Skip to main content
v2026.11,858 entries · CC-BY 4.0

California SB 53 (Transparency in Frontier Artificial Intelligence Act): The Foundational Explainer

A plain-language breakdown of what California SB 53 actually requires: who counts as a frontier developer, the frontier AI framework and transparency report obligations, the 15-day critical safety incident reporting duty, whistleblower protections, and civil penalties.

Written and maintained by CASRAI Editorial Board

Last updated

California’s SB 53, the Transparency in Frontier Artificial Intelligence Act (TFAIA), is the first US state law to directly regulate the developers of the largest AI models on the basis of catastrophic risk. Governor Newsom signed it on September 29, 2025, and its core obligations take effect January 1, 2026. Unlike most state AI legislation, which targets bias, discrimination, or consumer-facing harms, SB 53 is narrowly aimed at one thing: forcing the handful of companies training the most computationally intensive models to document, disclose, and report on how they manage risks that could cause mass casualties or catastrophic economic damage.

This guide explains who the law covers, what it requires, and how its reporting duties are enforced, based on the enacted bill text (codified primarily as new sections 22757.11 through 22757.15 of the California Business and Professions Code, plus a new Labor Code section 1107.1 for whistleblower protections).

Who SB 53 covers

SB 53 defines two tiers of covered entity, and the obligations differ between them.

  • Frontier developer. Any person or organization that has trained, or has begun training, a “frontier model” — defined as a foundation model trained using more than 1026 integer or floating-point operations of computing power. This is the same compute threshold used in the federal government’s earlier AI executive order reporting requirements, and it currently captures only the handful of labs training the largest general-purpose models.
  • Large frontier developer. A frontier developer that, together with its affiliates, had annual gross revenues exceeding $500,000,000 in the preceding calendar year. Large frontier developers carry the heaviest obligations under the law: publishing a full frontier AI framework and including catastrophic-risk assessment detail in their transparency reports. A frontier developer below the revenue threshold still owes a baseline transparency report, just a shorter one.

Because the thresholds are defined by compute and revenue rather than by naming specific companies, coverage will expand or contract automatically as more organizations cross the 1026-operation line or grow past $500 million in revenue.

The frontier AI framework requirement

A large frontier developer must write, implement, and clearly publish on its website a frontier AI framework — a public document describing how it identifies and manages catastrophic risk across the model lifecycle. The framework has to address cybersecurity practices around model weights, the thresholds and methodology the developer uses to assess catastrophic risk, mitigation strategies once a risk is identified, the developer’s use of third-party evaluators, and its internal governance and accountability structure for these decisions. Trade secrets and information that would create a security risk can be redacted, but the framework itself has to be public.

The framework isn’t a one-time filing: developers must review it at least annually, and publish any material modification within 30 days of making it. In practice, this creates a running public record of how a lab’s own stated risk thresholds and mitigations change over time — the kind of primary-source material NIKOLAI’s frontier-AI safety elements are built to track (more on that below).

The transparency report requirement

Before deploying a new frontier model, or a substantially modified version of an existing one, a frontier developer has to publish a transparency report. At minimum, every frontier developer’s report needs to include basic release information: website contact details, release date, supported languages, output modalities, intended uses, and any usage restrictions.

Large frontier developers owe more: their transparency reports must also summarize the catastrophic-risk assessments they ran on the model, the results of those assessments, and whether and how third-party evaluators were involved. This is the provision that turns SB 53 from a general disclosure law into something closer to a standardized, comparable safety-reporting format — assuming developers converge on comparable ways of describing “catastrophic risk assessment,” which is exactly the kind of terminology gap NIKOLAI exists to make legible.

Critical safety incident reporting

SB 53’s most operationally binding duty is incident reporting. A frontier developer must report any critical safety incident involving one of its frontier models to California’s Office of Emergency Services (Cal OES) within 15 days of discovering it. If the incident poses an imminent risk of death or serious physical injury, the reporting window shortens to 24 hours, and the report goes to the appropriate law enforcement or public safety authority rather than waiting for the standard OES channel.

The incidents the law cares about map directly to its definition of catastrophic risk: a foreseeable and material risk that a frontier model will contribute to the death of, or serious injury to, more than 50 people, or to more than $1 billion in property or economic damage, arising from the model’s role in creating or enabling a chemical, biological, radiological, or nuclear weapon; carrying out a cyberattack on critical infrastructure without meaningful human oversight; or acting with limited human oversight, intervention, or control in a way that evades its own developer’s or user’s control. Covered incidents include unauthorized access to or tampering with a model, any of the above catastrophic-risk scenarios actually materializing, loss of model control that causes death or injury, and a model’s use of deceptive techniques to undermine its operator’s ability to monitor or control it.

