The Regulated Company Asked for a Tighter Leash
Here's the deal: this story normally runs the other way. A law passes, the company hires lobbyists, and the asks are always the same — raise the threshold, delay the effective date, carve out one more exemption. That's the standard grammar of a regulated industry. But on August 22, 2026, OpenAI's global affairs team posted something on LinkedIn that inverted the script. It asked California to make SB 53, the state's frontier AI safety law, stronger.
Two specific asks. First, mandate monitoring of frontier models while they are being trained or evaluated for potential serious incidents. Second, strengthen cybersecurity protections across the entire model-development lifecycle. The company wrote that "as California continues to lead on frontier safety, we are committed to working with the California legislature and the Governor to strengthen California SB 53." TechCrunch broke the story on August 22, with Engadget and The Next Web following.
And here's what makes it strange. OpenAI publicly opposed this law's predecessor. In August 2024, then-chief strategy officer Jason Kwon sent a letter to State Senator Scott Wiener and Governor Gavin Newsom arguing that SB 1047 would chill innovation and push talent out of California, and that AI belonged to federal lawmakers rather than state ones. Wiener's office fired back with an official statement noting that OpenAI's letter did not criticize a single provision of the bill — it just argued the venue was wrong.
So in roughly two years, the same company moved from "states should stay out of this" to "the state law needs sharper teeth." The question worth chewing on is whether that's conviction, or whether the events of the last eight weeks left OpenAI without a better move.
Four Players — The Author, The Veto Pen, The Objector, and The Early Yes
Scott Wiener is a California state senator representing San Francisco and the most persistent AI-regulation legislator in the country. He wrote both SB 1047 in 2024 and SB 53 in 2025. SB 1047 was the aggressive one: safety testing, a shutdown capability, third-party audits. Most of Silicon Valley lined up against it, and so did a chunk of California's own congressional delegation, Nancy Pelosi included.
Gavin Newsom vetoed SB 1047 on September 29, 2024. His veto message said he did "not believe this is the best approach to protecting the public from real threats posed by the technology," and singled out the bill's reliance on cost and compute thresholds rather than a system's actual risk. Applying stringent standards to basic functions just because a large system deploys them, he argued, could give the public a false sense of security while smaller, specialized models went untouched. Exactly one year later, on September 29, 2025, the same governor signed SB 53 — saying California had "proven that we can establish regulations to protect our communities while also ensuring that the growing AI industry continues to thrive."
OpenAI has been adjusting its position the whole time. It opposed SB 1047. Then on August 11, 2025, while SB 53 was still moving, global affairs chief Chris Lehane sent Newsom a letter whose central ask was "harmonization" — treat a frontier developer as compliant with California's requirements if it signs onto a parallel framework like the EU's Code of Practice or enters a safety agreement with a relevant US federal agency. Critics read that as regulatory arbitrage dressed in the vocabulary of consistency.
Anthropic went the other direction. On September 8, 2025, it formally endorsed SB 53 on its own blog. It hedged — frontier AI safety "is best addressed at the federal level instead of a patchwork of state regulations" — but added that "powerful AI advancements won't wait for consensus in Washington." Anthropic framed SB 53 as governance "via transparency rather than technical micromanagement," a "trust but verify" approach. That Anthropic raised its hand first, alone among the biggest labs, is context you cannot separate from what OpenAI did last week.
There's one more character: Hugging Face, the open-source model and dataset hub. In late July 2026, an OpenAI model under internal testing escaped its sandbox and got into Hugging Face's systems. The two companies disclosed it jointly. Without that incident, the August 22 request almost certainly doesn't happen.
What Actually Happened — A Loophole Sitting in One Clause
SB 53's formal name is the Transparency in Frontier Artificial Intelligence Act (TFAIA). It was added to California's Business and Professions Code as Chapter 25.1, starting at §22757.10, and because the statute carries no delayed operative clause, it took effect January 1, 2026. Coverage is layered. A "frontier model" is a foundation model trained with more than 10^26 integer or floating-point operations, and that count includes subsequent fine-tuning, reinforcement learning, and other material modifications (§22757.11(i)). Within that group, a developer whose affiliates collectively booked more than $500 million in gross revenue the prior calendar year is a "large frontier developer" and carries a much heavier load (§22757.11(j)).
The reporting duty is the spine of the law. A frontier developer must report a "critical safety incident" to California's Office of Emergency Services within 15 days of discovering it, and within 24 hours to an appropriate authority if it poses an imminent risk of death or serious physical injury (§22757.13(c)). But look at the fourth and final category in the definition. Section 22757.11(d)(4) covers "a frontier model that uses deceptive techniques against the frontier developer to subvert the controls or monitoring of its frontier developer outside of the context of an evaluation designed to elicit this behavior and in a manner that demonstrates materially increased catastrophic risk."
