Illinois · House Bill · 104th General Assembly (2025–2026)
HB4799
Illinois HB 4799 — Transparency in Frontier Artificial Intelligence Act

Status ● Introduced Effective N/A Passage Likelihood L

WHAT THIS BILL REGULATES · 6 REQUIREMENT TYPES

How Is This Bill Enforced

Enforcement Authority
Attorney General enforcement only. Civil penalties are recovered in a civil action brought exclusively by the Attorney General. No private right of action.
Private Right of Action
No private right of action. Enforcement is exclusive to the designated authority.
Penalties
Civil penalty up to $1,000,000 per violation, dependent on severity. Loss of equity value does not count as damage to or loss of property. No injunctive relief or attorney fees specified.

What This Bill Requires

Verbatim statutory text on the left; plain-language analysis and a per-section checklist on the right. Numbered markers cross-link to the matching checklist row.

Statutory Text
Analysis & Obligations
Section 5
Definitions

As used in this Act: "AffiliateAffiliate"Affiliate" means a person controlling, controlled by, or under common control with a specified person, directly or indirectly, through one or more intermediaries.Section 5" means a person controlling, controlled by, or under common control with a specified person, directly or indirectly, through one or more intermediaries. "Artificial intelligenceArtificial intelligence"Artificial intelligence" has the meaning set forth in Section 2-101 of the Illinois Human Rights Act.Section 5" has the meaning set forth in Section 2-101 of the Illinois Human Rights Act. "Catastrophic riskCatastrophic risk"Catastrophic risk" means a foreseeable and material risk that a frontier developer's development, storage, use, or deployment of a frontier model will materially contribute to the death of, or serious injury to, more than 50 people or more than $1,000,000,000 in damage to, or loss of, property arising from a single incident involving a frontier model doing any of the following: (1) providing expert-level assistance in the creation or release of a chemical, biological, radiological, or nuclear weapon; (2) engaging in conduct with no meaningful human oversight, intervention, or supervision that is either a cyberattack or, if the conduct had been committed by a human, would constitute the crime of murder, assault, extortion, or theft, including theft by false pretense; or (3) evading the control of its frontier developer or user. "Catastrophic risk" does not include a foreseeable and material risk from any of the following: (1) information that a frontier model outputs if the information is otherwise publicly accessible in a substantially similar form from a source other than a foundation model; (2) lawful activity of the federal government; or (3) harm caused by a frontier model in combination with other software if the frontier model did not materially contribute to the harm.Section 5" means a foreseeable and material risk that a frontier developerFrontier developer"Frontier developer" means a person who has trained, or initiated the training of, a frontier model, with respect to which the person has used, or intends to use, at least as much computing power to train the frontier model as would meet the technical specifications found in the definition of "frontier model".Section 5's development, storage, use, or deployment of a frontier modelFrontier model"Frontier model" means a foundation model that was trained using a quantity of computing power greater than 10^26 integer or floating-point operations. The quantity of computing power described in this definition shall include computing for the original training run and for any subsequent fine-tuning, reinforcement learning, or other material modifications the developer applies to a preceding foundation model.Section 5 will materially contribute to the death of, or serious injury to, more than 50 people or more than $1,000,000,000 in damage to, or loss of, propertyProperty"Property" means tangible or intangible property.Section 5 arising from a single incident involving a frontier modelFrontier model"Frontier model" means a foundation model that was trained using a quantity of computing power greater than 10^26 integer or floating-point operations. The quantity of computing power described in this definition shall include computing for the original training run and for any subsequent fine-tuning, reinforcement learning, or other material modifications the developer applies to a preceding foundation model.Section 5 doing any of the following: (1) providing expert-level assistance in the creation or release of a chemical, biological, radiological, or nuclear weapon; (2) engaging in conduct with no meaningful human oversight, intervention, or supervision that is either a cyberattack or, if the conduct had been committed by a human, would constitute the crime of murder, assault, extortion, or theft, including theft by false pretense; or (3) evading the control of its frontier developerFrontier developer"Frontier developer" means a person who has trained, or initiated the training of, a frontier model, with respect to which the person has used, or intends to use, at least as much computing power to train the frontier model as would meet the technical specifications found in the definition of "frontier model".Section 5 or user. "Catastrophic riskCatastrophic risk"Catastrophic risk" means a foreseeable and material risk that a frontier developer's development, storage, use, or deployment of a frontier model will materially contribute to the death of, or serious injury to, more than 50 people or more than $1,000,000,000 in damage to, or loss of, property arising from a single incident involving a frontier model doing any of the following: (1) providing expert-level assistance in the creation or release of a chemical, biological, radiological, or nuclear weapon; (2) engaging in conduct with no meaningful human oversight, intervention, or supervision that is either a cyberattack or, if the conduct had been committed by a human, would constitute the crime of murder, assault, extortion, or theft, including theft by false pretense; or (3) evading the control of its frontier developer or user. "Catastrophic risk" does not include a foreseeable and material risk from any of the following: (1) information that a frontier model outputs if the information is otherwise publicly accessible in a substantially similar form from a source other than a foundation model; (2) lawful activity of the federal government; or (3) harm caused by a frontier model in combination with other software if the frontier model did not materially contribute to the harm.Section 5" does not include a foreseeable and material risk from any of the following: (1) information that a frontier modelFrontier model"Frontier model" means a foundation model that was trained using a quantity of computing power greater than 10^26 integer or floating-point operations. The quantity of computing power described in this definition shall include computing for the original training run and for any subsequent fine-tuning, reinforcement learning, or other material modifications the developer applies to a preceding foundation model.Section 5 outputs if the information is otherwise publicly accessible in a substantially similar form from a source other than a foundation modelFoundation model"Foundation model" means an artificial intelligence model that is all of the following: (1) trained on a broad data set; (2) designed for generality of output; and (3) adaptable to a wide range of distinctive tasks.Section 5; (2) lawful activity of the federal government; or (3) harm caused by a frontier modelFrontier model"Frontier model" means a foundation model that was trained using a quantity of computing power greater than 10^26 integer or floating-point operations. The quantity of computing power described in this definition shall include computing for the original training run and for any subsequent fine-tuning, reinforcement learning, or other material modifications the developer applies to a preceding foundation model.Section 5 in combination with other software if the frontier modelFrontier model"Frontier model" means a foundation model that was trained using a quantity of computing power greater than 10^26 integer or floating-point operations. The quantity of computing power described in this definition shall include computing for the original training run and for any subsequent fine-tuning, reinforcement learning, or other material modifications the developer applies to a preceding foundation model.Section 5 did not materially contribute to the harm. "Critical safety incidentCritical safety incident"Critical safety incident" means any of the following: (1) unauthorized access to, modification of, or exfiltration of, the model weights of a frontier model that results in death or bodily injury; (2) harm resulting from the materialization of a catastrophic risk; (3) loss of control of a frontier model causing death or bodily injury; or (4) a frontier model that uses deceptive techniques against the frontier developer to subvert the controls or monitoring of its frontier developer outside of the context of an evaluation designed to elicit this behavior and in a manner that demonstrates materially increased catastrophic risk.Section 5" means any of the following: (1) unauthorized access to, modification of, or exfiltration of, the model weights of a frontier modelFrontier model"Frontier model" means a foundation model that was trained using a quantity of computing power greater than 10^26 integer or floating-point operations. The quantity of computing power described in this definition shall include computing for the original training run and for any subsequent fine-tuning, reinforcement learning, or other material modifications the developer applies to a preceding foundation model.Section 5 that results in death or bodily injury; (2) harm resulting from the materialization of a catastrophic riskCatastrophic risk"Catastrophic risk" means a foreseeable and material risk that a frontier developer's development, storage, use, or deployment of a frontier model will materially contribute to the death of, or serious injury to, more than 50 people or more than $1,000,000,000 in damage to, or loss of, property arising from a single incident involving a frontier model doing any of the following: (1) providing expert-level assistance in the creation or release of a chemical, biological, radiological, or nuclear weapon; (2) engaging in conduct with no meaningful human oversight, intervention, or supervision that is either a cyberattack or, if the conduct had been committed by a human, would constitute the crime of murder, assault, extortion, or theft, including theft by false pretense; or (3) evading the control of its frontier developer or user. "Catastrophic risk" does not include a foreseeable and material risk from any of the following: (1) information that a frontier model outputs if the information is otherwise publicly accessible in a substantially similar form from a source other than a foundation model; (2) lawful activity of the federal government; or (3) harm caused by a frontier model in combination with other software if the frontier model did not materially contribute to the harm.Section 5; (3) loss of control of a frontier modelFrontier model"Frontier model" means a foundation model that was trained using a quantity of computing power greater than 10^26 integer or floating-point operations. The quantity of computing power described in this definition shall include computing for the original training run and for any subsequent fine-tuning, reinforcement learning, or other material modifications the developer applies to a preceding foundation model.Section 5 causing death or bodily injury; or (4) a frontier modelFrontier model"Frontier model" means a foundation model that was trained using a quantity of computing power greater than 10^26 integer or floating-point operations. The quantity of computing power described