Critical infrastructure: artificial intelligence systems: human oversight.
What changed between versions
The bill's core AI oversight provisions were moved from Section 8592.51 into a new Article 6.6 (Sections 8954.50, 8954.51, 8954.52) in Chapter 7 of Division 1 of Title 2 of the Government Code, changing the statutory placement and organization.
The definition of 'critical infrastructure' was expanded from six sectors (transportation, energy, food and agriculture, communications, emergency services, financial services) to a much longer list including chemical, commercial facilities, critical manufacturing, dams, defense industrial base, government facilities, health care and public health, information technology, nuclear reactors, materials and waste, and water and wastewater systems.
One legislative finding paragraph (regarding workforce development emphasis in the Governor's executive order) was removed from Section 1, though similar content remains in a renumbered paragraph.
A new defined term 'covered AI system' was added, meaning an AI system or automated decision system that an operator uses to operate, manage, oversee, or control access to critical infrastructure. All oversight requirements now apply specifically to 'covered AI systems' rather than broadly to any deployed artificial intelligence.
The definition of 'operator' was broadened from 'a state agency in charge of critical infrastructure' to 'a state agency responsible for operating, managing, overseeing, or controlling access to critical infrastructure,' potentially capturing more agencies.
New definitions were added for 'Department' (Department of Technology), 'Office' (Office of Emergency Services), and 'State agency' (incorporating the meaning from Section 11000).
A specific compliance deadline of July 1, 2026 was added for operators to establish their human oversight mechanisms.
The exception to real-time human review and approval was significantly expanded. Previously it only applied to existing automated decision systems critical to state infrastructure where oversight would cause an immediate pause that would destabilize the system. Now, if oversight personnel determine that prior review and approval is 'substantially disruptive to the operation of the covered AI system,' the operator may instead implement a process for periodically reviewing the system's actions to ensure accuracy and reliability.
Training requirements were changed: the Department of Technology must now 'develop' (rather than 'administer') specialized training, which must be given annually. Operators must designate at least one employee as oversight personnel responsible for administering the human oversight mechanism, and that person must complete the annual training.
Annual assessments are now conducted by 'oversight personnel' rather than the operator generally. A new assessment element was added requiring identification of necessary updates to the human oversight mechanism. The risk threshold was expanded to include property damage in excess of $500,000 in addition to mass casualty events.