The interim standards — the adopted texts, pinned
SEC. 3(c)(4) of the Model Act adopts, as its interim standards, the frontier artificial intelligence framework duties of three enacted state laws, “each as in effect on [1 August 2026] … as they so exist and not as they may afterward be amended, repealed, suspended, or invalidated in the enacting jurisdiction,” and directs that “the Agency shall make the adopted texts publicly available without charge.” A fourth state has since enacted one, and it is deliberately not below. Connecticut’s SB 5 became law on 27 May 2026, on the same 10²⁶-operation threshold, with a large-developer tier at $500,000,000 in annual revenue. It is not adopted at SEC. 3(c)(4), for two reasons stated here so that its absence is a decision rather than an oversight. First, adding an interim standard changes the tagged statutory text, and the reproducibility chain the reviewer’s copy rests on forbids editing a tagged file — see E10; it is therefore a v3.5 drafting question, held in the open cure queue. Second, and substantively, Connecticut’s frontier provision is an internal whistleblower channel rather than a safety-framework duty of the kind SEC. 3(c)(4) adopts — its operative requirement is that catastrophic-risk reports “shall be shared with the officers and directors of the large frontier developer at least quarterly”, with no duty attaching to those officers. Whether that belongs among the adopted duties is a question for a drafter, not a housekeeping fix. The full row is at the bill census; the miss that produced this paragraph is E16.
A research draft has no Agency; it has a repository. This file practices the rule before preaching it: the adopted texts, pinned here verbatim, free to read. State statutes are government edicts and carry no copyright (Georgia v. Public.Resource.Org, 590 U.S. 429 (2020)); the enacting jurisdictions’ official publishers control over any transcription error here. Line wrapping has been normalized from the source presentations; wording, numbering, and punctuation are untouched.
1. California — Business and Professions Code § 22757.12
Division 8, Chapter 25.1 (Transparency in Frontier Artificial Intelligence Act). Added by Stats. 2025, ch. 138, § 2 (SB 53), effective January 1, 2026. Reproduced from the 2025 California Code as published by Justia (law.justia.com/codes/california/code-bpc/division-8/chapter-25-1/section-22757-12/), retrieved 19 August 2026; the official publication at leginfo.legislature.ca.gov controls.
22757.12. (a) A large frontier developer shall write, implement, comply with, and clearly and conspicuously publish on its internet website a frontier AI framework that applies to the large frontier developer’s frontier models and describes how the large frontier developer approaches all of the following:
(1) Incorporating national standards, international standards, and industry-consensus best practices into its frontier AI framework.
(2) Defining and assessing thresholds used by the large frontier developer to identify and assess whether a frontier model has capabilities that could pose a catastrophic risk, which may include multiple-tiered thresholds.
(3) Applying mitigations to address the potential for catastrophic risks based on the results of assessments undertaken pursuant to paragraph (2).
(4) Reviewing assessments and adequacy of mitigations as part of the decision to deploy a frontier model or use it extensively internally.
(5) Using third parties to assess the potential for catastrophic risks and the effectiveness of mitigations of catastrophic risks.
(6) Revisiting and updating the frontier AI framework, including any criteria that trigger updates and how the large frontier developer determines when its frontier models are substantially modified enough to require disclosures pursuant to subdivision (c).
(7) Cybersecurity practices to secure unreleased model weights from unauthorized modification or transfer by internal or external parties.
(8) Identifying and responding to critical safety incidents.
(9) Instituting internal governance practices to ensure implementation of these processes.
(10) Assessing and managing catastrophic risk resulting from the internal use of its frontier models, including risks resulting from a frontier model circumventing oversight mechanisms.
(b) (1) A large frontier developer shall review and, as appropriate, update its frontier AI framework at least once per year.
(2) If a large frontier developer makes a material modification to its frontier AI framework, the large frontier developer shall clearly and conspicuously publish the modified frontier AI framework and a justification for that modification within 30 days.
(c) (1) Before, or concurrently with, deploying a new frontier model or a substantially modified version of an existing frontier model, a frontier developer shall clearly and conspicuously publish on its internet website a transparency report containing all of the following:
(A) The internet website of the frontier developer.
(B) A mechanism that enables a natural person to communicate with the frontier developer.
(C) The release date of the frontier model.
(D) The languages supported by the frontier model.
(E) The modalities of output supported by the frontier model.
(F) The intended uses of the frontier model.
(G) Any generally applicable restrictions or conditions on uses of the frontier model.
