← Back to Sia website
Sia RegAI  /  Blog  /  California SB53
Analysis · Frontier AI

California SB53: frontier-AI transparency requirements.

Published July 26, 2026Reviewed July 26, 20264-minute readBy Cyril Sayada

California's Transparency in Frontier Artificial Intelligence Act is deliberately narrow. It is not a general enterprise AI law: its central requirements apply to developers training models above a very high compute threshold, with additional governance duties for large frontier developers.

Direct answer: SB53 was signed on 29 September 2025. A frontier model is defined around training compute above 1026 integer or floating-point operations; a large frontier developer also crosses the statute's $500 million prior-year group-revenue threshold. Confirm both definitions before building the compliance program.

Step 1: establish coverage

The law defines a foundation model as one trained on a broad dataset, designed for generality of output and adaptable to a wide range of tasks. A frontier developer is a person that has trained or initiated training of a frontier model at the statutory compute threshold. The compute count includes the original training run and subsequent fine-tuning, reinforcement learning and other material modifications applied to a preceding model.

Document the calculation, affiliates, revenue period, model lineage and planned compute before training begins. The statute directs California to revisit definitions over time, so preserve the assumptions rather than storing only a yes/no result.

Public frontier-AI framework

A large frontier developer must write, implement, comply with and clearly publish a frontier-AI framework. The framework must explain how the developer:

  • uses national, international and industry-consensus standards;
  • sets and assesses catastrophic-risk capability thresholds;
  • selects mitigations from assessment results;
  • reviews assessments and mitigations before deployment or extensive internal use;
  • uses third-party evaluators;
  • updates the framework and treats substantial model modifications;
  • protects unreleased model weights;
  • identifies and responds to critical safety incidents;
  • maintains internal governance; and
  • manages catastrophic risk from internal model use.

The framework must be reviewed at least annually. A material modification must be published with a justification within 30 days.

Model transparency reports

Before or when deploying a new frontier model or substantially modified version, a frontier developer must publish basic information including contact mechanism, release date, supported languages and output modalities, intended uses, and generally applicable restrictions or conditions.

A large frontier developer must add summaries of catastrophic-risk assessments and results, third-party evaluator involvement, and other steps taken under the framework. A system card or model card can satisfy the requirement when it contains the statutory information. Build one controlled disclosure dataset and publish from it rather than maintaining separate, drifting documents.

Incident and internal-use reporting

The law requires mechanisms for reporting critical safety incidents to California's Office of Emergency Services and confidential summaries of catastrophic-risk assessments from extensive internal use. The operating model needs an incident-classification rule, escalation clock, protected channel, accountable submitter, legal and security review, and proof of submission.

Redactions and retention

Published compliance documents may redact information when necessary to protect trade secrets, cybersecurity, public safety, national security or compliance with other law. The public version must describe the character and justification of the redaction to the permitted extent, and the unredacted information must be retained for five years.

Whistleblower controls

SB53 adds protections for covered employees reporting specified catastrophic-risk or compliance concerns and requires large frontier developers to maintain an internal process for anonymous disclosure. Treat this as part of model governance, not only an HR policy: route issues to people with technical, safety, legal and remediation authority, and protect the reporter's identity.

Implementation checklist

  1. Establish a compute, model-lineage, affiliate and revenue coverage record.
  2. Map the public framework to real assessment, deployment and security processes.
  3. Create a reusable model-transparency-report data model.
  4. Define catastrophic-risk and critical-incident escalation and submission.
  5. Control public redactions and retain unredacted evidence for five years.
  6. Connect anonymous reporting to investigation and remediation governance.
  7. Review the framework annually and publish material modifications within 30 days.

How Sia RegAI can support the workflow

RegReview can monitor California updates, definition reviews and related federal or international standards. RegMatcher can map SB53 requirements to the model lineage, frontier-AI framework, assessment records, transparency reports, incident procedures, redaction decisions and retained evidence. Technical experts and counsel remain responsible for compute calculations, catastrophic-risk judgments, redactions and reports.

Primary source

This analysis is general information, not legal advice. Confirm the current statutory definitions, guidance and facts of the model and developer.

Connect frontier-model governance to the published evidence.

Keep thresholds, assessments, mitigations, disclosures and incidents tied to the controlling source.