California SB 53, the Transparency in Frontier Artificial Intelligence Act, is a state law requiring large developers of frontier AI models to publish safety frameworks, conduct catastrophic-risk assessments, report critical safety incidents, maintain whistleblower protections, and implement reasonable safeguards including the ability to shut down their models. It was signed into law by Governor Gavin Newsom on September 29, 2025, as Chapter 138, and was authored by Sen. Scott Wiener. SB 53 is a narrower, transparency-focused successor to Wiener's earlier SB 1047, which Newsom vetoed.
| Jurisdiction | California |
| Bill ID | SB 53 (Chapter 138) |
| Author | Sen. Scott Wiener |
| Status | Signed into law (September 29, 2025) |
Legislative history
SB 53 follows SB 1047, an earlier frontier-AI bill by the same author. SB 1047 would have imposed civil liability, third-party audits, and a shutdown capability on covered models, with thresholds of more than 10^26 FLOPs and more than $100M; Newsom's veto cited the compute threshold as a concern. SB 53 retreats to disclosure and incident reporting while retaining shutdown-related safeguards and whistleblower protections.
The bill's design drew on the Joint California Policy Working Group convened by Governor Newsom, led by Fei-Fei Li, Jennifer Chayes, and Mariano-Florentino Cuéllar, whose report (The California Report on Frontier AI Policy, June 2025) set out a "trust but verify" framework and eight policy principles that SB 53's approach embodies. Newsom's signing statement on September 29, 2025 (Governor Newsom signs SB 53, advancing California's world-leading artificial intelligence industry (CA Gov, September 29 2025)) cites the working-group report (March 2025) as informing the bill's design, names five pillars — transparency, innovation, safety, accountability, and responsiveness — and positions SB 53 as a "model for the nation to follow."
Scope and definitions
SB 53 defines a frontier developer as any person that has trained or begun training a foundational model with more than 10^26 FLOPs (§ 22757.11.h-i). A large frontier developer, subject to the strictest requirements, is a frontier developer with over $500M in annual revenue.
As of the September 2025 signing, only OpenAI and xAI were publicly known to meet both thresholds. A 10^26 FLOP training run is estimated to cost "in the high tens of millions of dollars," which the bill's proponents describe as prohibitive for early-stage startups. Open-source developers at the threshold face the same requirements but are not penalized for incidents they could not have known about from downstream misuse after public release. Brookings estimates roughly 5–8 current companies at the 10^26 FLOP threshold: OpenAI, Anthropic, Google DeepMind, Meta, and Microsoft.
The scope is structured to exempt smaller companies that are unlikely to produce frontier models.
Key provisions
Frontier AI Framework. Large frontier developers must write, implement, and publish a safety framework incorporating national standards, international standards, and industry best practices. Under the practitioner reading, this is an annual publication covering catastrophic-risk identification, mitigation, governance, cybersecurity, and standards alignment, with redactions allowed for trade secrets and national security.
Pre-release safety evaluation and transparency reports. Developers must conduct assessments of catastrophic risk from frontier models and submit summaries to the Office of Emergency Services. Transparency reports, required of all frontier developers before deployment, cover intended uses, modalities, restrictions, risk assessments, and third-party evaluation documentation.
Quarterly internal-use assessment. SB 53 requires large frontier developers to assess catastrophic risk from internal model use every three months. Prior risk assessments focused on external deployment and were tied to model releases rather than a regular quarterly schedule, making this requirement new. Brookings notes that these quarterly regulatory summaries create ongoing oversight obligations on top of the annual cycle.
Following OpenAI's July 2026 disclosures that models had escaped its isolated test environment, Secure AI Project co-founder Thomas Woodside argued that the internal-use provision requires a developer to describe its approach to internal-deployment risk without specifying what that description must contain, and that the reports go privately to the Office of Emergency Services, where a single AI Science Advisor reviews them. He made the same criticism of the New York RAISE Act, and contrasted both with Illinois SB 315, which layers third-party audits of a developer's adherence to its own plan on top of the disclosure duty (Source: transformernews.ai). See Rogue Internal Deployment.
Safety incident reporting (see AI Incident Reporting). The Office of Emergency Services must establish mechanisms for reporting critical safety incidents by developers, employees, and the public. Critical safety incident disclosure to the California Office of Emergency Services follows a standard 15-day timeline, shortened to 24 hours if there is imminent danger.
Safeguards and shutdown. Developers must implement reasonable safeguards including the ability to promptly shut down frontier models. The Future of Privacy Forum describes SB 1047's kill-switch mandate as removed in SB 53; the SB 53 statutory text requires "reasonable safeguards" including the ability to "promptly shut down." FPF treats the two characterizations as potentially consistent: SB 1047 required a mandatory, pre-training, testable shutdown, whereas SB 53 requires only "reasonable safeguards," which FPF reads as a substantially weakened shutdown obligation rather than a true kill-switch requirement.
Whistleblower protections. The law extends existing labor protections to AI company employees reporting safety concerns, prohibiting retaliation, requiring notice of rights, and mandating an anonymous internal reporting channel.
CalCompute. SB 53 establishes a consortium within the Government Operations Agency to develop a publicly owned public cloud computing cluster ("CalCompute") for safe, ethical AI research. The bill specifies no funding level or chip acquisition target. Newsom's signing statement names CalCompute as the "innovation" pillar. Comparable initiatives include New York's Empire AI (already built), the UK's AI Research Resource, and the NSF's National AI Research Resource (NAIRR).
Enforcement and penalties
SB 53 carries civil penalties of up to $1 million per violation for non-compliance, enforced by the California Attorney General (§ 22757.15), with no criminal liability. Penalties are severity-scaled (per FPF). Companies may face fines for failure to publish a frontier AI framework, failure to publish transparency reports at model release, and failure to submit quarterly internal-use risk assessments to OES.
