Updated July 19, 2026 · Attorney-written guide

California AI Laws (2026): The Complete Business Guide

I am Sergei Tokmakov, a California attorney. California now regulates AI through at least eight separate laws and one regulator rulemaking package, each with its own definitions, deadlines, and penalties. This page maps every one of them: what each law is, who it covers, when it bites, what it costs to get wrong, and what your company should actually do. The next hard date is August 2, 2026.

8+
CA AI laws and reg packages mapped below
Aug 2
2026: SB 942 and EU Article 50 both switch on
$5,000
Per violation per day under SB 942
$1,000
Per violation private right of action under SB 243
Sergei Tokmakov, Esq.
Sergei Tokmakov, Esq.
California attorney
CA Bar #279869 →
Start here

The short version

California did not pass one AI act. It passed a lattice: a transparency law for big generative AI systems (SB 942, operative August 2, 2026), a training-data disclosure law that reaches fine-tuners (AB 2013, in force since January 1, 2026), a companion-chatbot law with a private right of action (SB 243, also live), regulator-made rules on automated decisionmaking (CPPA ADMT), a frontier-model law for the largest developers (SB 53), and health-specific rules (AB 3030 and SB 1120). Each has different definitions, so a product can be outside one law and squarely inside another. The sections below are folded: open the laws that touch what you ship, or run the applicability helper first.

Why this page exists
Most "AI law" coverage is written for policy audiences. This guide is written for operators: every law below gets the same five answers. What it is. Who it covers. When it applies. What noncompliance costs. What to do about it. Citations go to the actual bill text or regulator source, not to commentary. For how the state-by-state landscape got this fragmented, read my companion analysis, The State AI Law War: Anthropic, OpenAI, and the 50-State Patchwork.
Compliance calendar

Every deadline, January 2026 to April 2028

Dates verified against the bill texts and regulator sources linked in each section. CA = California statute. US = other states you likely serve. EU = European Union, included because two of these dates land on the same day as California's.

January 1, 2026
The big switch-on CAUS
California: AB 2013 training-data disclosures due for covered generative AI systems; SB 243 companion-chatbot duties live with a $1,000-per-violation private right of action; the CPPA's ADMT, risk-assessment, and cybersecurity-audit regulations take effect. Elsewhere: Texas TRAIGA and Illinois HB 3773 (AI in employment) also went live this day.
August 2, 2026
The double deadline CAEU
California's SB 942 AI Transparency Act becomes operative for covered providers (AI detection tool, content disclosures, $5,000 per violation per day). The same day, Article 50 of the EU AI Act starts applying: chatbot disclosure and machine-readable marking of synthetic content for systems serving EU users.
December 2, 2026
EU marking grace period ends EU
The transition window for Article 50's watermarking and content-marking obligations closes. Systems serving EU users should have provenance marking fully in place by this date.
January 1, 2027
Platforms and the states join CAUS
California: AB 853's duties for large online platforms (2,000,000+ unique monthly users must surface provenance data) and generative AI hosting platforms begin; the CPPA's consumer-facing ADMT rights become operative. Elsewhere: Colorado SB 26-189 compliance begins (the narrower replacement for the repealed SB 24-205).
July 1, 2027
SB 243 reporting begins CA
Companion-chatbot operators begin required reporting to California's Office of Suicide Prevention under SB 243.
December 2, 2027
EU high-risk rules (delayed) EU
The EU Digital Omnibus (Council final approval June 29, 2026) pushed the Annex III high-risk obligations to this date for standalone systems, with embedded-in-product systems following August 2, 2028. If your EU plan still says "high-risk by August 2026," it is out of date.
January 1, 2028
Capture devices; Illinois frontier audits CAUS
California: AB 853's latent-disclosure requirements for capture-device manufacturers begin. Illinois: obligations under SB 315, the Artificial Intelligence Safety Measures Act (annual independent third-party safety audits for the largest developers), take effect per Capitol News Illinois.
April 1, 2028
First CPPA risk-assessment submissions CA
Businesses subject to the CPPA's risk-assessment requirements make their first submissions to the agency. The assessments cover processing back to when the rules took effect, so the record you keep in 2026 and 2027 is what you file in 2028.
Reading the calendar strategically
Two clusters matter for most companies: the January 1, 2026 duties that are already live (if you have not checked AB 2013 and SB 243 exposure, that is remediation, not planning), and the August 2, 2026 double deadline. Everything after that is buildable on a normal schedule if you start now. The $575 Written Gap Audit tells you in writing which cluster you are actually in.
Quick screen

