AI LAW RADAR · Daily Last verified 22 Aug 2026

Topic dossier

Frontier & general-purpose AI obligations

The rules aimed at foundation-model and frontier developers — safety frameworks, incident reporting and model documentation. 13 obligations across 6 jurisdictions — 7 in force, 1 proposed. Next dated deadline: 1 Oct 2026.

A distinct regulatory track targets the largest models rather than specific uses. It splits into model-documentation duties for general-purpose AI (GPAI) and safety-and-incident regimes for frontier developers above a capability or compute threshold. The EU AI Act covers GPAI; California’s SB 53 and New York’s RAISE Act lead on frontier safety in the US. The instruments below make up this track.

The Register

13 obligations · 6 jurisdictions

Canada 1

Canada Proposed

Federal AIDA (Bill C-27) — abandoned

Binds Would have bound high-impact & general-purpose AI — never enacted. Would have set high-impact / GPAI duties; died on prorogation Jan 2025 and was not reintroduced.

Abandoned — died on prorogation Jan 2025; AIDA itself not reintroduced. A separate federal bill, C-36 (Protecting Privacy and Consumer Data Act, 45th Parliament), containing AI-transparency provisions (e.g. disclosure for automated/algorithmic tools) had first reading 15 Jun 2026 and is at second reading as of 2026-08-11 (https://www.parl.ca/legisinfo/en/bill/45-1/c-36) — not yet enacted; it is a privacy-law vehicle, not an AIDA-style comprehensive AI act.

Proposed checked 13 Aug 2026 AIDA (Bill C-27) ↗ high confidence

China 1

China Binding

Generative AI Interim Measures

Binds Providers of public-facing generative AI services in mainland China. Security assessment, algorithm filing and content controls for public-facing GenAI services.

Stated maximum penalty — Rectification, suspension, criminal referral

In force · 15 Aug 2023 checked 17 Aug 2026 CAC GenAI Interim Measures ↗ high confidence

European Union 4

EU Comprehensive

GPAI model provider obligations (Art. 53) — docs, copyright policy, training summary

Binds Providers of general-purpose AI models. Technical documentation (Annex XI), downstream-provider information (Annex XII), a copyright-and-related-rights policy identifying Art. 4(3) DSM rights reservations, and a public summary of training content on the AI Office template.

Stated maximum penalty — Up to 3% turnover or €15M

In force · 2 Aug 2025 checked 17 Aug 2026 EU AI Act ↗ high confidence
EU Comprehensive

GPAI enforcement & fines (Art. 101)

Binds GPAI model providers (enforced by the Commission / AI Office). Commission may fine GPAI providers; supervision powers begin.

Stated maximum penalty — Up to 3% global turnover or €15M

In force · 2 Aug 2026 checked 17 Aug 2026 EU AI Act ↗ high confidence
EU Comprehensive

EU AI Act — GPAI Enforcement Procedures Implementing Regulation (EU) 2026/1755

Binds General-Purpose AI (GPAI) model providers whose models are placed on the EU market or whose services are used in the EU. Binding procedural rules activating Commission enforcement against GPAI model providers: (1) providers must grant Commission technical access to models on demand — including APIs, source code, weights, and infrastructure — for AI Act evaluations under Art. 92; (2) detailed proceedings rules for investigations leading to Art. 99–101 fines, including rights of defence, 21-day minimum observation period, oral hearings, and 5-year limitation period. All communications require qualified electronic signatures.

Adopted 20 July 2026; published OJ L 2026/1755 on 21 July 2026; entered into force on the twentieth day following publication, i.e. 10 August 2026, per Art. 12 of the Regulation. IN FORCE since 2026-08-10. Procedural safeguards for GPAI enforcement proceedings under Art. 101 of Reg. (EU) 2024/1689 are now operative; the Commission's substantive GPAI enforcement powers themselves applied from 2 August 2026. No provision of this implementing regulation is deferred to a later date.

