Article-by-article breakdown

California AI Transparency Act (SB 53)

California SB 53 — Transparency in Frontier Artificial Intelligence Act (TFAIA)

Article 1Scope and Key Definitions

Applies from: 2025-09-29

Applies to

  • Frontier Developers
  • Large Frontier Developers

Plain English

This article establishes the core definitions that determine who and what is regulated by SB 53. A 'Frontier model' is defined as a foundation model trained with over 10^26 computing operations, including fine-tuning. A 'Frontier developer' is anyone who trained such a model. The most stringent requirements apply to 'Large frontier developers,' which are frontier developers with over $500 million in annual gross revenue.

The law also precisely defines 'Catastrophic risk' as a foreseeable, material risk of causing death or serious injury to 50 or more people, or property damage exceeding $1 billion, stemming from specific AI misuse scenarios like CBRN weapon assistance, cyberattacks without human oversight, or model evasion. 'Critical safety incident' covers events like unauthorized access to model weights or the materialization of catastrophic risks. 'Covered employee' refers to staff involved in assessing or managing critical safety risks, who are protected by whistleblower provisions.

Key points

  • Defines 'Frontier model' by a 10^26 computing operations threshold.
  • Identifies 'Large frontier developers' by a $500M+ annual revenue threshold.
  • Specifies 'Catastrophic risk' criteria, including mass harm, CBRN, and cyberattacks.
  • Defines 'Critical safety incident' and 'Covered employee' for reporting and protection.

What you need to do

  1. 1.Assess your AI models' training compute to determine if they qualify as 'frontier models'.
  2. 2.Calculate your organization's annual gross revenue (including affiliates) to determine if you are a 'large frontier developer'.
  3. 3.Familiarize your legal and product teams with the precise definitions of 'catastrophic risk' and 'critical safety incident' to ensure accurate risk assessment and reporting.
  4. 4.Identify 'covered employees' within your organization to ensure compliance with whistleblower protections.

Cross-jurisdiction equivalents

EUEU AI Act, Article 51 (General-Purpose AI Models with Systemic Risk)The EU AI Act also targets highly capable AI models, using different criteria (e.g., compute, number of users, or power consumption) to define 'systemic risk' for General-Purpose AI models, conceptually aligning with SB 53's 'frontier model' focus.

Article 2Frontier AI Framework Publication

Applies from: 2025-09-29

Applies to

  • Large Frontier Developers

Plain English

Large frontier developers are required to establish and publicly publish a comprehensive 'Frontier AI Framework' on their websites. This framework must detail their approach to identifying, assessing, and mitigating catastrophic risks associated with their AI models. It needs to incorporate national and international standards and industry best practices.

Key components of this framework include defining and assessing capability thresholds that could lead to catastrophic risks, documenting specific mitigation measures, addressing the use of independent third-party evaluators for risk assessments, and outlining cybersecurity measures to protect unreleased model weights from unauthorized access. Developers must also establish internal governance structures to ensure the framework's effective implementation. These frameworks must be reviewed and updated at least annually, with material modifications published within 30 days along with justifications.

Key points

  • Mandatory public publication of a comprehensive Frontier AI Framework.
  • Framework must cover risk identification, assessment, and mitigation strategies.
  • Includes requirements for capability thresholds, third-party assessments, and cybersecurity for model weights.
  • Requires internal governance structures and at least annual framework updates.

What you need to do

  1. 1.Develop a detailed, publicly accessible Frontier AI Framework that addresses all specified elements.
  2. 2.Implement robust cybersecurity measures to protect unreleased model weights.
  3. 3.Establish internal processes and governance to ensure adherence to the published framework.
  4. 4.Plan for annual reviews and updates of your framework, publishing any material changes promptly.

Cross-jurisdiction equivalents

EUEU AI Act, Article 9 (Risk Management System)The EU AI Act mandates a comprehensive risk management system for high-risk AI systems, requiring providers to establish, implement, document, and maintain a continuous process for identifying, analyzing, and evaluating risks, similar to SB 53's framework requirement.

