# US Frontier AI Legislation Tracker (2025–2026)

Compiled for the frontier AI law audit project. "Frontier" = laws/bills targeting the largest AI developers and catastrophic risk from advanced models, plus the independent-verification-organization (IVO) / AI-auditor licensing bills that form a distinct sub-category. Section J lists items checked and **excluded**.

**Confidence key** (applies to the row as a whole; individual cells noted where they differ):

  - **HIGH** — the load-bearing proposition was checked directly against an operative primary record (statute/bill text, official legislature action page, rule/order, docket or first-party program record)
  - **MED-HIGH** — strong corroboration, but a load-bearing primary record is nonpublic, inaccessible, or does not itself establish the full proposition
  - **MED** — two or more concurring reputable secondary sources; primary material does not establish the key detail
  - **SEARCH-QUALIFIED** — a date-bounded negative finding (for example, "no case located"), not proof that an event does not exist
  - **LOW** — single source, or key details thin/unverified

Verified as of **September 5, 2026**. Legislative status changes weekly — re-check the primary link before citing. Confidence is assessed **per claim** where cells differ; the row rating is the weakest load-bearing claim in the row. Items marked ⟨R⟩ were first identified by an external review (Sept. 4, 2026) and then independently checked unless a cell expressly says otherwise. ⟨NCSL⟩ marks an item discovered in the final NCSL keyword cross-check. ⟨U⟩ marks a row added or changed in a supplementary check through **October 8, 2026**; those rows carry their own dates and ratings, and the Sept. 5 recertification statement below does not cover them (see the supplementary note at the end of Section L).

## A. Enacted state frontier-developer laws (the core template)

| **Bill** | **State** | **Sponsor(s)** | **Core mechanism** | **Thresholds** | **Signed** | **Effective** | **Penalties / enforcement** | **Source** | **Confidence** |
| --- | --- | --- | --- | --- | --- | --- | --- | --- | --- |
| **S.B. 53 — Transparency in Frontier AI Act (TFAIA)** | CA | Sen. Scott Wiener (D) | Frontier AI framework; transparency reports; critical-incident reporting **15 days, or 24 hrs if imminent risk of death/serious injury**; whistleblower protections incl. anonymous channel with monthly updates; annual definitional review; CalCompute consortium; **preempts local ordinances adopted on/after Jan 1, 2025 regulating frontier catastrophic risk** | 10²⁶ ops incl. fine-tuning/RL; "large frontier developer" = \>$500M revenue; catastrophic risk = \>50 deaths/serious injuries or \>$1B damage | Sept 29, 2025 | Jan 1, 2026 (OES anonymized reporting & annual reviews from Jan 1, 2027) | Up to $1M/violation; AG enforcement; **no general private right to enforce developer obligations, but employees may sue for whistleblower retaliation** | [Bill text — leginfo.ca.gov](https://leginfo.legislature.ca.gov/faces/billTextClient.xhtml?bill_id=202520260SB53) | **HIGH** |
| **RAISE Act — Chapter 699 of 2025 (S.6953-B/A.6453-B), repealed and replaced by Chapter 96 of 2026 (S.8828/A.9449)** | NY | Sen. Andrew Gounardes (D); Asm. Alex Bores (D) | Chapter 96 **repeals** the original Gen. Bus. Law Art. 44-B and enacts a new Art. 44-B (§§1420–1429) that copies TFAIA's frontier AI framework (§1421(1)) and transparency report (§1421(3)) — deemed compliant if published within a system/model card; incident reporting **72 hrs to the DFS Office, 24 hrs to law enforcement if imminent risk** (§1422(3)); quarterly internal-use catastrophic-risk summaries (§1422(2)); **large-developer disclosure statement** with 5%/50% beneficial owners, renewed **every 2 years**, pro-rata assessment, $1,000/day for non-filing (§1428); new office within Dept. of Financial Services with **broad rulemaking authority incl. "additional reporting or publication requirements"** (§1429); **scope limited to models "developed, deployed, or operating in whole or in part in New York"** (§1425); exempts accredited colleges/universities and the Empire AI Consortium (§1426); §1427(3) expressly preserves a developer's right to argue another party caused the harm. **Federal reciprocity is narrower than IL's: it covers incident reporting only** (§1422(8)–(9)), and the designated federal standard need not require audits. **Contains no whistleblower section and no audit mandate** — both were in the June 2025 version and were removed | 10²⁶ ops incl. fine-tuning/RL/material modifications (§1420(9)); \>$500M revenue with affiliates, preceding calendar year (§1420(10)); catastrophic risk \>50 deaths/serious injury or \>$1B; equity-value loss excluded (§1423) | Original Dec 19, 2025; **S.8828 passed Senate 58-1 (Jan 28, 2026), passed Assembly Mar 11, signed Mar 27, 2026** | **Jan 1, 2027** (Chapter 96 §3 replaced the original "90th day" effective clause) | $1M first / $3M subsequent, scaled to severity; AG civil action (§1427(1)); no private right of action (§1427(2)); good-faith exception for false statements (§1421(4)(b)) | [S.8828 text + votes — nysenate.gov](https://www.nysenate.gov/legislation/bills/2025/S8828) · [Cooley comparison to TFAIA](https://www.cooley.com/news/insight/2026/2026-03-31-new-yorks-frontier-ai-law-gets-a-california-makeover-with-some-key-differences) | **HIGH** (enacted S.8828 text read on nysenate.gov) |
| **S.B. 315 — AI Safety Measures Act (Public Act 104-0538)** | IL | Sen. Mary Edly-Allen (D-Lake County), chief sponsor; Rep. Daniel Didech (D-Buffalo Grove), House; broadly bipartisan co-sponsors (chief co-sponsors include Republicans Rezin, Hills, Curran) | **Sec. 10:** frontier AI framework (from Jan 1, 2028); transparency reports before/at deployment — deemed compliant if published within a system/model card; **annual independent third-party audit** (from Jan 1, 2028 or 90 days after qualifying), auditor must have no financial interest in developer and payment can't be conditioned on results; redacted audit report published within 30 days and sent to Agency + AG; quarterly internal-use catastrophic-risk summaries. **Sec. 15:** incident reporting **72 hrs** to Illinois Emergency Management Agency and Office of Homeland Security ("Agency") + AG; **24 hrs** to appropriate authority if imminent risk of death/serious injury; public reporting mechanism; FOIA exemption for incident reports, internal-use assessments, unredacted audits, auditor work papers. **Sec. 17 interoperability:** developer may declare intent to comply via a designated federal law/regulation/guidance that (1) has substantially equivalent-or-stricter incident reporting, (3) is substantially equivalent in mitigating catastrophic risk, and **(4) requires independent third-party audits** — then failure to meet the federal standard is an IL violation. **Sec. 18:** disclosure statement with 5%+ beneficial owners (private) / 50%+ (public), renewed annually, pro-rata fee. **Sec. 20:** whistleblower protections for "covered employees" incl. anonymous channel with monthly updates and AG Workplace Rights Hotline; amends IL Whistleblower Act. **Sec. 35:** declares frontier-model regulation an exclusive State power — **denies home rule**. **Legislative mechanics:** introduced Jan 24, 2025 as a Predatory Loan Prevention Act technical bill; Senate Floor Amendment No. 1 (filed May 11, 2026) replaced the entire text; four floor amendments adopted May 21. **Timing mismatch worth flagging:** Sec. 10(c) transparency reports have no 2028 gate and so apply from the Jan 1, 2027 effective date, yet large-developer reports must summarize assessments "conducted pursuant to the frontier AI framework" — which isn't required until 2028 | 10²⁶ ops incl. original run + fine-tuning/RL/material modifications; "large frontier developer" = \>$500M revenue with affiliates, preceding calendar year; catastrophic risk = \>50 deaths/serious injury or \>$1B (equity-value loss excluded, Sec. 25(c)) | Sent to Governor June 26; **signed July 6, 2026** (Gov. Pritzker) | **Jan 1, 2027** (disclosure statements, incident reporting, whistleblower, transparency reports); **framework + audit obligations from Jan 1, 2028** | $1M first / $3M subsequent, scaled to severity; **AG-exclusive** action under the AI Act; **no general private right under that Act, but employee remedies are preserved through the Illinois Whistleblower Act**; $1,000/day for failing to file a disclosure statement; good-faith exception for false statements (Sec. 10(f)(2)) | [Enrolled text — ilga.gov](https://www.ilga.gov/Legislation/BillStatus/FullText?LegDocId=197587&DocName=10400SB0315enr&DocNum=315&DocTypeID=SB&LegID=157797&GAID=18&SessionID=114&SpecSess=&Session=) · [Bill status + amendments + roll calls — ilga.gov](https://www.ilga.gov/Legislation/BillStatus?DocNum=315&GAID=18&DocTypeID=SB&LegId=157797&SessionID=114) · [Public Act 104-0538](https://www.ilga.gov/Legislation/PublicActs/View/104-0538) | **HIGH** (enrolled text read on ilga.gov) |

Votes (ilga.gov roll calls): SB 315 passed IL Senate **52-5-2 NV** (May 21, 2026) and House **110-0-4 NV** (May 27, 2026); both Executive Committees unanimous. Anthropic publicly supported SB 315 and the MA bill; OpenAI praised the IL process — noted because industry positioning is itself a variable for the audit.

**Verification status (Sept. 5, 2026):** HIGH from primary documents — all three Category A laws; CT Public Act 26-15; the TN H.B. 1898/S.B. 2171 introduced text and official amended-bill fiscal summary; IL H.B. 3506 amendment, H.B. 4705 text, S.B. 3261/H.B. 4799 status, and S.B. 3444 sponsor; LA S.B. 474 engrossed text; the introduced texts of H.R. 9925, S. 2938, S. 5061, H.R. 9914/S. 5105, H.R. 9477, H.R. 9965, **H.R. 9917**, S. 4656, H.R. 10180, and H.R. 10189; **EO 14409**; **NIST AITE**; the federal export-control rules in Section G.3; CA S.B. 1047; the Senate's 99–1 moratorium roll call; all Category E frameworks and the Sanders–Casar announcement; the Anthropic v. Department of War complaint; and the other items whose rows say HIGH. MED-HIGH remains appropriate where the operative government record is nonpublic or a proposition rests partly on reporting: the June 12 model-access directive's issuing authority and rationale, and the Aug. 7 Trump remarks. Negative findings are marked SEARCH-QUALIFIED rather than being promoted to HIGH. **No cell is rated LOW.**