Does this apply to my product?

Eight yes-or-no questions, then a list of the laws most likely in play for your product. Simplified screening logic, not legal advice.

California AI Law Applicability HelperCheck what describes your product, then see which laws likely reach it. Informational, not legal advice.

Informational only, simplified screening logic, not legal advice and not a scope of representation. Definitions in these statutes are technical; a real answer is confirmed in writing against your actual product.

Law 1 of 8 · Operative August 2, 2026

SB 942: the California AI Transparency Act

The headline deadline of 2026. If you run a big generative AI system, this is the one to open first.

🔍 What SB 942 requires, who it covers, and what it costs to missCovered providers over 1M monthly users · AI detection tool · content disclosures · $5,000 per violation per day
What it isProvenance and disclosure duties for large generative AI systems (SB 942, as amended by AB 853)
Who it covers"Covered providers": creators of GenAI systems with 1,000,000+ monthly visitors or users, publicly accessible in California
Key datesProviders: Aug 2, 2026 · Large platforms and GenAI hosting: Jan 1, 2027 · Capture devices: Jan 1, 2028
Penalty$5,000 civil penalty per violation, each day a separate violation; AG, city attorney, or county counsel; fee-shifting

What it actually requires

A covered provider must offer a free, public AI detection tool? that lets users assess whether content was created or altered by the provider's system, and must embed disclosures in AI-generated content that are permanent or extraordinarily difficult to remove to the extent technically feasible. The original SB 942 was signed in September 2024; AB 853, signed October 13, 2025, delayed the operative date to August 2, 2026 and added the platform layers.

The 2027 and 2028 layers most summaries miss

  • Large online platforms (over 2,000,000 unique monthly users during the preceding 12 months) must detect provenance data, disclose its availability in the user interface, let users inspect it, and must not strip it from uploaded content, starting January 1, 2027.
  • Generative AI hosting platforms must not distribute systems that lack the required disclosure capability, also from January 1, 2027.
  • Capture device manufacturers (cameras, recorders) owe latent-disclosure options from January 1, 2028.
The per-day math
$5,000 per violation with each day counted separately means a single defective disclosure surface running unnoticed for a quarter is not a $5,000 problem. Enforcement can come from the Attorney General, any city attorney, or county counsel, and prevailing plaintiffs recover fees. Do not calendar this as a nice-to-have.

What to do

First, answer the definitional question honestly: do you "create, code, or otherwise produce" a GenAI system, and does it clear 1,000,000 monthly users accessible in California? Builders on top of third-party models are often outside the covered-provider definition while their model vendor is inside it, but white-labeling and heavy modification can flip that. Second, if covered: scope the detection tool and disclosure pipeline now, since both are engineering projects, not policy documents. Third, if you are near the threshold or the definition is ambiguous for your architecture, that is a boundary question: the $575 Written Gap Audit resolves it in writing before you build the wrong thing.

Law 2 of 8 · In force since January 1, 2026

AB 2013: training-data disclosure

The quiet one that reaches far more companies than SB 942, because fine-tuning counts.

