Artificial Intelligence

Image for Critical infrastructure: artificial intelligence systems: human oversight.

Critical infrastructure: artificial intelligence systems: human oversight.

Requires human oversight and approval of AI systems managing critical state infrastructure by July 2026. Mandates annual AI safety training for state personnel overseeing critical infrastructure systems. Establishes yearly assessments of AI systems to evaluate risks and performance in critical infrastructure. Requires real-time human monitoring of AI operations in vital state services like energy and healthcare.

Critical infrastructure: artificial intelligence systems: human oversight.

Image for Critical infrastructure: artificial intelligence systems: human oversight.

Requires human oversight and approval of AI systems managing critical state infrastructure by July 2026. Mandates annual AI safety training for state personnel overseeing critical infrastructure systems. Establishes yearly assessments of AI systems to evaluate risks and performance in critical infrastructure. Requires real-time human monitoring of AI operations in vital state services like energy and healthcare.

Image for Cyberbullying Protection Act: liability.

Cyberbullying Protection Act: liability.

Increases penalties for social media platforms that violate cyberbullying prevention rules to $50,000 per violation. Establishes that each day of non-compliance counts as a separate violation for penalty purposes. Authorizes courts to order platforms to comply and award attorney fees to successful plaintiffs.

Cyberbullying Protection Act: liability.

Image for Cyberbullying Protection Act: liability.

Increases penalties for social media platforms that violate cyberbullying prevention rules to $50,000 per violation. Establishes that each day of non-compliance counts as a separate violation for penalty purposes. Authorizes courts to order platforms to comply and award attorney fees to successful plaintiffs.

Image for Artificial intelligence: auditors: enrollment.

Artificial intelligence: auditors: enrollment.

Establishes a new state registry system for artificial intelligence auditors who evaluate AI systems in California. Requires AI auditors to enroll with the state, pay fees, and follow industry standards by January 2027. Prohibits auditors from working for audited companies within 12 months before or after conducting an audit. Creates a public reporting system for misconduct and protects whistleblowers who report violations.

Artificial intelligence: auditors: enrollment.

Image for Artificial intelligence: auditors: enrollment.

Establishes a new state registry system for artificial intelligence auditors who evaluate AI systems in California. Requires AI auditors to enroll with the state, pay fees, and follow industry standards by January 2027. Prohibits auditors from working for audited companies within 12 months before or after conducting an audit. Creates a public reporting system for misconduct and protects whistleblowers who report violations.

Image for Location privacy.

Location privacy.

Prohibits businesses from collecting location data unless necessary to provide requested services. Requires prominent notices when location data is collected and mandates detailed privacy policies. Bans the sale or monetization of location information by businesses and government agencies. Establishes penalties up to $25,000 per violation and allows both state enforcement and private lawsuits.

Location privacy.

Image for Location privacy.

Prohibits businesses from collecting location data unless necessary to provide requested services. Requires prominent notices when location data is collected and mandates detailed privacy policies. Bans the sale or monetization of location information by businesses and government agencies. Establishes penalties up to $25,000 per violation and allows both state enforcement and private lawsuits.

Image for California Restaurant Reservation AntiPiracy Act.

California Restaurant Reservation AntiPiracy Act.

Prohibits third-party platforms from listing restaurant reservations without written agreements from establishments. Authorizes the Attorney General to impose civil penalties up to $1,000 per violation. Creates a state fund from collected penalties to enforce restaurant reservation regulations. Allows restaurants and authorized reservation services to sue unauthorized platforms for damages.

California Restaurant Reservation AntiPiracy Act.

Image for California Restaurant Reservation AntiPiracy Act.

Prohibits third-party platforms from listing restaurant reservations without written agreements from establishments. Authorizes the Attorney General to impose civil penalties up to $1,000 per violation. Creates a state fund from collected penalties to enforce restaurant reservation regulations. Allows restaurants and authorized reservation services to sue unauthorized platforms for damages.

Image for Mental health and artificial intelligence working group.

Mental health and artificial intelligence working group.

Establishes a state working group to evaluate artificial intelligence use in mental health treatment by July 2026. Requires input from health organizations, tech companies, and advocacy groups through three public meetings. Mandates comprehensive reports to the Legislature on AI in mental health by July 2028 and January 2030. Creates a framework for training mental health professionals on effective use of AI tools in treatment.

Mental health and artificial intelligence working group.

Image for Mental health and artificial intelligence working group.

Establishes a state working group to evaluate artificial intelligence use in mental health treatment by July 2026. Requires input from health organizations, tech companies, and advocacy groups through three public meetings. Mandates comprehensive reports to the Legislature on AI in mental health by July 2028 and January 2030. Creates a framework for training mental health professionals on effective use of AI tools in treatment.

Image for Law enforcement agencies: artificial intelligence.

