S-03
Safety & Prohibited Conduct
Frontier Model Safety Obligations
Developers of frontier AI models — defined by compute thresholds — face a distinct set of safety obligations focused on catastrophic and systemic risk. These go beyond general AI system safety obligations to address existential-scale harms, dual-use potential for weapons of mass destruction, and deployment gating based on risk thresholds.
Sub-obligations5
Bills23
Jurisdictions11
Enacted3
Show
Sort bills within section

5 sub-obligations of S-03

Click any row to jump to its bills below.
ID Sub-Obligation Enacted Live Failed Total
S-03.1 Catastrophic risk assessment and mitigation
Frontier model developers must assess and document the risk that their models could cause catastrophic harm — such as mass casualties, critical infrastructure attacks, or other existential-scale outcomes — and implement appropriate safeguards to prevent unreasonable risk of such harm.
1Enacted 10Live 1Failed 12Total Jump →
S-03.2 CBRN and critical infrastructure risk evaluation
Developers must evaluate whether the model provides meaningful uplift to individuals seeking to develop chemical, biological, radiological, or nuclear weapons, or to plan attacks on critical infrastructure. Must be documented and updated as capabilities change.
0Enacted 0Live 0Failed 0Total Jump →
S-03.3 Risk-threshold deployment prohibition
A developer may not deploy a frontier model if doing so would create an unreasonable risk of critical harm. Critical harm is defined in most statutes as CBRN weapon creation or mass-casualty autonomous AI conduct causing death or serious injury to 100+ people or $1B+ in damages.
1Enacted 7Live 1Failed 9Total Jump →
S-03.4 Compute and capability reporting
Developers of models trained above defined compute thresholds must report model characteristics — including training compute, architecture, capabilities, and safety evaluation results — to designated regulatory authorities.
0Enacted 2Live 0Failed 2Total Jump →
S-03.5 Frontier AI safety framework publication
Large frontier model developers must write, implement, comply with, and publicly publish a frontier AI safety framework detailing how the developer handles catastrophic risk assessment and thresholds, safety oversight, third-party evaluation processes, cybersecurity protections, and whistleblower procedures. The framework must be kept current and updated following material changes to the developer's systems or risk profile.
7Enacted 30Live 8Failed 45Total Jump →
Bills That Map This Requirement 68 mappings
S-03.1
Catastrophic risk assessment and mitigation
Frontier model developers must assess and document the risk that their models could cause catastrophic harm — such as mass casualties, critical infrastructure attacks, or other existential-scale outcomes — and implement appropriate safeguards to prevent unreasonable risk of such harm.
Enacted
1
Live
10
Failed
1
Total
12
NY
Enacted eff 2025-12-19
Large developers must, before deploying any frontier model: (1) implement a written safety and security protocol covering risk reduction, cybersecurity protections, testing procedures, compliance requirements, and senior personnel designation; (2) retain an unredacted copy of the protocol (including update records) for the duration of deployment plus five years; (3) conspicuously publish a redacted copy and transmit it to the Division of Homeland Security and Emergency Services; (4) grant DHSES or the attorney general access to the unredacted protocol upon request (with redactions only as required by federal law); (5) record and retain for deployment plus five years all test data and results from frontier model assessments, in sufficient detail for third-party replication; and (6) implement appropriate safeguards to prevent unreasonable risk of critical harm.
IL
Introduced eff 2027-01-01
Large frontier developers must write, implement, comply with, and publicly publish a safety plan detailing how they (1) define and assess catastrophic risk thresholds, (2) apply mitigations, (3) review risk assessments before deployment or extensive internal use, (4) use third parties to evaluate catastrophic risks, (5) implement cybersecurity for unreleased model weights, and (6) manage catastrophic risk from internal use. The plan must, if successfully implemented, prevent unreasonable catastrophic risk.
IL
Introduced eff 2027-01-01
Large frontier developers must write, implement, comply with, and publicly publish a public safety and child protection plan that describes how they define catastrophic risk thresholds, apply mitigations, review catastrophic risk assessments before deployment, engage third parties for risk evaluation, implement cybersecurity for unreleased model weights, and manage catastrophic risk from internal use. The plan must, if successfully implemented, prevent unreasonable catastrophic risk.