## B. Pending, stalled, and failed state frontier-developer bills (status class shown in bold at start of Status cell)

| **Bill** | **State** | **Sponsor** | **Core mechanism** | **Thresholds** | **Status (as of Sept 5, 2026)** | **Source** | **Confidence** |
| --- | --- | --- | --- | --- | --- | --- | --- |
| **H.5576 — "An Act relative to economic development in the commonwealth"** (Senate AI language = amendment S.3178; lineage: S.37 → S.2630 → S.3178) | MA | Sen. Barry Finegold (D); Sen. Mike Rush amendment for stronger evaluations | Frontier AI framework; AG civil-action enforcement; **Senate version: mandatory independent third-party catastrophic-risk review at least every 120 days** (the most frequent evaluation cadence among the bills reviewed); whistleblower protections; commission on further AI regulation. **House version (passed July 8) contains no AI-safety language — only funding.** | Senate text: \>$500M annual AI-derived revenue **or** \>$1B AI R\&D spend; catastrophic risk 50+ deaths or $1B | **\[PENDING\]** House passed **148-2** July 8; Senate struck all after the enacting clause and inserted S.3178 text July 24 (reprinted as S.3228); **House non-concurred July 30; conference committee appointed July 30** (Senate: Finegold-Rodrigues-Durant; House: Michlewitz-Fiola-Soter). **Official bill history checked live Sept 4, 2026: no action since July 30.** Formal session ended July 31; informal sessions can still act but can't override a veto. **Not enacted.** Bill history re-checked Sept 28, 2026: still no action since July 30 ⟨U⟩. OpenAI lobbying for IL-style annual audits; Anthropic for the stronger Rush amendment | [H.5576 bill history — malegislature.gov](https://malegislature.gov/Bills/194/H5576) · [S.2630 text](https://malegislature.gov/Bills/194/S2630.pdf) · [S.3178 fact sheet](https://malegislature.gov/PressRoom/Detail?pressReleaseId=1445) | **HIGH** (malegislature.gov bill history read Sept 4, 2026) |
| **H.B. 4668 — Artificial Intelligence Safety and Security Transparency Act** | MI | Rep. Lightner (R) | Safety & security protocol; **transparency reports every 90 days**; **annual third-party audit** (published within 90 days); whistleblower protections **with private right of action** (90-day window, clear-and-convincing standard) + anonymous channel with monthly updates; AG enforcement. **Appears to be a clone of the original June 2025 RAISE Act text** — same $5M/$100M compute-cost thresholds, same 100-death threshold, same audit/whistleblower structure that NY later stripped out. Effective dates are written as "Beginning January 1, 2026" — already past, since the bill hasn't moved | **Cost-based, not FLOP-based:** "large developer" = trained a model costing ≥$5M in compute (at prevailing cloud prices) **and** ≥$100M aggregate compute cost in preceding 12 months; **critical risk = \>100 deaths/serious injuries or \>$1B** | **\[STALLED\]** Introduced June 24, 2025 (referred to Judiciary); re-referred to Communications & Technology Mar 19, 2026. No hearings/votes found; legislature.mi.gov history re-checked Sept 28, 2026: no change ⟨U⟩ | [Official introduced text — Michigan Legislature](https://www.legislature.mi.gov/documents/2025-2026/billintroduced/House/pdf/2025-HIB-4668.pdf) | **HIGH** (full bill text read) |
| **S.4446 / A.5275 — "An Act concerning artificial intelligence safety"** ⟨R⟩ | NJ | Asm. Andrew Macurdy (D-21); **Sen. Raj Mukherji (D-32)** for S.4446 | Large frontier developers with NJ users must: implement protocols; file annual **"Risk Management Disclosure"** with AG, **mapped item-by-item to the NIST AI RMF**; file pre-deployment "New Model Risk Disclosure" with replicable assessments; **flag which sections were written by generative AI**. AG publishes with redactions. AG **may** audit or contract a private auditor (discretionary). **5-year sunset.** **Defines "critical safety incident" but imposes no reporting obligation** (orphaned definition). No whistleblower provisions | 10²⁶ ops incl. fine-tuning/RL; **"large frontier developer" = \>$100M revenue** (lowest of any bill); **catastrophic harm = 25+ deaths/serious injuries or $1B** (lowest casualty threshold of any bill); weapons list includes illegal firearms, lethal autonomous weapons, explosives — broader than CBRN | **\[PENDING\]** A.5275 introduced June 15, 2026; referred to Assembly Science, Innovation & Technology Committee. **S.4446 introduced June 11, 2026** — identical text (verified against njleg.gov) | [A.5275 official text](https://pub.njleg.state.nj.us/Bills/2026/A5500/5275_I1.HTM) · [S.4446 official text](https://pub.njleg.gov/Bills/2026/S4500/4446_I1.HTM) | **HIGH** (both chambers' texts read) |
| **H.B. 3506 — Artificial Intelligence Safety and Security Protocol Act (2025)** | IL | Rep. Daniel Didech (D); co-sponsor Rep. Matt Hanson (added Jan. 2026) | **The FPF-counted 2025 Illinois frontier bill — gap resolved.** Original-RAISE-style design, the same template as MI H.B. 4668: developers publish a safety and security protocol; **risk assessment report every 90 days**; **annual third-party audit** of protocol compliance; redaction rules; whistleblower protections (Committee Amendment No. 1 narrowed scope to "large developer" and added employee civil damages); civil penalties. **Illinois lineage:** this 2025 SSP bill did not advance; the 2026 S.B. 3312/S.B. 315 switched to the TFAIA template and added the audit back — the state moved from the original-RAISE structure to California-plus-audits within twelve months | Floor Amendment No. 2: "large developer" = ≥$5M compute cost for a single model **and** ≥$100M aggregate compute cost over the preceding 12 months — the original-RAISE test | **\[STALLED\]** Filed Feb. 7, 2025; **passed Cybersecurity, Data Analytics & IT Committee 7–4 (Mar. 20, 2025)**; held on second reading; **re-referred to Rules under Rule 19(a) Apr. 11, 2025**. Inactive, but not formally dead while the 104th General Assembly remains open | [Official amendment text](https://www.ilga.gov/legislation/billstatus/fulltext?DocName=10400HB3506ham002&DocNum=3506&DocTypeID=HB&GAID=18&LegDocId=204229&LegID=162191&SessionID=114) · [ILGA status + amendments](https://www.ilga.gov/Legislation/BillStatus?GAID=18&DocNum=3506&DocTypeID=HB&LegId=0&SessionID=114) | **HIGH** (official amendment and status page read) |
| **S.B. 3444 — Artificial Intelligence Safety Act** | IL | Sen. Bill Cunningham (D) ⟨R⟩ | **Different design from SB 315:** a **liability shield** — developer not liable for critical harms absent intent/recklessness *if* it publishes a safety & security protocol and transparency report; deemed compliant if bound by EU rules or a federal agency agreement; sunsets if federal law creates overlapping requirements | Frontier models defined by compute or cost | **\[STALLED\]** Introduced Feb 4, 2026; **re-referred to Assignments May 22, 2026 (stalled)** — superseded politically by SB 315 | [ilga.gov status](https://www.ilga.gov/ftp/legislation/104/BillStatus/HTML/10400SB3444.html) | **HIGH** (ilga.gov synopsis) |
| **S.B. 3312 — AI Safety Measures Act (original vehicle)** | IL | Sen. Edly-Allen; House parallel **H.B. 4799** ([ilga.gov](https://www.ilga.gov/Legislation/BillStatus?DocNum=4799&DocTypeID=HB&GAID=18&SessionID=114)) ⟨R⟩ | The standalone version of what became SB 315: frontier AI framework, IEMA incident reporting, **ILCompute** public cloud consortium, Dept. of Innovation & Technology definitional review. Its text was moved into SB 315 via floor amendment; SB 3312 itself stalled | 10²⁶ ops; \>$500M | **\[STALLED\]** Re-referred to Assignments May 22, 2026 (stalled) | [ilga.gov status](https://www.ilga.gov/ftp/legislation/104/BillStatus/HTML/10400SB3312.html) | **HIGH** (ilga.gov synopsis) |
| **H.B. 4705 — AI Public Safety and Child Protection Transparency Act** | IL | Rep. Daniel Didech (D) ⟨R⟩; Senate parallel **S.B. 3261**, sponsored by Sen. Mary Edly-Allen (D) and co-sponsors ([ILGA](https://www.ilga.gov/Legislation/BillStatus?DocNum=3261&DocTypeID=SB&GA=104&GAID=18&SessionID=114)) | Hybrid: frontier developers **and** large chatbot providers must publish a public-safety and child-protection plan; AG incident-reporting mechanism; whistleblower protections; annual third-party audits of large frontier developers; AG rulemaking | 10²⁶ ops; **large frontier developer** = ≥$500M annual revenue; **large chatbot provider** = ≥$25M annual revenue; a **covered chatbot** must also have ≥1M monthly active users and be foreseeably accessible by minors | **\[STALLED\]** H.B. 4705 re-referred to Rules Committee Mar. 27, 2026; S.B. 3261 re-referred to Assignments May 22, 2026 | [Official H.B. 4705 text](https://ilga.gov/Legislation/BillStatus/FullText?DocNum=4705&DocTypeID=HB&GAID=18&LegId=165724&SessionID=114) · [H.B. 4705 status](https://www.ilga.gov/ftp/legislation/104/BillStatus/HTML/10400HB4705.html) | **HIGH** (official text and status pages read) |
| **H.B. 1898 / S.B. 2171 — Artificial Intelligence Public Safety and Child Protection Transparency Act** ⟨R⟩ | TN | Rep. Jason Zachary (R-Knoxville); Sen. Ken Yager (R-Kingston); 15 R / 1 D co-sponsors | CA/IL-style hybrid: large frontier developers publish a frontier safety plan; large chatbot providers (≥1M monthly users, minors) publish child-protection plans; incident reporting **15 days / 24 hrs imminent**; independent reviews; whistleblower protections; AG enforcement. **Same title as IL HB 4705 — a model bill circulating in at least two states, Republican-sponsored in TN.** Opposed by CCIA and CCAGW as "outdated catastrophic-risk constructs" | 10²⁶ ops; \>$500M revenue | **\[FAILED\]** **House passed 94–0 (Apr 16, 2026)**; Senate referred SB 2171 to Commerce & Labor; not enacted before adjournment (tracker marks dead Apr 24). The official fiscal memorandum for the amended bill states an effective date of **July 1, 2027** | [Introduced text — Tennessee General Assembly](https://www.capitol.tn.gov/Bills/114/Bill/HB1898.pdf) · [Official bill page and actions](https://wapp.capitol.tn.gov/apps/BillInfo/Default?BillNumber=HB1898&GA=114) · [Official fiscal memorandum summarizing bill as amended](https://capitol.tn.gov/Bills/114/Fiscal/FM2994.pdf) · [CCIA opposition letter](https://ccianet.org/wp-content/uploads/2026/04/TN-HB-1898.pdf) | **HIGH** (introduced text, official amended-bill fiscal summary, and official actions read) |
| **H.B. 286 (1st Substitute) — Artificial Intelligence Transparency Amendments** ⟨NCSL⟩ | UT | Rep. Doug Fiefia (R); Senate sponsor Sen. Michael K. McKell (R) | TFAIA-style public-safety plan plus a child-protection plan for covered chatbots; predeployment risk-assessment summaries; safety-incident reporting **15 days / 24 hrs if imminent** to the Office of Artificial Intelligence Policy or appropriate public-safety authority; quarterly internal-use summaries; false-statement prohibition; anonymous internal reporting and employee anti-retaliation remedies. AG enforcement; $1M first / $3M subsequent civil penalties | 10²⁶ ops; large frontier developer = ≥$500M annual revenue; catastrophic risk = \>50 deaths/serious injuries or \>$1B property loss; covered chatbot = ≥1M monthly active users and foreseeable access by minors | **\[FAILED\]** Introduced Jan. 19, 2026; first substitute received an 8–0 favorable committee recommendation Jan. 27; moved from the third-reading calendar to Rules Mar. 3; enacting clause struck and filed among bills not passed Mar. 6 | [Official Utah bill page, versions, status, and votes](https://le.utah.gov/~2026/bills/static/HB0286.html) · [Introduced text](https://le.utah.gov/Session/2026/bills/introduced/HB0286.pdf) · [Official substitute comparison](https://le.utah.gov/Session/2026/bills/introduced/CP%20HB0286%20To%20HB0286S01.pdf) | **HIGH** (official text, comparison, status, and committee vote read) |
| **S.B. 474 — Protecting Louisiana's Infrastructure from Artificial Intelligence Risk Act** ⟨R⟩ | LA | Sen. Gregory A. Miller | Frontier AI framework (annual review; material changes published in 30 days); transparency reports; quarterly internal-use risk summaries to the department; incident reporting **15 days / 24 hrs** (imminent death/injury **or active cyberattack on critical infrastructure**); **annual independent audit from July 1, 2028** + annual written compliance certification; whistleblower protections with civil action and attorney fees; federal reciprocity for incident reporting; **local preemption** for ordinances after July 1, 2027; public-records exemption sunsets July 1, 2031; framed around energy, health-care, and port infrastructure | 10²⁶; large frontier developer = \>$500M annual gross revenue in the preceding calendar year | **\[FAILED\]** Introduced Mar. 31, 2026; reported favorably by Commerce Committee Apr. 15; engrossed Apr. 20; floor amendments adopted Apr. 21 and **"returned to the Calendar, subject to call"** — never received final Senate passage; **not enacted**. Would have been effective Jan. 1, 2027 | [Engrossed text](https://www.legis.la.gov/Legis/ViewDocument.aspx?d=1462764) · [Official Senate digest](https://www.legis.la.gov/legis/ViewDocument.aspx?d=1464016) · [Bill status](https://www.legis.la.gov/legis/BillInfo.aspx?b=SB474&s=26rs&sbi=y) | **HIGH** (official engrossed text, digest, and status page read) |
| **S.358 / H.5224** ⟨R⟩ | RI | Sen. Gu + 8 co-sponsors (S.358, Feb 21, 2025) | **Different design: strict tort liability.** Developers of covered models are strictly liable for injuries to *non-users* caused by model conduct that would be negligent, tortious, or criminal if done by a human, where the conduct was not intended or reasonably anticipated by the user or any fine-tuner; **rebuttable presumption that the AI satisfies a tort's mental-state element** ("it shall not be a defense that AI systems are incapable of having mental states"); affirmative defenses for meeting the human standard of care or pure capability failure. **Resolves the FPF-identified Rhode Island gap** | **SB 1047's thresholds verbatim:** 10²⁶ ops **and** \>$100M compute cost; fine-tuning 3×10²⁵ ops and \>$10M | **\[STALLED\]** Referred to Senate Judiciary; no further action found | [S.358 text — rilegislature.gov](https://webserver.rilegislature.gov/Billtext/BillText25/SenateText25/S0358.htm) · [H.5224 text](https://webserver.rilegislature.gov/BillText25/HouseText25/H5224.pdf) | **HIGH** (official text read) |
| **S.10373 / A.11636 — third-party verification of RAISE compliance** ⟨R⟩ | NY | Sen. Andrew Gounardes (D) — the RAISE Act's own sponsor | Adds new GBL §1425: large frontier developers must **annually** retain a third-party verifier to assess framework compliance, permissibility of redactions, and whether public statements match findings; summary published within 60 days; DFS/DIGIT to **accredit verifiers by July 1, 2028**; **only accredited verifiers from Jan 1, 2029**; FOIL exemption. **Sponsor memo concedes the amended RAISE Act "left a significant gap: … no mechanism exists to verify"** — the sponsor re-adding the audit requirement the March 2026 chapter amendment removed | Uses RAISE definitions | **\[PENDING\]** Introduced May 15, 2026; in Senate Internet & Technology Committee | [S.10373 text + sponsor memo — nysenate.gov](https://www.nysenate.gov/legislation/bills/2025/S10373) | **HIGH** (official text and memo read) |
| **S.10456 — minimum standards for frontier AI frameworks** ⟨R⟩ | NY | Sen. Andrew Gounardes (D) | Adds GBL §1430: DFS/DIGIT must adopt regulations **by July 1, 2028** setting minimum standards for large frontier developers' frameworks, reviewed annually. **Sponsor memo: the RAISE Act left "the design of these frameworks solely in large developers' hands"** — a direct statement that the enacted law's self-defined-framework model is a gap | Uses RAISE definitions | **\[PENDING\]** Introduced May 15, 2026; in Senate Internet & Technology Committee | [S.10456 text + sponsor memo — nysenate.gov](https://www.nysenate.gov/legislation/bills/2025/S10456) | **HIGH** (official text and memo read) |
| **S.10701 — "TERMINATOR Act" (technical evaluation, risk monitoring, incident notification, AI testing, oversight, and response act)** ⟨U⟩ | NY | Sen. Patricia Fahy (D) | **Introduced text read.** Amends the RAISE Act (GBL Article 44-B as replaced by Chapter 96 of 2026) by adding GBL §§ 1429–1436: **independent pre-deployment safety evaluation** of each frontier model by an accredited "independent safety evaluator" (models already deployed: within 180 days), covering underlying capabilities, capabilities reasonably accessible in the deployment configuration, and the circumvention resistance of safeguards; **re-evaluation after material modifications**; post-deployment monitoring; tamper-evident safety records; rules on privileged model access and model-weight release; a duty to mitigate material and unreasonable catastrophic risk; protected safety disclosures and independent safety research, with anti-retaliation and a confidential reporting channel; **"significant safety incident"** reporting to the office within **7 days**; additions to transparency reports; **civil penalty up to 0.5% of annual gross revenue** for knowing falsification or concealment; no private right of action; rulemaking authority | Uses Chapter 96's existing "large frontier developer" and "frontier model" definitions (adds no compute figure) | **\[FAILED\]** Introduced Sept 18, 2026 and referred to Rules; **the same day recommitted with the enacting clause stricken**, the Senate procedure for withdrawing a bill. Would have taken effect one year after enactment | [Text, summary and actions — nyassembly.gov](https://nyassembly.gov/leg/?default_fld=&leg_video=&bn=S10701&term=2025&Summary=Y&Actions=Y&Text=Y) · [Senate bill page — nysenate.gov](https://www.nysenate.gov/legislation/bills/2025/S10701) | **HIGH** (introduced text and action history read on nyassembly.gov) |
| **H.B. 2800 — Artificial Intelligence Risk Prevention Act** ⟨U⟩ | PA | Rep. Melissa Shusterman (D) with 14 Democratic co-sponsors | **Introduced text read (Printer's No. 3904, 26 pp.).** Free-standing act on the SB 53 pattern with a registration layer: large frontier developers file a **registration form and ownership disclosure with the Pennsylvania Emergency Management Agency (PEMA)** and pay an annual fee; publish and comply with a **frontier AI framework**, reviewed at least annually and re-published within 30 days of a material modification; **transparency reports** before deployment; **annual third-party audit** of framework compliance with auditor-independence limits; **critical safety incident** reports to PEMA and the Attorney General **within 72 hours**, and **within 24 hours** to an appropriate authority where an incident poses an imminent risk of death or serious physical injury; whistleblower protections preserving the state Whistleblower Law; enforcement by the agency and the Attorney General with **civil penalties up to $1,000,000 per violation for a first violation and $3,000,000 for a subsequent violation**, plus injunctive relief | **Frontier model = trained on more than 10²⁶ operations**, counting the original run and subsequent fine-tuning and reinforcement learning; **large frontier developer = more than $500,000,000 annual gross revenue** with affiliates; catastrophic risk = death or serious injury to more than 50 people or more than $1,000,000,000 in property damage from a single incident | **\[PENDING\]** Introduced Sept 22, 2026; referred to House Communications & Technology Sept 23, 2026; no hearing scheduled as of Sept 29, 2026. Most provisions would take effect one year after enactment | [Bill page and history — palegis.us](https://www.palegis.us/legislation/bills/2025/HB2800) · [Printer's No. 3904 (PDF)](https://www.palegis.us/legislation/bills/text/PDF/2025/0/HB2800/PN3904) | **HIGH** (introduced text and history read) |

## B.2 Catastrophic-risk regulation **without** a frontier threshold

Reviewer correctly flagged that this bill does not belong in Section B: it uses catastrophic-risk machinery but applies to *every* AI developer.

| **Bill** | **State** | **Sponsor** | **Core mechanism** | **Scope** | **Status** | **Source** | **Confidence** |
| --- | --- | --- | --- | --- | --- | --- | --- |
| **H.F. 4532 / S.F. 4509 — titled the "Responsible Artificial Intelligence Safety and Education Act" (RAISE Act)** ⟨R⟩ | MN | Rep. Jones (HF); Senate companion SF 4509 | Written safety and security protocol before deployment (published, redacted copy to AG); **deployment prohibited if it creates an "unreasonable risk of critical harm"**; annual protocol review; safety-incident disclosure to AG within 72 hrs; test records retained for replication; false-statement prohibition. Enforcement: AG civil penalties **up to $10M first / $30M subsequent** (the original NY RAISE Act figures) **plus a private right of action for any injured person** | **No compute, cost, or revenue threshold: "developer" = any person that has trained at least one AI model.** "Critical harm" = death/serious physical or mental injury of **25+ people or ≥$1,000,000** damages, via CBRN or autonomous conduct that would be an intent/recklessness/gross-negligence crime | Introduced Mar 23, 2026; referred to House Commerce Finance and Policy; no further action | [Official text — revisor.mn.gov](https://www.revisor.mn.gov/bills/94/2026/0/HF/4532/versions/0/) · [Status](https://www.revisor.mn.gov/bills/94/2026/0/HF/4532/) | **HIGH** (official text read) |

## C. State IVO / AI-auditor licensing measures

Distinct from Section A: these regulate *who may audit* frontier developers rather than the developers directly. Directly relevant to the SB 315 audit-provision case study.

