California SB 1047, the Safe and Secure Innovation for Frontier AI Models Act, was a frontier-AI safety bill authored by Sen. Scott Wiener (D-San Francisco), with co-authors Roth, Rubio, and Stern. It passed both houses of the California Legislature and was vetoed by Governor Gavin Newsom on September 29, 2024. A narrower transparency-focused reintroduction, SB 53, was signed in 2025.
Summary of provisions
Covered model threshold (§ 22602)
The bill defined a covered model by compute and cost. Before January 1, 2027, the threshold was greater than 10²⁶ FLOPs and greater than $100M cost, with cost including cloud-compute market prices. After January 1, 2027, the threshold was to be revised by the Government Operations Agency. Derivatives were also captured: fine-tunes exceeding 3×10²⁵ ops and $10M counted as covered models.
Critical harm definition
Critical harm covered four categories: (a) CBRN mass-casualty events; (b) $500M or more in damage, or mass casualties, from cyberattacks on critical infrastructure; (c) comparable harms from AI acting with limited human oversight in ways that would be criminal if done by a human; and (d) other grave harms of comparable severity.
Developer pre-training duties (§ 22603)
Before training, a developer was required to: implement cybersecurity protections for model weights; maintain a full-shutdown capability; produce a written Safety and Security Protocol (SSP) covering protections, shutdown conditions, and testing procedures for derivatives; retain the unredacted SSP for the model's lifetime plus 5 years; conduct an annual SSP review; publish a redacted SSP and provide an unredacted copy to the California Attorney General on request; meet a reasonable-care standard for safeguards; and designate a senior compliance officer.
Pre-commercial-use duties
Before commercial use, a developer was required to assess whether the model was capable of enabling critical harm, retain detailed test-replication records, implement reasonable safeguards, and ensure attributability. The bill prohibited releasing a model with an "unreasonable risk" of causing or materially enabling critical harm.
Annual third-party audit (§ 22603(e))
Beginning January 1, 2026, developers were to undergo an independent third-party compliance audit, with records retained for the model's lifetime plus 5 years.
Reporting
Reporting obligations included a CTO-signed annual compliance statement, incident reporting to the Attorney General within 72 hours, and an initial statement within 30 days of first commercial deployment.
Compute-cluster operator duties (§ 22604)
Operators of compute clusters faced know-your-customer obligations for customers using compute sufficient to train a covered model: collecting identity, business purpose, and IP addresses; maintaining a shutdown capability; 7-year retention; and annual revalidation.
Penalties (§ 22606)
Penalties included a civil penalty of up to 10% of training compute cost for a first violation and 30% for subsequent violations; injunctive relief; monetary and punitive damages; an aggregate cap of $10M for computing-cluster operators; and corporate-veil piercing for entities structured to evade accountability.
Whistleblower protections (§ 22607)
Developers could not block employee disclosures to the Attorney General or Labor Commissioner. The bill required internal anonymous reporting channels and extended Labor Code § 1102.5 protections.
Board of Frontier Models (§ 11547.6)
The bill established a 9-member Board of Frontier Models by 2026 within the Government Operations Agency, with seats for an open-source representative, industry, AI safety experts, academics, and a CBRN expert. Its functions included annual threshold updates, auditing standards, and guidance aligned with the federal AI Safety Institute.
CalCompute (§ 11547.6.1)
CalCompute was a public-cloud-compute consortium centered on the University of California, operative only on budget appropriation. It was never funded after the veto.
Newsom veto
Newsom vetoed the bill on September 29, 2024. His stated reasoning was that a compute-threshold trigger gives a "false sense of security" because smaller specialized models may also be dangerous; that the bill did not account for risk context, distinguishing high-risk from basic applications; and that regulation must be "based on empirical evidence and science," for which he pointed to the work of the US AI Safety Institute and to his own September 2023 California executive order. He noted that he had signed 12 or more narrower AI bills in the same month and signaled willingness to continue iterating. Newsom also stated that "we cannot afford to wait for a major catastrophe" and that California has a role in regulating national-security-relevant AI.
Key claims
The source advances several governance claims of differing confidence:
- That a compute-threshold combined with a cost-threshold can adequately identify frontier models at present. This was the central point of disagreement between the Wiener camp and the Newsom veto, and is contested.
- That third-party audits and SSP publication are feasible governance mechanisms. This was subsequently partially adopted in SB 53 (confidence: high).
- That model developers can be held liable for downstream critical harm under a "reasonable care" standard. This is contested: industry argued it chilled open-source releases, while backers argued it matched general tort law.
Relationships
- superseded-by: California SB 53 — Transparency in Frontier AI Act — narrower transparency-focused reintroduction signed 2025
- related: Executive Order 14110 — Safe, Secure, and Trustworthy AI — shares the 10²⁶ FLOPs threshold and dual-use foundation model framing
- related: AI Safety Cases and Frameworks, Frontier Compliance Framework (February 2026), Safety Cases for Frontier AI
- supports: Statement on AI Risk (CAIS), FLI — Pause Giant AI Experiments: An Open Letter — drew on these advocacy documents
- contradicts: Executive Order 14365 — Ensuring a National Policy Framework for AI, America's AI Action Plan — subsequent federal preemption posture
- related: Anthropic — Dario Amodei publicly expressed qualified support; OpenAI — lobbied against