California AI Laws carries 20 tracked obligations for companies in scope. This guide lists who is covered, the duty tiers, and every obligation with its deadline and statutory citation — all from Shieldra's versioned regulation pack, verified 2026-07-29.
What are the duty tiers under California AI Laws?
At-scale genAI provider (SB 942 covered provider) (Bus. & Prof. Code §§ 22757.1–22757.3 (SB 942 as amended by AB 853))
Citation: Bus. & Prof. Code §§ 22757.1–22757.3 (SB 942 as amended by AB 853) — https://leginfo.legislature.ca.gov/faces/codes_displaySection.xhtml?lawCode=BPC§ionNum=22757.1.
The 1,000,000 count is of the generative AI system's monthly visitors or users, and the duties attach to image, audio, and video content. AB 853 (Stats. 2025 ch. 674) moved the operative date from 1 January 2026 to 2 August 2026. Penalties: $5,000 per violation, with each day a covered provider is in violation deemed a discrete violation; the AG, city attorneys, and county counsel enforce; no private right of action, no cure period. AB 2013 training-data duties stack on top for the same system.
Companion chatbot operator (SB 243) (Bus. & Prof. Code §§ 22601–22606 (SB 243))
Citation: Bus. & Prof. Code §§ 22601–22606 (SB 243) — https://leginfo.legislature.ca.gov/faces/billTextClient.xhtml?bill_id=202520260SB243
No size, revenue, or user threshold — in force since 1 January 2026. Enforcement is a private right of action (§ 22605): injunctive relief, the GREATER of actual damages or $1,000 per violation, plus attorney's fees and costs — a plaintiff-side magnet for anything companion-shaped. Ordinary customer-service, productivity, and technical-assistance bots are excluded by definition.
GenAI developer or fine-tuner (AB 2013) (Cal. Civ. Code §§ 3110–3111 (AB 2013))
Citation: Cal. Civ. Code §§ 3110–3111 (AB 2013) — https://leginfo.legislature.ca.gov/faces/codes_displaySection.xhtml?lawCode=CIV§ionNum=3110.
No size, revenue, or user threshold — fine-tuning an open or third-party base model for a publicly available feature is enough (§ 3110(d)). Purely calling a third-party genAI API without retraining or fine-tuning is likely outside 'developer', but the boundary is unsettled and the AG has issued no guidance. xAI v. Bonta did not suspend the law: the preliminary injunction was denied 4 March 2026 and no stay is in place.
Employer using automated-decision systems (FEHA ADS) (Cal. Code Regs. tit. 2, § 11008 et seq. (Civil Rights Council ADS regulations))
Citation: Cal. Code Regs. tit. 2, § 11008 et seq. (Civil Rights Council ADS regulations) — https://www.mayerbrown.com/en/insights/publications/2025/08/california-adopts-new-employment-ai-regulations-effective-october-1-2025
In force since 1 October 2025 with no phase-in. Disparate impact suffices — there is no intent element — and sourcing the tool from a vendor is not a defense; vendors acting as your 'agents' expose you. Enforcement is ordinary FEHA: Civil Rights Department process plus private civil actions after a right-to-sue letter, with compensatory and punitive damages, attorney's fees, and injunctive relief. Evidence of anti-bias testing (its quality, scope, recency, results, and your response) is expressly weighable on both sides of a claim.
CCPA business using ADMT for significant decisions (Cal. Code Regs. tit. 11, §§ 7001, 7220–7222 (CPPA ADMT regulations))
Citation: Cal. Code Regs. tit. 11, §§ 7001, 7220–7222 (CPPA ADMT regulations) — https://cppa.ca.gov/regulations/ccpa_updates.html
Only CCPA 'businesses' are bound — below the thresholds there are zero ADMT duties. The regulations are in force since 1 January 2026 and ADMT compliance applies from 1 January 2027; risk-assessment and audit calendars run to 2028–2030. The human-in-the-loop exit is real: a reviewer who can interpret, analyze, and change the decision takes the tool out of ADMT entirely. CPPA administrative enforcement plus AG civil penalties (up to ~$2,663 per violation, ~$7,988 intentional or involving minors); cure is discretionary; no private right of action for ADMT violations.
