California Governor Gavin Newsom has officially signed a landmark set of artificial intelligence regulatory bills. Notably, this batch of new laws, aimed at strengthening the safety risk assessment of cutting-edge large models, transparency disclosure, and preventing catastrophic cyberattacks, received rare endorsements and public support from several leading Silicon Valley AI companies, including OpenAI and Anthropic, during previous legislative debates.

Models with Trillion-Parameter Scale Must Undergo "Red Team Drills + Third-Party Audit" Before Launch

In recent years, as the computational power of generative AI has expanded exponentially and the autonomous capabilities of cutting-edge foundational models have significantly improved, concerns about AI being misused for critical infrastructure destruction, automated biochemical weapon development, large-scale deepfake manipulation, and severe cybersecurity vulnerabilities have intensified. Due to continued stagnation in federal-level AI legislation in the U.S. Congress, the California State Legislature has taken on the role of a pioneer in AI legislation across the country.

The multiple bills signed this time focus on legally regulating the safety testing standards for ultra-large-scale foundational models. They require model developers to conduct standardized red team confrontation drills, establish strict catastrophe risk mitigation protocols, and submit compliance security reports that have been independently audited by third parties to state regulatory agencies before training and deploying frontier systems with trillion-parameter scale.

Different from previous radical regulatory proposals that caused intense turmoil in Silicon Valley and faced strong opposition from tech giants and venture capital institutions, this set of bills incorporated in-depth technical suggestions from leading AI laboratories during the drafting and revision process. Anthropic and OpenAI had previously expressed deep concerns about overly rigid provisions that could stifle the development of open-source communities or expand civil liability indefinitely. After intensive lobbying and minor adjustments to the clauses, the final enacted bills focus more on establishing transparent "pre-risk assessment frameworks" and "industry best practice benchmarks," rather than directly setting hard technical caps or implementing unworkable punitive measures, thus gaining collaborative support from major AI research institutions within the legal framework.

Deepfakes Must Be Watermarked, Whistleblowers Are Legally Protected

In addition to underlying safety reviews, the bill also includes traceability identification and watermarking standards for AI-generated content, requiring platforms and major content distribution channels to add system-level digital fingerprints to deepfake audio and video content to prevent the spread of false information in elections and malicious personal fraud. At the same time, the bill provides more explicit legal protection for internal employees and researchers who discover and expose potential major security vulnerabilities in models, strictly prohibiting companies from depriving technical personnel of their right to report catastrophic security risks to regulatory authorities through harsh confidentiality agreements.

This move marks that California, as a core hub for global AI research and development, has explored a regulatory approach that is relatively recognized by the industry, balancing stringent security boundaries with maintaining industrial innovation vitality.