MA
MA SB 37 (Frontier AI Safety) § G.L. c. 93M, § 2
Introduced
Developers must implement reasonable administrative, technical, and physical cybersecurity protections before beginning to train a covered model, including protections against advanced persistent threats and unauthorized access, misuse, or unsafe post-training modifications of the model and all derivatives controlled by the developer.
MA
MA SB 37 (Frontier AI Safety) § G.L. c. 93M, § 2
Introduced
Developers must implement the capability to promptly enact a full shutdown of all training, covered models, and covered model derivatives under their control before beginning to train a covered model.
MA
MA SB 37 (Frontier AI Safety) § G.L. c. 93M, § 2
Introduced
Developers must take reasonable care to implement other appropriate measures to prevent covered models and covered model derivatives from posing unreasonable risks of causing or materially enabling critical harms.
MA
MA SB 37 (Frontier AI Safety) § G.L. c. 93M, § 2
Introduced
Developers must, before deployment or commercial release of a covered model, (1) assess whether the model is reasonably capable of causing or materially enabling a critical harm, (2) record and retain test results for at least five years with sufficient detail for third-party replication, (3) implement appropriate safeguards to prevent critical harm, and (4) ensure that model actions and resulting harms can be accurately attributed to the specific model or derivative.
NJ
Introduced
Large frontier developers with users in New Jersey must write, implement, and annually review and update technical and organizational protocols to assess and reduce the risk that a frontier model materially contributes to catastrophic harm.
NJ
Introduced
Large frontier developers must submit to the Attorney General a New Model Risk Disclosure before or when deploying a new or substantially modified frontier model, containing replicable catastrophic-risk assessments, their results, the extent of third-party evaluator involvement, and other steps required by rule.
NJ
Introduced
Large frontier developers with users in New Jersey must write and implement technical and organizational protocols to assess and reduce the risk of a frontier model materially contributing to catastrophic harm.
NJ
Introduced
Large frontier developers must, before or concurrently with deploying a new or substantially modified frontier model, submit to the Attorney General a New Model Risk Disclosure containing (1) replicable catastrophic-risk assessments, (2) the assessment results, (3) the extent of third-party evaluator involvement, and (4) other steps required by the Attorney General's rules.
NY
Failed
Large developers must, before deploying a frontier model, implement appropriate safeguards to prevent unreasonable risk of critical harm. Critical harm is defined as death or serious injury of 100+ people or $1B+ in damages caused or materially enabled by the developer's frontier model through CBRN weapon creation/use or autonomous criminal conduct.
S-03.2
CBRN and critical infrastructure risk evaluation
Developers must evaluate whether the model provides meaningful uplift to individuals seeking to develop chemical, biological, radiological, or nuclear weapons, or to plan attacks on critical infrastructure. Must be documented and updated as capabilities change.
Enacted
0
Live
0
Failed
0
Total
0
No bills map this sub-obligation yet.
S-03.3
Risk-threshold deployment prohibition
A developer may not deploy a frontier model if doing so would create an unreasonable risk of critical harm. Critical harm is defined in most statutes as CBRN weapon creation or mass-casualty autonomous AI conduct causing death or serious injury to 100+ people or $1B+ in damages.
Enacted
1
Live
7
Failed
1
Total
9
NY
Enacted eff 2025-12-19
Large developers must not deploy a frontier model if doing so would create an unreasonable risk of critical harm. Critical harm is defined as death or serious injury of 100 or more people or at least $1 billion in damages through CBRN weapon creation/use or autonomous AI criminal conduct with limited human intervention.
IL
Introduced eff 2027-01-01
Large frontier developers must not use or deploy a frontier model if doing so would pose unreasonable catastrophic risk.
IL
Introduced eff 2027-01-01
Large frontier developers must not use or deploy a frontier model if doing so would pose unreasonable catastrophic risk.
IL
Introduced
Developers may alternatively satisfy the safe harbor requirements by (1) agreeing to be bound by the EU AI Act Article 56 safety and security requirements, or (2) entering a federal agency agreement that grants the agency access to the developer's frontier models for research and evaluation, facilitates evaluation of cyber and biological risks, and permits public release of evaluation results for publicly released models.
MA
MA SB 37 (Frontier AI Safety) § G.L. c. 93M, § 2
Introduced
Developers must not deploy or make available for commercial, public, or foreseeably public use a covered model or covered model derivative if there is an unreasonable risk that it will cause or materially enable a critical harm.
MN
MN HF 4532 (RAISE Act) § Minn. Stat. § 325M.41
Introduced
Developers must not deploy an AI model if doing so creates an unreasonable risk of critical harm.
