Cal. Bus. & Prof. Code, Chapters 22.2 · 22.2.5 · 22.2.6 (KOPIPA · ELPIPA · HESIPA), amended and added by Ch. 182, Stats. 2026
Jan 1, 2027 (KOPIPA, ELPIPA) · July 1, 2027 (HESIPA)
Operators of sites, services, and apps designed or marketed for K-12, preschool, or postsecondary use - and entities working on their behalf
September 14, 2026
The short version
On September 10, 2026, Governor Newsom signed AB 1159 (Addis) as Chapter 182, Statutes of 2026. With it, 2.9 million California college students now sit under the same style of vendor-privacy regime that has governed K-12 for a decade - the reach of the Higher Education Student Information Protection Act, or HESIPA, the new Chapter 22.2.6 the bill adds to the Business and Professions Code.
AB 1159 does three things at once. It amends KOPIPA, the K-12 Pupil Online Personal Information Protection Act at Chapter 22.2, to add an AI-training-use prohibition, a sensitive-categories bar, new retention and deletion duties, and a private right of action. It amends ELPIPA, the Early Learning Personal Information Protection Act covering preschool and pre-K vendors, in parallel. And it creates HESIPA to carry the K-12 vendor model into higher education, with the same duties.
The single sentence every district and every vendor needs to price sits in § 22584(b)(5) and its ELPIPA and HESIPA parallels: an operator may not use covered student information to train a generative AI system or service, or to develop an AI system. "Train" and "artificial intelligence" cross-reference the definitions in Civil Code § 3110. K-12 and preschool operators are covered January 1, 2027. Higher ed follows July 1, 2027.
Before AB 1159, KOPIPA barred K-12 operators from targeted advertising, from selling covered information, and from disclosing it except in narrow circumstances. Training AI on covered information wasn't on the list. Vendors that used student text, engagement telemetry, or assessment responses to train models argued the practice was neither an ad, nor a sale, nor a prohibited disclosure. AB 1159 closes the argument at § 22584(b)(5), and adds the same prohibition to ELPIPA at § 22586(b)(5) and to the new HESIPA at § 22587(b)(5).
The new AI bar is a use-restriction, not a disclosure rule. Written consent from a district, a parent, or a student doesn't cure it, because the prohibition binds the operator directly. The one real caveat sits at § 22584(c) and its ELPIPA and HESIPA parallels: subdivision (b) "does not prohibit the operator's use of information for maintaining, developing, supporting, improving, or diagnosing the operator's site, service, or application." That clause survived the amendment untouched. It isn't a consent gate, it's a product-improvement gate, and it's the sentence vendor counsel will cite back at any district raising the new AI bar.
The bill also adds a sensitive-categories prohibition at § 22584(b)(6), with parallels in ELPIPA and HESIPA: an operator may not collect, use, retain, or disclose covered information relating to a pupil's immigration status, reproductive or sexual health, or sexual orientation or gender identity. HESIPA extends the list with precise geolocation. For a California district this September, the immigration-status line is arguably the headline of the entire bill.
Retention and deletion duties tighten at § 22584(d). Operators must retain covered information only as long as reasonably necessary for the purpose collected; must maintain a written data-retention policy stating collection purpose, retention purpose, and deletion timeframe, available on request to a pupil, parent, guardian, education-rights holder, or K-12 personnel; and must delete covered information on request from the school, or from a parent or former pupil aged 18 or older after unenrollment, subject to the mandatory permanent pupil records under 5 CCR 430. Reach extends to entities working on behalf of the operator.
The reach test is easiest to trace by asking three questions in order.
Is the operator covered? New § 22584(a)(10)(A) defines an operator as any operator, or entity working on its behalf, of a site, service, or application "with actual knowledge that the site, service, or application is used for K-12 school purposes and was designed or marketed for K-12 school purposes." Three shifts from prior law matter. First, "primarily" is gone - a service used for K-12 purposes and other purposes can still be in scope. Second, "and" became "or" - a service either designed for K-12 or marketed to K-12 is now covered. Third, entities working on behalf of the operator are pulled in explicitly. A general-purpose consumer platform a district knowingly deploys to students is closer to in-scope under the new test than under the old one.
Is the information covered? Covered information under KOPIPA includes information created or provided by a student or parent to the operator, information created or provided by an employee or agent of the school, and information gathered by the operator through the operation of its service. The operator's own inferences drawn from that data are covered too.
Is the use prohibited? The two prohibited uses under the new AI subsection are training a generative AI system or service and developing an AI system, both taking the definitions in Civil Code § 3110. Two carve-outs live inside KOPIPA that vendors will position around: § 22584(f) permits an operator to use deidentified pupil covered information within its own products to improve them and to demonstrate their effectiveness, including in marketing; § 22584(g) permits sharing aggregated deidentified pupil covered information for the development and improvement of educational products. The compliance route most vendors will take is deidentification, which shifts the question from "is training permitted" to "does the vendor's deidentification method hold."
