AI Compliance · 2026-07-30 · 10 min read
California AI Laws 2026: The Complete Seven-Law Guide
California has no single AI Act — it has seven separate laws, and two of them reach small companies directly. Here is who each law covers, what it requires, when it bites, and what non-compliance costs in 2026.
Seven California AI laws matter to businesses in 2026: AB 2013 training-data disclosure (in force since January 1, 2026, with no size threshold), the SB 942/AB 853 AI Transparency Act (first duties apply from August 2, 2026), SB 243 companion-chatbot rules, the FEHA automated-decision employment regulations (in force since October 1, 2025), the CCPA ADMT regulations, the 2019 BOT Act, and SB 53 — which binds only frontier developers.
California regulates AI harder than any other US state, and it does it piecemeal: there is no single "California AI Act." Seven separate laws and regulations each carve out their own scope, dates, and penalties. This guide walks through all seven so you can tell in minutes which ones actually apply to your company.
Which California AI laws apply in 2026?
| Law | Who it covers | Core duty | Key date | Penalty |
|---|---|---|---|---|
| AB 2013 (Civ. Code §§3110–3111) | Any developer of generative AI made publicly available to Californians — no size threshold; fine-tuners included (§3110(d)) | Publish a 12-element training-data summary before public availability | In force since Jan 1, 2026 | UCL §17200, up to $2,500 per violation, no cure period |
| SB 942 / AB 853 (AI Transparency Act) | GenAI systems with >1,000,000 monthly users producing image, audio, or video | Covered-provider transparency duties | Applies from Aug 2, 2026 (weight-hosting and large-platform duties from Jan 1, 2027) | — |
| SB 243 (BPC §§22601–22606) | Companion chatbot operators; customer-service and business-ops bots excluded | Companion-chatbot safeguards and disclosures | In force since Jan 1, 2026 | Private right of action (§22605): greater of actual damages or $1,000 per violation, plus fees |
| FEHA ADS regulations (2 CCR §§11008.1, 11009(f)) | Employers with 5+ employees and at least one CA employee or applicant | Discrimination liability for automated-decision systems in employment; 4-year records (§11013(c)) | In force since Oct 1, 2025 | FEHA discrimination claims |
| CCPA ADMT regulations (11 CCR) | CCPA "businesses" only (e.g., >$26.6M revenue or data thresholds) | ADMT compliance obligations under the regulations | Regs effective Jan 1, 2026; obligations apply from Jan 1, 2027 | CCPA enforcement |
| BOT Act (BPC §17940) | Anyone using bots to incentivize purchases or influence votes | No misleading bot use without disclosure | In force since 2019 | — |
| SB 53 | Frontier developers only (~10^26-FLOP training runs / >$500M revenue) | Frontier-safety duties | Zero duties below the thresholds | N/A for nearly all companies |
The common mistake is assuming these laws only hit big tech: AB 2013 and the FEHA regulations reach startups and small businesses directly.
AB 2013: training-data disclosure with no size threshold
AB 2013 (Civ. Code §§3110–3111) is the California AI law most likely to apply to your company, precisely because it has no size threshold. In force since January 1, 2026, it requires developers of generative AI systems made publicly available to Californians to publish a 12-element summary of the system's training data before the system becomes publicly available.
Three things make this law easy to underestimate:
- Fine-tuning counts. "Developer" is not limited to companies that pretrain foundation models. Section 3110(d) expressly includes fine-tuning within "substantial modification" — so if you fine-tuned an open-weights model for your support product, you are a developer with your own disclosure duty, separate from whatever the base-model vendor publishes.
- The court challenge failed. xAI sued to block the law; the court denied the preliminary injunction on March 4, 2026 (xAI v. Bonta). The law is fully operative — waiting out the litigation is not a compliance strategy.
- There is no cure period. Enforcement runs through California's Unfair Competition Law (§17200) at up to $2,500 per violation, with no grace window once you are out of compliance.
If you ship any generative AI feature that Californians can reach, draft the 12-element summary before launch, not after.
SB 942 and AB 853: the AI Transparency Act deadlines
The AI Transparency Act (SB 942, as amended by AB 853) targets large-scale generative AI systems that produce synthetic media. Its duties arrive in two waves:
- Covered-provider duties apply from August 2, 2026 — three days from this post's publication date. A covered provider is a generative AI system with more than 1,000,000 monthly users that produces image, audio, or video content.
- The genAI weight-hosting gate applies from January 1, 2027, and large-online-platform duties also apply from January 1, 2027.
The million-monthly-user threshold means most companies are out of scope as providers — but note the date. August 2, 2026 is the same day the EU AI Act's Article 50 transparency obligations apply, including the duty to mark AI-generated content. If you produce synthetic media at scale and sell into Europe, the two regimes converge on a single deadline. Our free EU AI Act checker handles the EU side in about three minutes, no signup required.
SB 243: companion chatbots — and the exact business-bot carve-out
SB 243 (BPC §§22601–22606) has been in force since January 1, 2026. It imposes safeguard and disclosure duties on operators of companion chatbots — the AI-friend and AI-relationship category.
The question every SaaS company asks is: does my customer-service chatbot count? The answer is no. The statute excludes customer-service and business-operations bots — the carve-out covers bots used for "productivity and analysis related to source information." A support bot, an internal analytics assistant, a sales-qualification bot: none of these are companion chatbots under SB 243.
