Two definitions of “frontier”
AI laboratories hold a technical definition of frontier AI: systems near the state of the art in capability, generality, autonomy, dangerous-domain performance, or training compute. The proposed legislation holds a separate legal definition, and does not need to win an argument with the laboratories about vocabulary:
The laboratories may define the technical frontier. The legislature defines the legal class of companies and natural persons who bear duties when they develop, enable, or deploy it.
The law does not need to decide which company has the best model. It needs to decide which companies and officers have enough capability, control, wealth, and institutional reach to create or materially amplify frontier-AI risk. Coverage attaches where three things meet:
frontier system + frontier activity + control or scale.
The technical frontier — what a frontier-AI system is
A model, agent, or embodied system is technically frontier where it satisfies one or more objective tests: training compute at or above 10²⁶ integer or floating-point operations; performance near the state of the art across broad capability evaluations; advanced autonomous operation; dangerous capability in domains such as cyber operations, biological research, or software engineering; or the capability to materially assist the development of a successor system meeting this definition. The operative version of this definition in the tagged statute is SEC. 1(b)(1) — compute, or Agency designation as frontier-equivalent by capability — with a third route, the developer’s own designation of its model as frontier, proposed at CURE 6.
The legal frontier — what a covered enterprise is
Frontier AI is an industrial system, not a model file. It is produced by chips, data centers, cloud access, models, deployment platforms, sensitive data, institutional permissions, and the capital that sustains the whole. A company controlling one decisive layer of that system may hold more practical power over public risk than a smaller company that technically pressed train.
A covered frontier enterprise is therefore an entity with a material frontier function — developing or materially modifying a frontier model; owning, operating, financing, reserving, or supplying the compute materially capable of training or deploying one; or deploying and integrating such systems at mass-market, governmental, military, financial, health, or critical-infrastructure scale — combined with a frontier-scale condition: the compute threshold itself, hyperscale capacity, consequential-sector deployment, or the bracketed capacity measures (AI-infrastructure commitments, valuation, revenue), each conjoined to a function and never operating alone. The operative language is CURE 7 in the v3.5 queue.
The two definitions, side by side
| Question | The laboratories’ technical definition | This Act’s legal definition |
|---|---|---|
| What is defined? | A model or system | A system, an activity, an enterprise, and a responsible natural person |
| Main concern | Capability and benchmarks | Public risk, control, scale, accountability |
| Role of 10²⁶ operations | Evidence of frontier-scale training | One objective route into coverage, not the only route |
| Role of wealth | None | Evidence of capacity, only ever conjoined to a material AI function |
| Cloud providers | “Merely infrastructure” | Covered where they materially enable, host, or scale frontier systems |
| Chip companies | “We do not build models” | Covered where they control indispensable frontier compute |
| Enterprise platforms | “We only deploy others’ models” | Covered as deployers of what they deploy — never deemed developers |
| Physical AI | Often treated separately | Included where autonomous systems act in the physical world |
| Who decides status? | The company’s own evaluations and marketing | The legislature sets criteria; regulators and courts apply evidence |
| Must the company agree? | It may narrow or drop the word at will | No. Statutory classification does not depend on corporate consent |
| Legal result | “Our most capable model” | Defined duties, held by named natural persons |
The industry already uses the word
Google DeepMind: “We call our most powerful foundation models ‘frontier models’.” Anthropic operates a Frontier Red Team and discusses the option to pause “frontier AI development.” Meta’s framework defines “Frontier AI” and adopts 10²⁶ operations as its own criterion. OpenAI has named an enterprise product Frontier. xAI’s homepage opens: “Frontier AI models for everything you imagine.” The verbatim record, with sources, is in the frontier enterprises file and the models file. The legislature is not inventing a term; it is specifying the legal consequences of one the industry chose.
Criteria, not names
The statute names no company. A law imposing special criminal duties on enumerated companies would invite a bill-of-attainder challenge and would deserve to; criteria are law, and any company meeting them enters, whatever it calls itself. The project’s coverage set of twelve is an illustration that the criteria, applied to the facts of August 2026, capture the principal forms of frontier-AI power — model development, compute supply, cloud infrastructure, embodied autonomy, enterprise deployment, institutional integration. The selection test is stated there in full.
The protective clauses
The two strongest anticipated attacks are answered inside the definition rather than in litigation:
No entity is covered solely because of its wealth, market value, revenue, use of artificial intelligence, association with a covered enterprise, or provision of ordinary commercial goods or services. Coverage requires a material frontier function and a frontier-scale condition.
No person is liable under this Act for an activity over which the person lacked practical power to prevent, halt, restrict, or correct the violation. Scope follows the ecosystem; duty follows the function. No one answers for a layer they do not hold.
The threshold objections, answered from the text — added 23 August 2026
The strongest published critique of compute-threshold triggers (Ball & Ramakrishnan, Carnegie, July 2025 — the entity-based paper held at the enterprise file) runs: inference-time compute now rivals training compute; small distilled models inherit frontier capability below any line; “training compute” invites definitional games (restarts, synthetic data, failed runs); and a fixed number ages. Each lands on a statute that uses compute alone. This Act does not. SEC. 1(b)(1) counts lineage compute and expressly names fine-tuning, distillation, merging and aggregation, with rule elaboration; capability designation reaches any model below the number, prospectively; the open queue adds the developer’s own self-designation (CURE 6) and the enterprise category (CURE 7) — which is the paper’s own proposal. The scoping contrast with the enacted family makes the same point from the other side: California’s revenue screen covers, on the survey’s count, exactly two developers (CSIS, Aug 2026, via Epoch’s May 2026 census — three public models above 10²⁶). A trigger that narrow is a choice; this Act’s function-plus-scale architecture is the answer to it. And the lineage-counting rule now has a federal sibling (added the same night): H.R. 8094, the bipartisan AI Foundation Model Transparency Act of 2026, reaches a model “trained using a quantity of computing power greater than 10²⁶ … including … the original training run and … any subsequent fine-tuning, reinforcement learning, or other material modifications” — the same figure, counted the same lineage-inclusive way, with thresholds updatable by rule (the census carries the full row). The Act’s most-criticized definitional choice is now also Congress’s bipartisan drafting instinct.
Where the operative text stands
Nothing on this page pretends. The tagged statute is v3.4: its scope is training compute above 10²⁶ operations, or Agency designation. The self-designation route (CURE 6) and the covered-frontier-enterprise architecture (CURE 7) are drafted, anchored, and open for attack in the v3.5 queue; they enter the statute only at the v3.5 revision, and the known objections to them are published beside them.
The argument this page supports: the case — when a natural person has practical authority over a frontier-AI activity, responsibility for preventing public harm cannot disappear through delegation, corporate structure, or an “I did not personally build the system” defense.