| Enacted. Gov. JB Pritzker signed SB 315 on July 6, 2026; the law takes effect January 1, 2027 and the annual audit requirement begins January 1, 2028 or 90 days after a developer first qualifies, whichever is later | Illinois Artificial Intelligence Safety Measures Act annual independent audit | Large frontier developers: those whose combined annual gross revenue with affiliates exceeded $500 million in the preceding calendar year and that build foundation models trained using more than 10^26 integer or floating-point operations, including the original training run and later fine-tuning, reinforcement learning or other material modifications | A third party using generally accepted auditing standards and best practices, with competence that includes access to frontier-model safety expertise, no financial interest in the developer, and payment that cannot depend on the audit result; covered developers must also publish and follow a frontier AI framework addressing catastrophic-risk assessment, mitigations, model-weight security, incident response, governance and use of third parties, plus model disclosures, critical-safety-incident reporting and worker protections |
| Open. Applications opened July 28. CREST says a separate, technology-agnostic framework for organizations that test the security of AI-enabled systems is planned for a later phase and is not yet open | CREST accreditation for AI-enabled cybersecurity services | Service providers that use AI in delivering their own cybersecurity work, including penetration testing | Domain 7, Responsible AI Use, in the Company General Requirements and Annex B, AI-Enabled Penetration Testing, in the Penetration Testing Accreditation Standard; IT Europa reports applicants must show that material AI uses are approved and controlled, client and sensitive information is protected and appropriate human oversight is retained, with attestations checked against supporting evidence such as policies, methodologies, technical controls, redacted engagement records and final customer reports |
| Voluntary. NIST lists July 2026 as the program kickoff and says the first evaluation period begins in August 2026; initial tasks cover image analysis with large vision-language models in quantum science, genomics and public safety | NIST AI Technology Evaluation (AITE) | Voluntary participation by data providers and model providers, described as open to organizations and individuals that agree to NIST's participation agreement and rules | Submission of models for evaluation on blind data in a sequestered testbed, or of original non-public datasets and evaluation tasks; NIST supplies common data, metrics and scoring, and its participation rules are intended to keep evaluation data out of model training |
| Self-published disclosure. Issued May 28, 2026; it is not a regulator's finding that OpenAI complies and does not transfer an enterprise deployer's responsibilities for data, access, logging, oversight and incidents | OpenAI Frontier Governance Framework | OpenAI itself; the document identifies OpenAI OpCo LLC for California compliance and OpenAI Ireland Limited as the provider responsible for obligations tied to the EU Code of Practice for models with systemic risk | A public mapping of OpenAI's practices to California's Transparency in Frontier Artificial Intelligence Act and the EU Code of Practice for General-Purpose AI, covering risk assessment and mitigation for cyber offense, chemical, biological, radiological and nuclear risks, harmful manipulation and loss of control, plus model reporting, security-risk management, incident response, external expert input and policy updates |