in this definition shall include computing for the original training run and for any subsequent fine-tuning, reinforcement learning, or other material modifications the developer applies to a preceding foundation model.Section 5 that uses deceptive techniques against the frontier developerFrontier developer"Frontier developer" means a person who has trained, or initiated the training of, a frontier model, with respect to which the person has used, or intends to use, at least as much computing power to train the frontier model as would meet the technical specifications found in the definition of "frontier model".Section 5 to subvert the controls or monitoring of its frontier developerFrontier developer"Frontier developer" means a person who has trained, or initiated the training of, a frontier model, with respect to which the person has used, or intends to use, at least as much computing power to train the frontier model as would meet the technical specifications found in the definition of "frontier model".Section 5 outside of the context of an evaluation designed to elicit this behavior and in a manner that demonstrates materially increased catastrophic riskCatastrophic risk"Catastrophic risk" means a foreseeable and material risk that a frontier developer's development, storage, use, or deployment of a frontier model will materially contribute to the death of, or serious injury to, more than 50 people or more than $1,000,000,000 in damage to, or loss of, property arising from a single incident involving a frontier model doing any of the following: (1) providing expert-level assistance in the creation or release of a chemical, biological, radiological, or nuclear weapon; (2) engaging in conduct with no meaningful human oversight, intervention, or supervision that is either a cyberattack or, if the conduct had been committed by a human, would constitute the crime of murder, assault, extortion, or theft, including theft by false pretense; or (3) evading the control of its frontier developer or user. "Catastrophic risk" does not include a foreseeable and material risk from any of the following: (1) information that a frontier model outputs if the information is otherwise publicly accessible in a substantially similar form from a source other than a foundation model; (2) lawful activity of the federal government; or (3) harm caused by a frontier model in combination with other software if the frontier model did not materially contribute to the harm.Section 5. "DeployDeploy"Deploy" means to make a frontier model available to a third party for use, modification, copying, or combination with other software. "Deploy" does not include making a frontier model available to a third party for the primary purpose of developing or evaluating the frontier model.Section 5" means to make a frontier modelFrontier model"Frontier model" means a foundation model that was trained using a quantity of computing power greater than 10^26 integer or floating-point operations. The quantity of computing power described in this definition shall include computing for the original training run and for any subsequent fine-tuning, reinforcement learning, or other material modifications the developer applies to a preceding foundation model.Section 5 available to a third party for use, modification, copying, or combination with other software. "DeployDeploy"Deploy" means to make a frontier model available to a third party for use, modification, copying, or combination with other software. "Deploy" does not include making a frontier model available to a third party for the primary purpose of developing or evaluating the frontier model.Section 5" does not include making a frontier modelFrontier model"Frontier model" means a foundation model that was trained using a quantity of computing power greater than 10^26 integer or floating-point operations. The quantity of computing power described in this definition shall include computing for the original training run and for any subsequent fine-tuning, reinforcement learning, or other material modifications the developer applies to a preceding foundation model.Section 5 available to a third party for the primary purpose of developing or evaluating the frontier modelFrontier model"Frontier model" means a foundation model that was trained using a quantity of computing power greater than 10^26 integer or floating-point operations. The quantity of computing power described in this definition shall include computing for the original training run and for any subsequent fine-tuning, reinforcement learning, or other material modifications the developer applies to a preceding foundation model.Section 5. "Foundation modelFoundation model"Foundation model" means an artificial intelligence model that is all of the following: (1) trained on a broad data set; (2) designed for generality of output; and (3) adaptable to a wide range of distinctive tasks.Section 5" means an artificial intelligenceArtificial intelligence"Artificial intelligence" has the meaning set forth in Section 2-101 of the Illinois Human Rights Act.Section 5 model that is all of the following: (1) trained on a broad data set; (2) designed for generality of output; and (3) adaptable to a wide range of distinctive tasks. "Frontier artificial intelligence frameworkFrontier artificial intelligence framework"Frontier artificial intelligence framework" means documented technical and organizational protocols to manage, assess, and mitigate catastrophic risks.Section 5" means documented technical and organizational protocols to manage, assess, and mitigate catastrophic risksCatastrophic risk"Catastrophic risk" means a foreseeable and material risk that a frontier developer's development, storage, use, or deployment of a frontier model will materially contribute to the death of, or serious injury to, more than 50 people or more than $1,000,000,000 in damage to, or loss of, property arising from a single incident involving a frontier model doing any of the following: (1) providing expert-level assistance in the creation or release of a chemical, biological, radiological, or nuclear weapon; (2) engaging in conduct with no meaningful human oversight, intervention, or supervision that is either a cyberattack or, if the conduct had been committed by a human, would constitute the crime of murder, assault, extortion, or theft, including theft by false pretense; or (3) evading the control of its frontier developer or user. "Catastrophic risk" does not include a foreseeable and material risk from any of the following: (1) information that a frontier model outputs if the information is otherwise publicly accessible in a substantially similar form from a source other than a foundation model; (2) lawful activity of the federal government; or (3) harm caused by a frontier model in combination with other software if the frontier model did not materially contribute to the harm.Section 5. "Frontier developerFrontier developer"Frontier developer" means a person who has trained, or initiated the training of, a frontier model, with respect to which the person has used, or intends to use, at least as much computing power to train the frontier model as would meet the technical specifications found in the definition of "frontier model".Section 5" means a person who has trained, or initiated the training of, a frontier modelFrontier model"Frontier model" means a foundation model that was trained using a quantity of computing power greater than 10^26 integer or floating-point operations. The quantity of computing power described in this definition shall include computing for the original training run and for any subsequent fine-tuning, reinforcement learning, or other material modifications the developer applies to a preceding foundation model.Section 5, with respect to which the person has used, or intends to use, at least as much computing power to train the frontier modelFrontier model"Frontier model" means a foundation model that was trained using a quantity of computing power greater than 10^26 integer or floating-point operations. The quantity of computing power described in this definition shall include computing for the original training run and for any subsequent fine-tuning, reinforcement learning, or other material modifications the developer applies to a preceding foundation model.Section 5 as would meet the technical specifications found in the definition of "frontier modelFrontier model"Frontier model" means a foundation model that was trained using a quantity of computing power greater than 10^26 integer or floating-point operations. The quantity of computing power described in this definition shall include computing for the original training run and for any subsequent fine-tuning, reinforcement learning, or other material modifications the developer applies to a preceding foundation model.Section 5". "Frontier modelFrontier model"Frontier model" means a foundation model that was trained using a quantity of computing power greater than 10^26 integer or floating-point operations. The quantity of computing power described in this definition shall include computing for the original training run and for any subsequent fine-tuning, reinforcement learning, or other material modifications the developer applies to a preceding foundation model.Section 5" means a foundation modelFoundation model"Foundation model" means an artificial intelligence model that is all of the following: (1) trained on a broad data set; (2) designed for generality of output; and (3) adaptable to a wide range of distinctive tasks.Section 5 that was trained using a quantity of computing power greater than 10^26 integer or floating-point operations. The quantity of computing power described in this definition shall include computing for the original training run and for any subsequent fine-tuning, reinforcement learning, or other material modifications the developer applies to a preceding foundation modelFoundation model"Foundation model" means an artificial intelligence model that is all of the following: (1) trained on a broad data set; (2) designed for generality of output; and (3) adaptable to a wide range of distinctive tasks.Section 5. "Large frontier developerLarge frontier developer"Large frontier developer" means a frontier developer that together with its affiliates collectively had annual gross revenues in excess of $500,000,000 in the preceding calendar year.Section 5" means a frontier developerFrontier developer"Frontier developer" means a person who has trained, or initiated the training of, a frontier model, with respect to which the person has used, or intends to use, at least as much computing power to train the frontier model as would meet the technical specifications found in the definition of "frontier model".Section 5 that together with its affiliatesAffiliate"Affiliate" means a person controlling, controlled by, or under common control with a specified person, directly or indirectly, through one or more intermediaries.Section 5 collectively had annual gross revenues in excess of $500,000,000 in the preceding calendar year. "Model weightModel weight"Model weight" means a numerical parameter in a frontier model that is adjusted through training and that helps determine how inputs are transformed into outputs.Section 5" means a numerical parameter in a frontier modelFrontier model"Frontier model" means a foundation model that was trained using a quantity of computing power greater than 10^26 integer or floating-point operations. The quantity of computing power described in this definition shall include computing for the original training run and for any subsequent fine-tuning, reinforcement learning, or other material modifications the developer applies to a preceding foundation model.Section 5 that is adjusted through training and that helps determine how inputs are transformed into outputs. "PropertyProperty"Property" means tangible or intangible property.Section 5" means tangible or intangible propertyProperty"Property" means tangible or intangible property.Section 5.

