Direct comparison
EU AI Act vs SB 53: Transparency Compared
EU AI Act GPAI rules vs California SB 53: compare coverage thresholds, published disclosures, incident-reporting deadlines, penalties, and effective dates.
Written and maintained by CASRAI Editorial Board
Last updated
Ask CASRAI · free to try
Ask about EU AI Act vs SB 53: Transparency Compared
Ask your first 2 questions free below. Subscribers get 150 a day for $29 a month.
Ask CASRAI answers research-administration questions and cites the passages behind every claim. When our sources don't cover a question, it says so.
Answers draw on CASRAI's guides and dictionary plus the federal and funder documents we index: Federal Register, Grants.gov, Regulations.gov and UKRI.
Works on this site and inside Claude, Cursor and the AI tools you already use.
Everything CASRAI publishes — this page, the dictionary, the guides and the news — stays free to read, with no account and no card.
How do EU AI Act (GPAI provisions), California SB 53 (TFAIA) compare side by side?
The table below compares EU AI Act (GPAI provisions), California SB 53 (TFAIA) across 6 procurement-relevant dimensions, from who is covered through effective dates.
Side-by-side comparison
| Dimension | EU AI Act (GPAI provisions) | California SB 53 (TFAIA) |
|---|---|---|
| Who is covered | Providers of general-purpose AI (GPAI) models. All GPAI providers carry baseline transparency duties under Article 53; a subset carrying "systemic risk" carries the additional duties under Article 55. | "Large frontier developers" only — a narrower category than the EU's. A company must both train a covered model and clear a revenue threshold before SB 53's core duties apply. |
| What triggers coverage | A rebuttable presumption of "systemic risk" attaches once a GPAI model's cumulative training compute exceeds 10^25 FLOPs (Article 51(1)(a)-(2)). The European Commission can also designate a model as systemic-risk on other grounds, independent of the compute figure. | Two thresholds, both required: the model must be a "frontier model," defined as a foundation model trained using more than 10^26 computing operations, and the developer, together with its affiliates, must have had annual gross revenues over $500 million in the preceding calendar year (Cal. Bus. & Prof. Code §22757.11(h)-(j)). |
| What must be published | All GPAI providers: technical documentation of training and testing (Article 53(1)(a)), information for downstream providers on capabilities and limitations, a Copyright Directive compliance policy, and a "sufficiently detailed summary" of training content. Systemic-risk providers add documented adversarial testing and systemic-risk assessment and mitigation (Article 55(1)(a)-(b)). | A "frontier AI framework" published on the developer's website describing how it manages, assesses, and mitigates catastrophic risk, including safety standards it has adopted and its cybersecurity practices (§22757.12(a)), updated at least annually and within 30 days of a material change. A transparency report before deploying any new or substantially modified frontier model, covering release date, intended uses, and a summary of catastrophic-risk assessments (§22757.12(c)). A summary of any internal catastrophic-risk assessment every three months (§22757.12(d)). |
| Incident-reporting duties | Systemic-risk GPAI providers must track, document, and report serious incidents and any corrective measures to the AI Office and, where relevant, national competent authorities "without undue delay" (Article 55(1)(c)). The Act does not attach a fixed number of hours or days to that phrase for GPAI incidents. | Large frontier developers must report a "critical safety incident" to California's Office of Emergency Services within 15 days of discovery, or within 24 hours if there is an imminent risk of death or serious physical injury (§22757.13(c)). §22757.11(d) defines a critical safety incident to include unauthorized model-weight access causing death or injury, harm from a materialized catastrophic risk, loss-of-control incidents causing death or injury, and deceptive model behavior that subverts the developer's own controls. |
| Enforcement and penalties | The European Commission enforces GPAI obligations directly (not national regulators). Article 101 sets fines of up to 3% of a provider's total worldwide annual turnover for the preceding financial year, or €15,000,000, whichever is higher, for infringing GPAI provisions or obstructing the Commission's information and evaluation powers. | The California Attorney General is the sole enforcer — SB 53 creates no private right of action (§22757.15(b)). Civil penalties run up to $1,000,000 per violation (§22757.15(a)), covering failures to publish the required framework or transparency report, false statements about risk management, and failures to report incidents. |
| Effective dates | GPAI transparency and copyright obligations under Articles 53 and 55 applied from August 2, 2025 for models newly placed on the market; providers of models already on the market before that date have until August 2, 2027 to come into compliance. The Commission's enforcement powers against GPAI providers activated August 2, 2026. | Signed into law September 29, 2025; took effect January 1, 2026. The California Department of Technology must report on frontier-model risk and the CalCompute public-compute framework on or before January 1, 2027, and may update SB 53's statutory thresholds as the technology changes. |
Common questions
Common questions about EU AI Act (GPAI provisions) vs California SB 53 (TFAIA)
Does a model have to cross both the EU AI Act's threshold and SB 53's threshold to be covered by both laws?
+
No — the two thresholds are unrelated and are tested separately under each law. A model can clear the EU AI Act's 10^25 FLOPs compute presumption without its developer meeting SB 53's $500 million revenue threshold, and vice versa. A developer operating in both California and the EU has to test its models and its own revenue against each law's criteria independently.
Which law has the stricter incident-reporting deadline?
+
SB 53 sets fixed deadlines — 15 days generally, 24 hours if there is imminent risk of death or serious injury. The EU AI Act's Article 55(1)(c) uses the open-ended standard "without undue delay" for GPAI systemic-risk incidents, without a fixed number of days written into that provision.
Who enforces SB 53 versus the EU AI Act's GPAI rules?
+
SB 53 is enforced exclusively by the California Attorney General through civil actions, with no private right of action. The EU AI Act's GPAI provisions are enforced directly by the European Commission (via the AI Office) rather than by the national regulators that enforce most of the rest of the Act.
Are the penalty amounts comparable?
+
Not directly — they're structured differently. SB 53 penalties are capped at $1,000,000 per violation. EU AI Act Article 101 fines for GPAI infringements are calculated as the higher of €15,000,000 or 3% of the provider's total worldwide annual turnover, which for a large developer can exceed SB 53's fixed cap by a wide margin.
Going deeper