Law enforcement agencies: artificial intelligence.

Establishes a policy requiring per-page AI use disclosure and the officer's signature. Requires retention of the first AI draft for as long as the final report is kept. Mandates an audit trail showing who used AI and the input video or audio. Restricts contracted vendors to use data only for LEA purposes or court orders.

Law enforcement agencies: artificial intelligence.

Image for Law enforcement agencies: artificial intelligence.

Establishes a policy requiring per-page AI use disclosure and the officer's signature. Requires retention of the first AI draft for as long as the final report is kept. Mandates an audit trail showing who used AI and the input video or audio. Restricts contracted vendors to use data only for LEA purposes or court orders.

Image for California Cybersecurity Integration Center: artificial intelligence.

California Cybersecurity Integration Center: artificial intelligence.

Establishes a California AI cybersecurity collaboration playbook to unite cyber and AI defenses. Imposes mandatory information sharing with AI service providers and limits disclosures. Creates four annual expenditure reports on federal cybersecurity funding. Expands Cal-CSIC governance, adds a statewide strategy and a Cyber Incident Response Team.

California Cybersecurity Integration Center: artificial intelligence.

Image for California Cybersecurity Integration Center: artificial intelligence.

Establishes a California AI cybersecurity collaboration playbook to unite cyber and AI defenses. Imposes mandatory information sharing with AI service providers and limits disclosures. Creates four annual expenditure reports on federal cybersecurity funding. Expands Cal-CSIC governance, adds a statewide strategy and a Cyber Incident Response Team.

Image for Student personal information.

Student personal information.

Expands student privacy protections to cover K-12, preschool, and higher education institutions by July 2026. Prohibits operators from using student data to train AI systems unless specifically for educational purposes. Requires operators to implement data security measures and delete student information upon request. Allows students to sue operators for privacy violations with damages up to $500 per incident.

Student personal information.

Image for Student personal information.

Expands student privacy protections to cover K-12, preschool, and higher education institutions by July 2026. Prohibits operators from using student data to train AI systems unless specifically for educational purposes. Requires operators to implement data security measures and delete student information upon request. Allows students to sue operators for privacy violations with damages up to $500 per incident.

Image for Reporting mechanism: child sexual abuse material.

Reporting mechanism: child sexual abuse material.

Requires social media platforms to provide clear reporting mechanisms for child sexual abuse material. Mandates platforms to review reported content through hash matching and human review within 30 days. Imposes penalties up to $250,000 per day on platforms that fail to maintain functional reporting systems. Requires platforms to undergo bi-annual third-party safety audits and publicly release findings.

Reporting mechanism: child sexual abuse material.

Image for Reporting mechanism: child sexual abuse material.

Requires social media platforms to provide clear reporting mechanisms for child sexual abuse material. Mandates platforms to review reported content through hash matching and human review within 30 days. Imposes penalties up to $250,000 per day on platforms that fail to maintain functional reporting systems. Requires platforms to undergo bi-annual third-party safety audits and publicly release findings.

Image for Leading Ethical AI Development (LEAD) for Kids Act.

Leading Ethical AI Development (LEAD) for Kids Act.

Establishes the LEAD for Kids Act to regulate companion chatbots for California minors. Prohibits making a companion chatbot available to a child if it is foreseeably capable of harms. Authorizes civil penalties and private suits; penalties are $25,000 per violation. Prescribes child-status rules: knowledge before 2027; after, determine not-a-child.

Leading Ethical AI Development (LEAD) for Kids Act.

Image for Leading Ethical AI Development (LEAD) for Kids Act.

Establishes the LEAD for Kids Act to regulate companion chatbots for California minors. Prohibits making a companion chatbot available to a child if it is foreseeably capable of harms. Authorizes civil penalties and private suits; penalties are $25,000 per violation. Prescribes child-status rules: knowledge before 2027; after, determine not-a-child.

Image for Age verification signals: software applications and online services.

Age verification signals: software applications and online services.

Mandates real-time age-bracket signals to developers. OSs must collect birth date or age at setup and provide signals by January 1, 2027. Imposes penalties up to $2,500 per negligent and $7,500 per intentional child; enforcement by the Attorney General. Operative date 1/1/2027; July 1 transitions; exemptions for broadband, telecom, and physical products.

Age verification signals: software applications and online services.

Image for Age verification signals: software applications and online services.

Mandates real-time age-bracket signals to developers. OSs must collect birth date or age at setup and provide signals by January 1, 2027. Imposes penalties up to $2,500 per negligent and $7,500 per intentional child; enforcement by the Attorney General. Operative date 1/1/2027; July 1 transitions; exemptions for broadband, telecom, and physical products.

Image for Automated decision systems.

Automated decision systems.

