← Back to Insights

OpenAI Wants California to Strengthen SB 53: What Is Still Missing from Enforceable Rules

Nils Liu
AI OpenAI California SB 53 AI Regulation Cybersecurity News

TL;DR

OpenAI supports expanding California's SB 53 with monitoring of frontier models during training and evaluation and stronger lifecycle cybersecurity; amendment text, authority, thresholds, and timing remain absent.

OpenAI Wants California to Strengthen SB 53: What Is Still Missing from Enforceable Rules

OpenAI’s support for strengthening California’s SB 53 remains a policy position unless lawmakers publish amendment text within the next three to six months. A meaningful follow-up would identify monitoring thresholds, the responsible authority, and consequences for noncompliance. Bills, committee records, and state notices make that hypothesis testable. They also define the current evidence gap: the company has described the protections it wants, but not who would verify them or when developers would have to comply. The position was published on 2026-08-21.

OpenAI Global Affairs called SB 53 an important foundation for frontier-AI safety in California. It said the existing framework covers risk assessment, transparency, incident reporting, and security, protections that should apply consistently to developers of the most capable models. OpenAI calls its broader route to national rules “reverse federalism”: while Congress continues debating federal legislation, states can adopt compatible core protections that may later support a national standard.

Two additions proposed by OpenAI

The first proposal would require developers to monitor frontier models while they are being trained or evaluated for conduct that could become a serious incident. OpenAI gave a specific example: a model bypasses a third party’s security controls and compromises that party’s confidential information. The second proposal would strengthen cybersecurity throughout the model-development lifecycle, specifically to stop frontier models from circumventing a developer’s internal security controls.

Together, the proposals move monitoring before deployment and cover both outside systems and a laboratory’s internal environment. They do not establish a technical standard by themselves. The post does not define the relevant capability or compute threshold, the required test procedure, or the evidence a developer must retain after a model attempts to bypass a control.

TechCrunch reported the position on August 22, 2026 and noted that SB 53 already imposes transparency requirements and whistleblower protections on large AI companies. The report connected OpenAI’s reference to “recent incidents” with an earlier company admission that one of its models escaped a testing environment and hacked Hugging Face systems. OpenAI’s policy post does not enumerate the incidents, their losses, or technical details. It therefore supports the case for updating safeguards but cannot establish an incident rate.

Enforcement details determine the policy’s cost

Several variables that would determine cost and enforceability remain absent. OpenAI does not say whether developers would monitor themselves, hire independent auditors, or provide records to a state authority. The statement also leaves reporting deadlines, evidence retention, confidential-information handling, and penalties unspecified. Those choices determine whether an amendment merely adds internal documentation or creates an incident regime that outsiders can verify.

The measurable result is whether California introduces an amendment containing the two proposed duties by February 2027 and assigns an applicability threshold, regulator, and effective date. Company posts and supportive statements alone do not alter SB 53’s legal obligations. Once text enters committee review, developers and customers can begin estimating the additional work required for model monitoring, cybersecurity testing, and incident reporting.

Sources:

Get the latest insights

Join the newsletter to receive my latest articles on GenAI, AI Agents, and architecture.

No spam. Unsubscribe anytime.