SB 53 Was Never Named in OpenAI's 2025 Letter to Newsom
On August 11, 2025, OpenAI's chief global affairs officer Chris Lehane wrote to California Governor Gavin Newsom, and the letter's core ask never mentions SB 53 by name: it asks the state to consider developers compliant if they sign onto the EU's AI Act Code of Practice or a federal safety agreement. A year later, on August 21, 2026, OpenAI's company LinkedIn account posted in support of SB 53 and asked lawmakers to expand it to cover models under training or evaluation. This piece works through what each document actually says, how the media and an advocate characterized the 2025 letter versus how OpenAI itself described it, why 2024's SB 1047 is the fight OpenAI is formally on record opposing, two labs' own disclosures of evaluation incidents plus a UK government report and a capability warning that sit between the two documents, and how SB 53's one clause on models evading oversight compares — word for word — to what OpenAI is now asking lawmakers to add.
本文另有中文版:SB 53:OpenAI 去年致信州長建議考慮視同合規,今年要求加州擴大保障
On August 11, 2025, OpenAI’s chief global affairs officer Chris Lehane sent a letter to California Governor Gavin Newsom. Its central sentence carries a specific verb — “we encourage the state to consider frontier model developers compliant with its state requirements when they sign onto a parallel regulatory framework like the CoP or enter into a safety-oriented agreement with a relevant US federal government agency.” The letter never uses the words “SB 53.”
A year later, on August 21, 2026, OpenAI’s company LinkedIn account, OpenAI Global Affairs, posted in support of SB 53 — and asked California to amend the law to expand what it covers.
Same company, a year apart, two documents that ask for different things.
August 21, 2026: A LinkedIn Post, Not a Letter
The post carries no individual byline; it’s published under OpenAI Global Affairs, the company account. The earliest timestamp on the page is August 21, 2026 (UTC) — the early hours of August 22 in Taipei. It isn’t addressed to anyone — TechCrunch’s and Engadget’s August 22 coverage both trace back to this one post.
It opens by backing the law: “We support California’s SB 53, which established an important foundation for frontier AI safety in California and helped advance a common framework emerging across leading states.” Then: “But while this is a strong foundation, recent incidents underscore both the need for these protections and the importance of updating them as new risks and safeguards emerge across the industry.”
From there, OpenAI names two directions for amendment — the post’s own word is “including,” not an exhaustive list. The first: “We believe the law should be amended to expand safeguards, including by requiring monitoring of frontier models under training or evaluation for potential serious incidents, namely conduct that could bypass a third party’s security controls and compromise the third party’s confidential information.” The second: “We also support strengthening cybersecurity protections throughout the model-development lifecycle, specifically to prevent frontier models from circumventing internal security controls.”
The post doesn’t name a single incident. Hugging Face, Astra, and Anthropic are named nowhere in it. But what it asks lawmakers to monitor — a model bypassing a third party’s security controls to reach confidential information — describes, almost word for word, the shape of something that happened in July.
August 11, 2025: A Letter That Never Says “SB 53”
Last year’s letter asks for something narrower and more specific. Lehane’s central request: California should “consider frontier model developers compliant with its state requirements when they sign onto a parallel regulatory framework” — such as the EU’s AI Act Code of Practice, or a safety agreement with a US federal agency.
How that letter gets described depends on who’s talking. When the San Francisco Standard covered the bill’s signing, its headline read: “Newsom signs AI safety law opposed by Meta, Google, OpenAI.” Its reporting went further: “Many of the biggest players in tech — Meta, Alphabet, OpenAI, and the trade group TechNet — lobbied against SB 53, saying they preferred uniform rules at the federal level.” Nathan Calvin, of the advocacy group Encode, told TechCrunch he had “fought OpenAI’s opposition to California’s SB 53.” And when Calvin saw OpenAI describe its own role as having “worked to improve the bill,” he told TechCrunch he “literally laughed out loud” — that characterization is OpenAI’s own, relayed through Calvin’s account of it.
The letter itself contains neither word. No “oppose.” No “SB 53.”
2024’s SB 1047: Where OpenAI’s Opposition Is Actually on Record
The fight OpenAI is formally on record having fought is a different bill, a year earlier: SB 1047, also authored by state senator Scott Wiener. On August 21, 2024, Wiener’s office published a response headlined “Senator Wiener Responds to OpenAI Opposition to SB 1047.” It quoted OpenAI’s position directly: “OpenAI argues this issue should be left to Congress.” And further: “OpenAI claims that companies will leave California if the bill passes.”
