California AI Laws (2026): The Complete Business Guide
I am Sergei Tokmakov, a California attorney. California now regulates AI through at least eight separate laws and one regulator rulemaking package, each with its own definitions, deadlines, and penalties. This page maps every one of them: what each law is, who it covers, when it bites, what it costs to get wrong, and what your company should actually do. The next hard date is August 2, 2026.

The short version
California did not pass one AI act. It passed a lattice: a transparency law for big generative AI systems (SB 942, operative August 2, 2026), a training-data disclosure law that reaches fine-tuners (AB 2013, in force since January 1, 2026), a companion-chatbot law with a private right of action (SB 243, also live), regulator-made rules on automated decisionmaking (CPPA ADMT), a frontier-model law for the largest developers (SB 53), and health-specific rules (AB 3030 and SB 1120). Each has different definitions, so a product can be outside one law and squarely inside another. The sections below are folded: open the laws that touch what you ship, or run the applicability helper first.
Every deadline, January 2026 to April 2028
Dates verified against the bill texts and regulator sources linked in each section. CA = California statute. US = other states you likely serve. EU = European Union, included because two of these dates land on the same day as California's.
Does this apply to my product?
Eight yes-or-no questions, then a list of the laws most likely in play for your product. Simplified screening logic, not legal advice.
California AI Law Applicability HelperCheck what describes your product, then see which laws likely reach it. Informational, not legal advice.
Informational only, simplified screening logic, not legal advice and not a scope of representation. Definitions in these statutes are technical; a real answer is confirmed in writing against your actual product.
SB 942: the California AI Transparency Act
The headline deadline of 2026. If you run a big generative AI system, this is the one to open first.
🔍 What SB 942 requires, who it covers, and what it costs to missCovered providers over 1M monthly users · AI detection tool · content disclosures · $5,000 per violation per day ▾
What it actually requires
A covered provider must offer a free, public AI detection tool? that lets users assess whether content was created or altered by the provider's system, and must embed disclosures in AI-generated content that are permanent or extraordinarily difficult to remove to the extent technically feasible. The original SB 942 was signed in September 2024; AB 853, signed October 13, 2025, delayed the operative date to August 2, 2026 and added the platform layers.
The 2027 and 2028 layers most summaries miss
- Large online platforms (over 2,000,000 unique monthly users during the preceding 12 months) must detect provenance data, disclose its availability in the user interface, let users inspect it, and must not strip it from uploaded content, starting January 1, 2027.
- Generative AI hosting platforms must not distribute systems that lack the required disclosure capability, also from January 1, 2027.
- Capture device manufacturers (cameras, recorders) owe latent-disclosure options from January 1, 2028.
What to do
First, answer the definitional question honestly: do you "create, code, or otherwise produce" a GenAI system, and does it clear 1,000,000 monthly users accessible in California? Builders on top of third-party models are often outside the covered-provider definition while their model vendor is inside it, but white-labeling and heavy modification can flip that. Second, if covered: scope the detection tool and disclosure pipeline now, since both are engineering projects, not policy documents. Third, if you are near the threshold or the definition is ambiguous for your architecture, that is a boundary question: the $575 Written Gap Audit resolves it in writing before you build the wrong thing.
AB 2013: training-data disclosure
The quiet one that reaches far more companies than SB 942, because fine-tuning counts.
📚 Public documentation of what your model was trained onReaches developers AND substantial modifiers (fine-tuners) · live since Jan 1, 2026 ▾
What it actually requires
Post documentation on your website describing the datasets used to train the system: sources and owners, a description of the data, whether it includes personal information or copyrighted material, whether it was purchased or licensed, time period of collection, and related details. The duty attaches when the system is made available to Californians.
What to do
Inventory every model you ship: base models used as-is (vendor's disclosure problem), fine-tunes and retrains (yours), and RAG or prompting layers (generally not "training," but the line deserves a real look, not a guess). Then write the disclosure once, keep it versioned, and update it when training runs change. If your training data includes licensed-in datasets, this connects directly to my AI and data licensing practice: the disclosure you post has to match the license terms you actually hold.
SB 243: companion chatbots, with a private right of action
The most litigation-shaped law on this page. Users can sue you directly.
💬 Disclosure, crisis protocols, minor protections, and the $1,000-per-violation PRAIf your product sustains human-like relationships, read this before a plaintiff does ▾
What it actually requires
- Disclosure that the user is talking to AI where a reasonable person could be misled, with recurring reminders for minors.
- Crisis protocols: procedures for suicidal ideation and self-harm content, including referral to crisis services, published and followed.
- Minor protections: break reminders and restrictions on sexually explicit content for users the operator knows are minors.
- Reporting to California's Office of Suicide Prevention beginning July 1, 2027.
What to do
Do not assume "companion chatbot" means only romance apps. The statutory question is what the product does in sustained interaction, not what you call it. Map your features against the definitions, get the disclosures and crisis protocols in place if you are near the line, and write down the analysis either way: a documented good-faith classification is worth a lot the day a demand letter arrives. This is a classic gap audit question; if the answer is "covered," the protocols and disclosure copy become drafting work I scope in writing.