MN
Introduced
Developers must not deploy an AI model if doing so creates an unreasonable risk of critical harm. Critical harm is defined as death, serious physical injury, or mental injury to 25 or more people, or at least $1,000,000 in property damage, caused or materially enabled by the developer's use, storage, or release of the model, resulting from CBRN weapon creation or use, or autonomous criminal conduct.
US
Introduced
No person may deploy an advanced AI system for use in interstate or foreign commerce unless that person is in compliance with the program participation and information-provision obligations.
NY
Failed
Large developers must not deploy a frontier model if doing so would create an unreasonable risk of critical harm.
S-03.4
Compute and capability reporting
Developers of models trained above defined compute thresholds must report model characteristics — including training compute, architecture, capabilities, and safety evaluation results — to designated regulatory authorities.
Enacted
0
Live
2
Failed
0
Total
2
NJ
Introduced
Large frontier developers must submit to the Attorney General a New Model Risk Disclosure before or when deploying a new or substantially modified frontier model, containing replicable catastrophic-risk assessments, their results, the extent of third-party evaluator involvement, and other steps required by rule.
NJ
Introduced
Large frontier developers must, before or concurrently with deploying a new or substantially modified frontier model, submit to the Attorney General a New Model Risk Disclosure containing (1) replicable catastrophic-risk assessments, (2) the assessment results, (3) the extent of third-party evaluator involvement, and (4) other steps required by the Attorney General's rules.
S-03.5
Frontier AI safety framework publication
Large frontier model developers must write, implement, comply with, and publicly publish a frontier AI safety framework detailing how the developer handles catastrophic risk assessment and thresholds, safety oversight, third-party evaluation processes, cybersecurity protections, and whistleblower procedures. The framework must be kept current and updated following material changes to the developer's systems or risk profile.
Enacted
7
Live
30
Failed
8
Total
45
CA
CA SB 53 (Frontier AI Transparency) § Bus. & Prof. Code § 22757.12
Enacted eff 2026-01-01
Large frontier developers must write, implement, comply with, and clearly and conspicuously publish on their internet website a frontier AI framework that applies to the developer's frontier models and describes how the developer approaches: (1) incorporating national, international, and industry-consensus best practices; (2) defining and assessing thresholds for catastrophic risk capabilities, which may include multiple tiers; (3) applying mitigations based on assessment results; (4) reviewing assessments and mitigations as part of deployment decisions or extensive internal use; (5) using third parties to assess catastrophic risks and mitigation effectiveness; (6) revisiting and updating the framework, including criteria triggering updates and substantial-modification disclosure thresholds; (7) cybersecurity practices to secure unreleased model weights; (8) identifying and responding to critical safety incidents; (9) instituting internal governance to ensure implementation; and (10) assessing and managing catastrophic risk from internal use, including risks from frontier models circumventing oversight.
CA
CA SB 53 (Frontier AI Transparency) § Bus. & Prof. Code § 22757.12
Enacted eff 2026-01-01
Large frontier developers must review and, as appropriate, update their frontier AI framework at least once per year. If a material modification is made, the developer must clearly and conspicuously publish the modified framework and a justification for the modification within 30 days.
NY
Enacted eff 2025-12-19
Large developers must, before deploying any frontier model: (1) implement a written safety and security protocol covering risk reduction, cybersecurity protections, testing procedures, compliance requirements, and senior personnel designation; (2) retain an unredacted copy of the protocol (including update records) for the duration of deployment plus five years; (3) conspicuously publish a redacted copy and transmit it to the Division of Homeland Security and Emergency Services; (4) grant DHSES or the attorney general access to the unredacted protocol upon request (with redactions only as required by federal law); (5) record and retain for deployment plus five years all test data and results from frontier model assessments, in sufficient detail for third-party replication; and (6) implement appropriate safeguards to prevent unreasonable risk of critical harm.
NY
Enacted eff 2025-12-19
Large developers must conduct an annual review of their safety and security protocol to account for changes to frontier model capabilities and industry best practices, and must modify the protocol if necessary. If modifications are made, the updated protocol must be published and transmitted to DHSES in the same manner as the original.