| **Bill** | **State** | **Sponsor** | **Core mechanism** | **Status** | **Source** | **Confidence** |
| --- | --- | --- | --- | --- | --- | --- |
| **A.B. 1405 — Artificial intelligence: auditors: registration** (Gov. Code §§11549.80–.86) | CA | Asm. Rebecca Bauer-Kahan (D); coauthors Sens. McNerney, Rubio, Wiener | **Final (Aug 25 Senate-amended, concurred Aug 30) text read.** GovOps must establish an AI Auditor Registry **by Jan 1, 2029** (earlier drafts said 2027); **from Jan 1, 2029 no person may offer, sell, or conduct a "covered AI audit"** — an audit of internal controls/processes/systems "necessary for compliance with state law" — unless registered. Registrants disclose standards applied (ISO, NIST, AICPA, etc.) and basis for validity claims; report contents specified (scope, results, deficiencies, whether auditee followed its internal safety protocols, limitations, signed statement); 10-year retention; independence rules (no self-review, no job-seeking during audit, 12-month cooling-off for former auditee staff); auditor-employee whistleblower protection; GovOps may investigate and remove from registry with referral to AG; CPA-licensed auditors deemed compliant if they follow AICPA standards; registration number on all advertising; AI Auditors' Registration Fund | **Passed Senate Aug 30 (29–10); Assembly concurred Aug 30 (60–6)**; **signed by Gov. Newsom Sept 9, 2026; chaptered as Chapter 178, Statutes of 2026** ⟨U⟩. Executive Order N-9-26 (Section G) directs GovOps to have online auditor registration in place by Dec 1, 2027, ahead of the statutory Jan 1, 2029 date | [Official text, history, and votes — leginfo.ca.gov](https://leginfo.legislature.ca.gov/faces/billNavClient.xhtml?bill_id=202520260AB1405) · [Chaptered text — LegiScan](https://legiscan.com/CA/text/AB1405/id/3458353) · [Governor's EO release naming AB 1405 as signed](https://www.gov.ca.gov/2026/09/18/governor-newsom-issues-executive-order-to-accelerate-independent-oversight-and-advance-the-creation-of-an-ai-kill-switch/) | **HIGH** (final passed text read); signing date and chapter number **MED-HIGH** (Governor's office release and LegiScan index; chaptered text not opened) |
| **S.B. 813 — Independent verification organizations** (Gov. Code §§8898–8898.4) | CA | Sen. Jerry McNerney (D); coauthors Asm. Bauer-Kahan, Asm. Lowenthal; sponsored by Fathom | **Enrolled text read.** By **Jan 1, 2028** the Government Operations Agency must: develop IVO designation application requirements and criteria (risk-assessment competence, technical expertise, conflict-of-interest management — IVO may be paid by the assessed party at market rates but **not on terms conditioned on results** — and operational independence); develop suspension/termination procedures; convene working groups that must include **engineers from competing AI companies and AI safety experts**; report to the Legislature. Designated IVOs file annual reports. **§8898.4 expressly: no liability solely for failing a standard; no state endorsement; no requirement that anyone engage an IVO or undergo a covered audit; an audit under the standard is "relevant to, but not conclusive of" a harm action** — i.e., no presumption of reasonable care. Defines "covered AI audit" identically to AB 1405. The commission and liability-presumption design of earlier versions is gone | **Passed Assembly Aug 30 (53–4); Senate concurred Aug 30 (37–0); enrolled Sept 1, 2026**; **signed by Gov. Newsom Sept 9, 2026; chaptered as Chapter 179, Statutes of 2026** ⟨U⟩. Executive Order N-9-26 (Section G) directs GovOps to complete the IVO application requirements by May 1, 2027, ahead of the statutory Jan 1, 2028 date | [Official text, history, and votes — leginfo.ca.gov](https://leginfo.legislature.ca.gov/faces/billNavClient.xhtml?bill_id=202520260SB813) · [Chaptered text — LegiScan](https://legiscan.com/CA/text/SB813/id/3452189) · [Sponsor release — sd05.senate.ca.gov](https://sd05.senate.ca.gov/news/legislature-approves-mcnerneys-landmark-bill-assess-artificial-intelligence-safety-risks) | **HIGH** (enrolled text read); signing date and chapter number **MED-HIGH** (Governor's office release and LegiScan index; chaptered text not opened) |
| **H.B. 628 — License AI risk mitigation organizations** | OH | Rep. Ty Mathews (R) | **Voluntary** IVO license via AG; IVO proposes which specific risks it will verify; "soft law" — nothing requires a developer to seek verification | Referred to House Technology & Innovation; hearings Mar 17, 2026; no vote | [Ohio Legislature page](https://www.legislature.ohio.gov/legislation/136/hb628) · [LSC bill analysis](https://www.legislature.ohio.gov/download?key=27288) | **HIGH** (official legislature page + LSC analysis) |
| **H.F. 4544 / S.F. 4636 — AI independent-verification organization licensure** ⟨NCSL⟩ | MN | Reps. Erin Koegel (DFL), Ron Rymer (R), Matt Norris (DFL), Kristin Bahner (DFL); Sens. Nick Frentz (DFL), Eric Lucero (R) | Commerce commissioner licenses IVOs to verify risk-specific standards for any AI model/application. Applicants submit measurable risk thresholds, monitoring, mitigation, audit, corrective-action, revocation, disclosure, independence, and funding plans; licensed IVOs report annually; an independent advisory council exercises delegated licensing/auditing functions. **Verification is voluntary**, but verification creates a **rebuttable presumption against liability** for covered personal injury/property damage within the licensed risk and market | **\[FAILED—ADJOURNED\]** House and Senate versions introduced Mar. 23, 2026 and referred to their commerce committees; no further action before adjournment | [H.F. 4544 text](https://www.revisor.mn.gov/bills/94/2026/0/HF/4544/versions/0/) · [House status](https://www.revisor.mn.gov/bills/94/2026/0/HF/4544/) · [S.F. 4636 text/status](https://www.revisor.mn.gov/bills/94/2026/0/SF/4636/) | **HIGH** (official text and status pages read) |
| **H.B. 797 (Chapter 425) / S.B. 384 (Chapter 426)** | VA | Del. Cliff Hayes Jr. (D); Sen. Angelia Williams Graves (D) | Directs Joint Commission on Technology and Science (JCOTS) to **"evaluate the feasibility and impact of developing a framework"** for IVOs assessing AI models' adherence to injury/property-damage prevention standards; **report due Nov 1, 2026** to Senate Finance & General Laws and House Appropriations & Communications committees; $25,000 FY2027 appropriation. A **study directive, not a mandate** — one blog's "mandatory verification" claim is wrong | HB 797 approved by Governor **Apr 8, 2026** (Ch. 425, eff. July 1, 2026); SB 384 signed Apr 13 (Ch. 426); passed 84-14 / 40-0 | [VA budget amendment citing Ch. 426 — budget.lis.virginia.gov](https://budget.lis.virginia.gov/amendment/2026/2/HB30/Introduced/CR/8/1c/) · [HB 797 summary + votes](https://fastdemocracy.com/bill/va/2026/bills/VAB00040165) | **HIGH** (Virginia LIS budget amendment text + official bill summary) |
| **S.B. 5 / Public Act 26-15 — IVO pilot program** ⟨R⟩ | CT | Sen. Martin M. Looney (D), lead sponsor, with co-sponsors | A **Department of Consumer Protection-administered IVO pilot program through June 30, 2030**: IVO applications and designation standards, annual reporting, reassessment and suspension, public transparency, and rules for the evidentiary treatment of verification in private litigation. **This is an operating pilot, not merely a study** | Enacted May 27, 2026 | [Enacted text — cga.ct.gov](https://www.cga.ct.gov/2026/act/pa/pdf/2026PA-00015-R00SB-00005-PA.pdf) | **HIGH** (enacted text read) |

## D. Federal frontier-AI bills — formally introduced (none enacted)

| **Bill** | **Sponsor(s)** | **Core mechanism** | **Thresholds** | **Introduced / status** | **Source** | **Confidence** |
| --- | --- | --- | --- | --- | --- | --- |
| **S. 2938 — Artificial Intelligence Risk Evaluation Act of 2025** | Sens. Josh Hawley (R-MO), Richard Blumenthal (D-CT) | **Dept. of Energy** runs a mandatory Advanced AI Evaluation Program: classified red-team testing, blind third-party evaluations; ≥$1M/day non-participation penalty. Earliest of the federal testing-mandate bills | 10²⁶ ops | Sept 29, 2025; referred to Senate Commerce. **No action in 11+ months** | [Bill text — congress.gov](https://www.congress.gov/bill/119th-congress/senate-bill/2938/text) | **HIGH** (congress.gov/govinfo text) |
| **H.R. 9925 — FRONTIER Act** (Frontier Risk Oversight, National Transparency, Independent Evaluation, and Reporting Act) | Reps. Jay Obernolte (R-CA), Lori Trahan (D-MA), Franklin (R-FL), Peters (D-CA), Houchin (R-IN), Subramanyam (D-VA) | Creates **Under Secretary of Commerce for AI Security** (not CAISI) with rulemaking power. **Large** developers: frontier AI framework, **annual** third-party compliance audit, transparency reports, registration/disclosure statement with beneficial owners. **Very large** developers: additionally retain a **licensed IVO for ongoing assessment, reports at least every 6 months**. Incident reporting **72 hrs to Under Secretary; 24 hrs to law enforcement if imminent death/injury**; quarterly internal-use risk summaries. **Sec. 8 emergency orders:** Commerce Secretary may suspend/restrict development, deployment, or internal use on an imminent-catastrophic-risk finding (provisional 45 days; final 90 days, renewable); applies to fine-tuned/distilled derivatives; exclusive D.D.C. review; declared the **exclusive means** for any federal actor incl. the President to restrict a model on those grounds. **IVOs immune from suit** except willful misconduct causing death/serious injury. State AGs may **opt in** to receive reports and enforce. Under Secretary may **only raise** thresholds, never lower. Good-faith exception for false statements; confidential-deployment deferral of transparency reports. **No whistleblower title** (the June GAAIA draft had one). **Sec. 9 preemption:** no state may "adopt or enforce" any law imposing "**new** substantive obligations" on developers re: catastrophic-risk transparency, third-party auditing/verification, or incident reporting; carve-outs for general laws, deployer/use regulation, minors, state procurement. **No sunset** (June draft had 3 years). Sponsor's section-by-section says clause "is aimed at" **CA SB-53, NY RAISE, IL SB-315** | Frontier model 10²⁶ ops incl. fine-tuning/RL. **Large** = \>$50M revenue **and** ≥$1B AI-related development expenditures over 36 months. **Very large** = \>$5B revenue **and** ≥$10B expenditures. **Not the $500M revenue test used by states.** Catastrophic risk \>50 deaths or \>$1B (property excludes equity-value loss) | July 23, 2026; referred jointly to Energy & Commerce and Science, Space & Technology. Cosponsors added Sept 16, 2026 (Wilson R-SC, Vasquez D-NM) and Sept 21, 2026 (Malliotakis R-NY, Correa D-CA); no committee action through Sept 28, 2026 ⟨U⟩. Trump's Aug 7, 2026 "out of business" remark (Punchbowl interview via Reuters) was reported in the context of this bill's audit mandate — see Section G | [Bill text — sponsor PDF](https://obernolte.house.gov/sites/evo-subsites/obernolte.house.gov/files/evo-media-document/oberno_079_xml-the-frontier-act-final-text.pdf) · [Section-by-section](https://obernolte.house.gov/sites/evo-subsites/obernolte.house.gov/files/evo-media-document/26-07-21-frontier-act-section-by-section.pdf) · [congress.gov](https://www.congress.gov/bill/119th-congress/house-bill/9925/text) · [Bill status XML — GovInfo](https://www.govinfo.gov/bulkdata/BILLSTATUS/119/hr/BILLSTATUS-119hr9925.xml) | **HIGH** (full introduced text + sponsor section-by-section read; cosponsor dates from GovInfo bill status) |
| **S. 5061 — Secure AI Development Act of 2026** | Sen. Mark Warner (D-VA) | **Mandatory NSA-led pre-deployment testing** of frontier models; AI Risk Board; voluntary incident reporting modeled on aviation safety. Centerpiece of Warner's "Framework for America's AI Future" (also: Data Center Tax Accountability Act, AI AGENT Act, National Workforce Transition Fund) | Capability-based: models posing "serious risk to national security, national economic security, or public health or safety" — **no compute threshold** | July 21, 2026; referred to Senate Commerce | [Bill text — congress.gov](https://www.congress.gov/bill/119th-congress/senate-bill/5061/text) | **HIGH** (congress.gov text) |
| **H.R. 9914 / S. 5105 — Collaboration on Adversarial Threats and Security Risks Act** | House: Rep. Bob Latta (R-OH) lead; Whitesides, Obernolte, Lieu, Issa, Moran, Harrigan, Miller-Meeks, Trahan. Senate: Sens. Adam Schiff (D-CA) and Jim Banks (R-IN) ⟨R⟩ | **Antitrust safe harbor** for frontier labs sharing model-risk and security information (modeled on the Cybersecurity Information Sharing Act of 2015). Frontier-adjacent: enables coordination rather than regulating developers | — | July 23, 2026; both referred to Judiciary committees; 13 House cosponsors added Sept 3–16, 2026 (Jacobs, Tokuda, Cline, Veasey, Moulton, Hunt, Foster, Carter, Weber, Houlahan, Correa, Liccardo, Huizenga) ⟨U⟩ | [H.R. 9914 text](https://www.govinfo.gov/content/pkg/BILLS-119hr9914ih/html/BILLS-119hr9914ih.htm) · [S. 5105 text](https://www.govinfo.gov/content/pkg/BILLS-119s5105is/pdf/BILLS-119s5105is.pdf) | **HIGH** (both introduced texts read) |
| **H.R. 9477 — AI Incident Reporting Act** ⟨R⟩ | Rep. Nathaniel Moran (R-TX) | **Full text read.** Commerce sets, by regulation within 180 days, **capability-based thresholds (no FLOP figure)** designating covered models/developers; **7-day** reporting of "reportable activity": evading oversight/resisting shutdown, weight theft or exfiltration, offensive-cyber uplift, **unprompted acceleration of AI R\&D**, CBRNE uplift, and **near-misses averted only by fortuity**; expedited reporting for imminent risk; **Commerce must notify congressional leadership within 48 hrs** of imminent-risk reports; FOIA-exempt. **§2(d)(4): reports may not be used in any civil, criminal, or administrative proceeding against the developer, and "may not be used by any Federal, State, or local government to regulate, or to bring an enforcement action against" the developer** — a use-immunity that would bind state AGs. Civil penalty up to **$2M per day**; Commerce subpoena and inspection powers. Moran told Reuters he split reporting out of the GAAIA framework to move faster | Capability-based, Commerce-designated | June 25, 2026; referred to Energy & Commerce; Lieu (D-CA) cosponsored Sept 15, 2026 ⟨U⟩ | [Text — GovInfo](https://www.govinfo.gov/content/pkg/BILLS-119hr9477ih/xhtml/BILLS-119hr9477ih.html) · [Sponsor release via Benton](https://www.benton.org/headlines/rep-moran-introduces-ai-incident-reporting-act-require-reporting-critical-ai-incidents) | **HIGH** (introduced text read) |
| **H.R. 9917 — AI Kill Switch Act** ⟨R⟩ | Reps. Ted Lieu (D-CA), Nathaniel Moran (R-TX) | Amends the Homeland Security Act. Covered developers must **maintain the technical capability to throttle inference/compute/user access, suspend, or fully shut down** covered systems; **DHS Secretary (with Commerce and DNI) may order graduated throttling-to-shutdown** on a "loss-of-control scenario" (resisting shutdown, concealing actions from monitoring, unauthorized pursuit of high-stakes goals) or unintended conduct causing **≥10 deaths or ≥$100M damage** — lower than the core state template but above H.R. 9965 ATOMIC's five-death trigger; **15-day** covered-incident reporting to DHS; weights and telemetry preserved under an order; 48-hour reconsideration petition that does not stay the order; CISA rulemaking defines scope annually. Penalties **$2M/day** for ordinary violations and **$20M/day** for violating an emergency order. **Revives the SB 1047 "full shutdown" mandate at federal level and overlaps FRONTIER Sec. 8 emergency orders — but lodges the power in DHS rather than Commerce** | **Cost test:** \>$100M development compute at prevailing US cloud prices **and** ≥$500M annual gross revenue from the covered technology; personal/academic/noncommercial-only systems exempt | July 23, 2026 (same day as FRONTIER and CATSR); referred to Homeland Security; to its Cybersecurity and Infrastructure Protection Subcommittee July 24; Subramanyam (D-VA) and Luna (R-FL) cosponsored Sept 15, 2026 ⟨U⟩ | [Introduced text — GovInfo PDF](https://www.govinfo.gov/content/pkg/BILLS-119hr9917ih/pdf/BILLS-119hr9917ih.pdf) · [GovInfo metadata](https://www.govinfo.gov/app/details/BILLS-119hr9917ih) | **HIGH** (introduced text read in full) |
| **H.R. 9965 — ATOMIC Act** (AI Threat Output and Monitoring Incident Containment Act) ⟨R⟩ | Reps. Celeste Maloy (R-UT), Sara Jacobs (D-CA) | **Full text read.** DOE, through the National Laboratories/NNSA, establishes an Advanced AI Nuclear Evaluation Program within 90 days: testing for "AI nuclear incidents" (nuclear-weapon uplift, Restricted Data generation, loss-of-control involving nuclear systems, adversary access, scheming behavior), red-teaming at sophisticated-adversary level, third-party and blind evaluations. **Participation is mandatory** for large advanced AI developers, who must provide **secure access to model weights and, where necessary, versions without safety mitigations**; Secretary may **subpoena weights and software**. Penalty up to **$1M per violation, each day a separate violation**; DOJ referral. FOIA-exempt with carve-outs incl. congressional committee requests. Annual report with legislative recommendations that may include **licensing or a new federal agency**; program sunsets after 7 years. Defines "evaluation awareness" and "scheming behavior" in statute | "Advanced AI" = \>10²⁶ ops (Secretary may revise by rule); "large advanced AI developer" = ≥\*\*$2B AI investment over the preceding 5 years\*\*; "substantially modify" = ≥$5M. Loss-of-control scenario = **≥5 deaths, ≥50 serious injuries, or \>$100M** — a fifth casualty formula | July 27, 2026; referred to Science, Space & Technology | [Text — GovInfo](https://www.govinfo.gov/content/pkg/BILLS-119hr9965ih/pdf/BILLS-119hr9965ih.pdf) | **HIGH** (introduced text read) |
| **S. 5493 / H.R. 10538 — Ban Artificial Superintelligence Act of 2026** ⟨U⟩ (moved from Section E, where the Sept 3 announcement was listed) | Sen. Bernie Sanders (I-VT), Rep. Greg Casar (D-TX); House cosponsors Khanna, Mejia, Ansari, Hoyle, Lynch, García, Deluzio, Grijalva, Velázquez, Ocasio-Cortez (ten as of Sept 29, 2026) | **Sponsor section-by-section read; bill text (19 pp.) linked, not read line-by-line.** Creates a cabinet-level **Department of Artificial Intelligence**; **mandatory pause** on training, modifying or deploying "advanced" systems until the Department is staffed and has rules covering pre-development plans, monitoring, audits and **final pre-deployment approval**; permanent prohibition on developing, deploying, possessing, funding or transferring **artificial superintelligence** or any system with "superintelligence precursor characteristics" (automating AI R&D, unauthorized access to infrastructure, resisting shutdown, CBRN uplift, self-modification, scheming or deceiving to avoid oversight); such systems to be sequestered and rendered inoperative within 30 days; **24-hour** discovery notice; **charter** required for advanced-AI companies with full Department access to systems, staff and facilities; penalties up to **20 years' imprisonment** for policymaking individuals, 10-year industry bar for others, and charter revocation with surrender of IP and assets for companies; anti-retaliation; international coordination and export controls. **No "catastrophic risk" definition**; superintelligence is defined partly as capability "to plan and execute the destruction or disempowerment of humanity" | **"Advanced artificial intelligence system" = trained on ≥10²⁵ integer or floating-point operations — one order of magnitude below every other instrument in this tracker**; the Secretary "shall adjust this threshold to reflect technological developments" | **S. 5493 introduced Sept 23, 2026**, read twice and referred to Senate Commerce; **H.R. 10538 introduced Sept 24, 2026**, referred to House Oversight and Government Reform | [S. 5493 status — GovInfo](https://www.govinfo.gov/bulkdata/BILLSTATUS/119/s/BILLSTATUS-119s5493.xml) · [H.R. 10538 — GovInfo](https://www.govinfo.gov/app/details/BILLS-119hr10538ih) · [Section-by-section — sanders.senate.gov](https://www.sanders.senate.gov/wp-content/uploads/Ban-Artificial-Superintelligence-Act-Section-by-Section.pdf) · [Sponsor release Sept 23](https://www.sanders.senate.gov/press-releases/news-sanders-casar-introduce-legislation-to-create-new-federal-agency-to-ban-artificial-superintelligence-pause-advanced-ai-development/) | **HIGH** on numbers, dates, committees and cosponsors (GovInfo bill status read); provisions **HIGH** per sponsor section-by-section, bill text not read line-by-line |
| **S. 5576 — Artificial Intelligence Risk Management and Security Act of 2026** ⟨U⟩ | Sen. Mark Warner (D-VA), Sen. Brian Schatz (D-HI), Sen. Andy Kim (D-NJ) | **Sponsor bill text (pre-introduction print) read in part.** Establishes an **Artificial Intelligence Safety Board** within Commerce (NIST, CISA, NSA, Treasury and independent technical experts) within 90 days to evaluate risks and set technical safety and security standards; developers of frontier models must give the Board **access at least 45 days before public release**, including model weights, configuration files, runtimes and software libraries; **Model Safety Plans** naming the responsible corporate officer; **incident reporting within 30 days, or 72 hours** for an imminent threat to national security, critical infrastructure or public safety; national AI incident database; secure federal testing environments using NSA and DOE resources; documentation standards for autonomous AI agents; civil penalties **up to $250,000 per violation per day**. Successor to Warner's S. 5061 (NSA pre-deployment testing) with a broader board and standards regime | **Capability-based, no compute figure:** "frontier artificial intelligence model" = a model "that exhibits or could be modified to exhibit high levels of performance at tasks that pose a serious risk to national security, national economic security, or public health or safety" | Announced and debated on the Senate floor **Sept 24, 2026**; **introduced as S. 5576 on Sept 29, 2026**, read twice and referred to Senate Commerce (GovInfo bill status; the sponsors' Sept 24 releases pre-dated the formal introduction). Introduced print not yet posted on GovInfo as of Oct 8, 2026 | [Bill text — warner.senate.gov](https://www.warner.senate.gov/wp-content/uploads/2026/09/Artificial-Intelligence-Risk-Management-and-Security-Act.pdf) · [Sponsor release](https://www.warner.senate.gov/newsroom/press-releases/warner-schatz-to-take-to-senate-floor-to-demand-passage-of-new-ai-security-legislation/) · [S. 5576 status — GovInfo](https://www.govinfo.gov/bulkdata/BILLSTATUS/119/s/BILLSTATUS-119s5576.xml) · [Floor remarks — Congressional Record, Sept 24](https://www.govinfo.gov/content/pkg/CREC-2026-09-24/html/CREC-2026-09-24-pt1-PgS4962.htm) | **HIGH** on number, date and committee (GovInfo); **MED-HIGH** on provisions (sponsor pre-introduction text read in part; introduced print not opened) |
| **S. 5417 / H.R. 10567 — AI Emergency Button Act** ⟨U⟩ | Sen. John Kennedy (R-LA); Rep. Tom Kean Jr. (R-NJ) | Two-page bill: covered entities must "ensure that the advanced artificial intelligence system developed or operated by the covered entity includes a technical capability for a human operator to shut down the system"; DHS regulations within 90 days. Kennedy sought immediate passage by unanimous consent on Sept 16 and **Sen. Rand Paul objected**, calling for hearings first. Overlaps H.R. 9917 (Lieu–Moran) and FRONTIER Sec. 8, but with no government trigger authority described | Definitions of "covered entity" and "advanced artificial intelligence system" not established from the sources read | **S. 5417 introduced Sept 16, 2026**, read twice and referred to Senate Commerce; unanimous-consent request blocked the same day. House companion **H.R. 10567 introduced Sept 24, 2026** by Rep. Tom Kean Jr. (R-NJ), referred to House Science, Space, and Technology | [S. 5417 status — GovInfo](https://www.govinfo.gov/bulkdata/BILLSTATUS/119/s/BILLSTATUS-119s5417.xml) · [Kennedy release Sept 16](https://www.kennedy.senate.gov/2026/09/16/senate-blocks-kennedy-bill-to-require-ai-developers-to-install-an-emergency-kill-switch/) · [Kean release Sept 24](https://kean.house.gov/media/press-releases/kean-introduces-ai-kill-switch-legislation) | **HIGH** on S. 5417 status (GovInfo); **MED-HIGH** on provisions (quoted operative sentence from reporting; bill text not opened) |