CPPA ADMT, risk assessments, and cybersecurity audits
Not a statute: regulator-made rules under the CCPA, with the longest compliance tail on this page.
⚙️ Automated decisionmaking rights, mandatory risk assessments, and the 2028 filingRules live Jan 1, 2026 · ADMT rights Jan 1, 2027 · first submissions April 1, 2028 ▾
What it actually requires
Three workstreams travel together. ADMT: businesses using automated decisionmaking for significant decisions (think hiring, lending, housing, insurance, education access) owe pre-use notices and, from January 1, 2027, consumer rights to opt out and to access information about how the technology was used against them. Risk assessments: processing that presents significant risk, including training certain AI and profiling, requires documented risk assessments, with the first agency submissions due April 1, 2028 covering the period back to the rules' effective date. Cybersecurity audits: annual audits phase in for larger businesses.
What to do
Determine whether any decision flow in your product or your HR stack meets the significant-decision definitions. If yes: notices and opt-out mechanics get designed into the flow, and the risk assessment gets drafted alongside. The $1,500 AI SaaS Document Review covers reading your existing privacy stack (policy, notices, DPAs) against these rules; new builds fold it into the $2,500 Launch Package.
SB 53: frontier AI transparency (the one that probably is not about you)
Worth understanding precisely so you can stop worrying about it, and so your investors' diligence questions get crisp answers.
🏗️ Safety frameworks and incident reporting for the largest model developers10^26 FLOP training threshold; heaviest duties above $500M revenue ▾
SB 53 requires the largest developers to publish frontier AI safety frameworks, report critical safety incidents to state authorities, and protect whistleblowing employees. If your company builds on top of a frontier model rather than training one, you are almost certainly not the covered party. Two practical notes anyway: enterprise customers increasingly ask AI vendors SB 53-flavored questions regardless of coverage, and the law is the template being copied and escalated by other states, including New York and Illinois, as I cover in the state AI law war analysis.
Health AI: AB 3030 and SB 1120
If your AI touches patients or payers, California has already legislated your product category.
🩺 GenAI patient communications and AI in utilization reviewDisclaimers plus a human route (AB 3030); physicians keep the final call (SB 1120) ▾
AB 3030 (signed Sept 2024): when a health facility or clinic uses generative AI to produce patient communications about clinical information, the communication must carry a disclaimer that it was AI-generated and clear instructions for reaching a human provider. Communications reviewed by a licensed provider are exempt, which makes human review the practical compliance path for most deployments.
SB 1120 (signed Sept 2024): health plans and insurers using AI or algorithms in utilization review must ensure the tool considers the individual patient's circumstances rather than group data alone, and a licensed physician makes the final medical-necessity determination. If you sell UR tooling to payers, this statute is effectively part of your product spec.
Health AI deployments usually also sit inside HIPAA and state privacy rules; for the document stack side of that, see my Healthcare SaaS Legal Hub.
Beyond California: what else is on your calendar
California is the center of gravity, but a California company serves users everywhere. The states below are the ones most likely to matter, plus the EU dates that share your calendar. For the full story of how this patchwork got built on purpose, read my analysis of the state AI law war.
🗺️ Colorado, Texas, Illinois, Nevada, Utah, New York City, and the EUIncluding the one everyone still gets wrong: Colorado SB 24-205 is dead ▾
| Jurisdiction | Law | Status and dates | What it means for you |
|---|---|---|---|
| Texas | TRAIGA (HB 149) | Effective Jan 1, 2026 | Prohibited-use rules with AG-only enforcement, a 60-day cure period, and a safe harbor tied to the NIST AI RMF. Aligning your governance docs to NIST buys protection in Texas and credibility everywhere else. |
| Illinois | HB 3773 (employment) | Effective Jan 1, 2026 | Amends the Human Rights Act: no AI with discriminatory effect in employment decisions, and notice to employees and applicants when AI is used (summary). HR-tech vendors: your customers will push these duties into your contracts. |
| Illinois | SB 315, AI Safety Measures Act | Signed July 6, 2026; requirements from Jan 1, 2028 | First-in-the-nation annual independent third-party safety audits for the largest developers (over $500M revenue), published catastrophic-risk frameworks, 72-hour incident reporting (24 hours if imminent), AG penalties up to $1M initial and $3M subsequent (governor's release; Capitol News Illinois). |
| Illinois | HB 1806 (AI therapy ban) | In force since Aug 2025 | AI may not deliver therapy or make therapeutic decisions; licensed professionals may use AI only for administrative and supplementary support (IDFPR release). |
| Nevada | AB 406 | In force since July 2025 | No AI systems providing or claiming to provide professional mental or behavioral healthcare; civil penalties up to $15,000 per violation. |
| Utah | AI Policy Act, as amended (SB 226) | Amendments effective May 2025 | Disclosure duties when consumers interact with generative AI, sharpened to focus on high-risk and regulated-profession interactions. |
| New York City | Local Law 144 (AEDT bias audits) | In force; enforcement weak | The New York State Comptroller's December 2025 audit found enforcement "ineffective." Do not confuse weak enforcement with repeal: the duties remain, and audit findings tend to precede enforcement pushes. |
| EU | AI Act Article 50; Digital Omnibus | Art. 50: Aug 2, 2026 (marking grace to Dec 2, 2026); high-risk delayed to Dec 2, 2027 / Aug 2, 2028 | GPAI duties have applied since Aug 2, 2025. The omnibus bought time on high-risk, not on transparency: chatbot disclosure and synthetic-content marking start the same day as SB 942. |
The practical consequence: multistate AI compliance is now a matrix, not a checklist, and the matrix changes quarterly. Build to the strictest common denominator where cheap (disclosure, documentation, human oversight), and take jurisdiction-specific advice where the laws genuinely diverge (therapy bans, audit mandates, platform duties).
