California SB 53, the Transparency in Frontier Artificial Intelligence Act, was approved by the Governor on September 29, 2025 (Chapter 138) and takes effect January 1, 2026. It binds frontier developers, meaning those training foundation models with more than 10^26 operations, and not banks that deploy their models: large frontier developers (over $500 million in revenue) must publish a frontier AI framework, all frontier developers must publish transparency reports on new models, and critical safety incidents must be reported to the Office of Emergency Services within 15 days. Penalties are up to $1 million per violation, enforced only by the Attorney General. For a bank the effect is indirect: it creates no deployer duty and no right to incident notice, but it gives vendor-risk teams published safety frameworks and transparency reports to review when buying frontier models.
OFFICIAL TEXT: leginfo.legislature.ca.gov ↗ · IN FORCE · CALIFORNIA CPPA
| Document | California SB 53 (Transparency in Frontier AI Act) — Senate Bill 53: Artificial intelligence models: large developers (Transparency in Frontier Artificial Intelligence Act), Chapter 138, Statutes of 2025 |
| Issued by | California — Privacy Protection Agency (CCPA/CPRA automated decisionmaking, risk-assessment and cybersecurity-audit regulations), Attorney General, and Civil Rights Council |
| Type | Statute |
| Status | In force |
| Published | Sep 29, 2025 |
| Effective | Jan 1, 2026 |
| Applies to | 'Frontier developers' that train foundation models using more than 10^26 operations, and 'large frontier developers' with more than $500 million in annual gross revenue. It does not regulate banks as deployers or users of AI. A bank is covered only if it itself trains a model above the threshold, which is unlikely; its relevance to banks is as a source of safety disclosures from the frontier model vendors they buy from |
| Official source | leginfo.legislature.ca.gov ↗ |
| Use cases | Third-party & vendor AI · Generative & agentic AI · AI governance (general) · Cybersecurity · Model risk management |
What are the key points of California SB 53 (Transparency in Frontier AI Act)?
- Adds Chapter 25.1 (commencing with Section 22757.10) to Division 8 of the Business and Professions Code; the Act also adds Government Code §11546.8 (CalCompute) and Labor Code Chapter 5.1 (commencing with §1107) on whistleblowers. Approved by the Governor and filed September 29, 2025 as Chapter 138.
- §22757.11 definitions: a 'frontier model' is a foundation model trained using more than 10^26 integer or floating-point operations (including fine-tuning and reinforcement learning); a 'large frontier developer' is a frontier developer that, with its affiliates, had annual gross revenues above $500,000,000 in the preceding calendar year; 'catastrophic risk' means a foreseeable and material risk of death or serious injury to more than 50 people or more than $1 billion in damage from a single incident.
- §22757.12(a)–(b): a large frontier developer must write, implement, comply with and publish a frontier AI framework covering ten topics (standards, thresholds, mitigations, third-party assessment, cybersecurity for model weights, incident response, internal governance and others), review it at least annually, and publish material changes with a justification within 30 days.
- §22757.12(c): before or concurrently with deploying a new or substantially modified frontier model, every frontier developer must publish a transparency report (website, contact mechanism, release date, languages, output modalities, intended uses, restrictions); large frontier developers must add summaries of catastrophic-risk assessments, results and third-party involvement. A model or system card can satisfy it.
- §22757.12(d)–(e): large frontier developers must send the Office of Emergency Services a summary of catastrophic-risk assessments from internal use every three months (or another agreed schedule); no materially false or misleading statements about catastrophic risk or, for large developers, about compliance with their framework.
- §22757.13: critical safety incidents must be reported to the Office of Emergency Services within 15 days of discovery, or within 24 hours to an appropriate authority where there is an imminent risk of death or serious physical injury; reports are exempt from the California Public Records Act, and the Office produces anonymized annual reports from January 1, 2027.
- §22757.15: a large frontier developer that fails to publish or transmit required documents, makes a prohibited statement, fails to report an incident or fails to follow its own framework faces a civil penalty of up to $1,000,000 per violation, recoverable only in a civil action by the Attorney General.