Section 5 establishes the definitional framework for the Act. Key thresholds include the 10^26 floating-point operations compute threshold that triggers frontier model classification and the $500,000,000 annual gross revenue threshold (including affiliates) that elevates a frontier developer to large frontier developer status, which triggers the most burdensome obligations. The definition of catastrophic risk is narrowly scoped to CBRN weapon assistance, autonomous criminal conduct, and loss-of-control scenarios causing death or serious injury to more than 50 people or more than $1 billion in property damage.

Section 10
Frontier artificial intelligence framework
Developer

(a) 1 A large frontier developerLarge frontier developer"Large frontier developer" means a frontier developer that together with its affiliates collectively had annual gross revenues in excess of $500,000,000 in the preceding calendar year.Section 5 shall write, implement, comply with, and clearly and conspicuously publish on its website a frontier artificial intelligence frameworkFrontier artificial intelligence framework"Frontier artificial intelligence framework" means documented technical and organizational protocols to manage, assess, and mitigate catastrophic risks.Section 5 that applies to the large frontier developerLarge frontier developer"Large frontier developer" means a frontier developer that together with its affiliates collectively had annual gross revenues in excess of $500,000,000 in the preceding calendar year.Section 5's frontier modelsFrontier model"Frontier model" means a foundation model that was trained using a quantity of computing power greater than 10^26 integer or floating-point operations. The quantity of computing power described in this definition shall include computing for the original training run and for any subsequent fine-tuning, reinforcement learning, or other material modifications the developer applies to a preceding foundation model.Section 5 and describes how the large frontier developerLarge frontier developer"Large frontier developer" means a frontier developer that together with its affiliates collectively had annual gross revenues in excess of $500,000,000 in the preceding calendar year.Section 5 approaches all of the following: (1) incorporating national standards, international standards, and industry-consensus best practices into its frontier artificial intelligence frameworkFrontier artificial intelligence framework"Frontier artificial intelligence framework" means documented technical and organizational protocols to manage, assess, and mitigate catastrophic risks.Section 5; (2) defining and assessing thresholds used by the large frontier developerLarge frontier developer"Large frontier developer" means a frontier developer that together with its affiliates collectively had annual gross revenues in excess of $500,000,000 in the preceding calendar year.Section 5 to identify and assess whether a frontier modelFrontier model"Frontier model" means a foundation model that was trained using a quantity of computing power greater than 10^26 integer or floating-point operations. The quantity of computing power described in this definition shall include computing for the original training run and for any subsequent fine-tuning, reinforcement learning, or other material modifications the developer applies to a preceding foundation model.Section 5 has capabilities that could pose a catastrophic riskCatastrophic risk"Catastrophic risk" means a foreseeable and material risk that a frontier developer's development, storage, use, or deployment of a frontier model will materially contribute to the death of, or serious injury to, more than 50 people or more than $1,000,000,000 in damage to, or loss of, property arising from a single incident involving a frontier model doing any of the following: (1) providing expert-level assistance in the creation or release of a chemical, biological, radiological, or nuclear weapon; (2) engaging in conduct with no meaningful human oversight, intervention, or supervision that is either a cyberattack or, if the conduct had been committed by a human, would constitute the crime of murder, assault, extortion, or theft, including theft by false pretense; or (3) evading the control of its frontier developer or user. "Catastrophic risk" does not include a foreseeable and material risk from any of the following: (1) information that a frontier model outputs if the information is otherwise publicly accessible in a substantially similar form from a source other than a foundation model; (2) lawful activity of the federal government; or (3) harm caused by a frontier model in combination with other software if the frontier model did not materially contribute to the harm.Section 5, which may include multiple-tiered thresholds; (3) applying mitigations to address the potential for catastrophic risksCatastrophic risk"Catastrophic risk" means a foreseeable and material risk that a frontier developer's development, storage, use, or deployment of a frontier model will materially contribute to the death of, or serious injury to, more than 50 people or more than $1,000,000,000 in damage to, or loss of, property arising from a single incident involving a frontier model doing any of the following: (1) providing expert-level assistance in the creation or release of a chemical, biological, radiological, or nuclear weapon; (2) engaging in conduct with no meaningful human oversight, intervention, or supervision that is either a cyberattack or, if the conduct had been committed by a human, would constitute the crime of murder, assault, extortion, or theft, including theft by false pretense; or (3) evading the control of its frontier developer or user. "Catastrophic risk" does not include a foreseeable and material risk from any of the following: (1) information that a frontier model outputs if the information is otherwise publicly accessible in a substantially similar form from a source other than a foundation model; (2) lawful activity of the federal government; or (3) harm caused by a frontier model in combination with other software if the frontier model did not materially contribute to the harm.Section 5 based on the results of assessments undertaken under paragraph (2); (4) reviewing assessments and adequacy of mitigations as part of the decision to deployDeploy"Deploy" means to make a frontier model available to a third party for use, modification, copying, or combination with other software. "Deploy" does not include making a frontier model available to a third party for the primary purpose of developing or evaluating the frontier model.Section 5 a frontier modelFrontier model"Frontier model" means a foundation model that was trained using a quantity of computing power greater than 10^26 integer or floating-point operations. The quantity of computing power described in this definition shall include computing for the original training run and for any subsequent fine-tuning, reinforcement learning, or other material modifications the developer applies to a preceding foundation model.Section 5 or use it extensively internally; (5) using third parties to assess the potential for catastrophic risksCatastrophic risk"Catastrophic risk" means a foreseeable and material risk that a frontier developer's development, storage, use, or deployment of a frontier model will materially contribute to the death of, or serious injury to, more than 50 people or more than $1,000,000,000 in damage to, or loss of, property arising from a single incident involving a frontier model doing any of the following: (1) providing expert-level assistance in the creation or release of a chemical, biological, radiological, or nuclear weapon; (2) engaging in conduct with no meaningful human oversight, intervention, or supervision that is either a cyberattack or, if the conduct had been committed by a human, would constitute the crime of murder, assault, extortion, or theft, including theft by false pretense; or (3) evading the control of its frontier developer or user. "Catastrophic risk" does not include a foreseeable and material risk from any of the following: (1) information that a frontier model outputs if the information is otherwise publicly accessible in a substantially similar form from a source other than a foundation model; (2) lawful activity of the federal government; or (3) harm caused by a frontier model in combination with other software if the frontier model did not materially contribute to the harm.Section 5 and the effectiveness of mitigations of catastrophic risksCatastrophic risk"Catastrophic risk" means a foreseeable and material risk that a frontier developer's development, storage, use, or deployment of a frontier model will materially contribute to the death of, or serious injury to, more than 50 people or more than $1,000,000,000 in damage to, or loss of, property arising from a single incident involving a frontier model doing any of the following: (1) providing expert-level assistance in the creation or release of a chemical, biological, radiological, or nuclear weapon; (2) engaging in conduct with no meaningful human oversight, intervention, or supervision that is either a cyberattack or, if the conduct had been committed by a human, would constitute the crime of murder, assault, extortion, or theft, including theft by false pretense; or (3) evading the control of its frontier developer or user. "Catastrophic risk" does not include a foreseeable and material risk from any of the following: (1) information that a frontier model outputs if the information is otherwise publicly accessible in a substantially similar form from a source other than a foundation model; (2) lawful activity of the federal government; or (3) harm caused by a frontier model in combination with other software if the frontier model did not materially contribute to the harm.Section 5; (6) revisiting and updating the frontier artificial intelligence frameworkFrontier artificial intelligence framework"Frontier artificial intelligence framework" means documented technical and organizational protocols to manage, assess, and mitigate catastrophic risks.Section 5, including any criteria that trigger updates and how the large frontier developerLarge frontier developer"Large frontier developer" means a frontier developer that together with its affiliates collectively had annual gross revenues in excess of $500,000,000 in the preceding calendar year.Section 5 determines when its frontier modelsFrontier model"Frontier model" means a foundation model that was trained using a quantity of computing power greater than 10^26 integer or floating-point operations. The quantity of computing power described in this definition shall include computing for the original training run and for any subsequent fine-tuning, reinforcement learning, or other material modifications the developer applies to a preceding foundation model.Section 5 are substantially modified enough to require disclosures under subsection (c); (7) cybersecurity practices to secure unreleased model weightsModel weight"Model weight" means a numerical parameter in a frontier model that is adjusted through training and that helps determine how inputs are transformed into outputs.Section 5 from unauthorized modification or transfer by internal or external parties; (8) identifying and responding to critical safety incidentsCritical safety incident"Critical safety incident" means any of the following: (1) unauthorized access to, modification of, or exfiltration of, the model weights of a frontier model that results in death or bodily injury; (2) harm resulting from the materialization of a catastrophic risk; (3) loss of control of a frontier model causing death or bodily injury; or (4) a frontier model that uses deceptive techniques against the frontier developer to subvert the controls or monitoring of its frontier developer outside of the context of an evaluation designed to elicit this behavior and in a manner that demonstrates materially increased catastrophic risk.Section 5; (9) instituting internal governance practices to ensure implementation of these processes; and (10) assessing and managing catastrophic riskCatastrophic risk"Catastrophic risk" means a foreseeable and material risk that a frontier developer's development, storage, use, or deployment of a frontier model will materially contribute to the death of, or serious injury to, more than 50 people or more than $1,000,000,000 in damage to, or loss of, property arising from a single incident involving a frontier model doing any of the following: (1) providing expert-level assistance in the creation or release of a chemical, biological, radiological, or nuclear weapon; (2) engaging in conduct with no meaningful human oversight, intervention, or supervision that is either a cyberattack or, if the conduct had been committed by a human, would constitute the crime of murder, assault, extortion, or theft, including theft by false pretense; or (3) evading the control of its frontier developer or user. "Catastrophic risk" does not include a foreseeable and material risk from any of the following: (1) information that a frontier model outputs if the information is otherwise publicly accessible in a substantially similar form from a source other than a foundation model; (2) lawful activity of the federal government; or (3) harm caused by a frontier model in combination with other software if the frontier model did not materially contribute to the harm.Section 5 resulting from the internal use of its frontier modelsFrontier model"Frontier model" means a foundation model that was trained using a quantity of computing power greater than 10^26 integer or floating-point operations. The quantity of computing power described in this definition shall include computing for the original training run and for any subsequent fine-tuning, reinforcement learning, or other material modifications the developer applies to a preceding foundation model.Section 5, including risks resulting from a frontier modelFrontier model"Frontier model" means a foundation model that was trained using a quantity of computing power greater than 10^26 integer or floating-point operations. The quantity of computing power described in this definition shall include computing for the original training run and for any subsequent fine-tuning, reinforcement learning, or other material modifications the developer applies to a preceding foundation model.Section 5 circumventing oversight mechanisms.

(b)(1)–(2) 2 A large frontier developerLarge frontier developer"Large frontier developer" means a frontier developer that together with its affiliates collectively had annual gross revenues in excess of $500,000,000 in the preceding calendar year.Section 5 shall review and, as appropriate, update its frontier artificial intelligence frameworkFrontier artificial intelligence framework"Frontier artificial intelligence framework" means documented technical and organizational protocols to manage, assess, and mitigate catastrophic risks.Section 5 at least once per year. (2) If a large frontier developerLarge frontier developer"Large frontier developer" means a frontier developer that together with its affiliates collectively had annual gross revenues in excess of $500,000,000 in the preceding calendar year.Section 5 makes a material modification to its frontier artificial intelligence frameworkFrontier artificial intelligence framework"Frontier artificial intelligence framework" means documented technical and organizational protocols to manage, assess, and mitigate catastrophic risks.Section 5, the large frontier developerLarge frontier developer"Large frontier developer" means a frontier developer that together with its affiliates collectively had annual gross revenues in excess of $500,000,000 in the preceding calendar year.Section 5 shall clearly and conspicuously publish the modified frontier artificial intelligence frameworkFrontier artificial intelligence framework"Frontier artificial intelligence framework" means documented technical and organizational protocols to manage, assess, and mitigate catastrophic risks.Section 5 and a justification for that modification within 30 days.

(c)(1) 3 Before, or concurrently with, deploying a new frontier modelFrontier model"Frontier model" means a foundation model that was trained using a quantity of computing power greater than 10^26 integer or floating-point operations. The quantity of computing power described in this definition shall include computing for the original training run and for any subsequent fine-tuning, reinforcement learning, or other material modifications the developer applies to a preceding foundation model.Section 5 or a substantially modified version of an existing frontier modelFrontier model"Frontier model" means a foundation model that was trained using a quantity of computing power greater than 10^26 integer or floating-point operations. The quantity of computing power described in this definition shall include computing for the original training run and for any subsequent fine-tuning, reinforcement learning, or other material modifications the developer applies to a preceding foundation model.Section 5, a frontier developerFrontier developer"Frontier developer" means a person who has trained, or initiated the training of, a frontier model, with respect to which the person has used, or intends to use, at least as much computing power to train the frontier model as would meet the technical specifications found in the definition of "frontier model".Section 5 shall clearly and conspicuously publish on its website a transparency report containing all of the following: (A) the website of the frontier developerFrontier developer"Frontier developer" means a person who has trained, or initiated the training of, a frontier model, with respect to which the person has used, or intends to use, at least as much computing power to train the frontier model as would meet the technical specifications found in the definition of "frontier model".Section 5; (B) a mechanism that enables a natural person to communicate with the frontier developerFrontier developer"Frontier developer" means a person who has trained, or initiated the training of, a frontier model, with respect to which the person has used, or intends to use, at least as much computing power to train the frontier model as would meet the technical specifications found in the definition of "frontier model".Section 5; (C) the release date of the frontier modelFrontier model"Frontier model" means a foundation model that was trained using a quantity of computing power greater than 10^26 integer or floating-point operations. The quantity of computing power described in this definition shall include computing for the original training run and for any subsequent fine-tuning, reinforcement learning, or other material modifications the developer applies to a preceding foundation model.Section 5; (D) the languages supported by the frontier modelFrontier model"Frontier model" means a foundation model that was trained using a quantity of computing power greater than 10^26 integer or floating-point operations. The quantity of computing power described in this definition shall include computing for the original training run and for any subsequent fine-tuning, reinforcement learning, or other material modifications the developer applies to a preceding foundation model.Section 5; (E) the modalities of output supported by the frontier modelFrontier model"Frontier model" means a foundation model that was trained using a quantity of computing power greater than 10^26 integer or floating-point operations. The quantity of computing power described in this definition shall include computing for the original training run and for any subsequent fine-tuning, reinforcement learning, or other material modifications the developer applies to a preceding foundation model.Section 5; (F) the intended uses of the frontier modelFrontier model"Frontier model" means a foundation model that was trained using a quantity of computing power greater than 10^26 integer or floating-point operations. The quantity of computing power described in this definition shall include computing for the original training run and for any subsequent fine-tuning, reinforcement learning, or other material modifications the developer applies to a preceding foundation model.Section 5; and (G) any generally applicable restrictions or conditions on uses of the frontier modelFrontier model"Frontier model" means a foundation model that was trained using a quantity of computing power greater than 10^26 integer or floating-point operations. The quantity of computing power described in this definition shall include computing for the original training run and for any subsequent fine-tuning, reinforcement learning, or other material modifications the developer applies to a preceding foundation model.Section 5.

