Skip to main content
TrustEdge AI

San Francisco, CA

AI governance in San Francisco

Where the AI is the product

San Francisco buyers are usually not adopting someone else’s AI — they are shipping their own. That inverts the governance question. The exposure is not "what did we buy," it is "what did we build, what does it touch, and can we describe it to a customer’s security reviewer."

We work on-site in San Francisco. TrustEdge has no San Francisco office — our engineers and assessors travel to you, and AI Academy and agent engagements are delivered nationally.

The pressure

What San Francisco organisations are actually dealing with

Enterprise and healthcare customers now send AI questionnaires with their security agreements, and a startup that cannot answer them loses the deal at procurement rather than in the demo. Meanwhile the same California employment and privacy rules that apply to a hospital apply to a fifty-person company using an applicant-screening tool.

Sectors we serve here

  • Financial services and fintech
  • Health technology
  • Enterprise software

Regulatory context

The California rules that reach San Francisco buyers

California has more AI law in force than any other state. The rule most likely to reach you is not the frontier-AI headline act — it is an employment regulation that has bound every employer with five or more employees since October 1, 2025.

SB 53 — the headline law, which probably is not about you

The Transparency in Frontier Artificial Intelligence Act was chaptered September 29, 2025 and took effect January 1, 2026. It reaches frontier developers: entities that trained or initiated the training of a foundation model using more than 10^26 integer or floating-point operations, counting fine-tuning and modification. Heightened duties fall on "large frontier developers," meaning those whose annual gross revenues with affiliates exceeded $500,000,000 in the preceding calendar year. Obligations are to publish a frontier AI framework, publish transparency reports, report critical safety incidents, and protect whistleblowers. Enforced by the California Attorney General with penalties up to $1,000,000 per violation. If you buy or license models rather than train at that scale, SB 53 regulates your vendor and not you. Your access to what it produces is a contracting question, not a compliance one.

AB 2013 — training-data transparency, and it can catch fine-tuners

In effect since January 1, 2026. A developer of a generative AI system or service made publicly available to Californians on or after January 1, 2022 must post a high-level summary of the datasets used in training, across twelve enumerated categories: sources and owners of the datasets, how they further the intended purpose, the number of data points in ranges, whether the data includes copyrighted or licensed material, whether it includes personal information or aggregate consumer information, how it was cleaned or processed, collection and first-use timeframes, and whether synthetic data was used. The summary must be posted before public release and updated on substantial modification. The statute defines a developer as one who designs, codes, produces, or substantially modifies an AI system — so a materially retrained or fine-tuned model can bring you into scope even though you did not build the base model.

AB 1008 — CCPA rights can attach to the model itself

In effect since January 1, 2025 and routinely overlooked. AB 1008 confirms that personal information under the CCPA can exist in abstract digital formats, including an AI system capable of outputting personal information. Access, deletion, correction, and opt-out duties can therefore attach to a trained model, not only to the training dataset that produced it. This is a genuinely hard engineering problem and it is far cheaper to design around before you fine-tune on customer or patient data than to remediate afterward.

All California AI provisions, in full →

Reviewed against primary sources as of August 2, 2026.

How we help

What we do in San Francisco

Talk to us about AI governance in San Francisco

No pitch, no pressure. We will tell you what is actually in scope and what an assessor will accept.