Article 3Quarterly Catastrophic Risk Reporting

Applies from: 2025-09-29

Applies to

  • Large Frontier Developers

Plain English

Large frontier developers are obligated to submit summaries of their internal catastrophic risk assessments to the California Office of Emergency Services (Cal OES) on a quarterly basis. This reporting mechanism allows a state emergency management agency to monitor potential AI-related threats and integrate them into broader emergency preparedness efforts.

These submitted summaries are exempt from public disclosure under the California Public Records Act, which aims to encourage candid and comprehensive reporting from developers without concerns about competitive disadvantages or litigation risks. The specific schedule for these quarterly reports will be coordinated directly with Cal OES.

Key points

  • Mandatory quarterly submission of internal catastrophic risk assessment summaries.
  • Reports are submitted to the California Office of Emergency Services (Cal OES).
  • Information contained in these reports is exempt from public disclosure.
  • Reporting schedule to be coordinated with Cal OES.

What you need to do

  1. 1.Establish a recurring process for conducting and summarizing internal catastrophic risk assessments every three months.
  2. 2.Develop a secure and compliant method for transmitting these summaries to Cal OES.
  3. 3.Ensure internal risk assessments are thorough and well-documented to support the summaries.
  4. 4.Designate a point of contact for coordinating reporting schedules with Cal OES.

Cross-jurisdiction equivalents

US (Federal)Executive Order 14110, Section 4.2(b)The US Executive Order requires developers of certain powerful AI models to report their training, safety test results, and other information to the Commerce Secretary, serving a similar government oversight function for advanced AI risks.

Article 4Transparency Reports for New Deployments

Applies from: 2025-09-29

Applies to

  • Large Frontier Developers

Plain English

Before or concurrently with the deployment of any new frontier model, large frontier developers must publish transparency reports. These reports are intended to provide the public with clear information about the AI system being released.

Each report must detail the model's capabilities, the specific safety measures that have been implemented to mitigate risks, and the intended uses of the model. This requirement aims to foster greater public understanding and accountability for the introduction of powerful new AI systems, ensuring that stakeholders are informed about their potential impacts and the safeguards in place.

Key points

  • Requires publication of transparency reports for new frontier model deployments.
  • Reports must be published before or at the time of deployment.
  • Content includes model capabilities, safety measures, and intended uses.
  • Aims to increase public awareness and accountability for new AI systems.

What you need to do

  1. 1.Integrate the creation and publication of transparency reports into your product launch pipeline for all new frontier models.
  2. 2.Ensure reports are comprehensive, accurate, and clearly articulate the model's capabilities, safety features, and use cases.
  3. 3.Develop internal review processes to verify the content of these reports before publication.
  4. 4.Establish a public-facing mechanism for publishing these reports on your website.

Cross-jurisdiction equivalents

EUEU AI Act, Article 52 (Transparency obligations for certain AI systems)The EU AI Act includes transparency obligations for providers of general-purpose AI models, requiring them to provide information about the model's capabilities and limitations, which aligns with SB 53's goal of public disclosure before deployment.

Article 5Critical Safety Incident Reporting

Applies from: 2025-09-29

Applies to

  • Large Frontier Developers

Plain English

Large frontier developers are required to report 'critical safety incidents' to the California Office of Emergency Services (Cal OES). The standard reporting timeline is within 15 days of discovering such an incident. However, if an incident poses an imminent risk of death or serious injury, an expedited report must be made within 24 hours of discovery.

Critical safety incidents include events like unauthorized access to model weights that could lead to harm, the actual materialization of a catastrophic risk, loss of control over the AI model, or deceptive model behavior that subverts developer controls. These reports are crucial for enabling rapid government response and monitoring of actual AI-related threats. Similar to risk assessment summaries, these incident reports are exempt from public disclosure.

Key points

  • Mandatory reporting of 'critical safety incidents' to Cal OES.
  • 15-day reporting window for standard incidents.
  • 24-hour expedited reporting for incidents posing imminent death or injury risk.
  • Covers unauthorized access, catastrophic risk materialization, loss of control, and deceptive behavior.

What you need to do

  1. 1.Establish clear internal procedures for identifying, assessing, and classifying critical safety incidents.
  2. 2.Implement a rapid response protocol to ensure 24-hour reporting for imminent threats.
  3. 3.Train relevant personnel on incident detection, documentation, and reporting requirements and timelines.
  4. 4.Develop a secure channel for transmitting incident reports to Cal OES.