(c)(2) 4 Before, or concurrently with, deploying a new frontier modelFrontier model"Frontier model" means a foundation model that was trained using a quantity of computing power greater than 10^26 integer or floating-point operations. The quantity of computing power described in this definition shall include computing for the original training run and for any subsequent fine-tuning, reinforcement learning, or other material modifications the developer applies to a preceding foundation model.Section 5 or a substantially modified version of an existing frontier modelFrontier model"Frontier model" means a foundation model that was trained using a quantity of computing power greater than 10^26 integer or floating-point operations. The quantity of computing power described in this definition shall include computing for the original training run and for any subsequent fine-tuning, reinforcement learning, or other material modifications the developer applies to a preceding foundation model.Section 5, a large frontier developerLarge frontier developer"Large frontier developer" means a frontier developer that together with its affiliates collectively had annual gross revenues in excess of $500,000,000 in the preceding calendar year.Section 5 shall include in the transparency report required by paragraph (1) of subsection (c) summaries of all of the following: (A) assessments of catastrophic risksCatastrophic risk"Catastrophic risk" means a foreseeable and material risk that a frontier developer's development, storage, use, or deployment of a frontier model will materially contribute to the death of, or serious injury to, more than 50 people or more than $1,000,000,000 in damage to, or loss of, property arising from a single incident involving a frontier model doing any of the following: (1) providing expert-level assistance in the creation or release of a chemical, biological, radiological, or nuclear weapon; (2) engaging in conduct with no meaningful human oversight, intervention, or supervision that is either a cyberattack or, if the conduct had been committed by a human, would constitute the crime of murder, assault, extortion, or theft, including theft by false pretense; or (3) evading the control of its frontier developer or user. "Catastrophic risk" does not include a foreseeable and material risk from any of the following: (1) information that a frontier model outputs if the information is otherwise publicly accessible in a substantially similar form from a source other than a foundation model; (2) lawful activity of the federal government; or (3) harm caused by a frontier model in combination with other software if the frontier model did not materially contribute to the harm.Section 5 from the frontier modelFrontier model"Frontier model" means a foundation model that was trained using a quantity of computing power greater than 10^26 integer or floating-point operations. The quantity of computing power described in this definition shall include computing for the original training run and for any subsequent fine-tuning, reinforcement learning, or other material modifications the developer applies to a preceding foundation model.Section 5 conducted under the large frontier developerLarge frontier developer"Large frontier developer" means a frontier developer that together with its affiliates collectively had annual gross revenues in excess of $500,000,000 in the preceding calendar year.Section 5's frontier artificial intelligence frameworkFrontier artificial intelligence framework"Frontier artificial intelligence framework" means documented technical and organizational protocols to manage, assess, and mitigate catastrophic risks.Section 5; (B) the results of the assessments under subparagraph (A); (C) the extent to which third-party evaluators were involved; and (D) other steps taken to fulfill the requirements of the frontier artificial intelligence frameworkFrontier artificial intelligence framework"Frontier artificial intelligence framework" means documented technical and organizational protocols to manage, assess, and mitigate catastrophic risks.Section 5 with respect to the frontier modelFrontier model"Frontier model" means a foundation model that was trained using a quantity of computing power greater than 10^26 integer or floating-point operations. The quantity of computing power described in this definition shall include computing for the original training run and for any subsequent fine-tuning, reinforcement learning, or other material modifications the developer applies to a preceding foundation model.Section 5.

(c)(3) A frontier developerFrontier developer"Frontier developer" means a person who has trained, or initiated the training of, a frontier model, with respect to which the person has used, or intends to use, at least as much computing power to train the frontier model as would meet the technical specifications found in the definition of "frontier model".Section 5 that publishes the information described in paragraph (1) or (2) as part of a larger document, including a system card or model card, shall be deemed in compliance with the applicable paragraph.

(c)(4) A frontier developerFrontier developer"Frontier developer" means a person who has trained, or initiated the training of, a frontier model, with respect to which the person has used, or intends to use, at least as much computing power to train the frontier model as would meet the technical specifications found in the definition of "frontier model".Section 5 is encouraged, but not required, to make disclosures described in this subsection that are consistent with, or superior to, industry best practices.

(d) 5 A large frontier developerLarge frontier developer"Large frontier developer" means a frontier developer that together with its affiliates collectively had annual gross revenues in excess of $500,000,000 in the preceding calendar year.Section 5 shall transmit to the Attorney General a summary of any assessment of catastrophic riskCatastrophic risk"Catastrophic risk" means a foreseeable and material risk that a frontier developer's development, storage, use, or deployment of a frontier model will materially contribute to the death of, or serious injury to, more than 50 people or more than $1,000,000,000 in damage to, or loss of, property arising from a single incident involving a frontier model doing any of the following: (1) providing expert-level assistance in the creation or release of a chemical, biological, radiological, or nuclear weapon; (2) engaging in conduct with no meaningful human oversight, intervention, or supervision that is either a cyberattack or, if the conduct had been committed by a human, would constitute the crime of murder, assault, extortion, or theft, including theft by false pretense; or (3) evading the control of its frontier developer or user. "Catastrophic risk" does not include a foreseeable and material risk from any of the following: (1) information that a frontier model outputs if the information is otherwise publicly accessible in a substantially similar form from a source other than a foundation model; (2) lawful activity of the federal government; or (3) harm caused by a frontier model in combination with other software if the frontier model did not materially contribute to the harm.Section 5 resulting from internal use of its frontier modelsFrontier model"Frontier model" means a foundation model that was trained using a quantity of computing power greater than 10^26 integer or floating-point operations. The quantity of computing power described in this definition shall include computing for the original training run and for any subsequent fine-tuning, reinforcement learning, or other material modifications the developer applies to a preceding foundation model.Section 5 every 3 months or under another reasonable schedule specified by the large frontier developerLarge frontier developer"Large frontier developer" means a frontier developer that together with its affiliates collectively had annual gross revenues in excess of $500,000,000 in the preceding calendar year.Section 5 and communicated in writing to the Attorney General with written updates, as appropriate.

(e)(1)–(2) 6 A frontier developerFrontier developer"Frontier developer" means a person who has trained, or initiated the training of, a frontier model, with respect to which the person has used, or intends to use, at least as much computing power to train the frontier model as would meet the technical specifications found in the definition of "frontier model".Section 5 shall not make a materially false or misleading statement about catastrophic riskCatastrophic risk"Catastrophic risk" means a foreseeable and material risk that a frontier developer's development, storage, use, or deployment of a frontier model will materially contribute to the death of, or serious injury to, more than 50 people or more than $1,000,000,000 in damage to, or loss of, property arising from a single incident involving a frontier model doing any of the following: (1) providing expert-level assistance in the creation or release of a chemical, biological, radiological, or nuclear weapon; (2) engaging in conduct with no meaningful human oversight, intervention, or supervision that is either a cyberattack or, if the conduct had been committed by a human, would constitute the crime of murder, assault, extortion, or theft, including theft by false pretense; or (3) evading the control of its frontier developer or user. "Catastrophic risk" does not include a foreseeable and material risk from any of the following: (1) information that a frontier model outputs if the information is otherwise publicly accessible in a substantially similar form from a source other than a foundation model; (2) lawful activity of the federal government; or (3) harm caused by a frontier model in combination with other software if the frontier model did not materially contribute to the harm.Section 5 from its frontier modelsFrontier model"Frontier model" means a foundation model that was trained using a quantity of computing power greater than 10^26 integer or floating-point operations. The quantity of computing power described in this definition shall include computing for the original training run and for any subsequent fine-tuning, reinforcement learning, or other material modifications the developer applies to a preceding foundation model.Section 5 or its management of catastrophic riskCatastrophic risk"Catastrophic risk" means a foreseeable and material risk that a frontier developer's development, storage, use, or deployment of a frontier model will materially contribute to the death of, or serious injury to, more than 50 people or more than $1,000,000,000 in damage to, or loss of, property arising from a single incident involving a frontier model doing any of the following: (1) providing expert-level assistance in the creation or release of a chemical, biological, radiological, or nuclear weapon; (2) engaging in conduct with no meaningful human oversight, intervention, or supervision that is either a cyberattack or, if the conduct had been committed by a human, would constitute the crime of murder, assault, extortion, or theft, including theft by false pretense; or (3) evading the control of its frontier developer or user. "Catastrophic risk" does not include a foreseeable and material risk from any of the following: (1) information that a frontier model outputs if the information is otherwise publicly accessible in a substantially similar form from a source other than a foundation model; (2) lawful activity of the federal government; or (3) harm caused by a frontier model in combination with other software if the frontier model did not materially contribute to the harm.Section 5. A large frontier developerLarge frontier developer"Large frontier developer" means a frontier developer that together with its affiliates collectively had annual gross revenues in excess of $500,000,000 in the preceding calendar year.Section 5 shall not make a materially false or misleading statement about its implementation of, or compliance with, its frontier artificial intelligence frameworkFrontier artificial intelligence framework"Frontier artificial intelligence framework" means documented technical and organizational protocols to manage, assess, and mitigate catastrophic risks.Section 5. (2) This subsection does not apply to a statement that was made in good faith and was reasonable under the circumstances.

(f)(1)–(2) 7 When a frontier developerFrontier developer"Frontier developer" means a person who has trained, or initiated the training of, a frontier model, with respect to which the person has used, or intends to use, at least as much computing power to train the frontier model as would meet the technical specifications found in the definition of "frontier model".Section 5 publishes documents to comply with this Section, the frontier developerFrontier developer"Frontier developer" means a person who has trained, or initiated the training of, a frontier model, with respect to which the person has used, or intends to use, at least as much computing power to train the frontier model as would meet the technical specifications found in the definition of "frontier model".Section 5 may make redactions to those documents that are necessary to protect the frontier developerFrontier developer"Frontier developer" means a person who has trained, or initiated the training of, a frontier model, with respect to which the person has used, or intends to use, at least as much computing power to train the frontier model as would meet the technical specifications found in the definition of "frontier model".Section 5's trade secrets, the frontier developerFrontier developer"Frontier developer" means a person who has trained, or initiated the training of, a frontier model, with respect to which the person has used, or intends to use, at least as much computing power to train the frontier model as would meet the technical specifications found in the definition of "frontier model".Section 5's cybersecurity, public safety, or the national security of the United States or to comply with any federal or State law. (2) If a frontier developerFrontier developer"Frontier developer" means a person who has trained, or initiated the training of, a frontier model, with respect to which the person has used, or intends to use, at least as much computing power to train the frontier model as would meet the technical specifications found in the definition of "frontier model".Section 5 redacts information in a document in accordance with this subsection, the frontier developerFrontier developer"Frontier developer" means a person who has trained, or initiated the training of, a frontier model, with respect to which the person has used, or intends to use, at least as much computing power to train the frontier model as would meet the technical specifications found in the definition of "frontier model".Section 5 shall describe the character and justification of the redaction in any published version of the document to the extent permitted by the concerns that justify redaction and shall retain the unredacted information for 5 years.

Section 10 is the core governance and transparency provision of the Act. It imposes four distinct obligation clusters on frontier developers and large frontier developers. First, large frontier developers must write, implement, comply with, and publicly publish a comprehensive frontier AI safety framework covering ten enumerated topics — from catastrophic risk thresholds and mitigations to cybersecurity, third-party evaluation, and internal governance. Second, the framework must be reviewed at least annually and republished with justification within 30 days of material modification. Third, all frontier developers must publish a transparency report before or concurrently with deploying a new or substantially modified frontier model; large frontier developers must include catastrophic risk assessment summaries in that report. Fourth, large frontier developers must transmit quarterly catastrophic risk assessment summaries from internal model use to the Attorney General. The section also prohibits materially false or misleading statements about catastrophic risk and permits redactions for trade secrets, cybersecurity, or national security.

