Who it covers

Governor Newsom signed Senator Scott Wiener's SB 53, the Transparency in Frontier Artificial Intelligence Act, on September 29. The scope is set by two numbers. A frontier model is a foundation model trained with more than 10 to the power of 26 integer or floating point operations, counting fine-tuning and reinforcement learning on top of the base run. A large frontier developer is one that trained such a model and, together with its affiliates, had more than 500 million dollars in gross revenue in the previous calendar year.

Brookings estimates that puts somewhere between five and eight companies in the large-developer tier, naming OpenAI, Anthropic, Google DeepMind, Meta and Microsoft. Developers above the compute line but below the revenue line have lighter duties, mostly the transparency report. Everyone else is untouched, which is the main way this bill differs from the one vetoed last year.

What a large developer must publish

The central obligation is a frontier AI framework, posted publicly and reviewed at least once a year, with material changes published within 30 days. The statute lists what it must address. How the developer incorporates national and international standards. The thresholds it uses to decide a model poses catastrophic risk and the mitigations it applies when they are crossed. Pre-deployment review. Use of third-party evaluators. Cybersecurity for unreleased weights. How it identifies and responds to critical safety incidents. Internal governance, and risk management for internal use of the model.

If that list sounds familiar it is because it is roughly the table of contents of the responsible scaling policies and preparedness frameworks the labs already publish voluntarily. The law does not set the thresholds or name the mitigations. It requires that the document exist, that it be public, and that the company then report against it. Before deploying a new frontier model, a large developer must publish a transparency report summarising its catastrophic risk assessment, the results, whether third parties were involved, and how the deployment complied with its own framework.

Incidents, whistleblowers and penalties

Catastrophic risk has a statutory definition. It is a foreseeable and material risk that a frontier model will materially contribute to the death of or serious injury to more than 50 people, or more than one billion dollars in property damage, in a single incident involving weapons assistance, an uncontrolled cyberattack or violent crime, or a model evading its developer's control. Critical safety incidents include unauthorised access to weights that causes harm, a materialised catastrophic risk, loss of control that causes death or injury, and a model using deception to subvert developer controls outside of an evaluation.

Those incidents must be reported to the California Office of Emergency Services within 15 days of discovery, or within 24 hours if there is an imminent risk of death or serious injury. OES will publish an annual report on what it received starting January 1, 2027. Covered employees may disclose catastrophic risks or violations to authorities without contractual restriction, and large developers must run an anonymous internal reporting channel with quarterly status updates to leadership. The Attorney General enforces, with civil penalties up to one million dollars per violation.

The bill also creates CalCompute, a public cloud cluster to be housed within the University of California if feasible, with the stated aim of widening access to compute for research in the public interest. That part only takes effect if the legislature funds it.

How it compares with the voluntary policies

The honest comparison is that SB 53 codifies the form of the voluntary frameworks, not their content. Anthropic's RSP and OpenAI's preparedness framework already describe capability thresholds, evaluations and safeguards. What they lacked was any external consequence for quietly editing the document, skipping a report, or retaliating against an employee who noticed. The statute supplies those. A framework that is published and then not followed is now a matter for the Attorney General rather than for a blog post.

What it does not supply is a floor on what the framework says. A developer could publish thresholds that no model is likely to cross and be in full compliance. Brookings describes the law as converting years of voluntary commitment into public accountability, and as narrower than the EU AI Act while going further on transparency. We read that as accurate. The theory of the bill is that sunlight plus whistleblower protection plus incident reporting is enough, and that the state should not be in the business of specifying safeguards it cannot evaluate.

Compared with SB 1047, the changes are large. There is no requirement for a kill switch, no pre-training certification, and no liability for downstream harms. The compute threshold stayed at 10 to the 26, but the revenue test now excludes small developers and academic groups entirely. That removes the objection that did the most damage to the earlier bill, and it explains why the same governor signed this one.

What we will be watching

The first test is January 2027, when OES and the Attorney General publish their first annual reports. If the incident count is zero across every developer for a year, either nothing happened or the definitions are too narrow to catch anything, and we will not be able to tell which from the outside. The Department of Technology is also required to recommend updates to the thresholds annually, so the 10 to the 26 line is not fixed.

The second test is whether the published frameworks converge. If five companies must post comparable documents and report against them, researchers outside those companies can finally compare thresholds and evaluations side by side. That comparison is the thing we most want, and it is something voluntary policies never gave us because each one was written in its own vocabulary on its own schedule.

Sources

  1. Brookings: What is California’s AI safety law?
  2. California Legislative Information: SB 53 bill text
  3. Office of the Governor: Governor Newsom signs SB 53 (September 29, 2025)