For most K-12 EdTech products with an AI feature roadmap, the answer to all three questions is yes, and the follow-on question is what deidentification looks like in the vendor's pipeline.
The enforcement architecture changed materially. AB 1159 creates a private right of action across all three acts - new § 22585 (KOPIPA), new § 22586.1 (ELPIPA), new § 22587.1 (HESIPA). A pupil or student who suffers actual damages, or their parent, guardian, or education-rights holder, may sue on their own behalf and on behalf of a similarly situated class for:
Pre-suit notice is 60 days by certified mail. The operator defeats an individual claim by showing correction within 60 days of notice, and a plaintiff must furnish the complaint to the Attorney General within 10 days of filing.
Context makes the change land. Eleven years of KOPIPA produced roughly one AG enforcement action; the exposure until now was AG-capacity-limited. It no longer is. Two live reference points show what the two enforcement tracks look like:
The Illuminate Education multistate settlement - $5.1 million total, announced November 2025 with California, Connecticut, and New York, pled under KOPIPA - is the AG-track reference for the exact statute AB 1159 amends. The PowerSchool / Naviance settlement - $17.25 million, approved February 2026, a private class action with Chicago Public Schools - is the private-track reference. AB 1159 makes an action shaped like the second one routine against California operators.
For vendors, the exposure is enforcement plus procurement. A California district that discovers at renewal that its vendor used covered student information to train AI has grounds for non-renewal that survive any contractual notice requirement, because the underlying use was statutorily barred. That's a materially different negotiating position than a general privacy dispute - and now one supported by the plaintiff bar's economics under § 22585.
For districts, the exposure is contractual. A district that renews a DPA with a vendor whose AI-training practices violate AB 1159 has knowingly contracted for a service the operator is prohibited from providing. Whether that reaches a district's own liability depends on facts not yet tested, but it weakens the district's position in the parent complaint and the AG inquiry that are, together with the § 22585 private action, now the three exposure surfaces.
Districts should raise these at the next cabinet meeting, and again at the next board meeting.
Beginning January 1, 2027, operators covered by KOPIPA and ELPIPA may not use covered student information to train a generative AI system or service, or to develop an AI system. The same prohibition extends to HESIPA operators beginning July 1, 2027. In parallel, all three acts add a sensitive-categories bar, require written retention policies and honored deletion requests, and create a private right of action with a $500-per-violation floor. Consent doesn't cure the AI bar; § 22584(c) preserves use for maintaining, developing, supporting, improving, or diagnosing the operator's own product.
Every California-facing DPA needs an AI-training-use attestation and a written retention policy before renewal. The priority list is any vendor that has added an AI feature or announced an AI roadmap in the last twelve months. The pre-January-2027 renewal window is the easier conversation; after that, the prohibition is operative. The split clock changes how you scope the postsecondary side: any vendor marketed for higher education that touches your dual-enrollment or early-college students flips to HESIPA on July 1, 2027, while the rest of your stack is already under the K-12 amendments from six months earlier. Ask the split question at the vendor, not at the partner institution - a community college partner itself carries no HESIPA duty. And any state-funded TK or preschool program brings ELPIPA vendors into the same clock. The immigration-status prohibition is the item that will move to the top of your parent-facing communications in January.
Training-data provenance has to be defensible and attestable in writing, not verbally reassuring. The § 22584(c) product-improvement carve-out is the position most vendors will take; the ones that document how their training pipeline sits within (c) - and that separate that documentation from any use of deidentified information under (f) or (g) - will win the next procurement cycle. The ones that can't answer where a model was trained, on what data, and under what licensing terms will lose renewals, and under the new § 22585 private right of action will find those non-renewals accompanied by class-action exposure at $500 per plaintiff per violation.
We run DPA review against the PURPOSE framework, and California DPAs are already in the queue this quarter. The California scope adds an AB 1159 attestation module that asks the vendor whether covered information enters training or development pipelines, whether the vendor relies on § 22584(c), (f), or (g) as the basis for any use, and how the vendor documents deidentification. The review report flags where a vendor's answer is incomplete, evasive, or contradicted by its own product documentation. Districts already in DPA review pick up the module without a scope change.
AB 1159 doesn't sit alone. Read against the twelve other bills the Governor signed the same day, the shape of California's approach to child data in AI becomes visible. The state is treating training data as a distinct regulatory surface, separate from user-facing AI behavior: AB 1159 restricts what data enters a model; SB 1119 and SB 867 restrict how companion chatbots interact with children once released; AB 2246 restricts what a model can do with a child's data at the interface layer. Compliance with any one doesn't satisfy the others.
