OpenAI just told California lawmakers to make the state’s new AI safety bill tougher. Most people see that as tech finally showing some responsibility. I see it differently. When the richest company in any industry starts demanding stricter rules, it’s never about safety. It’s about keeping the door shut on everyone else.
What’s Actually Happening
California has been trying to regulate AI since 2024. Governor Gavin Newsom vetoed SB 1047, a sweeping AI safety bill, after massive industry pushback. According to the California Legislative Analyst’s Office, that bill would have required safety evaluations for any AI model trained on more than $100 million in compute. Now in 2026, Sacramento is back with new legislation, and this time OpenAI isn’t fighting it. They’re asking lawmakers to go further.
OpenAI submitted comments to the California legislature recommending stronger provisions around model transparency, incident reporting, and liability for high-risk AI systems. According to reporting from The Information, OpenAI’s policy team specifically pushed for requirements that would apply to frontier-tier models. That’s the exact tier where OpenAI operates and where most startups cannot compete.
This isn’t a coincidence. This is strategy.
The Regulation Moat Is Real
Here’s what the average builder or founder misses about this moment. Compliance costs money. Lots of it. According to a 2025 KPMG survey of U.S. technology companies, firms with fewer than 50 employees spend about 3.7 times more per capita on regulatory compliance than firms with over 500 employees. That gap doesn’t shrink when regulation gets tighter. It widens.
OpenAI has a compliance team. They have legal budgets. They have the lawyers, the government relations staff, and the infrastructure to absorb new rules. A two-person AI startup in Fresno does not.
This is the exact same playbook the big banks ran after the 2008 financial crisis. Dodd-Frank added thousands of pages of rules. JPMorgan Chase could afford to hire 13,000 compliance workers, according to Bloomberg. Smaller community banks couldn’t. Nearly 1,800 small banks closed or merged between 2010 and 2023, according to the FDIC. Regulation didn’t make banking safer. It made banking more concentrated.
I’m not saying AI safety rules are bad. I’m saying you should understand who benefits most when the rulebook gets thicker. It’s not you.
If you’re running an AI business right now, this is the moment to get your financial house in order. Companies that survive heavy regulatory environments are the ones that track every dollar of compliance spend with precision. I’ve seen founders use Wallester for their business card and expense management because it gives them real-time visibility into where money is going across teams. That kind of visibility matters more when compliance costs start showing up on your books.
What This Means for You
If you build with AI, here is what I would do right now.
First, assume California sets the national standard. California has 39 million people and the world’s fifth largest economy. When California regulates, the rest of the country tends to follow within two to three years. That’s not a guess. That’s the pattern from auto emissions, data privacy, and food labeling.
Second, document everything. Incident reports, model evaluations, data sourcing, safety testing. Start now even if the law doesn’t require it yet. Regulators reward companies that show good faith effort. Courts look at documentation when liability questions come up.
Third, think about your team. If AI compliance becomes a real cost center, you need people who understand both the technical side and the legal side. That means hiring carefully. Companies that are ahead of this use Gusto for payroll and HR so they can onboard compliance roles fast without the administrative mess. Getting the people infrastructure right before the rules hit is how you avoid panic hiring at triple the cost six months from now.
Fourth, stop assuming the rules won’t touch you because you’re small. SB 1047 had thresholds based on compute costs. Future bills will too, and those thresholds drop over time as compute gets cheaper. A model that costs $5 million to train today might cost $500,000 to train in 2028. The rules will catch up to you.
The Bottom Line
OpenAI calling for stronger AI rules is not a public service. It’s a business decision made by very smart people with very good lawyers. The question isn’t whether California passes a tougher bill. It will. The question is whether you’re building something that can absorb what’s coming or something that gets absorbed by it. Start treating compliance like a capital investment before the bill passes and the window closes.
Frequently Asked Questions
What is California’s AI safety bill about?
California’s AI safety legislation focuses on requiring transparency, safety evaluations, and incident reporting for high-risk AI systems. The push in 2026 builds on the vetoed SB 1047 from 2024 and targets models that could cause serious harm at scale.
Why does OpenAI support stronger AI regulation?
OpenAI’s public position is that stronger rules create accountability across the industry. The business reality is that large companies absorb compliance costs far more easily than startups, which means tougher rules often benefit established players at the expense of new entrants.
Will California’s AI safety bill affect businesses outside California?
Very likely yes. California’s regulations historically spread to other states over time. Any company with California customers or that uses California-based cloud infrastructure may also fall in scope depending on how the final bill is written.
How should small AI businesses prepare for new regulations?
Start documenting your model development process, data sourcing, and safety testing now. Build a compliance paper trail before it’s legally required. Companies that show proactive good faith effort tend to fare better when regulators or litigants come looking.
What compute threshold triggers the OpenAI California AI safety bill requirements?
California’s previous attempt used a $100 million compute cost as the trigger for compliance obligations. As compute prices fall, that threshold will capture more and more products over time, including many that seem well below it today.


