California's frontier-AI safety bill is back. A revised AB 1047 has returned to committee with amendments that strip out the developer-liability clause Governor Newsom vetoed in 2024, refocusing the measure on compute thresholds and incident reporting rather than guarantees that a model is safe. The revival is the latest sign that, absent a national statute, US AI governance is being written state by state — and that the resulting patchwork is becoming an operational burden for companies rather than a distant compliance question.
What the Revised Bill Changes
The original AB 1047 foundered on a central objection: that requiring developers to guarantee their most powerful models would not cause catastrophic harm was both unworkable and a drag on innovation. The new version narrows its ambitions. Rather than demanding safety assurances, it leans on measurable triggers — thresholds tied to the compute used to train frontier systems — and on mandatory incident reporting when things go wrong.
That is a meaningful shift in philosophy. Compute thresholds and reporting requirements are concrete and auditable; sweeping liability for hypothetical future harm is neither. By trading aspiration for measurability, the revised bill stands a better chance of surviving the legislative process — and reflects a broader convergence toward risk-based frameworks built around transparency and accountability rather than open-ended guarantees.
A Country Without a Single Rulebook
The deeper story is structural. As of July 2026, the United States has no single comprehensive AI statute. Federal executive actions set a policy layer, but binding duties on the private sector sit mostly in state law. The result is a growing quilt of obligations:
- California, Texas, Illinois and Utah duties are already in force, each with its own definitions and requirements.
- Colorado's replacement framework is scheduled to begin in January 2027.
- New York's financial regulator published binding AI model-risk-management guidance for insurers on July 1, 2026, with a compliance deadline of January 1, 2027 for any insurer using AI in underwriting or claims.
For a company operating nationally, that means reconciling multiple, sometimes divergent regimes at once — a compliance map that has to be maintained state by state rather than referenced from a single source.
The Preemption Fight Overhead
Hovering above all of this is a federal preemption battle that could reshape the entire landscape. A proposed measure would preempt state laws that impose disclosure requirements "inconsistent with" federal standards and create a limited safe harbor for companies that adopt a recognized federal risk-management framework.
The stakes are high and the outcome uncertain. State attorneys general are already challenging the "inconsistent with" language as unconstitutionally vague. If preemption passes, state-level compliance maps built over the last 18 months may need to be substantially rebuilt; if it fails, the patchwork hardens. Either way, businesses face a period of instability in which the rules governing their AI systems could shift depending on a single vote.
The Global Backdrop
The American fragmentation contrasts with movement abroad, where deadlines are firm and enforcement is beginning:
- The European Union's August 2 deadline is real and imminent, tightening obligations on general-purpose and higher-risk systems.
- South Korea has begun enforcement of its AI framework.
- Japan's trade ministry published revised governance guidelines adding specific requirements for AI used in government procurement, with a compliance horizon in 2027.
Analysts note a striking convergence in language across these very different legal traditions — risk-based tiers, transparency mandates and accountability structures recurring worldwide. July 2026, in this reading, is when that convergence stops being theoretical and becomes operational pressure on real deployments.
Why It Matters
For anyone building or deploying AI in the United States, the message is that governance can no longer be treated as a future problem. Obligations are already in force in multiple states, more take effect in 2027, and a federal fight could upend the map at any time. The revived AB 1047, with its shift toward compute thresholds and incident reporting, hints at where durable regulation is heading — measurable, auditable requirements rather than broad guarantees.
The practical response is to build for the strictest applicable regime and to instrument systems for transparency and incident reporting now, regardless of which bills ultimately pass. Companies that treat compliance as core engineering — logging, documentation, clear accountability — will absorb whatever emerges with far less disruption than those waiting for the dust to settle. In 2026, the dust is not settling; it is being kicked up in a dozen capitals at once.