The parallel Higher Education Student Information Protection Act is the medium-term signal. K-12 privacy has been a legislated space for a decade; postsecondary privacy hasn't. HESIPA is arguably the broadest state extension to date of K-12-style vendor duties into higher education, reaching roughly 2.9 million California college students per the Assembly Privacy Committee analysis. States that modeled their own K-12 privacy laws on the KOPIPA-family template - Illinois SOPPA, Colorado's Student Data Transparency and Security Act, Connecticut's Act Concerning Student Data Privacy - are the likely fast followers.
One in-record proof point matters for vendors reading this: CSU has already negotiated a contractual bar with OpenAI against using student data for training, and the legislative record notes it. The "no vendor can attest to this" objection has already been answered from a California institution, and can be pointed at when a district is told the ask is unreasonable.
AB 1159 sits alongside other laws with related reach, and three crosswalks matter for anyone whose compliance surface extends beyond California.
Against the rest of the September 10 package. Two of the thirteen land directly on K-12 districts: AB 302 (Bauer-Kahan) on addictive feeds in student communication platforms, and SB 1128 (Stern) on technology materials on school-issued devices. Two more govern AI companion chatbots: SB 1119 (Padilla, Wicks, Bauer-Kahan) on chatbot operators, and SB 867 (Padilla) on companion chatbots in toys. AB 2246 (Wicks) is best described as a narrowed recodification of the surviving AADC provisions - it moves those pieces into new code sections and further narrows certain provisions against the First Amendment challenge that enjoined AB 2273, which itself stays on the books and in litigation.
Against federal statute. FERPA governs education records held by educational agencies and institutions; it addresses disclosure and permits written consent. COPPA covers operators of services directed at children under 13, or with actual knowledge of collecting from them. AB 1159 governs operators of services designed or marketed for K-12, preschool, or postsecondary purposes; addresses use rather than disclosure; and admits no consent cure for its AI bar. It fills gaps FERPA and COPPA leave for California-facing operators.
Against other states' student-data laws. Illinois SOPPA, Colorado's Student Data Transparency and Security Act, and Connecticut's Act Concerning Student Data Privacy all use an operator definition substantially modeled on California's original KOPIPA vehicle. None of them, as of this brief's verification date, prohibits AI training on covered information or extends the same regime to higher education. Operators serving multiple states should treat the California approach as the ceiling other KOPIPA-modeled states move toward.
Two open questions we're watching, and the sooner they resolve, the sharper the compliance picture.
The first is how far Civil Code § 3110 - the definition AB 1159 cross-references for "train" and "artificial intelligence" - reaches into activities adjacent to base-model training: fine-tuning, retrieval-augmented generation, and reinforcement from human feedback. This is a readable-today question, not a wait-for-AG question. The § 3110 definition either encompasses those techniques or it doesn't, and the answer changes vendor architectures. AG guidance would settle a secondary layer - how § 3110 as incorporated by § 22584(b)(5) is enforced in a given fact pattern - but the primary question sits in existing Civil Code text.
The second is the school-sponsored versus informal-use ambiguity created by dropping "primarily" from the operator test. Under old KOPIPA, an operator was in scope only if its site was used primarily for K-12 purposes. Under new § 22584(a)(10)(A), that qualifier is gone. A general-purpose service a district knowingly deploys to students - a communication platform, a scheduling tool, a productivity suite - is closer to in-scope than it was, but the statute doesn't draw the line between "the school uses it" and "students use it in ways the school neither authorized nor prohibited." Vendors on that boundary have no answer on the face of the bill. Watch for early litigation to draw the line, and which side draws it first.
California districts: book a scoping call to review your top ten vendor DPAs against AB 1159 and return a prioritized renewal plan within two weeks. The plan sorts renewals by the January 1, 2027 K-12 effective date and the July 1, 2027 HESIPA date, flags the § 22584(c) reliance question for each vendor, and identifies which contracts touch the sensitive categories now barred.
Vendors serving California K-12, preschool, or higher education: book a scoping call to work through your AI-training-data provenance, your position on § 22584(c), (f), and (g), and the attestation language your district customers will require at the next renewal - and that plaintiffs' counsel will subpoena in a § 22585 action.
Read against the chaptered text of AB 1159 (Chapter 182, Statutes of 2026, signed September 10, 2026), last verified September 14, 2026.
This piece is provided for informational and educational purposes only and isn't legal, regulatory, or compliance advice. References to AB 1159 and the KOPIPA, ELPIPA, and HESIPA acts are general context on an evolving governance landscape, not a definitive statement of any district's or vendor's obligations. Every organization's technology environment, contracts, and governance practices are different. Leaders should consult legal counsel and their own technology leadership on how state and federal law applies to their circumstances. Loop + Ledger is an independent technology governance advisory firm. We don't provide legal services, legal opinions, or compliance determinations.