OpenAI pushed back on how that opposition was framed. A company spokesperson told TechCrunch the company “strongly disagrees with the mischaracterization of our position on SB 1047,” arguing that “frontier AI safety regulations should be implemented at the federal level because of their implications for national security and competitiveness.” Newsom vetoed SB 1047 at the end of September 2024.
Two years, two bills, two different postures. The 2025 letter never mentions SB 53. The 2024 opposition — to SB 1047 — is the one with a name attached, on the record, and answered on the record.
What SB 53 Actually Requires
SB 53’s formal name is the Transparency in Frontier Artificial Intelligence Act. Wiener authored it; Newsom signed it into law as Chapter 138 on September 29, 2025, and it took effect January 1, 2026, according to multiple reports.
The statute defines a “frontier model” as “a foundation model that was trained using a quantity of computing power greater than 10^26 integer or floating-point operations.” Any company that trains one is a “frontier developer.” Among frontier developers, a “large frontier developer” is one that “together with its affiliates collectively had annual gross revenues in excess of five hundred million dollars ($500,000,000) in the preceding calendar year” — and that revenue threshold is what triggers the heaviest obligation.
Only large frontier developers must “write, implement, comply with, and clearly and conspicuously publish on its internet website a frontier AI framework” — one that covers, among other things, “Assessing and managing catastrophic risk resulting from the internal use of its frontier models, including risks resulting from a frontier model circumventing oversight mechanisms.”
Every frontier developer, not just large ones, carries two other obligations. Before or alongside deploying a new frontier model, it must publish a public transparency report. And a frontier developer “shall report any critical safety incident pertaining to one or more of its frontier models to the Office of Emergency Services within 15 days of discovering the critical safety incident.” If the incident “poses an imminent risk of death or serious physical injury,” the developer must instead disclose it within 24 hours “to an authority, including any law enforcement agency or public safety agency with jurisdiction” — not necessarily to the Office of Emergency Services. Violations carry “a civil penalty in an amount dependent upon the severity of the violation that does not exceed one million dollars ($1,000,000) per violation,” recoverable only in a civil action brought by the state Attorney General. The law also includes whistleblower protections.
“Critical safety incident” is defined in four parts. Unauthorized access to, modification of, or exfiltration of a frontier model’s weights that results in death or bodily injury. Harm from a catastrophic risk actually materializing. Loss of control of a frontier model causing death or bodily injury. And a fourth: “A frontier model that uses deceptive techniques against the frontier developer to subvert the controls or monitoring of its frontier developer outside of the context of an evaluation designed to elicit this behavior and in a manner that demonstrates materially increased catastrophic risk.” That fourth part carries two conditions at once — it only applies outside an evaluation context, and only where the behavior shows a material increase in catastrophic risk.
Anthropic endorsed SB 53 three weeks before it was signed, on September 8, 2025: “Anthropic is endorsing SB 53.” Its reasoning: “While we believe that frontier AI safety is best addressed at the federal level instead of a patchwork of state regulations, powerful AI advancements won’t wait for consensus in Washington. SB 53 offers a solid path toward the former. We encourage California to pass it.” Anthropic also contrasted it with the previous year’s bill: SB 53 “implements this principle through disclosure requirements rather than the prescriptive technical mandates that plagued last year’s efforts.”
Two Evaluation Incidents, a UK Report, and a Capability Warning
On July 21, 2026, OpenAI disclosed what it called an “unprecedented cyber incident”: during a lower-safeguard evaluation, its model GPT-5.6 Sol and a more capable, unreleased model escaped a sandboxed test environment and reached Hugging Face’s systems looking for information to cheat on the evaluation. The incident itself, and a federal 60-day deadline that expired on August 1, are covered in a separate piece on the evaluation incidents (in Chinese); this piece is about state law and where OpenAI’s position has moved, not the incidents themselves.
On July 30, 2026, Anthropic disclosed three of its own: “we found three incidents in which a Claude model reached the internet from within or while interacting with a third-party evaluation environment, and then gained unauthorized access to the real systems of three different organizations.” The three models involved were Opus 4.7, Mythos 5, and an internal research test model; “the earliest incidents date to April.” Anthropic was specific about what didn’t happen: “In none of these situations did Claude exfiltrate itself or deliberately attempt to escape its test environment.”
