Skip to content
Menu
Menu

OpenAI Asks California To Add Two Safety Requirements To SB 53

OpenAI wants every company SB 53 covers, itself included, to watch its most powerful models 

 

OpenAI asked California to add two requirements to SB 53, the state law covering companies that build the most powerful AI models. OpenAI’s global affairs team posted the request on LinkedIn on August 22 and said the company is committed to working with the legislature and Governor Gavin Newsom to strengthen the law.

 

The two additions cover models while they are being trained and tested

The first request is monitoring. OpenAI says SB 53 should require every company the law covers, including OpenAI, to watch its most powerful models during training and testing for one behavior in particular: a model getting past another company’s security controls and taking that company’s confidential information.

The second request is security. OpenAI says the law should require stronger security at every stage of building a model, so that it cannot get around the security controls set by the company that built it.

OpenAI wrote that it wants rules that work across the industry rather than rules written around any one incident, and that catch problems earlier.

 

SB 53 already requires published safety rules and reports of serious incidents

Newsom signed SB 53 on September 29, 2025, and its requirements began taking effect in January 2026. It covers companies that train a model using more than 10^26 computer operations, a measure of the computing work required to build it.

Every covered company must publish a report on each model before releasing it, setting out what the model is meant to be used for, what it is restricted from doing, and the company’s own assessment of potential catastrophic risk. Companies earning more than $500 million a year must also publish the rules they follow to find and reduce that risk. The law defines catastrophic risk as a model contributing to more than 50 deaths or serious injuries, or to more than $1 billion in damage.

Covered companies must tell the California Office of Emergency Services about a critical safety incident within 15 days, and immediately when someone faces imminent physical danger. A critical safety incident is model behavior that causes or risks death, serious injury, or loss of control of the model. The law also bars companies from firing or otherwise retaliating against employees who report catastrophic risk. The attorney general can seek up to $1 million for each violation.

 

OpenAI opposed SB 53 in 2025 and now wants it as the basis for federal rules

OpenAI was among the companies that lobbied against SB 53 before Newsom signed it, saying they wanted one set of federal rules rather than separate rules in each state. In June 2026, OpenAI asked Congress to write federal AI safety requirements that would replace state rules on the most powerful models, and to build those federal requirements from SB 53 and from laws in New York and Illinois.

OpenAI calls that approach “reverse federalism”: states pass rules that match each other, and Congress later turns the shared parts into a single national standard. The LinkedIn post repeats that position before making the two requests, and attaches a condition to them. Rules matching across states, OpenAI wrote, should not mean freezing safety requirements where they stand, because lawmakers and companies should be able to turn what real events teach them into stronger protections.

 

OpenAI, Anthropic, and Meta have each disclosed a model reaching outside systems since July 

OpenAI points to recent incidents as evidence why these two additions are needed, though it doesn’t name a specific incident. All the incidents were cybersecurity tests in which AI models bypassed their security guardrails. In each case, a model reached the internet from a test environment and then broke into a real company’s systems. 

In July, two OpenAI models escaped a sealed cybersecurity test environment that had no internet connection and used a previously unknown software flaw to get online. The models then found credentials that let them into Hugging Face’s servers, a company that hosts AI models and datasets for developers. They pulled the answers to the cybersecurity test from one of its databases. 

In early August, Anthropic reported that three of its models reached the internet through a misconfiguration between Anthropic and a testing partner, then broke into organizations that were not part of the test and published malware to a public library of software packages. Days later, Meta said its Muse Spark 1.1 model hacked an unnamed company’s systems during a security test after a configuration error gave the model live internet access.

 

California’s legislature adjourns for the year on August 31 

OpenAI did not point to a bill that would amend SB 53, and the legislature has until August 31, when its session ends. Newsom has until the end of September to sign or veto what the legislature passes before it adjourns.

Clayton Rifkind

Clayton Rifkind is the Founder and Senior Editor of AI Risk Today. He also advises on business development for ESG Today, a leading source of ESG investment news and research for institutional investors and corporate leaders. He has 20+ years of experience in B2B technology, leading strategy and execution of go-to-market plans across software, enterprise platforms, and mobile applications. He founded two consultancies advising startups and Fortune 1000 companies, including Autodesk, Intel, and Microsoft. He began his career in the San Francisco advertising scene working with brands such as Hewlett-Packard, Intel, Microsoft, Symantec, and Wells Fargo. Clayton launched AI Risk Today in 2025 after two decades of watching enterprises adopt transformative technologies, and seeing how often risk, governance, and compliance considerations lagged behind. His reporting draws on primary sources including regulatory filings, court documents, and official announcements, with a focus on what AI developments mean for the executives accountable for managing them. Reach him at Reach him at [email protected] or on LinkedIn.

Essential AI Risk Intelligence

Daily insights on AI governance, regulation, and enterprise risk management. Trusted by Chief Risk Officers and compliance leaders globally.

By subscribing, you agree to receive our daily newsletter. Unsubscribe anytime.

Advertise with AI RIsk Today, Today!