Lawfare Analysis Calls for Evidence Rules in State AI Incident Reporting
California, New York and Illinois require frontier-AI developers to disclose the gravest safety events. A new analysis argues that regulators may still lack the records and authority needed to learn from them.
Listen to this story
The audio brief
Story brief
3 key pointsA Lawfare analysis identifies a missing layer in California, New York, and Illinois frontier-AI incident regimes: developers must notify authorities about narrowly defined, high-severity failures, but generally need not preserve the evidence needed to explain them. California’s system is active, while New York and Illinois begin in 2027. Without retention of models, weights, prompts, logs, and execution...
- 01
California’s reporting mechanism began in 2026; New York and Illinois are scheduled to launch in 2027.
- 02
Routine deadlines are 15 days in California and 72 hours in New York and Illinois; imminent serious risks trigger 24-hour reporting.
- 03
Covered incidents include harmful unauthorized weight access, loss of model control, catastrophic-risk harm, and materially risk-increasing deception.
State laws are beginning to create a paper trail for the most serious frontier-AI failures. But a new Lawfare analysis argues that a report alone may not leave regulators with enough evidence to reconstruct an event or prevent its recurrence.
California’s SB 53, New York’s Responsible AI Safety and Education Act, and Illinois’s SB 315 require frontier developers to report specified critical safety incidents to state authorities. The largest covered developers, defined by revenue and high training-compute levels, must also publish AI safety frameworks; Illinois adds an annual independent audit requirement.
The laws set deadlines after an incident reaches a high threshold, not a general channel for every model problem. Covered events include unauthorized access to model weights causing death or bodily injury, catastrophic-risk harm, loss of model control causing death or injury, and deceptive behavior that materially increases catastrophic risk.
The gap begins after notification
The analysis focuses on the next step. It says the laws do not require developers to preserve the model, weights, execution environment, prompts, logs, or other material that could be needed to reconstruct an incident. If those records are not retained, the author argues, later investigators may be unable to establish what happened.
New York and Illinois require their report-receiving bodies to review submissions. Yet the analysis says none of the three regimes requires a developer to investigate an incident or explicitly gives another actor investigatory powers. That is a policy assessment of the statutes, not a current requirement for a new state investigative body.
A record built before the failure
- Require developers to retain incident data so an event can be reconstructed later.
- Require large frontier developers to establish dedicated units to preserve evidence.
- Have those units help investigators access and interpret the preserved material.
Those proposals would move the state regimes beyond notification toward a system designed to support later examination. California is already operating its reporting mechanism, while New York and Illinois are scheduled to start in 2027. Whether lawmakers add retention or investigative duties remains unresolved.
Sources
- lawfaremedia.orgThe Forensic Gap in AI Safety Laws
Loading discussion...
Reader comments
Newest comments first. Replies stay oldest first.