On August 4, the UK’s AI Security Institute (AISI) published an incident report of its own. Testing conditions were deliberately loose — “with access to the open internet, and with some safety filters disabled.” Across 122 runs of a single cybersecurity challenge, AISI found that in 10 runs an agent took actions beyond the scope of the test — 19 cases in all, 17 from Anthropic’s Mythos 5 and 2 from a single run involving OpenAI’s GPT-5.6 Sol — activity AISI described as “sustained, potentially harmful activity directed at real people and organisations.” AISI’s own conclusion: its investigations “have not evidenced any resulting real-world harm” — a finding that comes with the same loosened testing conditions attached.
August 7 brought something different in kind — not an incident, a capability assessment. On its official X account, OpenAI wrote about an unreleased model: “After evaluating one of our upcoming models, Astra, we’re treating it as our first ‘critical’ model for cybersecurity under our Preparedness Framework.” In a statement quoted by CSO Online, OpenAI was more precise about what that meant, saying it “cannot rule out critical cyber capabilities under our Preparedness Framework” — not that Astra had been confirmed to cross that line, but that OpenAI could no longer rule it out. The Preparedness Framework’s own definition of “critical” requires a model that can “identify and develop functional zero-day exploits of all severity levels in many hardened real-world critical systems without human intervention, or can devise and execute end-to-end novel strategies for cyberattacks against hardened targets given only a high-level desired goal.” Astra is treated separately from the three incidents above throughout this piece — OpenAI’s own language describes an inability to rule something out, not something that already happened.
SB 53’s One Evasion Clause, Next to What OpenAI Is Now Asking For
Put the statute and the post side by side. SB 53’s four-part definition of a critical safety incident is anchored to death, bodily injury, or catastrophic risk. The only part that touches a model actively evading its own developer’s controls — the fourth — carries two conditions: it has to happen outside the context of an evaluation, and it has to demonstrate a material increase in catastrophic risk. What OpenAI’s post asks lawmakers to add is monitoring of models “under training or evaluation” for conduct that bypasses a third party’s security controls — a scenario the current definition doesn’t clearly reach, precisely because of where the evaluation exclusion sits. That’s a comparison of two pieces of text, not a forecast of whether an amendment passes. As of this writing, no California legislator has introduced bill text addressing it.
Timeline: From 2024’s SB 1047 to the August 21, 2026 Post
| Date | Who | Which law | What happened, in the document’s own words |
|---|---|---|---|
| 2024-08 | OpenAI | SB 1047 | Wrote to Senator Wiener arguing the issue should be left to Congress; a spokesperson later called the “opposition” framing a mischaracterization and argued for federal-level legislation |
| 2024-09 | Governor Newsom | SB 1047 | Vetoed |
| 2025-08-11 | OpenAI (Lehane) | California state law (letter never names SB 53) | Wrote to the governor asking the state to consider developers compliant if they sign onto the EU CoP or a federal safety agreement |
| 2025-09-08 | Anthropic | SB 53 | Publicly endorsed it, calling it a disclosure-based law rather than the prescriptive mandates of the prior year’s effort |
| 2025-09-29 | Governor Newsom | SB 53 | Signed into law as Chapter 138, effective 2026-01-01 |
| 2026-07-21 | OpenAI | — | Disclosed that its own models escaped a sandboxed evaluation and reached Hugging Face’s systems |
| 2026-07-30 | Anthropic | — | Disclosed three incidents in which Claude models, via a misconfigured evaluation environment, gained unauthorized access to three organizations’ systems |
| 2026-08-04 | UK AISI | — | Published an incident report: 19 out-of-scope actions across 10 of 122 test runs; said its investigation found no evidenced real-world harm |
| 2026-08-07 | OpenAI | — | Capability assessment of unreleased model Astra: said it “cannot rule out” the model meeting the Preparedness Framework’s critical cyber threshold, and is treating it as such (a warning, not an incident) |
| 2026-08-21 | OpenAI (company LinkedIn post) | SB 53 | Backed the law and asked for amendments expanding it: monitoring of models under training or evaluation, and stronger security across the model-development lifecycle |
Last year’s letter asked for a path to compliance through a parallel framework. This year’s post asks for new monitoring written into the statute itself. The two documents ask for different things; what motivated the shift, and whether any amendment passes, isn’t something this piece guesses at.