Compliance actions 7 items
1
Large frontier developersLarge frontier developer"Large frontier developer" means a frontier developer that together with its affiliates collectively had annual gross revenues in excess of $500,000,000 in the preceding calendar year.Section 5 must write, implement, comply with, and publicly publish a frontier AI safety framework covering catastrophic riskCatastrophic risk"Catastrophic risk" means a foreseeable and material risk that a frontier developer's development, storage, use, or deployment of a frontier model will materially contribute to the death of, or serious injury to, more than 50 people or more than $1,000,000,000 in damage to, or loss of, property arising from a single incident involving a frontier model doing any of the following: (1) providing expert-level assistance in the creation or release of a chemical, biological, radiological, or nuclear weapon; (2) engaging in conduct with no meaningful human oversight, intervention, or supervision that is either a cyberattack or, if the conduct had been committed by a human, would constitute the crime of murder, assault, extortion, or theft, including theft by false pretense; or (3) evading the control of its frontier developer or user. "Catastrophic risk" does not include a foreseeable and material risk from any of the following: (1) information that a frontier model outputs if the information is otherwise publicly accessible in a substantially similar form from a source other than a foundation model; (2) lawful activity of the federal government; or (3) harm caused by a frontier model in combination with other software if the frontier model did not materially contribute to the harm.Section 5 thresholds and assessment, mitigations, deployment-gating review, third-party evaluation, framework update criteria, cybersecurity for unreleased model weightsModel weight"Model weight" means a numerical parameter in a frontier model that is adjusted through training and that helps determine how inputs are transformed into outputs.Section 5, critical safety incidentCritical safety incident"Critical safety incident" means any of the following: (1) unauthorized access to, modification of, or exfiltration of, the model weights of a frontier model that results in death or bodily injury; (2) harm resulting from the materialization of a catastrophic risk; (3) loss of control of a frontier model causing death or bodily injury; or (4) a frontier model that uses deceptive techniques against the frontier developer to subvert the controls or monitoring of its frontier developer outside of the context of an evaluation designed to elicit this behavior and in a manner that demonstrates materially increased catastrophic risk.Section 5 response, internal governance, and internal-use risk management.
S-03.5
2
Large frontier developersLarge frontier developer"Large frontier developer" means a frontier developer that together with its affiliates collectively had annual gross revenues in excess of $500,000,000 in the preceding calendar year.Section 5 must review and, as appropriate, update their frontier AI safety framework at least annually. Material modifications must be republished with justification within 30 days.
S-03.5
3
Frontier developersFrontier developer"Frontier developer" means a person who has trained, or initiated the training of, a frontier model, with respect to which the person has used, or intends to use, at least as much computing power to train the frontier model as would meet the technical specifications found in the definition of "frontier model".Section 5 must publish a transparency report on their website before or concurrently with deploying a new or substantially modified frontier modelFrontier model"Frontier model" means a foundation model that was trained using a quantity of computing power greater than 10^26 integer or floating-point operations. The quantity of computing power described in this definition shall include computing for the original training run and for any subsequent fine-tuning, reinforcement learning, or other material modifications the developer applies to a preceding foundation model.Section 5, covering the developer's website, contact mechanism, release date, supported languages, output modalities, intended uses, and use restrictions.
G-02.1
4
Large frontier developersLarge frontier developer"Large frontier developer" means a frontier developer that together with its affiliates collectively had annual gross revenues in excess of $500,000,000 in the preceding calendar year.Section 5 must include in their pre-deployment transparency report summaries of catastrophic riskCatastrophic risk"Catastrophic risk" means a foreseeable and material risk that a frontier developer's development, storage, use, or deployment of a frontier model will materially contribute to the death of, or serious injury to, more than 50 people or more than $1,000,000,000 in damage to, or loss of, property arising from a single incident involving a frontier model doing any of the following: (1) providing expert-level assistance in the creation or release of a chemical, biological, radiological, or nuclear weapon; (2) engaging in conduct with no meaningful human oversight, intervention, or supervision that is either a cyberattack or, if the conduct had been committed by a human, would constitute the crime of murder, assault, extortion, or theft, including theft by false pretense; or (3) evading the control of its frontier developer or user. "Catastrophic risk" does not include a foreseeable and material risk from any of the following: (1) information that a frontier model outputs if the information is otherwise publicly accessible in a substantially similar form from a source other than a foundation model; (2) lawful activity of the federal government; or (3) harm caused by a frontier model in combination with other software if the frontier model did not materially contribute to the harm.Section 5 assessments, assessment results, the extent of third-party evaluator involvement, and other steps taken to fulfill the frontier AI framework requirements.
G-02.3
5
Large frontier developersLarge frontier developer"Large frontier developer" means a frontier developer that together with its affiliates collectively had annual gross revenues in excess of $500,000,000 in the preceding calendar year.Section 5 must transmit to the Attorney General a summary of catastrophic riskCatastrophic risk"Catastrophic risk" means a foreseeable and material risk that a frontier developer's development, storage, use, or deployment of a frontier model will materially contribute to the death of, or serious injury to, more than 50 people or more than $1,000,000,000 in damage to, or loss of, property arising from a single incident involving a frontier model doing any of the following: (1) providing expert-level assistance in the creation or release of a chemical, biological, radiological, or nuclear weapon; (2) engaging in conduct with no meaningful human oversight, intervention, or supervision that is either a cyberattack or, if the conduct had been committed by a human, would constitute the crime of murder, assault, extortion, or theft, including theft by false pretense; or (3) evading the control of its frontier developer or user. "Catastrophic risk" does not include a foreseeable and material risk from any of the following: (1) information that a frontier model outputs if the information is otherwise publicly accessible in a substantially similar form from a source other than a foundation model; (2) lawful activity of the federal government; or (3) harm caused by a frontier model in combination with other software if the frontier model did not materially contribute to the harm.Section 5 assessments from internal use of their frontier modelsFrontier model"Frontier model" means a foundation model that was trained using a quantity of computing power greater than 10^26 integer or floating-point operations. The quantity of computing power described in this definition shall include computing for the original training run and for any subsequent fine-tuning, reinforcement learning, or other material modifications the developer applies to a preceding foundation model.Section 5 every 3 months or on another reasonable schedule communicated in writing to the Attorney General.
R-02.1
6
Frontier developersFrontier developer"Frontier developer" means a person who has trained, or initiated the training of, a frontier model, with respect to which the person has used, or intends to use, at least as much computing power to train the frontier model as would meet the technical specifications found in the definition of "frontier model".Section 5 must not make materially false or misleading statements about catastrophic riskCatastrophic risk"Catastrophic risk" means a foreseeable and material risk that a frontier developer's development, storage, use, or deployment of a frontier model will materially contribute to the death of, or serious injury to, more than 50 people or more than $1,000,000,000 in damage to, or loss of, property arising from a single incident involving a frontier model doing any of the following: (1) providing expert-level assistance in the creation or release of a chemical, biological, radiological, or nuclear weapon; (2) engaging in conduct with no meaningful human oversight, intervention, or supervision that is either a cyberattack or, if the conduct had been committed by a human, would constitute the crime of murder, assault, extortion, or theft, including theft by false pretense; or (3) evading the control of its frontier developer or user. "Catastrophic risk" does not include a foreseeable and material risk from any of the following: (1) information that a frontier model outputs if the information is otherwise publicly accessible in a substantially similar form from a source other than a foundation model; (2) lawful activity of the federal government; or (3) harm caused by a frontier model in combination with other software if the frontier model did not materially contribute to the harm.Section 5 from their frontier modelsFrontier model"Frontier model" means a foundation model that was trained using a quantity of computing power greater than 10^26 integer or floating-point operations. The quantity of computing power described in this definition shall include computing for the original training run and for any subsequent fine-tuning, reinforcement learning, or other material modifications the developer applies to a preceding foundation model.Section 5 or their management of catastrophic riskCatastrophic risk"Catastrophic risk" means a foreseeable and material risk that a frontier developer's development, storage, use, or deployment of a frontier model will materially contribute to the death of, or serious injury to, more than 50 people or more than $1,000,000,000 in damage to, or loss of, property arising from a single incident involving a frontier model doing any of the following: (1) providing expert-level assistance in the creation or release of a chemical, biological, radiological, or nuclear weapon; (2) engaging in conduct with no meaningful human oversight, intervention, or supervision that is either a cyberattack or, if the conduct had been committed by a human, would constitute the crime of murder, assault, extortion, or theft, including theft by false pretense; or (3) evading the control of its frontier developer or user. "Catastrophic risk" does not include a foreseeable and material risk from any of the following: (1) information that a frontier model outputs if the information is otherwise publicly accessible in a substantially similar form from a source other than a foundation model; (2) lawful activity of the federal government; or (3) harm caused by a frontier model in combination with other software if the frontier model did not materially contribute to the harm.Section 5. Large frontier developersLarge frontier developer"Large frontier developer" means a frontier developer that together with its affiliates collectively had annual gross revenues in excess of $500,000,000 in the preceding calendar year.Section 5 additionally must not make materially false or misleading statements about their implementation of or compliance with their frontier AI framework. A good-faith safe harbor applies to statements that were reasonable under the circumstances.
CP-01
7
Frontier developersFrontier developer"Frontier developer" means a person who has trained, or initiated the training of, a frontier model, with respect to which the person has used, or intends to use, at least as much computing power to train the frontier model as would meet the technical specifications found in the definition of "frontier model".Section 5 that redact published documents for trade secret, cybersecurity, public safety, or national security reasons must describe the character and justification of each redaction in the published version and retain the unredacted information for 5 years.
G-01.3
Section 15
Reporting critical safety incidents
Developer

(a) The Attorney General shall establish a mechanism to be used by a frontier developerFrontier developer"Frontier developer" means a person who has trained, or initiated the training of, a frontier model, with respect to which the person has used, or intends to use, at least as much computing power to train the frontier model as would meet the technical specifications found in the definition of "frontier model".Section 5 or a member of the public to report a critical safety incidentCritical safety incident"Critical safety incident" means any of the following: (1) unauthorized access to, modification of, or exfiltration of, the model weights of a frontier model that results in death or bodily injury; (2) harm resulting from the materialization of a catastrophic risk; (3) loss of control of a frontier model causing death or bodily injury; or (4) a frontier model that uses deceptive techniques against the frontier developer to subvert the controls or monitoring of its frontier developer outside of the context of an evaluation designed to elicit this behavior and in a manner that demonstrates materially increased catastrophic risk.Section 5 that includes all of the following: (1) the date of the critical safety incidentCritical safety incident"Critical safety incident" means any of the following: (1) unauthorized access to, modification of, or exfiltration of, the model weights of a frontier model that results in death or bodily injury; (2) harm resulting from the materialization of a catastrophic risk; (3) loss of control of a frontier model causing death or bodily injury; or (4) a frontier model that uses deceptive techniques against the frontier developer to subvert the controls or monitoring of its frontier developer outside of the context of an evaluation designed to elicit this behavior and in a manner that demonstrates materially increased catastrophic risk.Section 5; (2) the reasons the incident qualifies as a critical safety incidentCritical safety incident"Critical safety incident" means any of the following: (1) unauthorized access to, modification of, or exfiltration of, the model weights of a frontier model that results in death or bodily injury; (2) harm resulting from the materialization of a catastrophic risk; (3) loss of control of a frontier model causing death or bodily injury; or (4) a frontier model that uses deceptive techniques against the frontier developer to subvert the controls or monitoring of its frontier developer outside of the context of an evaluation designed to elicit this behavior and in a manner that demonstrates materially increased catastrophic risk.Section 5; (3) a short and plain statement describing the critical safety incidentCritical safety incident"Critical safety incident" means any of the following: (1) unauthorized access to, modification of, or exfiltration of, the model weights of a frontier model that results in death or bodily injury; (2) harm resulting from the materialization of a catastrophic risk; (3) loss of control of a frontier model causing death or bodily injury; or (4) a frontier model that uses deceptive techniques against the frontier developer to subvert the controls or monitoring of its frontier developer outside of the context of an evaluation designed to elicit this behavior and in a manner that demonstrates materially increased catastrophic risk.Section 5; and (4) whether the incident was associated with internal use of a frontier modelFrontier model"Frontier model" means a foundation model that was trained using a quantity of computing power greater than 10^26 integer or floating-point operations. The quantity of computing power described in this definition shall include computing for the original training run and for any subsequent fine-tuning, reinforcement learning, or other material modifications the developer applies to a preceding foundation model.Section 5.

