Skip to content

California AI readiness

Selected California AI requirements and deadlines

This page covers selected California requirements most relevant to operational AI readiness. It is not a complete inventory of California laws that may apply to an AI system or organization.

Current as of 2026-09-26. Selected requirements and deadlines from 2025 through 2029. General information, not legal advice.

In this sectionOverview

The selected materials address privacy, automated decisions, employment, transparency, frontier models, healthcare and AI audit providers. Start with the legal entity, activity, system and affected people. Then examine the text that governs that situation and the evidence needed to support the work.

Status labels matter. Enacted statutes and operative final regulations are binding within their stated scope and effective dates. A statute or regulation with a future operative or compliance date may establish future duties, but those duties are not yet current compliance obligations. Official guidance and agency information are nonbinding unless a legal source gives them another effect. Requested recommendations and incomplete agency implementation remain pending or unresolved. Intelligence Coalition recommendations describe readiness work and are not legal requirements.

California AI regulation at a glance

AreaWho should examine itOperational issueEffective or compliance dateSource status
Privacy risk assessmentsCCPA businesses engaged in listed high risk processingassessment before new processing; assessment of continuing processing; executive attestation and submissioneffective 2026-01-01; continuing activities due 2027-12-31; first submission 2028-04-01final regulation Sources: CPPA approved regulations.
Automated decisionmakingCCPA businesses using ADMT to make a significant decisionpre-use notice, access and opt-out rights, subject to specified exceptions including a qualifying human appeal process; request handling and vendor supportcompliance begins 2027-01-01final regulation Sources: CPPA final rulemaking page; CPPA approved regulations.
Employment automated decision systemsCalifornia employers and other covered entities using automated systems in employment decisionsdiscrimination, records, disability related inquiries, vendor and agent responsibilityeffective 2025-10-01final regulation Sources: Civil Rights Council rulemaking actions.
Generative AI training dataDevelopers making covered generative AI systems available to Californianspublic training data documentation and release processoperative 2026-01-01statute Sources: AB 2013.
Synthetic content provenanceCovered generative AI providers; later duties for some platforms and capture device manufacturersdetection tools, manifest and latent disclosures, provenance handlingprovider duties operative 2026-08-02; some platform duties 2027-01-01; capture device manufacturer duties 2028-01-01statute Sources: SB 942; AB 853.
Frontier model safetyFrontier developers above the statutory compute threshold, with added duties for large frontier developers above the statutory revenue thresholdfrontier developers: transparency reports, critical safety incident reporting and whistleblower protections; large frontier developers also: a published frontier AI framework covering catastrophic risk assessment and unreleased model weight security, catastrophic risk assessment summaries and an anonymous internal reporting processeffective 2026-01-01statute Sources: SB 53.
Healthcare AIListed healthcare settings, health plans, disability insurers and AI health product developers or deployerspatient disclosure, human contact, utilization review limits, clinical decision authority and truthful presentation2025-01-01 and 2026-01-01, depending on the statutestatutes Sources: AB 3030; SB 1120; AB 489.
AI auditors and independent verificationAI audit providers and auditors seeking state designationauditor registration, independence, designation standards and pending agency implementationagency setup deadlines accelerated into 2027; covered audit practice restriction begins 2029-01-01statutes and executive order Sources: SB 813; AB 1405; Executive Order N-9-26.

This table is a screening aid, not an applicability conclusion. A legal review must use the current codified text, the entity's facts and any sector rules.

Which selected requirements should your organization examine?

Use these questions to identify sources that need closer review. They do not decide whether a requirement applies to a particular organization or system.

  • Do you use a system to make or substantially make decisions about lending, housing, education, employment, independent contracting or healthcare?
  • Does the system process personal information about California consumers, applicants, workers or patients?
  • Do you use automated systems to recruit, screen, rank, hire, assign work, set compensation, promote, discipline or terminate workers?
  • Do you develop a generative AI system or substantially modify one for public use in California?
  • Does your system generate image, audio or video content for users?
  • Do you operate a large online platform or host generative AI model code or weights?
  • Do you train a foundation model above the compute threshold in SB 53?
  • Do you use generative AI for patient communications or software for healthcare utilization review?
  • Do you sell AI audit services or plan to rely on a state designated independent verification organization?
  • Can your vendors provide the logic, output records, data documentation, tests and change notices you need?

Each cited law or regulation has its own actors, activities, thresholds, exceptions and territorial terms. Record the source and relevant facts for each applicability conclusion rather than applying one answer across the selected requirements.