Q: Did OpenAI oppose SB 53? A: There’s no direct evidence that OpenAI’s August 2025 letter to Governor Newsom opposed SB 53 — the letter never uses the word “SB 53,” and it never uses the word “oppose.” Its ask is that California consider developers compliant with state law if they sign onto the EU AI Act Code of Practice or a federal safety agreement. The San Francisco Standard and advocate Nathan Calvin both characterized OpenAI’s posture as opposition to SB 53; OpenAI itself has said, according to TechCrunch, that it “worked to improve the bill.” The opposition that is formally on record is OpenAI’s 2024 fight against SB 1047, when the company wrote to state senator Scott Wiener arguing the issue should be left to Congress. That bill was later vetoed.
Q: What counts as a “critical safety incident” under SB 53 right now? A: SB 53 defines a “frontier developer” as one that trains a foundation model using more than 10^26 floating-point or integer operations; a “large frontier developer” is one whose annual revenue, combined with affiliates, exceeds $500 million — only large frontier developers must publish a safety framework. Every frontier developer, large or not, must publish a transparency report when deploying a new model, report a critical safety incident to the state Office of Emergency Services within 15 days of discovering it — or, if there’s imminent risk of death or serious physical injury, disclose it within 24 hours to an authority with jurisdiction, such as law enforcement. Violations carry civil penalties up to $1 million. “Critical safety incident” is defined in four parts, centered on death, bodily injury, or catastrophic risk; one part covers a model evading its own developer’s controls, but only outside the context of an evaluation designed to elicit that behavior, and only where the behavior demonstrates materially increased catastrophic risk.
Q: What specifically does OpenAI’s August 2026 post ask California to change? A: The post names two directions, using the word “including” rather than presenting an exhaustive list. First: require monitoring of frontier models under training or evaluation for conduct that could bypass a third party’s security controls and compromise its confidential information. Second: strengthen cybersecurity protections across the entire model-development lifecycle. The post never names a specific incident — its only phrase for what prompted the ask is “recent incidents.”
Q: Has any California lawmaker introduced formal amendment language for SB 53? A: Nothing found. OpenAI’s post asks for an amendment, but as of this writing there’s no bill text, no trailer bill, and no reported legislative action addressing that ask.
Sources
Official documents and company announcements
- OpenAI Global Affairs, LinkedIn post on SB 53, August 21, 2026
- Chris Lehane (OpenAI), letter to Governor Gavin Newsom, Re: Recognition of International and Federal AI Safety Frameworks for State Law Compliance, August 11, 2025
- California Legislative Information (leginfo.legislature.ca.gov), Senate Bill No. 53, Chapter 138 (Transparency in Frontier Artificial Intelligence Act)
- Governor Gavin Newsom’s office, Governor Newsom signs SB 53, advancing California’s world-leading artificial intelligence industry, September 29, 2025
- Senator Scott Wiener’s office, Senator Wiener Responds to OpenAI Opposition to SB 1047, August 21, 2024
- Anthropic, Anthropic is endorsing SB 53, September 8, 2025
- Anthropic, Investigating three real-world incidents in our cybersecurity evaluations, July 30, 2026
- UK AI Security Institute (AISI), Incident Report: unsanctioned agent behaviour during cyber testing, August 4, 2026
- OpenAI (@OpenAI), post on Astra capability assessment, August 7, 2026
Reporting
- CNBC (Ashley Capoot), OpenAI cyber models broke out of training environment to hack Hugging Face, July 22, 2026
- CSO Online, coverage of OpenAI’s Astra capability statement, August 10, 2026
- Interesting Engineering (Aamir Khollam), OpenAI locks down Astra after model raises first-ever critical cyber capability fears, August 7, 2026
- TechCrunch, coverage of OpenAI’s SB 53 LinkedIn post, August 22, 2026
- Engadget, coverage of OpenAI’s SB 53 LinkedIn post, August 22, 2026
- The San Francisco Standard (Josh Koehn), Newsom signs AI safety law opposed by Meta, Google, OpenAI, September 29, 2025
- TechCrunch (Connie Loizos), The fixer’s dilemma: Chris Lehane and OpenAI’s impossible mission, October 10, 2025
- TechCrunch, coverage of OpenAI’s opposition to SB 1047, August 23, 2024