- What: Discussion on the lack of regulation for frontier AI
- Impact: Industry and policymakers
Informa TechTarget | SearchSecurity Cybersecurity Dive InformationWeek Channel Dive Explore our brands An Informa TechTarget Publication Dark Reading Resource Library Black Hat News Omdia Cybersecurity Advertise Newsletter Sign-Up Newsletter Sign-Up Cybersecurity Topics Related Topics Application Security Cybersecurity Careers Cloud Security Cyber Risk Cyberattacks & Data Breaches Cybersecurity Analytics Cybersecurity Operations Data Privacy Endpoint Security ICS/OT Security Identity & Access Mgmt Security Insider Threats IoT Mobile Security Perimeter Physical Security Remote Workforce Threat Intelligence Vulnerabilities & Threats Recent in Cybersecurity Topics Application Security Cursor IDE Auto-Executes Malicious Code in Poisoned Repos Cursor IDE Auto-Executes Malicious Code in Poisoned Repos by Alexander Culafi Jul 14, 2026 3 Min Read Cybersecurity Operations 'Yellow Teams' Are Defining the Future of AI Security 'Yellow Teams' Are Defining the Future of AI Security by Nate Nelson Jul 13, 2026 6 Min Read World Related Topics DR Global Middle East & Africa Asia Pacific Latin America Recent in World See All Cybersecurity Operations State IDs for AI Agents: Will Estonia Set a Precedent? State IDs for AI Agents: Will Estonia Set a Precedent? by Nate Nelson Jul 8, 2026 5 Min Read The Edge DR Technology Events Related Topics Upcoming Events Podcasts Webinars SEE ALL Resources Related Topics Resource Library White Papers Reports Webinars Newsletters Podcasts Heard It From a CISO Reporters' Notebook Dark Reading's 20th Videos Dark Reading Polls Partner Perspectives Meet the Editors Advertise With Us About Us Dark Reading Resource Library Cybersecurity Operations News, news analysis, and commentary on the latest trends in cybersecurity technology. Frontier AI: The Genie's Out of the Bottle, But Where's the Rulebook? Cutting-edge artificial intelligence models are deploying with more independence and less human oversight. Several state governments are trying to legislate transparency in their use. Arielle Waldman , Features Writer , Dark Reading July 14, 2026 4 Min Read Source: Fergregory via Getty Images As frontier artificial intelligence (AI) models grow more powerful and unpredictable, three states are racing to rein them in with new disclosure laws. Illinois governor JB Pritzker recently signed Senate Bill 315 ( SB315 ), the Artificial Intelligence Safety Measures Act in an effort to boost reporting requirements for frontier AI models that generate more than $500 million in annual revenue. New York and California also recently enacted similar disclosure laws. Once SB315 goes into effect in January of 2027, large frontier developers will be required to “create, implement, and annually update a comprehensive AI framework covering catastrophic-risk assessment, mitigations, governance, cybersecurity, third-party evaluations, and internal-use risks.” They must also submit transparency reports before deploying new or substantially modified models. In New York, the RAISE Act (Responsible AI Safety and Education Act) signed last December, will go into effect also on January 1, 2027. RAISE creates an oversight office within the state’s Department of Financial Services to assess large frontier developers and enable transparency. Related: Apple Reverses Age-Old Patch Policy to Keep Up With AI Signing the law, New York Gov. Kathy Hochul noted the law builds on California’s framework to help create a national benchmark for AI safety where the federal government has failed. California Gov. Gavin Newsom signed the Frontier Artificial Intelligence Act (TFAIA) last September, setting guardrails on the development of frontier artificial intelligence models. AI took off at a rapid pace, beginning with generative AI models like ChatGPT three years ago. But capabilities expanded quickly from chatbots giving restaurant recommendations to highly advanced models like Mythos which can autonomously identify and exploit zero-day vulnerabilities. AI disclosure laws continue to emerge because there was no regulation for frontier models, explains Sachin Jade, chief product officer at Cyware. Now that they’ve been circulating, risks have become apparent and people realize they were never "too big to fail," he says. Critical infrastructure organizations, including the U.S. government , are increasingly using these models in their environments. Models continue to access higher value information developers and companies use for training, and humans are less in the picture. One report recently cited the first AI-executed ransomware attack. 