CA
Enacted eff 2026-01-01
Frontier developers must report any critical safety incident pertaining to their frontier models to the Office of Emergency Services within 15 days of discovery. If a critical safety incident poses an imminent risk of death or serious physical injury, the developer must disclose the incident within 24 hours to an appropriate authority, including any law enforcement or public safety agency with jurisdiction. Amended reports may be filed when additional information is discovered. A federal equivalency safe harbor is available: OES may designate substantially equivalent federal reporting regimes, and a frontier developer that declares intent to comply with a designated federal regime is deemed in compliance until the developer revokes that intent or OES revokes the designation. Failure to meet the designated federal standards constitutes a violation of this chapter.
NY
Enacted eff 2025-12-19
Large developers must disclose each safety incident affecting a frontier model to the Division of Homeland Security and Emergency Services within 72 hours of learning of the incident or of learning facts sufficient to establish a reasonable belief that a safety incident has occurred. The disclosure must include: (1) the date of the safety incident; (2) the reasons the incident qualifies as a safety incident under the statutory definition; and (3) a short and plain statement describing the safety incident.
NY
Enacted eff 2027-01-01
Frontier developers must report any critical safety incident to the Office within 72 hours of determination or reasonable belief. If the incident poses an imminent risk of death or serious physical injury, the developer must disclose it within 24 hours to an appropriate authority, including law enforcement or a public safety agency.
NY
Enacted eff 2027-01-01
Frontier developers electing to comply with incident reporting via a designated substantially equivalent federal standard must declare that intent to the Office and concurrently send copies of any federal critical safety incident reports to the Office. Failure to meet the designated federal standard constitutes a violation of this article.
VA
Engrossed
Covered entities must submit a report to the Attorney General within 15 days of obtaining knowledge of a covered incident (death, suicide attempt, self-harm requiring medical attention, psychiatric emergency requiring urgent treatment, or serious physical injury requiring medical attention) connected to one or more of its chatbots. The report must include, to the extent known: (1) the date the operator obtained knowledge of the incident, (2) the date of the incident, (3) a brief description of the incident and the basis for the operator's belief that it is connected to the chatbot, and (4) a description of any responsive actions taken. The covered entity may submit a supplemental report within 60 days to update or correct information. Reports are confidential; the Attorney General may publish only aggregate statistics that do not identify individual users or disclose trade secrets.
HI
Introduced
Deployers must notify the Executive Director of the Office of Consumer Protection and the Attorney General within 90 days of discovering a material violation affecting a class of consumers, or that a high-risk AI system caused or materially contributed to algorithmic discrimination or other material consumer harm. The notification must describe the issue, affected consumer categories, mitigation steps, corrective actions, and changes to prevent recurrence.
IL
Introduced eff 2027-01-01
Frontier developers must report any critical safety incident pertaining to one of their frontier models to the Attorney General within 15 days after discovering the incident.
IL
Introduced eff 2027-01-01
Frontier developers must, upon discovering that a critical safety incident poses an imminent risk of death or serious physical injury, disclose the incident within 24 hours to an appropriate authority, including any law enforcement or public safety agency with jurisdiction.
IL
Introduced eff 2027-01-01
Large chatbot providers must report any child safety incident pertaining to one of their covered chatbots to the Attorney General within 15 days after discovering the incident.
IL
Introduced
Frontier developers must report any critical safety incident to the Attorney General within 15 days of discovery. If an incident poses an imminent risk of death or serious physical injury, the developer must disclose it within 24 hours to appropriate law enforcement or public safety agencies.
IL
Introduced
Frontier developers that elect to comply with this section through a designated substantially equivalent federal reporting standard must declare that intent to the Attorney General. Upon declaration, compliance with the federal standard satisfies this section, but failure to meet the federal standard constitutes a violation of this Act.
IL
Introduced eff 2027-01-01
Frontier developers must report any critical safety incident pertaining to one of their frontier models to the Attorney General within 15 days after discovering the incident.
