presentofai

California Enacts New Wave of AI and Privacy Laws

TL;DR

California's Governor Newsom signed a sweeping batch of AI and privacy bills by the September 30 deadline, making the state the third in the U.S. to mandate independent AI audits and enacting some of the strictest child online safety rules in the country.

What happened

  • Dozens of AI and privacy bills passed the California legislature on August 31, triggering a 30-day signing window that expired September 30.
  • SB 947, the "No Robo Bosses Act of 2026", signed on the deadline, bars employers from relying solely on automated decision systems for disciplinary or termination decisions.
  • AB 1405 and SB 813 place California alongside Connecticut and Virginia as the only states with a statutory independent AI auditing framework, including recognized third-party verification organizations.
  • Three child safety bills (AB 226, AB 1709, SB 1119) were signed September 10: AB 226 replaces the Age-Appropriate Design Code Act with stricter requirements, AB 1709 bans addictive platform features for users under 16, and SB 1119 requires independent child safety audits for companion chatbot operators.
  • AB 883 and SB 923 tighten data broker deletion rules, increasing DROP access frequency from every 45 days to every 30 days and expanding CCPA deletion rights to cover data a business collected indirectly about a consumer.

Why it matters

  • California effectively sets national standards: companies often apply its stricter rules nationwide rather than carve out state-by-state compliance, meaning these laws will shape AI and privacy practices far beyond California's borders.
  • AI auditing becomes a compliance cost center: organizations deploying AI systems must now plan for third-party assessments and independent verification, a requirement that will ripple through vendor contracts and procurement.
  • "No Robo Bosses" shifts HR tech liability: automated performance management and workforce analytics tools face direct legal exposure, a significant constraint on enterprise AI adoption in employment contexts.
  • Chatbot operators face new private litigation risk: SB 1119 grants children and parents a private right of action for harms caused by AI companion chatbots, a sharper enforcement mechanism than the agency-only model used in most other new bills, motivated in part by the death of teenager Adam Raine after months of interactions with ChatGPT.
  • Federal and state trajectories are diverging: while top AI executives were in Washington endorsing self-regulation alongside the Trump administration, California was codifying mandatory audits and hard prohibitions, setting up a structural conflict for multistate operators.

What to watch next

  • Legal challenges from the tech industry: California's child safety laws have already faced First Amendment suits; the new wave of bills, especially addictive-feature bans and chatbot audit mandates, are likely targets.
  • Whether other states follow on AI auditing: Connecticut and Virginia already have frameworks; if large industrial states adopt similar laws, a de facto national AI audit standard emerges without federal action.
  • SB 1000's immediate effect: the bill expanding the California AI Transparency Act took effect immediately upon signing, making it the first live test of how AI content provenance disclosures are enforced in practice.

Originally published on Present of AI, a daily source-linked AI news timeline. Read the full timeline or browse the open dataset.