'It Is a Start' States and regulating agencies want to ensure that employees within frontier AI organizations can report safety concerns, Jade adds, emphasizing that risks could affect critical infrastructure. Related: Segmentation Works for OT If Operators Are Paying Attention Illinois, California, and New York have similar core requirements, but details vary on features such as third-party audits and disclosure timelines, which will create patchwork compliance. While Trump's latest executive order addressed frontier AI security and included a voluntary framework for the private sector, the White House has not released any formal regulations. Illinois and New York allow frontier AI developers to report critical safety incidents to the agency and attorney generals within 72 hours of discovery, while California provides 15 days. Windows shrink to 24 hours if the "incident poses an imminent risk of death or serious physical injury ," according to the Illinois legislation . Varied compliance measures mean higher costs for developers, or anyone legally required to follow the laws. They will have to create different compliance reports. "There's no standardization at the moment, but it is a start in my opinion, which is needed," Jade tells Dark Reading. As regulation efforts burgeon, many questions remain. One detail weighing on Jade's mind that hasn't been fleshed out is: What happens to the downstream folks—the actual users of these models? The laws apply to frontier AI developers that generate more than $500 million revenue but Jade spots multiple grey areas. Related: AI Dominates RSAC Innovation Sandbox For example, some models are open source and designed for users to develop bots and agents, so what happens if someone modified their own model based on a frontier model? "What if I've engrained this model into my ecosystem or my workflow? What do I do?" he poses. "Laws don't address that yet." Back to the Basics… Again Because these laws are so novel, users should return to the core essence of security like maintaining strong visibility to reduce shadow AI risks, conducting regular audits, application mapping, and implementing identity and access management controls to understand access levels in order to comply, advises Jade. One challenge is that people think tools will solve security, but security is very much a mindset and a culture, he adds. Enterprises should consider what their AI risk model is, which models they're using, and who is using them. When it comes to payroll and human resources systems, enterprises could be using six different frontier models because that's what their vendors are using, he warns. While resolution and fix times vary by state, the AI disclosure laws do require developers to investigate as soon as an incident occurs. And that means visibility is essential. "Anytime you bring a vendor, do you have an audit trail, a guardrail of that agent, and do you know what it's supposed to do?" Jade says. "Build a risk registry and just do the basics 101 of security." About the Author Arielle Waldman Features Writer, Dark Reading Arielle spent the last decade working as a reporter, transitioning from human interest stories to covering all things cybersecurity related in 2020. Now, as a features writer for Dark Reading, she delves into the security problems enterprises face daily, providing context and actionable steps. She looks for stories that go past the initial news to understand where the industry is going. Her coverage areas include identity and access management, cyber risk and operations, industrial control systems, operational technology, and ransomware trends. She previously lived in Florida where she wrote for the Tampa Bay Times before returning to Boston where her cybersecurity career took off at TechTarget SearchSecurity. When she's not writing about cybersecurity, she pursues personal projects that include a mystery novel and poetry collection. See more from Arielle Waldman Want more Dark Reading stories in your Google search results? Add Us Now More Insights Industry Reports The State of Cloud Security: The Latest Challenges The total economic impact™ of Snyk How Organizations Are Managing Incident Response How Enterprises Are Developing Secure Applications Inside RSAC 2026: security leaders reveal the risks redefining your defense strategy Access More Research Webinars When AI Becomes an Insider: Rethinking Risk in Critical Infrastructure Governing the Agent; Identity Security in the Age of Autonomous AI Securing the AI Era: Shadow AI, AI Agents, and Why AI Detection and Response Changes Everything Practical Zero Trust Implementation on a Budget in the Age of Mythos Building a Risk Based Vulnerability Management Program More Webinars Latest Articles in DR Technology Cyberattacks & Data Breaches Turning the Tables on Email Scammers With 'ScamBuster' Jul 13, 2026 | 5 Min Read Identity & Access Management Security AI Agents Are a New Kind of Identity — and Most Organizations Aren't Ready Jul 9, 2026 | 6 Min Read Cybersecurity Operations Apple Reverses Age-Old Patch Policy to Keep Up With AI Jul 2, 2026 | 4 Min Read Vulnerabilities & Threats Anthropic's AI Finds Bugs. IBM Bets $5B It Can Fix Them. Jul 2, 2026 | 8 Min Read Read More DR Technology Discover More Black Hat Omdia Working With Us About Us Meet the Editors Advertise Reprints Join Us Newsletter Sign-Up Follow Us Copyright