Imposes safety, transparency, and reporting obligations on 'large developers' of frontier AI models — defined by a dual compute-cost threshold ($5M on a single frontier model and $100M aggregate). Before deploying a frontier model, large developers must implement, publish, and retain a written safety and security protocol; conduct pre-deployment testing; implement safeguards against unreasonable risk of critical harm; and may not deploy if the model poses an unreasonable risk of critical harm. Large developers must retain independent third-party auditors annually, report safety incidents to the Division of Homeland Security and Emergency Services within 72 hours, and protect employees who disclose safety concerns from retaliation. Enforcement is through Attorney General civil actions with penalties up to $10M for a first violation and $30M for subsequent violations. Accredited colleges and universities engaged in academic research are excluded from the large developer definition.