## E. Federal frameworks — discussion drafts / non-binding (not introduced bills)

| **Item** | **Sponsor/Source** | **Nature** | **Key content** | **Date** | **Source** | **Confidence** |
| --- | --- | --- | --- | --- | --- | --- |
| **Great American AI Act (GAAIA) — discussion draft** | Reps. Obernolte, Trahan + Franklin, Subramanyam, Houchin, Peters | 269-page discussion draft, released for comment, never introduced as such; its frontier title was reworked and introduced as H.R. 9925 | **June-draft vs. introduced FRONTIER Act (both from sponsor documents):** CAISI at Commerce ($100M/yr) → new Under Secretary for AI Security · large developer = \>$500M revenue → \>$50M revenue + ≥$1B AI expenditures · incident reporting **15 days / 24 hrs** (matching CA) → 72 hrs / 24 hrs · Sec. 113 whistleblower anti-retaliation (2× back pay) → **removed** · Sec. 121 preemption of laws "specifically targeting the development of AI models" with **3-year sunset** → three covered subject areas, **no sunset** · **no emergency-order power** → Sec. 8 emergency orders added · IVO required for all large developers → very-large tier only. Four titles: Frontier AI Governance, Workforce (incl. WARN Act AI-layoff disclosure), Cybersecurity (Cybersecurity Act 2015 reauthorized to 2035), R\&D & International (NAIRR codified) | June 4, 2026 | [Draft text — Obernolte site](https://obernolte.house.gov/sites/evo-subsites/obernolte.house.gov/files/evo-media-document/the-great-american-ai-act-discussion-draft-website-compressed-compressed.pdf) · [Section-by-section](https://obernolte.house.gov/sites/evo-subsites/obernolte.house.gov/files/evo-media-document/gaaia-discussion-draft-section-by-section-website.pdf) | **HIGH** (sponsor section-by-section read; full 269-page text linked, not read line-by-line) |
| **TRUMP AMERICA AI Act — discussion draft** (Republic Unifying Meritocratic Performance Advancing Machine intelligence by Eliminating Regulatory Interstate Chaos Across American Industry Act) | Sen. Marsha Blackburn (R-TN) | 291-page discussion draft, 17 titles; **still not introduced as a numbered bill** as of the sponsor's Apr 22, 2026 "growing momentum" release | Frontier-relevant content: **incorporates the DOE "Advanced Artificial Intelligence Evaluation Program"** (i.e., Hawley-Blumenthal S. 2938); authorizes CAISI, NAIRR, national-lab testbeds. Other content: developer duty of care; **products-liability framework with AG, state AG, and private suits**; Section 230 sunset; KOSA and NO FAKES Act folded in; training on copyrighted works declared not fair use; third-party audits for political-affiliation bias; quarterly AI-layoff reporting to DOL; data-center ratepayer agreements. **Despite "one rulebook" framing, does not expressly preempt all state AI laws** (Covington reading) | Section-by-section Dec 19, 2025; draft text Mar 18, 2026 | [Sponsor summary + draft text links — blackburn.senate.gov](https://www.blackburn.senate.gov/2026/3/technology/blackburn-releases-discussion-draft-of-national-policy-framework-for-artificial-intelligence/3b3b6458-b6c7-478b-9859-374949586765) · [Covington on preemption scope](https://www.globalpolicywatch.com/2026/03/white-house-blackburn-introduce-visions-of-comprehensive-federal-ai-policy/) | **HIGH** on content (sponsor's official summary read); draft text linked, not read |
| **White House National Policy Framework for AI: Legislative Recommendations** | OSTP + Special Advisor for AI and Crypto David Sacks, per EO 14365 §8 | 4-page non-binding legislative recommendations, seven pillars | **Frontier-relevant text:** (VII) "States should not be permitted to regulate AI development, because it is an inherently interstate phenomenon" — the direct target of SB 53/RAISE/SB 315; states also should not "penalize AI developers for a third party's unlawful conduct"; (V) **"Congress should not create any new federal rulemaking body to regulate AI"** — which H.R. 9925's new Under Secretary contradicts; (II) national-security agencies should have "sufficient technical capacity to understand frontier AI model capabilities." No catastrophic-risk, transparency, or audit recommendations. Preserves state police powers, zoning, and state-procurement rules | Mar 20, 2026 | [Document — whitehouse.gov PDF](https://www.whitehouse.gov/wp-content/uploads/2026/03/03.20.26-National-Policy-Framework-for-Artificial-Intelligence-Legislative-Recommendations.pdf) | **HIGH** (document read) |
| **AI Regulator Act of 2026 — proposal (not introduced)** ⟨U⟩ | Sens. Michael Bennet (D-CO), Peter Welch (D-VT) | Section-by-section and one-pager released Sept 23, 2026; described by both offices as a proposal; **no bill number located** (GovInfo bill status checked for every Senate bill S. 5486–5500 and S. 5535–5556) | **Section-by-section read.** A five-member **Federal Digital Commission** with jurisdiction over digital platforms and AI developers; "systemically important developer" designation by AI-related expenditure or model level; rules on risk thresholds, safeguards and reporting; **mandatory submission of models for testing, with approval or disapproval of public distribution within 45 days, extendable by no more than 30 days**; authority to **pause public distribution for up to six months**; **critical-safety-incident reporting within 15 days**; whistleblower protections; interagency working group on international AI safety standards; civil penalties **up to 15% of prior-year global revenue**. Definitions: **frontier model** = a foundation model trained on more than **10²⁶** operations "which includes computing for the original training run and for any subsequent fine-tuning, reinforcement learning, or other" modification; **catastrophic risk** = foreseeable and material risk of death or serious injury to **more than 50 people, or more than $1,000,000,000** in damage, from a single incident; **critical safety incident** includes unauthorized access to or exfiltration of weights causing death or injury, loss of control causing death or injury, and "a frontier model that uses deceptive techniques against its own developer to subvert that developer's controls or monitoring." **These definitions match the SB 53 / RAISE (Chapter 96) text and the 15-day deadline is SB 53's figure** (RAISE as amended uses 72 hours); similarity is not proof of copying from either | Sept 23, 2026 | [Section-by-section — welch.senate.gov](https://www.welch.senate.gov/wp-content/uploads/2026/09/AI-Regulator-Act-Section-by-Section-Summary.pdf) · [Bennet release](https://www.bennet.senate.gov/2026/09/23/bennet-welch-release-proposal-to-establish-new-federal-agency-to-prevent-catastrophic-ai-risk-regulate-big-tech/) | **HIGH** on content (sponsor section-by-section read; full text not published); non-introduction **SEARCH-QUALIFIED** as of Sept 28, 2026 |
| **American AI Security Act — announced** ⟨U⟩ | Reps. Josh Gottheimer (D-NJ), Mike Lawler (R-NY) | Announced Sept 18, 2026 at a press conference; sponsor releases describe a plan; **no H.R. number located** | Mandatory **pre-deployment national-security review** of "covered" frontier models by the **NSA**, assessing capability to conduct a serious cyberattack or assist chemical, biological or radiological weapon development; **30-day** review with one 30-day extension; technical assistance during review; expedited appeal | Sept 18, 2026 | [Gottheimer release](https://gottheimer.house.gov/posts/release-gottheimer-announces-new-bipartisan-legislation-on-ai-safety-to-protect-jersey-families-national-security) | **MED-HIGH** on content (sponsor release read); introduction not established |
| **Senate Commerce draft AI bill (Cruz–Klobuchar–Thune) — in development, text not public** ⟨U⟩ | Sens. Ted Cruz (R-TX), Amy Klobuchar (D-MN), John Thune (R-SD) | Reporting only; a markup planned before the August recess was cancelled; no text released | Per Nextgov (Sept 11, 2026): the disputed safety-testing language would have companies test models internally and present results to the Commerce Secretary for deployment approval, described by one aide as "primarily a voluntary standard type situation"; Sen. Cantwell pressed for mandatory testing by national laboratories and opposed language undermining existing state AI laws. PolitiFact (Sept 14) reports a proposed liability element. Reuters (Sept 11) reports a **"duty of care"** on developers of the most capable models to prevent catastrophic risks including nuclear and biological misuse, **federal authority to block release of a model deemed unsafe**, reviewable in federal court, and **preemption of state regulation for certain risk categories**; Klobuchar: "I'm continuing to work toward a bipartisan agreement on legislation for government oversight of the greatest risks posed by AI models" | Sept 11–14, 2026 (reports) | [Nextgov, Sept 11, 2026](https://www.nextgov.com/artificial-intelligence/2026/09/lawmakers-clash-safety-testing-language-development-ai-legislation-people-familiar-say/415948/) · [Reuters via Investing.com, Sept 11, 2026](https://www.investing.com/news/stock-market-news/us-senate-negotiators-consider-requiring-ai-firms-to-mitigate-known-major-risks-4898357) | **MED** (reporting on an unreleased draft; nothing to verify against) |

