AI Regulation Guide · California

California AI Laws: who's covered, what it requires

California AI Laws carries 20 tracked obligations for companies in scope. This guide lists who is covered, the duty tiers, and every obligation with its deadline and statutory citation — all from Shieldra's versioned regulation pack, verified 2026-09-08.

Who does California AI Laws apply to?

Out of scope only if: No California nexus reported. These laws reach AI and generative AI systems, chatbots, and bots made available to people in California (Civ. Code § 3110; Bus. & Prof. Code §§ 22757.1, 22601, 17940), employers with 5 or more employees and a California employee or applicant (2 CCR § 11008 et seq.), and businesses doing business in California that meet CCPA thresholds (Civ. Code § 1798.140).

Each California law carries its own gate; the branches evaluate independently, obligations stack across every matched law, and the tier shown is only the highest-priority headline. Watch: the 2026 session sent roughly 30 AI bills to the Governor with a 30 September 2026 deadline; SB 1000 (would remove SB 942's 1,000,000-user threshold), SB 1119 (companion-chatbot child safety), AB 1609 (customer-service chatbots at large businesses), and SB 947 (workplace ADS) would each change this screen if signed. Not modeled: AB 853's large-online-platform duties (2,000,000 monthly users, from 1 January 2027) and capture-device duties (from 1 January 2028).

  • What is your role for the AI systems you are screening?
  • Do you have a California nexus: an AI system, generative AI feature, chatbot, or bot available to people in California; any California employees or job applicants; or business in California involving California residents' personal information?
  • Do you design, code, produce, or substantially modify — 'substantial modification' expressly includes RETRAINING or FINE-TUNING, including of an open-source or third-party base model — a generative AI system or service made publicly available to Californians (including as a feature inside your product)?
  • Was that generative AI system or service released to the public on or after January 1, 2022 — or has it been substantially modified (retrained, fine-tuned, or materially changed in functionality or performance) on or after that date?
  • Is the generative AI system's SOLE purpose (a) helping ensure security and integrity, (b) the operation of aircraft in the national airspace, or (c) national security, military, or defense — available only to a federal entity?
  • Do you create, code, or otherwise produce a generative AI system that is publicly accessible within California AND has more than 1,000,000 monthly visitors or users?
  • Does that generative AI system create or alter image, audio, or video content (alone or in combination)?
  • Do you license and integrate someone else's covered generative AI system — one produced by a provider whose system has more than 1,000,000 monthly visitors or users — into your product or service?
  • Does any website or application you operate make the source code or model weights of a generative AI system available for DOWNLOAD by California residents?
  • Do you employ 5 or more people AND have at least one employee or job applicant located in California?
  • Do you — or any vendor acting on your behalf (ATS, recruiter, assessment or screening provider) — use a computational process (AI, machine learning, an algorithm, statistics, or other data processing) that makes a decision OR FACILITATES human decision-making about hiring, screening, promotion, pay, or any other employment benefit?
  • In the most recent calendar year, did your for-profit business doing business in California (a) exceed $26,625,000 in gross annual revenue, OR (b) buy, sell, or share the personal information of 100,000 or more California consumers or households, OR (c) derive 50% or more of annual revenue from selling or sharing personal information?
  • Do you use technology that processes personal information to make a 'significant decision' about a California consumer, employee, or job applicant — provision or denial of financial or lending services, housing, education enrollment or opportunity, employment or independent-contracting opportunities or compensation (including hiring, allocation of work, pay, promotion, demotion, suspension, or termination), or healthcare services — WITHOUT meaningful human involvement?
  • Do you TRAIN automated decisionmaking technology to make significant decisions about consumers, or train facial-recognition, emotion-assessment, or other identity-verification technology?
  • Do you make available to any user in California an AI chatbot with a natural-language interface that provides adaptive, human-like responses AND is capable of meeting a user's SOCIAL needs — for example an anthropomorphic persona that remembers the user personally and sustains a relationship across multiple sessions?
  • Is that chatbot used ONLY for customer service, your business's operational purposes, productivity and analysis related to source information, internal research, or technical assistance?
  • Can users you know to be minors interact with the companion chatbot?
  • Does any bot or automated online account you operate — where all or substantially all actions or posts are not the result of a person — communicate with people in California on a public-facing website or app in a way that could lead them to believe it is human, in connection with incentivizing a purchase or sale of goods or services or influencing a vote in an election?
  • Have you trained, or initiated the training of, a foundation model using more than 10^26 integer or floating-point operations of compute — a training run on the order of hundreds of millions of dollars, run by only a handful of frontier labs worldwide?