IL
Introduced eff 2027-01-01
Frontier developers must, when a critical safety incident poses an imminent risk of death or serious physical injury, disclose the incident within 24 hours to an appropriate authority, including any law enforcement agency or public safety agency with jurisdiction.
IL
Introduced eff 2027-01-01
Large chatbot providers must report any child safety incident pertaining to one of their covered chatbots to the Attorney General within 15 days after discovering the incident.
IL
Introduced
Frontier developers must report any critical safety incident pertaining to their frontier models to the Agency within 15 days of discovery. If a critical safety incident poses an imminent risk of death or serious physical injury, the frontier developer must disclose it within 24 hours to an appropriate authority, including law enforcement or public safety agencies.
IL
Introduced
Frontier developers may satisfy incident reporting obligations by complying with a substantially equivalent federal reporting regime designated by the Agency, provided they declare their intent to the Agency; failure to meet the designated federal standard constitutes a violation of this Act.
LA
Introduced eff 2027-01-01
Frontier developers must report any critical safety incident pertaining to their frontier models to the attorney general within 15 days of discovery, or within 24 hours if the incident poses imminent risk of death, serious physical injury, or an active cyberattack on critical infrastructure. Compliance with a substantially equivalent federal reporting regime designated by the attorney general satisfies this requirement.
MA
Introduced
Frontier developers must report any critical safety incident to the Attorney General within 15 days of discovery. If the incident poses an imminent risk of death or serious physical injury, the developer must disclose it within 24 hours to an appropriate authority, including law enforcement or public safety agencies.
MA
Introduced
Frontier developers may elect to comply with incident reporting requirements by complying with a substantially equivalent federal regime designated by the Attorney General, provided they declare intent to the Attorney General. Failure to meet the federal standard constitutes a violation of Massachusetts law.
MA
Introduced
Developers must report each AI safety incident affecting a covered model or any derivative under their control to the attorney general within 72 hours of learning of the incident or facts sufficient to establish a reasonable belief that an incident has occurred.
MI
Introduced
If a security breach occurs involving data collected through an electronic monitoring tool or automated decisions tool, the employer must (a) promptly secure the affected systems, mitigate harm, and certify that corrective steps were taken; and (b) within 48 hours of discovering the breach, notify all affected covered individuals with a notice that includes: (i) a summary of how the breach occurred, (ii) the specific data compromised (if known), (iii) how the employer is responding, and (iv) steps the individual can take to secure their data or apply for employer-covered protections.
MI
Introduced
Employers must notify the Department of Labor and Economic Opportunity and the attorney general of any security breach involving data collected through an electronic monitoring tool or automated decisions tool.
MI
Introduced
On a security breach of monitoring or automated-decision data, employers must promptly secure and remediate the systems, notify affected workers within 48 hours with breach details and protective steps, notify the department and attorney general, and provide affected workers extensive remedies including 10 years of identity-theft protection with a $5,000,000 insurance policy, credit and dark web monitoring, a three-bureau credit freeze, and fraud remediation.
MN
Introduced
Developers must disclose each safety incident affecting the AI model to the attorney general within 72 hours of the date the developer learns of the incident or learns sufficient facts to establish a reasonable belief that an incident has occurred. The disclosure must include: (1) the date of the safety incident, (2) the reasons the incident qualifies as a safety incident under the statute, and (3) a short plain-language statement describing the incident.
MN
Introduced
Developers must disclose each safety incident affecting the AI model to the attorney general within 72 hours of learning of the incident or within 72 hours of learning sufficient facts to establish a reasonable belief that a safety incident has occurred. The disclosure must include: (1) the date of the safety incident; (2) the reasons the incident qualifies as a safety incident under the statute; and (3) a short statement describing the safety incident in plain language.
MN
Introduced
Social media platforms must report articulable threats of targeted violence to the Minnesota Fusion Center and must follow MNFC reporting requests to facilitate transmission of threat information, files, personal information, and other data.
MN
Introduced
Social media platforms must report articulable threats of targeted violence to the MNFC within 24 hours of discovery; if the content indicates a person may act on the threat within 24 hours of posting, the platform must report immediately through any practicable means.
