GovernanceCore
EnforcedUnited States, California

California Transparency in Frontier Artificial Intelligence Act

Requires developers of the largest frontier models to publish safety frameworks, report critical safety incidents, and protect whistleblowers. It is the leading US model for frontier-AI transparency.

Status
Enforced
Jurisdiction
United States, California · State
Adopted
Sep 29, 2025
In force
Jan 1, 2026
Enforcement date
Jan 1, 2026
Regulator / body
California Attorney General / Office of Emergency Services
Sectors
Frontier AI developers
Extraterritorial
No

Overview

Scope works in two tiers, and the tier decides which duties apply. Training a foundation model with more than 10^26 integer or floating-point operations, counting the original training run plus any later fine-tuning, reinforcement learning or material modification, makes a developer a frontier developer and triggers a published transparency report before or alongside each deployment of a new or substantially modified model. Adding more than $500,000,000 in annual gross revenues across the developer and its affiliates in the preceding calendar year makes it a large frontier developer, which brings the published frontier AI framework, catastrophic-risk summaries inside the transparency report, quarterly internal-use risk summaries to the Office of Emergency Services, and an anonymous internal disclosure channel. Civil penalties of up to $1,000,000 per violation are drafted to bite on large frontier developers and are recoverable only by the Attorney General, so for a smaller frontier developer the live exposure is incident reporting plus the Labor Code whistleblower rules. One route out of duplicate reporting exists: where the Office of Emergency Services designates a federal law, regulation or guidance document as substantially equivalent or stricter, a developer can declare its intent to comply through that instead, after which failing the federal standard becomes a violation of the California chapter.

Key dates

  • Sep 29, 2025
    Signed into law
  • Jan 1, 2026
    Took effect

Risk areas addressed

Safety & robustnessTransparencyGovernance & accountability

Who it applies to

The compute test captures a small set of foundation-model developers: persons who have trained, or initiated training of, a model above 10^26 operations, or who intend to use that much compute (§ 22757.11(h) and (i)). Large-developer duties add a group revenue test of more than $500,000,000 in annual gross revenues in the preceding calendar year, measured across the developer and its affiliates (§ 22757.11(j)). Deployers, downstream fine-tuners below the compute threshold and enterprise users fall outside the chapter; the Act does not apply to the extent it strictly conflicts with a federal government contract or is preempted by federal law, and the whistleblower chapter protects only 'covered employees', meaning those responsible for assessing, managing or addressing the risk of critical safety incidents.

Key obligations

  • Write, implement, comply with and clearly publish on your website a frontier AI framework addressing all ten listed topics, from capability thresholds and mitigations through third-party assessment, cybersecurity for unreleased model weights, incident response and internal governance to catastrophic risk from internal use (§ 22757.12(a)).
  • Review the framework at least once a year, and where you make a material modification publish the revised framework and a justification for the change within 30 days (§ 22757.12(b)).
  • Publish a transparency report before, or concurrently with, deploying a new or substantially modified frontier model, covering your website, a mechanism for a person to contact you, the release date, supported languages, output modalities, intended uses and any generally applicable use restrictions (§ 22757.12(c)(1)).
  • As a large frontier developer, add to that report summaries of the catastrophic-risk assessments carried out under your framework, their results, the extent of third-party evaluator involvement, and other steps taken to satisfy the framework for that model (§ 22757.12(c)(2)).
  • Transmit to the Office of Emergency Services a summary of any assessment of catastrophic risk arising from internal use of your frontier models every three months, or on another reasonable schedule notified to that office in writing (§ 22757.12(d)).
  • Report each critical safety incident to the Office of Emergency Services within 15 days of discovery, and where the incident poses an imminent risk of death or serious physical injury disclose it within 24 hours to an appropriate law enforcement or public safety authority (§ 22757.13(c)(1) and (2)).
  • Make no materially false or misleading statement about catastrophic risk from your frontier models or your management of it, and, as a large frontier developer, none about your implementation of or compliance with your framework (§ 22757.12(e)).
  • Do not make, adopt, enforce or enter into any rule, policy or contract that stops a covered employee disclosing catastrophic-risk or compliance concerns, give covered employees clear notice of those rights by permanent workplace posting or annual acknowledged written notice, and, as a large frontier developer, run an anonymous internal disclosure process with monthly status updates to the discloser (Labor Code § 1107.1(a), (d) and (e)).

How to prepare

  1. Compute the training total for each foundation model, including fine-tuning and material modifications, against the 10^26 operation threshold, and total group annual gross revenues across affiliates against the $500,000,000 line, then record in writing which tier each entity and model sits in and when that could change.
  2. Draft the frontier AI framework against the ten topics in section 22757.12(a) and map each one to a control you actually operate, since failing to comply with your own published framework is itself a penalty trigger.
  3. Stand up a critical safety incident process with a named owner, a 24 hour escalation route for imminent-harm cases, a 15 day route to the Office of Emergency Services, and a report template capturing the incident date, why it qualifies, a short plain description and whether internal use was involved.
  4. Fold the transparency report into the model card or system card you already publish at launch, which the statute treats as compliant, and make its publication a release gate rather than a post-launch task.
  5. Set the quarterly cadence for internal-use catastrophic-risk summaries, and log every redaction with its character and justification in the published document while retaining the unredacted version for five years (§ 22757.12(f)).
  6. Issue the whistleblower notice to covered employees, strip conflicting language out of NDAs, severance templates and policies, and, if you are a large developer, launch the anonymous channel with monthly updates to the discloser and at least quarterly reporting of disclosures to officers and directors.

Penalties & enforcement

Up to $1,000,000 per violation depending on severity, recoverable only in a civil action brought by the Attorney General (§ 22757.15).

Enforced by: California Attorney General / Office of Emergency Services

Getting ready

California SB 53 is enforced by California Attorney General / Office of Emergency Services. Its obligations are already live, so a gap is a present exposure rather than a future one. In practice that means knowing which of your AI systems fall in scope in frontier AI developers, holding assessments that speak to safety & robustness, transparency and governance & accountability, and being able to produce that evidence on request.

Official source

California Legislature, SB 53

Related regulations

← All regulations