California lawmakers used an Aug. 10 Assembly hearing to press frontier AI developers and policy experts on whether fast-moving AI systems are making cyberattacks easier to carry out — and whether the state’s new reporting rules are being followed.
The hearing, held by the Assembly Select Committee on Cybersecurity and the Assembly Privacy and Consumer Protection Committee, focused on frontier AI cybersecurity risks, model evaluations and proposed safeguards for public safety, according to the hearing summary and transcript. Witnesses described AI systems that can help automate scanning, credential theft, ransomware workflows and other attack techniques, while also improving defensive tasks such as vulnerability scanning, patching and incident response.
One speaker pointed to a 27-year-old OpenBSD vulnerability and a one-line bug in video software that automated testing had missed millions of times, arguing that the gap between finding and exploiting weaknesses is shrinking. Another said agentic systems can gather information, use software tools, test code and carry out attacks with less human direction, lowering the time, expertise and cost needed for cybercrime.
Policy discussion centered on SB 53 and related reporting requirements. The hearing summary says one legislator questioned whether any company is actually complying with SB 53, while another speaker urged lawmakers to use enforceable pressure points rather than rely on voluntary commitments. Witnesses also discussed a reporting framework in which large frontier developers could confidentially submit reports and quarterly summaries of catastrophic-risk assessments.
The hearing transcript also referenced evaluation and containment practices, including cybersecurity testing before release, outside review, isolation and network controls for model testing, and safeguards on public releases. Speakers cited a model that was evaluated by the UK AI Security Institute before being released publicly as Fable 5, and described partnerships with the California Department of Technology, Cal OES, MSISAC and Lawrence Livermore to use AI for scanning, patching and other cyber-defense work.
The hearing summary does not identify which lawmakers asked the SB 53 compliance questions, and the available material does not show any formal committee action afterward.