(2) Before, or concurrently with, deploying a new frontier model or a substantially modified version of an existing frontier model, a large frontier developer shall include in the transparency report required by paragraph (1) summaries of all of the following:
(A) Assessments of catastrophic risks from the frontier model conducted pursuant to the large frontier developer’s frontier AI framework.
(B) The results of those assessments.
(C) The extent to which third-party evaluators were involved.
(D) Other steps taken to fulfill the requirements of the frontier AI framework with respect to the frontier model.
(3) A frontier developer that publishes the information described in paragraph (1) or (2) as part of a larger document, including a system card or model card, shall be deemed in compliance with the applicable paragraph.
(4) A frontier developer is encouraged, but not required, to make disclosures described in this subdivision that are consistent with, or superior to, industry best practices.
(d) A large frontier developer shall transmit to the Office of Emergency Services a summary of any assessment of catastrophic risk resulting from internal use of its frontier models every three months or pursuant to another reasonable schedule specified by the large frontier developer and communicated in writing to the Office of Emergency Services with written updates, as appropriate.
(e) (1) (A) A frontier developer shall not make a materially false or misleading statement about catastrophic risk from its frontier models or its management of catastrophic risk.
(B) A large frontier developer shall not make a materially false or misleading statement about its implementation of, or compliance with, its frontier AI framework.
(2) This subdivision does not apply to a statement that was made in good faith and was reasonable under the circumstances.
(f) (1) When a frontier developer publishes documents to comply with this section, the frontier developer may make redactions to those documents that are necessary to protect the frontier developer’s trade secrets, the frontier developer’s cybersecurity, public safety, or the national security of the United States or to comply with any federal or state law.
(2) If a frontier developer redacts information in a document pursuant to this subdivision, the frontier developer shall describe the character and justification of the redaction in any published version of the document to the extent permitted by the concerns that justify redaction and shall retain the unredacted information for five years.
(Added by Stats. 2025, Ch. 138, Sec. 2. (SB 53) Effective January 1, 2026.)
2. New York — General Business Law § 1421
Article 44-B (Responsible AI Safety and Education (RAISE) Act), added by ch. 96, L. 2026. Reproduced from the official New York State Senate OpenLegislation publication (nysenate.gov/legislation/laws/GBS/1421), revision of record 3 April 2026, retrieved 19 August 2026. The source carries the note “NB Effective January 1, 2027”; SEC. 3(c)(4)(A) of the Model Act adopts the duties without regard to the enacting jurisdiction’s effective or phase-in dates.
§ 1421. Transparency requirements. 1. A large frontier developer shall write, implement, comply with, and clearly and conspicuously publish on its internet website a frontier AI framework that applies to the large frontier developer’s frontier models and describes in detail how the large frontier developer handles all of the following:
(a) incorporating national standards, international standards, and industry consensus best practices into its frontier AI framework;
(b) defining and assessing thresholds used by the large frontier developer to identify and assess whether a frontier model has capabilities that could pose a catastrophic risk, which may include multiple-tiered thresholds;
(c) applying mitigations to address the potential for catastrophic risks based on the results of assessments undertaken pursuant to paragraph (b) of this subdivision;
(d) reviewing assessments and adequacy of mitigations as part of the decision to deploy a frontier model or use it extensively internally;
(e) using third parties to assess the potential for catastrophic risks and the effectiveness of mitigations of catastrophic risks;
(f) revisiting and updating the frontier AI framework, including any criteria that trigger updates and how the large frontier developer determines when its frontier models are substantially modified enough to require disclosures pursuant to subdivision three of this section;
(g) cybersecurity practices to secure unreleased model weights from unauthorized modification or transfer by internal or external parties;
(h) identifying and responding to critical safety incidents;
(i) instituting internal governance practices to ensure implementation of these processes; and
(j) assessing and managing catastrophic risk resulting from the internal use of its frontier models, including risks resulting from a frontier model circumventing oversight mechanisms.
- (a) A large frontier developer shall review and, as appropriate, update its frontier AI framework at least once per year.
(b) If a large frontier developer makes a material modification to its frontier AI framework, the large frontier developer shall clearly and conspicuously publish the modified frontier AI framework and a justification for that modification within thirty days.
- (a) Before, or concurrently with, deploying a new frontier model or a substantially modified version of an existing frontier model, a frontier developer shall clearly and conspicuously publish on its internet website a transparency report containing all of the following:
(i) the internet website of the frontier developer;
(ii) a mechanism that enables a natural person to communicate with the frontier developer;
(iii) the release date of the frontier model;
(iv) the languages supported by the frontier model;
(v) the modalities of output supported by the frontier model;
(vi) the intended uses of the frontier model; and
(vii) any generally applicable restrictions or conditions on uses of the frontier model.