- Labor Code §1107.1 protects covered employees who disclose catastrophic-risk dangers or violations and requires large frontier developers to run an anonymous internal reporting process; §5 of the Act preempts local rules on frontier developers' management of catastrophic risk adopted on or after January 1, 2025, and says it does not apply to the extent preempted by federal law.
What did California SB 53 (Transparency in Frontier AI Act) change for banks?
SB 53 is a California statute aimed squarely at frontier AI developers, built on transparency and incident reporting rather than prescriptive safety standards. It does not change any obligation for banks. Its practical significance for them is on the supply side: the frontier labs that supply foundation models to banks must now publish a safety framework and a transparency report for each new model, which gives vendor-risk and model-risk teams a standardized document to request and compare. It is not a substitute for a bank's own model validation, and it creates no contractual or notice right against the developer.
What does California SB 53 require, and does it apply to banks?
California SB 53, the Transparency in Frontier Artificial Intelligence Act (Business and Professions Code §§22757.10–22757.16), requires frontier developers, meaning those training foundation models with more than 10^26 operations, to publish transparency reports for new models and report critical safety incidents to the Office of Emergency Services within 15 days. Large frontier developers, with more than $500 million in annual revenue, must also publish and follow a frontier AI framework, review it annually, send quarterly summaries of internal-use risk assessments to the Office, and avoid materially false statements about catastrophic risk. Violations carry civil penalties up to $1 million each, enforced by the Attorney General. SB 53 does not apply to banks as users of AI; a bank is covered only if it trains a frontier model, so its effect on banks is indirect, through the disclosures its AI vendors must now make.
| Rule | Authority | What it requires | Applies |
|---|---|---|---|
| B&P Code §22757.11 — Thresholds | California CPPA | 'Frontier model' means more than 10^26 operations of training compute; 'large frontier developer' means more than $500 million in annual gross revenue with affiliates in the preceding year. | From January 1, 2026 |
| B&P Code §22757.12(a)–(b) — Frontier AI framework | California CPPA | Large frontier developers publish and follow a framework on catastrophic-risk standards, thresholds, mitigations, third-party assessment, weight security, incident response and governance; review it annually and publish material changes within 30 days. | From January 1, 2026 |
| B&P Code §22757.12(c) — Transparency report | California CPPA | Before or at deployment of a new or substantially modified frontier model, publish website, contact, release date, languages, modalities, intended uses and restrictions; large developers add catastrophic-risk assessment summaries. | From January 1, 2026 |
| B&P Code §22757.12(d) — Internal-use risk summaries | California CPPA | Large frontier developers send the Office of Emergency Services a summary of catastrophic-risk assessments from internal use every three months or on an agreed schedule. | From January 1, 2026 |
| B&P Code §22757.12(e) — No false statements | California CPPA | No materially false or misleading statements about catastrophic risk (all frontier developers) or about framework implementation and compliance (large developers), unless made in good faith and reasonable. | From January 1, 2026 |
| B&P Code §22757.13 — Critical safety incident reports | California CPPA | Report critical safety incidents to the Office of Emergency Services within 15 days of discovery, or within 24 hours to an appropriate authority if there is an imminent risk of death or serious physical injury. | From January 1, 2026 |
| B&P Code §22757.15 — Penalties | California CPPA | Civil penalty up to $1,000,000 per violation by a large frontier developer, recoverable only by the Attorney General. | From January 1, 2026 |
| Labor Code §1107.1 — Whistleblower protections | California CPPA | Frontier developers may not prevent or retaliate against covered employees' disclosures of catastrophic-risk dangers or violations; large developers must provide an anonymous internal reporting process. | From January 1, 2026 |
SB 53 is a disclosure and incident-reporting statute, not a safety standard: it does not prescribe what a developer's framework must conclude, only that the developer publish one, follow it and not misstate it. The compute threshold of 10^26 operations and the $500 million revenue test mean it reaches only a handful of the largest model developers; the Department of Technology must recommend by January 1, 2027 whether to update the definitions. The Act states its duties are cumulative with other law and does not apply to the extent preempted by federal law or in conflict with a federal contract.
