Signal · California Live
What does California require
right now?
The current bills, deadlines, enforcement patterns, and what your district should actually be doing about it.
curated by Loop + Ledger
Active Legislation Updated Sat Jul 25, 2026 Next deadline Aug 02, 2026 · CA SB 942 (2024) Source leginfo.legislature.ca.gov
Laws tracked
17
In this state
Enacted
10
On the books
In motion
7
Actively moving
Next deadline
Aug 02, 2026
CA SB 942 (2024)
Most recently enacted
What just became law?
Enacted
CA SB 942 (2024)AI Transparency Act
AI providers must disclose when content is AI-generated through watermarking or embedded metadata. Applies to audio, visual, and written content produced by AI systems distributed to consumers. Consumers must be able to verify AI origin of content.
— AI content watermarking is now law in CA — any platform producing AI-generated materials for districts needs disclosure mechanisms baked in before distribution.
Effective: Aug 02, 2026Source →
Effective
Aug 02
2026
Watch list
What's coming up?
02AUG
Effective CA SB 942 (2024)
Also on the books
What else is enacted?
Enacted
CA SB 362 (2023)California Delete Act (DROP System)
All registered data brokers must honor deletion and opt-out requests through a single CPPA-operated DELETE portal. Brokers must perform 45-day deletion sweeps after each opt-out submission. Non-compliance: $200 per day per violation. Applies to any entity that buys and sells personal data without direct consumer relationship.
— The CA Delete Act creates a single opt-out/deletion pipeline for data brokers — any platform monetizing student or district data needs to be registered and compliant by Jan 1, 2026.
Effective: Jan 01, 2026Source →
Enacted
CA SB 53 (2025)Transparency in Frontier AI Act
Requires developers of large frontier AI models (companies with $500M+ annual revenue) to publish risk frameworks, report safety incidents to the state AG, and implement whistleblower protections for employees who report AI safety concerns. Penalties up to $1 million per violation.
— California's frontier AI law puts transparency and incident reporting on the table for any large-scale AI vendor — if clients work with or near major AI platforms, new diligence obligations apply.
Effective: Jan 01, 2026Source →
Enacted
Cal. Civ. Code § 1798.100 et seq.California Consumer Privacy Act (CCPA / CPRA)
Grants consumers rights to access, delete, correct, and opt out of sale/sharing of personal data. 2026 ADMT regulations add mandatory opt-out mechanisms for automated decision-making that replaces human judgment, risk assessments for sensitive data processing, and cybersecurity audits defining reasonable security measures.
— CA leads the nation in privacy enforcement — the 2026 ADMT rules add a new compliance layer for any tech touching automated decisions about people. Districts using AI-driven platforms need to audit now.
Effective: Jan 01, 2026Enforcement: $2,500 per unintentional violation; $7,500 per intentional violation. $100-$750 per consumer per data breach incident. CPPA and AG…Source →
Enacted
CA AB 45 (2024)Consumer Health Data Privacy Law
Prohibits collection of personal data from individuals at reproductive health centers. Bans geofencing around healthcare facilities for advertising or tracking purposes. Covers location data, app data, and any data collected near protected health sites including counseling centers and clinics.
— CA health data protections include geofencing prohibitions — any mobile app or district tech collecting location data near school health or counseling facilities must review data practices.
Effective: Jan 01, 2026Source →
Enacted
CA AB 2013 (2024)AI Training Data Transparency Act
Generative AI developers must publish annual summaries of training datasets including data sources, types, licensing, intellectual property information, and whether personal data was used. Summaries must be posted publicly on the developer's website.
— Training data transparency is now a baseline for AI vendors operating in CA — any edtech or district AI tool should be disclosing its data lineage to comply.
Effective: Jan 01, 2026Source →
Enacted
11 CCR § 7001 et seq. (ADMT Regs)CCPA Automated Decision-Making Technology Regulations
Requires businesses using automated decision-making tools that substitute for human judgment to provide pre-use notices and consumer opt-outs. Annual cybersecurity audits required defining 'reasonable security.' Risk assessments mandatory for sensitive data processing. Full opt-out provisions for all ADMT effective Jan 1, 2027.
— CA's ADMT regs are the first state rules mandating opt-outs for algorithmic decisions — any AI platform making recommendations about students or staff in CA needs a compliance audit now.
