Regulation

California SB 53 Takes Effect, Reshaping Frontier AI Rules

SB 53 took effect Jan 1, 2026: frontier AI developers must publish transparency reports; large ones must also post safety frameworks and report incidents within 15 days, at up to $1M per violation.

California SB 53 Takes Effect, Reshaping Frontier AI Rules — article cover
On this page6 SECTIONS
  1. Who Is Covered: 10^26 FLOPs and the $500M Line
  2. Two New Documents: Transparency Reports and Safety Frameworks
  3. The Incident Clock and Whistleblower Protections
  4. Penalties, Enforcement, and the 2027 Wave
  5. What It Means for Dev and Product Teams
  6. Sources

On January 1, 2026, California’s SB 53 — the Transparency in Frontier Artificial Intelligence Act — took effect. Introduced by Senator Scott Wiener and signed by Governor Gavin Newsom on September 29, 2025, it is the first state law in the US aimed specifically at frontier AI models. It is also the corrected route after SB 1047’s 2024 veto: no kill switch, no pre-deployment licensing. Instead, developers must write their risk assessments down, publish them, and pay if they don’t.

The stakes are structural. Most frontier labs are headquartered or operate substantially in California, so every new model shipped after the effective date lands immediately under new disclosure duties. Together with OpenAI’s Rest-of-World terms, which also kicked in on New Year’s Day (see our opening outlook), it sets the tone for 2026: the rules are tightening.

Who Is Covered: 10^26 FLOPs and the $500M Line

The law draws its scope with two nested definitions. A “frontier model” is a foundation model trained with more than 10^26 integer or floating-point operations — and the count includes subsequent fine-tuning, reinforcement learning, and material modifications, not just the original run. A “frontier developer” is anyone who initiated training of such a model.

The heavier obligations fall only on “large frontier developers”: those whose combined annual gross revenues with affiliates exceeded $500 million in the prior calendar year. California’s Department of Technology must reassess these definitions annually, with a first round of recommended updates due by January 1, 2027. The thresholds are designed to move with reality, not stay frozen.

Two New Documents: Transparency Reports and Safety Frameworks

Every frontier developer must publish a transparency report before or concurrently with deploying a new or materially modified frontier model. It needs at minimum the developer’s website, a communication mechanism for users, the release date, and intended uses. An existing system card or model card that covers these items satisfies the requirement. Redactions are allowed for trade secrets, cybersecurity, or national security reasons — but the report must describe and justify each redaction, and unredacted versions must be retained for five years.

Large developers add summaries of catastrophic-risk assessments, their results, and how much third-party evaluators were involved. They must also write, actually follow, and publish on their website a Frontier AI Safety and Security Framework, reviewed and updated at least annually. The framework covers standards adoption, catastrophic-risk thresholds and assessment, pre- and post-deployment review, cybersecurity for unreleased model weights, incident response, and internal governance.

The law’s definition of catastrophic risk is concrete: a foreseeable, material risk of contributing to death or serious injury of 50 or more people, or more than $1 billion in property damage from a single incident — via CBRN weapons assistance, unsupervised cyberattacks or serious crimes, or evading developer and user control.

The Incident Clock and Whistleblower Protections

Reporting duties run on two clocks. After discovering a critical safety incident, developers must report to the California Office of Emergency Services (CalOES) within 15 days. If the incident poses an imminent risk of death or serious physical injury, disclosure to an appropriate law enforcement or public safety authority is required within 24 hours. Large developers additionally transmit summaries of internal-use catastrophic-risk assessments to CalOES every three months, or on another reasonable schedule.

Whistleblower protection is among the law’s sharpest teeth. Developers may not adopt policies or contracts that prevent or retaliate against employees who disclose — to the California Attorney General, federal authorities, supervisors, or colleagues conducting investigations — information they reasonably believe shows a specific, substantial public safety danger or an SB 53 violation. Large developers must offer an anonymous internal reporting channel with monthly status updates, and post annual notices of employee rights.

Penalties, Enforcement, and the 2027 Wave

Violating the framework publication, transparency report, or critical safety incident reporting duties carries civil penalties of up to $1 million per violation, enforceable only through civil actions by the California Attorney General. Note the fine print: failing to follow your own published safety framework is itself a violation. Once you publish the document, it becomes an enforceable commitment.

January 1, 2027 is the next milestone: CalOES starts publishing anonymized annual incident summaries, and the Department of Technology delivers its definition updates. The law also establishes the CalCompute public compute consortium. One clarification worth repeating: SB 942, the California AI Transparency Act covering provenance disclosure and watermarking of AI-generated content, was delayed by AB 853 to August 2, 2026. What went live on New Year’s Day is SB 53, not SB 942.

What It Means for Dev and Product Teams

Three practical moves. First, scope yourself honestly: keep training-compute records and aggregate affiliate revenue, because the $500 million line is easier to cross than most teams assume. Second, align your model card pipeline with the transparency report requirements, and document every redaction — what you said and what you omitted can both be examined in litigation. Third, add the 15-day and 24-hour clocks to your incident response plan and stand up an anonymous whistleblower channel. Neither is a legal-department-only task; model, safety, and engineering teams all have parts to play.

Sources

AI-assisted summary compiled from the sources above, reviewed by a human before publishing.

SHAREXEMAIL