California SB 1047 was a frontier-AI safety bill authored by Sen. Scott Wiener (D-San Francisco) that would have required developers of large covered models to adopt written safety protocols, build full-shutdown capability, undergo third-party audits, report safety incidents, and face civil penalties. It passed both chambers of the California State Legislature and was vetoed by Governor Gavin Newsom on September 29, 2024. A narrower transparency-focused successor, California SB 53 — Transparency in Frontier AI Act, by the same author, was signed into law one year later on September 29, 2025.
| Jurisdiction | California |
| Bill ID | SB 1047 (2023–2024 session) |
| Author | Sen. Scott Wiener (D-San Francisco); co-authors Roth, Rubio, Stern |
| Enacting body | California State Legislature (both chambers passed) |
| Effective date | Would have been Jan 1, 2026 (audit start); vetoed Sept 29, 2024 |
| Status | Vetoed |
Status and timeline
SB 1047 was introduced in the 2023–2024 California legislative session. It passed both chambers of the California State Legislature. Its third-party audit requirement was set to begin January 1, 2026 had it taken effect. Governor Newsom vetoed the bill on September 29, 2024. One year later, on September 29, 2025, the same author's narrower successor, California SB 53 — Transparency in Frontier AI Act, was signed into law.
Scope and definitions
A Covered Model (§ 22602) was defined by training thresholds. Before January 1, 2027, a model trained with more than 10²⁶ FLOPs and more than $100M in cloud-compute cost qualified. After January 1, 2027, the thresholds would be revised by the Government Operations Agency. Derivative models — fine-tunes using more than 3×10²⁵ operations and more than $10M — were also covered.
Critical Harm covered CBRN mass-casualty events; cyber damage of $500M or more on critical infrastructure; comparable harms from AI acting with limited human oversight; and other comparably grave harms.
Key provisions
Pre-training duties (§ 22603)
Before training a covered model, a developer was required to implement cybersecurity protections for model weights and full-shutdown capability, and to write a Safety and Security Protocol (SSP) documenting protections, shutdown conditions, and derivative-testing procedures. The developer had to retain the unredacted SSP for the model lifetime plus five years, publish a redacted copy, and provide the unredacted copy to the Attorney General on request. The SSP was subject to annual review. The bill set a reasonable-care standard and required a senior compliance officer.
Pre-commercial-use duties
Before commercial use, a developer had to assess whether the model could enable critical harm, retain test-replication records, implement safeguards, and ensure attributability. Release was prohibited if the model posed an "unreasonable risk" of enabling critical harm.
Annual third-party audit (§ 22603(e))
An independent compliance audit was required, starting January 1, 2026.
Reporting
Reporting obligations included a CTO-signed annual compliance statement, 72-hour AI safety incident reporting to the Attorney General, and an initial statement within 30 days of first commercial deployment.
Computing-cluster operator duties (§ 22604)
Operators were required to apply know-your-customer procedures for customers using compute sufficient to train a covered model, covering identity, business purpose, IP addresses, and shutdown capability, with 7-year retention and annual revalidation.
Penalties (§ 22606)
Penalties reached up to 10% of training-compute cost for a first violation and 30% for subsequent violations. The bill allowed injunctive, monetary, and punitive damages, set a $10M aggregate cap on computing-cluster-operator penalties, and permitted corporate-veil piercing.
Whistleblower protections (§ 22607)
Developers could not block disclosures to the Attorney General or Labor Commissioner. The bill required internal anonymous reporting channels and extended Labor Code § 1102.5 protections.
Board of Frontier Models (§ 11547.6)
The bill established a 9-member board, to be seated by 2026 within the Government Operations Agency, with members drawn from open-source, industry, AI safety, academic, and CBRN expertise. The board would set annual threshold updates and auditing standards and issue guidance aligned with the federal AI Safety Institute.
CalCompute (§ 11547.6.1)
CalCompute was a public-cloud consortium centered on the University of California. It was never funded after the veto.
Newsom veto
Governor Newsom vetoed SB 1047 on September 29, 2024, citing the bill's regulatory design rather than jurisdictional grounds. His stated reasoning held that compute-threshold triggers give a false sense of security, because smaller specialized models can also be dangerous, and that the bill ignored risk context by applying uniformly to high-risk and basic applications. He argued that regulation must be grounded in "empirical evidence and science," pointing to the US AI Safety Institute and his own September 2023 California executive order, and noted that he had signed 12 or more narrower AI bills in the same period. Newsom stated that California has a role in regulating national-security-relevant AI and that waiting for a catastrophe was unacceptable.
Comparison with related laws
| Law | Threshold | Triggered duties | Status |
|---|---|---|---|
| SB 1047 (vetoed) | 10²⁶ FLOPs + $100M | SSP, audits, 72h incident reporting, AG enforcement, third-party audit | Vetoed 2024 |
| California SB 53 — Transparency in Frontier AI Act | Revenue + frontier-model definition | Safety framework publication, catastrophic-risk assessments, OES incident reports, whistleblower | Signed 2025 |
| Executive Order 14110 — Safe, Secure, and Trustworthy AI | 10²⁶ FLOPs | Federal reporting only | Rescinded 2025 |
| EU AI Act (Regulation 2024/1689) | 10²⁵ FLOPs (GPAI systemic) | Audits, transparency, risk mgmt, GPAI Code of Practice | In force |
| New York RAISE Act (S. 8828) | Frontier model definition | Safety framework | Active |
| Colorado AI Act (SB 24-205) and SB 25B-004 (Date Amendment) | High-risk use case | Impact assessments, consumer disclosure | Active |
The central design tension was compute-threshold versus use-case-based regulation, which the Newsom veto identified as its core objection; California SB 53 — Transparency in Frontier AI Act, the New York RAISE Act (S. 8828), and the Colorado AI Act (SB 24-205) and SB 25B-004 (Date Amendment) each resolve this trade-off differently. SB 1047 imposed tort-style liability for critical harm, whereas SB 53 dropped this in favor of transparency disclosures. On federal pre-emption, Executive Order 14365 — Ensuring a National Policy Framework for AI would likely challenge SB 1047-style liability today. SB 1047's derivative-developer rules were heavily amended during the session to address open-source concerns; critics argued they remained chilling for open-source developers.
Successor and influence
California SB 53 — Transparency in Frontier AI Act is the narrower transparency-focused successor by the same author. The New York RAISE Act (S. 8828) resembles the publication-and-framework spine of SB 1047 without the liability backbone.
Relationships
- superseded-by: California SB 53 — Transparency in Frontier AI Act
- related: Executive Order 14110 — Safe, Secure, and Trustworthy AI — shared the 10²⁶ FLOPs threshold
- related: New York RAISE Act (S. 8828), Colorado AI Act (SB 24-205) and SB 25B-004 (Date Amendment)
- related: AI Safety Cases and Frameworks, Frontier Compliance Framework (February 2026), Safety Cases for Frontier AI, AI Race Dynamics
- supports: Statement on AI Risk (CAIS), FLI — Pause Giant AI Experiments: An Open Letter — drew on this advocacy current
- contradicts: Executive Order 14365 — Ensuring a National Policy Framework for AI, America's AI Action Plan — federal preemption posture