The selected materials address privacy, automated decisions, employment, transparency, frontier models, healthcare and AI audit providers. Start with the legal entity, activity, system and affected people. Then examine the text that governs that situation and the evidence needed to support the work.
Status labels matter. Enacted statutes and operative final regulations are binding within their stated scope and effective dates. A statute or regulation with a future operative or compliance date may establish future duties, but those duties are not yet current compliance obligations. Official guidance and agency information are nonbinding unless a legal source gives them another effect. Requested recommendations and incomplete agency implementation remain pending or unresolved. Intelligence Coalition recommendations describe readiness work and are not legal requirements.
California AI regulation at a glance
| Area | Who should examine it | Operational issue | Effective or compliance date | Source status |
|---|---|---|---|---|
| Privacy risk assessments | CCPA businesses engaged in listed high risk processing | assessment before new processing; assessment of continuing processing; executive attestation and submission | effective 2026-01-01; continuing activities due 2027-12-31; first submission 2028-04-01 | final regulation Sources: CPPA approved regulations. |
| Automated decisionmaking | CCPA businesses using ADMT to make a significant decision | pre-use notice, access and opt-out rights, subject to specified exceptions including a qualifying human appeal process; request handling and vendor support | compliance begins 2027-01-01 | final regulation Sources: CPPA final rulemaking page; CPPA approved regulations. |
| Employment automated decision systems | California employers and other covered entities using automated systems in employment decisions | discrimination, records, disability related inquiries, vendor and agent responsibility | effective 2025-10-01 | final regulation Sources: Civil Rights Council rulemaking actions. |
| Generative AI training data | Developers making covered generative AI systems available to Californians | public training data documentation and release process | operative 2026-01-01 | statute Sources: AB 2013. |
| Synthetic content provenance | Covered generative AI providers; later duties for some platforms and capture device manufacturers | detection tools, manifest and latent disclosures, provenance handling | provider duties operative 2026-08-02; some platform duties 2027-01-01; capture device manufacturer duties 2028-01-01 | statute Sources: SB 942; AB 853. |
| Frontier model safety | Frontier developers above the statutory compute threshold, with added duties for large frontier developers above the statutory revenue threshold | frontier developers: transparency reports, critical safety incident reporting and whistleblower protections; large frontier developers also: a published frontier AI framework covering catastrophic risk assessment and unreleased model weight security, catastrophic risk assessment summaries and an anonymous internal reporting process | effective 2026-01-01 | statute Sources: SB 53. |
| Healthcare AI | Listed healthcare settings, health plans, disability insurers and AI health product developers or deployers | patient disclosure, human contact, utilization review limits, clinical decision authority and truthful presentation | 2025-01-01 and 2026-01-01, depending on the statute | statutes Sources: AB 3030; SB 1120; AB 489. |
| AI auditors and independent verification | AI audit providers and auditors seeking state designation | auditor registration, independence, designation standards and pending agency implementation | agency setup deadlines accelerated into 2027; covered audit practice restriction begins 2029-01-01 | statutes and executive order Sources: SB 813; AB 1405; Executive Order N-9-26. |
This table is a screening aid, not an applicability conclusion. A legal review must use the current codified text, the entity's facts and any sector rules.
Which selected requirements should your organization examine?
Use these questions to identify sources that need closer review. They do not decide whether a requirement applies to a particular organization or system.
- Do you use a system to make or substantially make decisions about lending, housing, education, employment, independent contracting or healthcare?
- Does the system process personal information about California consumers, applicants, workers or patients?
- Do you use automated systems to recruit, screen, rank, hire, assign work, set compensation, promote, discipline or terminate workers?
- Do you develop a generative AI system or substantially modify one for public use in California?
- Does your system generate image, audio or video content for users?
- Do you operate a large online platform or host generative AI model code or weights?
- Do you train a foundation model above the compute threshold in SB 53?
- Do you use generative AI for patient communications or software for healthcare utilization review?
- Do you sell AI audit services or plan to rely on a state designated independent verification organization?
- Can your vendors provide the logic, output records, data documentation, tests and change notices you need?
Each cited law or regulation has its own actors, activities, thresholds, exceptions and territorial terms. Record the source and relevant facts for each applicability conclusion rather than applying one answer across the selected requirements.
What matters now
Several duties are already in force. The employment automated decision system rules took effect in October 2025. Generative AI training data documentation and SB 53 took effect in 2026. The California AI Transparency Act became operative in August 2026. Healthcare AI duties under AB 3030, SB 1120 and AB 489 are also in effect. Sources: Civil Rights Council rulemaking actions; SB 53; AB 3030; SB 1120; AB 489; AB 2013; SB 942; AB 853.