The stakes of getting the classification right are unusual, though. SB 243 carries a private right of action under §22605: the greater of actual damages or $1,000 per violation, plus attorney's fees — meaning plaintiffs' lawyers can enforce it directly, no waiting on the Attorney General. If your product deliberately builds emotional engagement or ongoing persona-based relationships, get a real legal read on which side of the carve-out you sit.
FEHA ADS regulations: the employment rules most companies miss
This is the sleeper of the seven. California's FEHA automated-decision system regulations (2 CCR §§11008.1, 11009(f)) have been in force since October 1, 2025, and they apply to any employer with 5 or more employees and at least one California employee or applicant.
In practice: if you use an AI resume screener, a video-interview scoring tool, or a ranking algorithm inside your ATS, discriminatory outcomes from that system carry FEHA civil-rights exposure. Two operational points from the regulations:
- Anti-bias testing is weighable evidence — documented testing is a defense asset, and its absence can cut the other way.
- Keep records for four years (§11013(c)).
The structure parallels NYC Local Law 144's bias-audit regime, where the employer owns the duty even for vendor ATS tools. If you hire in both California and New York City, the two obligations stack, and your vendor's marketing claims about "compliant AI" cover neither.
CCPA ADMT regulations: the 2027 clock is already running
The California Privacy Protection Agency's automated decisionmaking technology (ADMT) regulations (11 CCR) took effect January 1, 2026, but the ADMT compliance obligations themselves apply from January 1, 2027.
Scope matters here: these regulations bind only CCPA "businesses" — companies that meet the CCPA thresholds, for example more than $26.6M in annual revenue, or the data-volume thresholds. A small startup below the revenue line is typically out of scope; a mid-market company processing large volumes of consumer data is typically in.
If you cross the thresholds, the work between now and January 2027 is mostly inventory: you cannot comply with ADMT rules for systems you do not know you run. Our shadow AI discovery guide covers how to surface unapproved AI tools systematically before the deadline turns unknown tools into unknown violations.
The BOT Act: California's oldest bot-disclosure law
The BOT Act (BPC §17940) has been in force since 2019, long before the generative AI wave. Its rule is simple: bots must not mislead people in order to incentivize purchases or influence votes without disclosing that they are bots.
It gets overlooked because it predates ChatGPT, but an AI sales agent that lets prospects believe they are chatting with a human while pushing them toward a purchase sits squarely in its target zone. The fix is cheap — one honest "you're chatting with an AI assistant" line satisfies a lot of law at once.
SB 53: frontier-only — you almost certainly owe nothing
SB 53 is California's frontier AI safety law, and it deserves one paragraph precisely because so many companies waste time worrying about it. It binds developers at roughly the 10^26-FLOP training-compute scale or above $500M in revenue — the same frontier-only structure as New York's RAISE Act and Illinois SB 315. Below those thresholds, you owe nothing under SB 53. Cross it off and spend the attention on AB 2013 and the FEHA regulations instead.
For how California compares with Texas, Illinois, Colorado, and the rest, see our complete map of US state AI laws in 2026.
How to get compliant with California AI laws: 5 steps
- Inventory every AI system you build or use — fine-tuned models, embedded vendor tools, and the unofficial tools employees adopted on their own.
- Classify each system against the seven laws. Most trigger zero or one; employment tools and public genAI features are the usual multi-law hits.
- Publish AB 2013 disclosures before launch. The duty attaches before public availability, and there is no cure period.
- Fix employment AI first. The FEHA regulations have been in force since October 1, 2025 — you may already be behind. Document anti-bias testing and set up 4-year record retention now.
- Calendar the deadlines: August 2, 2026 (SB 942 covered providers — and EU Article 50); January 1, 2027 (CCPA ADMT obligations, SB 942 hosting and platform duties).
Shieldra automates steps 1 and 2: a deterministic rules engine classifies your AI systems against California's laws alongside the EU AI Act, Texas, Illinois, Colorado, and NYC Local Law 144 — every answer traced to a statutory citation, not an LLM guess. See what's included on our features page.
FAQ
Does AB 2013 apply to small startups?
Yes. AB 2013 (Civ. Code §§3110–3111) has no size threshold — any developer of a generative AI system made publicly available to Californians must publish the 12-element training-data summary before public availability. Fine-tuning counts as development under §3110(d). The law has been in force since January 1, 2026.
Is my customer-service chatbot covered by California's SB 243?
No. SB 243 excludes customer-service and business-operations bots — the statute carves out bots used for "productivity and analysis related to source information." The law targets companion chatbots that build ongoing emotional relationships. But classification matters: companion-bot operators face a private right of action under §22605 for the greater of actual damages or $1,000 per violation, plus attorney's fees.
What happened in the xAI lawsuit against AB 2013?
xAI challenged AB 2013 and sought a preliminary injunction. The court denied it on March 4, 2026 (xAI v. Bonta), so the law is fully operative. Enforcement runs through the Unfair Competition Law (§17200) at up to $2,500 per violation, with no cure period.
When do the CCPA ADMT rules actually take effect?
The ADMT regulations (11 CCR) took effect January 1, 2026, but the compliance obligations for automated decisionmaking technology apply from January 1, 2027. They bind only CCPA "businesses" — companies over roughly $26.6M in annual revenue or meeting the data-volume thresholds — so smaller companies are typically out of scope.
Do I need to comply with California SB 53?
Almost certainly not. SB 53 binds only frontier developers — roughly 10^26-FLOP training runs or more than $500M in revenue. Below those thresholds there are zero duties. Unless you are training frontier-scale models, your California obligations come from AB 2013, the FEHA employment regulations, and possibly SB 942 or the CCPA ADMT rules instead.