Loop + Ledger Signal States California
Signal · California Live

What does California require right now?

The current bills, deadlines, enforcement patterns, and what your district should actually be doing about it · curated by Loop + Ledger.

Active Legislation Updated Aug 04, 2026 Source leginfo.legislature.ca.gov
Laws tracked
17
In this state
Enacted
11
On the books
In motion
6
Actively moving
On the books
What's the law in California?
Enacted
CA SB 942 (2024)
AI providers must disclose when content is AI-generated through watermarking or embedded metadata. Applies to audio, visual, and written content produced by AI systems distributed to consumers. Consumers must be able to verify AI origin of content.
Effective: Aug 02, 2026 Source →
Enacted
SB 243 (2025-26)
Regulates AI companion chatbot systems interacting with minors: disclosures that chatbots are not human, break reminders for minors, restrictions on sexual content involving minors, and self-harm/suicide-prevention protocols with crisis referrals. Signed into law October 2025; effective January 1, 2026. Serving as a model for other states' child-safety chatbot bills.
Effective: Jan 01, 2026 Source →
Enacted
CA SB 362 (2023)
All registered data brokers must honor deletion and opt-out requests through a single CPPA-operated DELETE portal. Brokers must perform 45-day deletion sweeps after each opt-out submission. Non-compliance: $200 per day per violation. Applies to any entity that buys and sells personal data without direct consumer relationship.
Effective: Jan 01, 2026 Source →
Enacted
CA SB 53 (2025)
Requires developers of large frontier AI models (companies with $500M+ annual revenue) to publish risk frameworks, report safety incidents to the state AG, and implement whistleblower protections for employees who report AI safety concerns. Penalties up to $1 million per violation.
Effective: Jan 01, 2026 Source →
Enacted
Cal. Civ. Code § 1798.100 et seq.
Grants consumers rights to access, delete, correct, and opt out of sale/sharing of personal data. 2026 ADMT regulations add mandatory opt-out mechanisms for automated decision-making that replaces human judgment, risk assessments for sensitive data processing, and cybersecurity audits defining reasonable security measures.
Effective: Jan 01, 2026 Enforcement: $2,500 per unintentional violation; $7,500 per intentional violation. $100-$750 per consumer per data breach incident. CPPA and AG enforcement. Cure period eliminated Jan 2023. Source →
Enacted
CA AB 45 (2025)
Prohibits collection of personal data from individuals at reproductive health centers. Bans geofencing around healthcare facilities for advertising or tracking purposes. Covers location data, app data, and any data collected near protected health sites including counseling centers and clinics.
Effective: Jan 01, 2026 Source →
Enacted
CA AB 2013 (2024)
Generative AI developers must publish annual summaries of training datasets including data sources, types, licensing, intellectual property information, and whether personal data was used. Summaries must be posted publicly on the developer's website.
Effective: Jan 01, 2026 Source →
Enacted
11 CCR § 7001 et seq. (ADMT Regs)
Requires businesses using automated decision-making tools that substitute for human judgment to provide pre-use notices and consumer opt-outs. Annual cybersecurity audits required defining 'reasonable security.' Risk assessments mandatory for sensitive data processing. Full opt-out provisions for all ADMT effective Jan 1, 2027.
Effective: Jan 01, 2026 Source →
Enacted
Cal. Bus. & Prof. Code §22584
Prohibits EdTech operators from using student data for targeted advertising or building behavioral profiles.
Enacted
SB 1288 (2024)
Establishes a working group on AI use in public schools to develop a model policy on safe and effective AI use in K-12. Working group must address classroom deployment, student data protections, equity, and teacher professional development. Guidance from working group expected to become de facto standard for district AI policies.
Enacted
AB 2885 (2024)
Establishes a single unified definition of 'artificial intelligence' across California statutes (based on the OECD 2023 definition), preventing a patchwork of conflicting definitions. Chaptered September 2024. Does not direct the CDE to issue K-12 AI guidance (that function sits with SB 1288's working group / AB 2876 curriculum provisions).
In motion
What's active right now?
PENDING
CA AB 2575 (2025-26)
Would require healthcare AI systems to disclose when AI is used in clinical decision-making, obtain patient consent for AI-informed diagnoses or treatment recommendations, and maintain audit trails for all AI-assisted clinical decisions. Passed Assembly; pending Senate.
PENDING
CA AB 1883 (2025-26)
Would require employers to disclose use of electronic surveillance and AI-powered monitoring tools to employees in advance and in writing. Covers biometric monitoring, communications surveillance, productivity tracking, and behavioral analysis tools. Passed Assembly; pending Senate and governor.
PENDING
CA SB 867 (2025-26)
Imposes a moratorium (through January 1, 2031) on manufacturing, selling, or possessing for sale toys that include AI companion chatbots; enforceable by civil action ($1,000 statutory damages per violation or actual damages). Does NOT itself impose parental-consent or crisis-protocol mandates — those obligations come from SB 243 (2025). Passed Senate; in Assembly committee as of June 2026.
IN COMMITTEE
SB 420 (2025-26)
Would establish a state-level AI bill of rights and impose impact assessment and transparency requirements on high-risk AI systems in high-stakes domains including employment, housing, and access to essential services. Developers and deployers must document risks and protections. Would make California the strictest U.S. state on high-risk AI and algorithmic accountability, likely setting de facto national standards. Advanced in 2025; still moving in 2026.
IN COMMITTEE
AB 1018 (2025-26)
Would impose disclosure and fairness requirements on AI systems used in high-impact decisions including hiring, housing, and essential services. Organizations using AI for consequential decisions must inform individuals and provide fairness protections. Part of California's move toward sectoral automated decision-making regulation. Advancing through 2026.
IN COMMITTEE
AB 1159 (2025-26)
Creates the Higher Education Student Information Protection Act (HESIPA), extending K-12-style student data privacy protections to college and university students. Prohibits EdTech operators from using student data to train AI systems (deidentified data permitted), requires data minimization, bars collection of sensitive categories, and adds a private right of action. In committee as of early 2026.
Book a working session
A 20-minute working session on California compliance.
We show up with the actual bill language, your high-risk vendor exposures, and what to do about it before the next deadline.
Book California session →
← Back to all 50 states