California’s AI rulebook just got bigger. The world is watching

California has once again put itself at the centre of the US technology-regulation debate.

As the state legislature closed its 2026 session on August 31, lawmakers sent a wave of new privacy and AI legislation to Governor Gavin Newsom. The measures cover everything from how businesses handle sensitive personal information to whether an employer can let an AI system fire a worker.

The scale is important. One account of the session identifies eight privacy bills and 16 AI bills in the main package, while broader counts of AI-related legislation put the number passed during the 2026 session at around 30. The difference reflects how “AI-related” bills are being counted, but the underlying message is the same: California is rapidly expanding its technology rulebook.

The bills now go to Governor Newsom, who has until September 30 to decide which ones become law. 

And if even a significant portion of them are signed, businesses operating in California will have to rethink not just their privacy compliance, but how they design, deploy and oversee AI.

Privacy is moving from data collection to data control

Several of the privacy measures continue California’s expansion of the California Consumer Privacy Act (CCPA).

AB 1542 would restrict businesses from selling or sharing sensitive personal information with third parties unless the consumer intentionally initiates or directs that disclosure or interaction.

That is important because it moves the conversation beyond the traditional question of whether a business has a lawful basis for processing information. It puts greater emphasis on whether the consumer actually intended the information to be disclosed.

SB 923 would broaden the CCPA deletion right so that it applies to all information a business has collected about a consumer. It would also require businesses that operate exclusively online to provide an online mechanism, such as a webform or portal, for deletion requests rather than relying solely on email.

Meanwhile, AB 883 would shorten the period for data brokers to respond to deletion requests from 45 days to 30 days.

These measures all point towards a more demanding model of privacy compliance. Consumers are being given increasingly direct control over the information businesses hold, how it is shared and how quickly it must be removed.

For businesses, that means privacy rights processes cannot simply exist on paper. They need to work operationally, at scale and within increasingly tight deadlines.

California is going after the tech behind the privacy problem

Some of the most interesting provisions target the technology itself.

AB 2561 would prohibit operating systems and applications from undoing a user’s affirmative privacy setting without consent.

That reflects a much bigger regulatory trend. Privacy regulators have traditionally asked businesses what information they collect, why they collect it and how they protect it. Increasingly, regulators and lawmakers are also asking whether the design of the technology itself nudges users away from privacy.

That is a big shift.

A privacy setting that technically exists but is quietly reset, buried or overridden may no longer be enough. Businesses may increasingly have to demonstrate that privacy choices are meaningful and durable.

Children are becoming the centre of AI regulation

California is also taking a particularly aggressive approach to children and technology.

AB 2246 would repeal the state’s controversial Age-Appropriate Design Code Act and replace it with a broader harm-prevention standard for online services likely to be accessed by children.

AB 1709 goes further, targeting addictive design features for users under 16. Covered platforms would be prohibited from offering features such as personalised feeds and autoplay to children in that age group, while also being required to take reasonable measures to prevent children from receiving those features. The bill would create an e-Safety Advisory Commission.

This is particularly significant because it shows regulators moving away from a narrow privacy-by-design model towards something closer to safety-by-design.

The question is no longer simply whether a platform collects too much information about a child. It is whether the way the platform is designed creates foreseeable harm.

That distinction could have major consequences for product teams, not just privacy departments.

Chatbots are becoming a regulatory category of their own

California is also treating AI chatbots as a distinct area of risk.

SB 867 would prohibit companion chatbots from being incorporated into toys.

SB 1119 would add protections for minors using companion chatbots, including independent child-safety audits.

And AB 1609 would impose new requirements on customer-service chatbots operated by large private businesses with more than $500 million in annual national revenue.

This is an important development. Chatbots were initially treated largely as another type of software. California’s approach increasingly treats them as systems that can create their own categories of consumer and child-safety risk.

That matters because the compliance question becomes more sophisticated than “Are we using AI?”

Companies may need to ask what kind of AI system they are deploying, who can interact with it, what the system can say or do, what safeguards exist and whether those safeguards can be independently tested.

Will the workplace be an AI battleground?

Perhaps the most consequential measures for ordinary businesses concern employment.

SB 947, the proposed “No Robo Bosses Act,” would prevent employers from relying solely on an automated decision system to discipline or terminate an employee. Where an employer primarily relies on an AI system, a human would have to corroborate the decision, with a post-use notice provided to the employee.

The significance is not simply the requirement for a human somewhere in the process. It is the suggestion that human accountability cannot be outsourced to an algorithm.

That principle is already familiar from AI governance frameworks around the world, but California would be putting it directly into employment law.

At the same time, AB 1883 would restrict AI-powered workplace surveillance, including tools that collect neural data or attempt to identify a worker’s emotional state. AB 1331 would prohibit employers from monitoring employees in workplace bathrooms.

Employers may increasingly need to demonstrate not just that an AI system is accurate, but that its use is appropriate in the first place.

Healthcare gets a similar human-oversight message

The same principle appears in the healthcare measures.

AB 1979 would prevent healthcare facilities and practices from deploying AI to independently perform clinical functions that legally require a licensed professional.

SB 503 would require developers and deployers of clinical decision-support systems to identify and address reasonably foreseeable risks of biased impacts.

AB 2575 would protect healthcare workers’ ability to exercise professional judgment and override AI-powered clinical decision-support systems.

SB 903 addresses AI and transcription in professional mental-health therapy.

AI can assist professional judgment, but it should not silently replace it. That could become one of the defining principles of California’s AI regime.

And then there are digital replicas

California is also responding to one of the more commercially explosive applications of generative AI, synthetic people.

SB 1111 would clarify that name, image and likeness protections extend to AI-generated digital replicas, including highly realistic synthetic representations of a person’s voice or appearance.

SB 1050 would require clear disclosure when advertisements feature a synthetic performer.

This matters well beyond Hollywood. Marketing departments can now create synthetic presenters, voices and actors without traditional production costs. But California is signalling that consumers should know when the person appearing in an advertisement isn’t actually a person who performed the role.

That creates a new compliance consideration for advertising, influencer marketing and branded content.

Can California regulate the regulators?

There is also an effort to formalise AI auditing itself.

SB 813 would establish a framework for independent third-party assessment of AI safety risks. AB 1405 would create an AI Auditor Registry and establish requirements for organisations conducting AI audits.

AI governance increasingly depends on independent testing such as bias assessments, safety evaluations, security testing, risk assessments and verification of controls. California is now looking at the question of who is qualified to perform those assessments and what makes an AI audit credible.

That could eventually create a market in regulated AI assurance in much the same way that financial and information-security assurance have become established disciplines.

Could this be bigger than California?

California has a history of legislating where technology and consumer protection intersect, and its influence extends far beyond its borders.

The state is home to a huge proportion of the US technology industry. Companies that build products for a national or global market may find it easier to adopt California’s requirements across their entire product rather than create a separate version just for California.

That is how state regulation can become de facto national regulation.

It is also significant that California is not pursuing one giant AI law. Instead, it is building regulation piece by piece: employment, healthcare, children, advertising, chatbots, privacy, auditing and digital identity.

That makes the regulatory landscape harder to reduce to a single compliance checklist.

A business could be compliant with one set of AI requirements and still face obligations under another because of the context in which its AI is being used.

AI compliance is becoming business compliance

Perhaps the most important lesson from California’s 2026 session is that AI regulation is moving away from the technology department.

The proposed laws reach into HR decisions, healthcare, marketing, customer service, product design, privacy operations and workplace management. That means AI governance increasingly has to involve the people who actually make business decisions.

Our AI courses will make sure you are in compliance and can change how work gets done at your company

Try them here →