Pseudonymize your documents, and include the values in your AI deliverablesPseudonymize your documents consistently, and restore (de-pseudonymize) the original values in your AI assistants' outputs

Marvin Systems CEO

Of the 50 largest AI companies in the world, 32 are headquartered in California. California is an important market, on par with Europe.
A landmark law, officially titled the Transparency in Frontier AI Act and better known as SB-53, was passed and signed into law last September by the Governor of California.
It marks a turning point in AI regulation. It targets the cutting-edge models of tomorrow: those exceeding 10^26FLOPS* of training, which is beyond the current state-of-the-art (approximately 10^25FLOPS).
Unlike the AI Act, which regulates the entire value chain (those who create and those who use the models), SB-53 targets exclusively the creators of cutting-edge models with significant resources (over $500 million in revenue). Giants such as OpenAI, Anthropic, xAI, and DeepSeek are affected when they operate in California, just as they are affected by the provisions of the AI Act when they operate on European soil.
Europe favors a pyramid approach (with risk categories ranging from minimal to unacceptable, including so-called “high-risk”** systems, which must comply with strict obligations) and a sectoral approach.
California, meanwhile, targets risks that are “catastrophic” in scale: 50+ deaths, $1 billion+ in damage, CBRN weapons, autonomous cyberattacks, or loss of control of systems.
Developers of advanced models covered by SB-53 must publish their internal governance policies covering the detection of serious incidents, anti-intrusion measures, and testing protocols.
In addition, companies must create anonymous reporting channels allowing employees to report (internally or to the relevant authorities) their concerns about risks to public health and safety, within the limits defined by the law.
Unlike the prescriptive requirements of the AI Act (documentation, third-party audits), SB-53 allows companies to define their own protocols, but requires them to comply with them publicly.
The penalty? $1 million per violation. This may seem insignificant compared to the billions of dollars invested in their data centers. However, all violations must be recorded in an annual report. In an industry where trust is paramount, the reputational risk far outweighs the fine. Above all, this mandatory transparency creates peer pressure: no company wants to be seen as having the lowest standards.
The AI Act imposes a strict regulatory framework (with heavy penalties of up to €35 million or 7% of global turnover), while SB-53 focuses on accountability. Europe regulates comprehensively, while California targets critical players.
These two approaches are not opposed, but rather complementary. Europe seeks to prevent already tangible abuses (discrimination in hiring, abusive facial recognition, exploitation of people's vulnerabilities, social scoring, algorithmic surveillance, etc. – all risks that directly affect citizens and public services).
California, for its part, anticipates emerging dangers and extreme scenarios: the creation of AI-assisted biological weapons, large-scale autonomous cyberattacks, or loss of control over ultra-powerful models. These risks remain exceptional today, but are becoming technically feasible with tomorrow's cutting-edge models.
California, which currently allows companies to define their own security and governance protocols, as mentioned above, could, over time, impose more precise technical standards, particularly as models exceed new thresholds of complexity.
This would bring it closer to the prescriptive European model, based on verifiable obligations and coordinated controls by the authorities.
For its part, Europe is also beginning to actively monitor the most powerful models, with the European AI Office working to structure a specific response to the new systemic risks associated with future ultra-powerful models.
The two approaches converge towards the same goal: to regulate both current uses and tomorrow's technologies, while laying the foundations for transatlantic coordination on the governance of advanced AI.
Beyond their technical differences, their respective frameworks, one structured, the other more agile, illustrate an attempt to establish comprehensive international safeguards in the face of the technological race.
The AI Act and SB-53 illustrate an urgent need to reduce the gap between the speed of innovation and the ability of the law to prevent serious risks to the community. In a context where AI models are reaching unprecedented levels of capability, inaction is no longer an option.
Ultimately, these regulations could inspire a common set of principles for the safety and transparency of cutting-edge models, around which future international AI law will be built.
* Floating Point Operations Per Second (number of floating point operations per second). This is a unit of measurement for the computing speed of a computer system and therefore part of its performance.
** “AI systems [...] that may undermine people's safety or fundamental rights, which justifies subjecting their development to stricter requirements” (CNIL, 2025).
For further information : California Just Passed the First U.S. Frontier AI Law. Here’s What It Does.