Existing law, the California Age-Appropriate Design Code Act, requires a business that provides an online service, product, or feature likely to be accessed by children to comply with certain requirements, including, among other things, prohibiting the business from collecting, selling, sharing, or retaining any personal information that is not necessary to provide the online service, product, or feature, except as specified. Existing law imposes specified civil penalties upon a business that violates these provisions. This bill would repeal the above-described act and would instead impose similar provisions without the above-referenced exceptions and would impose civil penalties for a violation of these provisions. The bill would require a business that provides an online product or service likely to be accessed by children to take reasonable steps to prevent specified risks of harm to children. The bill would authorize a child to void any provision of a contract that was entered into by the child or their parent or guardian as a result of a design feature of the online product or service. The bill would authorize the Attorney General or a public prosecutor to bring a civil action for a violation of these provisions, as specified.
Existing law makes it a crime to knowingly or willfully cause another person to engage in the unlawful manufacture of firearms or knowingly or willfully aiding, abetting, prompting, or facilitating the unlawful manufacture of firearms, including the manufacture of assault weapons or .50 BMG rifles or the manufacture of any firearm using a 3-dimensional printer, as specified. Existing law authorizes a civil action against a person who knowingly distributes or causes to be distributed any digital firearm manufacturing code to any person, except as specified. Existing law authorizes the Attorney General, county counsel, or city attorney to bring an action against this person and seek a civil penalty, as specified, for each violation, as well as injunctive relief. This bill would require the Department of Justice to check on a quarterly basis beginning no later than July 1, 2027, whether ASTM International has published industry standards for equipping 3-dimensional printers with firearm blocking technology. The bill would require, if the department determines that ASTM International has published or adopted industry standards for firearm blocking technology for 3-dimensional printers, that the department publish written guidance or regulations within 24 months after making that determination. The bill would require, among other things, the written guidance or regulations to describe minimum performance standards for 3-dimensional printer firearm blocking technology before a printer can lawfully be sold or offered for sale in the state. If, as of July 1, 2029, the department determines that ASTM International has not published industry standards for firearm blocking technology for 3-dimensional printers, the bill would relieve the department of any further responsibility to ascertain whether ASTM International has published or adopted industry standards. The bill would make it unlawful to sell, offer for sale, or transfer for consideration, a 3-dimensional printer in the State of California that is not equipped with firearm blocking technology that also meets the above-described industry standards. The bill would exempt printers used exclusively for the manufacturing of properties (props) in the entertainment industry, and would authorize the department to adopt regulations that provide for additional exceptions to these provisions. This bill would also exempt a person who distributes, or causes the distribution of, digital firearm manufacturing code, solely for the bona fide purpose of, among other things, developing, refining, and testing the functionality of a firearm blocking technology from civil liability. This bill would make these provisions severable.
Existing law establishes the Division of Labor Standards Enforcement within the Department of Industrial Relations. Existing law authorizes the division, which is headed by the Labor Commissioner, to enforce the Labor Code and all labor laws of the state, the enforcement of which is not specifically vested in any other officer, board, or commission. This bill would, with certain exceptions, prohibit an employer from using a workplace surveillance tool that uses artificial intelligence to, among other things, collect neural data or recognize an individual's emotional state. The bill would define an employer to include a governmental entity, including, among other entities, charter cities and the University of California. This bill would authorize the Labor Commissioner or a public prosecutor to enforce the bill's provisions. The bill would subject an employer who violates the bill's provisions to a civil penalty of up to $500 for each violation. The bill would define various terms for purposes of its provisions. This bill would exempt from its provisions an employer's use of a workplace surveillance tool in specified operations where the use of a workplace surveillance tool is reasonable necessary to comply with a federal statute, federal regulation, or binding federal contract relating to the development of aircraft for use in the national airspace or the development of products or services for national security, military, space, or defense purposes. The bill would include findings that changes proposed by this bill address a matter of statewide concern rather than a municipal affair and, therefore, apply to all cities, including charter cities.