What are the duty tiers under California AI Laws?

At-scale genAI provider (SB 942 covered provider) (Bus. & Prof. Code §§ 22757.1–22757.3 (SB 942 as amended by AB 853))

Citation: Bus. & Prof. Code §§ 22757.1–22757.3 (SB 942 as amended by AB 853) — https://leginfo.legislature.ca.gov/faces/codes_displaySection.xhtml?lawCode=BPC&sectionNum=22757.1.

The 1,000,000 count is of the generative AI system's monthly visitors or users, and the duties attach to image, audio, and video content. AB 853 (Stats. 2025 ch. 674) moved the operative date from 1 January 2026 to 2 August 2026. Penalties: $5,000 per violation, with each day a covered provider is in violation deemed a discrete violation; the AG, city attorneys, and county counsel enforce; no private right of action, no cure period. AB 2013 training-data duties stack on top for the same system.

Companion chatbot operator (SB 243) (Bus. & Prof. Code §§ 22601–22606 (SB 243))

Citation: Bus. & Prof. Code §§ 22601–22606 (SB 243) — https://leginfo.legislature.ca.gov/faces/billTextClient.xhtml?bill_id=202520260SB243

No size, revenue, or user threshold — in force since 1 January 2026. Enforcement is a private right of action (§ 22605): injunctive relief, the GREATER of actual damages or $1,000 per violation, plus attorney's fees and costs — a plaintiff-side magnet for anything companion-shaped. Ordinary customer-service, productivity, and technical-assistance bots are excluded by definition.

GenAI developer or fine-tuner (AB 2013) (Cal. Civ. Code §§ 3110–3111 (AB 2013))

Citation: Cal. Civ. Code §§ 3110–3111 (AB 2013) — https://leginfo.legislature.ca.gov/faces/codes_displaySection.xhtml?lawCode=CIV&sectionNum=3110.

No size, revenue, or user threshold — fine-tuning an open or third-party base model for a publicly available feature is enough (§ 3110(d)). Purely calling a third-party genAI API without retraining or fine-tuning is likely outside 'developer', but the boundary is unsettled and the AG has issued no guidance. xAI v. Bonta did not suspend the law: the preliminary injunction was denied in early March 2026 (order dated 5 March 2026) and no stay is in place.

Employer using automated-decision systems (FEHA ADS) (Cal. Code Regs. tit. 2, § 11008 et seq. (Civil Rights Council ADS regulations))

Citation: Cal. Code Regs. tit. 2, § 11008 et seq. (Civil Rights Council ADS regulations) — https://www.mayerbrown.com/en/insights/publications/2025/08/california-adopts-new-employment-ai-regulations-effective-october-1-2025

In force since 1 October 2025 with no phase-in. Disparate impact suffices — there is no intent element — and sourcing the tool from a vendor is not a defense; vendors acting as your 'agents' expose you. Enforcement is ordinary FEHA: Civil Rights Department process plus private civil actions after a right-to-sue letter, with compensatory and punitive damages, attorney's fees, and injunctive relief. Evidence of anti-bias testing (its quality, scope, recency, results, and your response) is expressly weighable on both sides of a claim.

CCPA business using ADMT for significant decisions (Cal. Code Regs. tit. 11, §§ 7001, 7220–7222 (CPPA ADMT regulations))

Citation: Cal. Code Regs. tit. 11, §§ 7001, 7220–7222 (CPPA ADMT regulations) — https://cppa.ca.gov/regulations/ccpa_updates.html

Only CCPA 'businesses' are bound — below the thresholds there are zero ADMT duties. The regulations are in force since 1 January 2026 and ADMT compliance applies from 1 January 2027; risk-assessment and audit calendars run to 2028–2030. The human-in-the-loop exit is real: a reviewer who can interpret, analyze, and change the decision takes the tool out of ADMT entirely. CPPA administrative enforcement plus AG civil penalties (up to ~$2,663 per violation, ~$7,988 intentional or involving minors); cure is discretionary; no private right of action for ADMT violations.

