On January 1, 2026, California’s SB 53 imposed groundbreaking new requirements on developers of the most advanced artificial intelligence systems, known as “frontier models.” Companies that develop or deploy frontier models should conduct a threshold analysis to determine whether SB 53 applies and begin building the internal governance infrastructure the law requires. Following up on our first blog post on this topic, we provide an overview of this law’s key compliance obligations, effective dates, and recommended action items for businesses.
SB 53: Transparency in Frontier Artificial Intelligence Act
Effective: January 1, 2026 (with some provisions effective on January 1, 2027)
On September 29, 2025, Gov. Gavin Newsom signed SB 53, the Transparency in Frontier Artificial Intelligence Act (TFAIA), making California the first state to impose broad safety and transparency requirements on developers of advanced AI models. TFAIA creates a regulatory structure focused on transparency, accountability, and catastrophic risk management for frontier AI development. The law defines “catastrophic risk” as a foreseeable and material risk that a frontier developer’s development, storage, use, or deployment of a frontier model will materially contribute to the death of, or serious injury to, more than 50 people, or more than $1 billion in damage to property, arising from a single incident.
Who Is Covered
The law regulates “frontier developers.” A frontier developer is any person that has trained, or initiated the training of, a frontier model — a foundation model trained using a quantity of computing power greater than 10^26 integer or floating-point operations. The law’s most demanding obligations fall on “large frontier developers,” defined as frontier developers whose annual gross revenues, together with those of their affiliates, exceeded $500 million in the preceding calendar year. The California Department of Technology must review these definitions annually and may recommend updates, meaning the law’s scope will likely evolve over time.
Obligations in Effect Now
All frontier developers must publish a transparency report on their website at or before deploying any new or substantially modified frontier model, identifying the model’s release date, output modalities, intended uses, and a mechanism for users to contact the developer.
Large frontier developers must additionally draft, implement, and publicly post a “Frontier AI Framework,” an enterprise-level governance document describing how the company identifies and assesses catastrophic risk, incorporates industry standards, leverages independent third-party evaluators, secures unreleased model weights, and governs internal use of its frontier models. The framework must be reviewed at least annually and updated within 30 days of any material change.
Any frontier developer that discovers a critical safety incident must notify the California Office of Emergency Services within 15 days. If the incident presents an imminent risk of death or serious physical injury, that window shrinks to 24 hours. The law also prohibits retaliation against employees who report safety risks or legal violations, requires large frontier developers to maintain an anonymous internal reporting channel, and entitles successful whistleblowers to attorneys’ fees. Civil penalties under the law can reach up to $1 million per violation and are enforced by the California attorney general.
Provisions Effective in 2027
By January 1, 2027, the California Office of Emergency Services will begin publishing anonymized annual summaries of critical safety incidents, which include the loss of control of a frontier model resulting in death or bodily injury and deceptive behavior by a frontier model that subverts the developer’s controls in a manner that materially increases catastrophic risk. The attorney general will begin releasing anonymized annual reports drawn from whistleblower disclosures. In addition, by January 1, 2027, a consortium established under the law must deliver a report on the design and funding structure for “CalCompute,” a proposed state-operated public cloud computing cluster intended to expand affordable access to high-performance computing for researchers and startups.
Compliance Takeaways
With some obligations already in effect and additional deadlines approaching in 2027, companies should assess their potential exposure now. Key considerations include:
- Determining whether your business’ models and revenues meet the definitions of “frontier developer” or “large frontier developer” under SB 53 and performing an ongoing analysis of whether your business falls within the law’s scope. These definitions will likely expand over time.
- Creating a Frontier AI Framework, treating the framework as a living governance document rather than a static compliance filing, and aligning the framework with established standards such as NIST AI 600-1 or ISO/IEC 42001.
- If SB 53 applies, establishing internal escalation protocols for critical safety incident reporting, given the strict 15-day and 24-hour reporting windows.
- For businesses working with frontier models, create or update your internal whistleblower policies to cover employees who report health and safety risks posed by your frontier model.
SB 53 marks a turning point in how California intends to regulate frontier AI developers and their models in order to manage catastrophic risk. Companies that invest in governance infrastructure now will hold a competitive advantage as thresholds evolve. If you have questions about this law or its impact on your operations, please contact the authors.