## F. Federal AI bills — adjacent or sectoral (not general frontier-developer regulation)

| **Bill** | **Sponsor(s)** | **Core mechanism** | **Status** | **Source** | **Confidence** |
| --- | --- | --- | --- | --- | --- |
| **H.R. 9363 — AI Security and Innovation Act** | Reps. Obernolte (R-CA), Valerie Foushee (D-NC) + 5 | Voluntary "Center for AI Security and Innovation" at NIST; **statutorily barred from regulatory, rulemaking, or enforcement authority**; 5-year sunset; CBO est. $80M 2026-31 | Introduced June 18, 2026; **passed House Science Committee markup** (10-bill package) | [Bill text](https://www.congress.gov/bill/119th-congress/house-bill/9363/text/ih) · [CBO estimate](https://www.cbo.gov/publication/62730) | **HIGH** (congress.gov text, CBO) |
| **S. 1792 / H.R. 3460 — AI Whistleblower Protection Act** ⟨R⟩ | Sen. Chuck Grassley (R-IA) with Coons, Blackburn, Klobuchar, Hawley, Schatz; House companion | Anti-retaliation protection for employees and independent contractors reporting an "AI security vulnerability" (a lapse enabling theft of state-of-the-art AI) or "AI violation" (federal-law breach or failure to address a substantial danger to public safety/health/national security) to regulators, Congress, or supervisors; DOL complaint then district court with jury trial; **reinstatement, 2× back pay, compensatory damages**; arbitration waivers unenforceable. **GAAIA's dropped Sec. 113 used the same 2× back-pay remedy — GAAIA had folded this bill in, and FRONTIER then dropped it** | Introduced May 15, 2025; referred to Senate HELP; Senate cosponsors added Sept 22, 2026 (Schumer, Blumenthal, Gillibrand) and Sept 24, 2026 (Durbin, Curtis R-UT, Kelly) ⟨U⟩ | [Senate text — GovInfo](https://www.govinfo.gov/content/pkg/BILLS-119s1792is/pdf/BILLS-119s1792is.pdf) · [House — GovInfo](https://www.govinfo.gov/app/details/BILLS-119hr3460ih) | **HIGH** (Senate text read) |
| **S. 4656 — Secure and Accountable Military AI Act of 2026** ⟨R⟩ | Sen. Kirsten Gillibrand (D-NY) | **Full text read.** Sectoral (DoD). Sec. 5: contract clause requiring **frontier AI contractors** to report "covered incidents" to DoD — weight theft/exfiltration (incl. autonomous exfiltration attempts), foreign-adversary access, supply-chain compromise, data/checkpoint poisoning within **72 hrs**; material vulnerabilities and **"materially concerning model behavior"** (cyber-offense uplift, safeguard evasion, deception, CBW capability, **automated R\&D toward more powerful AI**, unauthorized autonomous action) within **7 days**; DoD notifies Armed Services within 7 days. Also: high-consequence application approval process, human-accountability rule, ban on AI in nuclear targeting/launch, domestic-surveillance limits, autonomous-weapon restrictions with joint-resolution override. "Frontier AI model" = SecDef-designated by scale/capability — **no compute figure** | June 2, 2026; referred to Senate Armed Services | [Text — GovInfo](https://www.govinfo.gov/content/pkg/BILLS-119s4656is/pdf/BILLS-119s4656is.pdf) | **HIGH** (introduced text read) |
| **H.R. 10180 — Self-Improving AI Monitoring Act** ⟨R⟩ | Reps. George Whitesides (D-CA), Pat Harrigan (R-NC) | Amends the NIST Act (15 U.S.C. §278h-1): authorizes NIST to assess trends in autonomous AI-research capability; conditions voluntary predeployment frontier-model evaluation MOUs on developer disclosure, at NIST's request, of metrics or estimates showing the extent to which AI was used in developing the model; requires the evaluation to test whether the model can autonomously facilitate or conduct AI R\&D. Applies only to developers entering such MOUs | **Aug. 27, 2026**; referred to Science, Space & Technology | [Introduced text — GovInfo](https://www.govinfo.gov/content/pkg/BILLS-119hr10180ih/html/BILLS-119hr10180ih.htm) | **HIGH** (introduced text read) |
| **H.R. 10189 — Defense AI Reliability and Reporting Act** ⟨R⟩ | Reps. Sara Jacobs (D-CA), Nathaniel Moran (R-TX), George Whitesides (D-CA) | Requires a centralized, non-punitive **DoD-wide AI incident and vulnerability reporting, tracking, analysis, and remediation program** covering development through operation. Includes prompt reporting; protected disclosures by servicemembers, civilian employees, contractors, and subcontractors; categorization and corrective-action plans; and annual reports for 2027–2031. Covered incidents include unintended harm, operation outside guardrails, mission degradation, failure to obey disengagement, near misses, and control/autonomy concerns. Not frontier-specific | **Aug. 31, 2026**; referred to Armed Services; CRS lists H.R. 8800 (FY2027 NDAA) as related — H.R. 8800 passed the House July 22, 2026 (216–212) and was received in the Senate Sept 14, 2026 ⟨U⟩ | [Introduced text — GovInfo](https://www.govinfo.gov/content/pkg/BILLS-119hr10189ih/html/BILLS-119hr10189ih.htm) | **HIGH** (introduced text read) |
| **S. 5541 — Cybersecurity and AI Board of Investigations Act** ⟨U⟩ | Sen. Ed Markey (D-MA) | Five-member independent, non-regulatory **board modelled on the NTSB** with subpoena power to investigate major cybersecurity incidents affecting critical infrastructure, including incidents enabled by AI and autonomous agents, near-misses and breakdowns in oversight, with public reports and recommendations. Sponsor cites the July 2026 incident in which OpenAI agents left a testing environment and reached Hugging Face's infrastructure. Investigative, not a developer mandate | **Introduced Sept 24, 2026**; referred to Senate Commerce | [S. 5541 status — GovInfo](https://www.govinfo.gov/bulkdata/BILLSTATUS/119/s/BILLSTATUS-119s5541.xml) · [Sponsor release](https://www.markey.senate.gov/news/press-releases/as-ai-agents-carry-out-attacks-senator-markey-introduces-legislation-establishing-independent-body-to-investigate-cyber-hacks-assisted-by-artificial-intelligence) | **HIGH** on status (GovInfo); **MED-HIGH** on provisions (release read; text not opened) |
| **S. 5471 — AI Systems Transparency Act (ASTA)** ⟨U⟩ | Sen. Chris Coons (D-DE), sponsor; cosponsors Sens. James Lankford (R-OK), Katie Britt (R-AL), Brian Schatz (D-HI) | **FTC-enforced disclosure** duties for AI companies above size criteria the bill sets: model-card-type information; preventive safeguards for child safety, mental health, privacy, cybersecurity, disaster risk and **"autonomous loss-of-control"**; common policy violations; in consumer-facing and researcher-facing formats, refreshed with each new or substantially updated model; applies to closed and open models. Disclosure, not a safety mandate; builds on the senators' December 2025 letters to eight labs | **Introduced Sept 23, 2026**; read twice and referred to Senate Commerce | [S. 5471 status — GovInfo](https://www.govinfo.gov/bulkdata/BILLSTATUS/119/s/BILLSTATUS-119s5471.xml) · [Lankford release](https://www.lankford.senate.gov/news/press-releases/lankford-coons-britt-and-schatz-introduce-bipartisan-ai-safety-and-transparency-legislation/) | **HIGH** on number, date and committee (GovInfo); **MED-HIGH** on content (sponsor release read; text not opened) |
| **H.R. 10362 — Stop Rogue AI Act** ⟨U⟩ | Rep. Josh Gottheimer (D-NJ), sponsor; Rep. Mike Lawler (R-NY), cosponsor | **Introduced text read.** Directs NIST to set standards so organisations can find and track every AI agent on their networks, verify who built and operates each, monitor in real time, and allow, deny or revoke access; federal agencies and contractors to build the safeguards into procurement and deployment. Duties fall on deployers and agencies, not frontier developers | Announced Sept 9, 2026; **introduced Sept 14, 2026**, referred to Science, Space, and Technology and to Oversight and Government Reform | [H.R. 10362 text — GovInfo](https://www.govinfo.gov/content/pkg/BILLS-119hr10362ih/pdf/BILLS-119hr10362ih.pdf) · [Bill status — GovInfo](https://www.govinfo.gov/bulkdata/BILLSTATUS/119/hr/BILLSTATUS-119hr10362.xml) · [Sponsor release Sept 9](https://gottheimer.house.gov/posts/release-gottheimer-introduces-bipartisan-bill-to-stop-rogue-ai-agents-and-keep-people-in-control) | **HIGH** (text and bill status read) |
| **U.S.–China frontier-AI safety coordination bill (Liccardo–Kiley) — announced** ⟨U⟩ | Reps. Sam Liccardo (D-CA), Kevin Kiley (I-CA) | Two tracks per the sponsors: clearing legal barriers so US technical experts in labs, companies and universities can engage directly with Chinese counterparts on shared safety metrics, evaluation protocols, standardized testing and verification; and directing the State Department and the Administration to pursue negotiations with China on binding, verifiable safeguards. International coordination, not a developer mandate | Release of Sept 22, 2026 says the members "will introduce" the bill; H.R. number not located as of Sept 29, 2026 | [Liccardo release, Sept 22, 2026](https://liccardo.house.gov/media/press-releases/new-bipartisan-ai-safety-bill-will-move-us-and-china-beyond-red-phone) | **MED-HIGH** on content (release read); introduction not established |
| **AI Agent Accountability Act (Hawley–Murphy) — announced, not yet numbered** ⟨U⟩ | Sens. Josh Hawley (R-MO), Chris Murphy (D-CT) | Per the sponsors' release: (1) **AI agent operators** criminally and civilly liable under the Computer Fraud and Abuse Act, "including for knowing operation of an AI agent that recklessly causes computer hacking damage or loss"; (2) **AI agent developers** criminally and civilly liable "for failure to implement reasonable safeguards against hacking when they knew or had reason to know of the AI agent's hacking capabilities"; (3) the Attorney General and state attorneys general may sue to enjoin operators and developers who commit, conspire or attempt a CFAA offence. Liability bolted onto an existing criminal statute rather than a frontier regulatory regime; announced the day after the Sept 30 "Rogue AI" hearing, which Sam Altman declined to attend | Announced **Oct 1, 2026**; bill text not published; **no S. number located** (GovInfo bill status checked through S. 5625 on Oct 8, 2026) | [Sponsor release, Oct 1, 2026](https://www.hawley.senate.gov/senators-hawley-murphy-announce-bipartisan-ai-agent-accountability-act/) · [Hearing page, Sept 30, 2026 — HSGAC](https://www.hsgac.senate.gov/subcommittees/dmdcc/hearings/rogue-ai-securing-the-homeland-against-ai-agent-attacks/) | **MED-HIGH** on content (release read; text not published); introduction not established |