(b) Before, or concurrently with, deploying a new frontier model or a substantially modified version of an existing frontier model, a large frontier developer shall include in the transparency report required by paragraph (a) of this subdivision, summaries of all of the following:
(i) assessments of catastrophic risks from the frontier model conducted pursuant to the large frontier developer’s frontier AI framework;
(ii) the results of the assessments under subparagraph (i) of this paragraph;
(iii) the extent to which third-party evaluators were involved; and
(iv) other steps taken to fulfill the requirements of the frontier AI framework with respect to the frontier model.
(c) A frontier developer that publishes the information described in paragraph (a) or (b) of this subdivision as part of a larger document, including a system card or model card, shall be deemed in compliance with the applicable paragraph.
- (a) (i) A frontier developer shall not make a materially false or misleading statement about catastrophic risk from its frontier models or its management of catastrophic risk.
(ii) A large frontier developer shall not make a materially false or misleading statement about its implementation of, or compliance with, its frontier AI framework.
(b) This subdivision shall not apply to a statement that was made in good faith and was reasonable under the circumstances.
- (a) When a frontier developer publishes documents to comply with this section, such frontier developer may make redactions to such documents that are necessary to protect such frontier developer’s trade secrets, such frontier developer’s cybersecurity, public safety, or the national security of the United States or to comply with any federal or state law.
(b) If a frontier developer redacts information in a document pursuant to this subdivision, such frontier developer shall describe the character and justification of such redaction in any published version of such document to the extent permitted by the concerns that justify redaction and shall retain the unredacted information for five years.
NB Effective January 1, 2027
3. Illinois — Artificial Intelligence Safety Measures Act, Section 10
Public Act 104-0538 (SB 315, 104th General Assembly), the Artificial Intelligence Safety Measures Act; approved July 6, 2026; the Act takes effect January 1, 2027 (Section 99). Reproduced from the enrolled bill as published by the Illinois General Assembly (ilga.gov/documents/legislation/104/SB/PDF/10400SB0315lv.pdf), retrieved 20 August 2026; the official ILGA publication of P.A. 104-0538 controls.
Section 10. Frontier AI framework.
(a) Beginning January 1, 2028, a large frontier developer shall write, implement, comply with, and clearly and conspicuously publish on its website a frontier AI framework that applies to the large frontier developer’s frontier models and describes how the large frontier developer approaches all of the following:
(1) incorporating national standards, international standards, and industry-consensus best practices into its frontier AI framework;
(2) defining and assessing thresholds used by the large frontier developer to identify and assess whether a frontier model has capabilities that could pose a catastrophic risk, which may include multiple-tiered thresholds;
(3) applying mitigations to address the potential for catastrophic risks based on the results of assessments undertaken pursuant to paragraph (2);
(4) reviewing assessments and adequacy of mitigations as part of the decision to deploy a frontier model or use it extensively internally;
(5) using third parties to assess the potential for catastrophic risks and the effectiveness of mitigations of catastrophic risks;
(6) revisiting and updating the frontier AI framework, including any criteria that trigger updates and how the large frontier developer determines when its frontier models are substantially modified enough to require disclosures pursuant to subsection (c);
(7) cybersecurity practices to secure unreleased model weights from unauthorized modification or transfer by internal or external parties;
(8) identifying and responding to critical safety incidents;
(9) instituting internal governance practices to ensure implementation of these processes; and
(10) assessing and managing catastrophic risk resulting from the internal use of its frontier models, including risks resulting from a frontier model circumventing oversight mechanisms.
(b)(1) A large frontier developer shall review and, as appropriate, update its frontier AI framework at least once per year.
(2) If a large frontier developer makes a material modification to its frontier AI framework, the large frontier developer shall clearly and conspicuously publish on its website the modified frontier AI framework and a justification for that modification within 30 days.
(c)(1) Before, or concurrently with, deploying a new frontier model or a substantially modified version of an existing frontier model, a frontier developer shall clearly and conspicuously publish on its website a transparency report containing all of the following:
(A) the website of the frontier developer;
(B) a mechanism that enables a natural person to communicate with the frontier developer;
(C) the release date of the frontier model;
(D) the languages supported by the frontier model;
(E) the modalities of output supported by the frontier model;
(F) the intended uses of the frontier model; and
(G) any generally applicable restrictions or conditions on uses of the frontier model.