What matters now

Several duties are already in force. The employment automated decision system rules took effect in October 2025. Generative AI training data documentation and SB 53 took effect in 2026. The California AI Transparency Act became operative in August 2026. Healthcare AI duties under AB 3030, SB 1120 and AB 489 are also in effect. Sources: Civil Rights Council rulemaking actions; SB 53; AB 3030; SB 1120; AB 489; AB 2013; SB 942; AB 853.

The ADMT article has a January 1, 2027 compliance date for covered uses that began earlier. The regulation requires covered businesses to describe the system's role in a decision and respond to access requests. Preparing system, data and decision records before the compliance date is an Intelligence Coalition recommendation. Sources: CPPA approved regulations.

SB 813 directs the Government Operations Agency to establish a designation program for independent verification organizations. AB 1405 directs it to establish a registry and practice rules for providers of covered AI audits. Executive Order N-9-26 directs earlier agency work and requests recommendations on possible new frontier model duties. The requested recommendations are pending policy work, not enacted private sector requirements. Sources: SB 813; AB 1405; Executive Order N-9-26.

Operational readiness

The Intelligence Coalition uses the following sequence to turn legal questions into operating work. It is a readiness method, not a statutory checklist.

1. Inventory

List AI systems, models, vendors, use cases, affected decisions, data, legal entities and owners. Include systems embedded in HR, lending, healthcare, customer service and productivity software. Do not rely on a list of internally developed models.

2. Determine applicability

Map each requirement to the activity, system, person and legal entity it may cover. Record the basis for the conclusion and the facts that could change it.

3. Map controls

Identify the notices, rights handling, human review, discrimination testing, risk assessment, safety, security, incident, content disclosure and vendor controls each system needs.

4. Identify evidence

Name the records that should show the control operating. These may include notices, request logs, appeal decisions, risk assessments, tests, model cards, provenance records, training data documentation, approvals, incident reports and change records.

5. Test effectiveness

Check whether the controls work in realistic cases. A human appeal process is weak if the reviewer lacks time, information, skill or authority. A provenance control is weak if ordinary export or platform processing removes it.

6. Resolve dependencies

Find the vendor, data, model, engineering, procurement, legal and business dependencies that prevent compliance. Assign owners and dates rather than recording them as general gaps.

7. Prepare for review

Resolve material gaps before a regulator, customer, internal audit team or independent reviewer asks for proof. Keep the evidence tied to the relevant system version and period.

Common questions

What does this overview include?

This overview groups selected statutes and regulations by operational topic. It does not use "California AI Act" as the title for the collection. "California AI Transparency Act" is the name used for the synthetic content statute discussed here.

Which selected requirements are in effect in 2026?

The answer depends on the activity. Important 2026 requirements include generative AI training data documentation, the California AI Transparency Act, SB 53 frontier model duties, employment automated decision system rules and healthcare AI statutes. CPPA risk assessment duties also began in 2026, while the ADMT rights article has a January 1, 2027 compliance date.

What do the selected AI audit statutes require?

SB 813 directs the creation of a designation program for independent verification organizations. AB 1405 regulates providers of covered AI audits and sets a January 1, 2029 restriction on unregistered covered audit practice. Executive Order N-9-26 directs earlier agency setup. Determine any audit, assessment or review obligation from the source that governs the specific activity rather than inferring it from these provider statutes.

What evidence should a company keep?

The answer follows the applicable law and system. A useful starting set includes the system inventory, applicability decision, version records, data and model documentation, risk assessments, notices, request and appeal records, tests, approvals, incident records, vendor obligations and change history.

How is California different from the EU AI Act?

The EU AI Act is one cross-sector regulation built around defined roles, system categories and phased obligations. The selected California sources use different definitions, thresholds, agencies and dates. An organization examining both should not import EU classifications into a California analysis unless the relevant California source uses them.

What remains unsettled

  • Agency implementation of SB 813, AB 1405 and Executive Order N-9-26 is still in progress.
  • Recommendations requested by Executive Order N-9-26 may lead to proposed statutory changes, but they are not yet law.
  • The application of several rules depends on facts such as CCPA business status, human involvement, system purpose, personal information processing and vendor roles.
  • Insurance, lending, housing, education, children, elections, advertising, entertainment, companion chatbots, public procurement and algorithmic pricing are outside this selected baseline.
  • Litigation, later amendments and agency guidance may change how existing requirements operate.

Primary sources