📚 Public documentation of what your model was trained onReaches developers AND substantial modifiers (fine-tuners) · live since Jan 1, 2026
What it isWebsite documentation of GenAI training datasets (AB 2013, signed Sept 2024)
Who it coversDevelopers of GenAI made available to Californians, including those who substantially modify (fine-tune, retrain) a model
Key dateIn force January 1, 2026; applies before making the system available
ExposureCivil enforcement; the bigger practical risk is diligence and enterprise-deal friction from missing documentation

What it actually requires

Post documentation on your website describing the datasets used to train the system: sources and owners, a description of the data, whether it includes personal information or copyrighted material, whether it was purchased or licensed, time period of collection, and related details. The duty attaches when the system is made available to Californians.

The fine-tuning trap
AB 2013 treats a person who substantially modifies a model as a developer with their own disclosure duty. A SaaS company that fine-tunes an open-weight model on its own corpus can owe documentation about that training run even though the base-model developer separately documents the original training. "We just use someone else's model" is only a defense if you actually just use it.

What to do

Inventory every model you ship: base models used as-is (vendor's disclosure problem), fine-tunes and retrains (yours), and RAG or prompting layers (generally not "training," but the line deserves a real look, not a guess). Then write the disclosure once, keep it versioned, and update it when training runs change. If your training data includes licensed-in datasets, this connects directly to my AI and data licensing practice: the disclosure you post has to match the license terms you actually hold.

Law 3 of 8 · In force since January 1, 2026

SB 243: companion chatbots, with a private right of action

The most litigation-shaped law on this page. Users can sue you directly.

💬 Disclosure, crisis protocols, minor protections, and the $1,000-per-violation PRAIf your product sustains human-like relationships, read this before a plaintiff does
What it isDuties on operators of companion chatbots (SB 243, signed Oct 13, 2025)
Who it coversOperators of chatbots that sustain human-like, relationship-style interaction with users; heightened duties for minors
Key datesDuties live Jan 1, 2026; operator reporting to the Office of Suicide Prevention from July 1, 2027
PenaltyPrivate right of action: greater of actual damages or $1,000 per violation, plus injunctive relief and attorney fees

What it actually requires

  • Disclosure that the user is talking to AI where a reasonable person could be misled, with recurring reminders for minors.
  • Crisis protocols: procedures for suicidal ideation and self-harm content, including referral to crisis services, published and followed.
  • Minor protections: break reminders and restrictions on sexually explicit content for users the operator knows are minors.
  • Reporting to California's Office of Suicide Prevention beginning July 1, 2027.
Why the PRA changes the risk profile
Every other California AI law on this page is enforced by public officials with limited bandwidth. SB 243 is enforced by anyone injured, at the greater of actual damages or $1,000 per violation, with fee-shifting. Statutory-damages-plus-fees is the architecture that built wiretapping and accessibility litigation industries in California. If any surface of your product could be characterized as a companion chatbot, the cheapest time to fix that characterization is before launch.

What to do

Do not assume "companion chatbot" means only romance apps. The statutory question is what the product does in sustained interaction, not what you call it. Map your features against the definitions, get the disclosures and crisis protocols in place if you are near the line, and write down the analysis either way: a documented good-faith classification is worth a lot the day a demand letter arrives. This is a classic gap audit question; if the answer is "covered," the protocols and disclosure copy become drafting work I scope in writing.

Law 4 of 8 · Regulations effective January 1, 2026

CPPA ADMT, risk assessments, and cybersecurity audits

Not a statute: regulator-made rules under the CCPA, with the longest compliance tail on this page.

⚙️ Automated decisionmaking rights, mandatory risk assessments, and the 2028 filingRules live Jan 1, 2026 · ADMT rights Jan 1, 2027 · first submissions April 1, 2028
What it isCPPA regulations on automated decisionmaking technology, risk assessments, and cybersecurity audits (approved September 2025)
Who it coversBusinesses subject to the CCPA that use ADMT for significant decisions about California consumers, or whose processing triggers risk-assessment duties
Key datesEffective Jan 1, 2026 · ADMT consumer rights operative Jan 1, 2027 · first risk-assessment submissions due April 1, 2028
ExposureCCPA enforcement by the CPPA and Attorney General; administrative fines per violation

What it actually requires

Three workstreams travel together. ADMT: businesses using automated decisionmaking for significant decisions (think hiring, lending, housing, insurance, education access) owe pre-use notices and, from January 1, 2027, consumer rights to opt out and to access information about how the technology was used against them. Risk assessments: processing that presents significant risk, including training certain AI and profiling, requires documented risk assessments, with the first agency submissions due April 1, 2028 covering the period back to the rules' effective date. Cybersecurity audits: annual audits phase in for larger businesses.