The ADMT article has a January 1, 2027 compliance date for covered uses that began earlier. The regulation requires covered businesses to describe the system's role in a decision and respond to access requests. Preparing system, data and decision records before the compliance date is an Intelligence Coalition recommendation. Sources: CPPA approved regulations.
SB 813 directs the Government Operations Agency to establish a designation program for independent verification organizations. AB 1405 directs it to establish a registry and practice rules for providers of covered AI audits. Executive Order N-9-26 directs earlier agency work and requests recommendations on possible new frontier model duties. The requested recommendations are pending policy work, not enacted private sector requirements. Sources: SB 813; AB 1405; Executive Order N-9-26.
Operational readiness
The Intelligence Coalition uses the following sequence to turn legal questions into operating work. It is a readiness method, not a statutory checklist.
1. Inventory
List AI systems, models, vendors, use cases, affected decisions, data, legal entities and owners. Include systems embedded in HR, lending, healthcare, customer service and productivity software. Do not rely on a list of internally developed models.
2. Determine applicability
Map each requirement to the activity, system, person and legal entity it may cover. Record the basis for the conclusion and the facts that could change it.
3. Map controls
Identify the notices, rights handling, human review, discrimination testing, risk assessment, safety, security, incident, content disclosure and vendor controls each system needs.
4. Identify evidence
Name the records that should show the control operating. These may include notices, request logs, appeal decisions, risk assessments, tests, model cards, provenance records, training data documentation, approvals, incident reports and change records.
5. Test effectiveness
Check whether the controls work in realistic cases. A human appeal process is weak if the reviewer lacks time, information, skill or authority. A provenance control is weak if ordinary export or platform processing removes it.
6. Resolve dependencies
Find the vendor, data, model, engineering, procurement, legal and business dependencies that prevent compliance. Assign owners and dates rather than recording them as general gaps.
7. Prepare for review
Resolve material gaps before a regulator, customer, internal audit team or independent reviewer asks for proof. Keep the evidence tied to the relevant system version and period.
Common questions
What does this overview include?
This overview groups selected statutes and regulations by operational topic. It does not use "California AI Act" as the title for the collection. "California AI Transparency Act" is the name used for the synthetic content statute discussed here.
Which selected requirements are in effect in 2026?
The answer depends on the activity. Important 2026 requirements include generative AI training data documentation, the California AI Transparency Act, SB 53 frontier model duties, employment automated decision system rules and healthcare AI statutes. CPPA risk assessment duties also began in 2026, while the ADMT rights article has a January 1, 2027 compliance date.
What do the selected AI audit statutes require?
SB 813 directs the creation of a designation program for independent verification organizations. AB 1405 regulates providers of covered AI audits and sets a January 1, 2029 restriction on unregistered covered audit practice. Executive Order N-9-26 directs earlier agency setup. Determine any audit, assessment or review obligation from the source that governs the specific activity rather than inferring it from these provider statutes.
What evidence should a company keep?
The answer follows the applicable law and system. A useful starting set includes the system inventory, applicability decision, version records, data and model documentation, risk assessments, notices, request and appeal records, tests, approvals, incident records, vendor obligations and change history.
How is California different from the EU AI Act?
The EU AI Act is one cross-sector regulation built around defined roles, system categories and phased obligations. The selected California sources use different definitions, thresholds, agencies and dates. An organization examining both should not import EU classifications into a California analysis unless the relevant California source uses them.
What remains unsettled
- Agency implementation of SB 813, AB 1405 and Executive Order N-9-26 is still in progress.
- Recommendations requested by Executive Order N-9-26 may lead to proposed statutory changes, but they are not yet law.
- The application of several rules depends on facts such as CCPA business status, human involvement, system purpose, personal information processing and vendor roles.
- Insurance, lending, housing, education, children, elections, advertising, entertainment, companion chatbots, public procurement and algorithmic pricing are outside this selected baseline.
- Litigation, later amendments and agency guidance may change how existing requirements operate.
Primary sources
- CPPA final rulemaking page
- CPPA approved regulations
- Civil Rights Council rulemaking actions
- AB 2013, Generative artificial intelligence: training data transparency
- SB 942, California AI Transparency Act
- AB 853, California AI Transparency Act amendments
- SB 53, Transparency in Frontier Artificial Intelligence Act
- AB 3030, Health care services: artificial intelligence
- SB 1120, Health care coverage: utilization review
- AB 489, Health care professions: deceptive terms or letters: artificial intelligence
- SB 813, Independent verification organizations
- AB 1405, Artificial intelligence auditors registration
- Executive Order N-9-26