On July 16, roughly 200 delegates, including Nobel laureates and former heads of state and government, signed a declaration in Rome calling for broad global governance of artificial intelligence. Ten days earlier, in Chicago, Illinois, Gov. J.B. Pritzker signed a law requiring large frontier AI developers to submit to independent annual audits. Pritzker’s act received less fanfare—but it may ultimately matter more for the way AI risks are regulated around the world.
The Illinois law joins earlier legislation passed in California and New York that, together, will impact every major AI developer in the United States. Collectively, these laws require AI companies to publicly document how they manage catastrophic risk, report safety incidents to state authorities, and, with Illinois’s new legislation, open their safety frameworks to external scrutiny.
On July 16, roughly 200 delegates, including Nobel laureates and former heads of state and government, signed a declaration in Rome calling for broad global governance of artificial intelligence. Ten days earlier, in Chicago, Illinois, Gov. J.B. Pritzker signed a law requiring large frontier AI developers to submit to independent annual audits. Pritzker’s act received less fanfare—but it may ultimately matter more for the way AI risks are regulated around the world.
The Illinois law joins earlier legislation passed in California and New York that, together, will impact every major AI developer in the United States. Collectively, these laws require AI companies to publicly document how they manage catastrophic risk, report safety incidents to state authorities, and, with Illinois’s new legislation, open their safety frameworks to external scrutiny.
These efforts show that, even without any comprehensive federal statute or international agreement, U.S. states have the power to meaningfully regulate AI. Most frontier AI developers are headquartered in California, and California law applies to any company doing business there. As other states copy and strengthen Sacramento’s regulations, the rule sets will increasingly function as national, even in some respects international, standards. And they may prove more enforceable—and even more open to democratic pressure—than the global grand bargains experts call for.
BREAK
The Rome Declaration is just one of many recent appeals for global AI governance. In his first encyclical, Magnifica Humanitas, Pope Leo XIV called for multilateral efforts to address AI. U.N. Secretary-General António Guterres recently called for worldwide controls, and last week more than 1,000 employees at leading AI companies signed a letter urging Washington to lead an international effort to curb AI’s rapid development.
But global efforts to regulate AI face strong geopolitical headwinds. In 2024, the United States and China produced a joint statement that decisions to use nuclear weapons should remain under human control, but nothing broader followed. Washington and Beijing have both organized their AI policies around outpacing the other. This July, 29 governments including Russia established the World Artificial Intelligence Cooperation Organization in Shanghai, signaling a Sinocentric counter to the United States’ Pax Silica AI coalition. Washington has also been reluctant to join some global efforts, refusing to sign a 2025 Paris summit declaration on AI ethics while Beijing did.
Efforts at the federal level in the United States are more promising but still limited. After many years of failed legislation, two bills were introduced in late July that would help create a national standard on AI. But both face a long road through Congress, not to mention a White House skeptical of AI regulation. Indeed, just last year the Trump administration directed the Justice Department to challenge state AI laws and, this spring, urged Congress to preempt those that conflict with federal policy. This month it completed a voluntary framework giving the government early access to frontier models before release, but the details remain undisclosed.
Yet AI regulation is moving ahead quickly at the state level. U.S. states passed 109 AI laws in the first six months of 2026 alone, following the passage of a similar number in 2025. And three laws in particular—California’s Senate Bill 53, New York’s RAISE Act, and Illinois’s AI Safety Measures Act—are doing something the international instruments propose but have not yet managed: placing binding obligations on the companies building the most capable, and risky, models.
This patchwork governance doesn’t obviate the need for federal or international intervention. But it does offer a valuable tool for concerned experts and citizens in the meantime.
[BREAK]
Patchwork governance—where multiple jurisdictions devise their own approaches to an issue—isn’t perfect. Born of ground-up local processes that reflect local concerns (and, sometimes, local color), it leaves gaps. Often messy, it is open to local contestation and revision, and frequently comes in for opprobrium from central authorities. Moreover, patchworks are frustrating for companies operating in multiple jurisdictions, who are asked to comply with a dozen rule sets at once.
But when it comes to AI, patchwork legislation is already producing binding rules, which are only growing stronger as they converge. In September 2025, California Gov. Gavin Newsom signed the Transparency in Frontier Artificial Intelligence Act, or simply SB 53. This legislation requires AI developers who train sufficiently powerful models to create public transparency reports with model data and report critical safety incidents to California’s emergency services office within 15 days, or 24 hours if the incident poses an imminent risk of death or serious injury. Developers with more than $500 million in yearly revenue must also create and publish “Frontier AI Frameworks” that outline how they plan to “manage, assess, and mitigate catastrophic risk.”
