Existing law establishes the Medi-Cal program, which is administered by the State Department of Health Care Services and under which qualified low-income individuals receive health care services. The Medi-Cal program is, in part, governed and funded by federal Medicaid program provisions. Existing law generally imposes penalties on a person who negligently, willfully, or maliciously discloses the results of a human immunodeficiency virus (HIV) test to a third party in a manner that identifies or provides identifying characteristics of the person to whom the test results apply, as specified. Existing law, notwithstanding the above-described restrictions, authorizes the recording of the HIV test results by the physician who ordered the test in the test subject's medical record and authorizes other disclosure of the results without written authorization of the test subject, or the subject's representative, to the test subject's providers of health care, excluding a regulated health care service plan, for purposes of diagnosis, care, or treatment of the patient. This bill would authorize a provider of health care to disclose the results of an HIV test that identifies or provides identifying characteristics of a Medi-Cal beneficiary without written authorization of the test subject, or the subject's representative, to the Medi-Cal managed care plan to which the beneficiary is assigned, if applicable, and to external quality review organizations conducting external quality reviews of Medi-Cal managed care plans, for the purpose of administering quality improvement programs, including, but not limited to, value-based payment programs and healthy behavior incentive programs, designed to improve HIV care for Medi-Cal beneficiaries. Under the bill, HIV test results that do not identify or provide identifying characteristics of the test subjects would be authorized for disclosure without written authorization by the Medi-Cal managed care plan to departmental staff for the above-described purpose. The bill would make certain clarifying or declaratory statements with regard to related provisions.
Existing law provides that everyone is responsible not only for the result of their willful acts, but also for an injury occasioned to another by their want of ordinary care or skill in the management of their property or person. Existing law requires the developer of a generative artificial intelligence system or service that is released on or after January 1, 2022, and made publicly available to Californians for use, to post on the developer's internet website documentation regarding the data used by the developer to train the generative artificial intelligence system or service. Existing law defines "artificial intelligence" for these purposes. This bill would prohibit a defendant who developed, modified, or used artificial intelligence, as defined, from asserting a defense that the artificial intelligence autonomously caused the harm to the plaintiff.
Existing law grants to a depicted individual a cause of action against a person who creates and intentionally discloses sexually explicit material if the person knows, or reasonably should have known, that the depicted individual in that material did not consent to its creation or disclosure or who intentionally discloses sexually explicit material that the person did not create if the person knows the depicted individual in that material did not consent to the creation of the sexually explicit material. Existing law defines "sexually explicit material" for purposes of that provision to mean any portion of an audiovisual work that shows the depicted individual performing in the nude or appearing to engage in, or being subjected to, sexual conduct and defines "depicted individual" to mean an individual who appears, as a result of digitization, to be giving a performance the individual did not actually perform or to be performing in an altered depiction. Existing law authorizes a plaintiff to recover, among other relief, statutory damages of not less than $1,500 but not more than $30,000, or $150,000 for a malicious violation, as prescribed. This bill would revise and recast the provision described above to additionally grant to a depicted individual a cause of action against a person who knows, or reasonably should know, that the depicted individual was a minor when the digitized sexually explicit material was created and would additionally grant a cause of action to that depicted individual against a person who knowingly facilitates or recklessly aids or abets conduct prohibited by that provision. The bill would define "digitized sexually explicit material" to mean any portion of a visual or audiovisual work created or substantially altered through digitization, including an image, that shows the depicted individual in the nude or appearing to engage in, or being subjected to, sexual conduct. This bill would make a person that provides a service that enables the ongoing operation of a deepfake pornography service presumed to be engaged in knowing facilitation or reckless aiding or abetting, as described above, if a depicted individual or public prosecutor provides the person with evidence sufficient to demonstrate that the person is providing services that enable the ongoing operation of a deepfake pornography service that engages in conduct described in the provisions described above, and the person fails to take all necessary steps to stop providing services that enable the ongoing operation of a deepfake pornography service within 30 days of receiving that evidence, as specified. This bill would increase the maximum statutory damages available to a depicted individual to $50,000 if the violation was not malicious and $250,000 for a malicious violation and would authorize certain public attorneys to bring a civil action to enforce these provisions, as specified.
