California SB 53, the Transparency in Frontier Artificial Intelligence Act (TFAIA), is a state law requiring large frontier AI developers to publish safety frameworks, conduct pre-release catastrophic-risk testing, implement the ability to promptly shut down models, report safety incidents, and protect whistleblowers. Authored by Sen. Scott Wiener, it was signed on September 29, 2025 and enacted as Chapter 138, Statutes of 2025.
Status and timeline
The bill was signed by the Governor on September 29, 2025 and took effect as Chapter 138, Statutes of 2025. The full text is recorded as SB 53, Chapter 138, California Statutes of 2025.
Scope and definitions
The law applies to "large frontier developers," defined by training-compute thresholds, and exempts smaller companies. Brookings estimates that approximately 5–8 entities are currently covered at the 10^26 FLOP plus $500M revenue thresholds (Brookings, via FPF and Brookings — California SB 53 Compliance Analyses (Oct–Dec 2025)). Brookings also notes a regulatory-cliff dynamic in which the thresholds create a structural incentive for developers to stay just below them.
Key provisions
Frontier AI framework (§22757.12)
Large frontier developers must write, implement, and publish a frontier AI framework covering how national and international standards and industry best practices are incorporated; internal governance and reporting structure for safety; pre-release safety evaluation procedures; and how identified risks are mitigated before deployment.
Pre-release testing
Frontier developers must conduct assessments of catastrophic risk from internal use of frontier models and submit summaries to the Office of Emergency Services. These catastrophic-risk summaries are submitted quarterly, creating continuous oversight (per FPF and Brookings — California SB 53 Compliance Analyses (Oct–Dec 2025)).
Safety incident reporting
The Office of Emergency Services must establish mechanisms for frontier developers to report critical safety incidents, for members of the public to report safety incidents, and for large frontier developers to confidentially submit catastrophic-risk assessments. Critical safety incident disclosure follows a 15-day standard, shortened to 24 hours where the risk is imminent (per FPF and Brookings — California SB 53 Compliance Analyses (Oct–Dec 2025)).
Safeguards
Developers must implement reasonable safeguards, including the ability to promptly shut down frontier models (kill-switch requirements).
Whistleblower protections
The law extends existing labor whistleblower protections to employees of AI companies reporting safety concerns, and mandates anonymous reporting channels (per FPF and Brookings — California SB 53 Compliance Analyses (Oct–Dec 2025)).
CalCompute
The law establishes a consortium within the Government Operations Agency to develop a framework for a public cloud computing cluster, "CalCompute," for safe AI research.
Obligations by actor
Practitioner analysis combining Future of Privacy Forum (Gluck, Oct 2025) and Brookings (Alikhani & Kane, Dec 2025) identifies four discrete obligations not all visible from the statutory text alone (FPF and Brookings — California SB 53 Compliance Analyses (Oct–Dec 2025)): the Frontier AI Framework (large developers); pre-deployment Transparency Reports (all frontier developers); Critical Safety Incident Disclosure (15-day standard, 24-hour for imminent risk); and Whistleblower Protections with mandated anonymous reporting channels.
Enforcement and penalties
Civil penalties are enforced by the Attorney General, capped at $1M per violation. Brookings characterizes this cap as substantially lighter than the EU AI Act and the NY RAISE Act, which reach $10M–$30M (FPF and Brookings — California SB 53 Compliance Analyses (Oct–Dec 2025)). The Attorney General has no rulemaking power under the law; it provides only for Department of Technology recommendations, subject to Legislative approval.
Reactions
The law had previously been referenced in the wiki only through Dario Amodei's description in The Adolescence of Technology. Amodei advocates a transparency-first regulatory approach — measure and disclose before restricting, with minimal collateral damage — which the law's framework-and-disclosure structure reflects.
Brookings argues that "much of the law codifies practices that major companies already claim to follow," which it reads as implying low marginal compliance cost but also limited marginal safety gain (FPF and Brookings — California SB 53 Compliance Analyses (Oct–Dec 2025)).
The law is an instance of state-led AI regulation of the kind the techno-federalism framework describes, with California leading in software governance while the federal government takes a less active role.
For practitioner-oriented compliance analysis — concrete obligations, enforcement mechanics, timeline, and comparison with the NY RAISE Act — see FPF and Brookings — California SB 53 Compliance Analyses (Oct–Dec 2025), combining Future of Privacy Forum (Gluck, Oct 2025) and Brookings (Alikhani & Kane, Dec 2025).
Sources
- Full text: SB 53, Chapter 138, California Statutes of 2025
- FPF and Brookings — California SB 53 Compliance Analyses (Oct–Dec 2025) — practitioner compliance analysis (FPF + Brookings, Oct–Dec 2025)