Whistleblower protections

SB 53 adds a new whistleblower provision, Labor Code section 1107.1, specifically for employees and contractors of frontier developers. Covered employees can’t be prevented or retaliated against for disclosing information — to the state Attorney General, a federal authority, a supervisor, or another employee with authority to investigate — about a catastrophic risk or a violation of the transparency and safety-framework chapter. Large frontier developers additionally have to stand up an anonymous internal reporting channel and provide monthly status updates to anyone who uses it. A successful whistleblower plaintiff can recover reasonable attorney’s fees.

Penalties and enforcement

SB 53 has no private right of action. It is enforced exclusively by the California Attorney General through civil actions, and violations — failing to publish a required framework or report, or making false or misleading statements in one — carry civil penalties of up to $1,000,000 per violation, scaled to the severity of the violation. There’s no per-day accrual specified in the statute; the ceiling is set per violation, decided case by case.

How SB 53 relates to NIKOLAI

California SB 53 is one of the primary sources NIKOLAI, CASRAI’s open dictionary of frontier-AI safety elements, draws on to build its vocabulary, alongside frameworks like Anthropic’s Responsible Scaling Policy, OpenAI’s Preparedness Framework, Google DeepMind’s Frontier Safety Framework, and the EU’s GPAI Code of Practice. That matters because SB 53 doesn’t define most of its operative terms in isolation — “catastrophic risk,” “frontier AI framework,” and “critical safety incident” are all concepts that labs were already describing, inconsistently, in their own voluntary safety documentation before the law existed. NIKOLAI’s job is to map how a given lab’s own framework language lines up (or doesn’t) with what a statute like SB 53 actually requires, without CASRAI certifying anyone as “compliant.” For anyone trying to compare what a frontier developer’s published framework says against what SB 53 obligates it to say, NIKOLAI is the reference point for the underlying terminology.

Frequently asked questions

Does SB 53 apply to AI companies outside California?

Yes, if they do business in California and meet the frontier-developer and, where relevant, large-frontier-developer thresholds. The law is not limited to companies headquartered in the state; it applies based on the developer’s activity and revenue, not its location of incorporation.

Does SB 53 regulate AI use, or only AI development?

SB 53 regulates frontier model developers, not downstream deployers or users of AI systems. A company that merely uses a frontier model built by someone else is not a “frontier developer” under this law and has no direct obligations under it.

Is SB 53 the same as California’s other AI bills from 2025?

No. SB 53 followed Governor Newsom’s veto of the broader SB 1047 in 2024, and it is deliberately narrower — focused on transparency and disclosure rather than mandating specific safety testing or imposing a “kill switch” requirement. It should not be confused with California’s separate AI bills covering areas like automated decision-making, deepfakes, or chatbot disclosure, which impose different obligations on different entities.

What counts as a “substantially modified” model that triggers a new transparency report?

SB 53’s enacted text does not give a bright-line technical definition of “substantially modified” beyond tying the transparency-report trigger to deployment of a new or substantially modified frontier model. Developers and regulators will likely need implementing guidance or enforcement precedent to settle edge cases like major fine-tunes or retrained checkpoints.

Does the 15-day incident reporting clock start at the incident or at discovery?

At discovery. The statute measures the 15-day window (and the 24-hour window for imminent death or injury risk) from when the frontier developer discovers the critical safety incident, not from when the incident itself occurred.

Follow CASRAI

Research-administration guidance, standards updates and independent tool reviews.

Ask CASRAI · free to try

Ask about California SB 53 (Transparency in Frontier Artificial Intelligence Act): The Foundational Explainer

Ask your first 2 questions free below. Subscribers get 150 a day for $29 a month.

Ask CASRAI answers research-administration questions and cites the passages behind every claim. When our sources don't cover a question, it says so.

Answers draw on CASRAI's guides and dictionary plus the federal and funder documents we index: Federal Register, Grants.gov, Regulations.gov and UKRI.

Works on this site and inside Claude, Cursor and the AI tools you already use.

Everything CASRAI publishes — this page, the dictionary, the guides and the news — stays free to read, with no account and no card.

Referenced across the research world

University of Cambridge logoColumbia University logoCrossref logoUniversity of Edinburgh logoHarvard University logoUniversity of Oxford logoPrinceton University logoStanford School of Medicine logoUniversity College London logoORCID logoUniversity of Cambridge logoColumbia University logoCrossref logoUniversity of Edinburgh logoHarvard University logoUniversity of Oxford logoPrinceton University logoStanford School of Medicine logoUniversity College London logoORCID logo
  • University of Cambridge logo
  • Columbia University logo
  • Crossref logo
  • University of Edinburgh logo
  • Harvard University logo
  • University of Oxford logo
  • Princeton University logo
  • Stanford School of Medicine logo
  • University College London logo
  • ORCID logo

View CASRAI adoption →