Effective: Jan 01, 2026Source →
Enacted
SB 243 (2025-26)SB 243 — AI Companion Chatbots and Child Safety
Would regulate AI companion and chatbot systems interacting with minors, requiring: disclosures that chatbots are not human, restrictions on sexual content involving minors, and safeguards around self-harm content. Already serving as a model for other states' 2026 child-safety chatbot bills. Advancing in California legislature.
Enacted
SB 1288 (2024)SB 1288 — AI Working Group for Public Schools
Establishes a working group on AI use in public schools to develop a model policy on safe and effective AI use in K-12. Working group must address classroom deployment, student data protections, equity, and teacher professional development. Guidance from working group expected to become de facto standard for district AI policies.
Enacted
AB 2885 (2025)AB 2885 — K-12 AI Guidance Directive
Requires the California Department of Education to issue guidance on AI use in public schools, including AI literacy frameworks and ethical-use standards for districts. Covers classroom deployment, data privacy, and equity considerations. Districts expected to align local policies to state guidance once issued.
In motion
What's active right now?
IN COMMITTEE
SB 420 (2025-26)SB 420 — AI Bill of Rights / High-Risk AI Impact Assessments
Would establish a state-level AI bill of rights and impose impact assessment and transparency requirements on high-risk AI systems in high-stakes domains including employment, housing, and access to essential services. Developers and deployers must document risks and protections. Would make California the strictest U.S. state on high-risk AI and algorithmic accountability, likely setting de facto national standards. Advanced in 2025; still moving in 2026.
PENDING
CA AB 2575 (2025-26)Health Care Services: AI Disclosure
Would require healthcare AI systems to disclose when AI is used in clinical decision-making, obtain patient consent for AI-informed diagnoses or treatment recommendations, and maintain audit trails for all AI-assisted clinical decisions. Passed Assembly; pending Senate.
— CA is extending AI transparency into clinical care — any school district health or mental health tech using AI for student clinical decisions should track this closely.
PENDING
CA AB 1883 (2025-26)Workplace Surveillance Tools Disclosure
Would require employers to disclose use of electronic surveillance and AI-powered monitoring tools to employees in advance and in writing. Covers biometric monitoring, communications surveillance, productivity tracking, and behavioral analysis tools. Passed Assembly; pending Senate and governor.
— Workplace surveillance disclosure is moving fast in CA — any HR tech or monitoring platform used in schools or districts will likely fall under this once signed.
IN COMMITTEE
AB 1018 (2025-26)AB 1018 — Automated Decision-Making in High-Impact Areas
Would impose disclosure and fairness requirements on AI systems used in high-impact decisions including hiring, housing, and essential services. Organizations using AI for consequential decisions must inform individuals and provide fairness protections. Part of California's move toward sectoral automated decision-making regulation. Advancing through 2026.
IN COMMITTEE
AB 1159 (2025-26)AB 1159 — Bar on Student Data for AI Training
Would prohibit using student data to train AI models unless doing so directly benefits the school and stays tied to educational purposes. Closes gap in older student privacy statutes by explicitly targeting AI model training on K-12 data. Advancing through committee. If passed, vendor DPAs for AI tools in California schools will require explicit language on training-data usage and retention.
PENDING
CA SB 867 (2025-26)Companion Chatbots: Children's Safety
Prohibits AI companion chatbot providers from deploying to users under 18 without verified parental consent. Requires mandatory safety protocols, crisis escalation pathways to licensed mental health professionals, and data minimization for minor users. Passed Senate; pending Assembly and governor.
— AI chatbots in educational settings are under active scrutiny — CA's pending bill would require consent and mental health crisis protocols for any conversational AI used by minors.
ACTIVE
Cal. Bus. & Prof. Code §22584SOPIPA
Prohibits EdTech operators from using student data for targeted advertising or building behavioral profiles.
— Many free tools districts adopt have business models SOPIPA prohibits.
Enforcement teeth
Who enforces this — and what does it cost?
Cal. Civ. Code § 1798.100 et seq.
California Consumer Privacy Act (CCPA / CPRA)
$2,500 per unintentional violation; $7,500 per intentional violation. $100-$750 per consumer per data breach incident. CPPA and AG enforcement. Cure period eliminated Jan 2023.
Book a working session
A 20-minute working session on California compliance.
See clearly.
Act strategically.
Protect what matters.