California Adopts AI Safety and Transparency Law

Posted

California has enacted the Transparency in Frontier Artificial Intelligence Act (SB 53), establishing one of the most comprehensive state-level frameworks for AI governance in the United States. Signed into law on September 29, 2025, the measure requires large-scale developers of frontier AI models to publish safety frameworks, release transparency reports, and report critical safety incidents to state authorities.

Governor Gavin Newsom said the bill “establishes commonsense guardrails that protect communities while allowing California’s AI industry to continue thriving,” underscoring the balance between innovation and risk management.

Key Requirements

Under the new law, a large frontier developer—defined as a company with over $500 million in annual revenue that trains or deploys frontier-scale models—must:

  • Publish a frontier AI framework outlining how the company incorporates national and international standards, risk thresholds, mitigation strategies, third-party testing, cybersecurity measures, and update cycles.
  • Release transparency reports when deploying new or substantially modified models. These must include summaries of catastrophic risk assessments, third-party evaluations, and governance steps taken before deployment.
  • Report critical safety incidents to the California Office of Emergency Services within 15 days, or within 24 hours if the incident presents an imminent risk of death or serious injury. Penalties of up to $1 million per violation may be imposed for noncompliance.

Critical safety incidents are defined to include unauthorized access to model weights resulting in injury, loss of control of a model, or behavior that materially increases catastrophic risk, such as enabling cyberattacks or biological threats.

Whistleblower Protections

The law also creates new labor protections for employees of frontier developers. Covered employees who disclose concerns about catastrophic risks are shielded from retaliation and may use mandated anonymous reporting channels within their organizations. Companies must provide annual notice of these rights and maintain internal processes for handling such disclosures.

CalCompute Initiative

SB 53 also authorizes the creation of CalCompute, a state-managed public cloud computing framework intended to support AI research and development that is “safe, ethical, equitable, and sustainable.” The Government Operations Agency must deliver a framework for CalCompute to the Legislature by January 1, 2027. The report will include cost analyses, governance recommendations, workforce implications, and potential partnerships with universities and private-sector entities.

Broader Context

The measure follows debates over the scope of California’s role in AI regulation. A previous proposal, SB 1047, was vetoed in 2024 amid concerns about its potential to stifle innovation. SB 53 narrows the focus to transparency, incident reporting, and whistleblower protections, positioning California’s approach closer to voluntary frameworks already adopted by major AI firms while making them mandatory and enforceable.

Starting in 2027, annual aggregated reports from the Office of Emergency Services and the Attorney General will provide public insight into reported safety incidents and employee disclosures, offering policymakers and industry observers new data on the governance of frontier AI.

Environment + Energy Leader