California: four statutes, one stack

Lesson 3 of 6 in State AI Laws in Depth: Colorado, California, Texas, Illinois, NYC, and Beyond.

California did not pass one AI law. It passed a stack — four regimes aimed at different layers of the AI supply chain, all landing between January 2026 and August 2026. Read them as answers to four different questions: what went into the model? (AB 2013), is this content synthetic? (SB 942, as amended by AB 853), is the frontier model safe? (SB 53), and is an automated decision being made about me? (the CCPA ADMT regulations).

Keep the layering straight, because obligations attach to different actors: AB 2013 and SB 942 bind generative AI providers; SB 53 binds a handful of frontier developers; the ADMT regulations bind any CCPA-covered business using automated decision-making on Californians — which is most large employers and consumer companies, whether or not they build any AI at all.

AB 2013 — training data

Training-data transparency (effective January 1, 2026). Developers of generative AI systems made available to Californians must publicly post documentation of the training data — applying retroactively to systems released since January 1, 2022. The posting must describe the datasets and their sources, whether they include personal information, whether they include copyrighted or licensed material, and whether synthetic data was used.

It is disclosure-only — no quality or licensing mandate — but it is the discovery roadmap for every copyright and privacy plaintiff, which is exactly why developers fought it.

SB 942 + AB 853 — synthetic content

The California AI Transparency Act (in force since August 2026, after AB 853 delayed and extended it). Covered large GenAI providers must offer a free public AI-detection tool, and give users both manifest disclosures (visible labels) and latent disclosures (embedded provenance metadata) in AI-generated content. Providers must revoke licenses of third parties that strip disclosures.

AB 853 extended the scheme beyond generators: large online platforms must surface the provenance metadata that content carries, and capture devices (cameras, recorders) get authenticity-provenance duties. This is content provenance law — the US counterpart to EU AI Act Article 50.

SB 53 — frontier models

The Transparency in Frontier Artificial Intelligence Act (TFAIA) — signed September 29, 2025, effective January 1, 2026, the successor to the vetoed SB 1047. It reaches only frontier developers, defined by a training-compute threshold, with a heavier tier for large frontier developers crossing an annual-revenue floor.

Duties: publish a frontier AI framework describing how the developer assesses and mitigates catastrophic risk; publish transparency reports at deployment; report critical safety incidents to Cal OES on short statutory clocks (with a fast lane where there is imminent risk of death or serious injury); and honor whistleblower protections for employees raising catastrophic-risk concerns. Civil penalties are enforced by the AG. The act also launched CalCompute, a public compute cluster.

Where SB 1047 mandated shutdown capability and pre-harm liability, SB 53 mandates transparency about your own safety framework — governance by forced publication.

CCPA ADMT regs

The CPPA’s ADMT, risk-assessment, and cybersecurity-audit regulations (OAL-approved September 23, 2025; effective January 1, 2026). For businesses using ADMT for significant decisions about Californians (employment, lending, housing, insurance, education, healthcare access), the regulations require pre-use notice, an opt-out right (with exceptions), and access/explanation rights — with full ADMT compliance required by January 1, 2027.

Companion duties phase in later: risk assessments for high-risk processing with first submissions/attestations due April 1, 2028, and cybersecurity audits phased 2028–2030 by revenue tier. AB 1008 separately confirmed that personal information inside AI model outputs remains CCPA-regulated personal information.

Context law: SB 243 — companion chatbots

Safety duties for companion chatbot operators: crisis-referral protocols, reminders to minors that they are talking to a machine, and reporting. Part of the post-2025 wave of child-safety AI laws — the category EO 14365 expressly declined to challenge.

Context law: AB 1836 and AB 2602 — digital replicas

Consent requirements for digital replicas of performers: AB 2602 makes contract clauses permitting AI replicas unenforceable without informed consent and representation; AB 1836 protects deceased performers’ likenesses. The entertainment-industry corner of deepfake law.

Context law: the B.O.T. Act — bot disclosure

California’s 2019 bot disclosure law: it is unlawful to use an undisclosed bot to incentivize a purchase or influence a vote. Small, old, and routinely forgotten — and it already covers a lot of GenAI customer-facing deployments.

Interactive checkpoint quiz (2 questions) — open this page in a browser to take it.