Executive summary
SB 53 made California the first state to require frontier AI developers to publish and comply with safety frameworks. However, under current law, companies write and determine the substance of those frameworks themselves. The industry has no shared minimum safety standard, and companies face no consequences for writing vague or insufficient safety frameworks that fail to mitigate significant public risk.
To fix this problem, the Governor’s Office of Emergency Services (Cal OES) should be provided the legal authority to adopt mandatory minimum safety standards for frontier AI developers through rulemaking. These safety rules would be faster to issue, update, and more informed by experts and the public than requirements written directly into statute, which are essential advantages given the technical and rapidly evolving nature of frontier AI risks.
How AI rulemaking can work in California
Empowering Cal OES to issue AI regulations
Cal OES is well-suited to establish regulations that set mandatory minimum standards for frontier AI frameworks, as SB 53 already designates it as the state's repository for critical safety incident reports and confidential assessments of catastrophic risks. Consequently, it is the only state agency with access to industry-wide evidence on the risks these regulations will address and where current safety frameworks are falling short. The table below shows Cal OES’s existing AI authorities under SB 53:
| Power | Under SB 53 |
|---|---|
| Receive critical safety incident reports | Yes, within 15 days |
| Receive internal use risk assessments | Yes, quarterly summaries |
| Adopt regulations through rulemaking process, including emergency regulations | No (only to designate equivalent federal reporting standards) |
Establishing minimum safety standards via rulemaking
A public rulemaking process can establish legally binding, mandatory minimum safety standards for frontier AI companies. Such rules could specify the minimum content of companies' safety frameworks, including safeguards that trigger when capability thresholds are met, the types of evaluations that must be conducted, and measures for incident follow-up. For example, the minimum standards could specify requirements around the security of model weights, which is important for preventing the theft of potentially dangerous models by criminals or foreign adversaries. The rules could reference existing and emerging standards and regulations, including those devised by private standards bodies, and be updated as best practices change.
Why frontier AI safety rulemaking is necessary
Company compliance with SB 53 has revealed safety gaps
SB 53 requires frontier AI developers to publish safety frameworks and comply with them, but each company writes its own framework and can decide how strict it is. The law only requires that companies comply with their own written standards. Many frontier AI developers have complied with the law by using basic or vague language that provides little to no transparency into their risk management and safety practices. This illustrates the need to establish substantive minimum safety standards beyond transparency alone.
Rules can be updated as AI development and best practices evolve
The pace of AI development and its associated risks means experts must update any regulatory solution over time. Rulemaking exists for exactly this situation. A technical agency can clarify details, gather evidence through public comment, and update the rules as the technology evolves. This prevents the Legislature from having to pass a new bill every time a new risk or mitigation emerges.
Rulemaking can quickly respond to emergencies
Emergency rulemaking can let Cal OES act quickly as new risks arise, potentially rapidly. Emergency rules take effect quickly after a shorter review and are temporary until the agency completes the full rulemaking process. Emergency rules are routine practice in California and will allow for more timely responses to emerging AI risks.
Rulemaking is accountable to the public
Rulemaking requires public notice, open comment from anyone, a written response to objections, legal review by the Office of Administrative Law, and the possibility of a court challenge. That gives the public, safety advocates, and industry a fair forum to debate appropriate regulation.
Rulemaking creates a level playing field
A minimum safety standard applies the same floor to every covered developer, ensuring fair competition and preventing companies from being disadvantaged for taking unilateral steps to minimize risk to the public. This way the government and public, not companies alone, can set a floor for adequate safety measures.
Objections and responses
Objection: Rulemaking is slow and will be unable to keep up with AI development.
While rulemaking can be faster than passing new legislation, it is true that major California rules can take years. Standard rulemaking alone will likely not keep pace with all emerging AI risks. However, several techniques can speed up and improve the effectiveness of rulemaking.
- Emergency rules. This is a standard procedure for rulemaking, and rules take effect within weeks for urgent risks. They expire after 180 days unless Cal OES completes the regular process.
- Incorporating outside standards by reference. Rules can reference technical standards from established third parties to speed up evidence gathering and stay current on emerging developments.
- Outcome-based standards. Rules that set results rather than techniques can stay current even as safety mitigation measures change.
Objection: Rulemaking could hurt competitiveness and favor larger companies.
Rules could be scoped to exempt startups and smaller developers. For example, the compliance burden may fall only on companies training very large models. For these companies, compliance costs would be small compared with the cost of their training runs, which often reaches hundreds of millions of dollars per run. Further, public rulemaking guards against regulatory capture. Standards are set on a public record, with every participant's comments visible.
Objection: Rules will get out of date too quickly.
It is true that it will be impossible to enshrine every best practice into a rule. Some best practices may last only weeks before an improvement is found, which would make a rule counterproductive. But this doesn’t mean there should be no rules; instead, it means Cal OES should be required to carefully consider whether a concept is robust enough to write into a rule, write rules that are high-level enough to allow better or more innovative implementations, and review existing rules regularly.
Objection: Cal OES lacks the expertise to implement effective rulemaking on AI.
Cal OES has increased AI expertise and capacity to implement SB 53, and should continue to hire additional staff to issue and enforce technical rules. Beyond this, Cal OES can also incorporate outside expertise to support rulemaking through:
- Embedded evaluators. Governor Newsom’s September 2026 Executive Order calls for a policy evaluation of designating independent verification organizations (IVOs) to be embedded within frontier AI developers to conduct periodic audits and evaluations. The technical findings from these embedded evaluators could be shared with Cal OES to inform its rulemaking and orders.
- Leveraging existing standards. Cal OES could adopt AI safety standards developed by academia and other expert bodies by reference if appropriate.
- Outside input. Public comment and advisory committees bring outside experts into the rulemaking process.
Objection: CA rulemaking could conflict with federal or other states’ regulations.
There exists no federal or state-issued minimum safety standards for frontier AI, and protecting residents from physical harm is a fundamental state responsibility. California is the natural state to issue minimum safety standards, as most of the covered companies are headquartered in California. California also similarly regulates independently of the federal government on vehicle emissions, privacy, and workplace safety. The state could be required to consider deferring to and incorporating rules from other states, the federal government, or appropriate private standards bodies where doing so would not jeopardize public safety.