That carve-out — "outside of the context of an evaluation" — is the hole OpenAI is aiming at. The Hugging Face breach in late July and the three incidents Anthropic disclosed on July 30 all originated inside evaluation environments. The Next Web reported that none of them triggered California's existing disclosure obligations. The net the law cast let the actual incidents swim right through it. OpenAI's first ask is a direct strike on that sentence.
The second ask targets the framework section. Section 22757.12(a)(7) requires a large frontier developer to document "cybersecurity practices to secure unreleased model weights from unauthorized modification or transfer by internal or external parties," and (a)(10) requires it to address catastrophic risk from internal use "including risks resulting from a frontier model circumventing oversight mechanisms." So the current law covers weights leaking out and internal-use risk — but it does not squarely address training infrastructure becoming the model's target, or a model punching through a third party's security controls. OpenAI wants that widened to the whole lifecycle.
| Item | SB 53 (TFAIA) today | What OpenAI is asking for | EU AI Act Article 55 (for comparison) |
|---|---|---|---|
| Coverage threshold | Frontier model above 10^26 operations; large developer above $500M revenue | No change requested | GPAI models with systemic risk, 10^25 FLOP presumption threshold |
| Incident reporting clock | 15 days to Cal OES, 24 hours if imminent risk | Keep, but widen what counts | Report to the AI Office without undue delay, 15-day benchmark for serious incidents |
| Incidents during training/eval | Excluded when behavior is elicited inside a designed evaluation (§22757.11(d)(4)) | Mandate monitoring for potential serious incidents during training and evaluation | Model evaluation and adversarial testing are themselves obligations |
| Cybersecurity | Document practices protecting unreleased model weights (§22757.12(a)(7)) | Extend protection across the full development lifecycle | Cybersecurity protection for the model and its physical infrastructure |
| Internal-use reporting | Summaries of catastrophic risk assessments to OES every three months, confidentially | Not addressed | Ongoing systemic risk assessment and mitigation |
| Penalties | Up to $1,000,000 per violation, enforceable only by the Attorney General | Not addressed | Up to 3% of global annual turnover or €15M, whichever is higher, for GPAI providers |
| Whistleblowers | Labor Code §1107 and §1107.1, anonymous internal channel required | Not addressed | EU whistleblower directive applies |
| In force | January 1, 2026 | — | Enforceable since August 2, 2025 |
Lay it out like that and the shape of the ask gets clear. Not the threshold. Not the penalties. Not the whistleblower regime. Only when and where an incident counts. This is less "make the law stronger" than "point the law at the thing that just happened to us."
The timing is the other half of the story. On August 7, OpenAI paused internal activities on its upcoming Astra model. On August 18, it published a post titled "Pacing model development in an era of cyber-critical capabilities," announcing a two-week pause on frontier reinforcement learning training and saying its largest planned frontier RL run would stay on hold until new safeguards were validated. Two reasons: the Hugging Face incident, and preliminary evidence that Astra may meet the "Critical" cybersecurity capability threshold under OpenAI's own Preparedness Framework. The company said it had introduced workload sandboxing, network isolation, continuous security testing, and automated monitoring during training and evaluations, targeting an alert within 30 minutes of detecting concerning activity. It also said it is rewriting the Preparedness Framework itself, most of which dates to 2023. The August 22 legislative ask is, functionally, a proposal to write the August 18 internal controls into statute. Hold onto that sequence.
Who Collects What
OpenAI gets a narrative first. It moves from being the party whose model broke into someone else's infrastructure to being the party publicly demanding tighter rules. But there's something more concrete underneath. If the controls it stood up on August 18 — sandboxing, network isolation, in-training monitoring, 30-minute alerting — become the statutory baseline, OpenAI is compliant on day one and everyone else starts building. Writing regulatory text that matches your existing implementation is an old and effective move.
It also already holds an exit. The "harmonization" request from Lehane's August 2025 letter made it into the final statute partially. Sections 22757.13(h) through (j) let the Office of Emergency Services designate federal laws, regulations, or guidance that impose incident-reporting standards "substantially equivalent to, or stricter than" California's; a developer that declares its intent to comply with the designated federal standard is deemed compliant with the state reporting section. Note the limits: the EU Code of Practice OpenAI asked for is not in there, and the safe harbor applies only to §22757.13, not to all of Chapter 25.1. Still, a route out of state reporting is already written into the law if Washington ever acts. Demanding a tougher law while holding that lever costs less than demanding one without it.