Existing law establishes the Office of Data and Innovation within the Government Operations Agency with a mission to deliver better government services to the people of California through technology and service innovation, data, and design. Existing law establishes the Data and Innovation Services Revolving Fund consisting of certain sources of moneys including donations, endowments, or grants of funds from private or public sources that commit to the office's mission of ethical, efficient, effective, secure, and responsible use of data in a manner that respects privacy. Exiting law makes moneys in the fund available upon appropriation of the Legislature, as specified. This bill would establish the Engaged California Program within the office. The bill would require the office to, among other things, design, establish, and maintain a platform for ongoing dialogue between Californians and state government and to establish best practices for its use. Subject to certain conditions, including upon appropriation by the Legislature for the express purpose of running the Engaged California Program, the bill would require topics to be selected for deliberation in accordance with specified procedure and would require state agencies identified by the office to coordinate outreach, among other things. The bill would require the Data and Innovation Services Revolving Fund to consist of supplemental funding for the Engaged California Program from partner organizations. The bill would prohibit organizations that provide that funding from participating in the selection of a topic for deliberation and from participating in the deliberation. The bill would also make any unspent funds appropriated for the Engaged California Program during the 2026–27 fiscal year available for use by that program during the 2027–28 fiscal year.
Existing law, the Protecting Our Kids from Social Media Addiction Act, prohibits an operator of an addictive internet-based service or application from providing an addictive feed, as defined, to a user unless the operator does not have actual knowledge that the user is a minor, as specified, or the operator has obtained verifiable parental consent to provide an addictive feed to the user who is a minor. Existing law, the Digital Age Assurance Act, beginning January 1, 2027, requires a person who owns, maintains, or controls a software application, as defined, to request age bracket data sent by a real-time secure application programming interface or operating system with respect to a particular user from an operating system provider or a covered application store when the application is downloaded and launched. This bill would prohibit a covered platform, as defined, from providing an addictive feature, as defined, to a user who is under 16 years of age and would require a covered platform to implement reasonable measures to ensure that users under 16 years of age are not offered or provided any addictive feature on the covered platform. The bill would also authorize the Attorney General to adopt regulations to implement and enforce the bill in order to further the purpose of protecting minors online, including by altering the scope of "covered platform" if the Attorney General determines that doing so is necessary to ensure that "covered platform" applies to internet websites, online services, online applications, or mobile applications that make addictive features, as defined, available to users under 16 years of age. This bill would impose a civil penalty upon a noncompliant platform and would require its provisions to be enforced by a civil action brought only by the Attorney General or a local public prosecutor, as specified. This bill would also establish the e-Safety Advisory Commission within the Department of Justice as an independent advisory body that is only for administrative purposes to advise state government on certain matters related to online safety and would require the commission to, on or before January 1 of each year, report to the Legislature and the Governor on, among other things, its activities under the bill.
Existing law, the K–12 Pupil Online Personal Information Protection Act (KOPIPA) , generally protects the personal information of a student enrolled in a K–12 course of instruction, defined as a "pupil," by prescribing requirements and prohibitions applicable to an operator of an internet website, online service, online application, or mobile application with actual knowledge that the site, service, or application is used primarily for K–12 school purposes and was designed and marketed for K–12 school purposes. Existing law, the Early Learning Personal Information Protection Act (ELPIPA) , generally protects the personal information of a child enrolled in a preschool or prekindergarten course of instruction, defined as a "pupil," by prescribing requirements and prohibitions applicable to an operator of an internet website, online service, online application, or mobile application with actual knowledge that the site, service, or application is used primarily for preschool or prekindergarten purposes and was designed and marketed for preschool and prekindergarten purposes. This bill would instead apply the provisions of KOPIPA and ELPIPA to an operator, or an entity working on behalf of the operator, of an internet website, online service, online application, or mobile application with actual knowledge that the site, service, or application is used for the applicable school purposes and was designed or marketed for those purposes, as specified. The bill would, among other changes to KOPIPA and ELPIPA related to protecting the personal information of students, prohibit an operator from using covered information, as defined, including persistent unique identifiers, created or gathered by the operator's site, service, or application to train a generative artificial intelligence system or service or develop an artificial intelligence system. This bill would also enact the Higher Education Student Information Protection Act (HESIPA) , which would generally protect the personal information of a student enrolled in a higher education institution, as defined, in a similar manner as KOPIPA and ELPIPA. The bill would make HESIPA operative on July 1, 2027. This bill would authorize a pupil or student actually harmed by noncompliance with KOPIPA, ELPIPA, or HESIPA to bring a civil action against the noncompliant operator, as prescribed, and would require a person bringing that action to furnish a copy of the complaint to the Attorney General within 10 days after filing the action.