NY
Enacted eff 2025-12-19
Any person who is not yet a large developer but who sets out to train a frontier model that, if completed as planned, would qualify that person as a large developer must, before beginning training: (1) implement a written safety and security protocol (excluding the testing-procedure detail requirements of paragraphs (c) and (d) of the protocol definition); and (2) transmit an appropriately redacted copy of the protocol to the Division of Homeland Security and Emergency Services. Accredited colleges and universities engaging in academic research are excluded.
NY
Enacted eff 2027-01-01
Large frontier developers must write, implement, comply with, and clearly and conspicuously publish on their website a frontier AI framework covering: incorporation of national and international standards; catastrophic risk thresholds and assessment; mitigations; deployment-decision review; third-party risk assessment; framework update criteria; cybersecurity for unreleased model weights; critical safety incident response; internal governance; and internal-use catastrophic risk management including risks from frontier models circumventing oversight.
NY
Enacted eff 2027-01-01
Large frontier developers must review and, as appropriate, update their frontier AI framework at least once per year. Any material modification must be published with a justification within thirty days.
IL
Introduced
Developers must produce, implement, follow, and conspicuously publish a safety and security protocol covering critical risk management, testing procedures, security protections, safeguards, incident response, and deployment gating. Material modifications must be published within 30 days of taking effect.
IL
Introduced
Developers must not knowingly make false or materially misleading statements or omissions in or regarding documents produced under their safety and security protocol obligations.
IL
Introduced eff 2027-01-01
Large frontier developers must write, implement, comply with, and publicly publish a safety plan detailing how they (1) define and assess catastrophic risk thresholds, (2) apply mitigations, (3) review risk assessments before deployment or extensive internal use, (4) use third parties to evaluate catastrophic risks, (5) implement cybersecurity for unreleased model weights, and (6) manage catastrophic risk from internal use. The plan must, if successfully implemented, prevent unreasonable catastrophic risk.
IL
Introduced
Large frontier developers must write, implement, comply with, and publicly publish a frontier AI safety framework covering catastrophic risk thresholds and assessment, mitigations, deployment-gating review, third-party evaluation, framework update criteria, cybersecurity for unreleased model weights, critical safety incident response, internal governance, and internal-use risk management.
IL
Introduced
Large frontier developers must review and, as appropriate, update their frontier AI safety framework at least annually. Material modifications must be republished with justification within 30 days.
IL
Introduced eff 2027-01-01
Large frontier developers must write, implement, comply with, and publicly publish a public safety and child protection plan that describes how they define catastrophic risk thresholds, apply mitigations, review catastrophic risk assessments before deployment, engage third parties for risk evaluation, implement cybersecurity for unreleased model weights, and manage catastrophic risk from internal use. The plan must, if successfully implemented, prevent unreasonable catastrophic risk.
IL
Introduced eff 2027-01-01
Large frontier developers and large chatbot providers must describe in their public safety and child protection plan how they incorporate national, international, and industry-consensus standards; how they revisit and update the plan, including criteria triggering updates and substantial-modification thresholds; how they identify and respond to safety incidents; and how they institute internal governance practices to ensure implementation.
IL
Introduced eff 2027-01-01
Large frontier developers and large chatbot providers must publish any material modification to their public safety and child protection plan, along with a justification for the modification, within 30 days after the modification is made.
IL
Introduced
Large frontier developers must write, implement, comply with, and publicly publish on their website a frontier AI framework covering catastrophic risk thresholds, mitigation strategies, third-party evaluation, cybersecurity for unreleased model weights, critical safety incident response, internal governance, and internal-use risk management.
IL
Introduced
Large frontier developers must review and, as appropriate, update their frontier AI framework at least annually, and must publish any material modification with justification within 30 days.
IL
Introduced
Developers must publish a safety and security protocol satisfying Section 15 requirements and adhere to it prior to releasing a frontier model, and must publish a transparency report satisfying Section 20 requirements at the time of release, in order to qualify for the liability safe harbor against critical harm claims. These requirements do not apply where the developer does not reasonably foresee a material difference between the new model's capabilities or risks and a previously evaluated model.
IL
Introduced
Developers must create a safety and security protocol documenting technical and organizational procedures for managing, assessing, and mitigating risk of critical harm, including high-level summaries of (1) testing procedures, (2) risk thresholds and tiered response actions, (3) mitigation measures and effectiveness assessments, (4) third-party assessment plans, (5) cybersecurity practices for protecting unreleased model weights, (6) post-deployment monitoring and response procedures, and (7) processes for identifying when a model presents material new risks requiring additional assessment. Appropriate redactions for model security, trade secrets, and proprietary information are permitted.