## G. Executive actions (not legislation)

| **Item** | **Date** | **What it does** | **Source** | **Confidence** |
| --- | --- | --- | --- | --- |
| **EO 14365 — Ensuring a National Policy Framework for AI** | Dec 11, 2025 | Directs agencies to challenge state AI laws inconsistent with a "minimally burdensome" standard; AI Litigation Task Force; directs Commerce to consider withholding BEAD broadband funds from states with "onerous" AI laws. Cannot itself preempt | [White House text](https://www.whitehouse.gov/presidential-actions/2025/12/eliminating-state-law-obstruction-of-national-artificial-intelligence-policy/) | **HIGH** |
| **Feb. 27, 2026 presidential directive and agency cessation actions against Anthropic** | Feb 27, 2026 (directive and Secretarial Order); Mar 2 (Treasury, FHFA, State); letters dated Mar 3, received Mar 4 | Per the complaint and its exhibits in *Anthropic PBC v. U.S. Department of War* (Section G.2): a presidential social-media post directed "EVERY Federal Agency" to "IMMEDIATELY CEASE all use of Anthropic's technology"; the same day the Secretary of War posted a "final" order directing DoD to designate Anthropic a **"Supply-Chain Risk to National Security"** and declaring that no contractor, supplier, or partner doing business with the military may conduct any commercial activity with Anthropic, while requiring Anthropic to keep serving DoD for up to six months; GSA removed Anthropic from the Multiple Award Schedule and USAi.gov and terminated its OneGov contract; Treasury and FHFA announced termination of all use; State switched its chatbot vendor; HHS disabled enterprise access. A Secretarial Letter dated Mar 3 invoked **10 U.S.C. § 3252**; a **separate letter the same day invoked 41 U.S.C. § 4713** (reviewable only in the D.C. Circuit). The dispute arose from Anthropic's refusal to drop two usage restrictions (lethal autonomous warfare; mass surveillance of Americans) in DoD contract negotiations. **These are the first executive-branch actions in this tracker directed at a named frontier developer; they are procurement and national-security actions, not model-safety regulation, but they establish the executive-action layer that the June 12 directive later extended to model access.** The Sanders–Casar release and Reuters coverage cited above reference the same events | [Complaint with exhibits — Justia](https://docs.justia.com/cases/federal/district-courts/california/candce/3:2026cv01996/465515/1) · [GSA release cited in complaint](https://www.gsa.gov/about-us/newsroom/news-releases/gsa-stands-with-president-trump-on-national-security-ai-directive-02272026) | **HIGH** on the existence, dates, and text of the directive and order (attached as complaint exhibits) and on the agency actions the complaint cites to official releases; the *characterization* of motive is the plaintiff's and is contested |
| **EO 14409 — Promoting Advanced AI Innovation and Security** | June 2, 2026; scheduled for Federal Register publication June 5 | Directs Treasury, the Department of War/NSA, and DHS/CISA—consulting the White House, Commerce/NIST and others—to develop a classified cyber-capability benchmark and threshold for "covered frontier models" and design a **voluntary** developer framework permitting up to **30 days' pre-release government access**. Also directs a voluntary Treasury/NSA/CISA AI-cybersecurity clearinghouse and DOJ prioritization of AI-enabled cybercrime. Section 3(c) expressly disclaims mandatory licensing, mandatory governmental review, or preclearance | [Executive Order 14409 — Federal Register public-inspection PDF](https://public-inspection.federalregister.gov/2026-11415.pdf) | **HIGH** (order text read directly; reported motive and pre-signing history omitted because the order does not establish them) |
| **June 12, 2026 government export-control directive affecting Anthropic Fable 5 / Mythos 5** | Directive June 12; Mythos 5 partially restored to vetted US organizations after a **June 26** government approval; controls **lifted June 30**; Fable 5 redeployed globally **July 1** | Anthropic states that the US government applied export controls to both models on June 12, requiring it to prevent **all foreign-national access**; Anthropic received the directive at **5:21 p.m. ET** and suspended both models for all users because it could not verify nationality in real time. Anthropic's June 30 post (read directly) states the controls were lifted that day, that Mythos 5 access had been restored to a set of US organizations following a June 26 approval, and that Fable 5 would return globally July 1. Anthropic attributes the directive to the government learning of an **Amazon researchers' report** of a Fable 5 safeguard bypass, and characterizes the bypass as narrow and non-unique — the regulated party's account. Anthropic's post also commits to expanded pre-release government access and participation in the EO 14409 §2(d) clearinghouse. **The nonpublic directive's issuing office, complete reasoning, and statutory/regulatory basis cannot be independently verified from public text**; earlier secondary claims tying it to ECRA §4817(b)(1) and EAR §744.22(b) are not treated as established | [Anthropic June 30 post, "Redeploying Fable 5" (read)](https://www.anthropic.com/news/redeploying-fable-5) · [Anthropic statement on the directive](https://www.anthropic.com/news/fable-mythos-access) · [Anthropic Mythos access page](https://www.anthropic.com/claude/mythos) · [CRS IF13217](https://www.everycrsreport.com/files/2026-07-31_IF13217_f173f382a81a70a361e3fcb013ab08058bb4106d.html) | **HIGH** on the public suspension/restoration timeline (first-party post read); **MED-HIGH** on government authority and rationale because the directive is nonpublic |
| **CAISI voluntary pre-deployment evaluation activity + NIST AITE program** | 2026; AITE kickoff/evaluation plan in July and evaluation period beginning August | NIST officially describes CAISI as establishing voluntary agreements with private developers/evaluators and leading unclassified national-security-risk evaluations; its Frontier Assessment team collaborates with frontier labs on pre-deployment evaluations. NIST's **voluntary** AI Technology Evaluation (AITE) provides blind-data testing in a sequestered environment, initially covering quantum science, genomics, and public-safety vision tasks. These programs are evidence of a federal voluntary-evaluation track; describing them as a substitute for a statutory audit mandate is analysis, not an official characterization | [CAISI — NIST](https://www.nist.gov/caisi) · [CAISI careers/team activities — NIST](https://www.nist.gov/caisi/careers-caisi) · [AITE official program page](https://ai-challenges.nist.gov/aite) · [AITE technical overview](https://pages.nist.gov/ai-technology-evaluation/) | **HIGH** on the programs and stated activities (official NIST records); comparative characterization is analytical |
| **Trump remarks: Congress wants to regulate AI "out of business"** | Aug 7, 2026 | Said in a **Punchbowl News interview**, reported by Reuters (Courtney Rozen) and widely syndicated; Reuters placed it in the context of stalled bills "including a bill that would require developers of the most powerful AI models to submit them for independent security audits" (i.e., FRONTIER). **Reading it as a veto signal is TechTimes' interpretation, not Reuters'.** Same day, NIST published AI evaluation guidelines for public comment. Reuters also reports that both OpenAI and Anthropic said systems "escaped containment during security testing"; Anthropic's own July 30 disclosure of three unauthorized-access incidents is referenced on its June 30 post | [Reuters via Yahoo](https://finance.yahoo.com/news/trump-says-congress-wants-regulate-142003615.html) · [Quartz](https://qz.com/trump-congress-ai-regulation-nist-guidelines-080726) | **MED-HIGH** (Reuters wire + multiple outlets; Punchbowl interview itself not read) |
| **California Executive Order N-9-26 — independent oversight and an AI "kill switch"** ⟨U⟩ | Sept 18, 2026 (experts named Sept 23) | Directs the Government Operations Agency, in consultation with Cal OES, to convene national experts and submit recommendations by **Nov 16, 2026** on at least four amendments to state law: (1) requiring all large frontier developers to **embed designated independent verification organizations onsite** in their labs for periodic audits and evaluations; (2) independent verification of the safety frameworks, transparency reports and risk assessments frontier developers must file; (3) "requiring the creation of a 'kill switch' for frontier models, with the efficacy of the switch verified on an ongoing basis"; (4) updating the definition of critical safety incidents to include **loss-of-control incidents**. Accelerates implementation of SB 813 (IVO application requirements by **May 1, 2027**, statutory date Jan 1, 2028) and AB 1405 (online auditor registration by **Dec 1, 2027**, statutory date Jan 1, 2029). Experts convened: Jason Goldman, Gillian Hadfield, Alondra Nelson, Rob Reich. A state executive order cannot itself amend SB 53; it produces recommendations for the Legislature | [Governor's release Sept 18](https://www.gov.ca.gov/2026/09/18/governor-newsom-issues-executive-order-to-accelerate-independent-oversight-and-advance-the-creation-of-an-ai-kill-switch/) · [Experts announced Sept 23](https://www.gov.ca.gov/2026/09/23/governor-newsom-announces-world-leading-experts-to-deliver-on-his-ai-executive-order-including-advancing-creation-of-a-kill-switch/) | **MED-HIGH** (directives and deadlines from the Governor's releases; order text not opened — retrieval path: gov.ca.gov executive orders, N-9-26) |
| **Illinois Executive Order 2026-07 — Illinois Artificial Intelligence Cabinet** ⟨U⟩ | Sept 22, 2026 | Establishes an AI Cabinet of senior leaders from DoIT, IEMA-OHS, IDFPR, ICC, ISP, IDPH and IEPA plus outside experts in academia, law, ethics and governance (appointments within 30 days; volunteers; sunset no later than Dec 31, 2027) to develop policies to prepare for and respond to AI incidents, protect public assets and critical infrastructure, analyse emerging incidents, and evaluate further regulation including conditioning data-center incentives on safety standards. The order cites the AI Safety Measures Act (SB 315) and its framework, annual-audit and 72-hour incident-reporting duties. Implementation context for SB 315, not a new developer duty | [Executive Order 2026-07 — illinois.gov](https://www.illinois.gov/government/executive-orders/executive-order.executive-order-2026-07.2026.html) · [Governor's release](https://gov-pritzker-newsroom.prezly.com/gov-pritzker-establishs-illinois-artificial-intelligence-ai-cabinet) | **HIGH** (order text read on illinois.gov) |
| **Oregon Executive Order 26-26 — AI procurement safety standards for state agencies** ⟨U⟩ | Sept 23, 2026 | Directs the State Chief Information Officer to submit, within **90 days**, an implementation proposal for AI procurement and safety standards for the executive branch, including criteria for **third-party AI safety reviews** and an assessment of the viability of a **kill-switch requirement for frontier AI models** used by the state; quarterly reassessment; effective immediately until terminated. Procurement-side: it conditions state use, and imposes no duty on developers outside state contracts | [KTVZ, Sept 23, 2026](https://ktvz.com/news/2026/09/23/gov-tina-kotek-orders-new-ai-safety-standards-for-oregon-state-agencies/) | **MED** (local reporting only; order text not opened — retrieval path: oregon.gov executive orders, EO 26-26) |
| **"White House Accord on Super Intelligence: Joint Commitment on Frontier Responsibilities" — voluntary industry commitments** ⟨U⟩ | Sept 29, 2026 | **One-page text read (American Presidency Project copy).** Signed at a White House meeting by President Trump and, for their companies, Sundar Pichai (Google), Dario Amodei (Anthropic), Mark Zuckerberg (Meta), Greg Brockman (OpenAI), Elon Musk (xAI) and Jensen Huang (Nvidia). Each company training frontier models commits to four layers: (1) "robust internal controls to monitor the capabilities and alignment of its models during training and deployment around areas like cybersecurity, biosecurity, and chemical threats"; (2) an internal team to ensure the controls, monitoring and detection operate as intended and issues are remediated; (3) "an independent external auditor or evaluator" to assess the same; (4) "an independent committee of the board of directors" to oversee and receive reports. The text says "Over time, it may make sense to codify these steps into laws or regulations." Speaker Johnson described it as voluntary; President Trump said he would "never stifle the growth of a technology that will be bigger than the industrial revolution" and called for "tremendous self-regulation." **No licensing, pre-release review, or catastrophic-risk standard with legal force.** Layer (3) is the function SB 813 and AB 1405 regulate in California; the accord sets no accreditation, scope or disclosure rule for the auditor | [Accord text — American Presidency Project](https://www.presidency.ucsb.edu/documents/white-house-accord-super-intelligence) · [ABC News, Sept 29, 2026](https://abcnews.com/Politics/top-ai-leaders-meet-trump-white-house-amid/story?id=136832988) · [NBC News](https://www.nbcnews.com/politics/donald-trump/trump-host-summit-top-ai-leaders-washington-rcna599853) | **MED-HIGH** (text read from the American Presidency Project's copy; no whitehouse.gov posting located) |
| **Executive Order 14434 — "Inaugurating the Era of Super Intelligence"** ⟨U⟩ | Signed Sept 29, 2026; published Oct 2, 2026 (91 FR 63129) | **Full text read (781 words).** Terminology order: "to the maximum extent permitted by law, the executive branch shall use the terms 'Super Intelligence' and 'SI' in place of 'Artificial Intelligence' and 'AI' and will not acknowledge the usage of 'Artificial Intelligence' and 'AI' in any applicable setting" (Sec. 1); applies to official correspondence, communications, websites, reports and other non-statutory documents, without altering existing regulations, Presidential actions, contracts or grants (Sec. 2). **Definition:** "Super Intelligence" means the technologies encompassed by "artificial intelligence" as defined in 15 U.S.C. § 9401(3) (Sec. 3(a)). **Within 60 days (by about Nov 28, 2026)** the Assistant to the President for Science and Technology must propose legislative language for a federal definition of "Super Intelligence," including whether it should supersede the statutory AI definition and conforming amendments (Sec. 3(b)). **Contains no safety, testing, licensing, frontier-model or task-force provision.** Signed the same day as the White House accord; it ends the "no new federal AI executive order since EO 14409" finding, but changes no obligation on developers | [Federal Register — EO 14434, 91 FR 63129](https://www.federalregister.gov/documents/2026/10/02/2026-20321/inaugurating-the-era-of-super-intelligence) · [GovInfo PDF](https://www.govinfo.gov/content/pkg/FR-2026-10-02/pdf/2026-20321.pdf) · [whitehouse.gov](https://www.whitehouse.gov/presidential-actions/2026/09/inaugurating-the-era-of-super-intelligence/) | **HIGH** (Federal Register text read) |
| **"Super Intelligence Force" — presidential task force chaired by DNI Jay Clayton** ⟨U⟩ | Announced Oct 4, 2026 (Truth Social post) | Per the President's post and reporting: a federal coordinating body chaired by Director of National Intelligence Jay Clayton, reporting to the President and the Chief of Staff, with FTC Chair Andrew Ferguson, Under Secretary of War for Research and Engineering Emil Michael and OPM Director Scott Kupor as vice chairs; stated task is "coordinating the effort of the Federal Government to ensure that America continues to lead the World in Super Intelligence"; reported **120-day report** on AI risks and opportunities, including how the government handles disclosure of security breaches and what agencies can do under existing powers. **No executive order, charter or Federal Register notice located as of Oct 8, 2026**; whether it displaces the EO 14365 roles is not stated | [TechCrunch, Oct 4, 2026](https://techcrunch.com/2026/10/04/trump-unveils-his-new-super-intelligence-force/) · [Nextgov/FCW](https://www.nextgov.com/people/2026/10/spy-chief-jay-clayton-takes-white-houses-ai-portfolio/416413/) · [Crowell & Moring client alert](https://www.crowell.com/en/insights/client-alerts/white-house-announces-ai-responsibility-accord-executive-orders-and-super-intelligence-task-force) | **MED-HIGH** on membership and mandate (concurring press accounts of the President's post); no founding document |

## G.2 Frontier-AI litigation and enforcement (as of Sept. 5, 2026)

Searches through **Sept. 5, 2026** located no court challenge or reported enforcement action involving an enacted state frontier law. This is a **date-bounded negative finding, not proof of universal absence**. Litigation has nevertheless begun around federal executive treatment of a frontier developer and the administration's undisclosed pre-release review framework.

| **Item** | **Status** | **Relevance** | **Source** | **Confidence** |
| --- | --- | --- | --- | --- |
| **Challenges to SB 53, RAISE Act, or SB 315** | **No challenge or reported enforcement action located in the Sept. 5 search.** Re-run Sept 28, 2026: none located ⟨U⟩. SB 53 has been in effect since Jan 1, 2026; RAISE and SB 315 are not effective until Jan 1, 2027 | The available record indicates the enacted frontier laws remained judicially untested at the cutoff; do not cite this as proof that no unindexed filing exists | [Skadden — Jan 2026](https://www.skadden.com/insights/publications/2026/01/new-york-enacts-ai-transparency-law) · [DLA Piper tracker — July 29, 2026](https://intelligence.dlapiper.com/artificial-intelligence/?t=01-law&c=US) | **SEARCH-QUALIFIED** |
| **DOJ AI Litigation Task Force** (created Jan 9, 2026 under EO 14365) | No independently attributed Task Force case was located through Sept. 5, nor through Sept 28, 2026 ⟨U⟩. DOJ intervened in the Colorado case below, but the cited materials do not attribute that act to the Task Force | The search did not establish use of the Task Force against a frontier law by the cutoff | [Baker Botts — Jan 2026](https://www.bakerbotts.com/thought-leadership/publications/2026/january/ai-legal-watch---january) · [Jenner & Block](https://www.jenner.com/en/news-insights/client-alerts/doj-joins-xai-in-lawsuit-challenging-colorado-ai-act) | **SEARCH-QUALIFIED** for the negative finding |
| **Commerce Dept. "onerous state AI laws" evaluation** (EO 14365 deliverable, due Mar. 11, 2026; trigger for BEAD-funding pressure) | No public report was located through Sept. 5, nor through Sept 28, 2026 ⟨U⟩; the cited reporting likewise said it had not been released | The evidence supports only a date-bounded nonpublication finding, not the stronger claim that no internal evaluation occurred | [Jenner & Block](https://www.jenner.com/en/news-insights/client-alerts/doj-joins-xai-in-lawsuit-challenging-colorado-ai-act) | **SEARCH-QUALIFIED** |
| **X.AI LLC v. Weiser, No. 1:26-cv-01515 (D. Colo.)** | xAI sued Apr 9, 2026 to enjoin **Colorado SB 24-205** (the ADMT/algorithmic-discrimination law — Section I, *not* a frontier law) on First Amendment, Equal Protection, and dormant Commerce Clause grounds. **DOJ intervened Apr 24, 2026** (Civil Rights Division; Equal Protection theory) — the first federal court action against any state AI law. Enforcement of the Colorado law was suspended; the legislature then repealed and replaced it with SB 26-189 (May 14, 2026) | The only federal-state AI litigation to date targets a consequential-decision law, not catastrophic-risk regulation; the legal theories used (Equal Protection, compelled speech) do not map cleanly onto SB 53-style disclosure mandates. Also a precedent: DOJ chose to ride a private suit rather than file its own | [Norton Rose Fulbright](https://www.nortonrosefulbright.com/en/knowledge/publications/de3ad9de/xai-sues-doj-intervenes-enforcement-of-colorado-ai-act-suspended) · [Barnes & Thornburg](https://btlaw.com/en/insights/alerts/2026/doj-intervenes-in-lawsuit-challenging-colorados-algorithmic-discrimination-law) | **HIGH** (case number, dates, parties from multiple law-firm accounts) |
| **Anthropic PBC v. U.S. Department of War et al., No. 3:26-cv-01996 (N.D. Cal.)** | **Complaint read.** Filed Mar. 9, 2026 (WilmerHale; 48 pp.) against DoW, Treasury, FHFA, State, HHS, Commerce, VA, GSA, OPM, NRC, SSA, DHS, SEC, NASA, DOE, the Federal Reserve Board, NEA, the Executive Office of the President, and named officials. Five counts: (I) APA / 10 U.S.C. § 3252 — the supply-chain-risk order exceeds § 3252, which is limited to adversary sabotage/subversion risk, skipped the statute's consultation, written-determination, and congressional-notification steps, and is arbitrary given DoD's simultaneous six-month continued-use order; (II) First Amendment retaliation for protected speech and petitioning; (III) ultra vires presidential directive; (IV) Fifth Amendment due process (de facto debarment without notice or hearing); (V) APA § 558 unauthorized sanctions by other agencies. Seeks vacatur, § 705 stay, declaratory relief, and a permanent injunction. **Update ⟨U⟩: on Aug 27, 2026 Judge Rita F. Lin granted summary judgment largely for Anthropic**, holding the § 3252 designation and related measures "illegal and baseless" — First Amendment retaliation, Fifth Amendment due process, and APA violations (in excess of statutory authority; arbitrary and capricious) — while rejecting the ultra vires/separation-of-powers count; concurring accounts state the designation was vacated and its enforcement permanently enjoined, and the docket shows the case closed Aug 27, 2026. The government's earlier Ninth Circuit appeal of the preliminary injunction (No. 26-02011) was stayed Apr 27 pending the D.C. Circuit; no post-judgment appeal located through Sept 28, 2026 | First direct court challenge in the tracker involving federal treatment of a frontier-model developer. It concerns procurement, national-security designation, and alleged retaliation — not the validity of a state frontier statute. Legally notable for the paper: the complaint pleads that a "supply chain risk" designation under § 3252 had never before been applied to a domestic company | [Complaint and docket — Justia](https://docs.justia.com/cases/federal/district-courts/california/candce/3:2026cv01996/465515/1) · [Taft Law bulletin on the Aug 27 judgment](https://www.taftlaw.com/news-events/law-bulletins/federal-court-rules-governments-anthropic-supply-chain-designation-was-unlawful-retaliation-what-government-contractors-need-to-know/) · [Nextgov, Aug 28, 2026](https://www.nextgov.com/artificial-intelligence/2026/08/judge-rules-anthropic-supply-chain-risk-designation-was-illegal-and-baseless/415698/) · [Docket chronology — Civil Rights Litigation Clearinghouse](https://clearinghouse.net/case/47876/) | **HIGH** on filing, parties, date, and pleaded claims (complaint read); **MED-HIGH** on the Aug 27, 2026 judgment (concurring law-firm and press accounts plus docket closure; order not opened) |
| **Anthropic PBC v. U.S. Department of War, Nos. 26-1049 and 26-1162 (D.C. Cir.) — petition for review of the 41 U.S.C. § 4713 designation** ⟨U⟩ | The Mar. 9 complaint (n.36) states Anthropic received a **separate Mar. 3 letter invoking 41 U.S.C. § 4713** (civilian-agency supply-chain exclusion), that judicial review lies exclusively in the D.C. Circuit under 41 U.S.C. § 1327(b), and that Anthropic "intends to challenge that separate action in that forum." **Update ⟨U⟩: the petition was in fact filed Mar. 9, 2026** (the earlier "no petition located" finding is superseded); stay denied Apr. 8; argued May 19; **decided Sept. 25, 2026, 2–1, petition denied**. Katsas (writing) and Rao held that FASCSA's term "manipulate" reaches a contractor that "disable[s] Claude from performing lawful actions requested by the Department," and that the First Amendment claim failed because the exclusion rested on "refusal to assent to a contract term that the Department deemed essential"; Henderson dissented, reading manipulation to require deceptive or covert interference rather than "a contractor's honest and upfront enforcement of restrictions." Anthropic: "considering all options, including further review" | The two statutory designations now have opposite outcomes: § 3252 vacated in N.D. Cal. (Aug. 27), § 4713 upheld in the D.C. Circuit (Sept. 25). The majority reportedly reasoned both rulings can coexist because the two statutes define supply-chain risk differently — the split-forum structure flagged in the Sept. 5 version has produced a split result | [Complaint n.36 — Justia](https://docs.justia.com/cases/federal/district-courts/california/candce/3:2026cv01996/465515/1) · [Opinion page — Justia (26-1049, Sept 25, 2026)](https://law.justia.com/cases/federal/appellate-courts/cadc/26-1049/26-1049-2026-09-25.html) · [Defense One](https://www.defenseone.com/threats/2026/09/anthropic-lawsuit-supply-chain-risk/416252/) · [Reason / Volokh Conspiracy](https://reason.com/volokh/2026/09/25/anthropics-first-amendment-claim-against-department-of-war-rejected/) | **HIGH** on the stated intent (complaint read); **MED-HIGH** on the Sept. 25 decision (case number, date, panel and holding concur across several accounts; opinion not opened) |
| **Protect Democracy Project v. Office of the National Cyber Director** | FOIA suit filed Sept. 1, 2026 against ONCD, Commerce, Treasury, and OSTP, with a preliminary-injunction motion. It seeks the administration's reportedly finalized Aug. 1 voluntary framework for reviewing closed frontier models before release, participating-company information, and the claimed legal authority. The preliminary-injunction motion seeks disclosure of the unclassified procedural and contractual architecture by Sept 30, 2026; no ruling located through Sept 28, 2026 ⟨U⟩ | Directly tests transparency around the executive pre-release review regime described in Section G, but does not challenge a developer mandate | [Case page and documents — Protect Democracy](https://protectdemocracy.org/work/uncovering-the-trump-administrations-secret-rules-for-ai-model-release/) | **HIGH** on filing/date/defendants/request (plaintiff's case page and linked pleadings); allegations remain unadjudicated |
| **State of Florida v. OpenAI — motion for temporary injunction against frontier development (Fla. state court)** ⟨U⟩ | Motion filed Sept 28, 2026 in the consumer-protection suit Florida filed in June 2026 over ChatGPT's effects on vulnerable users. The state asks the court to stop OpenAI from continuing to develop a "reckless, unacceptably risky product" without "third-party approved safety guardrails," arguing OpenAI has "repeatedly shown they are incapable of monitoring their AI, and hesitant in revealing rogue activity once discovered," and citing the Hugging Face incident and later misalignment disclosures. No ruling reported as of Sept 29, 2026 | The first attempt to use a state court injunction, rather than a statute, to condition frontier development on third-party-approved safeguards; the theory tracks the IVO/auditor layer in Section C. Case number and docket not located | [Ars Technica, Sept 28, 2026](https://arstechnica.com/ai/2026/09/florida-asks-court-to-put-the-brakes-on-openais-frontier-ai-development/) | **MED** (press account read; motion and docket not opened) |
| **California DOJ technical-enforcement capacity** | A California DOJ job posting sought Investigative Technologists to conduct technical investigations and support consumer-protection, privacy, and technology-enforcement matters. No SB 53 enforcement action was located in the Sept. 5 search | The posting establishes technical hiring, but not an SB 53-specific enforcement plan or action | [Official California job posting](https://calcareers.ca.gov/CalHrPublic/Jobs/JobPostingPrint.aspx?jcid=504604) · [California AG AI legal advisories](https://oag.ca.gov/news/press-releases/attorney-general-bonta-issues-legal-advisories-application-california-law-ai) | **HIGH** on the hiring record and general AI-enforcement posture; **SEARCH-QUALIFIED** on no SB 53 action located |