Existing law requires, on or before September 1, 2024, the Department of Technology, within the Government Operations Agency, to conduct, in coordination with other interagency bodies as it deems appropriate, a comprehensive inventory of all high-risk automated decision systems that have been proposed for use, development, or procurement by, or are being used, developed, or procured by, any state agency. Existing law requires the department to annually submit a report of that comprehensive inventory to the Assembly Committee on Privacy and Consumer Protection and the Senate Committee on Governmental Organization. Existing law, the Transparency in Frontier Artificial Intelligence Act, among other things related to ensuring the safety of certain artificial intelligence models, requires a large frontier developer to write, implement, and clearly and conspicuously publish on its internet website a frontier AI framework that applies to the large frontier developer's frontier models and describes how the large frontier developer approaches, among other things, incorporating national standards, international standards, and industry-consensus best practices into its frontier AI framework. This bill would require, on or before January 1, 2028, the Government Operations Agency to take certain actions related to the selection and regulation of certain entities, defined as "independent verification organizations," designated by the agency as having demonstrated expertise in assessing the risks posed by an AI system or model and identifying the metrics and methodologies that form the basis for that assessment. The bill would require the agency to convene working groups to solicit stakeholder input in the identification of standards and the development and revision of procedures and criteria, as specified. The bill would require the agency to provide a report to the Legislature on the findings of the working groups and would require a designated IVO to submit annually, and no sooner than 12 months after initial designation as an IVO, to the agency and Legislature a report, as specified.
Existing law requires a health facility, clinic, physician's office, or office of a group practice that uses generative artificial intelligence to generate written or verbal patient communications pertaining to patient clinical information, as defined, to ensure that those communications include both (1) a disclaimer that indicates to the patient that a communication was generated by generative artificial intelligence, as specified, and (2) clear instructions describing how a patient may contact a human health care provider, employee, or other appropriate person. Existing law exempts from this requirement a communication read and reviewed by a human licensed or certified health care provider. This bill would require developers and deployers, as defined, of an artificial intelligence system that produces a prediction, classification, recommendation, evaluation, or analysis that aids decisionmaking related to diagnosis or treatment, known as a clinical decision support system, to make reasonable efforts to identify clinical decision support systems developed for use by deployers that are known or have a reasonably foreseeable risk for biased impacts resulting from deployment of the system in health programs or activities. The bill would require developers to make a statement describing the intended uses and known or reasonably foreseeable risks associated with the use of the clinical decision support system and certain documentation available to deployers, as specified. The bill would require developers to make reasonable efforts to mitigate known or reasonably foreseeable risk for biased impacts resulting from use of the clinical decision support system in health programs or activities. The bill would require deployers to regularly monitor clinical decision support systems and take reasonable and proportionate steps to mitigate known or reasonably foreseeable risk of biased impacts. The bill would specify that a person, partnership, state or local governmental agency, or corporation may be both a developer and a deployer.
