Analysis
Massachusetts is on track to adopt the strictest state-level artificial intelligence safety law in the country, and the two labs it would regulate most directly -- Anthropic and OpenAI -- have taken opposite public positions on whether it should pass, Bloomberg reported Thursday. An economic development bill the state Senate passed in July includes a requirement that leading AI labs submit their frontier models to independent third-party reviews of catastrophic risks -- broadly defined as incidents that could kill or injure at least 50 people or cause more than $1 billion in property damage -- on a roughly 120-day cadence, on top of a broader annual compliance review. Governor Healey's office has separately been courting AI companies to build in the state even as this bill would regulate them more tightly than any other state currently does.
## What the bill actually requires The Massachusetts proposal borrows its basic structure from Illinois, which Governor JB Pritzker signed into law in July 2026 requiring AI developers to submit to an annual third-party audit. Massachusetts goes further on two fronts: it adds the more frequent catastrophic-risk review cycle on top of the annual audit, and it gives third-party reviewers explicit authority to focus on models capable of causing mass-casualty or mass-property-damage events rather than auditing for general compliance alone. Neither bill specifies a regulator with enforcement teeth comparable to, say, a banking regulator's supervisory authority -- the reviews are disclosure-and-audit mechanisms, not pre-market approval gates, which is itself part of what OpenAI and Anthropic are fighting over.
## Anthropic's bet on being the safety-first lab Anthropic retained Boston-based lobbying firm Tremont Strategies Group earlier this year, and Cesar Fernandez, the company's head of US state and local government relations, praised the bill directly: "We applaud the Massachusetts Senate for passing the clearest and strongest AI safety legislation in the country." That stance is consistent with how Anthropic has positioned itself against OpenAI on the enterprise side -- Pulse previously covered how Anthropic's slower, more conservative data-retention policies have become a selling point against OpenAI with security-conscious enterprise buyers. Backing binding state safety reviews is the regulatory version of the same pitch: if you're trying to win customers on trust, publicly welcoming outside scrutiny of your own models is a differentiator, not just a compliance cost.
“## OpenAI's bet on federal uniformity OpenAI hired lobbying shop Benchmark Strategies to push the opposite case.”
## OpenAI's bet on federal uniformity OpenAI hired lobbying shop Benchmark Strategies to push the opposite case. Donnie Fowler, OpenAI's head of US state policy and partnerships, said an inconsistent state-by-state approach "just means confusion," PYMNTS reported, and the company has argued specifically that a 120-day catastrophic-risk review cycle could slow the release of cybersecurity-focused models -- tools meant to help defend against attacks -- at the exact moment attackers are moving fastest. OpenAI has floated Illinois's lighter, annual-only audit requirement as the standard it would rather see other states copy, rather than Massachusetts's stacked annual-plus-120-day structure.
## Why this matters beyond two companies Every additional state that legislates its own AI safety-review cadence adds a distinct compliance obligation for any lab operating nationally, and the frontier labs are not the only ones exposed -- any startup fine-tuning or deploying a covered model inside Massachusetts inherits some version of this reporting burden through its vendor contracts. A fragmented 50-state patchwork of review cycles, thresholds, and audit formats is a genuinely different cost structure than one federal standard, and it's the kind of compliance overhead that favors incumbents with in-house policy teams over smaller AI-native startups that can't staff a state-by-state legal function.
What the coverage of this fight tends to skip is that the bill still has to clear the Massachusetts House and get Governor Healey's signature before any of this takes effect, and it's not yet public what enforcement penalties -- if any -- attach to a lab that skips or fails a review. A bill lawmakers are racing to pass before a November election is also, by definition, moving on a political timeline rather than a technical one, which means the final catastrophic-risk threshold and review cadence could still shift in conference before it's law.
Watch whether other states use Massachusetts's language as a template the way California's privacy law became a template after it passed -- that's the mechanism by which one state's bill becomes a de facto national standard regardless of what Congress does.