(2) Before, or concurrently with, deploying a new frontier model or a substantially modified version of an existing frontier model, a large frontier developer shall include in the transparency report required by paragraph (1) of this subsection (c) summaries of all of the following:
(A) assessments of catastrophic risks from the frontier model conducted pursuant to the large frontier developer’s frontier AI framework;
(B) the results of the assessments under subparagraph (A);
(C) the extent to which third-party evaluators were involved; and
(D) other steps taken to fulfill the requirements of the frontier AI framework with respect to the frontier model.
(3) All summaries required under paragraph (2) shall be provided in a machine-readable format to facilitate verification of model claims.
(4) A frontier developer that publishes the information described in paragraph (1) or (2) as part of a larger document, including a system card or model card, shall be deemed in compliance with the applicable paragraph.
(5) A frontier developer is encouraged, but not required, to make disclosures described in this subsection (c) that are consistent with, or superior to, industry best practices.
(d) Beginning on January 1, 2028 or 90 days after a developer first qualifies as a large frontier developer, whichever is later, a large frontier developer shall annually retain a third party to perform an independent audit of compliance with the requirements of this Section. The third party shall conduct audits consistent with generally accepted auditing standards and best practices and shall possess demonstrated competence to perform the audit, including experience employing or contracting with individuals who possess technical expertise in the safety of frontier models. A large frontier developer shall not retain a third party if either the large frontier developer or the third party has a financial interest in the other party. A large frontier developer may compensate a third party for its services but shall not condition any payment or the amount of any payment on the results of the third party’s audit.
(1) The third party shall be granted access to all materials reasonably necessary to comply with the third party’s obligations under this subsection (d), including, but not limited to, all unredacted versions of materials published pursuant to this Act. To protect the frontier developer’s trade secrets and confidential business information, cybersecurity, national security of the United States, or public safety, a large frontier developer may impose security protocols on the third party, including, but not limited to, restrictions on note taking, copying, retaining, or removing materials; requirements for on-premise review; and confidentiality requirements.
(2) The third party shall produce a report that includes all of the following:
(A) a description of whether the large frontier developer has substantially complied with the requirements of this Section;
(B) if applicable, a description of material deviations from the requirements of this Section, an explanation of any deviation and its rationale, and any recommendations for how the developer can improve its policies and processes for ensuring compliance with the requirements of this Section;
(C) a detailed assessment of the large frontier developer’s internal controls, including its designation and empowerment of senior personnel responsible for such implementation by the large frontier developer, its employees, and its contractors;
(D) a list of the personnel involved in the audit;
(E) the third party’s procedures for managing conflicts of interest and any conflicts of interest of any personnel involved in the audit;
(F) the methodology of the audit and the nature of the information reviewed by the third party to conduct the audit; and
(G) the signature of the lead auditor certifying the results of the audit.
(3) The large frontier developer shall retain an unredacted copy of the report for as long as a frontier model is deployed plus 5 years.
(4)(A) No later than 30 days after receiving the audit report, the large frontier developer shall conspicuously publish on its website a high-level summary of the audit findings and a copy of the third party’s report with appropriate redactions and transmit a copy of the redacted report to the Agency and the Attorney General.
(B) The large frontier developer shall grant the Agency and the Attorney General access to the third party’s report, with redactions, upon request, subject to the redactions permitted under subsection (g).
(e) A large frontier developer shall transmit to the Agency a summary of any assessment of catastrophic risk resulting from internal use of its frontier models every 3 months or pursuant to another reasonable schedule specified by the large frontier developer and communicated in writing to the Agency and the Attorney General with written updates, as appropriate and agreed upon by the Agency.
(f)(1) A frontier developer shall not make a materially false or misleading statement about catastrophic risk from its frontier models or its management of catastrophic risk.
A large frontier developer shall not make a materially false or misleading statement about its implementation of, or compliance with, its frontier AI framework.
(2) This subsection (f) does not apply to a statement that was made in good faith and was reasonable under the circumstances.
(g)(1) When a frontier developer publishes documents to comply with this Section, the frontier developer may make redactions to those documents that are necessary to protect the frontier developer’s trade secrets, the frontier developer’s cybersecurity, public safety, or the national security of the United States or to comply with any federal or State law.
(2) If a frontier developer redacts information in a document pursuant to this subsection (g), the frontier developer shall describe the character and justification of the redaction in any published version of the document to the extent permitted by the concerns that justify redaction and shall retain the unredacted information for 5 years.
NB Act effective January 1, 2027 (Section 99); subsection (a) operates from January 1, 2028, and subsection (d) from January 1, 2028 or 90 days after a developer first qualifies as a large frontier developer, whichever is later.
Retrieved and pinned 19–20 August 2026. Where any text above differs from the enacting jurisdiction’s official publication, the official publication controls, and a correction here is an erratum for the register.