Existing law makes any person who knowingly uses another's name, voice, signature, photograph, or likeness in products, merchandise, or goods, or for purposes of advertising or selling, or soliciting purchases of, products, merchandise, goods, or services, without that person's prior consent liable for damages, as specified. This bill would provide that a party seeking relief pursuant to those provisions may also seek an injunction or temporary restraining order according to specified procedures. The bill would require the respondent to comply with the order within 2 business days from the day the order is served, unless otherwise required by the order, if the court grants the applicant a temporary restraining order without notice to the opposing party that requires the respondent to remove, recall, or otherwise cease the publication or distribution of the petitioner's name, voice, signature, photograph, or likeness. The bill would make other nonsubstantive changes. This bill would incorporate additional changes to Section 3344 of the Civil Code proposed by SB 11 to be operative only if this bill and SB 11 are enacted and this bill is enacted last.
The California Consumer Privacy Act of 2018 (CCPA) grants a consumer various rights with respect to personal information that is collected or sold by a business, including the right to request that a business disclose specified information that has been collected about the consumer, to request that a business delete personal information about the consumer that the business has collected from the consumer, and to direct a business not to sell or share the consumer's personal information, as specified. The CCPA defines various terms for these purposes. The California Privacy Rights Act of 2020 (CPRA) , approved by the voters as Proposition 24 at the November 3, 2020, statewide general election, amended, added to, and reenacted the CCPA and establishes the California Privacy Protection Agency (agency) and vests the agency with full administrative power, authority, and jurisdiction to enforce the CCPA. Existing law requires a data broker to register with the agency, and defines "data broker" to mean a business that knowingly collects and sells to third parties the personal information of a consumer with whom the business does not have a direct relationship, subject to specified exceptions. Existing law requires a data broker, in registering with the agency, to pay a registration fee in an amount determined by the agency and provide specified information, including, among other things, the name of the data broker and its primary physical, email, and internet website addresses, and whether the data broker collects the personal information of minors, consumers' precise geolocation, or consumers' reproductive health care data. This bill would require a data broker to provide additional information to the agency, including whether the data broker collects consumers' names, dates of birth, ZIP Codes, email addresses, phone numbers, login or account information, various government identification numbers, mobile advertising, connected television, or vehicle identification numbers, citizenship data, union membership status, sexual orientation status, gender identity and gender expression data, biometric data, and up to 3, but no fewer than one, of the most common types of personal information that the data broker collects, as provided. The bill would also require a data broker to provide information regarding whether, in the past year, the data broker shared or sold consumers' data to a foreign actor, as defined, the federal government, other state governments, law enforcement, as provided, or a developer of a GenAI system, as defined. The bill would make changes to the administrative fines and costs that apply to data brokers who fail to register. Existing law requires, beginning January 1, 2026, the California Privacy Protection Agency to establish an accessible deletion mechanism that, among other things, allows a consumer, through a single verifiable consumer request, to request that every data broker that maintains any personal information delete any personal information related to that consumer held by the data broker or associated service provider or contractor. Existing law requires, beginning August 1, 2026, a data broker to access the accessible deletion mechanism at least once every 45 days and, among other things, process a denied request to delete personal information as an opt-out of the sale or sharing of the consumer's personal information under the CCPA, as specified. This bill would require a data broker to process the above-described denied request within 45 days of receiving the request. Existing law requires the agency to create a page on its internet website where registration information provided by data brokers and the accessible deletion mechanism is accessible to the public. This bill would prohibit the agency from making accessible to the public on its internet website information regarding whether the data broker collects consumers' names, dates of birth, zip codes, email addresses, phone numbers, mobile advertising, connected television, or vehicle identification numbers, and the most common types of personal information that it collects. This bill would declare that it furthers the purposes and intent of the CPRA for specified reasons.