SB 942 edge duties (licensee / weight hosting) (Bus. & Prof. Code §§ 22757.3(c), 22757.3.2, 22757.4 (SB 942 as amended by AB 853))
Citation: Bus. & Prof. Code §§ 22757.3(c), 22757.3.2, 22757.4 (SB 942 as amended by AB 853) — https://leginfo.legislature.ca.gov/faces/codes_displaySection.xhtml?lawCode=BPC§ionNum=22757.3.
The two threshold-free SB 942 duties that can land on an SMB, both applying from 2 August 2026: a licensee of a covered provider's system must not disable its disclosure capability (the provider must revoke the licence within 96 hours of discovery, and use after revocation carries direct liability under § 22757.4 — injunctive relief plus the plaintiff's attorney's fees), and a site or app making genAI model weights or source code downloadable by California residents may not knowingly host non-disclosure-compliant systems. Split operative dates: licensee duty applies from 2 August 2026; hosting-platform gate applies from 1 January 2027 (BPC § 22757.3.2).
Commercial bot operator (BOT Act) (Bus. & Prof. Code §§ 17940–17942 (BOT Act, SB 1001))
Citation: Bus. & Prof. Code §§ 17940–17942 (BOT Act, SB 1001) — https://leginfo.legislature.ca.gov/faces/codes_displaySection.xhtml?sectionNum=17940&lawCode=BPC
In force since 1 July 2019. The prohibition carries a stacked intent element — intent to mislead about artificial identity in order to incentivize a purchase or sale or influence a vote — and a clear, conspicuous bot disclosure is a complete safe harbor. No statutory penalty of its own; enforced in practice by public prosecutors through the UCL (up to $2,500 per violation).
In scope — no current duties from these laws (California AI laws survey (Civ. Code §§ 3110–3111; Bus. & Prof. Code §§ 17940–17943, 22601–22606, 22757–22757.6, 22757.10–22757.16; 2 CCR § 11008 et seq.; 11 CCR §§ 7001–7222))
Citation: California AI laws survey (Civ. Code §§ 3110–3111; Bus. & Prof. Code §§ 17940–17943, 22601–22606, 22757–22757.6, 22757.10–22757.16; 2 CCR § 11008 et seq.; 11 CCR §§ 7001–7222) — https://www.cooley.com/news/insight/2026/2026-04-24-state-ai-laws-where-are-they-now
No current obligations from the screened California laws. SB 53 (TFAIA) imposes zero duties below 10^26 FLOPs of training compute regardless of company size. Re-screen if: you start retraining or fine-tuning a genAI model (AB 2013 attaches immediately), a genAI system you produce approaches 1,000,000 monthly users (SB 942), you cross a CCPA threshold (ADMT compliance applies from 1 January 2027), or you ship a companion-style persona (SB 243). Watchlist: SB 947 ('No Robo Bosses Act of 2026') was in Assembly Appropriations as of 2 July 2026 with a 30 September 2026 governor-action deadline — re-verify in October 2026; AB 1018 remains on the Senate inactive file.
What should you do about each obligation?
Post the 12-element training-data disclosure before public availability (Cal. Civ. Code § 3111(a) (AB 2013))
Post on your website, before the generative AI system or service is made publicly available to Californians, a high-level summary of ALL datasets used in its development (including training, testing, validation, and fine-tuning) covering the 12 statutory elements: dataset sources or owners; how the datasets further the intended purpose; number of data points (general ranges acceptable); data types and labels; whether the data includes copyrighted, trademarked, or patented material or is wholly public domain; whether purchased or licensed; whether it includes personal information and whether it includes aggregate consumer information (CCPA definitions); cleaning, processing, or modification done and why; the collection period (with notice if collection is ongoing); the dates the datasets were first used; and whether synthetic data generation was used. Systems released on or after 1 January 2022 owed the posting on or before 1 January 2026. AB 2013 has no enforcement section of its own; failure to post is actionable as an 'unlawful' practice under the UCL (B&P Code § 17200) — civil penalties up to $2,500 per violation via the AG, district attorneys, or city attorneys, with no cure period (the $5,000-per-day figure some sources cite belongs to SB 942, not AB 2013).