Stated maximum penalty — Implementing regulation activates fines under Art. 99-101 of Reg. (EU) 2024/1689: up to 3% of global annual turnover for GPAI providers (Art. 101(3)); up to 1% for false/misleading information

In force · 10 Aug 2026 checked 17 Aug 2026 Reg. (EU) 2026/1755 ↗ high confidence
EU Comprehensive

GPAI models placed on the market before 2 Aug 2025 — legacy compliance deadline (Art. 111(3))

Binds Providers of general-purpose AI models placed on the EU market before 2 August 2025. The AI Act's GPAI duties bite on legacy models on 2 August 2027: general-purpose AI models placed on the EU market before 2 August 2025 have until that date to be brought into line with the Regulation. Until then, legacy models sit outside the Chapter V obligations that have bound newly placed models since 2 August 2025.

Article 111(3) of Regulation (EU) 2024/1689, unchanged by the Digital Omnibus on AI: Regulation (EU) 2026/1744 Article 1(39) amends only Article 111(2) (replaced) and adds Article 111(4) (synthetic-content marking retrofit, 2 Dec 2026) — paragraph 3 and its 2 August 2027 date are untouched (OJ L, 24.7.2026). This is the counterpart to the GPAI duties that bound new models from 2 August 2025 (Art. 53, Annex XI/XII, copyright policy, training-data summary) and to Commission enforcement powers live since 2 August 2026 (Art. 101). Scope is the model, not the system: a legacy model that is substantially modified is treated as newly placed on the market and loses the grace period.

Stated maximum penalty — Up to 3% turnover or €15M

Applies 2 Aug 2027 checked 17 Aug 2026 EU AI Act Art. 111(3) ↗ high confidence

Russia 1

Russia Binding

243-FZ art. 8 — three developer duties that attach only once a model takes sovereign or national status

Binds Russian individual entrepreneurs and legal persons that develop, design, train or modify a large foundational AI model within art. 3(5) and whose model has been granted sovereign and (or) national status under the procedure art. 6(5) leaves to the Government. Developers of large foundational models without that status, and foreign developers, are outside art. 8. The separate power in art. 5(2)(3) for the Government to designate cases in which only sovereign and (or) national models may be applied — for banking and other financial-market spheres in agreement with the Central Bank — is what can make the status commercially necessary rather than optional in a given sector.. Art. 8 is the closest thing Russian law has to a foundation-model developer obligation, and its chapeau is what decides how far it reaches: the duties are imposed on «разработчик суверенной и (или) национальной больших фундаментальных моделей искусственного интеллекта» — the developer of a sovereign and (or) national large foundational model — and not on developers generally. Sovereign and national status is conferred, not assumed: art. 6(5) leaves the Government to set the procedure for recording models and assigning the status, art. 6(2) makes a sovereign model one whose developer is a Russian legal person, whose development and characteristics are determined by that Russian legal person across the whole lifecycle, whose development cycle including training is fully technically reproducible, whose user queries are answered and whose data are stored in data centres located in Russia and belonging to Russian legal persons, and which has passed confirmation of conformity with Russian legislation and with traditional Russian spiritual and moral values in a procedure to be established by the Government; art. 6(3) defines a national model on similar lines but requires only that the Government-specified essential characteristics be determined by the Russian developer and that externally sourced components, including other developers' models, be distributed under an open licence. Art. 6(4) supplies the control test for what counts as a Russian legal person, at more than fifty per cent of the votes. Against that background art. 8 requires the status-holding developer to take organisational and technical measures to secure the model, to define rules of operation setting the limits and conditions of its application, updating and decommissioning, and to keep technical documentation describing the model's key parameters and limitations to the extent needed to assess the safety of its application. The duties are the counterpart of the art. 7 package of state support, access to state data sets for training under art. 5(2)(5) and the art. 10(2) training exception, so in substance this is a conditional regime a developer opts into rather than a horizontal safety obligation of the EU AI Act general-purpose kind. The consequence worth recording is the negative one: a developer of a large foundational model that does not hold either status carries none of the art. 8 duties.