Banks sit downstream. They are 'users' of frontier models, not developers, so SB 53 gives them no direct obligations and no right to receive incident reports, which go to the Office of Emergency Services and are exempt from public-records disclosure. The statute also does not override a bank's own supervisory expectations for third-party risk and model risk management; it adds a published framework and a transparency report per model that a bank can request and read.
SB 53 should be read next to New York's RAISE Act, which follows the California model with a shorter incident window and a new DFS oversight office, and to California's other AI rules, notably the California Privacy Protection Agency's ADMT regulations, which are the instruments that reach bank decisions about customers and employees.
WHAT THIS MEANS IN PRACTICE
- Do not treat SB 53 as a compliance obligation for the bank; record it in the AI vendor-risk file as a source of vendor disclosures instead.
- When onboarding a frontier model, request the vendor's published frontier AI framework and transparency report and map them to your third-party risk and model validation checklist.
- Add contract terms requiring the vendor to notify the bank of incidents that affect it, because SB 53 sends critical safety incident reports to California's Office of Emergency Services, not to customers.
- Check each vendor's thresholds: a developer under 10^26 operations or $500 million in revenue may fall outside the Act, so its absence of an SB 53 framework is not itself a red flag.
- Keep the bank's own validation, explainability and fair-lending testing in place; vendor safety disclosures about catastrophic risk do not address credit bias, accuracy or conduct risks.
Does California SB 53 apply to banks?
Not as deployers or users of AI. SB 53 regulates 'frontier developers' that train foundation models with more than 10^26 operations, and 'large frontier developers' with over $500 million in revenue. A bank would be covered only if it trained a model above that threshold itself. Banks' own AI use is governed by other law.
When does California SB 53 take effect?
SB 53 was approved by the Governor on September 29, 2025 and takes effect January 1, 2026. The Office of Emergency Services and Attorney General begin annual public reports on January 1, 2027, and the Department of Technology's first annual review of the definitions is due on or before January 1, 2027.
What are the penalties under California SB 53?
A large frontier developer that fails to publish or transmit required documents, makes a prohibited false statement, fails to report an incident or breaks its own framework faces a civil penalty of up to $1,000,000 per violation. Only the Attorney General can bring the civil action to recover the penalty.
What does SB 53 mean for bank AI vendors?
Frontier model providers above the thresholds must publish a frontier AI framework (large developers) and a transparency report for each new model, and report critical safety incidents to the Office of Emergency Services. Banks do not receive those incident reports, so vendor contracts should still require their own notification and audit rights.
How does California SB 53 compare with the New York RAISE Act?
Both target large frontier developers with published safety frameworks and incident reporting. New York's final law sets a 72-hour incident-reporting window against California's 15 days, adds registration and fees through a new office within DFS, and allows penalties up to $1 million for a first and $3 million for later violations; California's maximum is $1 million per violation.
| Date | Document | Status |
|---|---|---|
| Sep 30, 2026 | SB 947 — Employment: Automated Decision Systems (No Robo Bosses Act) | Final |
| Sep 28, 2026 | AB 1609 — Customer Service Chatbots (Right to Human Customer Service Act) | Final |
| Sep 22, 2025 | CPPA ADMT, risk-assessment and cybersecurity-audit regulations — CCPA Updates, Cybersecurity Audits, Risk Assessments, Automated Decisionmaking Technology, and Insurance Companies — approved regulation text (11 CCR Division 6) | In force |
| Jun 27, 2025 | Civil Rights Council ADS employment regulations — Modifications to Employment Regulations Regarding Automated-Decision Systems (Fair Employment and Housing Act regulations, 2 CCR) | In force |
| Jan 13, 2025 | California AG legal advisory on AI (Jan 2025) — Legal Advisory: Application of Existing California Laws to Artificial Intelligence | Final |
| Jun 28, 2018 | Cal. Civ. Code §1798.145 (CCPA exemptions, incl. GLBA data) — California Consumer Privacy Act — exemptions, including the data-level exemption for information subject to the Gramm-Leach-Bliley Act and the California Financial Information Privacy Act (Civil Code §1798.145) | In force |
Follow every document these regulators publish
when one of these regulators moves, the next morning's brief says so · six sourced stories · 7 am ET · free
plus every tracker, bank and agent page update, the morning after · leave any morning