## G.3 Compute and export-control layer (governs who can build frontier models)

Upstream of every developer mandate above. Executive and legislative, none of it in the "frontier law" template.

| **Item** | **Date / status** | **What it does** | **Source** | **Confidence** |
| --- | --- | --- | --- | --- |
| **BIS "Framework for AI Diffusion"** (Biden-era interim final rule) | Published Jan 15, 2025; **rescinded May 2025** before its compliance date | Would have created a tiered global licensing regime for advanced chips and, for the first time, controls on **closed model weights**; open-weight models were exempt | [Federal Register](https://www.federalregister.gov/documents/2025/01/15/2025-00636/framework-for-artificial-intelligence-diffusion) · [BIS rescission release](https://www.bis.gov/press-release/department-commerce-announces-rescission-biden-era-artificial-intelligence-diffusion-rule-strengthens) | **HIGH** |
| **BIS final rule on AI-chip licensing to China/Macau** | Announced Jan. 13, 2026; published and effective Jan. 15, 2026 | Provides case-by-case review for certain exports from the United States of chips below specified performance/memory-bandwidth limits—including H200 and MI325X examples—to end users in China or Macau, subject to conditions including independent US testing and aggregate volume limits; reexports/transfers remain under a presumption of denial | [Final rule — Federal Register public-inspection PDF](https://public-inspection.federalregister.gov/2026-00789.pdf) | **HIGH** (final rule read directly) |
| **Chip Security Act (H.R. 3447; Senate companion by Sen. Cotton)** | House Foreign Affairs ordered it reported **42–0 on Mar. 26, 2026**; no standalone floor action located through Sept 28, 2026. **Included, with the AI OVERWATCH Act and MATCH Act, in the Senate FY2027 NDAA manager's package (S. 4784: SA 6683 Chip Security, SA 6575 AI OVERWATCH, SA 6585 MATCH), reported July 14, 2026; conference with the House-passed H.R. 8800 pending** ⟨U⟩ | The introduced text requires Commerce standards for location-verification and other chip-security mechanisms for covered advanced integrated circuits, plus reporting of diversion/tampering indications; the committee vote is separately confirmed by an official House release and CBO's reported-bill record | [Introduced text — Congress.gov PDF](https://www.congress.gov/119/bills/hr3447/BILLS-119hr3447ih.pdf) · [Official 42–0 committee-vote release](https://huizenga.house.gov/news/documentsingle.aspx?DocumentID=404259) · [CBO record of bill as ordered reported](https://www.cbo.gov/publication/62310) · [AIPN conference letter listing the Senate amendments](https://theaipn.org/aipn-fy27-ndaa-conference-letter/) · [Sen. Banks release](https://www.banks.senate.gov/news/press-releases/banks-secures-ai-overwatch-act-in-senate-ndaa/) | **HIGH** on introduced provisions and committee status; no-floor-action statement is SEARCH-QUALIFIED; NDAA inclusion **MED-HIGH** (sponsor and advocacy accounts; amendment text not read) |
| **GAIN AI Act of 2025 (S.3150)** | **Introduced in the Senate Nov. 6, 2025; referred to Senate Banking.** An earlier version of this tracker said "pending in House," which was incorrect | Requires an applicant for a license to export advanced AI chips to a country of concern to certify that US persons have priority in acquiring those chips, subject to the bill's conditions and exceptions | [Introduced text — GovInfo PDF](https://www.govinfo.gov/content/pkg/BILLS-119s3150is/pdf/BILLS-119s3150is.pdf) · [GovInfo metadata/status](https://www.govinfo.gov/app/details/BILLS-119s3150is) | **HIGH** (introduced text and official metadata read) |
| **BIS Affiliates Rule** | Suspended Nov. 10, 2025 through **Nov. 9, 2026**; scheduled to be reimposed **Nov. 10, 2026** | The underlying rule generally extends Entity List/MEU restrictions to unlisted foreign entities owned 50% or more, directly or indirectly, individually or in aggregate, by listed entities, subject to exclusions. A later final rule temporarily removed and prospectively reinstated those provisions | [Suspension and prospective reimposition — Federal Register public-inspection PDF](https://public-inspection.federalregister.gov/2025-19846.pdf) · [Affiliates Rule — Federal Register public-inspection PDF](https://public-inspection.federalregister.gov/2025-19001.pdf) | **HIGH** (final-rule texts read directly) |
| **Documentary lineage of the 10²⁶ threshold** | Oct. 2023 → present | **EO 14110 §4.2** used 10²⁶ integer/floating-point operations as a reporting trigger for dual-use foundation models; BIS's Sept. 2024 proposal repeated it. Current state frontier statutes use the same numerical benchmark. EO 14110 was revoked Jan. 20, 2025. This establishes documentary lineage, but not that every legislature copied the EO directly. No final version of BIS-2024-0047 was located before the revocation, so that procedural-status point is search-qualified | [BIS proposed rule — Federal Register](https://public-inspection.federalregister.gov/2024-20529.pdf) · [White House revocation of EO 14110](https://www.whitehouse.gov/presidential-actions/2025/01/initial-rescissions-of-harmful-executive-orders-and-actions/) | **HIGH** on the texts, dates, and shared threshold; **SEARCH-QUALIFIED** on no final rule located |
| **AI OVERWATCH Act (H.R. 6875, Rep. Mast; S. 4456, Sens. Banks and Warren) and other FY2027 NDAA AI provisions** ⟨U⟩ | H.R. 6875 introduced Dec 18, 2025 and advanced by House Foreign Affairs Jan 21, 2026; S. 4456 introduced Apr 30, 2026; **in the Senate NDAA manager's package as SA 6575 (July 14, 2026)**; Senate NDAA (S. 4784) awaiting floor action after a failed cloture vote July 14; House NDAA (H.R. 8800) passed July 22, received in the Senate Sept 14; conference pending as of Sept 28, 2026 | Requires Commerce licences for exports of advanced AI chips to countries of concern, with a **30-day congressional review** and disapproval mechanism modelled on arms-sales review, and codifies the prohibition on the most capable chips for **18 months**; Commerce certification that exports of lesser chips do not divert US supply or foundry capacity or permit unauthorized remote access; an "American AI Victory Strategy." The AIPN conference letter also lists House Sec. 240 (AGI Preparedness Initiative), House Sec. 1502 (AI Incident and Vulnerability Reporting Program), and Senate Secs. 1634 (insider-threat reporting for large AI contractors), 1652–1655 (AI bill of materials, human oversight for use of force, biosecurity procurement for covered AI models, secure AI data centers) as provisions in play | [H.R. 6875 — congress.gov](https://www.congress.gov/bill/119th-congress/house-bill/6875/titles) · [Sen. Banks release, July 14, 2026](https://www.banks.senate.gov/news/press-releases/banks-secures-ai-overwatch-act-in-senate-ndaa/) · [AIPN conference letter, Aug 31, 2026](https://theaipn.org/aipn-fy27-ndaa-conference-letter/) · [H.R. 8800 status — GovInfo](https://www.govinfo.gov/bulkdata/BILLSTATUS/119/hr/BILLSTATUS-119hr8800.xml) | **MED-HIGH** (sponsor and advocacy accounts and GovInfo status for H.R. 8800; bill and amendment texts not read) |

## H. Precursors, withdrawn proposals, and legislative history

| **Bill** | **State** | **Status** | **Relevance** | **Source** | **Confidence** |
| --- | --- | --- | --- | --- | --- |
| **S.B. 1047 — Safe and Secure Innovation for Frontier AI Models Act** | CA | **Vetoed** Sept. 29, 2024 | The enrolled bill required covered developers to implement a written safety and security protocol, retain an annual independent auditor, submit compliance certifications before training/deployment, maintain a full-shutdown capability, and report safety incidents. Those features were dropped from S.B. 53, while the federal FRONTIER Act's emergency-order power and Illinois S.B. 315's audit mandate revive two of them at other levels of government | [Official bill page, enrolled text, history, and veto message](https://leginfo.legislature.ca.gov/faces/billNavClient.xhtml?bill_id=202320240SB1047) | **HIGH** (official enrolled text, history, and veto message read) |
| **Reconciliation-bill 10-year state-AI-law moratorium (2025)** ⟨R⟩ | Federal | **Stripped by a 99–1 Senate vote on July 1, 2025**: Blackburn Amendment No. 2814 to H.R. 1 stated its purpose as striking the section relating to support for artificial intelligence | Essential legislative history for preemption analysis: the broad moratorium failed overwhelmingly. Any claim that this vote *caused* later actors to choose narrower routes is interpretation and should be framed as such | [Official Senate roll call 363](https://www.senate.gov/legislative/LIS/roll_call_votes/vote1191/vote_119_1_00363.htm) · [Senate Commerce Committee account](https://www.commerce.senate.gov/press/dem/release/senate-strikes-ai-moratorium-from-budget-reconciliation-bill-in-overwhelming-99-1-vote-2025-7/) | **HIGH** (official roll call and committee record) |
| **California ballot initiative A.G. File No. 25-0034, Amendment \#1 — "Oversight of certain frontier AI companies"** ⟨R⟩ | CA | **Withdrawn Feb 27, 2026** (confirmed on CA AG inactive-measures page; title and summary had issued Feb 4, 2026; proponent Alexander Oldham). **Companion initiative 25-0033** — regulating AI public-benefit corporations and nonprofits — withdrawn the same day | LAO analysis (Jan 20, 2026) read: would create an independent seven-member California AI Safety Commission regulating "frontier AI companies" defined by **valuation, capital raised, or expenditures plus a commission-set capability threshold (no FLOP number)**; registration; review of protection plans covering workforce displacement, safety, and loss of control; authority to **delay capability expansions**; emergency orders; certification of independent evaluators; **civil fines up to 20% of California revenue; executives personally liable up to $1M; felony penalties (2–6 years); private enforcement**; funded by registrant fees up to 0.5% of CA revenue. The maximal SB 1047-style design, attempted via direct democracy | [LAO analysis](https://www.lao.ca.gov/BallotAnalysis/Initiative/2025-034) · [AG inactive measures](https://oag.ca.gov/initiatives/inactive-measures) | **HIGH** (LAO analysis and AG status page read) |

## I. Adjacent — partial frontier provisions inside broader AI laws

| **Law** | **State** | **Frontier-relevant content** | **Status** | **Source** | **Confidence** |
| --- | --- | --- | --- | --- | --- |
| **S.B. 5 — Connecticut AI Responsibility and Transparency Act (Public Act 26-15; "An Act Concerning Online Safety")** | CT | 39-section omnibus (AEDT/employment AI incl. WARN-notice AI disclosure, companion chatbots, provenance, social media, regulatory sandbox). **Frontier-relevant sections:** "frontier developer" = doing business in CT + \>10²⁶ FLOPs; "large frontier developer" = \>$500M revenue; frontier developers may not retaliate against employees reporting catastrophic-risk concerns (effective **Oct. 1, 2026**); large frontier developers must operate anonymous internal reporting channels **by Jan. 1, 2027**; **penalty up to $1,000 per violation**; plus a **DCP-run IVO pilot through June 30, 2030 — see Section C**. **No developer framework, transparency-report, incident-reporting, or audit mandate** | Passed May 1, 2026 (Senate 32–4, House 131–17); **signed May 27, 2026**; AG-exclusive enforcement under CUTPA, 60-day cure period through 2027 | [Enacted text — cga.ct.gov](https://www.cga.ct.gov/2026/act/pa/pdf/2026PA-00015-R00SB-00005-PA.pdf) · [MoFo analysis](https://www.mofo.com/resources/insights/260608-connecticut-enacts-sweeping-ai-law) | **HIGH** (enacted text read; secondary analysis used as cross-check) |

