2026-01-01 · US-CA · in force now
Starting January 1, 2026, frontier AI model developers above California's compute and revenue thresholds must publish safety protocols, report critical safety incidents, and maintain whistleblower protections. The obligation is now in force.
What it requires
Frontier model developers must publish their safety protocols—the internal standards and processes they use to identify and mitigate risks. They must report critical safety incidents to the state. They must also establish and maintain whistleblower protections for employees or contractors who report safety concerns internally or to regulators. The law does not specify the format, frequency, or level of detail for incident reports; teams should verify California's implementation guidance for those specifics.
Who it binds
This obligation binds developers of frontier AI models that exceed California's statutory compute or revenue thresholds. Frontier status is determined by model scale and capability. In-house counsel, product and safety teams, and compliance officers at qualifying organizations own implementation. Third-party model providers and vendors below the threshold are not directly bound, but customers using their models may need to assess whether they are.
How to check whether you comply
Identify whether your organization's largest AI models exceed California's compute and revenue thresholds (verify the current thresholds in California's regulatory guidance or the statute).
Document your existing safety protocols and confirm they cover risk identification and mitigation; prepare them for publication.
Audit your incident reporting process to ensure it captures and logs critical safety incidents; test the chain of custody to regulators.
Review your whistleblower policy and employee handbook to confirm protections for safety reporting are explicit and accessible.
What teams get wrong
The law took effect January 1, 2026—the deadline has passed. If your organization is a frontier model developer, this is now a live compliance obligation, not a future deadline. Verify which safety incidents qualify as 'critical' under California's guidance; underreporting or misclassification is a common gap. Ensure whistleblower protections are actually communicated to staff, not just documented.
This is one of 17 dated AI obligations we track
This one is already in force. There are 16 others across the EU, UK, and US, and they do not arrive in a convenient order. The AI Compliance Deadline Radar lists every one of them with a live countdown.
Get The AI Reg Brief — free. Twice a month, three minutes. Every issue leads with a countdown to the next deadline that binds you, so the one about to land finds you rather than the other way round.
CCPA regulations — risk assessments — US-CA, 2026-01-01
California AI Transparency Act (SB 942) — US-CA, 2026-08-02
California AI Transparency Act (SB 942) — platform duties — US-CA, 2027-01-01
Source
Not legal advice. This summarizes a public source so you can act on it; verify against the primary text before you rely on it.
