California’s legislature passed a successor frontier AI safety bill in the 2026 session. [Established — California Legislature enrolled bill; September 30 is the constitutional deadline for gubernatorial action on bills passed in the final legislative days, established under California Constitution Article IV, Section 10. Tier 1.] The bill’s core architecture imposes safety-testing and transparency obligations on developers of AI systems above a defined compute threshold. The 2024 veto of SB 1047 was explicit: Newsom said the bill was “well-intentioned” but “an AI model’s size is not a reliable measure of its potential for harm.” The successor legislation has been revised to address that objection — the specific revisions, and whether they are sufficient to change the governor’s analysis, are the variables that September 30 will resolve. [Assessed with moderate confidence — exact bill text and governor’s stated position as of publication not independently confirmed at Tier-1 level; the structural framework described is consistent with published legislative summaries.]
1. The 2024 Veto and What It Actually Decided
Governor Newsom vetoed SB 1047 on 29 September 2024, after the bill had passed the California Assembly and Senate with strong margins. [Established — California Governor’s Office, veto message for SB 1047 (Scott Wiener), 29 September 2024. Tier 1.] The veto message was careful: it did not reject the goal of AI safety regulation in principle. It rejected the specific instrument. The governor argued that a compute-threshold approach — applying obligations to any AI model trained above a defined number of floating-point operations — was both over-inclusive (capturing models with no realistic harm pathway) and under-inclusive (missing dangerous narrow AI systems that do not reach the compute trigger). He also cited uncertainty about federal preemption risk.
What the veto resolved was the specific text of SB 1047. What it did not resolve was the underlying question: does the state of California have an obligation to impose safety requirements on AI systems developed within its borders, and if so, what are those requirements? The legislature’s answer to that second question, then and now, is yes. The 2024 veto did not extinguish the bill’s authors; it redirected them.
The 2026 successor bill represents approximately eighteen months of redrafting. The compute-threshold structure has been modified: the triggers are now more specifically tied to categories of use — autonomous systems, critical infrastructure integration, and large-scale public deployment — rather than to training compute alone. Whether that revision answers the governor’s 2024 objection depends on whether the new threshold is legible enough to produce compliance without creating the over-broad chilling effect his veto message named. [Assessed with moderate confidence — based on published legislative analysis of the successor bill; Tier-2 legal analysis from law firm advisories consistent with this framework.]
2. What the Bill Would Do If Signed
The bill’s core obligations — as established by published legislative summaries — require developers of covered frontier AI systems to: conduct pre-deployment safety testing against defined harm categories; publish safety frameworks describing how testing was conducted and what risks were identified; maintain the ability to disable systems found to produce specified types of catastrophic or irreversible harm; and notify California’s Attorney General of any safety incident meeting defined thresholds. [Assessed with high confidence — consistent with multiple published legislative summaries; Tier-1 bill text review pending final enrolled version.]
Enforcement sits with the Attorney General’s office, not a dedicated agency. The civil penalty structure is risk-graduated. There is no private right of action in the version that has been described in legislative committee reports — an explicit change from SB 1047’s original version, which one of the governor’s 2024 objections addressed. [Assessed with moderate confidence.]
The bill exempts AI systems used in research that is not publicly deployed and does not reach the deployment thresholds. Open-source models are addressed through a tiered approach that distinguishes between developers who release model weights to the public — and therefore cannot control downstream deployment — and those who maintain proprietary access controls. The open-source exemption structure was one of the more contested elements of the 2025–2026 legislative debate and remains a pressure point for industry opponents. [Assessed with moderate confidence — consistent with published legislative debate records and Tier-2 legal analysis.]
3. The EU Comparison: What Enforcement Actually Requires
The EU AI Act entered its first compliance phase in August 2026, with transparency obligations for general-purpose AI model providers now legally effective. [Established — Official Journal of the European Union, EU AI Act (Regulation (EU) 2024/1689), compliance timetable. Tier 1.] The EU’s experience over the first months of compliance is instructive for what California’s bill would require in practice.