The bill is far from perfect. Its most stringent obligations fall on “large frontier developers”: the richest companies with the most compute-intensive models. Future models could achieve the same capabilities more efficiently, thereby falling below its metric for measuring power. The bill’s incident-reporting regime is also backward-looking: Developers don’t need to report incidents until harm has already occurred. (The one exception is that developers must report models that deceive them to evade oversight, something that has already occurred.) Furthermore, the bill does not require companies to meet any specific safety test before training or releasing a model. And its maximum civil penalty is just $1 million per violation—chump change for the companies it regulates.
In June last year, New York passed its own frontier AI bill: the Responsible AI Safety and Education (“RAISE”) Act. Gov. Kathy Hochul then worked to bring key RAISE provisions in line with SB 53, creating what she described as “a unified benchmark among the country’s leading tech states as the federal government lags behind.”
Like California, New York ended up diluting the regulatory ambitions it started with, shrinking penalties and altering its coverage thresholds to match California’s. It also abandoned a plan to prohibit developers from deploying models that posed “unreasonable risks of death or injury.” Yet despite these similarities, New York’s bill has tighter regulatory standards, especially on incident reporting. After January of next year, developers must report incidents within 72 hours, rather than 15 days. There is also a lower threshold for what must be reported; New York requires companies to act whenever they have a “reasonable belief” that an incident occurred. And Hochul announced the creation of a new office to receive company reports and further revise the act’s rule set, requesting $21 million for it in her 2027 budget.
Then, finally, Illinois. Its AI Safety Measures Act adopts the same coverage threshold as New York and California and adopts New York’s stricter 72-hour incident-reporting clock. It adds one crucial ingredient to the regulatory mix as well: an annual audit conducted by independent, third-party examiners, who must file a public summary of their work. This is the first requirement of its kind in U.S. law.
[BREAK]
Four mechanisms make the patchwork approach particularly promising in regulating AI. The first is geography: Most leading frontier AI developers are headquartered or have major operations in California. SB 53 covers not only them, but any firms that do business there. SB 53 therefore reaches far beyond the Golden State’s borders.
The second is the “Brussels effect”: Companies sometimes adhere to stringent regional regulations across their global operations to save the cost of regional customization. Apple, for example, switched to USB-C in all markets when the EU required common charging ports on portable electronic devices.
For some AI vendors, complying with the strictest rule set everywhere may be less costly than customization, particularly when the rule set governs a home market. Moving out of state would be costly, cutting a developer off from not only the market but California’s high concentration of human capital. And firms headquartered elsewhere would still want access to California’s market.
A third mechanism stems from the borderless nature of AI models themselves. SB 53 requires developers to publish transparency reports online and allows them to include the information in a “system” or “model card,” the standard device developers use to disseminate model information. The report is, in effect, borderless: Anyone can read and scrutinize it.
The last factor is emulation. Regulation addressing “companion” chatbots spread from California and New York in 2025 to more than a dozen states this year, split almost evenly between red and blue in their politics. Most of these efforts drew from the New York and California bills, creatively copying the parts they wanted and leaving the rest. Frontier transparency bills based on SB 53 have been introduced in Michigan and Utah. This horizontal convergence could also go vertical, providing federal or international legislators with a menu of best practices to choose from. Indeed, one of the two bills now introduced in Congress—the FRONTIER Act—draws its provisions on incident reporting, transparency, and independent audits from California, New York, and Illinois.
Patchwork has limits, of course. It only works if AI development is geographically concentrated and the states regulating it have important markets that companies cannot afford to ignore. Beyond that, the limit is the reach of the law itself, and that reach can be short. State law can’t regulate AI development in other countries, or what those models are used to build or do abroad. It cannot impose export controls on the advanced chips frontier models need, nor can it govern how AI is integrated into weapons systems, including nuclear ones. These are the kinds of risks the Rome Declaration, and the global governance it calls for, must address.
Despite these limitations, patchwork governance has already demonstrated the democratic control of AI in action. Global governance regimes are often negotiated at a distance from the people they affect and enforced by technocrats or other expert classes who are not elected. AI harms are local: Data centers spike energy prices in towns, teens are harmed by chatbots in communities, self-driving cars fail in neighborhoods. It’s at the local level where citizens can transform concern about those harms into leverage against the current constellation of interests—vendors, investors, and politicians—that still prioritizes power, profit, and production over public safety. Governance must start somewhere.


