Large frontier developers must send periodic summaries of catastrophic-risk assessments to the state
Context fileUnder California SB 53, Business and Professions Code Section 22757.12 (as added by SB 53)
What does it require?
A large frontier developer must transmit to the California Office of Emergency Services, on the periodic schedule the statute sets, a summary of any assessment of catastrophic risk that results from the internal use of its frontier models. This covers risks arising before public deployment, such as during internal evaluation or use of the model to accelerate research, and complements the public transparency report.
Practical action
Schedule a recurring internal-use risk assessment and a state submission with a fixed owner in the safety team.
Who does it apply to?
Large frontier developers above the statutory compute and revenue thresholds.
- Sectors
- Cross-sector / all sectors
- Use cases
- Generative AI and foundation models
Applies from:
Which controls meet this duty?
Satisfies: the control, operated properly, does the work the duty asks for. Supports: it contributes but the duty needs more. Each control page lists every other duty it serves, so work done once can be counted once.
-
satisfiesPolicyHead of AI safety · annualFrontier model safety and security framework
Serves 9 recorded duties · evidence: Published frontier safety framework, Dangerous-capability evaluation report, Threshold notification to an authority
Framework defines the catastrophic-risk assessment whose summaries are submitted.
-
supportsTechnical measureAI security or safety lead · at launch and on material changeAdversarial and red-team testing for generative AI
Serves 8 recorded duties · evidence: Red-team exercise report, Red-team rules of engagement and scenario library, Adversarial findings tracker
Dangerous-capability evaluations feed the assessment.
What evidence would a reviewer expect?
| Evidence | Type | Notes |
|---|---|---|
| Internal-use catastrophic risk assessment summary sent to the Office of Emergency Services | report |
Framework mappings
Original editorial crosswalks. They cite clause numbers only and reproduce no standard text; confidence reflects how direct the mapping is.
See every California (United States) duty mapped this way →
| Framework | Reference | Note | Confidence |
|---|---|---|---|
| NIST AI RMF 1.0 | MEASURE 2.6, MANAGE 1.2, GOVERN 4.3 | Safety evaluation, prioritisation and information sharing with authorities. | medium |
| ISO/IEC 42001:2023 | Clause 9.1; Annex A.8.3 | Monitoring and external reporting. | low |
Cite this record
AIPolicyTracker (2026). “Large frontier developers must send periodic summaries of catastrophic-risk assessments to the state (California SB 53)”. https://aipolicytracker.org/obligations/us-california-sb-53-catastrophic-risk-assessment-summaries (accessed 24 September 2026). Data licensed CC BY 4.0.
Cite the official text alongside it: SB 53 Transparency in Frontier Artificial Intelligence Act, California Legislative Information, https://leginfo.legislature.ca.gov/faces/billNavClient.xhtml?bill_id=202520260SB53.
Similar obligations in other instruments
- Manage systemic risk for high-impact general-purpose models — EU AI Act, European Union
- Operators of AI above the compute threshold must run lifecycle risk management and report safety results — Framework Act on the Development of Artificial Intelligence and Establishment of a Foundation for Trust, South Korea
- Large frontier developers must publish a frontier AI framework — California SB 53, California (United States)
- Measure and test trustworthiness characteristics (Measure) — NIST AI RMF, United States (voluntary)
Informational only, not legal advice. Verify every claim against the linked official sources and consult qualified counsel before acting.