Existing law requires the governing board of a school district, a county board of education, and the governing body of a charter school to, no later than July 1, 2026, develop and adopt, and update every 5 years, a policy to limit or prohibit the use by its pupils of smartphones while the pupils are at a schoolsite or while the pupils are under the supervision and control of an employee or employees of that local educational agency. Under existing law, a pupil shall not be prohibited from possessing or using a smartphone under specified circumstances, including, among others, when the possession or use of a smartphone is required in a pupil's individualized education program. This bill, commencing July 1, 2028, would require the above-described policy to continue to apply only to pupils in any of grades 9 to 12, inclusive. The bill would require the governing board of a school district, a county board of education, and the governing body of a charter school that serves pupils in transitional kindergarten, kindergarten, or grades 1 to 8, inclusive, to, no later than July 1, 2028, develop and adopt a policy that prohibits the use of smartphones by those pupils while the pupils are at a schoolsite or while the pupils are under the supervision and control of an employee or employees of that local educational agency, as provided. The bill, commencing July 1, 2028, would prohibit instruction provided to pupils in transitional kindergarten, kindergarten, and any of grades 1 to 8, inclusive, from requiring the use of a smartphone by a pupil. The bill, commencing January 1, 2027, would require (1) a pupil in any grade to also be allowed to possess or use a smartphone when the possession or use of a smartphone is required in a pupil's plan developed pursuant to the federal Rehabilitation Act of 1973 and (2) a policy adopted or updated pursuant to these provisions be included in a pupil handbook, if one is provided. By imposing additional duties on local educational agencies, the bill would constitute a state-mandated local program. This bill would require the State Department of Education, on or before January 1, 2029, to submit to the appropriate policy and fiscal committees of the Legislature, and post on their internet website, a report that contains (1) a description of the pupil smartphone policies of at least 30 selected local educational agencies that have provided consent to participate and that are representative of the demographic and geographic diversity of the state, including a copy of each policy, as provided, (2) the results of a survey of those local educational agencies, which the bill would require the department to conduct, and (3) recommended best practices for future local educational agency pupil smartphone use policies. The bill would authorize the department to collaborate with specified organizations with relevant expertise in preparing the report. The bill would repeal these provisions on January 1, 2033. The California Constitution requires the state to reimburse local agencies and school districts for certain costs mandated by the state. Statutory provisions establish procedures for making that reimbursement. This bill would provide that, if the Commission on State Mandates determines that the bill contains costs mandated by the state, reimbursement for those costs shall be made pursuant to the statutory provisions noted above.
(1) Existing law, the Digital Financial Assets Law, prohibits a person, on or after July 1, 2026, from engaging in digital financial asset business activity, or holding itself out as being able to engage in digital financial asset business activity, with, or on behalf of, a resident, unless any of certain criteria are met, including that the person is licensed with the Department of Financial Protection and Innovation, as prescribed, or the person submits an application on or before July 1, 2026, and is awaiting approval or denial of that application. This bill would revise the above-described latter criterion to specify that the person submits a completed application, as provided. The Digital Financial Assets Law authorizes the Commissioner of Financial Protection and Innovation to issue a conditional license to an applicant who holds or maintains a license to conduct virtual currency business activity in the State of New York, as specified, provided the license was issued or approved no later than January 1, 2023. This bill would revise the above-described authorization to require that the license be issued or approved no later than January 1, 2025. (2) The Digital Financial Assets Law defines "digital financial asset business activity" to mean any of specified activities, including, among others, exchanging, transferring, or storing a digital financial asset, as specified, or exchanging one or more digital representations of value used within one or more online games, game platforms, or family of games, as provided. This bill would remove exchanging one or more digital representations of value used within one or more online games, game platforms, or family of games from the definition of "digital financial business activity." The bill would specify that a "digital