LA
Introduced eff 2027-01-01
Large frontier developers must write, implement, comply with, and publicly publish on their website a frontier AI framework describing their approach to catastrophic risk management across ten enumerated domains, including cybersecurity risk thresholds for critical infrastructure, biochemical weapon risk, third-party evaluation, model weight security, incident response protocols, and internal governance.
LA
Introduced eff 2027-01-01
Large frontier developers must review and update their frontier AI framework at least annually, and must publish any material modification on their website within 30 days along with a justification for the modification.
LA
Introduced eff 2027-01-01
Frontier developers must not make materially false or misleading statements about catastrophic risk, their management of catastrophic risk, or their implementation of or compliance with their frontier AI framework, unless the statement was made in good faith and was reasonable under the circumstances.
MA
Introduced
Large frontier developers must write, implement, comply with, and publicly publish on their website a frontier AI framework covering catastrophic risk thresholds, mitigations, third-party assessment, cybersecurity of unreleased model weights, critical safety incident response, internal governance, and internal-use risk management.
MA
Introduced
Large frontier developers must review and update their frontier AI framework at least annually, and must publish any material modification with a justification within 30 days.
MA
MA SB 37 (Frontier AI Safety) § G.L. c. 93M, § 2
Introduced
Developers must implement a written safety and security protocol before beginning to train a covered model that specifies protections and testing procedures for evaluating and mitigating the risk of critical harm from the model and its derivatives, including detailed procedures for post-training modification risk assessment, shutdown conditions, and protocol modification.
MA
MA SB 37 (Frontier AI Safety) § G.L. c. 93M, § 2
Introduced
Developers must conspicuously publish a redacted copy of the safety and security protocol and transmit a copy to the attorney general. Redactions are permitted only for public safety, trade secrets, or confidential information. The unredacted protocol must be provided to the AG upon request. Material modifications must be published and transmitted within 30 days.
MI
Introduced eff 2026-01-01
Large developers must ensure their safety and security protocol describes in detail all of the following, as applicable: (1) criteria for excluding limited-risk foundation models from coverage; (2) intolerable critical-risk thresholds, justifications, and responses upon threshold breach; (3) testing and assessment procedures for investigating critical risks, including model evasion, misuse, modification, increased compute execution, and derivative model creation; (4) deployment gating procedures for foundation models posing critical risks; (5) physical, digital, and organizational security protections against unauthorized insider or third-party access that could create critical risk; (6) safeguards and risk mitigation measures, including efficacy and limitation assessments; (7) incident response procedures for materialized or imminent critical risks; (8) reassessment triggers and procedures when modifying models, expanding access, or combining models with other software; (9) incident reporting conditions and designated report recipients; (10) conditions for modifying the protocol itself; (11) identification of protocol components with sufficient scientific detail for independent replication, and designation of experts receiving unredacted versions; and (12) any role played by a financially disinterested third party.
MI
Introduced eff 2026-01-01
Large developers must produce, implement, comply with, and conspicuously publish a safety and security protocol meeting the requirements of Section 5, beginning January 1, 2026.
MI
Introduced eff 2026-01-01
Large developers must conspicuously publish any material modifications to their safety and security protocol not more than 30 days after the modification is made.
MI
Introduced eff 2026-01-01
Large developers must not knowingly make false or materially misleading statements or omissions in or regarding documents produced in accordance with this act.
MN
MN HF 4532 (RAISE Act) § Minn. Stat. § 325M.41
Introduced
Developers must, before deploying an AI model, implement a written safety and security protocol that describes reasonable protections to reduce the risk of critical harm, cybersecurity protections against unauthorized access or misuse, detailed testing procedures for evaluating critical-harm risk, and designated senior compliance personnel. Developers must retain an unredacted copy of the protocol, including all update records and dates of revisions, for the entire period the AI model is deployed plus five years.
MN
MN HF 4532 (RAISE Act) § Minn. Stat. § 325M.41
Introduced
Developers must conspicuously publish a copy of the safety and security protocol with appropriate redactions, and transmit a copy of the redacted protocol to the attorney general. If the attorney general requests access, the developer must grant access to the protocol with redactions only to the extent required by federal law.
NJ
Introduced
Large frontier developers must annually submit to the Attorney General a Risk Management Disclosure explaining the technical and organizational protocols implemented to assess and reduce catastrophic-harm risk.