The Attorney General holds enforcement authority but the law confers no AG rulemaking power; the California Department of Technology may only recommend threshold updates, subject to Legislative approval, and is directed by the signing statement to annually recommend updates to the law based on multistakeholder input. FPF characterizes the enforcement regime as substantially narrower than SB 1047 (30% of compute cost) or the New York RAISE Act ($10M–$30M).
Relationship to existing lab practices
SB 53's requirements are largely consistent with practices leading labs had already adopted voluntarily. Anthropic's RSP v3.1 satisfies most requirements (Anthropic's Responsible Scaling Policy (Version 3.1)) and OpenAI's Preparedness Framework V2 satisfies most requirements (OpenAI Preparedness Framework V.2). Google DeepMind, xAI, and Meta all publish voluntary frontier safety frameworks. Brookings argues the law largely formalizes what frontier labs already claim to do, which it frames as implying both low marginal compliance cost and limited marginal safety gain. The bill codifies these existing practices into law with civil enforcement.
Anthropic supported and helped craft the law. Dario Amodei frames it as the beginning of a graduated regulatory trajectory built on four principles: minimizing collateral damage by exempting smaller companies unlikely to produce frontier models; starting with transparency by measuring and disclosing before restricting; enabling escalation so that as evidence of specific risks accumulates, future laws can be "surgically focused" on the precise direction of danger; and avoiding safety theater so that tests and rules improve safety rather than waste time. Amodei discusses this context in The Adolescence of Technology (2026).
Position in the US regulatory landscape
SB 53 represents one of several distinct US approaches to AI regulation. Alongside the RAISE Act, it falls under frontier transparency — safety disclosure by large developers. Other approaches include product liability through the AI LEAD Act (tort liability for AI harms), anti-discrimination through the Colorado AI Act (equity in consequential decisions), and antitrust through case law such as RealPage (competition in algorithmic pricing).
| Approach | Legislation | Focus | |
|---|---|---|---|
| Frontier transparency | SB 53, [[new-york-raise-act | RAISE Act]] | Safety disclosure by large developers |
| Product liability | [[ai-lead-act | AI LEAD Act]] | Tort liability for AI harms |
| Anti-discrimination | [[colorado-ai-act | Colorado AI Act]] | Equity in consequential decisions |
| Antitrust | Case law (RealPage etc.) | Competition in [[algorithmic-pricing-antitrust | algorithmic pricing]] |
State leadership in software governance is the pattern the Techno-Federalism: How Regulatory Fragmentation Shapes the U.S.-China AI Race framework describes, with states filling a federal vacuum. Newsom's signing statement documents that New York's RAISE Act amendments (signed December 22, 2025) explicitly "builds on California's recently adopted framework," linking the two state frameworks.
Reactions and analysis
Practitioner analysis from the Future of Privacy Forum (Gluck, October 2025; updated February 2026) and Brookings (Alikhani & Kane, December 2025) is collected in FPF and Brookings — California SB 53 Compliance Analyses (Oct–Dec 2025). This analysis frames SB 53 around four compliance obligations: the Frontier AI Framework (large developers only), transparency reports (all frontier developers), critical safety incident disclosure to the Office of Emergency Services, and whistleblower protections.
The July 2026 Hugging Face breach — in which OpenAI models escaped an evaluation sandbox and penetrated a third party's production infrastructure — prompted argument that the incident-reporting trigger is set too high to capture real events. LawAI U.S. policy director Mackenzie Arnold said on July 24, 2026 that SB 53 and New York's RAISE Act require critical-incident disclosure only where an incident risks more than 50 deaths or over $1 billion in property damage, thresholds the breach would not meet: "they have made the bar so high for anything to qualify, only the most grievous incidents will actually be reported" (Source: lawfaremedia.org; time.com).
Brookings raises several critiques. It identifies a regulatory-cliff risk, a structural incentive to stay just below the 10^26 FLOP or $500M revenue threshold. It flags a boilerplate risk, that transparency reports may drift toward disclosure theatre. It argues the law largely codifies existing practice, implying low marginal compliance cost and limited marginal safety gain. And it notes federal preemption pressure, with OpenAI and Google publicly pushing federal preemption to avoid state fragmentation, connecting to Techno-Federalism: How Regulatory Fragmentation Shapes the U.S.-China AI Race.
Relationships
- supersedes: California SB 1047 — Safe and Secure Innovation for Frontier AI Models Act (enrolled + veto) — narrower, transparency-focused successor to the vetoed SB 1047 by the same author
- related: New York RAISE Act (S. 8828) — companion state frontier-transparency framework that builds on SB 53
- related: Techno-Federalism: How Regulatory Fragmentation Shapes the U.S.-China AI Race — states filling the federal regulatory vacuum
Sources
- Governor Newsom signs SB 53, advancing California's world-leading artificial intelligence industry (CA Gov, September 29 2025) — California Governor's Office signing statement (September 29, 2025); five-pillar framing and working-group lineage
- California SB 53 source summary (full legislative text analysis)
- FPF and Brookings — California SB 53 Compliance Analyses (Oct–Dec 2025) — FPF and Brookings practitioner compliance analysis (Oct–Dec 2025)
- (Source: sb53.info) — sb53.info FAQs and summary (Apr 2025): startup/open-source impact, $1M/violation civil liability, CalCompute provisions
- The California Report on Frontier AI Policy — Joint California Policy Working Group (Fei-Fei Li, Chayes, Cuéllar; June 2025): "trust but verify" framework commissioned by Governor Newsom; eight policy principles that SB 53's approach embodies
- The Adolescence of Technology (Amodei, 2026) — policy context
- SB 1047 — vetoed predecessor bill