financial asset" does not include, among other things, a transaction in which a merchant grants digital representations of value that primarily relate to an affinity or rewards program, as provided, or a digital representation of value issued by or on behalf of a publisher and used primarily within online games or game platforms and that is not otherwise a digital financial asset. The Digital Financial Assets Law declares that its provisions do not apply to specified activity, including by a person who does not receive compensation for providing digital financial asset products or services or for conducting financial asset business activity or that is engaged in testing products or services with the person's own funds. This bill would specify that the above-described exclusion includes a person who merely retains the ability to terminate, suspend, or interrupt a digital financial transaction solely to prevent unauthorized or fraudulent activity and who is not compensated for that service. The Digital Financial Assets Law prohibits a covered person from exchanging, transferring, or storing a digital financial asset that is a stablecoin or engaging in digital financial asset administration of a stablecoin, as specified, unless certain conditions are met. However, existing law authorizes a covered person to exchange, transfer, or store a stablecoin or engage in digital financial asset administration of that stablecoin, as specified, if the stablecoin is approved by the commissioner and complies with certain requirements, restrictions, or prohibitions established by the commissioner. This bill would repeal the above-described provisions related to stablecoins. (3) The Digital Financial Assets Law requires a licensee to submit an annual report, as provided, containing specified information, including a description of any data security breach or cybersecurity event of the licensee. Existing law requires a licensee to file with the department, as applicable, a report of, among other things, a change in the licensee's business for the conduct of its digital financial asset business activity with, or on behalf of, a resident that meets one of specified criteria, including that the proposed change might raise safety and soundness or operational concerns. This bill would revise the above-described annual report to instead include a description of any material data security breach or cybersecurity event of the licensee. The bill would revise the specified criteria in the requirement to file the above-described report of a change in the licensee's business to instead include that the proposed change might raise material safety and soundness or operational concerns. Before engaging in digital financial asset business activity with a resident, the Digital Financial Assets Law requires a covered person, defined as a person required to obtain a license pursuant to that law, to disclose, as provided, certain information, including the resident's right to at least 14 days' prior notice of specified changes that have a material impact on digital financial asset business activity with the resident, or the policies applicable to the resident's account. Existing law requires a covered exchange, as provided, to certify on a form provided by the department that the covered exchange has taken specified actions, except for any digital financial asset approved for listing on or before January 1, 2023. In a transaction for or with a resident, existing law prohibits the covered exchange from interjecting a third party between the covered exchange and the best market for the digital financial asset in a manner inconsistent with specified requirements. This bill would prohibit the 14-day notice requirement from applying to changes in terms, conditions, or policies that are reasonably necessary to address a risk of loss to the resident or covered person, to the extent that the change does not relate to the fee schedule. The bill would instead exclude from the above-described certification requirement a digital financial asset approved for listing on or before January 1, 2025. The bill would require a covered person to provide and make available an up-to-date description of the order execution practices of the covered person, as specified. The bill would exempt a transaction in which a resident receives stablecoin, as defined, in exchange for legal tender or bank or credit union credit from the above-described prohibition against interjecting a third party. The Digital Financial Assets Law requires an applicant, as provided, to create, and during licensure, maintain in a record specified policies and procedures. Existing law requires these policies and procedures be disclosed separately from other disclosures made available to a resident, as specified, except for, among other things, an adopted information security program or an operational security program. This bill would instead exclude from the above-described requirement to disclose separately from other disclosures programs with information that is sensitive to potential security risks, as specified. This bill would declare that it is to take effect immediately as an urgency statute.
