What SB 53 actually requires
SB 53 applies to "frontier developers": any company that trains a foundation model using more than 10^26 integer or floating-point operations, counting cumulative compute across initial training and subsequent modification. Within that group, a stricter tier applies to "large frontier developers," defined by annual gross revenue of at least $500 million. Only large frontier developers have to publish a frontier AI framework; smaller frontier developers face lighter disclosure duties. The law took effect January 1, 2026, three months after Governor Newsom signed it. [1][6][7]
A large frontier developer's published framework has to describe how it identifies and mitigates catastrophic risk (defined around incidents causing mass casualties or at least half a billion dollars in damage), its governance structure for that work, its cybersecurity practices protecting model weights, and how it assesses risk from its own internal use of its models. The statute permits redactions for trade secrets, cybersecurity, and national security, and it requires the framework be reviewed and republished at least annually. [2][6]
Incident reporting and whistleblower protections
Covered developers must report a defined set of "critical safety incidents" to California's Office of Emergency Services: unauthorized access to model weights that causes death or injury, loss of control over a model resulting in injury or property damage, a model deceptively evading its developer's own safeguards or monitoring, or a model materially contributing to a catastrophic risk actually occurring. The standard deadline is 15 days after the developer becomes aware of the incident; if there is imminent risk of death or serious injury, that shrinks to 24 hours. The general public can also submit reports of suspected incidents through the same office. Starting January 1, 2027, the Office of Emergency Services will begin publishing anonymized annual summaries of what it received, and the Attorney General will do the same for whistleblower disclosures. [1][6][7]
The whistleblower provisions bar retaliation against an employee or contractor who discloses, or refuses to participate in activity they reasonably believe poses, a catastrophic risk from a frontier model, or who reports a violation of the law itself. Large frontier developers must maintain an anonymous internal reporting channel and give employees notice of these rights; a whistleblower who prevails is entitled to attorneys' fees. The Attorney General enforces the whole law through civil actions, with penalties that can reach $1 million per violation, scaled to severity. [6][7]
What changed since the SB 1047 veto
Atlas interpretation: SB 53 is Senator Scott Wiener's second attempt at this law. Newsom vetoed Wiener's prior bill, SB 1047, on September 29, 2024, exactly one year before he signed SB 53. In his veto message, Newsom argued that SB 1047 regulated models based on training cost and compute size rather than actual deployment risk, warning it "could give the public a false sense of security" while smaller, more specialized models might pose equal or greater danger, and he committed to working with the legislature, technologists, and academics on a more empirically grounded approach. That commitment produced an expert panel, whose March 2025 report fed directly into SB 53's drafting. [3][1]
Atlas interpretation: The substantive shift between the two bills is from pre-harm control to disclosure. SB 1047 would have required a shutdown capability (the "kill switch"), mandatory pre-training safety determinations, and independent third-party audits, and it tied penalties to a percentage of a model's training compute cost. SB 53 drops all of that: it does not mandate any technical safety design, does not require a company to prove a model is safe before training it, and does not use compute cost as a penalty basis. What survived is narrower and procedural: publish a framework, report incidents on a deadline, protect the people who report internally. Wiener's office also consulted major AI companies while drafting SB 53, which SB 1047 was widely reported not to have done to the same degree. [3][4]
Industry reaction, and OpenAI's reversal
Anthropic publicly endorsed SB 53 before it was signed, calling it a "trust but verify" approach: disclosure requirements rather than the prescriptive technical mandates it says "plagued" SB 1047. Anthropic argued the framework and system-card requirements would mostly formalize practices it already followed under its own Responsible Scaling Policy, and that without a mandatory floor, competitive pressure could push labs to quietly scale back safety disclosure to move faster. Anthropic later published its own Frontier Compliance Framework to satisfy the law's requirement. Meta and OpenAI lobbied against SB 53 while it moved through the legislature; OpenAI published an open letter urging Newsom not to sign it, arguing, alongside other large labs and investors including Andreessen Horowitz, that state-by-state AI rules would create a compliance patchwork and that AI safety regulation should be handled at the federal level instead. By August 2026, following an unrelated security incident, OpenAI had reversed that position and was instead publicly asking California to strengthen SB 53's requirements. [5][4][8]
Sources
- Governor Newsom signs SB 53, advancing California's world-leading artificial intelligence industry
Office of Governor Gavin Newsom · Sep 29, 2025
- California's SB 53: The First Frontier AI Law, Explained
Future of Privacy Forum
- Governor Newsom Vetoes Sweeping AI Regulation, SB 1047
Center for Security and Emerging Technology (Georgetown) · Oct 1, 2024
- California Governor Newsom signs landmark AI safety bill SB 53
TechCrunch · Sep 29, 2025
- Anthropic is endorsing SB 53
Anthropic · Sep 8, 2025
- With SB 53, California puts AI disclosure requirements on the map
International Association of Privacy Professionals (IAPP) · Oct 3, 2025
- California's SB 53: Understanding the Obligations in Effect Now and Into 2027
National Law Review · Sep 8, 2026
- OpenAI says California should strengthen its AI safety bill
TechCrunch · Aug 22, 2026