SB 942 edge duties (licensee / weight hosting) (Bus. & Prof. Code §§ 22757.3(c), 22757.3.2, 22757.4 (SB 942 as amended by AB 853))

Citation: Bus. & Prof. Code §§ 22757.3(c), 22757.3.2, 22757.4 (SB 942 as amended by AB 853) — https://leginfo.legislature.ca.gov/faces/codes_displaySection.xhtml?lawCode=BPC&sectionNum=22757.3.

The two threshold-free SB 942 duties that can land on an SMB, both applying from 2 August 2026: a licensee of a covered provider's system must not disable its disclosure capability (the provider must revoke the licence within 96 hours of discovery, and use after revocation carries direct liability under § 22757.4 — injunctive relief plus the attorney's fees of the public enforcer — the AG, a city attorney, or county counsel; there is no private right of action), and a site or app making genAI model weights or source code downloadable by California residents may not knowingly host non-disclosure-compliant systems. Split operative dates: licensee duty in force since 2 August 2026; hosting-platform gate applies from 1 January 2027 (BPC § 22757.3.2).

Commercial bot operator (BOT Act) (Bus. & Prof. Code §§ 17940–17942 (BOT Act, SB 1001))

Citation: Bus. & Prof. Code §§ 17940–17942 (BOT Act, SB 1001) — https://leginfo.legislature.ca.gov/faces/codes_displaySection.xhtml?sectionNum=17940&lawCode=BPC

In force since 1 July 2019. The prohibition carries a stacked intent element — intent to mislead about artificial identity in order to incentivize a purchase or sale or influence a vote — and a clear, conspicuous bot disclosure is a complete safe harbor. No statutory penalty of its own; enforced in practice by public prosecutors through the UCL (up to $2,500 per violation).

In scope — no current duties from these laws (California AI laws survey (Civ. Code §§ 3110–3111; Bus. & Prof. Code §§ 17940–17943, 22601–22606, 22757–22757.6, 22757.10–22757.16; 2 CCR § 11008 et seq.; 11 CCR §§ 7001–7222))

Citation: California AI laws survey (Civ. Code §§ 3110–3111; Bus. & Prof. Code §§ 17940–17943, 22601–22606, 22757–22757.6, 22757.10–22757.16; 2 CCR § 11008 et seq.; 11 CCR §§ 7001–7222) — https://www.wiley.law/alert-California-Closes-Legislative-Session-with-Significant-AI-and-Privacy-Developments

No current obligations from the screened California laws. SB 53 (TFAIA) imposes zero duties below 10^26 FLOPs of training compute regardless of company size. Re-screen if: you start retraining or fine-tuning a genAI model (AB 2013 attaches immediately), a genAI system you produce approaches 1,000,000 monthly users (SB 942), you cross a CCPA threshold (ADMT compliance applies from 1 January 2027), or you ship a companion-style persona (SB 243). Watchlist (Governor's action deadline 30 September 2026 — re-verify in October 2026): SB 947 ('No Robo Bosses Act of 2026', enrolled 4 September 2026, operative 1 July 2027 if signed) would bar sole reliance on an automated-decision system for discipline or termination; SB 1000 (urgency bill) would delete SB 942's 1,000,000-monthly-user threshold so every publicly accessible generative-AI provider becomes a covered provider; SB 1119 ('Adam's Law') would add child-safety duties for companion chatbots from 1 July 2027; AB 1609 would require customer-service chatbots at businesses over $500M revenue to disclose AI status and offer a human agent. AB 1018 died at the 31 August 2026 house-of-origin deadline.

What are the obligations and deadlines under California AI Laws?