Cross-jurisdiction equivalents

EUEU AI Act, Article 62 (Reporting of serious incidents)The EU AI Act requires providers of high-risk AI systems to report serious incidents and malfunctions to market surveillance authorities, with specific timelines, mirroring SB 53's incident reporting obligations.

Article 6Whistleblower Protection

Applies from: 2025-09-29

Applies to

  • Frontier Developers
  • Large Frontier Developers

Plain English

SB 53 includes robust protections for 'covered employees' who report concerns related to AI safety. It explicitly prohibits retaliation against employees who disclose information about potential catastrophic risks or critical safety incidents. This protection applies whether the disclosure is made to government authorities, company management, or other employees with investigative authority.

To facilitate such reporting, developers are required to establish anonymous internal reporting mechanisms. Furthermore, companies must post notices in the workplace informing employees of their rights under these whistleblower provisions. In cases of alleged retaliation, the burden of proof shifts to the developer to demonstrate that any adverse employment action would have occurred regardless of the protected disclosure, strengthening employee protections.

Key points

  • Prohibits retaliation against 'covered employees' for reporting AI safety concerns.
  • Protections apply to disclosures made to authorities, management, or internal investigators.
  • Requires establishment of anonymous internal reporting mechanisms.
  • Mandates posting of employee rights notices and shifts burden of proof in retaliation cases.

What you need to do

  1. 1.Implement a secure and truly anonymous internal reporting system for AI safety concerns.
  2. 2.Develop and prominently display notices of employee whistleblower rights in all workplaces.
  3. 3.Train HR and management on anti-retaliation policies and the specific protections afforded by SB 53.
  4. 4.Review and update internal policies to align with the shifted burden of proof in whistleblower cases.

Cross-jurisdiction equivalents

US (Federal)Sarbanes-Oxley Act (SOX), Section 806While not AI-specific, SOX provides whistleblower protections for employees of publicly traded companies who report fraud, offering a general parallel for protecting employees who report corporate wrongdoing.

Article 7Enforcement and Penalties

Applies from: 2025-09-29

Applies to

  • Large Frontier Developers

Plain English

The California Attorney General holds exclusive authority for enforcing SB 53, meaning no private right of action exists for individuals to sue under this law. Violations can lead to significant civil penalties, with fines not exceeding $1 million per violation. Each distinct failure to comply, such as failing to publish a required document or making a materially false statement about catastrophic risks, constitutes a separate violation, potentially leading to substantial cumulative penalties.

Specific violations include failure to publish or transmit required documents (frameworks, transparency reports, incident reports), making materially false or misleading statements regarding catastrophic risks, failure to report critical safety incidents, and non-compliance with the developer's own published framework. In whistleblower cases, courts may award attorney's fees to prevailing employees, providing a financial incentive for employees to pursue valid claims of retaliation. The law also includes protections for developers, allowing redaction of trade secrets, cybersecurity vulnerabilities, or national security information from disclosures, provided unredacted versions are retained for five years.

Key points

  • Exclusive enforcement by the California Attorney General; no private right of action.
  • Civil penalties up to $1 million per violation, with each failure counting separately.
  • Covers failures in reporting, publication, false statements, and framework non-compliance.
  • Attorney's fees may be awarded to prevailing employees in whistleblower cases.

What you need to do

  1. 1.Ensure rigorous compliance with all reporting, publication, and framework requirements to avoid substantial financial penalties.
  2. 2.Maintain accurate and complete records of all compliance activities and disclosures.
  3. 3.Be aware that the Attorney General has broad discretion in pursuing enforcement actions.
  4. 4.Understand the specific types of violations that can trigger penalties and implement controls to prevent them.

Cross-jurisdiction equivalents

EUEU AI Act, Article 99 (Penalties)The EU AI Act also imposes significant fines for non-compliance, with penalties reaching up to €35 million or 7% of global annual turnover for certain violations, demonstrating a global trend towards substantial financial consequences for AI regulatory breaches.