Refresh the training-data disclosure on every substantial modification (Cal. Civ. Code §§ 3110(d), 3111(a) (AB 2013))
Re-publish the training-data disclosure each time the system is substantially modified — a new version, release, or update that materially changes functionality or performance, expressly including retraining or fine-tuning (§ 3110(d)). Build the refresh into your model-release checklist so every fine-tuning run that ships re-triggers the posting, and version and date each disclosure so a regulator can match releases to postings.
Covered provider: provide a free public AI detection tool (Bus. & Prof. Code § 22757.2 (SB 942 as amended by AB 853))
Make available a FREE, publicly accessible AI detection tool that assesses whether image, video, or audio content was created or altered by your generative AI system. It must output system provenance data (never personal provenance data), support content uploads or URLs plus API access, and collect user feedback, with strict limits on retaining users' content and personal information. Exposure: $5,000 per violation, and each day a covered provider is in violation is deemed a discrete violation — $5,000 per day, compounding — enforced by the Attorney General, city attorneys, or county counsel; no private right of action, no cure period.
Covered provider: embed latent disclosures and offer a manifest disclosure option (Bus. & Prof. Code § 22757.3(a)–(b) (SB 942 as amended by AB 853))
Embed a mandatory LATENT disclosure in AI-generated or AI-altered image, video, and audio content conveying your name, the system's name and version, the creation or alteration timestamp, and a unique identifier — detectable by your own detection tool, consistent with widely adopted industry standards, and permanent or extraordinarily difficult to remove to the extent technically feasible (§ 22757.3(b)). Separately, OFFER users the option of a manifest disclosure identifying content as AI-generated that is clear, conspicuous, appropriate to the medium, and permanent or extraordinarily difficult to remove (§ 22757.3(a)). Same $5,000-per-violation-per-day exposure as the detection tool; no private right of action, no cure period.
Covered provider: bind licensees to preserve disclosures and revoke within 96 hours (Bus. & Prof. Code § 22757.3(c) (SB 942 as amended by AB 853))
If you license your covered generative AI system to third parties, contractually require each licensee to maintain the system's disclosure capability. If you discover a licensee has disabled it, you must revoke the licence within 96 hours, and the licensee must cease using the system on revocation. Build capability-monitoring and revocation mechanics into licence agreements before the duty attaches — the 96-hour clock runs from discovery.
Licensee: do not disable the licensed system's disclosure capability (Bus. & Prof. Code §§ 22757.3(c)(3), 22757.4 (SB 942 as amended by AB 853))
Do not disable, strip, or bypass the licensed covered system's built-in AI-disclosure capability when integrating it, and verify in integration testing that provenance disclosures survive your rendering and processing pipeline. If the provider discovers the capability was disabled it must revoke your licence within 96 hours, you must cease using the system after revocation, and continued use violates § 22757.3(c)(3) with direct liability — injunctive relief plus the prevailing plaintiff's attorney's fees and costs (§ 22757.4). This duty has no size threshold on the licensee side.
GenAI hosting platform: do not host non-compliant downloadable systems (Bus. & Prof. Code § 22757.3.2 (AB 853))
If a website or application you operate makes the source code or model weights of a generative AI system available for download by California residents, you are a 'GenAI hosting platform' with no size threshold: do not knowingly make available for download a generative AI system that does not place the § 22757.3 disclosures. Before hosting weights or source, verify the system's disclosure posture or gate the download. Exposure: $5,000 civil penalty per violation, enforced by the AG, city attorneys, or county counsel (the per-day deeming clause names covered providers, large online platforms, and capture-device manufacturers).
Assess employment ADS for discrimination and document anti-bias testing (2 CCR §§ 11008.1, 11009(f))
It is unlawful to use an automated-decision system — or selection criteria run through one — that discriminates against applicants or employees on a FEHA protected basis, whether by disparate treatment or disparate IMPACT; there is no intent element, and sourcing the tool from a third party is not a defense. Assess every employment ADS for discriminatory impact before and during use, and document anti-bias testing or similar proactive efforts: the regulations make the testing's quality, scope, recency, results, and your response expressly relevant evidence in defending — or proving — a claim. Exposure is ordinary FEHA enforcement: Civil Rights Department process plus private civil actions after a right-to-sue letter, with compensatory and punitive damages, attorney's fees, and injunctive relief, and no cure period.