ObligationWhoDeadlineCitation
Post the 12-element training-data disclosure before public availabilitydeveloper, deployerin force since 1 January 2026Cal. Civ. Code § 3111(a) (AB 2013) — https://leginfo.legislature.ca.gov/faces/codes_displaySection.xhtml?lawCode=CIV&sectionNum=3111.
Refresh the training-data disclosure on every substantial modificationdeveloper, deployerin force since 1 January 2026Cal. Civ. Code §§ 3110(d), 3111(a) (AB 2013) — https://leginfo.legislature.ca.gov/faces/codes_displaySection.xhtml?lawCode=CIV&sectionNum=3110.
Covered provider: provide a free public AI detection tooldeveloper, deployerin force since 2 August 2026Bus. & Prof. Code § 22757.2 (SB 942 as amended by AB 853) — https://leginfo.legislature.ca.gov/faces/codes_displaySection.xhtml?lawCode=BPC&sectionNum=22757.2.
Covered provider: embed latent disclosures and offer a manifest disclosure optiondeveloper, deployerin force since 2 August 2026Bus. & Prof. Code § 22757.3(a)–(b) (SB 942 as amended by AB 853) — https://leginfo.legislature.ca.gov/faces/codes_displaySection.xhtml?lawCode=BPC&sectionNum=22757.3.
Covered provider: bind licensees to preserve disclosures and revoke within 96 hoursdeveloper, deployerin force since 2 August 2026Bus. & Prof. Code § 22757.3(c) (SB 942 as amended by AB 853) — https://leginfo.legislature.ca.gov/faces/codes_displaySection.xhtml?lawCode=BPC&sectionNum=22757.3.
Licensee: do not disable the licensed system's disclosure capabilitydeveloper, deployerin force since 2 August 2026Bus. & Prof. Code §§ 22757.3(c)(3), 22757.4 (SB 942 as amended by AB 853) — https://leginfo.legislature.ca.gov/faces/codes_displaySection.xhtml?lawCode=BPC&sectionNum=22757.3.
GenAI hosting platform: do not host non-compliant downloadable systemsdeveloper, deployerapplies from 1 January 2027 (BPC § 22757.3.2 operative date)Bus. & Prof. Code § 22757.3.2 (AB 853) — https://leginfo.legislature.ca.gov/faces/codes_displaySection.xhtml?lawCode=BPC&sectionNum=22757.3.2.
Assess employment ADS for discrimination and document anti-bias testingdeveloper, deployerin force since 1 October 20252 CCR §§ 11008.1, 11009(f) — https://www.mayerbrown.com/en/insights/publications/2025/08/california-adopts-new-employment-ai-regulations-effective-october-1-2025
Retain ADS data and employment records for four yearsdeveloper, deployerin force since 1 October 2025Cal. Code Regs. tit. 2, § 11013(c) — https://www.mayerbrown.com/en/insights/publications/2025/08/california-adopts-new-employment-ai-regulations-effective-october-1-2025
Treat ATS and screening vendors as your FEHA agentsdeveloper, deployerin force since 1 October 2025Cal. Code Regs. tit. 2, §§ 11008–11008.1 ('agent' and ADS definitions) — https://www.mayerbrown.com/en/insights/publications/2025/08/california-adopts-new-employment-ai-regulations-effective-october-1-2025
Screen ADS assessments for medical-inquiry and disability exposuredeveloper, deployerin force since 1 October 20252 CCR §§ 11008.1, 11016, 11071(e) — https://www.mayerbrown.com/en/insights/publications/2025/08/california-adopts-new-employment-ai-regulations-effective-october-1-2025
Deliver the ADMT pre-use noticedeveloper, deployerapplies from 1 January 2027Cal. Code Regs. tit. 11, § 7220 — https://cppa.ca.gov/regulations/ccpa_updates.html
Build the ADMT opt-out or qualify for an exceptiondeveloper, deployerapplies from 1 January 2027Cal. Code Regs. tit. 11, § 7221 — https://cppa.ca.gov/regulations/ccpa_updates.html
Answer ADMT access requestsdeveloper, deployerapplies from 1 January 2027Cal. Code Regs. tit. 11, § 7222 — https://cppa.ca.gov/regulations/ccpa_updates.html
Complete risk assessments before high-risk processing and calendar CPPA filingsdeveloper, deployerin force since 1 January 2026 (pre-2026 processing must be assessed by 31 December 2027; first CPPA attestation due 1 April 2028)Cal. Code Regs. tit. 11, § 7150 et seq. (risk assessments); §§ 7120–7124 (cybersecurity audits) — https://cppa.ca.gov/regulations/ccpa_updates.html
Companion chatbot: disclose AI status clearly and conspicuouslydeveloper, deployerin force since 1 January 2026Bus. & Prof. Code §§ 22601–22606 (SB 243) — https://leginfo.legislature.ca.gov/faces/billTextClient.xhtml?bill_id=202520260SB243
Companion chatbot: maintain and publish the self-harm crisis protocoldeveloper, deployerin force since 1 January 2026Bus. & Prof. Code §§ 22601–22606 (SB 243) — https://leginfo.legislature.ca.gov/faces/billTextClient.xhtml?bill_id=202520260SB243
Companion chatbot: implement the known-minor protectionsdeveloper, deployerin force since 1 January 2026Bus. & Prof. Code §§ 22601–22606 (SB 243) — https://leginfo.legislature.ca.gov/faces/billTextClient.xhtml?bill_id=202520260SB243
Label commercial bots as automated (BOT Act safe harbor)developer, deployerin force since 1 July 2019Bus. & Prof. Code §§ 17940–17941 (BOT Act, SB 1001) — https://leginfo.legislature.ca.gov/faces/codes_displaySection.xhtml?sectionNum=17941&lawCode=BPC
Frontier developer: transparency reports and Cal OES incident reportingdeveloper, deployerin force since 1 January 2026Bus. & Prof. Code §§ 22757.12, 22757.13, 22757.15 (SB 53 TFAIA) — https://leginfo.legislature.ca.gov/faces/codes_displaySection.xhtml?lawCode=BPC&sectionNum=22757.12.