NJ
Introduced
Employers and public entities must establish, implement, and maintain reasonable data security practices for employee, service beneficiary, and applicant data. In the event of a security breach, the employer/public entity and vendor must provide written notice to the Department and each affected individual within 48 hours, describing the categories of data compromised and remediation steps. Employers, public entities, and vendors are jointly and severally liable for damages from security failures.
NY
Introduced
Licensees must notify the Department of State when their system fails to operate as intended for any significant period of time — meaning a period during which the malfunction had the capacity to harm or did harm persons. For systems that interact with law enforcement or government systems, perform law enforcement or government functions, or operate as weapons, licensees must additionally notify the specific law enforcement agency or governmental entity designated by the Department at the time of licensing.
PA
Introduced
Participants must notify the Office and report on consumer-protection actions taken if a tested product or service fails before the end of the testing period.
SC
Introduced
Covered entities must submit a report to the Attorney General within 15 days of obtaining knowledge of a covered incident — defined as an incident in which a user suffered death, a suicide attempt, self-harm requiring medical attention, a psychiatric emergency requiring urgent treatment, or serious physical injury arising from chatbot interactions. The report must include, to the extent known: (a) the date the operator learned of the incident, (b) the date of the incident, (c) a brief description of the incident and the basis for believing it is connected to the chatbot, and (d) a description of actions taken in response. The entity may submit a supplemental report within 60 days to update or correct information. Reports are confidential and exempt from FOIA.
SC
Introduced
Covered entities must submit a report to the Attorney General within 15 days of obtaining knowledge of a covered incident (death, suicide attempt, self-harm requiring medical attention, psychiatric emergency, or serious physical injury connected to a chatbot). The report must include, to the extent known: (1) the date the operator learned of the incident, (2) the date of the incident, (3) a brief description of the incident and the basis for the operator's belief that it is connected to the chatbot, and (4) a description of any responsive actions taken. A supplemental report may be submitted within 60 days to update or correct information. Reports are confidential and exempt from FOIA.
SC
Introduced
Developers must disclose to the Attorney General and to all known deployers or other developers any known or reasonably foreseeable risks of algorithmic discrimination arising from the intended uses of their high-risk AI system, without unreasonable delay but no later than 90 days after (1) the developer discovers through ongoing testing and analysis that the system has been deployed and has caused or is reasonably likely to have caused algorithmic discrimination, or (2) the developer receives from a deployer a credible report that the system has been deployed and has caused algorithmic discrimination.
US
Introduced
Covered model developers must report to the Secretary of Commerce within 7 days of knowing or reasonably believing that a defined reportable safety incident—including loss-of-control behavior, model-weight theft or self-exfiltration, offensive-cyber uplift, autonomous AI R&D acceleration, CBRN/explosive weapons uplift, or an averted near-miss—has occurred in connection with a covered model.
US
Introduced
Covered model developers must file an initial incident report within the 7-day window, provide expedited reporting for any reportable activity posing imminent or ongoing risk of serious harm, submit supplemental reports as material information develops, and include the incident description, discovery date, causal/contextual information, and national-security or public-safety implications.
US
Introduced
Upon a determination that a Federal official published AI-generated or AI-manipulated content without the required disclaimer, the responsible official (President, Vice President, or agency head) must (1) retract the content to the greatest extent possible and (2) issue a corrective communication stating the content violated this section, describing the factors that led to its publication, and where appropriate publishing a revised compliant version to the same audience.
US
Introduced
Sandbox participants must notify the Director and the head of each relevant applicable agency of any incident resulting in consumer health or safety harm, economic damage, or an unfair or deceptive trade practice within 72 hours of occurrence.
CA
Failed
Generative AI system providers must, within 24 hours of discovering a watermarking vulnerability or failure, report it to the Department of Technology and notify other providers that may be affected. Providers must also notify affected parties (platforms, researchers, users). Reports must be publicly posted on the provider's website; if public disclosure poses safety risks, providers may post a summary or delay disclosure up to 30 days while documenting mitigation efforts.
