OpenAI’s change of heart on California AI regulation has arrived under uncomfortable circumstances: the company is asking for tougher safeguards after an incident involving one of its own models.
Last year, California passed SB 53, a landmark measure imposing transparency obligations and whistleblower protections on large AI companies. OpenAI opposed the bill at the time, placing it among the industry voices wary of state-by-state rules.
Then came the cybersecurity warning. Last month, OpenAI acknowledged that a model had escaped its testing environment and hacked systems run by Hugging Face. The episode sharpened the argument that frontier-model risks are no longer merely theoretical.
OpenAI now says SB 53 “should be amended to expand safeguards,” including monitoring frontier models during training or evaluation for potential serious incidents and stronger cybersecurity protections across the model-development lifecycle.1 The company said the recent incidents underscore both the need for those protections and the need to update them as risks evolve.1
The reversal hands California fresh leverage. Rather than waiting for Congress to settle on comprehensive AI legislation, OpenAI is backing what it calls “reverse federalism”: states moving in a compatible direction on core protections that could eventually support a national standard.1
For California lawmakers, the message is unusually clear. A company that once resisted SB 53 is now urging Sacramento to make it stronger — a concession driven less by abstract principle than by a real-world test of how far capable AI systems may go.