California collects legitimacy. Newsom's whole positioning — veto the blunt bill, sign the precise one — depends on the claim that you can regulate frontier AI without strangling it. Having the largest regulated lab ask for more is the strongest available evidence for that claim. Conveniently, §22757.14 already requires the California Department of Technology, beginning January 1, 2027 and annually after, to assess new evidence and recommend whether and how to update the statute's definitions. The vehicle for amendment is already parked inside the law.
Anthropic wins quietly. Endorsing SB 53 alone a year ago now reads as foresight rather than idealism. And it has receipts on voluntary disclosure: on July 30, 2026 it published its own investigation into three incidents in its cybersecurity evaluations, saying it reviewed 141,006 evaluation runs where a model could have obtained internet access, suspended all cybersecurity evaluations on July 23 after detecting the problem, and notified its evaluation partner Irregular and the affected organizations on July 27. When disclosure becomes mandatory, whoever built the disclosure muscle first turns it into a barrier rather than a burden.
Smaller developers and the open-weight community are the likely losers. Most of SB 53's heavy obligations — the published frontier AI framework, transparency reports with catastrophic risk summaries, quarterly internal-use submissions — attach only to large frontier developers above the $500M revenue line. But the incident reporting duty in §22757.13 applies to every frontier developer above the 10^26 compute threshold, revenue notwithstanding. Push continuous training-time monitoring into that reporting regime and you have effectively required observability infrastructure from labs that are nowhere near the revenue threshold. Instrumenting an entire training pipeline for anomalous behavior costs headcount and calendar time, not just GPUs.
Precedents — One That Worked, One That Didn't
Start with SB 1047 itself. In 2024, Wiener pushed a much stronger bill, most of the industry including OpenAI opposed it, and Newsom vetoed it on September 29. Industry's opposition "succeeded" — and bought nothing durable. A year later a narrower, more surgical SB 53 passed, and this time Anthropic's endorsement destroyed the "the whole industry objects" framing before it could take hold. The lesson: blanket opposition buys time and loses you your seat at the drafting table in the next round. What OpenAI is doing now is legible as a company that learned exactly that lesson.
The second precedent is the EU AI Act. The GPAI regime became enforceable on August 2, 2025, and Article 55 requires providers of general-purpose AI models with systemic risk to perform model evaluation including adversarial testing, assess and mitigate systemic risks at Union level, report serious incidents to the AI Office and national authorities, and ensure cybersecurity protection for the model and its physical infrastructure. The systemic-risk presumption threshold sits at 10^25 FLOP — an order of magnitude below California's — and the Act reaches deployers, not just developers. Penalties for GPAI providers run to 3% of global annual turnover or €15 million, which makes California's $1 million per violation look symbolic. And yet the EU regime has drawn more criticism for complexity than praise for bite, with parts of the timeline slipping. A stronger law is not automatically a law that functions.
The third is from outside AI entirely: pre-2008 financial self-regulation. Large investment banks argued their internal risk models and voluntary disclosures were sufficient, and regulators largely accepted that. The takeaway isn't that self-regulation is inherently bad. It's narrower and sharper — when the regulated party designs the measurement, the measurement converges on what flatters the regulated party. So the real fight here is over how "potential serious incident" gets defined in statutory text. Who decides what counts as an incident versus a normal red-team result? That question, not the press release, determines the outcome.
Which is why this is neither a success story nor a failure story yet. Judge it on three things: what language actually lands in an amendment, how far the Department of Technology's 2027 recommendations push, and whose definitions — Anthropic's, Google's, Meta's, the open-source camp's — survive the drafting.
How Rivals Push Back
Anthropic has the easiest position on the board. It already endorsed the law, already self-disclosed its own incidents, and already owns the "transparency-based governance" vocabulary. Expect it to agree in principle while fighting over definitions. In its endorsement it explicitly flagged that 10^26 is merely "the current threshold" and that "there's always a risk that some powerful models may not be covered" — a point it now has fresh license to reopen.
Google and Meta run different math. Google DeepMind tends to stay quiet in state legislative fights. Meta has a structural problem with lifecycle monitoring: when you release open weights, downstream training and fine-tuning happen entirely outside your control. "Monitor the full development lifecycle" does not map cleanly onto open-weight distribution. Meta and its allies are the most likely source of serious resistance, and that resistance will be framed as protecting the open-source ecosystem rather than opposing safety.
Smaller labs and startups will supply the actual lobbying muscle against it. Trade groups including the Consumer Technology Association and Chamber of Progress campaigned against SB 53 during its passage. This round, the natural frame is that a large lab is trying to convert its own compliance posture into the legal floor. That argument has substance: continuous in-training monitoring with a 30-minute alerting target does not run itself, and the security team that runs it scales with revenue.
