California: Frontier AI Safety and Transparency
California's SB 53, the Transparency in Frontier Artificial Intelligence Act, focuses on frontier developers and large frontier developers. The law creates requirements around frontier AI frameworks, transparency, critical safety incidents, and protections for employees who raise specified safety concerns.
The structure matters. California is not imposing a general catastrophic-risk assessment duty on every business that uses an AI service. It is placing defined duties on actors with particular frontier-model development roles and capabilities.
Illinois: A Similar Frontier Focus
Illinois's Artificial Intelligence Safety Measures Act likewise focuses on frontier models and large frontier developers. Its statutory definition of catastrophic risk uses concrete severity thresholds and specified pathways involving matters such as chemical, biological, radiological, or nuclear harm; cyber or other criminal conduct; and loss of control.
The Illinois framework also requires covered large frontier developers to establish and maintain a Frontier AI Framework addressing how catastrophic risks are identified, assessed, and managed.
What the Laws Tell Practitioners
| Question | California | Illinois |
|---|---|---|
| Primary focus | Frontier AI developers | Frontier AI developers |
| Core safety mechanism | Frontier AI framework and transparency duties | Frontier AI Framework and risk-management duties |
| Incident concept | Critical safety incidents | Critical safety incidents |
| Ordinary downstream deployer automatically covered? | No, not merely because it uses AI | No, not merely because it uses AI |
The Boundary Matters
Practitioners should preserve that boundary. Do not describe an ordinary downstream company's severe operational risk as a statutory catastrophic AI risk unless the applicable law supports that conclusion. Do not imply that a deployer inherits a frontier developer's statutory duties simply by purchasing access to a model.
At the same time, the laws provide useful risk information. They identify classes of severe harm, emphasize documented safety frameworks, require attention to safety incidents, and make clear that some model capabilities deserve governance before an incident occurs. A downstream organization can learn from those ideas without claiming that the law directly regulates its deployment.
Part 3 separates the legal question from the analytical one and asks: how can a practitioner start with a severe harm and work backward through the conditions that could produce it?