(b)(1)–(2) The Attorney General shall establish a mechanism to be used by a large frontier developerLarge frontier developer"Large frontier developer" means a frontier developer that together with its affiliates collectively had annual gross revenues in excess of $500,000,000 in the preceding calendar year.Section 5 to confidentially submit summaries of any assessments of the potential for catastrophic riskCatastrophic risk"Catastrophic risk" means a foreseeable and material risk that a frontier developer's development, storage, use, or deployment of a frontier model will materially contribute to the death of, or serious injury to, more than 50 people or more than $1,000,000,000 in damage to, or loss of, property arising from a single incident involving a frontier model doing any of the following: (1) providing expert-level assistance in the creation or release of a chemical, biological, radiological, or nuclear weapon; (2) engaging in conduct with no meaningful human oversight, intervention, or supervision that is either a cyberattack or, if the conduct had been committed by a human, would constitute the crime of murder, assault, extortion, or theft, including theft by false pretense; or (3) evading the control of its frontier developer or user. "Catastrophic risk" does not include a foreseeable and material risk from any of the following: (1) information that a frontier model outputs if the information is otherwise publicly accessible in a substantially similar form from a source other than a foundation model; (2) lawful activity of the federal government; or (3) harm caused by a frontier model in combination with other software if the frontier model did not materially contribute to the harm.Section 5 resulting from internal use of its frontier modelsFrontier model"Frontier model" means a foundation model that was trained using a quantity of computing power greater than 10^26 integer or floating-point operations. The quantity of computing power described in this definition shall include computing for the original training run and for any subsequent fine-tuning, reinforcement learning, or other material modifications the developer applies to a preceding foundation model.Section 5. (2) The Attorney General shall take all necessary precautions to limit access to any reports related to internal use of frontier modelsFrontier model"Frontier model" means a foundation model that was trained using a quantity of computing power greater than 10^26 integer or floating-point operations. The quantity of computing power described in this definition shall include computing for the original training run and for any subsequent fine-tuning, reinforcement learning, or other material modifications the developer applies to a preceding foundation model.Section 5 to only personnel with a specific need to know the information and to protect the reports from unauthorized access.

(c) 8 A frontier developerFrontier developer"Frontier developer" means a person who has trained, or initiated the training of, a frontier model, with respect to which the person has used, or intends to use, at least as much computing power to train the frontier model as would meet the technical specifications found in the definition of "frontier model".Section 5 shall report any critical safety incidentCritical safety incident"Critical safety incident" means any of the following: (1) unauthorized access to, modification of, or exfiltration of, the model weights of a frontier model that results in death or bodily injury; (2) harm resulting from the materialization of a catastrophic risk; (3) loss of control of a frontier model causing death or bodily injury; or (4) a frontier model that uses deceptive techniques against the frontier developer to subvert the controls or monitoring of its frontier developer outside of the context of an evaluation designed to elicit this behavior and in a manner that demonstrates materially increased catastrophic risk.Section 5 pertaining to one or more of its frontier modelsFrontier model"Frontier model" means a foundation model that was trained using a quantity of computing power greater than 10^26 integer or floating-point operations. The quantity of computing power described in this definition shall include computing for the original training run and for any subsequent fine-tuning, reinforcement learning, or other material modifications the developer applies to a preceding foundation model.Section 5 to the Attorney General within 15 days of discovering the critical safety incidentCritical safety incident"Critical safety incident" means any of the following: (1) unauthorized access to, modification of, or exfiltration of, the model weights of a frontier model that results in death or bodily injury; (2) harm resulting from the materialization of a catastrophic risk; (3) loss of control of a frontier model causing death or bodily injury; or (4) a frontier model that uses deceptive techniques against the frontier developer to subvert the controls or monitoring of its frontier developer outside of the context of an evaluation designed to elicit this behavior and in a manner that demonstrates materially increased catastrophic risk.Section 5. If a frontier developerFrontier developer"Frontier developer" means a person who has trained, or initiated the training of, a frontier model, with respect to which the person has used, or intends to use, at least as much computing power to train the frontier model as would meet the technical specifications found in the definition of "frontier model".Section 5 discovers that a critical safety incidentCritical safety incident"Critical safety incident" means any of the following: (1) unauthorized access to, modification of, or exfiltration of, the model weights of a frontier model that results in death or bodily injury; (2) harm resulting from the materialization of a catastrophic risk; (3) loss of control of a frontier model causing death or bodily injury; or (4) a frontier model that uses deceptive techniques against the frontier developer to subvert the controls or monitoring of its frontier developer outside of the context of an evaluation designed to elicit this behavior and in a manner that demonstrates materially increased catastrophic risk.Section 5 poses an imminent risk of death or serious physical injury, the frontier developerFrontier developer"Frontier developer" means a person who has trained, or initiated the training of, a frontier model, with respect to which the person has used, or intends to use, at least as much computing power to train the frontier model as would meet the technical specifications found in the definition of "frontier model".Section 5 shall disclose that incident within 24 hours to an authority, including any law enforcement agency or public safety agency with jurisdiction, that is appropriate based on the nature of that incident and as required by law. A frontier developerFrontier developer"Frontier developer" means a person who has trained, or initiated the training of, a frontier model, with respect to which the person has used, or intends to use, at least as much computing power to train the frontier model as would meet the technical specifications found in the definition of "frontier model".Section 5 that discovers information about a critical safety incidentCritical safety incident"Critical safety incident" means any of the following: (1) unauthorized access to, modification of, or exfiltration of, the model weights of a frontier model that results in death or bodily injury; (2) harm resulting from the materialization of a catastrophic risk; (3) loss of control of a frontier model causing death or bodily injury; or (4) a frontier model that uses deceptive techniques against the frontier developer to subvert the controls or monitoring of its frontier developer outside of the context of an evaluation designed to elicit this behavior and in a manner that demonstrates materially increased catastrophic risk.Section 5 after filing the initial report required by this subsection may file an amended report. A frontier developerFrontier developer"Frontier developer" means a person who has trained, or initiated the training of, a frontier model, with respect to which the person has used, or intends to use, at least as much computing power to train the frontier model as would meet the technical specifications found in the definition of "frontier model".Section 5 is encouraged, but not required, to report critical safety incidentsCritical safety incident"Critical safety incident" means any of the following: (1) unauthorized access to, modification of, or exfiltration of, the model weights of a frontier model that results in death or bodily injury; (2) harm resulting from the materialization of a catastrophic risk; (3) loss of control of a frontier model causing death or bodily injury; or (4) a frontier model that uses deceptive techniques against the frontier developer to subvert the controls or monitoring of its frontier developer outside of the context of an evaluation designed to elicit this behavior and in a manner that demonstrates materially increased catastrophic risk.Section 5 pertaining to foundation modelsFoundation model"Foundation model" means an artificial intelligence model that is all of the following: (1) trained on a broad data set; (2) designed for generality of output; and (3) adaptable to a wide range of distinctive tasks.Section 5 that are not frontier modelsFrontier model"Frontier model" means a foundation model that was trained using a quantity of computing power greater than 10^26 integer or floating-point operations. The quantity of computing power described in this definition shall include computing for the original training run and for any subsequent fine-tuning, reinforcement learning, or other material modifications the developer applies to a preceding foundation model.Section 5.

(d) The Attorney General shall review critical safety incidentCritical safety incident"Critical safety incident" means any of the following: (1) unauthorized access to, modification of, or exfiltration of, the model weights of a frontier model that results in death or bodily injury; (2) harm resulting from the materialization of a catastrophic risk; (3) loss of control of a frontier model causing death or bodily injury; or (4) a frontier model that uses deceptive techniques against the frontier developer to subvert the controls or monitoring of its frontier developer outside of the context of an evaluation designed to elicit this behavior and in a manner that demonstrates materially increased catastrophic risk.Section 5 reports submitted by frontier developersFrontier developer"Frontier developer" means a person who has trained, or initiated the training of, a frontier model, with respect to which the person has used, or intends to use, at least as much computing power to train the frontier model as would meet the technical specifications found in the definition of "frontier model".Section 5 and may review reports submitted by members of the public.

(e) The Attorney General may transmit reports of critical safety incidentsCritical safety incident"Critical safety incident" means any of the following: (1) unauthorized access to, modification of, or exfiltration of, the model weights of a frontier model that results in death or bodily injury; (2) harm resulting from the materialization of a catastrophic risk; (3) loss of control of a frontier model causing death or bodily injury; or (4) a frontier model that uses deceptive techniques against the frontier developer to subvert the controls or monitoring of its frontier developer outside of the context of an evaluation designed to elicit this behavior and in a manner that demonstrates materially increased catastrophic risk.Section 5 to the General Assembly, the Governor, the federal government, or appropriate State agencies. The Attorney General shall strongly consider any risks related to trade secrets, public safety, cybersecurity of a frontier developerFrontier developer"Frontier developer" means a person who has trained, or initiated the training of, a frontier model, with respect to which the person has used, or intends to use, at least as much computing power to train the frontier model as would meet the technical specifications found in the definition of "frontier model".Section 5, or national security when transmitting reports.

(f) A report of a critical safety incidentCritical safety incident"Critical safety incident" means any of the following: (1) unauthorized access to, modification of, or exfiltration of, the model weights of a frontier model that results in death or bodily injury; (2) harm resulting from the materialization of a catastrophic risk; (3) loss of control of a frontier model causing death or bodily injury; or (4) a frontier model that uses deceptive techniques against the frontier developer to subvert the controls or monitoring of its frontier developer outside of the context of an evaluation designed to elicit this behavior and in a manner that demonstrates materially increased catastrophic risk.Section 5 submitted to the Attorney General under this Section and a report of assessments of catastrophic riskCatastrophic risk"Catastrophic risk" means a foreseeable and material risk that a frontier developer's development, storage, use, or deployment of a frontier model will materially contribute to the death of, or serious injury to, more than 50 people or more than $1,000,000,000 in damage to, or loss of, property arising from a single incident involving a frontier model doing any of the following: (1) providing expert-level assistance in the creation or release of a chemical, biological, radiological, or nuclear weapon; (2) engaging in conduct with no meaningful human oversight, intervention, or supervision that is either a cyberattack or, if the conduct had been committed by a human, would constitute the crime of murder, assault, extortion, or theft, including theft by false pretense; or (3) evading the control of its frontier developer or user. "Catastrophic risk" does not include a foreseeable and material risk from any of the following: (1) information that a frontier model outputs if the information is otherwise publicly accessible in a substantially similar form from a source other than a foundation model; (2) lawful activity of the federal government; or (3) harm caused by a frontier model in combination with other software if the frontier model did not materially contribute to the harm.Section 5 from internal use in subsection (d) of Section 10 shall be exempt from disclosure under the Illinois Freedom of Information Act.

