Requires large developers of foundation models — defined by a dual compute-cost threshold ($5M per model and $100M aggregate in the preceding 12 months) — to produce, implement, follow, and conspicuously publish a detailed safety and security protocol addressing critical risks (CBRN, cyberattack, autonomous harmful conduct causing 100+ deaths or $1B+ damages). Mandates quarterly transparency reports, five-year recordkeeping, and annual third-party audits of protocol compliance. Provides robust whistleblower protections including anonymous internal reporting channels, anti-retaliation rules, and a private right of action for employees. Enforcement is primarily by the Michigan Attorney General with civil fines up to $1M per violation of protocol and reporting requirements.