The record you keep now is the filing you make in 2028
The April 1, 2028 date reads far away, but the submission covers processing conducted from 2026 forward. A business that starts assessing in late 2027 will be reconstructing two years of decisions from memory. Start the risk-assessment template now, populate it as processing changes, and the 2028 filing becomes an export, not a project.

What to do

Determine whether any decision flow in your product or your HR stack meets the significant-decision definitions. If yes: notices and opt-out mechanics get designed into the flow, and the risk assessment gets drafted alongside. The $1,500 AI SaaS Document Review covers reading your existing privacy stack (policy, notices, DPAs) against these rules; new builds fold it into the $2,500 Launch Package.

Law 5 of 8 · In force

SB 53: frontier AI transparency (the one that probably is not about you)

Worth understanding precisely so you can stop worrying about it, and so your investors' diligence questions get crisp answers.

🏗️ Safety frameworks and incident reporting for the largest model developers10^26 FLOP training threshold; heaviest duties above $500M revenue
What it isThe Transparency in Frontier Artificial Intelligence Act (SB 53, signed Sept 29, 2025)
Who it coversDevelopers training models above a 10^26 FLOP compute threshold; large frontier developers above $500M annual revenue carry the fullest duties
Key dutiesPublished safety frameworks, critical-incident reporting to the state, whistleblower protections
For everyone elseNot your regulated lane, but your model vendor's compliance posture is now a diligence item in your vendor review

SB 53 requires the largest developers to publish frontier AI safety frameworks, report critical safety incidents to state authorities, and protect whistleblowing employees. If your company builds on top of a frontier model rather than training one, you are almost certainly not the covered party. Two practical notes anyway: enterprise customers increasingly ask AI vendors SB 53-flavored questions regardless of coverage, and the law is the template being copied and escalated by other states, including New York and Illinois, as I cover in the state AI law war analysis.

Laws 6 and 7 of 8 · In force

Health AI: AB 3030 and SB 1120

If your AI touches patients or payers, California has already legislated your product category.

🩺 GenAI patient communications and AI in utilization reviewDisclaimers plus a human route (AB 3030); physicians keep the final call (SB 1120)

AB 3030 (signed Sept 2024): when a health facility or clinic uses generative AI to produce patient communications about clinical information, the communication must carry a disclaimer that it was AI-generated and clear instructions for reaching a human provider. Communications reviewed by a licensed provider are exempt, which makes human review the practical compliance path for most deployments.

SB 1120 (signed Sept 2024): health plans and insurers using AI or algorithms in utilization review must ensure the tool considers the individual patient's circumstances rather than group data alone, and a licensed physician makes the final medical-necessity determination. If you sell UR tooling to payers, this statute is effectively part of your product spec.

Mental health is stricter than health
Separate from California: Illinois banned AI-provided therapy outright in 2025 (HB 1806), and Nevada's AB 406 prohibits offering AI systems that provide, or claim to provide, professional mental or behavioral healthcare, with civil penalties up to $15,000 per violation. Wellness apps drift into this zone through marketing language alone. If your copy says anything therapy-shaped, have it read.

Health AI deployments usually also sit inside HIPAA and state privacy rules; for the document stack side of that, see my Healthcare SaaS Legal Hub.

Law 8 of 8, plus the map around it

Beyond California: what else is on your calendar

California is the center of gravity, but a California company serves users everywhere. The states below are the ones most likely to matter, plus the EU dates that share your calendar. For the full story of how this patchwork got built on purpose, read my analysis of the state AI law war.

