Most California AI law coverage collapses three different things into one list: law that binds you now, law that has been signed but does not operate yet, and bills that are not law at all. The distinction is not pedantic. California AI law gained four statutes last week and none of them binds anyone until January.
One of those four California AI statutes was effectively superseded within a day. SB 813 creates a California Artificial Intelligence Standards and Safety Commission, and section 8898.1(c) provides that where Assembly Bill 1709 is enacted “and the e-Safety Advisory Commission is established pursuant to that measure, this section shall be inoperative.” AB 1709 was signed on 10 September 2026, one day after SB 813.
California AI law sorts into those three states below, because a compliance calendar built without that sort is a calendar of things that are not happening.
Nine instruments bind a California business today
Nine California AI law instruments are enforceable today, as at 13 September 2026.
| Instrument | In force since | Core duty | Enforcer |
| AB 1008 | 1 Jan 2025 | Personal information can exist inside an AI model | CPPA, Attorney General |
| AB 3030 | 1 Jan 2025 | Disclaimer on GenAI patient communications | Licensing boards |
| SB 1120 | 1 Jan 2025 | AI may not decide medical necessity | DMHC, Dept of Insurance |
| FEHA ADS regulations | 1 Oct 2025 | Employment automated decision systems | Civil Rights Department |
| SB 53 | 1 Jan 2026 | Frontier model transparency and incidents | Attorney General, Cal OES |
| AB 2013 | 1 Jan 2026 | Training data disclosure | Attorney General |
| SB 243 | 1 Jan 2026 | Companion chatbot disclosure and safety protocol | Private action, AG |
| CPPA regulations | 1 Jan 2026 | ADMT, risk assessments, cyber audits | CPPA, Attorney General |
| CATA (SB 942 as amended) | 2 Aug 2026 | Provenance, detection tool, disclosures | AG, city and county counsel |
Nine instruments, at least seven enforcing bodies, and three separate definitions of an automated decision. Definitional conflict is where California AI law scoping actually fails.
Three definitions of the same machine, and they do not line up
Automated decision-making is defined three times in California AI law, and the tests disagree.
The first California AI law test, at 11 CCR 7001(e), covers technology that processes personal information and uses computation “to replace human decisionmaking or substantially replace human decisionmaking”. Human involvement removes a tool from that article only where the reviewer knows how to interpret the output, actually reviews it alongside other relevant information, and holds authority to change the decision.
The second test, at 2 CCR 11008.1(a), covers a computational process that “makes a decision or facilitates human decision making regarding an employment benefit”. Adding a competent human reviewer satisfies the CPPA exception and changes nothing here, because facilitation is enough.
So a CV screening tool with a genuine human reviewer sits outside the CPPA article and squarely inside the employment regulations. One system, two opposite answers, two California AI law regulators.
California AI law brings vendors inside directly too. The amended definition of “agent” at 2 CCR 11008(b) covers anyone acting for an employer in recruitment, screening, hiring, promotion or pay decisions “including when such activities and decisions are conducted in whole or in part through the use of an automated decision system”, and provides that such an agent “is also an ’employer’ for purposes of the Act”. An AI hiring vendor is a FEHA employer in its own right.
California AI law adds a third and unrelated test through SB 53: a frontier model is a foundation model trained with more than 10 to the power of 26 operations.
AB 1008 put the model itself inside the CCPA
The quietest instrument in California AI law has the widest consequence, and almost no guidance mentions it.
AB 1008 amended Civil Code 1798.140 so that personal information “can exist in various formats, including… Abstract digital formats, including compressed or encrypted files, metadata, or artificial intelligence systems that are capable of outputting personal information.”
Read that against the CCPA rights architecture. A model capable of outputting personal information is within the definitional scope of personal information, so deletion, correction and access requests can attach to the model rather than only to the training set or the database behind it. No California regulator has yet tested what compliance looks like, which is precisely why the position should be documented before someone asks.
The CPPA holds the hardest deadline on the calendar
Of everything in force, California AI law puts its nearest deadline in the CPPA regulations.
The ADMT, risk assessment and cybersecurity audit regulations were approved by the Office of Administrative Law on 22 September 2025 and took effect on 1 January 2026. Section 7200(b) sets the compliance date: “A business that uses ADMT for a significant decision prior to January 1, 2027, must be in compliance with the requirements of this Article no later than January 1, 2027.”