Existing law prohibits a public agency, which includes the state, a city, a county, a city and county, or any agency or political subdivision of the state, a city, a county, or a city and county, including, but not limited to, a law enforcement agency, from selling, sharing, or transferring automated license plate recognition (ALPR) information, except to another public agency, and only as otherwise permitted by law. Existing law defines ALPR information as information or data collected through the use of an ALPR system. This bill would provide that "public agency" does not include a transportation agency, a public transit operator, or a local department of transportation or public works department, as specified. The bill would, beginning January 1, 2026, require new, updated, expansions of, or addendums of contractual agreements with ALPR vendors, manufacturers, or suppliers to mandate that no default access is provided to any national ALPR database and that an agency's collected scans are by default not accessible to any other agency, and would impose new requirements on sharing between California state law enforcement agencies. The bill would authorize a law enforcement agency to use ALPR information only for purposes of locating vehicles or persons when either are reasonably suspected of being involved in the commission of a public offense. The bill would prohibit a public agency from retaining ALPR information for more than 60 days after the date of collection if it does not match information on an authorized hot list, as defined, and as of January 1, 2026, would require a public agency to delete all ALPR information that has been held for more than 60 days and does not match information on an authorized hot list within 14 days. By imposing new requirements on public agencies, which include local agencies, this bill would impose a state-mandated local program. Existing law defines an ALPR operator as a person that operates an ALPR system, which does not include a transportation agency. Existing law defines an ALPR end-user a person that accesses or uses an ALPR system, which does not include, among other things, a transportation agency. This bill would additionally exclude from the definitions of "ALPR operator" and "ALPR end-user" a public transit operator, a local department of transportation or public works department, or an airport or airport operator, as provided. Existing law requires an ALPR operator and ALPR end-user to maintain reasonable security procedures and practices, including operational, administrative, technical, and physical safeguards, to protect ALPR information from unauthorized access, destruction, use, modification, or disclosure. This bill would require those security procedures and practices to include safeguards for managing which employees can see the data from their systems, as specified, and requiring data security training and data privacy training for all employees that access ALPR information. Existing law requires an ALPR operator and ALPR end-user to implement a usage and privacy policy that includes, among other things, a description of the job title or other designation of the employees and independent contractors who are authorized to access and use ALPR information. This bill would require the usage and privacy policy to identify what purpose employees and independent contractors access and use ALPR information for. The bill would also require the Department of Justice to, contingent upon an appropriation of sufficient funds, conduct annual random audits on a public agency that is an ALPR operator or ALPR end-user to determine whether they have implemented and are adhering to that usage and privacy policy. Existing law requires an ALPR operator that accesses or provides access to ALPR information to require that ALPR information only be used for the authorized purposes described in the usage and privacy policy and to maintain a record of that access that includes, among other things, the purpose for accessing the information. This bill would instead require that record of access maintained by the ALPR operator to include the case file number or task force name, as applicable, that justifies the search query, and would provide that no queries shall be allowed without a log entry with a valid and current case file number or task force name from the agency conducting the query. The bill would include findings that changes proposed by this bill address a matter of statewide concern rather than a municipal affair and, therefore, apply to all cities, including charter cities. The California Constitution requires the state to reimburse local agencies and school districts for certain costs mandated by the state. Statutory provisions establish procedures for making that reimbursement. This bill would provide that, if the Commission on State Mandates determines that the bill contains costs mandated by the state, reimbursement for those costs shall be made pursuant to the statutory provisions noted above.
Existing law requires the Department of Technology to conduct, in coordination with other interagency bodies as it deems appropriate, a comprehensive inventory of all high-risk automated decision systems (ADS) that have been proposed for use, development, or procurement by, or are being used, developed, or procured by, any state agency. Existing law establishes the Labor and Workforce Development Agency, which is composed of various departments responsible for protecting and promoting the rights and interests of workers in California, including the Division of Labor Standards Enforcement, led by the Labor Commissioner, within the Department of Industrial Relations. This bill would require an employer to provide a written notice that an ADS, for the purpose of making employment-related decisions, not including hiring, is in use at the workplace to all workers that will foreseeably be directly affected by the ADS, as specified. The bill would require the employer to maintain an updated list of all ADS currently in use. The bill would require an employer to notify, as provided, a job applicant that the employer utilizes an ADS when making hiring decisions, if the employer will use the ADS in making decisions for that position. The bill would prohibit an employer from using an ADS that does certain functions and would limit the purposes and manner in which an ADS may be used to make decisions. The bill would authorize a worker to request, and require an employer to provide, a copy of the most recent 12 months of the worker's own data primarily used by an ADS to make a discipline, termination, or deactivation decision, as specified. The bill would require an employer that primarily relied on an ADS to make a discipline, termination, or deactivation decision to provide the affected worker with a written notice, as specified. This bill would prohibit an employer from discharging, threatening to discharge, demoting, suspending, or in any manner discriminating or retaliating against any worker for taking certain actions asserting their rights under the bill. The bill would require the Labor Commissioner to enforce the bill's provisions, as specified, and would authorize a public prosecutor to bring a civil action. The bill would set forth specified types of relief that a plaintiff may seek and specified penalties that an employer that violates these provisions is subject to, including a $500 civil penalty. The bill would also provide that an employer who complies with the requirements related to notice in this bill is not required to comply with any substantially similar provisions under any other state law, except as specified. The bill would not apply to parties covered by a valid collective bargaining agreement if the agreement contains specified information, including an explicit waiver of the bill's provisions. The bill would declare that its provisions do not prohibit any employer from complying with regulatory or contractual requirements in the provision of products or services to the federal government, as defined. This bill would declare that its provisions are severable.
