California's Transparency in Frontier AI Act (SB 53) requires large frontier developers to publish frontier AI frameworks addressing catastrophic risk, model weight cybersecurity and incident response, and to report critical safety incidents to the Office of Emergency Services. Its catastrophic risk definition includes a model engaging, with no meaningful human oversight, in conduct that is a cyberattack, where a single incident causes death or serious injury to more than 50 people or more than $1 billion in property damage.
Why it matters
It is a binding US state law that ties catastrophic risk to autonomous cyberattack conduct by a model.
Key facts
As stated in the sources, with where to find them.
- Catastrophic risk includes a frontier model engaging, with no meaningful human oversight, intervention or supervision, in conduct that is a cyberattack, where a single incident causes death or serious injury to more than 50 people or more than $1 billion in property damage or loss.Definitions, 'catastrophic risk'
- Critical safety incidents must be reported to the Office of Emergency Services within 15 days; an incident posing imminent risk of death or serious physical injury must be disclosed within 24 hours to an appropriate authority, such as a law enforcement or public safety agency.Critical safety incident reporting provisions
- Applies to frontier models trained above 10^26 operations; 'large frontier developer' means annual revenue above $500 million; civil penalties up to $1 million per violation.Definitions; enforcement
Findings that cite this record
No tracked finding cites this record yet.
Sources
Related records
Jul 10, 2025
Aug 2, 2025
Jun 2, 2026
Jul 23, 2025
Sep 23, 2026
May 22, 2026