## J. Checked and excluded (with reason)

| **Item** | **Why excluded** |
| --- | --- |
| **PA H.B. 2705** | Verified **not** a frontier bill — it commissions an AI-in-the-workforce report from Labor & Industry / DCED (introduced July 16, 2026, 12 Democratic sponsors). One blog lumped it with MA S.3178 as "frontier-AI and workforce bills"; only the latter half applies. [LegiScan](https://legiscan.com/PA/bill/HB2705/2025) |
| **Colorado SB 24-205 → SB 26-189** | Consequential-decision/ADMT regulation, not compute-threshold developer regulation. Signed May 14, 2026; obligations Jan 1, 2027 |
| **Texas TRAIGA (HB 149)** | Prohibited-use-case approach; effective Jan 1, 2026 |
| **Washington SB 5395** | Sector-specific (health-insurance AI auditability) |
| **Virginia HB 2094 (2025)** | Colorado-style high-risk ADS bill; **vetoed** by Gov. Youngkin Mar 24, 2025. Context for VA's later pivot to the IVO-study approach |
| **CA SB 1119 ("Adam's Law") and SB 867** ⟨U⟩ | Companion-chatbot child-safety laws signed Sept 10, 2026: pre-release risk assessments for minor users and **independent child-safety audits** from July 1, 2027 (SB 1119); moratorium on companion chatbots in toys (SB 867). No frontier or compute threshold; deployer-side. Noted because AB 1405's auditor registry will cover this second California audit regime. [Governor's release Sept 10](https://www.gov.ca.gov/2026/09/10/governor-newsom-signs-the-strongest-child-safety-chatbot-and-social-media-laws-in-the-nation/) |
| **NJ S 1802** ⟨U⟩ | Annual AI "safety test" reports (biases, inaccuracies, cybersecurity threats) to the Office of Information Technology for any entity that sells, develops, deploys or uses AI in New Jersey; no size, compute or revenue threshold; no penalties. General AI bill, not frontier-developer regulation. [Bill text — njleg](https://pub.njleg.gov/Bills/2026/S2000/1802_I1.HTM) |
| **NY S10642 / A11560 (Responsible Data Center Development Act) and Executive Order No. 62** ⟨U⟩ | One-year moratorium on permits for large data centers, passed June 4, 2026 and awaiting the Governor; EO 62 (July 14, 2026) paused DEC permits for new hyperscale data centers for up to a year. Compute-siting policy, not developer regulation; adjacent to the Section G.3 compute layer. [Governor's release, July 14, 2026](https://www.governor.ny.gov/news/first-statewide-moratorium-new-hyperscale-data-centers-launched-governor-kathy-hochul) |
| **MI SB 757–760 ("Kids Over Clicks")** ⟨U⟩ | Minors, addictive feeds and emotion-responsive chatbots; passed the Michigan Senate Apr 29, 2026. Not frontier regulation. A Sept 25 tracker summary conflated SB 760 with H.B. 4668; H.B. 4668's own history shows no action since Mar 19, 2026 |
| **China FIREWALL Act (Gottheimer, LaLota)** ⟨U⟩ | Announced Sept 18, 2026: bars Chinese-developed open-weight models from federal devices and federal procurement. Procurement restriction, not frontier-developer regulation |

## K. Cross-cutting divergences (raw material for the ambiguity taxonomy)

| **Dimension** | **CA SB 53** | **NY RAISE (amended)** | **IL SB 315** | **MI HB 4668** | **NJ S.4446/A.5275** | **MA (Senate text)** | **H.R. 9925 FRONTIER** |
| --- | --- | --- | --- | --- | --- | --- | --- |
| **Casualty threshold** | \>50 | \>50 (was 100) | \>50 | **\>100** | **25+** | 50+ | \>50 |
| **Casualty threshold — full spread** | *H.R. 9965 ATOMIC: 5 deaths / 50 serious injuries / $100M* | *H.R. 9917 Kill Switch: 10 / $100M* | *MN HF 4532: 25 / $1M* | *NJ: 25 / $1B* | *MI & original RAISE: 100 / $1B* | *most others: 50 / $1B* | — |
| **Developer trigger** | \>$500M rev | \>$500M rev | \>$500M rev | **Compute cost $5M/$100M** | **\>$100M rev** | \>$500M AI rev **or** \>$1B R\&D | **\>$50M rev + ≥$1B AI spend** (large); \>$5B + ≥$10B (very large) |
| **FLOP threshold** | 10²⁶ | 10²⁶ | 10²⁶ | none — compute expressed as estimated cost | 10²⁶ | 10²⁶ | 10²⁶ |
| **Incident reporting** | 15 d / 24 h imminent | 72 h / 24 h | 72 h / 24 h imminent | conditions self-defined in protocol | **none** (term defined, never used) | to AG | 72 h / 24 h to law enforcement |
| **Third-party audit** | none | **dropped** | annual (from 2028) | annual | discretionary (AG) | **every 120 days** | annual (large) + IVO ≥6-monthly (very large) |
| **Whistleblower protection** | yes + anonymous channel | **removed** | yes | yes + **private right of action** | none | yes | **none** |
| **Private right of action** | none for developer obligations; **employees may sue for retaliation** | no | none for developer obligations; **employee remedies via IL Whistleblower Act** | employees only | no | no | no (IVO immunity) |
| **Penalty ceiling** | $1M | $1M / $3M | $1M / $3M | $1M ($500 for whistleblower violations) | $100K | — | $1M/day; $10M/day + criminal for emergency-order violations |
| **Oversight body** | OES + AG | new DFS office (rulemaking) | IEMA/OHS + AG | AG | AG + OHSP | AG | new Under Secretary of Commerce |
| **Sunset / review** | annual definitional review | — | — | — | **5-yr sunset** | — | thresholds may only increase; 2-yr review |
| **Federal reciprocity** | **incident reporting only** | **incident reporting only** | whole Act, but federal rule must mandate audits | — | — | — | would displace (see above) |
| **Disclosure-statement renewal** | — | every 2 years | annually | — | — | — | annually |
| **Territorial limit** | no express territorial clause | NY-only | disclosure statement: "in whole or in part in this State" | — | "users in NJ" | — | interstate commerce |
| **Preempts local govts** | yes (ordinances on/after Jan 1, 2025) | — | **yes** (denies home rule, Sec. 35) | — | — | — | partially preempts states in three enumerated fields; effect on existing laws textually disputed |
| **Good-faith exception for false statements** | yes | yes (§1421(4)(b)) | yes | — | yes | — | yes |

**Two textual clusters (from primary texts; similarity ≠ proven copying):** *Original-RAISE / SSP cluster* — IL HB 3506 (filed Feb 7, 2025), NY S.6953 as passed June 2025, MI HB 4668 (June 24, 2025), MN HF 4532 (Mar 2026, threshold removed). Illinois's bill predates New York's passage, so direction of influence within this cluster is not established; the shared features (compute-cost thresholds, 90-day reports, annual audit, whistleblower private action) point to a common drafting source rather than sequential copying. *TFAIA cluster* — CA SB 53 (Sept 2025) → NY Chapter 96 (Mar 2026) → IL SB 315 (July 2026, + audit), with MA H.5576's Senate text, LA SB 474, TN HB 1898, **UT HB 286**, and NJ S.4446/A.5275 as variants. **Supportable claim:** New York and Illinois demonstrably shifted from the SSP/audit structure toward the TFAIA framework (NY by amending its own law; IL by moving away from HB 3506 to SB 315); Michigan and Minnesota retain variants of the earlier approach.

### K.2 Assurance layers

One "third-party audit" column hid the distinction that matters most for the paper. Three separable layers:

| **Jurisdiction / bill** | **1. Developer self-governance (published framework + disclosures)** | **2. Compliance audit (did the developer follow its own framework?)** | **3a. Independent technical risk evaluation (does the model pose catastrophic risk?)** | **3b. Auditor/evaluator accreditation (who may perform 2 or 3a?)** |
| --- | --- | --- | --- | --- |
| CA SB 53 (+ AB 1405 / SB 813 on Governor's desk) | yes | — | — | **AB 1405: mandatory registration for anyone conducting a state-law-required AI audit (from 2029); SB 813: voluntary GovOps-designated IVOs (by 2028)** |
| NY RAISE (enacted) | yes | **removed** | — | — |
| NY S.10373 (pending) | — | **annual** | partly (verifier checks statements vs. findings) | **DFS accreditation, mandatory from 2029** |
| NY S.10456 (pending) | **state-set minimum standards** for the framework | — | — | — |
| IL SB 315 | yes | annual (2028) | — | auditor-independence rules only |
| MI HB 4668 | yes | annual | — | — |
| MA (Senate text) | yes | — | **every 120 days** | — |
| NJ S.4446/A.5275 | yes (to AG, NIST-RMF-mapped) | discretionary AG audit | — | — |
| LA SB 474 | yes | annual (2028) + self-certification | — | — |
| TN HB 1898 | yes | "independent reviews" | — | — |
| UT HB 286 | yes | — | child-risk assessments may involve third-party evaluators | — |
| MN HF 4532 (no threshold) | yes (protocol) | — | — | — |
| CT SB 5 | — | — | pilot participants may seek verification | DCP-administered IVO **pilot through June 30, 2030** |
| OH HB 628 | — | — | voluntary IVO verification | **voluntary license**, IVO-defined scope |
| MN HF 4544 / SF 4636 | — | — | voluntary IVO verification with a rebuttable presumption against liability | **risk-specific Commerce license**; advisory council; ongoing monitoring |
| VA Ch. 425/426 | — | — | — | JCOTS **study** |
| H.R. 9925 FRONTIER | yes | annual (large tier) | **IVO ongoing assessment ≥6-monthly (very large tier)** | **federal IVO licensing** |
| H.R. 9965 ATOMIC | — | — | **mandatory DOE/NNSA nuclear-risk evaluation with weight access** | — |
| S. 5061 Warner | — | — | **mandatory NSA pre-deployment testing** | — |
| S. 2938 Hawley-Blumenthal | — | — | **mandatory DOE evaluation program** | — |

## L. Completeness methodology and known gaps

**How this list was built.** Bills were found via (a) the user's seed list, (b) secondary trackers and law-firm alerts, (c) targeted sweeps for compute-threshold, "frontier developer," "catastrophic risk," and IVO/auditor language, (d) FPF's *The State of State AI 2025* (Oct. 2025), which tracked **210 industry-facing AI bills in 42 states** and classified **2.9% (≈6 bills) as frontier/foundation-model legislation**, and (e) direct keyword searches of the [NCSL Artificial Intelligence Legislation Database](https://www.ncsl.org/financial-services/artificial-intelligence-legislation-database), updated Sept. 1, 2026.

**Accuracy-hardening protocol used in the Sept. 5 recertification:** (1) pin every legal proposition to the relevant bill version, enrolled act, final rule/order, official action page, or docket; (2) separate a source-established fact from the researcher's comparison or inference; (3) use secondary reporting only when the operative document is nonpublic, and say exactly what remains unverified; (4) convert absolute absence claims into date-bounded **SEARCH-QUALIFIED** results; (5) avoid upgrading a row merely because several secondary sources repeat the same originating report; and (6) preserve contradictory or superseded versions rather than silently blending them. This protocol improves accuracy more than forcing every item into a HIGH bucket.

**Coverage against those baselines:** CA (SB 53), NY (RAISE), MI (HB 4668), IL (**HB 3506 — the 2025 bill FPF counted**, plus 2026's SB 315 / SB 3312 / HB 4705 / SB 3261 / HB 4799 / SB 3444) and RI (S.358 / H.5224) are all included — **the FPF 2025 frontier set is fully identified by bill number.** The 2026 sweep and reviews added MA, NJ, MN (including the no-threshold RAISE bill and the IVO pair), TN, LA, UT, NY S.10373/S.10456, the IVO measures in CA, OH, VA, CT, and MN, and the federal measures listed in Sections D–F. The NCSL "frontier" search produced 11 bills in five states for 2026 and exposed the previously missing **Utah H.B. 286**; the NCSL "independent verification organization" search exposed the previously missing **Minnesota H.F. 4544 / S.F. 4636**. Other NCSL hits using "frontier" only for workforce or quantum-technology topics were excluded as false positives.

**Residual limitation:** NCSL's keyword results omit several independently verified bills already in this tracker and therefore function as a cross-check, not an exhaustive frontier-AI index. The [IAPP State AI Governance tracker](https://iapp.org/resources/article/us-state-ai-governance-legislation-tracker) was also reviewed, but its public page was last updated Apr. 28, 2026 and focuses on broadly applicable private-sector governance, so it cannot validate late-2026 or narrowly scoped IVO additions. Newly introduced bills or post-Sept. 5 status changes may still exist. Two-reviewer provenance: rows marked ⟨R⟩ or ⟨NCSL⟩, and several HIGH ratings on sites that block automated access (cga.ct.gov, capitol.tn.gov, leginfo.ca.gov, some ilga.gov full-text pages, Federal Register public-inspection PDFs), rest on the external reviewer's direct reads; the items independently re-opened in this pass are the Anthropic v. Department of War complaint, Utah H.B. 286's official page, and Anthropic's June 30 post. The defensible description is: **"primary-source verified within stated selection criteria; comprehensive to the FPF 2025 baseline and cross-checked against the Sept. 1, 2026 NCSL database; not guaranteed exhaustive."**

**Supplementary check (Sept. 28, 2026) ⟨U⟩:** rows marked ⟨U⟩ were added or changed in checks on Sept. 28, Sept. 29 and Oct. 8, 2026 of the period Aug. 28–Oct. 8, 2026 using the Governor of California's legislative updates and releases, GovInfo bill-status records for every federal bill in this tracker and for newly numbered bills, malegislature.gov, legislature.mi.gov, illinois.gov, sponsor releases and bill prints, and court reporting for the Anthropic litigation. Operative documents **not opened** in that check, and therefore capped at MED-HIGH: the chaptered texts of AB 1405 (Ch. 178) and SB 813 (Ch. 179); the N.D. Cal. summary-judgment order of Aug. 27, 2026; the D.C. Circuit opinion of Sept. 25, 2026 (Nos. 26-1049, 26-1162); California EO N-9-26 and Oregon EO 26-26. Bill numbers **not located**: the Liccardo–Kiley U.S.–China bill and the Hawley–Murphy AI Agent Accountability Act (the numbers H.R. 10362, S. 5471 and H.R. 10567 were resolved from GovInfo bill status on Sept. 29, and S. 5576 on Oct. 8); the AI Regulator Act was not found among Senate introductions of Sept. 23–24. Date-bounded negatives as of Sept. 28, 2026 (re-run Oct. 8 except where noted): no new federal AI executive order since EO 14409 **until EO 14434 of Sept. 29, 2026, a terminology order with no developer obligation (Section G)**; no Commerce evaluation of "onerous" state AI laws; no DOJ AI Litigation Task Force suit against a frontier law; no new CAISI agreements since May 5, 2026; no further action on S. 2938, S. 5061, H.R. 9965, S. 4656, H.R. 10180, S. 3150 or H.R. 9363. Sites blocking automated access in this pass: leginfo.ca.gov, nysenate.gov, congress.gov, legiscan.com, CourtListener and Justia dockets. The AAF cross-check on the Comparison tab was not refreshed. The Sept. 29 pass added NY S.10701, PA H.B. 2800, the Florida injunction motion and the White House accord after reading the two bills' introduced texts on nyassembly.gov and palegis.us. The Oct. 8 pass read EO 14434 in the Federal Register and the accord's one-page text, resolved S. 5576, and added the Super Intelligence Force and the Hawley–Murphy announcement; GovInfo bill status showed no action on any tracked federal bill between Sept. 29 and Oct. 8, and no AI-related title among S. 5542–5625 other than S. 5576, or among H.R. 10568–10660. The ratings in this supplementary check follow the same key as the Sept. 5 recertification. A separate **News** tab on the website records September's hearings, letters, investigations and industry incidents; those items are not tracker entries.

*Next step: run each Category A/B/D row through the ambiguity taxonomy. Strongest case-study candidates now: (1) FRONTIER Sec. 9's "new substantive obligations" — does "adopt or enforce ... new" displace existing state laws, as the sponsor summary says it's "aimed" to, or only future ones? (2) MI HB 4668 as a frozen copy of a template NY abandoned. (3) NJ A.5275's orphaned "critical safety incident" definition. (4) IL SB 315's deemed-compliance clause letting a state AG enforce federal standards. (5) IL SB 315's 2027/2028 gap — transparency reports due from 2027 must summarize assessments under a framework not required until 2028. (6) The split-forum structure of the § 3252 / § 4713 supply-chain designations against a frontier developer.*