Existing law generally provides for the regulation of law enforcement agencies, including, among other things, requiring each local law enforcement agency to conspicuously post on their internet websites all current standards, policies, practices, operating procedures, and education and training materials that would otherwise be available to the public under specified circumstances. This bill would require each law enforcement agency to maintain a policy to require an official report prepared by a law enforcement officer or any member of a law enforcement agency that is generated using artificial intelligence either fully or partially to include specified information, including a disclosure statement and the signature of the law enforcement officer or member of a law enforcement agency who prepared the official report, as specified. If an officer or any member of an agency uses artificial intelligence to create an official report, the bill would require the first draft created to be retained for as long as the official report is retained. The bill would, except for the official report, prohibit a draft of any report created with the use of artificial intelligence from constituting an officer's statement. The bill would require an agency utilizing artificial intelligence to generate a first draft or official report to maintain an audit trail that identifies, at a minimum, certain things, including the person who used artificial intelligence to create a report. The bill would prohibit a contracted vendor from sharing, selling, or otherwise using information provided by a law enforcement agency to be processed by artificial intelligence, except as provided. The bill would define terms for purposes of these provisions. By requiring local law enforcement agencies to adopt a new policy, this bill would impose a state-mandated local program. The California Constitution requires the state to reimburse local agencies and school districts for certain costs mandated by the state. Statutory provisions establish procedures for making that reimbursement. This bill would provide that, if the Commission on State Mandates determines that the bill contains costs mandated by the state, reimbursement for those costs shall be made pursuant to the statutory provisions noted above.
Existing law provides that it is the intent of the Legislature that all public schools, teaching kindergarten or any of grades 1 to 12, inclusive, operated by a school district, in cooperation with specified entities and individuals, develop a comprehensive school safety plan, as provided. Existing law provides that school districts and county offices of education are responsible for the overall development of a comprehensive school safety plan for each of its schools, as provided. Existing law requires a comprehensive school safety plan to, among other things, identify appropriate strategies and programs that will provide or maintain a high level of school safety and address the school's procedures for complying with existing laws related to school safety. Existing law requires the governing board of a school district, a county board of education, and the governing body of a charter school to, by July 1, 2026, develop and adopt a policy to limit or prohibit the use by its pupils of smartphones while the pupils are at a schoolsite or while the pupils are under the supervision and control of an employee or employees of that school district, county office of education, or charter school. Existing law, however, specifies circumstances in which a pupil may not be prohibited from possessing or using a smartphone, including, among others, in the case of an emergency or in response to a perceived threat of danger. This bill would instead authorize the prohibition on the use of a smartphone by a pupil in the case of an emergency or in response to a perceived threat of danger if that circumstance is explicitly addressed in a comprehensive school safety plan.
