web analytics
State AI Laws

California AI Laws

AB 2013, SB 942, AB 3030, and more

The one-paragraph answer

California AI laws are the largest stack of AI-specific legislation in the United States. California has not passed a single comprehensive AI act. Instead, it has passed dozens of targeted laws covering training data disclosure (AB 2013), AI content labeling (SB 942), healthcare AI (AB 3030), employment AI, AI in political advertising, and generative AI transparency. Any company touching California users needs to comply with the stack, not just one law.

The pain California AI laws are causing our customers

Executives ask for "the California AI law." There is no single law. There is a stack. Companies operating in California, or with California users, are dealing with a rolling series of new obligations covering different slices of AI activity. Each law has its own effective date, its own definitions, its own enforcement mechanism, and its own penalty structure. Keeping the map current is a full-time compliance job.

The pain is stacking obligations without a unifying framework. Unlike the Colorado AI Act, which covers all "high-risk" AI in one law, California prefers narrow, targeted laws. That gives clearer scope per law but creates coordination cost across laws. Missing one because you thought you were compliant with another is a common failure pattern.

The California AI laws stack, in operating order

AB 2013 (Generative AI Training Data Transparency)

Signed in 2024, effective January 1, 2026. Requires developers of generative AI systems used or made available in California to post on their websites documentation about training data: sources, size, description, whether personal information or copyrighted material is included, and modifications made. Applies to models released or substantially modified from January 1, 2022 onward. Enforced by the California Attorney General.

SB 942 (California AI Transparency Act)

Signed in 2024, effective January 1, 2026. Requires "covered providers" of generative AI systems to provide free AI detection tools, apply latent disclosures to AI-generated content, and offer manifest disclosures on request. A covered provider is one whose system has over one million monthly California users.

AB 3030 (Healthcare AI Disclosure)

Signed in 2024, effective January 1, 2025. Requires healthcare providers using generative AI to communicate with patients about clinical information to disclose that AI was used and provide clear instructions for reaching a human. This is arguably the first US state law regulating clinical AI communications.

SB 1001 (Bolstering Online Transparency Act, "Bot Disclosure")

Effective 2019, ongoing. Requires bots that attempt to influence commercial or political decisions to identify themselves as bots. Applies to chatbots, automated messaging, and AI-driven agents.

AB 2655 and AB 2839 (Political AI)

Regulate AI-generated political content and deepfakes in elections, though implementation has been affected by ongoing First Amendment litigation. Companies whose products are used in political advertising need to track the status.

The CPPA's ADMT regulations, the biggest one nobody lists

The California Privacy Protection Agency finalised regulations on automated decision-making technology under the CCPA/CPRA. They are distinct from every statute above, and they are the closest thing California has to a comprehensive AI decision law. Businesses using ADMT for a significant decision (employment, lending, housing, education, healthcare) owe consumers pre-use notice, a right to opt out, and a right to access meaningful information about the logic. Risk assessments are required for higher-risk processing. Obligations phase in from 2027, with the first risk-assessment attestations due to the Agency thereafter.

If your California AI compliance plan covers AB 2013 and SB 942 but not the ADMT regulations, it is missing the piece that most closely resembles the Colorado regime that was repealed. California kept, through its privacy agency, roughly what Colorado gave up.

Employment AI laws

California civil rights agencies have issued regulations under existing state anti-discrimination law that apply to AI in employment decisions. The California Civil Rights Council's automated-decision-systems regulations effectively add impact assessment and bias testing obligations to any employer using AI in hiring, promotion, or termination decisions in California.

Why California AI laws matter to you

California has 39 million residents, the world's fifth-largest economy, and a plaintiffs' bar highly active in consumer protection and privacy litigation. Any AI system used by California residents is potentially in scope. Enforcement risk is real (the California Attorney General, the California Civil Rights Department, and city attorneys all have enforcement authority). Private right of action exists for several laws in the stack.

California AI laws also shape national practice by market force. When a large software company complies with California's stack for California users, it usually applies the compliance uniformly across all users because segregating by state is impractical. This means California AI laws effectively set the national floor for many AI transparency obligations.

What the research says about California AI laws

The academic literature on California AI laws is ahead of most corporate practice, and it is unusually blunt. Two findings are worth putting in front of any executive who thinks this is a compliance formality.

“concerns about their impact on individual and societal wellbeing, particularly due to the lack of transparency and accountability”

That is the gap between having AI and governing it. The second finding is the one that tends to change the room.

“all those who are involved in the research, development and maintenance of AI systems have social and ethical responsibilities”

Neither of these is a fringe position. Both come from peer-reviewed work, and both describe the condition most organisations are actually in when the question about California AI laws arrives from the board, the buyer, or the regulator.

How to get compliant with California AI Laws: a 5-step path

This is the sequence that works, and it is not the sequence most organisations choose. They start with the framework and work backwards toward reality. Start with reality.

  1. Inventory the AI in scope. List every AI system that could fall under California AI laws. Record what it does, what decision it influences, what data it touches, and who owns it. You cannot govern AI you cannot name, and almost every organisation we assess is running more AI than its leadership believes.
  2. Determine whether you are actually in scope. Work out precisely which of your AI systems and activities California AI laws reaches, and write the determination down with its reasoning. Do this in writing. A documented scope determination, right or wrong, is defensible. An undocumented assumption is not.
  3. Assign one accountable owner. Name a person, not a committee, with the authority to stop a deployment. Governance without someone who can say no is documentation, not control.
  4. Build the evidence file. Assemble the documentation California AI laws expects: the scope, the risk assessment, the controls, the testing evidence, and the incident record. Assemble it before anyone asks. Reconstructing it under a regulator's deadline costs several times more and looks exactly like what it is.
  5. Set a review cadence and hold it. Re-run the assessment on a schedule and after any material change to the model, the data, or the use case. Alignment decays. A control tested once is a snapshot, not a control.

Done in this order, California AI laws becomes tractable. Done out of order, it becomes a document nobody uses and a control nobody exercises.

Frequently asked questions about California AI laws

Do we need to comply if we are not based in California?

Yes, if California residents use your AI systems. Extraterritorial reach is the norm, not the exception.

Which of the California AI laws is the most urgent?

For generative AI providers, AB 2013 and SB 942 both take effect January 1, 2026, so both need attention now. For healthcare organizations, AB 3030 is already in effect (January 2025). For employers, the California Civil Rights Council regulations are in effect now.

How do California AI laws interact with CCPA/CPRA?

CCPA/CPRA covers personal data. California AI laws cover AI decision-making and transparency. Many systems trigger both. Integrated compliance is required.

Where do California AI laws fit in SRJ's work?

The AI Business Enablement Audit™ includes a California-specific compliance overlay. Volume III of The Operating Discipline for AI Library™ maps operating artifacts to individual California statutes in Appendix L.

Primary sources on California AI laws

The authoritative texts and agency pages behind this summary. We keep this page current, but where a compliance decision turns on exact wording, read the source. Anything concerning California AI laws that carries legal consequence should be confirmed against the enrolled text or the issuing body, not against a secondary summary, including this one.

Ready to see where you stand?

The AI Business Enablement Audit™ measures your organization against every framework in this library, including California AI Laws, and delivers a defensible governance dossier. Start or finish your audit below.

Start or finish your AI Audit →
Schedule a Free AI Consultation