What should you do about each obligation?

Post the 12-element training-data disclosure before public availability (Cal. Civ. Code § 3111(a) (AB 2013))

Post on your website, before the generative AI system or service is made publicly available to Californians, a high-level summary of ALL datasets used in its development (including training, testing, validation, and fine-tuning) covering the 12 statutory elements: dataset sources or owners; how the datasets further the intended purpose; number of data points (general ranges acceptable); data types and labels; whether the data includes copyrighted, trademarked, or patented material or is wholly public domain; whether purchased or licensed; whether it includes personal information and whether it includes aggregate consumer information (CCPA definitions); cleaning, processing, or modification done and why; the collection period (with notice if collection is ongoing); the dates the datasets were first used; and whether synthetic data generation was used. Systems released on or after 1 January 2022 owed the posting on or before 1 January 2026. AB 2013 has no enforcement section of its own; failure to post is actionable as an 'unlawful' practice under the UCL (B&P Code § 17200) — civil penalties up to $2,500 per violation via the AG, district attorneys, or city attorneys, with no cure period; private plaintiffs with UCL standing can seek injunctive relief or restitution but not penalties (the $5,000-per-day figure some sources cite belongs to SB 942, not AB 2013).

Refresh the training-data disclosure on every substantial modification (Cal. Civ. Code §§ 3110(d), 3111(a) (AB 2013))

Re-publish the training-data disclosure each time the system is substantially modified — a new version, release, or update that materially changes functionality or performance, expressly including retraining or fine-tuning (§ 3110(d)). Build the refresh into your model-release checklist so every fine-tuning run that ships re-triggers the posting, and version and date each disclosure so a regulator can match releases to postings.

Covered provider: provide a free public AI detection tool (Bus. & Prof. Code § 22757.2 (SB 942 as amended by AB 853))

Make available a FREE, publicly accessible AI detection tool that assesses whether image, video, or audio content was created or altered by your generative AI system. It must output system provenance data (never personal provenance data), support content uploads or URLs plus API access, and collect user feedback, with strict limits on retaining users' content and personal information. Exposure: $5,000 per violation, and each day a covered provider is in violation is deemed a discrete violation — $5,000 per day, compounding — enforced by the Attorney General, city attorneys, or county counsel; no private right of action, no cure period.

Covered provider: embed latent disclosures and offer a manifest disclosure option (Bus. & Prof. Code § 22757.3(a)–(b) (SB 942 as amended by AB 853))

Embed a mandatory LATENT disclosure in AI-generated or AI-altered image, video, and audio content conveying your name, the system's name and version, the creation or alteration timestamp, and a unique identifier — detectable by your own detection tool, consistent with widely adopted industry standards, and permanent or extraordinarily difficult to remove to the extent technically feasible (§ 22757.3(b)). Separately, OFFER users the option of a manifest disclosure identifying content as AI-generated that is clear, conspicuous, appropriate to the medium, and permanent or extraordinarily difficult to remove (§ 22757.3(a)). Same $5,000-per-violation-per-day exposure as the detection tool; no private right of action, no cure period.