Ask my AI Legal Analyst about your California AI exposure?
Describe what your product does and the analyst maps it against the laws on this page, or start from one of the common questions below. It knows this page's content: the definitions, the dates, and the penalties.
California AI laws 2026: the questions I actually get
📅What California AI laws take effect in 2026?▾
Three big ones started January 1, 2026: AB 2013 (training-data disclosure), SB 243 (companion chatbots, with a private right of action), and the CPPA's ADMT, risk-assessment, and cybersecurity-audit regulations. The next major date is August 2, 2026, when the SB 942 California AI Transparency Act becomes operative for covered generative AI providers. SB 53 (frontier AI) and the health AI rules in AB 3030 and SB 1120 are also already in force.
🎯Does SB 942 apply to my company?▾
SB 942, as amended by AB 853, applies to a "covered provider": a person that creates, codes, or otherwise produces a generative AI system with over 1,000,000 monthly visitors or users that is publicly accessible in California. Below that threshold the core provider duties do not attach, but large-online-platform duties (2,000,000+ unique monthly users) and GenAI hosting-platform duties start January 1, 2027. Whether your architecture crosses a definition is a fact question worth a written answer, not a guess.
💰What are the penalties under SB 942?▾
$5,000 per violation, and each day of noncompliance is a separate violation, enforceable by the Attorney General, a city attorney, or a county counsel, with attorney fees for a prevailing plaintiff. The per-day structure is the point: undiscovered defects compound.
🔧I fine-tune an open model. Does AB 2013 reach me?▾
Very possibly. AB 2013 treats someone who substantially modifies a model, which can include fine-tuning or retraining, as a developer with their own duty to post training-data documentation before making the system available to Californians. It has been in force since January 1, 2026. Whether your modification is "substantial" is a boundary question I resolve in writing in the gap audit.
⚖️What is the private right of action under SB 243?▾
A person injured by a violation can sue the operator for the greater of actual damages or $1,000 per violation, plus injunctive relief and attorney fees. Statutory damages plus fee-shifting is the formula that industrializes litigation in California, which is why the companion-chatbot classification question deserves attention even from products that do not think of themselves as companions.
📊When do the CPPA ADMT rules actually apply?▾
The regulations took effect January 1, 2026. The consumer-facing ADMT rights (opt-out, access) are operative January 1, 2027, and first risk-assessment submissions to the agency are due April 1, 2028, covering processing back to the effective date. Build the record as you go; do not plan to reconstruct it in 2028.
🏔️Is the Colorado AI Act still happening?▾
Not as SB 24-205, which never took effect and was repealed and reenacted through SB 26-189 (signed May 14, 2026) as a narrower ADMT disclosure law with compliance starting January 1, 2027. Purge SB 24-205 from your vendor questionnaires and compliance memos.
🚨What happens on August 2, 2026?▾
California's SB 942 becomes operative for covered GenAI providers, and the EU AI Act's Article 50 transparency obligations start applying to systems serving EU users, with the content-marking grace period running to December 2, 2026. Companies with users on both continents hit both on the same day.
🚀Does SB 53 apply to startups?▾
Almost never: it targets developers training above a 10^26 FLOP threshold, with the heaviest duties above $500 million in annual revenue. Builders on third-party models are typically outside it, though enterprise customers increasingly ask SB 53-style diligence questions of every AI vendor.
🧭What should my company do first?▾
Map your product against the definitions: covered provider (SB 942), developer or substantial modifier (AB 2013), operator (SB 243), ADMT user (CPPA). Most companies land inside one or two, not all. That mapping, in writing with a prioritized fix list, is my $575 Written Gap Audit; a new product launch builds on it with the $2,500 AI SaaS Launch Package; a single narrow question fits the $240 written consultation.
Know where you stand before August 2
A written attorney answer to "which of these laws applies to us, and what do we fix first." Fixed fees agreed before work starts, delivered in writing, scoped to what you actually ship.
Sergei Tokmakov, Esq., CA Bar #279869. Attorney advertising. Have documents already? The $1,500 AI SaaS Document Review reads them against these laws; a single question fits the $240 Written Attorney Consultation.