🗺️ Colorado, Texas, Illinois, Nevada, Utah, New York City, and the EUIncluding the one everyone still gets wrong: Colorado SB 24-205 is dead
Colorado: the compliance plan everyone needs to un-write
Colorado's much-discussed AI Act, SB 24-205, never took effect. It was repealed and reenacted through SB 26-189, signed May 14, 2026, as a narrower automated-decisionmaking disclosure law: developer documentation and attorney-general disclosure rules by January 1, 2027, consumer rights to human review, data access, and explanations for adverse algorithmic decisions, with AG enforcement and statutory runway provisions extending into 2030. If your vendor questionnaire, DPA exhibit, or compliance memo still references SB 24-205 impact assessments, it cites a law that no longer exists.
JurisdictionLawStatus and datesWhat it means for you
TexasTRAIGA (HB 149)Effective Jan 1, 2026Prohibited-use rules with AG-only enforcement, a 60-day cure period, and a safe harbor tied to the NIST AI RMF. Aligning your governance docs to NIST buys protection in Texas and credibility everywhere else.
IllinoisHB 3773 (employment)Effective Jan 1, 2026Amends the Human Rights Act: no AI with discriminatory effect in employment decisions, and notice to employees and applicants when AI is used (summary). HR-tech vendors: your customers will push these duties into your contracts.
IllinoisSB 315, AI Safety Measures ActSigned July 6, 2026; requirements from Jan 1, 2028First-in-the-nation annual independent third-party safety audits for the largest developers (over $500M revenue), published catastrophic-risk frameworks, 72-hour incident reporting (24 hours if imminent), AG penalties up to $1M initial and $3M subsequent (governor's release; Capitol News Illinois).
IllinoisHB 1806 (AI therapy ban)In force since Aug 2025AI may not deliver therapy or make therapeutic decisions; licensed professionals may use AI only for administrative and supplementary support (IDFPR release).
NevadaAB 406In force since July 2025No AI systems providing or claiming to provide professional mental or behavioral healthcare; civil penalties up to $15,000 per violation.
UtahAI Policy Act, as amended (SB 226)Amendments effective May 2025Disclosure duties when consumers interact with generative AI, sharpened to focus on high-risk and regulated-profession interactions.
New York CityLocal Law 144 (AEDT bias audits)In force; enforcement weakThe New York State Comptroller's December 2025 audit found enforcement "ineffective." Do not confuse weak enforcement with repeal: the duties remain, and audit findings tend to precede enforcement pushes.
EUAI Act Article 50; Digital OmnibusArt. 50: Aug 2, 2026 (marking grace to Dec 2, 2026); high-risk delayed to Dec 2, 2027 / Aug 2, 2028GPAI duties have applied since Aug 2, 2025. The omnibus bought time on high-risk, not on transparency: chatbot disclosure and synthetic-content marking start the same day as SB 942.

The practical consequence: multistate AI compliance is now a matrix, not a checklist, and the matrix changes quarterly. Build to the strictest common denominator where cheap (disclosure, documentation, human oversight), and take jurisdiction-specific advice where the laws genuinely diverge (therapy bans, audit mandates, platform duties).

AI Legal Analyst

Ask my AI Legal Analyst about your California AI exposure?

Describe what your product does and the analyst maps it against the laws on this page, or start from one of the common questions below. It knows this page's content: the definitions, the dates, and the penalties.

Loading the AI Legal Analyst...
FAQ

California AI laws 2026: the questions I actually get

📅What California AI laws take effect in 2026?

Three big ones started January 1, 2026: AB 2013 (training-data disclosure), SB 243 (companion chatbots, with a private right of action), and the CPPA's ADMT, risk-assessment, and cybersecurity-audit regulations. The next major date is August 2, 2026, when the SB 942 California AI Transparency Act becomes operative for covered generative AI providers. SB 53 (frontier AI) and the health AI rules in AB 3030 and SB 1120 are also already in force.