Retain ADS data and employment records for four years (Cal. Code Regs. tit. 2, § 11013(c))
Retain for at least FOUR years (extended from two): applications, personnel records, selection criteria, and 'automated-decision system data' — any data used in or resulting from the ADS, including inputs and decision outcomes — measured from the later of record creation or the personnel action. Confirm your ATS and assessment vendors can actually export and preserve ADS inputs and outputs for the full period; a vendor's retention gap is your compliance gap.
Treat ATS and screening vendors as your FEHA agents (Cal. Code Regs. tit. 2, §§ 11008–11008.1 ('agent' and ADS definitions))
Anyone acting on your behalf to exercise a traditional employer function — recruitment, screening, hiring, promotion, or pay decisions — including in whole or in part through an automated-decision system, is your FEHA 'agent', and their tools create your exposure. Contract with ATS, assessment, and screening vendors for bias-testing documentation, ADS-data retention and export support, and accommodation workarounds, and keep the diligence file current. This includes AI features embedded in mainstream ATS products, not just standalone AI hiring tools.
Screen ADS assessments for medical-inquiry and disability exposure (2 CCR §§ 11008.1, 11016, 11071(e))
Review ADS-delivered assessments — personality tests, puzzles and games, reaction-time measures, and facial-expression, voice, or word-choice analysis in video interviews — for whether they elicit disability information and so function as unlawful medical or psychological inquiries; personality and reaction-time assessments are expressly flagged as disability-discrimination risks. Provide reasonable-accommodation paths around ADS screens, and apply existing FEHA limits (criminal-history individualized assessment, pre-employment inquiry rules) equally when executed through an ADS.
Deliver the ADMT pre-use notice (Cal. Code Regs. tit. 11, § 7220)
Before using ADMT for a significant decision, deliver a pre-use notice covering the purpose; how the ADMT works (categories of personal information used, its outputs, and how outputs are used in the decision); the opt-out method; and the alternative decision process if the consumer opts out. A business already using ADMT for significant decisions before 1 January 2027 must be fully compliant by that date — start now. Enforcement: CPPA administrative enforcement plus AG civil penalties under the CCPA (up to ~$2,663 per violation, ~$7,988 if intentional or involving minors, inflation-adjusted); cure is a discretionary consideration, not a right; no private right of action for ADMT violations.
Build the ADMT opt-out or qualify for an exception (Cal. Code Regs. tit. 11, § 7221)
Offer consumers an opt-out from ADMT used for significant decisions, or document that a § 7221 exception applies: (1) an appeal path to a qualified human reviewer with authority to overturn the decision; (2) for admission, acceptance, hiring, allocation-of-work, or compensation decisions — ADMT used solely to assess ability to perform, with documented steps ensuring it works as intended and does not unlawfully discriminate; or (3) security, fraud-prevention, or safety uses. Decide the path per decision type and keep the analysis with your risk assessment.
Answer ADMT access requests (Cal. Code Regs. tit. 11, § 7222)
On request, disclose the specific purpose of the ADMT, the logic used and how outputs were generated, the output itself and how it was used in the decision, and planned future use. Build ADMT access requests into your existing CCPA request workflow — and remember the CCPA reaches employees and job applicants, so HR must be able to answer these too.
Complete risk assessments before high-risk processing and calendar CPPA filings (Cal. Code Regs. tit. 11, § 7150 et seq. (risk assessments); §§ 7120–7124 (cybersecurity audits))
Conduct and document a risk assessment BEFORE initiating high-risk processing — the triggers include using ADMT for significant decisions and TRAINING such ADMT (or facial/emotion/identity recognition). Processing already underway before 1 January 2026 must be assessed by 31 December 2027, and the first attestation with summary information is due to the CPPA by 1 April 2028 (covering 2026–2027), then annually each 1 April. Separately, annual cybersecurity audits phase in for businesses meeting the audit triggers — first audits due 1 April 2028 (over $100M revenue), 1 April 2029 ($50–100M), or 1 April 2030 (under $50M) — so confirm your audit-trigger status with counsel and calendar the applicable date.