(g)(1)–(3) Beginning January 1, 2028, and annually thereafter, the Attorney General shall produce a report with anonymized and aggregated information about critical safety incidentsCritical safety incident"Critical safety incident" means any of the following: (1) unauthorized access to, modification of, or exfiltration of, the model weights of a frontier model that results in death or bodily injury; (2) harm resulting from the materialization of a catastrophic risk; (3) loss of control of a frontier model causing death or bodily injury; or (4) a frontier model that uses deceptive techniques against the frontier developer to subvert the controls or monitoring of its frontier developer outside of the context of an evaluation designed to elicit this behavior and in a manner that demonstrates materially increased catastrophic risk.Section 5 that have been reviewed by the Attorney General since the preceding report. (2) The Attorney General shall not include information in a report that would compromise the trade secrets or cybersecurity of a frontier developerFrontier developer"Frontier developer" means a person who has trained, or initiated the training of, a frontier model, with respect to which the person has used, or intends to use, at least as much computing power to train the frontier model as would meet the technical specifications found in the definition of "frontier model".Section 5, public safety, or the national security of the United States or that would be prohibited by any federal or State law. (3) The Attorney General shall transmit a report under this subsection to the General Assembly and to the Governor.

(h)–(j) 9 The Attorney General may adopt rules designating one or more federal laws, regulations, or guidance documents that meet all of the following conditions for the purposes of subsection (i): (1) the law, regulation, or guidance document imposes or states standards or requirements for critical safety incidentCritical safety incident"Critical safety incident" means any of the following: (1) unauthorized access to, modification of, or exfiltration of, the model weights of a frontier model that results in death or bodily injury; (2) harm resulting from the materialization of a catastrophic risk; (3) loss of control of a frontier model causing death or bodily injury; or (4) a frontier model that uses deceptive techniques against the frontier developer to subvert the controls or monitoring of its frontier developer outside of the context of an evaluation designed to elicit this behavior and in a manner that demonstrates materially increased catastrophic risk.Section 5 reporting that are substantially equivalent to, or stricter than, those required by this Section; (2) the law, regulation, or guidance document described in paragraph (1) does not need to require critical safety incidentCritical safety incident"Critical safety incident" means any of the following: (1) unauthorized access to, modification of, or exfiltration of, the model weights of a frontier model that results in death or bodily injury; (2) harm resulting from the materialization of a catastrophic risk; (3) loss of control of a frontier model causing death or bodily injury; or (4) a frontier model that uses deceptive techniques against the frontier developer to subvert the controls or monitoring of its frontier developer outside of the context of an evaluation designed to elicit this behavior and in a manner that demonstrates materially increased catastrophic risk.Section 5 reporting to the State of California; and (3) the law, regulation, or guidance document is intended to assess, detect, or mitigate the catastrophic riskCatastrophic risk"Catastrophic risk" means a foreseeable and material risk that a frontier developer's development, storage, use, or deployment of a frontier model will materially contribute to the death of, or serious injury to, more than 50 people or more than $1,000,000,000 in damage to, or loss of, property arising from a single incident involving a frontier model doing any of the following: (1) providing expert-level assistance in the creation or release of a chemical, biological, radiological, or nuclear weapon; (2) engaging in conduct with no meaningful human oversight, intervention, or supervision that is either a cyberattack or, if the conduct had been committed by a human, would constitute the crime of murder, assault, extortion, or theft, including theft by false pretense; or (3) evading the control of its frontier developer or user. "Catastrophic risk" does not include a foreseeable and material risk from any of the following: (1) information that a frontier model outputs if the information is otherwise publicly accessible in a substantially similar form from a source other than a foundation model; (2) lawful activity of the federal government; or (3) harm caused by a frontier model in combination with other software if the frontier model did not materially contribute to the harm.Section 5. (i)(1) A frontier developerFrontier developer"Frontier developer" means a person who has trained, or initiated the training of, a frontier model, with respect to which the person has used, or intends to use, at least as much computing power to train the frontier model as would meet the technical specifications found in the definition of "frontier model".Section 5 that intends to comply with this Section by complying with the requirements of, or meeting the standards stated by, a federal law, regulation, or guidance document designated in subsection (h) shall declare its intent to do so to the Attorney General. (2) After a frontier developerFrontier developer"Frontier developer" means a person who has trained, or initiated the training of, a frontier model, with respect to which the person has used, or intends to use, at least as much computing power to train the frontier model as would meet the technical specifications found in the definition of "frontier model".Section 5 has declared its intent under paragraph (1), both of the following apply: (A) the frontier developerFrontier developer"Frontier developer" means a person who has trained, or initiated the training of, a frontier model, with respect to which the person has used, or intends to use, at least as much computing power to train the frontier model as would meet the technical specifications found in the definition of "frontier model".Section 5 shall be deemed in compliance with this Section to the extent that the frontier developerFrontier developer"Frontier developer" means a person who has trained, or initiated the training of, a frontier model, with respect to which the person has used, or intends to use, at least as much computing power to train the frontier model as would meet the technical specifications found in the definition of "frontier model".Section 5 meets the standards of, or complies with the requirements imposed or stated by, the designated federal law, regulation, or guidance document until the frontier developerFrontier developer"Frontier developer" means a person who has trained, or initiated the training of, a frontier model, with respect to which the person has used, or intends to use, at least as much computing power to train the frontier model as would meet the technical specifications found in the definition of "frontier model".Section 5 declares the revocation of that intent to the Attorney General or the Attorney General repeals a relevant rule under subsection (j); and (B) the failure by a frontier developerFrontier developer"Frontier developer" means a person who has trained, or initiated the training of, a frontier model, with respect to which the person has used, or intends to use, at least as much computing power to train the frontier model as would meet the technical specifications found in the definition of "frontier model".Section 5 to meet the standards of, or comply with the requirements stated by, the federal law, regulation, or guidance document designated under subsection (h) shall constitute a violation of this Act. (j) The Attorney General shall repeal a rule adopted under subsection (h) if the requirements of subsection (h) are no longer met.

Section 15 establishes the Attorney General as the reporting hub for critical safety incidents. It requires the Attorney General to create reporting mechanisms for both frontier developers and the public, and a confidential submission mechanism for catastrophic risk assessment summaries from large frontier developers' internal model use. Frontier developers must report critical safety incidents within 15 days, with an accelerated 24-hour window for incidents posing imminent risk of death or serious physical injury. The section includes a federal safe harbor: the Attorney General may designate substantially equivalent federal reporting standards, and a frontier developer that declares its intent to comply with those standards is deemed compliant with this section — but failure to meet the designated federal standard constitutes a violation of the Act. Beginning January 1, 2028, the Attorney General must produce an annual anonymized aggregate report on critical safety incidents and transmit it to the General Assembly and Governor. All reports are exempt from FOIA disclosure.

Compliance actions 2 items
8
Frontier developersFrontier developer"Frontier developer" means a person who has trained, or initiated the training of, a frontier model, with respect to which the person has used, or intends to use, at least as much computing power to train the frontier model as would meet the technical specifications found in the definition of "frontier model".Section 5 must report any critical safety incidentCritical safety incident"Critical safety incident" means any of the following: (1) unauthorized access to, modification of, or exfiltration of, the model weights of a frontier model that results in death or bodily injury; (2) harm resulting from the materialization of a catastrophic risk; (3) loss of control of a frontier model causing death or bodily injury; or (4) a frontier model that uses deceptive techniques against the frontier developer to subvert the controls or monitoring of its frontier developer outside of the context of an evaluation designed to elicit this behavior and in a manner that demonstrates materially increased catastrophic risk.Section 5 to the Attorney General within 15 days of discovery. If an incident poses an imminent risk of death or serious physical injury, the developer must disclose it within 24 hours to appropriate law enforcement or public safety agencies.
R-01.1
9
Frontier developersFrontier developer"Frontier developer" means a person who has trained, or initiated the training of, a frontier model, with respect to which the person has used, or intends to use, at least as much computing power to train the frontier model as would meet the technical specifications found in the definition of "frontier model".Section 5 that elect to comply with this section through a designated substantially equivalent federal reporting standard must declare that intent to the Attorney General. Upon declaration, compliance with the federal standard satisfies this section, but failure to meet the federal standard constitutes a violation of this Act.
R-01.1
Section 20
Department of Innovation and Technology recommendations
Government