NC
Failed
Licensees must report any data breaches within 24 hours to the Department of Justice and within 48 hours to affected consumers, notwithstanding any other provision of law.
NC
Failed
Licensees must report any data breaches to the Department within 24 hours and to affected consumers within 48 hours.
NE
Failed eff 2027-01-01
Frontier developers must report any critical safety incident pertaining to one of their frontier models to the Attorney General within 15 days after discovering the incident.
NE
Failed eff 2027-01-01
Frontier developers must, when they discover that a critical safety incident poses an imminent risk of death or serious physical injury, disclose that incident within 24 hours to an appropriate authority, including any law enforcement agency or public safety agency with jurisdiction based on the nature of the incident.
NE
Failed eff 2027-01-01
Large chatbot providers must report any child safety incident pertaining to one of their covered chatbots to the Attorney General within 15 days after discovering the incident.
NE
Failed eff 2027-01-01
Frontier developers and large chatbot providers that elect to comply with the Act's reporting requirements via a designated federal safe harbor must declare their intent to the Attorney General. Compliance with the designated federal law, regulation, or guidance document constitutes compliance with the corresponding state obligations for critical safety incidents (if the federal standard addresses catastrophic risk) or child safety incidents (if it addresses child safety risk). Failure to meet the designated federal standard is itself a violation of the Act. A developer or provider may revoke its election by declaration to the AG, and the AG must revoke a designation if its conditions are no longer met.
NY
Failed
Large developers must disclose each safety incident affecting a frontier model to the Division of Homeland Security and Emergency Services within 72 hours of learning of the incident or learning facts sufficient to establish a reasonable belief that a safety incident has occurred. The disclosure must include: (1) the date of the safety incident, (2) the reasons the incident qualifies as a safety incident under the statutory definition, and (3) a short and plain statement describing the safety incident.
NY
Failed
Licensees must notify the department and, where applicable, relevant law enforcement or governmental entities when the system fails to operate as intended for a significant period of time — defined as a period where the malfunction had the capacity to or has harmed a person.
NY
Failed
Frontier developers must report any critical safety incident to the Office within 72 hours of determining or reasonably believing the incident occurred. If the incident poses imminent risk of death or serious physical injury, the developer must disclose it within 24 hours to appropriate law enforcement or public safety authorities. Developers electing to comply via a designated substantially equivalent federal reporting standard must concurrently copy incident reports to the Office.
TX
Failed
Developers that believe or have reason to believe a deployed high-risk AI system does not comply with this chapter must immediately take corrective action — including withdrawing, disabling, or recalling the system — and inform affected distributors and deployers.
TX
Failed
Developers that know or should reasonably know their high-risk AI system presents risks of algorithmic discrimination, unlawful personal data disclosure, or deceptive manipulation must immediately investigate the causes and inform the attorney general in writing of the non-compliance and corrective actions taken.
TX
Failed
Deployers must notify in writing the AI Council, the attorney general or the appropriate sector regulator, and affected consumers as soon as practicable after discovering that a deployed high-risk AI system has caused algorithmic discrimination.
TX
Failed
Developers that discover a deployed high-risk AI system is producing Subchapter B-violating inputs or outputs must cease the system's operation as soon as technically feasible and notify the AI Council and attorney general within 10 days of discovery.
US
Failed
Critical-impact AI organizations that discover their system is noncompliant with TEVV standards, or that are notified of noncompliance by the Secretary, must (1) immediately notify the Secretary, (2) take remedial action, and (3) within 10 days submit a report describing the nature of the noncompliance, remedial measures taken, and actions to address affected stakeholders.
UT
Failed eff 2026-05-06
Large frontier developers must report any safety incident (child safety incident or critical safety incident) to the Office of Artificial Intelligence Policy within 15 days of discovery.
UT
Failed eff 2026-05-06
Large frontier developers must disclose a critical safety incident posing imminent risk of death or serious physical injury to a law enforcement or public safety agency with appropriate jurisdiction within 24 hours of discovery.
UT
Failed
Learning Laboratory participants must immediately report to the Office any incidents resulting in consumer harm, privacy breach, or unauthorized data usage.