Existing law generally governs the transactions between a rental car company, also referred to as a rental company, and its customers, as provided. Existing law prohibits a rental company from using, accessing, or obtaining any information relating to the renter's use of the rental vehicle that was obtained using electronic surveillance technology, as defined, except under specified circumstances. Existing law permits a rental company and a renter to limit the responsibilities of a renter in specified events, including loss due to theft of the rented vehicle up to its fair market value, as provided. Existing law establishes, in the situation described in the previous sentence, a presumption that the renter has no liability for loss due to theft if specified conditions are met, including that an authorized driver has possession of the ignition key or establishes that the ignition key was not in the vehicle at the time of the theft, as provided. This bill would allow a rental company to use geofence technology, as specified, to detect rental vehicle movement in prescribed circumstances. The bill, with respect to the above-described provisions relating to the renter's liability for loss due to theft, would revise the presumption that the renter has no liability for loss due to theft to instead apply this presumption if an authorized driver returns the ignition key.
Under existing law, the residence address, telephone number, and email address of a registered voter is confidential, except that under certain circumstances a county elections official must provide that information to any candidate for federal, state, or local office, to any committee for or against any initiative or referendum measure, and to any person for election, scholarly, journalistic, political, or governmental purposes. This bill would exempt the residence address, telephone number, and email address of a federal, state, or local elected official or candidate from that disclosure requirement, except that the information may be disclosed for journalistic or governmental purposes under specified conditions. The bill would require the Secretary of State to provide each county elections official with a list identifying each federal and state elected official or candidate residing in the county, require the county elections official to add each local elected official or candidate to that list, and require the county elections official to make the elected official or candidate's information confidential within 5 business days. The bill would require the county elections official to exclude the elected official or candidate's confidential information when producing any list, roster, or index. The bill would require an elected official or candidate to contact their county elections official to ensure their voter registration record has been made confidential. The bill would authorize an elected official or candidate to opt out of making their residence address, telephone number, and email address confidential. By adding new duties for county elections officials, this bill would create a state-mandated local program. This bill would incorporate additional changes to Section 2194 of the Elections Code proposed by AB 827 to be operative only if this bill and AB 827 are enacted and this bill is enacted last. Existing constitutional provisions require that a statute that limits the right of access to the meetings of public bodies or the writings of public officials and agencies be adopted with findings demonstrating the interest protected by the limitation and the need for protecting that interest. This bill would make legislative findings to that effect. The California Constitution requires the state to reimburse local agencies and school districts for certain costs mandated by the state. Statutory provisions establish procedures for making that reimbursement. This bill would provide that, if the Commission on State Mandates determines that the bill contains costs mandated by the state, reimbursement for those costs shall be made pursuant to the statutory provisions noted above.
Existing law requires the Office of Emergency Services to establish and lead the California Cybersecurity Integration Center. Existing law states that the center's mission is to reduce the likelihood and severity of cyber incidents that could damage California's economy, its critical infrastructure, or public and private sector computer networks in the state. Existing law requires the center to serve as the central organizing hub of state government's cybersecurity activities and coordinate information sharing with specified entities, including local, state, and federal agencies. This bill would require the California Cybersecurity Integration Center to develop, on or before January 1, 2027, in consultation with the Office of Information Security and the Government Operations Agency, a California AI Cybersecurity Collaboration Playbook, as specified, to facilitate information sharing across the cyber and artificial intelligence communities and to strengthen collective cyber defenses against emerging threats. The bill would require the center to review federal requirements, standards, and industry best practices, as specified, and to use those resources to inform the development of the California AI Cybersecurity Collaboration Playbook. Except as specified, the bill would provide that any information related to cyber threat indicators or defensive measures for a cybersecurity purpose shared in accordance with the California AI Cybersecurity Collaboration Playbook is confidential and would prohibit that information from being disclosed, except as specified. The bill would also make findings and declarations related to its provisions. Existing constitutional provisions require that a statute that limits the right of access to the meetings of public bodies or the writings of public officials and agencies be adopted with findings demonstrating the interest protected by the limitation and the need for protecting that interest. This bill would make legislative findings to that effect.