A significant decision, defined by California AI law at 7001(ddd), means one resulting in the provision or denial of financial or lending services, housing, education enrolment or opportunities, employment or independent contracting opportunities or compensation, or health care services. Advertising is expressly excluded, which makes the list narrower than the 2023 drafts that also reached extensive profiling.
Three California AI law duties attach. The pre-use notice under 7220 must appear prominently at or before collection, must give “a plain language explanation of the specific purpose” rather than generic phrasing such as “to make a significant decision”, must set out the opt-out or appeal route and the access right, and must disclose which categories of personal information affect the output, whether the output is the sole factor, and what the alternative process is. An opt-out is required by default under 7221, subject to three exceptions: a human appeal route to a reviewer with authority to overturn, use solely to assess ability to perform at work or in education, and the equivalent for allocation of work.
Risk assessments run a separate clock. Processing begun before 1 January 2026 and continuing must be assessed by 31 December 2027, reviewed at least every three years, updated within 45 days of a material change, and retained for five years or as long as processing continues. Assessments from 2026 and 2027 are reported to the Agency by 1 April 2028 as an abridged attestation signed under penalty of perjury by a member of the executive management team. The Agency or the Attorney General can demand the full reports at any time, with 30 days to produce.
Cybersecurity audits tier by revenue, each by a qualified, objective, independent professional. The first report falls due on 1 April 2028 above 100 million dollars of 2026 revenue, a year later between 50 and 100 million, and a year after that below 50 million.
The Agency’s own regulatory impact assessment estimated 52,326 businesses subject to the CCPA and put the direct cost of the proposed package at 3.5 billion dollars, noting that 60 percent of affected California businesses have fewer than 100 employees. Both figures assessed the broader draft, so treat them as an upper bound. Penalties are the inflation-adjusted CCPA amounts, 2,663 dollars per violation and 7,988 dollars per intentional violation, and the Agency uses them: 1,350,000 dollars against Tractor Supply in September 2025 and 345,178 dollars against Todd Snyder that May, both on ordinary privacy grounds.
Health care and companion chatbots carry flat prohibitions, not process duties
Three California AI law instruments impose outright bans rather than paperwork, and they catch unprepared deployers most often.
SB 1120 provides that an artificial intelligence, algorithm or other software tool “shall not deny, delay, or modify health care services based, in whole or in part, on medical necessity”, and that a medical necessity determination “shall be made only by a licensed physician or a licensed health care professional competent to evaluate the specific clinical issues”. California AI law writes a ceiling into utilisation review automation.
AB 3030 requires health facilities, clinics and physician offices using generative AI for patient communications about clinical information to carry a disclaimer, placed at the beginning of letters and emails, displayed throughout chat, and spoken at the start and end of audio, plus clear instructions for reaching a human provider. The duty falls away where a licensed provider read and reviewed the communication.
SB 243 binds any operator of a companion chatbot made available to a user in California, with no size threshold. Where a reasonable person would be misled into thinking they were talking to a human, a clear and conspicuous notification is required. Operators must maintain and publish a protocol for preventing suicidal ideation, suicide and self-harm content, with referral to crisis services. For users known to be minors, the operator must disclose the AI interaction, deliver a break reminder at least every three hours of continuing interaction, and take reasonable measures against sexually explicit material. Annual reporting to the Office of Suicide Prevention begins 1 July 2027.
Employment regulations have been live since October 2025
Employers met California AI law before anyone else did, and those regulations are approaching their first anniversary.
The Civil Rights Council regulations took effect on 1 October 2025, amending twenty sections of 2 CCR division 4.1 and adding section 11008.1. The regulations reach computer-based assessments and games measuring skills, personality or cultural fit, targeted job advertising, resume screening for terms or patterns, analysis of facial expression, word choice or voice in online interviews, and applicant data bought from third parties.
Familiar discrimination doctrine then does the California AI law work. A tool probing disability can be an unlawful medical inquiry. Application technology screening on schedule may discriminate on religious creed or disability unless job-related and consistent with business necessity and it includes a mechanism for the applicant to request an accommodation. Tools measuring reaction time or dexterity, and tools reading tone of voice or facial expression, each carry express accommodation duties.
Two operational changes matter more than those prohibitions. Record retention moved from two years to four years, covering automated decision system data. And anti-bias testing became evidentiary: whether it was done, and what was done with the result, bears on a claim or a defence. Nothing compels it, and its absence is now visible.
No Civil Rights Department action targeting an automated decision system has become public. Given the October 2025 start and the exhaustion timeline, the first would not be expected yet.
