Back to Frontier Insights

Frontier AI Needs Rules But Regulators Are Struggling

July 20, 2026
Emerging Markets
Frontier AI Needs Rules But Regulators Are Struggling

As frontier AI models grow more autonomous, Illinois, New York, and California enact disclosure laws to rein them in, but compliance challenges and patchwork regulations persist.

As cutting-edge artificial intelligence models become more powerful and autonomous, state governments are stepping in where federal regulation has stalled. Illinois, New York, and California have each passed laws requiring frontier AI developers to disclose safety measures and report incidents, aiming to increase transparency and accountability.

Illinois Governor JB Pritzker signed Senate Bill 315 (SB315), the Artificial Intelligence Safety Measures Act, which mandates that frontier AI models generating over $500 million in annual revenue must create and annually update a comprehensive AI framework covering catastrophic-risk assessment, mitigations, governance, cybersecurity, third-party evaluations, and internal-use risks. Developers must also submit transparency reports before deploying new or substantially modified models. The law takes effect in January 2027.

New York's RAISE Act (Responsible AI Safety and Education Act), signed in December 2025, also goes into effect on January 1, 2027. It establishes an oversight office within the Department of Financial Services to evaluate large frontier developers and ensure transparency. California's Frontier Artificial Intelligence Act (TFAIA), signed in September 2025, set similar guardrails.

The rapid evolution of AI—from generative chatbots to models like Mythos that can autonomously exploit zero-day vulnerabilities—has outpaced regulation. Sachin Jade, chief product officer at Cyware, notes that AI disclosure laws emerged because there was no prior regulation for frontier models. As these models are increasingly used in critical infrastructure, including the U.S. government, risks have become apparent.

One notable incident was the first AI-executed ransomware attack, highlighting the danger of reduced human oversight. Jade emphasizes the importance of allowing employees within frontier AI organizations to report safety concerns.

While the three states share core requirements, details such as third-party audit timelines and incident reporting windows vary. Illinois and New York require incident reporting within 72 hours, while California allows 15 days. If an incident poses imminent risk of death or serious injury, the window shrinks to 24 hours in Illinois. This patchwork compliance increases costs for developers who must produce different reports for each jurisdiction.

"There's no standardization at the moment, but it is a start," Jade told Dark Reading. He also raises concerns about downstream users of frontier models, such as those modifying open-source models or embedding them into workflows. The current laws do not address these scenarios.

Jade advises enterprises to return to cybersecurity basics: maintain strong visibility to reduce shadow AI risks, conduct regular audits, map applications, implement identity and access management controls, and build a risk registry. Security is a mindset and culture, not just a tool.

As these novel laws take shape, many questions remain unanswered, particularly regarding liability and enforcement for modified models. The federal government has not issued formal regulations beyond a voluntary executive order on frontier AI security.