(1) Existing law generally regulates artificial intelligence, including by requiring, on or before January 1, 2026, and before each time thereafter, that a generative artificial intelligence system or service, or a substantial modification to a generative artificial intelligence system or service, released on or after January 1, 2022, is made publicly available to Californians for use, the developer of the system or service to post on the developer's internet website documentation regarding the data used by the developer to train the generative artificial intelligence system or service, as prescribed. This bill would enact the Transparency in Frontier Artificial Intelligence Act (TFAIA) that would, among other things related to ensuring the safety of a foundation model, as defined, developed by a frontier developer, require a large frontier developer to write, implement, and clearly and conspicuously publish on its internet website a frontier AI framework that applies to the large frontier developer's frontier models and describes how the large frontier developer approaches, among other things, incorporating national standards, international standards, and industry-consensus best practices into its frontier AI framework. The TFAIA would also require a large frontier developer to transmit to the Office of Emergency Services a summary of any assessment of catastrophic risk, as defined, resulting from internal use of its frontier models, as specified. The TFAIA would require the Office of Emergency Services to establish a mechanism to be used by a frontier developer or a member of the public to report, as prescribed, a critical safety incident, as defined, and would also require the Office of Emergency Services to establish a mechanism to be used by a large frontier developer to confidentially submit summaries of any assessments of the potential for catastrophic risk resulting from internal use of its frontier models, as prescribed. The TFAIA would exempt from the California Public Records Act a report of a critical safety incident submitted to the Office of Emergency Services, a report of assessments of catastrophic risk from internet use, and a covered employee report made pursuant to the whistleblower protections described below. The TFAIA would impose a civil penalty for noncompliance with the TFAIA to be enforced by the Attorney General, as prescribed. (2) Existing law establishes the Department of Technology within the Government Operations Agency. Existing law requires the department to conduct, in coordination with other interagency bodies as it deems appropriate, a comprehensive inventory of all high-risk automated decision systems that have been proposed for use, development, or procurement by, or are being used, developed, or procured by, any state agency. This bill would establish within the Government Operations Agency a consortium required to develop a framework for the creation of a public cloud computing cluster to be known as "CalCompute" that advances the development and deployment of artificial intelligence that is safe, ethical, equitable, and sustainable by, among other things, fostering research and innovation that benefits the public, as prescribed. The bill would require the Government Operations Agency to, on or before January 1, 2027, submit a report from the consortium to the Legislature with that framework and would dissolve the consortium upon submission of that report. The bill would make those provisions operative only upon an appropriation in a budget act, or other measure, for its purposes. (3) Existing law prohibits employers and their agents from making, adopting, or enforcing a rule, regulation, or policy preventing an employee from disclosing information to certain entities or from providing information to, or testifying before, any public body conducting an investigation, hearing, or inquiry if the employee has reasonable cause to believe that the information discloses a violation of a law, as specified, and prohibits retaliation against an employee for, among other things, exercising these rights. This bill would, among other things related to protecting whistleblowers working with foundation models, prohibit a frontier developer from making, adopting, enforcing, or entering into a rule, regulation, policy, or contract that prevents a covered employee, as defined, from disclosing, or retaliates against a covered employee for disclosing, information to the Attorney General, a federal authority, a person with authority over the covered employee, or another covered employee who has authority to investigate, discover, or correct the reported issue, if the covered employee has reasonable cause to believe that the information discloses that the frontier developer's activities pose a specific and substantial danger to the public health or safety resulting from a catastrophic risk or that the frontier developer has violated the TFAIA. This bill would require a large frontier developer to provide a certain internal process through which a covered employee may anonymously disclose information to the large frontier developer if the covered employee believes in good faith that the information indicates that the large frontier developer's activities present a specific and substantial danger to the public health or safety resulting from a catastrophic risk or that the large frontier developer violated the TFAIA. The bill would specify provisions particular to the enforcement of those whistleblower protections and would authorize attorney's fees to a plaintiff who brings a successful action for a violation. This bill would preempt any rule, regulation, code, ordinance, or other law adopted by a city, county, city and county, municipality, or local agency on or after January 1, 2025, specifically related to the regulation of frontier developers with respect to their management of catastrophic risk. Existing constitutional provisions require that a statute that limits the right of access to the meetings of public bodies or the writings of public officials and agencies be adopted with findings demonstrating the interest protected by the limitation and the need for protecting that interest. This bill would make legislative findings to that effect.
