack, or would be the crime of murder, assault, extortion or theft;
  • a model that evades the control of its developer or user.
  • Would require: a frontier AI framework on eleven topics;
  • a standing residual-risk report every 180 days;
  • an annual third-party audit;
  • independent evaluation of the models themselves at least every 120 days;
  • critical safety incidents to the Attorney General in 15 days.
Not law. House non-concurred 30 July 2026; conference committees appointed in both branches. Chapter 93M would take effect 1 July 2027 if enacted.
CT Public Act 26-15 (SB 5): An Act Concerning Online Safety
SB 53's whistleblower chapter only, with the penalty cut from $1,000,000 to $1,000 per violation.
No retaliation for a safety report; an anonymous internal channel; reports escalated to officers and directors at least quarterly; notice of rights. Enacted; in force 1 October 2026; internal channel due 1 January 2027.

Also on the books

These laws regulate using AI, not building it. That is why this site does not track them.
Decisions about people
Colorado SB 26-189: Automated Decision-Making Technology Takes effect 1 January 2027. When a company uses AI to help decide a person's job, loan, housing, insurance, school admission, health care, or government benefits, it must say so, and after a bad decision the person can ask for a human review and get errors corrected.
Official text ↗
AI use, not development
Texas HB 149: Responsible Artificial Intelligence Governance Act In force since 1 January 2026. Limits specific uses of AI, sets rules for government use, and lets companies test AI products under lighter rules for three years.
Official text ↗
Must say it's AI
Utah SB 149: Artificial Intelligence Policy Act (as amended 2025) In force since 1 May 2024, expires 1 July 2027. Businesses and licensed professionals must tell you when you are talking to an AI.
Official text ↗