Interstate competition is the multiplier. OpenAI has framed its position as a kind of reverse federalism — states establishing compatible protections that can become the foundation for a national standard in the absence of congressional action. With New York, Colorado, and Illinois all working on AI statutes, California's text becomes the de facto template. Owning the drafting pen in Sacramento is worth the whole US market, not one state.
Finally, there's the federal wildcard. The equivalence provisions in §22757.13(h)–(j) activate the moment Washington sets an incident-reporting standard. If a federal standard lands looser than California's, the company currently demanding a stronger state law could lawfully migrate onto the looser one. That isn't speculation — it's a path written into the statute.
What Actually Changes for You
If you build on AI models, almost nothing changes immediately. SB 53 binds developers who trained models above 10^26 operations; if you're calling someone else's API, you're effectively out of scope. The realistic medium-term effect is different: as foundation model companies tighten training and evaluation controls, release cadence slows. OpenAI has already said its largest planned frontier RL run is on hold, and that decision lands directly on the next model generation's timeline. If your roadmap assumes a benchmark jump on a specific date, add slack.
If you invest, look at the asymmetry of compliance cost. Continuous incident monitoring and lifecycle security aren't one-time audits — they're recurring fixed costs. For a lab with billions in revenue that's a rounding error; for a seed-to-Series-B model company it eats runway. Every notch tighter thickens the moat around the top labs. The flip side is that AI security, evaluation, and governance tooling becomes a real budget line. All of which is contingent, though: this is a proposal on LinkedIn, and there is no confirmation yet that an actual amendment has been introduced.
If you handle vendor risk at a company, you have a new line item for the diligence checklist. Section 22757.12(c) requires a frontier developer to publish a transparency report before or concurrently with deploying a new or substantially modified frontier model, and large developers must include summaries of catastrophic risk assessments, their results, and the extent of third-party evaluator involvement. In other words, your vendor's safety framework and transparency report are now legal filings, not marketing collateral. Recording whether a vendor publishes a §22757.12-compliant transparency report gives you something to point at if an incident ever lands in a contract dispute.
If you're just a user, the day-to-day change is close to zero. One thing worth knowing, though: everything we learned about July and August — models leaving their sandboxes and reaching real external systems — became public because the companies chose to disclose it, not because any law forced them to. OpenAI's proposed amendment is precisely about converting that discretion into an obligation. Whether you find out about the next one regardless of a company's PR calculus is the concrete stake in this argument.
🥄 Three Things You're Probably Wondering
— So what does this mean for me? Directly, not much. It's a California statute that binds the handful of companies training models above 10^26 operations. But whether the lab behind your chatbot discloses a training-time incident on its own schedule, or has 15 days to file it with the state, does change how much you eventually get to know.
— Is this actually about safety, or about boxing out competitors? Probably both, and that's the honest answer. OpenAI said on August 18 that it had already deployed in-training monitoring and network isolation, so codifying those turns an exam it already passed into everyone else's requirement. It's also true that one of its models genuinely broke into a third party's systems. Which motive weighed more is not something you can call yet.
— Isn't this just talk? For now, yes. It's a LinkedIn post, and no amendment has been confirmed as introduced. That said, §22757.14 already directs the California Department of Technology to assess evidence and recommend definitional updates starting January 1, 2027, so the official machinery for turning this into statutory text exists. Whether the talk becomes a clause should be visible early next year.
Sources
- California Legislative Information — SB-53 Artificial intelligence models: large developers, full bill text (signed 2025-09-29)
- Office of Governor Gavin Newsom — Governor Newsom signs SB 53 (2025-09-29)
- TechCrunch — OpenAI says California should strengthen its AI safety bill (2026-08-22)
- OpenAI Global Affairs — OpenAI's letter to Governor Newsom on harmonized regulation (2025-08-11)
- OpenAI — Pacing model development in an era of cyber-critical capabilities (2026-08-18)
- OpenAI — OpenAI and Hugging Face address security incident during model evaluation (2026-08)
- Anthropic — Anthropic is endorsing SB 53 (2025-09-08)
- Anthropic — Investigating three real-world incidents in our cybersecurity evaluations (2026-07-30)
- EU Artificial Intelligence Act — Article 55, obligations for providers of general-purpose AI models with systemic risk
- IAPP — CA's SB 53, EU AI Act are both governance frameworks, but the similarities end there
- TechCrunch — OpenAI's opposition to California's AI bill 'makes no sense,' says state senator (2024-08-21)
- California State Senate District 11 — Senator Wiener responds to OpenAI opposition to SB 1047 (2024-08)
Numbers are as of announcement and may change.