Existing law establishes the Attorney General as the head of the Department of Justice, with charge of all legal matters in which the state is interested, except as specified. Existing law imposes various responsibilities on the Attorney General related to consumer protection, including, among others, the supervision of charitable trusts and the enforcement of antitrust laws. Existing law, commonly known as the Cartwright Act, identifies certain acts that are unlawful restraints of trade and unlawful trusts and prescribes provisions for its enforcement through civil actions. This bill would enact the California Preventing Algorithmic Collusion Act of 2025, to prohibit a person, as described, from distributing or making recommendations based on the use of a pricing algorithm to 2 or more competitors, as defined, under specified circumstances, if the person knows or should know that the pricing algorithm processes competitor data, as defined. This bill would also prohibit a person from using the recommendation of a pricing algorithm that processes competitor data, as specified, if the person knows or should know that the pricing algorithm uses or incorporates competitor data. The bill would establish an affirmative defense to liability under this prohibition for a person who demonstrates by a preponderance of evidence that they exercised reasonable due diligence before using the recommendations of a pricing algorithm, as specified. The bill would specify when the use, recommendation, or distribution of a pricing algorithm constitutes separate violations. The bill would declare that these provisions do not apply if all of the competitor data processed by the pricing algorithm was collected more than one year before the use, recommendation, or distribution of the pricing algorithm. The bill would declare that a contract that violates these provisions is to that extent void. This bill would authorize the Attorney General, a district attorney, a county counsel, or a city attorney to bring a civil action for violation of the above-described provisions to seek restitution, punitive damages, a civil penalty of up to $25,000 per violation, and other appropriate relief, as provided. The bill would declare that its provisions shall not impair or limit the applicability of antitrust laws, as defined. The bill would exempt from its provisions the development, distribution, output, or use of a credit score or other computational tool either subject to specified law or provided by a commercial credit reporting agency, as specified.
Existing law, the California Consumer Privacy Act of 2018 (CCPA) , grants a consumer various rights with respect to personal information that is collected or sold by a business, as defined, including the right to direct a business that sells or shares personal information about the consumer to third parties not to sell or share the consumer's personal information, as specified. Existing law, the California Privacy Rights Act of 2020, approved by the voters as Proposition 24 at the November 3, 2020, statewide general election, amended, added to, and reenacted the CCPA and establishes the California Privacy Protection Agency and vests the agency with full administrative power, authority, and jurisdiction to enforce those provisions. Existing law requires a retail grocery store or grocery department within a general retail merchandise store that uses a point-of-sale system to have a clearly readable price indicated on 85% of the total number of packaged consumer commodities offered for sale, subject to specified exemptions. This bill would, subject to certain exceptions, prohibit a grocery establishment, as defined, from engaging in surveillance pricing. The bill would define "surveillance pricing" to mean offering or setting a customized price increase for a good or service for a specific consumer or group of consumers, based, in whole or in part, on personally identifiable information collected through electronic surveillance technology, as specified. The bill would provide that only a public prosecutor, as specified, may bring an action against a violator of these provisions to recover specified civil penalties, injunctive relief, and reasonable attorney's fees and costs, and would authorize a consumer to bring an action for injunctive relief and reasonable attorney's fees and costs. The bill would declare that any waiver of these provisions is against public policy and is void and unenforceable. This bill would declare that its provisions further the purposes and intent of the California Privacy Rights Act of 2020.
Existing law requires the Public Utilities Commission to appoint a chief internal auditor to hold office at the pleasure of the commission. Existing law requires the chief internal auditor to be responsible for the oversight of the internal audit unit and to plan, initiate, and perform audits of key financial, management, operational, and information technology functions within the commission to improve accountability and transparency to executive and state management. This bill would delete the provision providing for the appointment of the chief internal auditor and instead provide that, effective January 1, 2026, the internal audit unit of the commission and its staff are transferred to the Independent Office of Audits and Investigations, which the bill would establish within the commission, as specified. The bill would provide for the appointment and removal of the director of the office, who would have the title of Inspector General. The bill would require that the office have access and authority to examine all records, files, documents, accounts, reports, correspondence, or other property of the commission, public utilities, and other entities regulated by the commission, as specified. The bill would require the Inspector General to report to the Governor and the Legislature, as provided. Under existing law, a violation of the Public Utilities Act or any order, decision, rule, direction, demand, or requirement of the commission is a crime. Because the provisions of this bill would be a part of the act and because a violation of a commission action implementing the bill's requirements would be a crime, the bill would impose a state-mandated local program. The California Constitution requires the state to reimburse local agencies and school districts for certain costs mandated by the state. Statutory provisions establish procedures for making that reimbursement. This bill would provide that no reimbursement is required by this act for a specified reason.