Law / United States / California

Transparency in Frontier Artificial Intelligence Act (SB 53)

Cal. Bus. and Prof. Code Sections 22757.10 to 22757.16

A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.

What follows is LexLint's own research summary of this law, not legal advice.

In force 9 months, effective 1 January 2026.

An AI governance rule binding private bodies.

As of 8 September 2026.

What it requires

  • If you are a large frontier developer (a frontier developer whose group had annual gross revenues over $500,000,000 in the prior calendar year), write, implement and publish on your website a frontier AI framework describing how you define and assess catastrophic-risk thresholds for your frontier models and apply mitigations, and review that framework at least once a year
  • Before or when you deploy a new or substantially modified frontier model, publish a transparency report giving the model's release date, supported languages, output modalities, intended uses, and any generally applicable restrictions
  • If you are a large frontier developer, add to that transparency report summaries of your catastrophic-risk assessments, their results, and the extent of any third-party evaluator involvement
  • If you are a large frontier developer, transmit summaries of catastrophic-risk assessments from your frontier models' internal use to the California Office of Emergency Services on a quarterly or agreed schedule
  • Report a critical safety incident to the Office of Emergency Services within 15 days of discovering it, or within 24 hours if it poses an imminent risk of death or serious injury
  • Do not make a materially false or misleading statement about catastrophic risk from your frontier models, or, if you are a large frontier developer, about your compliance with your own frontier AI framework
  • Do not retaliate against a covered employee who discloses, in good faith and with reasonable cause, that your activities pose a catastrophic-risk danger to public health or safety or that you violated this Act; if you are a large frontier developer, also provide an internal channel for anonymous disclosure of that kind

If you get it wrong

Criminal exposureNo

Private right of actionYes

Penalty structure

Bus. and Prof. Code section 22757.15(a): a large frontier developer that fails to publish or transmit a required document, makes a false or misleading statement in violation of section 22757.12(e), fails to report a critical safety incident, or fails to comply with its own frontier AI framework is subject to a civil penalty, scaled to the severity of the violation, of up to $1,000,000 per violation. Section 22757.15(b) limits recovery to a civil action brought by the Attorney General alone.

Rule
Per violation only
As of
8 September 2026
Currency
USD
Per violation unit
Violation
Per violation amount
1,000,000

Who enforces it

Enforcement body

The chapter's own civil penalty (Section 22757.15) is recovered only in a civil action brought by the Attorney General. The whistleblower-retaliation protections in Labor Code Section 1107 et seq. are enforced separately, through a covered employee's own civil action.

Enforcement record

The Attorney General's own dedicated page for the Transparency in Frontier Artificial Intelligence Act describes the covered-employee whistleblower reporting channel and the annual aggregated whistleblower-report disclosure required by Section 22757.14(d), a report not yet due, but names no civil action or civil penalty brought under the chapter's own enforcement provision, Section 22757.15. A review of the Attorney General's most recent press releases, September 1 through September 17, 2026, within the chapter's 2026-01-01 to date effective period, names no frontier developer, catastrophic-risk finding, or Section 22757.15 penalty; earlier weeks of the chapter's effective period were not reviewed.

As of
17 September 2026
Source link
https://oag.ca.gov/sb53

What it reaches

Obligation class

Disclosure, Governance, Reporting

What it makes you log

Who may demand the log

Regulator, Public

What the log must hold

Event time, System identity, Decision basis

Log retention

Section 22757.12(f)(2)'s five-year floor applies to the unredacted version of information a frontier developer redacts from a published framework or transparency report; it does not apply to a document the developer never redacts.

Unit
Years
As of
21 September 2026
Basis
Fixed
Minimum value
5

Logging duty

A large frontier developer must publish a frontier AI framework and a transparency report, and every frontier developer must report a critical safety incident to the Office of Emergency Services stating its date, the reasons it qualifies, a description, and whether it involved internal use. Section 22757.13 never uses the words log, record, event recording, or audit trail; it uses report, and section 22757.12(f) uses document. Filing an accurate incident report, and the transparency report's own summaries of risk assessments, cannot be produced on demand without an underlying record the developer already keeps.

Kind
Implicit
As of
21 September 2026
Provision
Sections 22757.12 and 22757.13
Trigger
security_incident

Why the legislator wanted it

SEC. 1(i) of the enacted bill, part of the Legislature's own findings and declarations that precede the chapter's operative text.

As of
21 September 2026
Quote
Incident reporting systems enable monitoring of the post-deployment impacts of artificial intelligence.
Source link
https://leginfo.legislature.ca.gov/faces/billTextClient.xhtml?bill_id=202520260SB53
Source kind
Recital
Purpose
  • incident_reconstruction
  • oversight_and_correction

Who checks it

Audit expectation

continuous

What this law does

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

California's Transparency in Frontier Artificial Intelligence Act (TFAIA) was added by SB 53, chaptered as Stats 2025 Chapter 138, and is effective 1 January 2026 per the code's own history note.

A large frontier developer (a frontier developer whose group had annual gross revenues over $500,000,000 in the preceding year) to write, implement and publish on its website a frontier AI framework describing how it defines and assesses catastrophic-risk thresholds for its frontier models (foundation models trained using more than 10^26 integer or floating-point operations) and applies mitigations, and to review that framework at least annually.

Before or when deploying a new or substantially modified frontier model, every frontier developer must publish a transparency report with baseline model information, and a large frontier developer must add summaries of its catastrophic-risk assessments and any third-party evaluator involvement.

A large frontier developer must also transmit summaries of internal-use catastrophic-risk assessments to the Office of Emergency Services on a quarterly or agreed schedule, and every frontier developer must report a critical safety incident to the Office within 15 days of discovering it, or 24 hours if it poses an imminent risk of death or serious injury.

A frontier developer may not make a materially false or misleading statement about catastrophic risk or, for a large frontier developer, about its framework compliance, and a companion whistleblower chapter (Lab.

Code Section 1107 et seq.) bars a frontier developer from retaliating against a covered employee who reports a reasonable belief of catastrophic-risk danger or a TFAIA violation, arming that employee with a private civil action and attorney's fees, separate from the chapter's own civil penalty which the Attorney General alone may bring.

When LexLint raises it

  • trains_models
  • generates_content

Read the law

official California Legislative Information (leginfo) chaptered bill text

Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.

Back to the example  ·  Lint your app