Covered provider: bind licensees to preserve disclosures and revoke within 96 hours (Bus. & Prof. Code § 22757.3(c) (SB 942 as amended by AB 853))

If you license your covered generative AI system to third parties, contractually require each licensee to maintain the system's disclosure capability. If you discover a licensee has disabled it, you must revoke the licence within 96 hours, and the licensee must cease using the system on revocation. Build capability-monitoring and revocation mechanics into licence agreements before the duty attaches — the 96-hour clock runs from discovery.

Licensee: do not disable the licensed system's disclosure capability (Bus. & Prof. Code §§ 22757.3(c)(3), 22757.4 (SB 942 as amended by AB 853))

Do not disable, strip, or bypass the licensed covered system's built-in AI-disclosure capability when integrating it, and verify in integration testing that provenance disclosures survive your rendering and processing pipeline. If the provider discovers the capability was disabled it must revoke your licence within 96 hours, you must cease using the system after revocation, and continued use violates § 22757.3(c)(3) with direct liability — injunctive relief plus the enforcing public prosecutor's attorney's fees and costs (§ 22757.4; only the AG, a city attorney, or county counsel may sue — no private right of action). This duty has no size threshold on the licensee side.

GenAI hosting platform: do not host non-compliant downloadable systems (Bus. & Prof. Code § 22757.3.2 (AB 853))

If a website or application you operate makes the source code or model weights of a generative AI system available for download by California residents, you are a 'GenAI hosting platform' with no size threshold: do not knowingly make available for download a generative AI system that does not place the § 22757.3 disclosures. Before hosting weights or source, verify the system's disclosure posture or gate the download. Exposure: $5,000 civil penalty per violation, enforced by the AG, city attorneys, or county counsel (the per-day deeming clause names covered providers, large online platforms, and capture-device manufacturers).

Assess employment ADS for discrimination and document anti-bias testing (2 CCR §§ 11008.1, 11009(f))

It is unlawful to use an automated-decision system — or selection criteria run through one — that discriminates against applicants or employees on a FEHA protected basis, whether by disparate treatment or disparate IMPACT; there is no intent element, and sourcing the tool from a third party is not a defense. Assess every employment ADS for discriminatory impact before and during use, and document anti-bias testing or similar proactive efforts: the regulations make the testing's quality, scope, recency, results, and your response expressly relevant evidence in defending — or proving — a claim. Exposure is ordinary FEHA enforcement: Civil Rights Department process plus private civil actions after a right-to-sue letter, with compensatory and punitive damages, attorney's fees, and injunctive relief, and no cure period.

Retain ADS data and employment records for four years (Cal. Code Regs. tit. 2, § 11013(c))

Retain for at least FOUR years (extended from two): applications, personnel records, selection criteria, and 'automated-decision system data' — any data used in or resulting from the ADS, including inputs and decision outcomes — measured from the later of record creation or the personnel action. Confirm your ATS and assessment vendors can actually export and preserve ADS inputs and outputs for the full period; a vendor's retention gap is your compliance gap.

Treat ATS and screening vendors as your FEHA agents (Cal. Code Regs. tit. 2, §§ 11008–11008.1 ('agent' and ADS definitions))

Anyone acting on your behalf to exercise a traditional employer function — recruitment, screening, hiring, promotion, or pay decisions — including in whole or in part through an automated-decision system, is your FEHA 'agent', and their tools create your exposure. Contract with ATS, assessment, and screening vendors for bias-testing documentation, ADS-data retention and export support, and accommodation workarounds, and keep the diligence file current. This includes AI features embedded in mainstream ATS products, not just standalone AI hiring tools.

Screen ADS assessments for medical-inquiry and disability exposure (2 CCR §§ 11008.1, 11016, 11071(e))

Review ADS-delivered assessments — personality tests, puzzles and games, reaction-time measures, and facial-expression, voice, or word-choice analysis in video interviews — for whether they elicit disability information and so function as unlawful medical or psychological inquiries; personality and reaction-time assessments are expressly flagged as disability-discrimination risks. Provide reasonable-accommodation paths around ADS screens, and apply existing FEHA limits (criminal-history individualized assessment, pre-employment inquiry rules) equally when executed through an ADS.