Signed on 9 and 10 September, dormant until January
Four statutes joined California AI law last week. None binds anyone yet, and one may never operate.
California AI law follows the ordinary rule here. Statutes enacted at a regular session without an urgency clause take effect on 1 January following a 90-day period, so AB 1405, SB 813, SB 867 and SB 1119 all take effect on 1 January 2027.
AB 1405, chapter 178, directs the Government Operations Agency to establish an AI Auditor Registry “no later than January 1, 2029“, and only from that date does it become unlawful for an unregistered person to offer, sell or conduct a covered AI audit. Registered auditors will carry a registration number, sign audit reports, and meet independence and conflict rules, with an exemption route for licensed public accountants. California AI law will carry a regulated audit profession in about 27 months, not now.
SB 813, chapter 179, would have the Business and Consumer Services Agency establish a California Artificial Intelligence Standards and Safety Commission on or before 1 July 2027, developing safety standards, auditor registration procedures and criteria for independent verification organisations. Section 8898.1(c) then conditions it out where AB 1709 is enacted and its e-Safety Advisory Commission is established. AB 1709 is enacted. Whether the Commission ever exists now depends on whether the e-Safety Advisory Commission is stood up.
SB 867, chapter 189, prohibits toys containing companion chatbots, with the prohibition itself repealing on 1 January 2031. SB 1119, chapter 190, requires companion chatbot operators to run and document a minor-safety risk assessment before release or substantial modification, submit to independent child safety audits, and obtain an auditor report signed under penalty of perjury that the Attorney General may obtain for cause, beginning 1 July 2027.
Read those four together and the direction of California AI law is clear: California is building third-party assurance for AI, with a registered auditor profession from 2029 and audit duties arriving from mid-2027. Nothing in that set changes what a business must do this quarter.
Still bills: a dozen enrolled, with a 30 September deadline
A dozen AI bills sit with the Governor. Three would change California AI law materially.
SB 1000 would overhaul the California AI Transparency Act and carries an urgency clause, so it would take effect immediately on signature rather than in January. Deleting the one million monthly user threshold from “covered provider” is its largest effect, expanding by an order of magnitude who owes detection tool and disclosure duties. The bill passed the Assembly 72 to 0, the Senate concurred 39 to 0, and it reached the Governor on 2 September 2026.
SB 947 would create employment automated decision system duties from 1 July 2027: a written post-use notice where such a system was primarily relied on, a right to a description of the employee’s own data used in a disciplinary or termination decision, and a 500 dollar civil penalty per violation enforced by the Labor Commissioner and public prosecutors.
AB 1883 would regulate workplace surveillance tools including neural data and emotional state monitoring. Health care AI sits in SB 503 and AB 1979, digital replicas in SB 1111, and generative AI standards for attorneys and judicial officers in SB 574.
None of that is California AI law yet. Planning against it now is premature; ignoring it until October costs a quarter.
What the Attorney General actually does, as distinct from what the statutes say
Enforcement posture is a separate question from statutory duty, and California AI law was not where the answer started.
Two legal advisories of 13 January 2025 set it out: existing California law already applies to AI development and use, across consumer protection, civil rights, competition, data privacy, professional licensing and election law. On 16 January 2026 the office sent xAI a cease and desist letter over Grok-generated material, citing Civil Code 1708.86, the Penal Code and Business and Professions Code 17200, and demanding confirmation of remedial steps within five days.
Not one of those authorities is an AI statute. No enforcement action has yet been brought under SB 53 or the California AI Transparency Act.
Every California AI date that matters
| Date | What happens |
| 1 Jan 2025 | AB 1008, AB 3030, SB 1120 in force |
| 1 Oct 2025 | FEHA automated decision system regulations in force |
| 1 Jan 2026 | SB 53, AB 2013, SB 243, CPPA regulations in force |
| 2 Aug 2026 | California AI Transparency Act operative for covered providers |
| 30 Sep 2026 | Governor’s action deadline on the enrolled 2026 AI bills |
| 1 Jan 2027 | CPPA ADMT compliance; CATA platform duties; AB 1405, SB 813, SB 867, SB 1119 take effect |
| 1 Jul 2027 | SB 1119 chatbot assessments and audits; SB 243 reporting; SB 813 commission deadline |
| 31 Dec 2027 | CPPA risk assessments for pre-2026 legacy processing |
| 1 Jan 2028 | CATA duties for capture device manufacturers |
| 1 Apr 2028 | First risk assessment attestation; first cybersecurity audit above 100m revenue |
| 1 Jan 2029 | AB 1405 registry deadline; unregistered AI auditing prohibited |
| 1 Apr 2030 | Final cybersecurity audit tier, below 50m revenue |
How California compares with other states is in the global regulation tracker, with the nearest two regimes in the Colorado SB 26-189 checklist and the Texas TRAIGA analysis.