Establishes comprehensive regulations for automated decision systems that make consequential decisions affecting individuals. Requires developers to conduct impact assessments and annual audits of automated decision systems starting January 2027. Mandates that deployers provide clear disclosures to individuals before and after automated decisions are made. Authorizes civil penalties up to $25,000 per violation and enforcement by state agencies and local prosecutors.

Automated decision systems.

Image for Automated decision systems.

Establishes comprehensive regulations for automated decision systems that make consequential decisions affecting individuals. Requires developers to conduct impact assessments and annual audits of automated decision systems starting January 2027. Mandates that deployers provide clear disclosures to individuals before and after automated decisions are made. Authorizes civil penalties up to $25,000 per violation and enforcement by state agencies and local prosecutors.

Image for High-risk artificial intelligence systems: duty to protect personal information.

High-risk artificial intelligence systems: duty to protect personal information.

Requires businesses using high-risk AI systems to implement comprehensive data security programs to protect personal information. Mandates annual security reviews and immediate updates when business practices significantly change. Establishes strict access controls including encryption, monitoring, and unique authentication for AI system data. Violations are classified as deceptive trade practices subject to penalties under California's Unfair Competition Law.

High-risk artificial intelligence systems: duty to protect personal information.

Image for High-risk artificial intelligence systems: duty to protect personal information.

Requires businesses using high-risk AI systems to implement comprehensive data security programs to protect personal information. Mandates annual security reviews and immediate updates when business practices significantly change. Establishes strict access controls including encryption, monitoring, and unique authentication for AI system data. Violations are classified as deceptive trade practices subject to penalties under California's Unfair Competition Law.

Image for Economic development: industry strategies.

Economic development: industry strategies.

Establishes GO-Biz to craft industry strategies for blueprint sectors with quantum priority. Requires quantum technology strategy submission by July 1, 2026 with regional input. Ensures six elements are included: overview, risks, projects, policies, outcomes, public info. Requires no new appropriation and relies on oversight through reporting.

Economic development: industry strategies.

Image for Economic development: industry strategies.

Establishes GO-Biz to craft industry strategies for blueprint sectors with quantum priority. Requires quantum technology strategy submission by July 1, 2026 with regional input. Ensures six elements are included: overview, risks, projects, policies, outcomes, public info. Requires no new appropriation and relies on oversight through reporting.

Image for State agencies: information security: Zero Trust architecture.

State agencies: information security: Zero Trust architecture.

Requires all California state agencies to implement Zero Trust cybersecurity architecture by 2030. Mandates multifactor authentication and continuous monitoring for all state systems and data access. Establishes a two-phase implementation with Advanced maturity required by 2026 and Optimal by 2030. Requires agencies to submit annual security assessment reports tracking Zero Trust implementation progress.

State agencies: information security: Zero Trust architecture.

Image for State agencies: information security: Zero Trust architecture.

Requires all California state agencies to implement Zero Trust cybersecurity architecture by 2030. Mandates multifactor authentication and continuous monitoring for all state systems and data access. Establishes a two-phase implementation with Advanced maturity required by 2026 and Optimal by 2030. Requires agencies to submit annual security assessment reports tracking Zero Trust implementation progress.

Image for California AI Transparency Act.

California AI Transparency Act.

Delays the act’s operative date and expands AI transparency to platforms and devices. Requires large online platforms to detect provenance data and disclose content origin by 2027. Requires GenAI hosting platforms to place disclosures in outputs by 2027. Requires capture device makers to embed latent disclosures by default by 2028.

California AI Transparency Act.

Image for California AI Transparency Act.

Delays the act’s operative date and expands AI transparency to platforms and devices. Requires large online platforms to detect provenance data and disclose content origin by 2027. Requires GenAI hosting platforms to place disclosures in outputs by 2027. Requires capture device makers to embed latent disclosures by default by 2028.

Image for Automated decision systems.

Automated decision systems.

Requires developers to assess high-risk AI systems for discrimination before deployment starting January 2026. Mandates companies notify individuals when AI systems are used in decisions affecting their rights or benefits. Establishes penalties up to $25,000 for AI systems that discriminate based on protected characteristics. Prohibits state agencies from contracting AI systems unless certified to comply with civil rights laws.

Automated decision systems.

Image for Automated decision systems.

Requires developers to assess high-risk AI systems for discrimination before deployment starting January 2026. Mandates companies notify individuals when AI systems are used in decisions affecting their rights or benefits. Establishes penalties up to $25,000 for AI systems that discriminate based on protected characteristics. Prohibits state agencies from contracting AI systems unless certified to comply with civil rights laws.

Image for Preventing Algorithmic Price Fixing Act: prohibition on certain price-setting algorithm uses.

Preventing Algorithmic Price Fixing Act: prohibition on certain price-setting algorithm uses.