Deliver the ADMT pre-use notice (Cal. Code Regs. tit. 11, § 7220)

Before using ADMT for a significant decision, deliver a pre-use notice covering the purpose; how the ADMT works (categories of personal information used, its outputs, and how outputs are used in the decision); the opt-out method; and the alternative decision process if the consumer opts out. A business already using ADMT for significant decisions before 1 January 2027 must be fully compliant by that date — start now. Enforcement: CPPA administrative enforcement plus AG civil penalties under the CCPA (up to ~$2,663 per violation, ~$7,988 if intentional or involving minors, inflation-adjusted); cure is a discretionary consideration, not a right; no private right of action for ADMT violations.

Build the ADMT opt-out or qualify for an exception (Cal. Code Regs. tit. 11, § 7221)

Offer consumers an opt-out from ADMT used for significant decisions, or document that a § 7221 exception applies: (1) an appeal path to a qualified human reviewer with authority to overturn the decision; (2) for admission, acceptance, hiring, allocation-of-work, or compensation decisions — ADMT used solely to assess ability to perform, with documented steps ensuring it works as intended and does not unlawfully discriminate; or (3) security, fraud-prevention, or safety uses. Decide the path per decision type and keep the analysis with your risk assessment.

Answer ADMT access requests (Cal. Code Regs. tit. 11, § 7222)

On request, disclose the specific purpose of the ADMT, the logic used and how outputs were generated, the output itself and how it was used in the decision, and planned future use. Build ADMT access requests into your existing CCPA request workflow — and remember the CCPA reaches employees and job applicants, so HR must be able to answer these too.

Complete risk assessments before high-risk processing and calendar CPPA filings (Cal. Code Regs. tit. 11, § 7150 et seq. (risk assessments); §§ 7120–7124 (cybersecurity audits))

Conduct and document a risk assessment BEFORE initiating high-risk processing — the triggers include using ADMT for significant decisions and TRAINING such ADMT (or facial/emotion/identity recognition). Processing already underway before 1 January 2026 must be assessed by 31 December 2027, and the first attestation with summary information is due to the CPPA by 1 April 2028 (covering 2026–2027), then annually each 1 April. Separately, annual cybersecurity audits phase in for businesses meeting the audit triggers — first audits due 1 April 2028 (over $100M revenue), 1 April 2029 ($50–100M), or 1 April 2030 (under $50M) — so confirm your audit-trigger status with counsel and calendar the applicable date.

Companion chatbot: disclose AI status clearly and conspicuously (Bus. & Prof. Code §§ 22601–22606 (SB 243))

If a reasonable person interacting with your companion chatbot could be misled into believing they are talking with a human, issue a clear and conspicuous notification that the chatbot is artificially generated and not human. Also disclose that companion chatbots may not be suitable for some minors. Exposure is a private right of action (§ 22605): any person injured by noncompliance may sue for injunctive relief, the GREATER of actual damages or $1,000 per violation, and reasonable attorney's fees and costs — no agency gatekeeper, no cure period.

Companion chatbot: maintain and publish the self-harm crisis protocol (Bus. & Prof. Code §§ 22601–22606 (SB 243))

Do not let the companion chatbot engage with users unless you maintain — and PUBLISH on your website — a protocol for preventing the production of suicidal-ideation, suicide, or self-harm content, including referral to crisis services (such as a 988-type hotline) when a user expresses suicidal ideation, and use evidence-based methods for measuring suicidal ideation. Beginning 1 July 2027, file the annual report to the Office of Suicide Prevention on crisis-referral notifications issued and your detection, removal, and response protocols (published in de-identified aggregate). The § 22605 private right of action applies: the greater of actual damages or $1,000 per violation, plus fees.

Companion chatbot: implement the known-minor protections (Bus. & Prof. Code §§ 22601–22606 (SB 243))

For users you know are minors: disclose that the user is interacting with AI; provide a clear and conspicuous notification at least every 3 hours of continuing interaction reminding the user to take a break and that the chatbot is AI; and institute reasonable measures preventing the chatbot from producing sexually explicit content or directing sexual statements at the minor. Design your age-signal handling deliberately — these duties turn on users the operator KNOWS are minors, so document what your product knows and when.