Companion chatbot: disclose AI status clearly and conspicuously (Bus. & Prof. Code §§ 22601–22606 (SB 243))
If a reasonable person interacting with your companion chatbot could be misled into believing they are talking with a human, issue a clear and conspicuous notification that the chatbot is artificially generated and not human. Also disclose that companion chatbots may not be suitable for some minors. Exposure is a private right of action (§ 22605): any person injured by noncompliance may sue for injunctive relief, the GREATER of actual damages or $1,000 per violation, and reasonable attorney's fees and costs — no agency gatekeeper, no cure period.
Companion chatbot: maintain and publish the self-harm crisis protocol (Bus. & Prof. Code §§ 22601–22606 (SB 243))
Do not let the companion chatbot engage with users unless you maintain — and PUBLISH on your website — a protocol for preventing the production of suicidal-ideation, suicide, or self-harm content, including referral to crisis services (such as a 988-type hotline) when a user expresses suicidal ideation, and use evidence-based methods for measuring suicidal ideation. Beginning 1 July 2027, file the annual report to the Office of Suicide Prevention on crisis-referral notifications issued and your detection, removal, and response protocols (published in de-identified aggregate). The § 22605 private right of action applies: the greater of actual damages or $1,000 per violation, plus fees.
Companion chatbot: implement the known-minor protections (Bus. & Prof. Code §§ 22601–22606 (SB 243))
For users you know are minors: disclose that the user is interacting with AI; provide a clear and conspicuous notification at least every 3 hours of continuing interaction reminding the user to take a break and that the chatbot is AI; and institute reasonable measures preventing the chatbot from producing sexually explicit content or directing sexual statements at the minor. Design your age-signal handling deliberately — these duties turn on users the operator KNOWS are minors, so document what your product knows and when.
Label commercial bots as automated (BOT Act safe harbor) (Bus. & Prof. Code §§ 17940–17941 (BOT Act, SB 1001))
Give the bot a disclosure that is clear, conspicuous, and reasonably designed to inform the counterparty that it is a bot (for example, 'I'm an AI assistant') — that disclosure is a complete safe harbor from § 17941 liability. The prohibition itself requires a stacked intent showing (intent to mislead about artificial identity, to knowingly deceive about the communication's content, in order to incentivize a purchase or sale or influence a vote), so an undisclosed bot is not per se unlawful — but the one-line label removes the question entirely. The chapter has no penalty of its own; public prosecutors enforce through the UCL (up to $2,500 per violation), § 17942(c) places no duties on hosting/ISP service providers, and the 10,000,000-visitor 'online platform' threshold does not exempt bot operators on small sites.
Frontier developer: transparency reports and Cal OES incident reporting (Bus. & Prof. Code §§ 22757.12, 22757.13, 22757.15 (SB 53 TFAIA))
As a frontier developer (you trained, or initiated the training of, a foundation model using more than 10^26 operations of compute): publish a transparency report before or with deploying a new or substantially modified frontier model (website, contact mechanism, release date, languages, modalities, intended uses, restrictions — trade-secret, cybersecurity, public-safety, and national-security redactions permitted), and report critical safety incidents to the California Office of Emergency Services within 15 days of discovery — within 24 hours to an appropriate authority if the incident poses imminent risk of death or serious injury. Large frontier developers (over $500,000,000 annual gross revenue with affiliates) must additionally write, implement, publish, and annually review a frontier AI framework and send quarterly confidential catastrophic-risk summaries to Cal OES, and no frontier developer may make materially false or misleading statements about catastrophic risk or its own framework compliance. Penalties: § 22757.15 imposes up to $1,000,000 per violation, scaled to severity, on LARGE frontier developers only (>$500M group revenue), recoverable in a civil action brought only by the Attorney General; no private right of action, no cure period. The statute prescribes no civil penalty for frontier developers below the $500M revenue tier. If you have not crossed the compute threshold, SB 53 imposes no duties on you.