NJ
Introduced
Large frontier developers must structure their Risk Management Disclosure to map each of their actions to the NIST AI Risk Management Framework suggested actions, stating relevance, adoption, implementation details or justification for non-adoption, compliance criteria, and responsible personnel.
NJ
Introduced
Large frontier developers must clearly identify in the Risk Management Disclosure which sections were written, edited, or otherwise contributed to by a generative AI system.
NY
Introduced
Large frontier developers must ensure their frontier AI frameworks meet minimum standards adopted by the office within the Department of Financial Services to prevent unreasonable levels of catastrophic risk. The office must adopt these regulations by July 1, 2028, considering industry best practices, national and international standards, and other jurisdictions' laws, and must solicit feedback from academia, the Empire AI research institute, the attorney general, civil society, frontier model developers, and foundation model developers.
NY
Introduced
The office must review frontier AI framework regulations annually and update them as necessary to account for changes in scientific understanding of catastrophic risk, technical advancements in frontier models, critical safety incidents, and identified gaps in existing regulations.
NE
Failed eff 2027-01-01
Large frontier developers must write, implement, comply with, and clearly and conspicuously publish on their website a public safety and child protection plan that describes in detail how the developer: (1) defines and assesses capability thresholds for catastrophic risk, including multiple-tiered thresholds; (2) applies mitigations based on those assessments; (3) reviews catastrophic risk assessments and mitigation adequacy as part of deployment or extensive internal use decisions; (4) uses third parties to assess catastrophic risk potential and mitigation effectiveness; (5) implements cybersecurity practices to secure unreleased frontier model weights from unauthorized modification or transfer; (6) assesses and manages catastrophic risk from internal model use, including oversight circumvention risks; (7) incorporates national, international, and industry-consensus standards and best practices; (8) revisits and updates the plan, including update-trigger criteria and substantial-modification thresholds; (9) identifies and responds to safety incidents; and (10) institutes internal governance practices to ensure plan implementation. Large chatbot providers must publish a plan covering child safety risk assessment, mitigation, third-party evaluation, and the same shared elements (standards incorporation, updates, incident response, and governance).
NE
Failed eff 2027-01-01
Large frontier developers and large chatbot providers must, within 30 days of making a material modification to their public safety and child protection plan, clearly and conspicuously publish on their website the modified plan and a justification for the modification.
NY
Failed
Large developers must, before deploying a frontier model, implement a written safety and security protocol covering risk reduction procedures, cybersecurity protections, detailed testing procedures (including misuse, modification, and evasion scenarios), compliance requirements stated with sufficient specificity for third-party verification, a description of how the developer will fulfill its obligations under the article, and designation of senior personnel responsible for compliance. The large developer must retain an unredacted copy of the protocol, including records and dates of all updates or revisions, for as long as the frontier model is deployed plus five years.
NY
Failed
Large developers must conduct an annual review of any safety and security protocol to account for changes to their frontier models' capabilities and industry best practices, and must make modifications as necessary. If modifications are made, the developer must republish the protocol (with appropriate redactions) and transmit a copy to the Division of Homeland Security and Emergency Services.
NY
Failed
Any person who is not yet a large developer but who sets out to train a frontier model that, if completed as planned, would qualify them as a large developer must, before beginning such training: (1) implement a written safety and security protocol (excluding the detailed testing and misuse-assessment elements required of existing large developers), and (2) transmit an appropriately redacted copy of the protocol to the Division of Homeland Security and Emergency Services.
NY
Failed
Large frontier developers must write, implement, comply with, and clearly and conspicuously publish on their website a frontier AI framework covering catastrophic risk thresholds and assessment, mitigation measures, deployment-gating review, third-party evaluation, framework update criteria, cybersecurity practices for model weights, critical safety incident response, internal governance, and management of internal-use catastrophic risk including model control evasion.
NY
Failed
Large frontier developers must review and, as appropriate, update their frontier AI framework at least annually and must clearly and conspicuously publish any material modification along with a justification within thirty days.
UT
UT HB 286 (AI Transparency Act) § Utah Code § 13-72b-102
Failed eff 2026-05-06
Large frontier developers must write, implement, comply with, and publicly publish on their website a public safety plan detailing catastrophic risk thresholds, mitigation measures, third-party evaluation, cybersecurity protections for model weights, incident response, and internal governance. Material modifications must be published with justification within 30 days.