AB 2013, SB 942, AB 3030, and more
The one-paragraph answer
California AI laws are the largest stack of AI-specific legislation in the United States. California has not passed a single comprehensive AI act. Instead, it has passed dozens of targeted laws covering training data disclosure (AB 2013), AI content labeling (SB 942), healthcare AI (AB 3030), employment AI, AI in political advertising, and generative AI transparency. Any company touching California users needs to comply with the stack, not just one law.
Executives ask for "the California AI law." There is no single law. There is a stack. Companies operating in California, or with California users, are dealing with a rolling series of new obligations covering different slices of AI activity. Each law has its own effective date, its own definitions, its own enforcement mechanism, and its own penalty structure. Keeping the map current is a full-time compliance job.
The pain is stacking obligations without a unifying framework. Unlike the Colorado AI Act, which covers all "high-risk" AI in one law, California prefers narrow, targeted laws. That gives clearer scope per law but creates coordination cost across laws. Missing one because you thought you were compliant with another is a common failure pattern.
Signed in 2024, effective January 1, 2026. Requires developers of generative AI systems used or made available in California to post on their websites documentation about training data: sources, size, description, whether personal information or copyrighted material is included, and modifications made. Applies to models released or substantially modified from January 1, 2022 onward. Enforced by the California Attorney General.
Signed in 2024, effective January 1, 2026. Requires "covered providers" of generative AI systems to provide free AI detection tools, apply latent disclosures to AI-generated content, and offer manifest disclosures on request. A covered provider is one whose system has over one million monthly California users.
Signed in 2024, effective January 1, 2025. Requires healthcare providers using generative AI to communicate with patients about clinical information to disclose that AI was used and provide clear instructions for reaching a human. This is arguably the first US state law regulating clinical AI communications.
Effective 2019, ongoing. Requires bots that attempt to influence commercial or political decisions to identify themselves as bots. Applies to chatbots, automated messaging, and AI-driven agents.
Regulate AI-generated political content and deepfakes in elections, though implementation has been affected by ongoing First Amendment litigation. Companies whose products are used in political advertising need to track the status.
The California Privacy Protection Agency finalised regulations on automated decision-making technology under the CCPA/CPRA. They are distinct from every statute above, and they are the closest thing California has to a comprehensive AI decision law. Businesses using ADMT for a significant decision (employment, lending, housing, education, healthcare) owe consumers pre-use notice, a right to opt out, and a right to access meaningful information about the logic. Risk assessments are required for higher-risk processing. Obligations phase in from 2027, with the first risk-assessment attestations due to the Agency thereafter.
If your California AI compliance plan covers AB 2013 and SB 942 but not the ADMT regulations, it is missing the piece that most closely resembles the Colorado regime that was repealed. California kept, through its privacy agency, roughly what Colorado gave up.
California civil rights agencies have issued regulations under existing state anti-discrimination law that apply to AI in employment decisions. The California Civil Rights Council's automated-decision-systems regulations effectively add impact assessment and bias testing obligations to any employer using AI in hiring, promotion, or termination decisions in California.
California has 39 million residents, the world's fifth-largest economy, and a plaintiffs' bar highly active in consumer protection and privacy litigation. Any AI system used by California residents is potentially in scope. Enforcement risk is real (the California Attorney General, the California Civil Rights Department, and city attorneys all have enforcement authority). Private right of action exists for several laws in the stack.
California AI laws also shape national practice by market force. When a large software company complies with California's stack for California users, it usually applies the compliance uniformly across all users because segregating by state is impractical. This means California AI laws effectively set the national floor for many AI transparency obligations.
The academic literature on California AI laws is ahead of most corporate practice, and it is unusually blunt. Two findings are worth putting in front of any executive who thinks this is a compliance formality.
“concerns about their impact on individual and societal wellbeing, particularly due to the lack of transparency and accountability”
That is the gap between having AI and governing it. The second finding is the one that tends to change the room.
“all those who are involved in the research, development and maintenance of AI systems have social and ethical responsibilities”
Neither of these is a fringe position. Both come from peer-reviewed work, and both describe the condition most organisations are actually in when the question about California AI laws arrives from the board, the buyer, or the regulator.
This is the sequence that works, and it is not the sequence most organisations choose. They start with the framework and work backwards toward reality. Start with reality.
Done in this order, California AI laws becomes tractable. Done out of order, it becomes a document nobody uses and a control nobody exercises.
Yes, if California residents use your AI systems. Extraterritorial reach is the norm, not the exception.
For generative AI providers, AB 2013 and SB 942 both take effect January 1, 2026, so both need attention now. For healthcare organizations, AB 3030 is already in effect (January 2025). For employers, the California Civil Rights Council regulations are in effect now.
CCPA/CPRA covers personal data. California AI laws cover AI decision-making and transparency. Many systems trigger both. Integrated compliance is required.
The AI Business Enablement Audit™ includes a California-specific compliance overlay. Volume III of The Operating Discipline for AI Library™ maps operating artifacts to individual California statutes in Appendix L.
The authoritative texts and agency pages behind this summary. We keep this page current, but where a compliance decision turns on exact wording, read the source. Anything concerning California AI laws that carries legal consequence should be confirmed against the enrolled text or the issuing body, not against a secondary summary, including this one.
The AI Business Enablement Audit™ measures your organization against every framework in this library, including California AI Laws, and delivers a defensible governance dossier. Start or finish your audit below.
Start or finish your AI Audit →