(1) Existing law generally regulates artificial intelligence, including by requiring, on or before January 1, 2026, and before each time thereafter, that a generative artificial intelligence system or service, or a substantial modification to a generative artificial intelligence system or service, released on or after January 1, 2022, is made publicly available to Californians for use, the developer of the system or service to post on the developer's internet website documentation regarding the data used by the developer to train the generative artificial intelligence system or service, as prescribed. This bill would enact the Transparency in Frontier Artificial Intelligence Act (TFAIA) that would, among other things related to ensuring the safety of a foundation model, as defined, developed by a frontier developer, require a large frontier developer to write, implement, and clearly and conspicuously publish on its internet website a frontier AI framework that applies to the large frontier developer's frontier models and describes how the large frontier developer approaches, among other things, incorporating national standards, international standards, and industry-consensus best practices into its frontier AI framework. The TFAIA would also require a large frontier developer to transmit to the Office of Emergency Services a summary of any assessment of catastrophic risk, as defined, resulting from internal use of its frontier models, as specified. The TFAIA would require the Office of Emergency Services to establish a mechanism to be used by a frontier developer or a member of the public to report, as prescribed, a critical safety incident, as defined, and would also require the Office of Emergency Services to establish a mechanism to be used by a large frontier developer to confidentially submit summaries of any assessments of the potential for catastrophic risk resulting from internal use of its frontier models, as prescribed. The TFAIA would exempt from the California Public Records Act a report of a critical safety incident submitted to the Office of Emergency Services, a report of assessments of catastrophic risk from internet use, and a covered employee report made pursuant to the whistleblower protections described below. The TFAIA would impose a civil penalty for noncompliance with the TFAIA to be enforced by the Attorney General, as prescribed. (2) Existing law establishes the Department of Technology within the Government Operations Agency. Existing law requires the department to conduct, in coordination with other interagency bodies as it deems appropriate, a comprehensive inventory of all high-risk automated decision systems that have been proposed for use, development, or procurement by, or are being used, developed, or procured by, any state agency. This bill would establish within the Government Operations Agency a consortium required to develop a framework for the creation of a public cloud computing cluster to be known as "CalCompute" that advances the development and deployment of artificial intelligence that is safe, ethical, equitable, and sustainable by, among other things, fostering research and innovation that benefits the public, as prescribed. The bill would require the Government Operations Agency to, on or before January 1, 2027, submit a report from the consortium to the Legislature with that framework and would dissolve the consortium upon submission of that report. The bill would make those provisions operative only upon an appropriation in a budget act, or other measure, for its purposes. (3) Existing law prohibits employers and their agents from making, adopting, or enforcing a rule, regulation, or policy preventing an employee from disclosing information to certain entities or from providing information to, or testifying before, any public body conducting an investigation, hearing, or inquiry if the employee has reasonable cause to believe that the information discloses a violation of a law, as specified, and prohibits retaliation against an employee for, among other things, exercising these rights. This bill would, among other things related to protecting whistleblowers working with foundation models, prohibit a frontier developer from making, adopting, enforcing, or entering into a rule, regulation, policy, or contract that prevents a covered employee, as defined, from disclosing, or retaliates against a covered employee for disclosing, information to the Attorney General, a federal authority, a person with authority over the covered employee, or another covered employee who has authority to investigate, discover, or correct the reported issue, if the covered employee has reasonable cause to believe that the information discloses that the frontier developer's activities pose a specific and substantial danger to the public health or safety resulting from a catastrophic risk or that the frontier developer has violated the TFAIA. This bill would require a large frontier developer to provide a certain internal process through which a covered employee may anonymously disclose information to the large frontier developer if the covered employee believes in good faith that the information indicates that the large frontier developer's activities present a specific and substantial danger to the public health or safety resulting from a catastrophic risk or that the large frontier developer violated the TFAIA. The bill would specify provisions particular to the enforcement of those whistleblower protections and would authorize attorney's fees to a plaintiff who brings a successful action for a violation. This bill would preempt any rule, regulation, code, ordinance, or other law adopted by a city, county, city and county, municipality, or local agency on or after January 1, 2025, specifically related to the regulation of frontier developers with respect to their management of catastrophic risk. Existing constitutional provisions require that a statute that limits the right of access to the meetings of public bodies or the writings of public officials and agencies be adopted with findings demonstrating the interest protected by the limitation and the need for protecting that interest. This bill would make legislative findings to that effect.