The EU framework is structurally different — it applies across a single regulatory market of 27 member states with a dedicated enforcement agency (the AI Office) and significant enforcement resources. California’s bill would apply within one state, enforced by an Attorney General’s office that already carries a substantial enforcement portfolio. The comparison is not direct. But the EU’s experience has revealed a consistent operational problem: disclosure-based compliance regimes require companies to produce safety documentation, but they do not create an independent capacity to evaluate whether the documentation accurately reflects system behaviour. [Assessed with high confidence — documented in European Parliament Committee on Legal Affairs analysis and NGO monitoring reports on EU AI Act first-phase compliance, mid-2026.]
California’s bill, as structured, faces the same constraint. The safety-testing obligation requires documentation of what the developer did. It does not create an independent capability to verify whether the documentation reflects what the system actually does. The structural gap between disclosure and verification is the central weakness of first-generation AI regulation globally — and it applies to the California bill as directly as it applies to Brussels. [Assessed with high confidence — structural observation consistent with academic AI governance literature and regulatory analysis.]
4. Why the September 30 Decision Travels Beyond California
The federal government has not enacted comprehensive AI safety legislation. Congress has held hearings; the current federal AI governance landscape consists of executive orders, voluntary commitments from major AI developers, and sector-specific agency guidance under existing statutory authority. None of it constitutes a binding legal obligation on frontier AI development at the federal level. [Established — As of September 2026, no comprehensive federal AI legislation has been enacted. NIST AI Risk Management Framework is voluntary. Executive Order 14110 (2023) provisions were partially rescinded in early 2025. Tier-1 sources: NIST, Federal Register, Congressional Research Service.]
In the absence of federal law, state legislation becomes the de facto national patchwork. Several states — including Colorado, Texas, and Illinois — have enacted or are advancing AI governance legislation in specific domains (employment, insurance, biometric data). California’s frontier AI bill is different in kind: it addresses the development of the most capable AI systems themselves, not downstream applications in specific sectors.
If Newsom signs the bill, California becomes the only US jurisdiction with binding safety obligations on frontier AI developers. The companies primarily affected — concentrated in the Bay Area and other California locations — immediately face compliance requirements that their competitors in other states do not. That creates both an incentive to seek federal preemption and a precedent for other states to adopt comparable frameworks. [Assessed with moderate confidence — analytical inference; the specific regulatory dynamics would depend on industry legal strategy and other states’ legislative calendars.]
If he vetoes again, the signal is different but equally consequential: California’s governor has declined twice to impose safety obligations on frontier AI development, and the gap between regulatory ambition and enacted law widens further. That gap is not filled by goodwill alone. It is filled, structurally, by whatever incidents and failures produce sufficient political pressure to force a third attempt — under conditions that may be less favourable to careful drafting than the current moment. [Assessed with moderate confidence — standard regulatory-politics pattern; not unique to AI governance.]
Prediction: Governor Newsom signs the California frontier AI safety bill before the September 30, 2026 deadline, accompanied by a signing statement that explicitly references the absence of federal legislation as a primary rationale; the signing triggers at least one federal preemption challenge from an AI developer or industry association within 90 days; and at least two additional US states introduce comparable frontier-AI safety legislation within six months of the California signing.
Confidence: Assessed low-moderate. The political dynamics have shifted toward signing since 2024: the EU precedent reduces the “California acting alone” argument; the absence of federal legislation reduces the federal preemption cover the 2024 veto implicitly relied on; and the revised threshold structure addresses the governor’s stated textual objection. The principal failure mode is a second veto accompanied by a call for federal action — a defensible position, but one that leaves the regulatory field empty indefinitely.
Resolution: 30 September 2026. Check: California Governor’s Office, chaptered bill or veto message. Subsequent predictions on preemption and state adoption resolve December 2026 and March 2027 respectively.
Bottom line: The September 30 deadline is not merely a California matter. It is the next visible decision point in the slow-motion question of whether the United States will impose legally binding safety obligations on the development of frontier AI systems — or whether that obligation will continue to be deferred to voluntary commitments, executive orders, and the kind of regulatory capture that occurs when the period of governance vacuum outlasts the period of technical uncertainty. Newsom signed the EU AI Act comparison into his 2024 veto message as a caution about regulatory overreach. In September 2026, the EU Act is in force and the United States is not. That changes what the caution points at.