🎯Does SB 942 apply to my company?

SB 942, as amended by AB 853, applies to a "covered provider": a person that creates, codes, or otherwise produces a generative AI system with over 1,000,000 monthly visitors or users that is publicly accessible in California. Below that threshold the core provider duties do not attach, but large-online-platform duties (2,000,000+ unique monthly users) and GenAI hosting-platform duties start January 1, 2027. Whether your architecture crosses a definition is a fact question worth a written answer, not a guess.

💰What are the penalties under SB 942?

$5,000 per violation, and each day of noncompliance is a separate violation, enforceable by the Attorney General, a city attorney, or a county counsel, with attorney fees for a prevailing plaintiff. The per-day structure is the point: undiscovered defects compound.

🔧I fine-tune an open model. Does AB 2013 reach me?

Very possibly. AB 2013 treats someone who substantially modifies a model, which can include fine-tuning or retraining, as a developer with their own duty to post training-data documentation before making the system available to Californians. It has been in force since January 1, 2026. Whether your modification is "substantial" is a boundary question I resolve in writing in the gap audit.

⚖️What is the private right of action under SB 243?

A person injured by a violation can sue the operator for the greater of actual damages or $1,000 per violation, plus injunctive relief and attorney fees. Statutory damages plus fee-shifting is the formula that industrializes litigation in California, which is why the companion-chatbot classification question deserves attention even from products that do not think of themselves as companions.

📊When do the CPPA ADMT rules actually apply?

The regulations took effect January 1, 2026. The consumer-facing ADMT rights (opt-out, access) are operative January 1, 2027, and first risk-assessment submissions to the agency are due April 1, 2028, covering processing back to the effective date. Build the record as you go; do not plan to reconstruct it in 2028.

🏔️Is the Colorado AI Act still happening?

Not as SB 24-205, which never took effect and was repealed and reenacted through SB 26-189 (signed May 14, 2026) as a narrower ADMT disclosure law with compliance starting January 1, 2027. Purge SB 24-205 from your vendor questionnaires and compliance memos.

🚨What happens on August 2, 2026?

California's SB 942 becomes operative for covered GenAI providers, and the EU AI Act's Article 50 transparency obligations start applying to systems serving EU users, with the content-marking grace period running to December 2, 2026. Companies with users on both continents hit both on the same day.

🚀Does SB 53 apply to startups?

Almost never: it targets developers training above a 10^26 FLOP threshold, with the heaviest duties above $500 million in annual revenue. Builders on third-party models are typically outside it, though enterprise customers increasingly ask SB 53-style diligence questions of every AI vendor.

🧭What should my company do first?

Map your product against the definitions: covered provider (SB 942), developer or substantial modifier (AB 2013), operator (SB 243), ADMT user (CPPA). Most companies land inside one or two, not all. That mapping, in writing with a prioritized fix list, is my $575 Written Gap Audit; a new product launch builds on it with the $2,500 AI SaaS Launch Package; a single narrow question fits the $240 written consultation.

Know where you stand before August 2

A written attorney answer to "which of these laws applies to us, and what do we fix first." Fixed fees agreed before work starts, delivered in writing, scoped to what you actually ship.

Written Gap Audit · $575 flat

Sergei Tokmakov, Esq., CA Bar #279869. Attorney advertising. Have documents already? The $1,500 AI SaaS Document Review reads them against these laws; a single question fits the $240 Written Attorney Consultation.

General information, not legal advice. This guide, including the timeline, the applicability helper, and the AI Legal Analyst, is general information current as of July 19, 2026, prepared by Sergei Tokmakov (CA Bar #279869). AI statutes and regulations are amended frequently, several of the laws described here have pending rulemaking or amendment activity, and how any of them applies to a specific product depends on facts I would confirm in an engagement. Statutory citations link to the official bill text or regulator source; always check the current version. Nothing here creates an attorney-client relationship, and no outcome is guaranteed.
Gap Audit · $575