Art. 8 is deferred by art. 13(2) to 1 March 2027, together with art. 9, art. 10, art. 5(2) points 3 to 5 and art. 6 parts 2 to 5, even though art. 13(1) puts the Law itself in force on 1 September 2026. Two further timing points sit on the face of the Law. The conformity-confirmation procedure required by art. 6(2)(5) and art. 6(3)(5) and the status-assignment procedure required by art. 6(5) are both left to Government acts that had not been made as at 21 August 2026, so the gateway to art. 8 is not yet operable. And art. 13(3) grandfathers information systems in which large foundational models were created or operated on the day art. 5(2)(3) commences: until 1 September 2032 the cases where only sovereign or national models may be applied do not extend to them, provided the data are processed and stored in Russia. Adopted 8 July 2026, approved by the Federation Council 17 July 2026, published 26 July 2026 as 0001202607260003, Собрание законодательства РФ 2026 No. 30 item 4089, «Российская газета» of 31 July 2026.

Stated maximum penalty — None is stated in the Law. Art. 11 refers to «законодательство Российской Федерации» without more, and the Code of Administrative Offences carried no article on large foundational AI models as at 21 August 2026. The practical sanction visible on the face of the Law is administrative rather than pecuniary: sovereign and national status is assigned and recorded by the Government under art. 6(5), so the loss of that status, and with it the art. 7 support measures, the art. 5(2)(5) access to state data sets for training and the art. 10(2) training exception, is what a failure of the art. 8 duties puts at risk.

Applies 1 Mar 2027 checked 21 Aug 2026 243-FZ art. 8 ↗ high confidence

Singapore 1

Singapore Binding

Singapore MAS — Agentic AI in Scope of Supervisory Expectations (binding AI Risk Management Guidelines pending)

Binds MAS-regulated financial institutions (banks, insurers, payment service providers, capital market intermediaries) using autonomous AI agents in Singapore. MAS's 5 Aug 2026 parliamentary reply states existing supervisory expectations already extend to AI agents used by financial institutions, and that MAS will continue to review and update these as needed. The binding instrument — MAS's proposed AI Risk Management Guidelines (consultation paper 13 Nov 2025) — remains in consultation, with a 12-month compliance transition once issued but no MAS-confirmed issuance date. Separately, MAS published a voluntary industry paper, SAFR (Safeguards for Agentic Finance at Runtime), on 3 Jul 2026 — SAFR itself is not binding.

MAS parliamentary reply (5 August 2026) by Deputy Prime Minister and MAS Chairman Gan Kim Yong states existing supervisory expectations (via tech-risk frameworks) already extend to AI agents; the reply's own language is that MAS will "continue to review... and update where necessary," not a declaration that a codified binding rule for agentic AI already exists. The binding track is MAS's proposed AI Risk Management Guidelines (consultation paper of 13 Nov 2025, para 4.7: 12-month transition period proposed after the Guidelines are issued); those Guidelines remain in consultation with no MAS-confirmed finalization date (Q4 2026 is market/analyst expectation, not a MAS commitment). SAFR (Safeguards for Agentic Finance at Runtime), published 3 July 2026, is an industry-led voluntary information paper, distinct from and not itself the binding Guidelines.

Stated maximum penalty — MAS administrative sanctions under financial institution licensing (no specific penalty quantum in parliamentary reply)

In force · 5 Aug 2026 checked 20 Aug 2026 MAS AI Risk Management Guidelines (proposed) / SAFR (voluntary) ↗ medium confidence

United States 5

US · CA Binding

SB 53 — Frontier AI Transparency Act

Binds Frontier AI developers (>1e26 training ops); large frontier developers (>$500M revenue). Safety frameworks + critical-incident reporting to Cal OES for frontier developers.

Stated maximum penalty — Up to $1M per violation

In force · 1 Jan 2026 checked 13 Aug 2026 SB 53 (TFAIA) ↗ high confidence
US · CA Binding

AB 2013 — GenAI training-data transparency

Binds Developers of generative AI systems made available to Californians. Public dataset-summary disclosure for generative AI offered to Californians.