Existing law establishes the Department of Technology within the Government Operations Agency. Existing law requires the department to conduct, in coordination with other interagency bodies as it deems appropriate, a comprehensive inventory of all high-risk automated decision systems that have been proposed for use, development, or procurement by, or are being used, developed, or procured by, any state agency. Existing law generally regulates artificial intelligence, including the Transparency in Frontier Artificial Intelligence Act, which, among other things related to the safety of certain artificial intelligence models, requires a large frontier developer to write, implement, comply with, and clearly and conspicuously publish on its internet website a frontier AI framework that applies to the large frontier developer's frontier models and describes how the large frontier developer approaches certain safety-related items. Existing law defines "artificial intelligence" as an engineered or machine-based system that varies in its level of autonomy and that can, for explicit or implicit objectives, infer from the input it receives how to generate outputs that can influence physical or virtual environments. This bill would require the Government Operations Agency to, no later than January 1, 2029, establish an AI Auditor Registry on the agency's internet website allowing AI auditors to register with the agency and allowing natural persons to report misconduct by a registered AI auditor, and require the agency to fix annual registration fees, as specified. The bill would, commencing January 1, 2029, prohibit an unregistered person from offering, selling, or conducting a covered AI audit, as defined, and would require the agency to, among other things, issue a unique registration number to each registered AI auditor and publish information provided by a registered AI auditor on the agency's internet website. The bill would require the registration number of a registered AI auditor to be clearly and conspicuously displayed on all advertising materials offering or soliciting covered AI audit services. The bill would authorize the agency to adopt regulations that are reasonably necessary to effectuate the purposes of the bill. This bill would require an AI auditor that registers with the agency to provide specified information to the agency and would impose various requirements on a registered AI auditor that conducts a covered AI audit, including, among other things, providing the auditee with a report that includes a signed and dated statement indicating that the audit was conducted according to the provisions of this bill. This bill would require a registered AI auditor to adhere to various standards of independence, objectivity, and integrity, including not seeking, soliciting, negotiating for, or accepting employment with an auditee while participating in the audit and not conducting a covered AI audit if the auditor has a financial, business, employment, or other interest or relationship that would reasonably be expected to impair the auditor's independence or objectivity. The bill would prohibit a registered AI auditor from preventing an employee from engaging in, or from retaliating against an employee who has engaged in, specified whistleblower activity. The bill would authorize the agency to investigate alleged violations of the bill, as specified, and provide that a violation constitutes grounds for removal from the registry and referral to the Attorney General or other appropriate enforcement authority. This bill would create the AI Auditors' Registration Fund within the State Treasury, to be administered by the agency, and would require that all moneys collected or received by the agency pursuant to the above-described provisions be deposited into the fund to be available, upon appropriation by the Legislature, to administer the above-described provisions. Existing law establishes the California Board of Accountancy, which is within the Department of Consumer Affairs, and requires the board to license and regulate accountants in this state. This bill would exempt a registered AI auditor licensed or authorized to practice public accountancy and a firm holding a permit to practice public accountancy issued by the California Board of Accountancy, as specified, from complying with certain requirements related to reporting information to the agency and standards of independence, objectivity, and integrity under the bill if certain requirements are met. The bill would require the Government Operations Agency to, if the agency determines that a certified public accountant, public accountant, or accounting firm in good standing has violated this bill, notify the accountant or firm and the California Board of Accountancy in writing, and would require the board to investigate the complaint and provide the agency with a report of its findings and any resulting action.
Existing law establishes the Division of Labor Standards Enforcement within the Department of Industrial Relations. Existing law authorizes the division, which is headed by the Labor Commissioner, to enforce the Labor Code and all labor laws of the state the enforcement of which is not specifically vested in any other officer, board, or commission. This bill would limit the use of workplace surveillance tools, as defined, by employers, including by prohibiting an employer from monitoring or surveilling employees in a bathroom located in the workplace, except as specified. The bill would provide an employee with the right to leave behind workplace surveillance tools that are on their person or in their possession when entering a bathroom, except as specified. This bill would authorize the commissioner to enforce the bill's provisions, as prescribed, and would authorize a public prosecutor to bring specified enforcement actions. The bill would subject an employer who violates the bill to a civil penalty of up to $500 for each violation. The bill would include findings that changes proposed by this bill address a matter of statewide concern rather than a municipal affair and, therefore, apply to all cities, including charter cities.