Skip to main content
v2026.11,858 entries · CC-BY 4.0

Direct comparison

EU AI Act vs SB 53: Transparency Compared

EU AI Act GPAI rules vs California SB 53: compare coverage thresholds, published disclosures, incident-reporting deadlines, penalties, and effective dates.

Written and maintained by CASRAI Editorial Board

Last updated

Ask CASRAI · free to try

Ask about EU AI Act vs SB 53: Transparency Compared

Ask your first 2 questions free below. Subscribers get 150 a day for $29 a month.

Ask CASRAI answers research-administration questions and cites the passages behind every claim. When our sources don't cover a question, it says so.

Answers draw on CASRAI's guides and dictionary plus the federal and funder documents we index: Federal Register, Grants.gov, Regulations.gov and UKRI.

Works on this site and inside Claude, Cursor and the AI tools you already use.

Everything CASRAI publishes — this page, the dictionary, the guides and the news — stays free to read, with no account and no card.

How do EU AI Act (GPAI provisions), California SB 53 (TFAIA) compare side by side?

The table below compares EU AI Act (GPAI provisions), California SB 53 (TFAIA) across 6 procurement-relevant dimensions, from who is covered through effective dates.

Side-by-side comparison

DimensionEU AI Act (GPAI provisions)California SB 53 (TFAIA)
Who is coveredProviders of general-purpose AI (GPAI) models. All GPAI providers carry baseline transparency duties under Article 53; a subset carrying "systemic risk" carries the additional duties under Article 55."Large frontier developers" only — a narrower category than the EU's. A company must both train a covered model and clear a revenue threshold before SB 53's core duties apply.
What triggers coverageA rebuttable presumption of "systemic risk" attaches once a GPAI model's cumulative training compute exceeds 10^25 FLOPs (Article 51(1)(a)-(2)). The European Commission can also designate a model as systemic-risk on other grounds, independent of the compute figure.Two thresholds, both required: the model must be a "frontier model," defined as a foundation model trained using more than 10^26 computing operations, and the developer, together with its affiliates, must have had annual gross revenues over $500 million in the preceding calendar year (Cal. Bus. & Prof. Code §22757.11(h)-(j)).
What must be publishedAll GPAI providers: technical documentation of training and testing (Article 53(1)(a)), information for downstream providers on capabilities and limitations, a Copyright Directive compliance policy, and a "sufficiently detailed summary" of training content. Systemic-risk providers add documented adversarial testing and systemic-risk assessment and mitigation (Article 55(1)(a)-(b)).A "frontier AI framework" published on the developer's website describing how it manages, assesses, and mitigates catastrophic risk, including safety standards it has adopted and its cybersecurity practices (§22757.12(a)), updated at least annually and within 30 days of a material change. A transparency report before deploying any new or substantially modified frontier model, covering release date, intended uses, and a summary of catastrophic-risk assessments (§22757.12(c)). A summary of any internal catastrophic-risk assessment every three months (§22757.12(d)).
Incident-reporting dutiesSystemic-risk GPAI providers must track, document, and report serious incidents and any corrective measures to the AI Office and, where relevant, national competent authorities "without undue delay" (Article 55(1)(c)). The Act does not attach a fixed number of hours or days to that phrase for GPAI incidents.Large frontier developers must report a "critical safety incident" to California's Office of Emergency Services within 15 days of discovery, or within 24 hours if there is an imminent risk of death or serious physical injury (§22757.13(c)). §22757.11(d) defines a critical safety incident to include unauthorized model-weight access causing death or injury, harm from a materialized catastrophic risk, loss-of-control incidents causing death or injury, and deceptive model behavior that subverts the developer's own controls.
Enforcement and penaltiesThe European Commission enforces GPAI obligations directly (not national regulators). Article 101 sets fines of up to 3% of a provider's total worldwide annual turnover for the preceding financial year, or €15,000,000, whichever is higher, for infringing GPAI provisions or obstructing the Commission's information and evaluation powers.The California Attorney General is the sole enforcer — SB 53 creates no private right of action (§22757.15(b)). Civil penalties run up to $1,000,000 per violation (§22757.15(a)), covering failures to publish the required framework or transparency report, false statements about risk management, and failures to report incidents.
Effective datesGPAI transparency and copyright obligations under Articles 53 and 55 applied from August 2, 2025 for models newly placed on the market; providers of models already on the market before that date have until August 2, 2027 to come into compliance. The Commission's enforcement powers against GPAI providers activated August 2, 2026.Signed into law September 29, 2025; took effect January 1, 2026. The California Department of Technology must report on frontier-model risk and the CalCompute public-compute framework on or before January 1, 2027, and may update SB 53's statutory thresholds as the technology changes.

Common questions

Common questions about EU AI Act (GPAI provisions) vs California SB 53 (TFAIA)

Does a model have to cross both the EU AI Act's threshold and SB 53's threshold to be covered by both laws?

+

No — the two thresholds are unrelated and are tested separately under each law. A model can clear the EU AI Act's 10^25 FLOPs compute presumption without its developer meeting SB 53's $500 million revenue threshold, and vice versa. A developer operating in both California and the EU has to test its models and its own revenue against each law's criteria independently.

Which law has the stricter incident-reporting deadline?

+

SB 53 sets fixed deadlines — 15 days generally, 24 hours if there is imminent risk of death or serious injury. The EU AI Act's Article 55(1)(c) uses the open-ended standard "without undue delay" for GPAI systemic-risk incidents, without a fixed number of days written into that provision.

Who enforces SB 53 versus the EU AI Act's GPAI rules?

+

SB 53 is enforced exclusively by the California Attorney General through civil actions, with no private right of action. The EU AI Act's GPAI provisions are enforced directly by the European Commission (via the AI Office) rather than by the national regulators that enforce most of the rest of the Act.

Are the penalty amounts comparable?

+

Not directly — they're structured differently. SB 53 penalties are capped at $1,000,000 per violation. EU AI Act Article 101 fines for GPAI infringements are calculated as the higher of €15,000,000 or 3% of the provider's total worldwide annual turnover, which for a large developer can exceed SB 53's fixed cap by a wide margin.

Referenced across the research world

University of Cambridge logoColumbia University logoCrossref logoUniversity of Edinburgh logoHarvard University logoUniversity of Oxford logoPrinceton University logoStanford School of Medicine logoUniversity College London logoORCID logoUniversity of Cambridge logoColumbia University logoCrossref logoUniversity of Edinburgh logoHarvard University logoUniversity of Oxford logoPrinceton University logoStanford School of Medicine logoUniversity College London logoORCID logo
  • University of Cambridge logo
  • Columbia University logo
  • Crossref logo
  • University of Edinburgh logo
  • Harvard University logo
  • University of Oxford logo
  • Princeton University logo
  • Stanford School of Medicine logo
  • University College London logo
  • ORCID logo

View CASRAI adoption →