Prohibits algorithms that use competitors' private data to set prices or rental rates in the same market. Imposes penalties up to $1,000 per violation for companies selling or using price-setting algorithms illegally. Allows businesses to avoid penalties by obtaining written proof that algorithms do not use nonpublic competitor data. Authorizes state and local prosecutors to enforce the law through civil actions and seek damages.

Preventing Algorithmic Price Fixing Act: prohibition on certain price-setting algorithm uses.

Image for Preventing Algorithmic Price Fixing Act: prohibition on certain price-setting algorithm uses.

Prohibits algorithms that use competitors' private data to set prices or rental rates in the same market. Imposes penalties up to $1,000 per violation for companies selling or using price-setting algorithms illegally. Allows businesses to avoid penalties by obtaining written proof that algorithms do not use nonpublic competitor data. Authorizes state and local prosecutors to enforce the law through civil actions and seek damages.

Image for Employment: artificial intelligence.

Employment: artificial intelligence.

Requires a state study on artificial intelligence's impact on jobs and worker well-being in California. Mandates the UCLA Labor Center to conduct the comprehensive workforce impact study. Sets a June 2027 deadline for submitting study findings to the state Legislature.

Employment: artificial intelligence.

Image for Employment: artificial intelligence.

Requires a state study on artificial intelligence's impact on jobs and worker well-being in California. Mandates the UCLA Labor Center to conduct the comprehensive workforce impact study. Sets a June 2027 deadline for submitting study findings to the state Legislature.

Image for Data brokers: data collection and deletion.

Data brokers: data collection and deletion.

Requires data brokers to register annually and disclose the data they collect. Mandates an accessible deletion mechanism with 45-day processing and no fee. Prohibits public disclosure of certain sensitive data on the agency site. Requires independent audits of data brokers every three years starting 2028.

Data brokers: data collection and deletion.

Image for Data brokers: data collection and deletion.

Requires data brokers to register annually and disclose the data they collect. Mandates an accessible deletion mechanism with 45-day processing and no fee. Prohibits public disclosure of certain sensitive data on the agency site. Requires independent audits of data brokers every three years starting 2028.

Image for Deepfake pornography.

Deepfake pornography.

Expands liability for digitized sexually explicit material and deepfake pornography. Adds claims for minor victims and for those who knowingly facilitate the acts. Presumes deepfake service owners knew lack of consent unless consent shown. Imposes a 30-day halt for providers after evidence and expands penalties.

Deepfake pornography.

Image for Deepfake pornography.

Expands liability for digitized sexually explicit material and deepfake pornography. Adds claims for minor victims and for those who knowingly facilitate the acts. Presumes deepfake service owners knew lack of consent unless consent shown. Imposes a 30-day halt for providers after evidence and expands penalties.

Image for Food delivery platforms: customer service.

Food delivery platforms: customer service.

Strengthens price integrity, tipping protections, and pay transparency. Mandates itemized cost disclosures to customers, facilities, and drivers. Establishes a refund framework with gratuity refunds for non-delivery, wrong orders, and partial orders. Requires live customer service access with escalation and limits listing-site direct communication.

Food delivery platforms: customer service.

Image for Food delivery platforms: customer service.

Strengthens price integrity, tipping protections, and pay transparency. Mandates itemized cost disclosures to customers, facilities, and drivers. Establishes a refund framework with gratuity refunds for non-delivery, wrong orders, and partial orders. Requires live customer service access with escalation and limits listing-site direct communication.

Image for California Consumer Privacy Act of 2018: opt-out preference signal.

California Consumer Privacy Act of 2018: opt-out preference signal.

Requires browsers to include a consumer-configurable opt-out signal by January 1, 2027. Mandates public disclosures explaining how the opt-out signal works and its effect. Grants immunity to browser developers for violations by downstream recipients. Authorizes CPPA to adopt regulations to implement and administer the provision.

California Consumer Privacy Act of 2018: opt-out preference signal.

Image for California Consumer Privacy Act of 2018: opt-out preference signal.

Requires browsers to include a consumer-configurable opt-out signal by January 1, 2027. Mandates public disclosures explaining how the opt-out signal works and its effect. Grants immunity to browser developers for violations by downstream recipients. Authorizes CPPA to adopt regulations to implement and administer the provision.

Image for Health care professions: deceptive terms or letters: artificial intelligence.

Health care professions: deceptive terms or letters: artificial intelligence.

Prohibits AI/GenAI from using terms that imply licensure to practice health care. Enforces by licensing boards with injunctive relief and separate violations. Leaves penalties undefined; enforcement relies on boards, creating a state-mandated local program.

Health care professions: deceptive terms or letters: artificial intelligence.

Image for Health care professions: deceptive terms or letters: artificial intelligence.

Prohibits AI/GenAI from using terms that imply licensure to practice health care. Enforces by licensing boards with injunctive relief and separate violations. Leaves penalties undefined; enforcement relies on boards, creating a state-mandated local program.