(a)–(c) 10 On or before January 1, 2028, and annually thereafter, the Department of Innovation and Technology shall assess recent evidence and developments relevant to the purposes of this Act and shall make recommendations about whether and how to update any of the following definitions for the purposes of this Act to ensure that they accurately reflect technological developments, scientific literature, and widely accepted national and international standards: (1) "frontier modelFrontier model"Frontier model" means a foundation model that was trained using a quantity of computing power greater than 10^26 integer or floating-point operations. The quantity of computing power described in this definition shall include computing for the original training run and for any subsequent fine-tuning, reinforcement learning, or other material modifications the developer applies to a preceding foundation model.Section 5", so that it applies to foundation modelsFoundation model"Foundation model" means an artificial intelligence model that is all of the following: (1) trained on a broad data set; (2) designed for generality of output; and (3) adaptable to a wide range of distinctive tasks.Section 5 at the frontier of artificial intelligenceArtificial intelligence"Artificial intelligence" has the meaning set forth in Section 2-101 of the Illinois Human Rights Act.Section 5 development; (2) "frontier developerFrontier developer"Frontier developer" means a person who has trained, or initiated the training of, a frontier model, with respect to which the person has used, or intends to use, at least as much computing power to train the frontier model as would meet the technical specifications found in the definition of "frontier model".Section 5", so that it applies to developers of frontier modelsFrontier model"Frontier model" means a foundation model that was trained using a quantity of computing power greater than 10^26 integer or floating-point operations. The quantity of computing power described in this definition shall include computing for the original training run and for any subsequent fine-tuning, reinforcement learning, or other material modifications the developer applies to a preceding foundation model.Section 5 who are themselves at the frontier of artificial intelligenceArtificial intelligence"Artificial intelligence" has the meaning set forth in Section 2-101 of the Illinois Human Rights Act.Section 5 development; and (3) "large frontier developerLarge frontier developer"Large frontier developer" means a frontier developer that together with its affiliates collectively had annual gross revenues in excess of $500,000,000 in the preceding calendar year.Section 5", so that it applies to well-resourced frontier developersFrontier developer"Frontier developer" means a person who has trained, or initiated the training of, a frontier model, with respect to which the person has used, or intends to use, at least as much computing power to train the frontier model as would meet the technical specifications found in the definition of "frontier model".Section 5. (b) In making recommendations under this Section, the Department of Innovation and Technology shall take into account all of the following: (1) similar thresholds used in international standards or federal law, guidance, or regulations for the management of catastrophic riskCatastrophic risk"Catastrophic risk" means a foreseeable and material risk that a frontier developer's development, storage, use, or deployment of a frontier model will materially contribute to the death of, or serious injury to, more than 50 people or more than $1,000,000,000 in damage to, or loss of, property arising from a single incident involving a frontier model doing any of the following: (1) providing expert-level assistance in the creation or release of a chemical, biological, radiological, or nuclear weapon; (2) engaging in conduct with no meaningful human oversight, intervention, or supervision that is either a cyberattack or, if the conduct had been committed by a human, would constitute the crime of murder, assault, extortion, or theft, including theft by false pretense; or (3) evading the control of its frontier developer or user. "Catastrophic risk" does not include a foreseeable and material risk from any of the following: (1) information that a frontier model outputs if the information is otherwise publicly accessible in a substantially similar form from a source other than a foundation model; (2) lawful activity of the federal government; or (3) harm caused by a frontier model in combination with other software if the frontier model did not materially contribute to the harm.Section 5 and shall align with a definition adopted in a federal law or regulation to the extent that it is consistent with the purposes of this Act; (2) input from stakeholders, including academics, industry, the open-source community, and governmental entities; (3) the extent to which a person will be able to determine, before beginning to train or deployDeploy"Deploy" means to make a frontier model available to a third party for use, modification, copying, or combination with other software. "Deploy" does not include making a frontier model available to a third party for the primary purpose of developing or evaluating the frontier model.Section 5 a foundation modelFoundation model"Foundation model" means an artificial intelligence model that is all of the following: (1) trained on a broad data set; (2) designed for generality of output; and (3) adaptable to a wide range of distinctive tasks.Section 5, whether that person will be subject to the definition as a frontier developerFrontier developer"Frontier developer" means a person who has trained, or initiated the training of, a frontier model, with respect to which the person has used, or intends to use, at least as much computing power to train the frontier model as would meet the technical specifications found in the definition of "frontier model".Section 5 or as a large frontier developerLarge frontier developer"Large frontier developer" means a frontier developer that together with its affiliates collectively had annual gross revenues in excess of $500,000,000 in the preceding calendar year.Section 5 with an aim toward allowing earlier determinations if possible; (4) the complexity of determining whether a person or foundation modelFoundation model"Foundation model" means an artificial intelligence model that is all of the following: (1) trained on a broad data set; (2) designed for generality of output; and (3) adaptable to a wide range of distinctive tasks.Section 5 is covered, with an aim toward allowing simpler determinations if possible; and (5) the external verifiability of determining whether a person or foundation modelFoundation model"Foundation model" means an artificial intelligence model that is all of the following: (1) trained on a broad data set; (2) designed for generality of output; and (3) adaptable to a wide range of distinctive tasks.Section 5 is covered, with an aim toward definitions that are verifiable by parties other than the frontier developerFrontier developer"Frontier developer" means a person who has trained, or initiated the training of, a frontier model, with respect to which the person has used, or intends to use, at least as much computing power to train the frontier model as would meet the technical specifications found in the definition of "frontier model".Section 5. (c) Upon developing recommendations under this Section, the Department of Innovation and Technology shall submit a report to the General Assembly and to the Governor.

Section 20 directs the Department of Innovation and Technology to conduct annual assessments beginning January 1, 2028 and to recommend whether and how to update the definitions of frontier model, frontier developer, and large frontier developer. The recommendations must account for international standards, federal alignment, stakeholder input, ex ante determinability, complexity, and external verifiability. Results are submitted to the General Assembly and Governor. This section creates obligations on a government agency, not on private-sector frontier developers.

Compliance actions 1 item
10
The Department of Innovation and Technology must annually assess and recommend to the General Assembly and Governor whether and how to update the statutory definitions of frontier modelFrontier model"Frontier model" means a foundation model that was trained using a quantity of computing power greater than 10^26 integer or floating-point operations. The quantity of computing power described in this definition shall include computing for the original training run and for any subsequent fine-tuning, reinforcement learning, or other material modifications the developer applies to a preceding foundation model.Section 5, frontier developerFrontier developer"Frontier developer" means a person who has trained, or initiated the training of, a frontier model, with respect to which the person has used, or intends to use, at least as much computing power to train the frontier model as would meet the technical specifications found in the definition of "frontier model".Section 5, and large frontier developerLarge frontier developer"Large frontier developer" means a frontier developer that together with its affiliates collectively had annual gross revenues in excess of $500,000,000 in the preceding calendar year.Section 5 to reflect technological developments and international standards.
Section 25
Civil penalty

(a)–(c) A large frontier developerLarge frontier developer"Large frontier developer" means a frontier developer that together with its affiliates collectively had annual gross revenues in excess of $500,000,000 in the preceding calendar year.Section 5 that fails to publish or transmit a compliant document required to be published or transmitted under this Act, makes a statement in violation of subsection (e) of Section 10, fails to report an incident as required by Section 15, or fails to comply with its own frontier artificial intelligence frameworkFrontier artificial intelligence framework"Frontier artificial intelligence framework" means documented technical and organizational protocols to manage, assess, and mitigate catastrophic risks.Section 5 shall be subject to a civil penalty in an amount dependent upon the severity of the violation that does not exceed $1,000,000 per violation. (b) A civil penalty described in this Section shall be recovered in a civil action brought only by the Attorney General. (c) The loss of value of equity does not count as damage to or loss of propertyProperty"Property" means tangible or intangible property.Section 5 for the purposes of this Act.

Section 25 establishes the enforcement mechanism: civil penalties up to $1,000,000 per violation, recoverable only through civil actions brought by the Attorney General. The penalty amount depends on the severity of the violation. Covered violations include failure to publish or transmit required documents, making materially false or misleading statements about catastrophic risk, failure to report critical safety incidents, and failure to comply with the developer's own frontier AI framework. The section clarifies that loss of equity value does not count as property damage under the Act.

Section 30
Consortium for ILCompute
Government

(a)–(k) 11 There is hereby established within the Department of Innovation and Technology a consortium that shall develop, under this Section, a framework for the creation of a public cloud computing cluster to be known as ILCompute. (b) The consortium shall develop a framework for the creation of ILCompute that advances the development and deployment of artificial intelligenceArtificial intelligence"Artificial intelligence" has the meaning set forth in Section 2-101 of the Illinois Human Rights Act.Section 5 that is safe, ethical, equitable, and sustainable by doing, at a minimum, both of the following: (1) fostering research and innovation that benefits the public; and (2) enabling equitable innovation by expanding access to computational resources. (c) The consortium shall make reasonable efforts to ensure that ILCompute is established within the University of Illinois to the extent possible. (d) ILCompute shall include, but not be limited to, all of the following: (1) a fully owned and hosted cloud platform; (2) necessary human expertise to operate and maintain the platform; and (3) necessary human expertise to support, train, and facilitate the use of ILCompute. (e) The consortium shall operate in accordance with all relevant labor and workforce laws and standards. (f)(1) On or before January 1, 2028, the Department of Innovation and Technology shall submit a report from the consortium to the General Assembly with the framework developed under subsection (b) for the creation and operation of ILCompute. (2) The report required by this subsection shall include all of the following elements: (A) a landscape analysis of Illinois' current public, private, and nonprofit cloud computing platform infrastructure; (B) an analysis of the cost to the State to build and maintain ILCompute and recommendations for potential funding sources; (C) recommendations for the governance structure and ongoing operation of ILCompute; (D) recommendations for the parameters for use of ILCompute, including, but not limited to, a process for determining which users and projects will be supported by ILCompute; (E) an analysis of the state's technology workforce and recommendations for equitable pathways to strengthen the workforce, including the role of ILCompute; (F) a detailed description of any proposed partnerships, contracts, or licensing agreements with nongovernmental entities; and (G) recommendations regarding how the creation and ongoing management of ILCompute can prioritize the use of the current public sector workforce. (g) The consortium shall consist of the following members: (1) four representatives of the University of Illinois and other public and private academic research institutions and national laboratories, appointed by the Governor; (2) four representatives of impacted workforce labor organizations, with one representative appointed by each of the following: the Speaker of the House of Representatives; the Minority Leader of the House of Representatives; the President of the Senate; and the Minority Leader of the Senate; (3) four representatives of stakeholder groups with relevant expertise and experience, including, but not limited to, ethicists, consumer rights advocates, and other public interest advocates, with one representative appointed by each of the following: the Speaker of the House of Representatives; the Minority Leader of the House of Representatives; the President of the Senate; and the Minority Leader of the Senate; and (4) four experts in technology and artificial intelligenceArtificial intelligence"Artificial intelligence" has the meaning set forth in Section 2-101 of the Illinois Human Rights Act.Section 5 to provide technical assistance, appointed by the Governor. (h) The members of the consortium shall serve without compensation, but shall be reimbursed for all necessary expenses actually incurred in the performance of their duties. (i) The consortium shall be dissolved upon submission of the report required under subsection (f) to the General Assembly. (j) If ILCompute is established within the University of Illinois, the University of Illinois may receive private donations for the purposes of implementing ILCompute. (k) This Section is subject to appropriation.

Section 30 establishes a consortium within the Department of Innovation and Technology to develop a framework for ILCompute, a publicly owned cloud computing cluster intended to advance safe, ethical, equitable, and sustainable AI development. The consortium must submit a comprehensive report to the General Assembly by January 1, 2028, covering infrastructure analysis, cost projections, governance recommendations, user parameters, workforce analysis, and partnership descriptions. The consortium is composed of 16 members appointed by the Governor and legislative leaders, serves without compensation, and dissolves upon report submission. This section creates obligations on a state government body and is subject to appropriation.

Compliance actions 1 item
11
The Department of Innovation and Technology must establish a consortium to develop a framework for ILCompute, a public cloud computing cluster for AI research, and submit a comprehensive report to the General Assembly by January 1, 2028.
Section 80
Freedom of Information Act conforming amendment

The Freedom of Information Act is amended by changing Section 7.5 as follows: (vvv) Information prohibited from being disclosed under subsection (f) of Section 15 of the Artificial IntelligenceArtificial intelligence"Artificial intelligence" has the meaning set forth in Section 2-101 of the Illinois Human Rights Act.Section 5 Safety Measures Act.

Section 80 amends the Illinois Freedom of Information Act (5 ILCS 140/7.5) to add a new exemption for information prohibited from disclosure under subsection (f) of Section 15 of this Act — i.e., critical safety incident reports and internal-use catastrophic risk assessment summaries submitted to the Attorney General. This is a conforming change that creates no new compliance obligation on frontier developers.

Passage Likelihood

Low
Status Introduced
Chamber No passage
Committee No action
Majority party Yes
Bipartisan No
Prior session None

Legislative History

2026-02-02 Filed with the Clerk by Rep. Kimberly Du Buclet
2026-02-06 First Reading
2026-02-06 Referred to Rules Committee

Entry Last Reviewed

2026-05-20
AI generated