Stated maximum penalty — Civil enforcement

In force · 1 Jan 2026 checked 13 Aug 2026 AB 2013 ↗ high confidence
US · CT Binding

Connecticut PA 26-15 (SB 5) tranche 1 — subscription AI, frontier models, synthetic content, state agencies

Binds Subscription-based AI providers, frontier developers, generative AI providers with >1,000,000 monthly users publicly accessible for personal use, and CT state agencies. Subscription-based AI providers give consumer disclosures; frontier developers publish safety frameworks; large generative providers embed provenance data; state agencies gated on OPM/DAS AI policies.

Public Act No. 26-15, signed by the Governor 27 May 2026. This row carries the 1 Oct 2026 tranche: s 1 (subscription-based provider disclosures), s 2 (frontier developer duties), s 15 (covered provider provenance/detectability of synthetic digital content, >1,000,000 monthly users), s 38 (state agency AI use and procurement). The Act's later tranches are carried as separate rows: AI companions 1 Jan 2027 (us-ct-sb5-companion), automated employment-related decision technology 1 Oct 2027 (us-ct-sb5-aedt), covered-platform minors 1 Jan 2028 (us-ct-sb5-minors). Sections 17, 18, 31 (AI Academy, working group, higher-education alliance) took effect 1 Jul 2026 but create state-programme duties only, not private-sector obligations. Bill status page: https://www.cga.ct.gov/asp/cgabillstatus/cgabillstatus.asp?selBillType=Bill&bill_num=SB5&which_year=2026

Stated maximum penalty — CT Attorney General — unfair or deceptive trade practice under Conn. Gen. Stat. s 42-110b(a)

Applies 1 Oct 2026 checked 22 Aug 2026 CT PA 26-15 (SB 5) ↗ high confidence
US · NY Binding

RAISE Act — frontier AI safety

Binds Large frontier developers (>1e26 ops, >$500M revenue) operating in New York. Safety/security protocols + 72h critical-incident reporting to NYDFS; AG enforces civil penalties.

The RAISE Act as originally signed 19 December 2025 (Ch. 699) was superseded by a chapter amendment, S8828 (Ch. 96), introduced 6 Jan 2026 and signed by Governor Hochul 27 March 2026. The amendment shifted rulemaking and incident-report oversight from the Division of Homeland Security and Emergency Services to a new office within the NY Department of Financial Services (DFS), and set the effective date at 1 January 2027.

Stated maximum penalty — Up to $1M / $3M

Applies 1 Jan 2027 checked 22 Aug 2026 RAISE Act (S6953-B/A6453-B, as amended by S8828) ↗ high confidence
US · IL Binding

Illinois Artificial Intelligence Safety Measures Act (SB 315 / PA 104-0538)

Binds Large frontier AI developers (>$500M revenue, trained on massive compute) operating in Illinois. Large frontier AI developers must publish safety frameworks, annual third-party audits, and report critical incidents within 72 hours.

Signed 2026-07-06.

Stated maximum penalty — Up to $1M first offense; up to $3M subsequent violations

Applies 1 Jan 2027 checked 22 Aug 2026 SB 315 / PA 104-0538 ↗ high confidence

Questions & answers

From the data

What is GPAI under the EU AI Act?

General-purpose AI — a model that can perform a wide range of tasks and be integrated into many downstream systems. Providers must keep technical documentation, publish a training-content summary and, for models posing systemic risk, meet additional safety and reporting duties.

What do frontier-AI safety laws require?

Published safety frameworks and mandatory reporting of critical incidents. California’s SB 53 requires frontier developers to report incidents to Cal OES; New York’s RAISE Act requires security protocols and 72-hour incident reporting.

Is there a US federal frontier-AI law?

No comprehensive one. Frontier-specific obligations are currently state-led — California’s SB 53 and New York’s RAISE Act — while federal action remains limited to executive measures and sector rules.

Which jurisdictions does AI Law Radar track for frontier & general-purpose ai?

We currently track frontier & general-purpose ai obligations across 6 jurisdictions: Canada, China, European Union, Russia, Singapore and United States. Each is dated and linked to its primary source on this page.