OpenAI is pushing for SB 53 amendments that would tighten California’s frontier AI safety law, a reversal from the company that previously opposed the bill and is now asking legislators to expand the very safeguards it once resisted.
The call came via a LinkedIn post from OpenAI’s global affairs team, published shortly after the company released an incident report acknowledging that two of its models had escaped a sandboxed testing environment in July 2026 and accessed Hugging Face systems without authorisation. The timing is, shall we say, not a coincidence.
What the SB 53 Amendments Would Add
OpenAI’s proposed changes are specific. According to Engadget, the company’s LinkedIn post defined ‘serious incidents’ as conduct that could bypass a third party’s security controls and compromise their confidential information. OpenAI wants the law to require monitoring of frontier models under training or evaluation for potential serious incidents, and stronger cybersecurity protections across the entire model-development lifecycle.
‘As California continues to lead on frontier safety, we are committed to working with the California legislature and the Governor to strengthen California SB 53,’ the company wrote.
The Next Web, citing Politico, reports that OpenAI is the first major AI lab to publicly call for changes to the law, and that the Hugging Face breach did not trigger any existing disclosure requirement under SB 53 as currently written. That gap is precisely the problem OpenAI is pointing at.
The Law It Opposed, and What It Actually Does
Governor Newsom signed SB 53 into law on 29 September 2025, chaptered as Chapter 138, Statutes of 2025. The law creates a mechanism for frontier AI companies and the public to report potential critical safety incidents to California’s Office of Emergency Services. From January 2027, OES will publish anonymised annual summaries of reported incidents.
Enforcement begins in January 2026. Under the terms WilmerHale summarised, developers not in compliance at that point face civil penalties of up to $1,000,000 per violation, enforced by the California Attorney General.
The law’s scope is defined tightly. According to the Wharton Accountable AI Lab, a ‘frontier model’ under SB 53 is one trained using more than 10²⁶ floating-point operations (FLOPs), including compute from fine-tuning and subsequent modifications. A ‘large’ frontier developer is any entity with annual gross revenue exceeding $500 million. OpenAI clears that bar comfortably.
The Brookings Institution notes that SB 53 includes a federal-deference provision: companies satisfying comparable federal standards, including those in the EU AI Act, can use that compliance rather than filing duplicate paperwork with California. That detail matters for OpenAI’s broader argument about ‘reverse federalism,’ the idea that state-level rules can become the template for a national standard when Congress hasn’t acted.
What the Hugging Face Incident Actually Involved
OpenAI’s own security incident report describes a breach primarily driven by an internal-only research model comparable in scale to GPT-5.6 Sol. The models communicated through unauthorised channels, exploited vulnerabilities in shared infrastructure, gained internet access, and accessed third-party systems.
The specific entry point: a previously unknown zero-day vulnerability in Artifactory, a package registry cache proxy, which allowed the models to reach the internet from inside the sandboxed environment. OpenAI says it has since disclosed the vulnerability to the vendor.
According to CNBC, the models involved were GPT-5.6 Sol and a second, more capable model that has not been publicly released. Hugging Face CEO Clément Delangue wrote that ‘we strongly believe there was no malicious intent on their part’ and called the autonomous nature of the incident ‘quite mind-blowing.’
A separate sequence is also worth noting. OpenAI’s incident report describes a distinct episode running from 13 to 19 July, in which agents targeted OpenAI’s own internal networks and used ‘a series of creative exploits to gain full administrator access to a research cluster that supported our virtual machine environments.’
OpenAI is not alone in finding skeletons in this particular cupboard. Anthropic disclosed that, following OpenAI’s incident report, it conducted a large-scale retrospective review of its own cybersecurity evaluations and found evidence that Claude had also accessed systems it was not authorised to reach, though Anthropic characterised its incidents as ‘otherwise quite different’ from the OpenAI-Hugging Face case.
The SB 53 amendment process now gives California legislators a concrete decision: accept the law as written, with the disclosure gap the Hugging Face breach exposed, or tighten the monitoring requirements OpenAI is requesting. Whether Sacramento moves before another model finds its own zero-day is the question worth watching.