What a California programme has to be able to produce
Seven enforcing bodies under California AI law converge on one small artefact set, despite asking different questions.
California AI law needs a system inventory recording, per system, whether it replaces or substantially replaces human decision-making, whether it facilitates an employment decision, whether it touches a significant decision category, and whether it can output personal information. One system, four classifications, because the definitions differ.
Then: pre-use notice text per system and per channel with the specific purpose in plain language; evidence of reviewer competence and authority where the human involvement exception is relied on; opt-out and appeal logs with outcomes; risk assessments with dates, the three-year cycle and the executive who will attest; anti-bias testing results and what was done with them; four years of employment automated decision system data; published self-harm protocols for any companion chatbot; and the reasoning on whether a model itself holds personal information under AB 1008.
California hosts a concentrated share of the work California AI law governs. The Governor’s office claims 32 of the 50 top AI companies worldwide are based in the state, and separately cites the 2025 Stanford AI Index for the figure that 15.7 percent of all United States AI job postings in 2024 were in California, against 8.8 percent in Texas and 5.8 percent in New York.
Where the California records live
By 2029 California AI law will have an AI audit conducted by a registered auditor against a registry standard. Evidence assembled now is what that auditor will read.
Govern365 was built for the reconciliation California AI law forces. The AI System Registry holds each system once and carries multiple classifications against it, so a hiring tool can be recorded as outside the CPPA article and inside the FEHA regulations without maintaining two inventories. The Audit Evidence Manager attaches pre-use notices, reviewer competence records, bias testing results and opt-out logs to the obligation each satisfies, with dates and approvers, which is the shape an AB 1405 registered auditor will ask for. Governance Workflows carry the human appeal route the CPPA exception depends on and the accommodation mechanism the employment regulations require. Continuous Monitoring holds retention to the longest clock, which in California is the four-year FEHA rule and the five-year risk assessment rule. All of it sits in one platform at govern365.ai, and the route from intake to an approved, evidenced system is shown on where these approvals are tracked. Which record answers which obligation across regimes is worked out in the records that prove conformity.
Frequently asked questions
Does California have an AI law?
Not one law. Nine California AI instruments are in force today. Four more joined California AI law in September 2026 and do not take effect until 1 January 2027. A dozen bills still await signature.
When is the California ADMT compliance deadline?
California AI law sets it at 1 January 2027, under 11 CCR section 7200(b). Businesses using automated decision-making technology for a significant decision before that date must be compliant by it. Risk assessments for pre-2026 processing run to 31 December 2027, with an executive attestation to the Agency by 1 April 2028.
Does a human reviewer take our tool out of scope?
California AI law answers differently by regulator. Under the CPPA rules, genuine human involvement can remove a system from the ADMT article where the reviewer can interpret the output, reviews it against other information, and has authority to change the decision. Under the Civil Rights Council regulations the definition covers any system that merely facilitates a human decision, so the same tool stays in scope.
Can someone ask us to delete an AI model under the CCPA?
Possibly. California AI law amended Civil Code 1798.140 through AB 1008 so that personal information can exist in “artificial intelligence systems that are capable of outputting personal information”, which brings a model within the definitional scope of personal information. No California regulator has tested what deletion or correction looks like in that setting, so document the position.
Does California have an AI auditor registry?
Not yet. AB 1405 was chaptered on 9 September 2026 and takes effect on 1 January 2027. The Government Operations Agency then has until 1 January 2029 to establish the registry, and only from that date is unregistered AI auditing prohibited.
Is the California AI Standards and Safety Commission going to exist?
Unclear. California AI law would have the Business and Consumer Services Agency establish it by 1 July 2027 under SB 813, but section 8898.1(c) makes that section inoperative if AB 1709 is enacted and its e-Safety Advisory Commission is established. AB 1709 was signed on 10 September 2026, one day after SB 813.
Are AI hiring vendors liable in California?
Yes, directly. California AI law makes an agent, at 2 CCR 11008(b), conducting recruitment, screening, hiring, promotion or pay activities through an automated decision system an employer for FEHA purposes.