Label commercial bots as automated (BOT Act safe harbor) (Bus. & Prof. Code §§ 17940–17941 (BOT Act, SB 1001))

Give the bot a disclosure that is clear, conspicuous, and reasonably designed to inform the counterparty that it is a bot (for example, 'I'm an AI assistant') — that disclosure is a complete safe harbor from § 17941 liability. The prohibition itself requires a stacked intent showing (intent to mislead about artificial identity, to knowingly deceive about the communication's content, in order to incentivize a purchase or sale or influence a vote), so an undisclosed bot is not per se unlawful — but the one-line label removes the question entirely. The chapter has no penalty of its own; public prosecutors enforce through the UCL (up to $2,500 per violation), § 17942(c) places no duties on hosting/ISP service providers, and the 10,000,000-visitor 'online platform' threshold does not exempt bot operators on small sites.

Frontier developer: transparency reports and Cal OES incident reporting (Bus. & Prof. Code §§ 22757.12, 22757.13, 22757.15 (SB 53 TFAIA))

As a frontier developer (you trained, or initiated the training of, a foundation model using more than 10^26 operations of compute): publish a transparency report before or with deploying a new or substantially modified frontier model (website, contact mechanism, release date, languages, modalities, intended uses, restrictions — trade-secret, cybersecurity, public-safety, and national-security redactions permitted), and report critical safety incidents to the California Office of Emergency Services within 15 days of discovery — within 24 hours to an appropriate authority if the incident poses imminent risk of death or serious injury. Large frontier developers (over $500,000,000 annual gross revenue with affiliates) must additionally write, implement, publish, and annually review a frontier AI framework and send quarterly confidential catastrophic-risk summaries to Cal OES, and no frontier developer may make materially false or misleading statements about catastrophic risk or its own framework compliance. Penalties: § 22757.15 imposes up to $1,000,000 per violation, scaled to severity, on LARGE frontier developers only (>$500M group revenue), recoverable in a civil action brought only by the Attorney General; no private right of action, no cure period. The statute prescribes no civil penalty for frontier developers below the $500M revenue tier. If you have not crossed the compute threshold, SB 53 imposes no duties on you.

Disclaimer

Compliance guidance, not legal advice. Confirm obligations with counsel. Content version 2026.09.08-1, verified 2026-09-08.

Frequently asked questions

Who does California AI Laws apply to?

No California nexus reported. These laws reach AI and generative AI systems, chatbots, and bots made available to people in California (Civ. Code § 3110; Bus. & Prof. Code §§ 22757.1, 22601, 17940), employers with 5 or more employees and a California employee or applicant (2 CCR § 11008 et seq.), and businesses doing business in California that meet CCPA thresholds (Civ. Code § 1798.140). Coverage turns on the screening questions listed on this page — each obligation then applies its own statutory gate.

When does California AI Laws take effect?

in force since 1 January 2026. in force since 2 August 2026. applies from 1 January 2027 (BPC § 22757.3.2 operative date). in force since 1 October 2025. applies from 1 January 2027. in force since 1 January 2026 (pre-2026 processing must be assessed by 31 December 2027; first CPPA attestation due 1 April 2028). in force since 1 July 2019

What are the obligations under California AI Laws?

Post the 12-element training-data disclosure before public availability; Refresh the training-data disclosure on every substantial modification; Covered provider: provide a free public AI detection tool; Covered provider: embed latent disclosures and offer a manifest disclosure option; Covered provider: bind licensees to preserve disclosures and revoke within 96 hours; Licensee: do not disable the licensed system's disclosure capability; GenAI hosting platform: do not host non-compliant downloadable systems; Assess employment ADS for discrimination and document anti-bias testing; Retain ADS data and employment records for four years; Treat ATS and screening vendors as your FEHA agents; Screen ADS assessments for medical-inquiry and disability exposure; Deliver the ADMT pre-use notice; Build the ADMT opt-out or qualify for an exception; Answer ADMT access requests; Complete risk assessments before high-risk processing and calendar CPPA filings; Companion chatbot: disclose AI status clearly and conspicuously; Companion chatbot: maintain and publish the self-harm crisis protocol; Companion chatbot: implement the known-minor protections; Label commercial bots as automated (BOT Act safe harbor); Frontier developer: transparency reports and Cal OES incident reporting.