Article 8Annual Definition Assessment

Applies from: 2027-01-01

Applies to

  • California Department of Technology

Plain English

To ensure the regulation remains relevant and effective in a rapidly evolving technological landscape, SB 53 mandates that the California Department of Technology conduct an annual assessment. Starting January 1, 2027, the Department must evaluate whether the key definitions—'frontier model,' 'large frontier developer,' and 'catastrophic risk'—continue to be appropriate as AI capabilities advance.

This provision creates a built-in mechanism for regulatory adaptation, allowing the state to adjust the scope and focus of the law without requiring new legislative action each time AI technology progresses significantly. The Department's assessments may lead to recommendations for legislative updates if the definitions are found to be outdated or no longer accurately capture the intended scope of regulation.

Key points

  • California Department of Technology to conduct annual assessments.
  • Focuses on the appropriateness of 'frontier model,' 'large frontier developer,' and 'catastrophic risk' definitions.
  • First assessment due by January 1, 2027.
  • Provides a mechanism for regulatory adaptation to technological advancements.

What you need to do

  1. 1.Stay informed about the Department of Technology's annual assessments and any potential changes to key definitions, as these could alter your compliance obligations.
  2. 2.Consider engaging with the Department of Technology if your organization has insights or concerns regarding the current definitions' applicability.
  3. 3.Anticipate that the regulatory landscape for AI may evolve based on these annual reviews.

Article 9Preemption of Local Regulations

Applies from: 2025-09-29

Applies to

  • Local California Jurisdictions

Plain English

SB 53 includes a preemption clause that prevents local regulations from creating a fragmented regulatory environment for advanced AI safety. Specifically, the act preempts any local regulations adopted after January 1, 2025, that specifically aim to regulate frontier developers' management of catastrophic risks.

This provision ensures statewide uniformity in the governance of frontier AI safety, meaning that developers operating across California will be subject to a single, consistent set of state-level requirements rather than a patchwork of potentially conflicting local ordinances. This simplifies compliance for developers and provides clarity regarding the applicable regulatory framework.

Key points

  • Preempts local regulations adopted after January 1, 2025.
  • Applies to local laws specifically regulating frontier AI catastrophic risk management.
  • Ensures statewide uniformity in AI safety governance.
  • Prevents a fragmented regulatory landscape for developers.

What you need to do

  1. 1.Developers can rely on SB 53 as the primary state-level regulation for frontier AI safety, without needing to navigate diverse local ordinances.
  2. 2.Local governments in California are restricted from enacting new, specific regulations on frontier AI catastrophic risk management.
  3. 3.Focus compliance efforts on the statewide requirements established by SB 53.

Article 10CalCompute Public Computing Consortium

Applies from: Upon appropriation (report due by 2027-01-01)

Applies to

  • California State Agencies
  • Academic Institutions
  • AI Researchers

Plain English

Beyond direct regulatory requirements, SB 53 also directs the development of the 'CalCompute' public cloud computing consortium. The primary objective of this initiative is to democratize access to essential AI research resources, particularly high-performance computing capabilities.

This aims to address concerns about the concentration of powerful computing resources among a few large entities, fostering a more diverse and accessible AI research ecosystem. While the consortium's full implementation is contingent on appropriations, a report on its planning and progress is due by January 1, 2027, after which the initial planning body will dissolve.

Key points

  • Directs the creation of the 'CalCompute' public cloud computing consortium.
  • Aims to democratize access to AI research resources and computing power.
  • Addresses concerns about compute concentration in the AI industry.
  • A report on the consortium is due by January 1, 2027.

What you need to do

  1. 1.While not a direct compliance obligation for developers, this initiative could foster a more diverse and competitive AI research landscape in California.
  2. 2.Monitor the development of CalCompute for potential opportunities for collaboration or access to computing resources for research and development.
  3. 3.This initiative may influence the talent pool and innovation ecosystem for AI in the state.

Cross-jurisdiction equivalents

US (Federal)National AI Research Resource (NAIRR)The US federal government has also proposed the National AI Research Resource (NAIRR) to provide AI researchers with access to computational resources, data, and educational tools, sharing a similar goal of democratizing AI research infrastructure.

Need help applying this to your case?

The wizard takes 60 seconds and tells you which articles you actually need to worry about based on your jurisdictions, use case, and data.

Start the wizard →