Lawfare Analysis Calls for Evidence Rules in State AI Incident Reporting

California, New York and Illinois require frontier-AI developers to disclose the gravest safety events. A new analysis argues that regulators may still lack the records and authority needed to learn from them.

By 2 min read
Lawfare Analysis Calls for Evidence Rules in State AI Incident Reporting
Lawfare Analysis Calls for Evidence Rules in State AI Incident Reporting

Listen to this story

The audio brief

About 1:41
0:001:41
Read transcript
California has started requiring frontier-AI developers to report the most severe safety failures. But a new Lawfare analysis says regulators could receive a report and still lack the evidence needed to understand what happened. The rules come from California’s SB 53, New York’s Responsible AI Safety and Education Act, and Illinois’s SB 315. They apply to large developers meeting revenue and high training-compute thresholds, and cover narrowly defined events: unauthorized access to model weights that causes death or bodily injury, loss of model control with similar consequences, catastrophic-risk harm, or deceptive behavior that materially increases catastrophic risk. California’s system began in 2026. Routine reports are due within 15 days. New York and Illinois are scheduled to begin in 2027, with 72-hour deadlines. In all three states, an imminent risk of death or serious injury triggers reporting within 24 hours. The gap comes after notification. The analysis says the laws generally do not require developers to preserve the model, its weights, prompts, logs, or execution environment. They also do not require the developer to investigate, or clearly give another actor investigative powers. So the paper trail may exist without the underlying record needed to reconstruct an incident. The analysis proposes retention duties and dedicated preservation units that could help investigators access and interpret evidence. Illinois also requires annual independent audits, while large developers must publish safety frameworks. Whether lawmakers add these deeper evidence and investigation requirements remains unresolved as the newer regimes approach their 2027 launch.

Story brief

3 key points

A Lawfare analysis identifies a missing layer in California, New York, and Illinois frontier-AI incident regimes: developers must notify authorities about narrowly defined, high-severity failures, but generally need not preserve the evidence needed to explain them. California’s system is active, while New York and Illinois begin in 2027. Without retention of models, weights, prompts, logs, and execution...

  1. 01

    California’s reporting mechanism began in 2026; New York and Illinois are scheduled to launch in 2027.

  2. 02

    Routine deadlines are 15 days in California and 72 hours in New York and Illinois; imminent serious risks trigger 24-hour reporting.

  3. 03

    Covered incidents include harmful unauthorized weight access, loss of model control, catastrophic-risk harm, and materially risk-increasing deception.

State laws are beginning to create a paper trail for the most serious frontier-AI failures. But a new Lawfare analysis argues that a report alone may not leave regulators with enough evidence to reconstruct an event or prevent its recurrence.

California’s SB 53, New York’s Responsible AI Safety and Education Act, and Illinois’s SB 315 require frontier developers to report specified critical safety incidents to state authorities. The largest covered developers, defined by revenue and high training-compute levels, must also publish AI safety frameworks; Illinois adds an annual independent audit requirement.

The laws set deadlines after an incident reaches a high threshold, not a general channel for every model problem. Covered events include unauthorized access to model weights causing death or bodily injury, catastrophic-risk harm, loss of model control causing death or injury, and deceptive behavior that materially increases catastrophic risk.

The gap begins after notification

The analysis focuses on the next step. It says the laws do not require developers to preserve the model, weights, execution environment, prompts, logs, or other material that could be needed to reconstruct an incident. If those records are not retained, the author argues, later investigators may be unable to establish what happened.

New York and Illinois require their report-receiving bodies to review submissions. Yet the analysis says none of the three regimes requires a developer to investigate an incident or explicitly gives another actor investigatory powers. That is a policy assessment of the statutes, not a current requirement for a new state investigative body.

A record built before the failure

  • Require developers to retain incident data so an event can be reconstructed later.
  • Require large frontier developers to establish dedicated units to preserve evidence.
  • Have those units help investigators access and interpret the preserved material.

Those proposals would move the state regimes beyond notification toward a system designed to support later examination. California is already operating its reporting mechanism, while New York and Illinois are scheduled to start in 2027. Whether lawmakers add retention or investigative duties remains unresolved.

Sources

  1. lawfaremedia.orgThe Forensic Gap in AI Safety Laws

Loading discussion...

Lawfare Analysis Calls for Evidence Rules in State AI Incident Reporting | Superpower Daily