California AI Governance — Trustible
California Transparency in Frontier Artificial Intelligence Act (SB 53) and Related Laws

California AI Governance

California regulates AI through a wide set of targeted laws rather than one general statute, anchored by SB 53’s frontier-model transparency regime and layered with training-data transparency, content provenance, employment, and health insurance rules. Organizations operating in California should expect to track several California-specific obligations in parallel with any federal or multistate program.

Requirement
What It Means
Frontier AI Safety Framework
Large frontier developers must publish and annually update a framework describing how they assess and mitigate catastrophic risk, defined as foreseeable material contribution to mass casualties or over $1 billion in property damage.
Transparency Reports
Before deploying a new or substantially modified frontier model, developers must publish a report on capabilities, intended uses, limitations, and catastrophic-risk assessment summaries.
Critical Safety Incident Reporting
Incidents must be reported to the California Office of Emergency Services within 15 days of discovery, or 24 hours if there is imminent danger to life or safety.
Whistleblower Protections
Large frontier developers must establish anonymous internal reporting channels and protect employees from retaliation for reporting safety concerns.

The California Attorney General enforces SB 53, with civil penalties up to $1 million per violation.

Other California AI Laws in Effect

Requirement
What It Means
AB 2013 (Generative AI Training Data Transparency, effective Jan. 1, 2026)
Developers of generative AI systems available to Californians must publicly document training data sources and types, including whether copyrighted material or personal information was used, before public release.
SB 942 / AB 853 (California AI Transparency Act, operative Aug. 2, 2026)
Generative AI providers with more than one million monthly California users must embed tamper-resistant provenance data in AI-generated image, video, and audio content, offer a free public detection tool, and let users add visible AI-content labels. Penalties start at $5,000 per violation per day.
AB 1008 (CCPA/AI Clarification, effective Jan. 1, 2025)
Clarifies that “personal information” under the CCPA includes information in abstract digital formats, expressly covering AI and generative AI system outputs.
Civil Rights Council Automated-Decision-System Regulations (effective Oct. 1, 2025)
Amends FEHA regulations to prohibit employment automated-decision systems that produce disparate impact or treatment, flags disability-related inquiry risk, and requires four years of record retention.
AB 1836 and AB 2602 (Digital Replica Laws, effective Jan. 1, 2025)
Bar creating a deceased personality’s digital replica without estate consent, and void contract terms letting a digital replica substitute for a performer’s in-person work without informed, represented consent.
SB 1120 (AI in Health Insurance Utilization Review, effective Jan. 1, 2025)
Requires that only licensed healthcare professionals make medical necessity determinations, barring AI or automated tools from independently denying, delaying, or modifying coverage decisions.

How Trustible Supports California Compliance

Compliance
Trustible Capability
AI Inventory
Tracks foundation model dependencies against frontier-developer thresholds, and separately tracks training-data, content-provenance, and employment AI obligations across California’s layered law set.
Risk Management
Documents FEHA-aligned disparate impact and disparate treatment review for employment automated-decision systems, with four-year record retention built into workflow history.
Model and Vendor Evaluations
Surfaces whether foundation model vendors meet SB 53’s frontier or large frontier developer thresholds and can produce the required safety framework and transparency report.
Policy Management
Connects internal AI content policy to SB 942/AB 853 provenance and watermarking obligations for customer-facing generative AI products.
Insights Taxonomies
Keeps catastrophic-risk definitions and disparate-impact criteria current as California Attorney General and Civil Rights Council guidance develops.
Reporting & Dashboards
Produces audit-ready documentation for the multiple California regulators involved: the Attorney General, Civil Rights Council, and Department of Insurance-adjacent utilization review requirements.

Your First 90 Days

Day 30: Map California’s Layered Obligations

Identify which California laws apply to which AI systems: frontier model dependencies under SB 53, generative AI products under AB 2013 and SB 942/AB 853, employment tools under the Civil Rights Council regulations, and any health coverage decisioning under SB 1120.

Day 60: Assess Disparate Impact and Vendor Safety Disclosures

Launch FEHA-aligned bias testing for employment automated-decision systems, and request safety framework and transparency report documentation from foundation model vendors that may qualify as frontier developers.

Day 90: Operationalize Provenance and Reporting

Confirm content-provenance and watermarking obligations are built into generative AI product workflows, and connect incident reporting processes to the 15-day and 24-hour SB 53 timelines.

California AI FAQs

SB 53 applies to frontier developers, the organizations training foundation models above the compute threshold, not to downstream enterprises deploying those models. Enterprises are affected indirectly, through the safety and transparency documentation their model vendors must produce.

Any organization that trained a model above 10^26 FLOPs is a frontier developer. Large frontier developers, those with more than $500 million in annual revenue, face the fuller set of obligations, including the published safety framework and whistleblower protections.

The Civil Rights Council’s automated-decision-system regulations prohibit disparate impact and disparate treatment and require four years of record retention, but the specific audit mechanics differ from NYC Local Law 144’s annual independent audit model.

No. SB 1047 was vetoed in September 2024. SB 53 is the operative frontier-model law and takes a more transparency-focused approach than SB 1047’s proposed testing and kill-switch requirements.

A December 2025 federal executive order and a proposed federal FRONTIER Act have raised that possibility, but as of this writing no federal preemption of SB 53 or related California laws has taken effect.

See How Trustible Operationalizes California AI Compliance in a Unified Governance Program.

© 2026 Trustible