The closing days of September illustrated the growing tension at the heart of U.S. AI governance: While Governor Gavin Newsom contemplated the latest round of AI and privacy laws in California, top AI company executives met with President Trump in Washington DC to endorse a federal vision that favors self-regulation by the industry over government oversight. A month prior, California state legislators made headlines when they passed dozens of AI- and privacy-related bills on the last day of the state’s legislative session on August 31. The end of the legislative session then triggered the 30-day countdown for Governor Newsom to sign or veto the bills on his desk; if he did not take any action, any enrolled bills would become law without his signature.
These bills addressed a variety of AI and privacy issues and topics, including youth online safety, AI transparency and disclosures, AI in advertising, California Invasion of Privacy Act (CIPA) claims, data broker regulation, and AI auditing. For example, SB 947, the “No Robo Bosses Act of 2026,” proposed to amend the California Labor Code to prohibit employers from relying solely on “automated decision systems” (ADS) for making disciplinary or termination decisions, or conducting behavioral analyses, among other things. While the California Federation of Labor Unions AFL-CIO sponsored the bill, business advocacy group CalChamber led the opposition and argued the bill had “overly broad definitions or undefined standards that would create compliance problems for employers.” On the day of the September 30th deadline, Governor Newsom signed SB 947 into law.
Notably, the approval of many AI and privacy bills passed by the legislature was not pushed to the deadline. Key child online safety bills AB 226, AB 1709, and SB 1119 were all signed by Governor Newsom on September 10. AB 226 repeals California’s Age-Appropriate Design Code Act and replaces it with a similar but stricter requirements framework intended to protect children’s data online, while AB 1709 creates an e-Safety Advisory Commission and establishes prohibitions on addictive features on covered platforms for users under 16. SB 1119 establishes additional protections for minors interacting with companion chatbots, including requirements for independent child safety audits for chatbot operators.
With the September 30 signing deadline behind us, speculation has given way to certainty: businesses now have a clearer view of California’s AI and privacy regulatory landscape for the coming year. In this post, we highlight the key takeaways from the close of California’s legislative session and summarize some of the most notable bills to be passed and vetoed in the session. To stay up to date on the latest state privacy law developments, please subscribe to the WilmerHale Privacy and Cybersecurity Law Blog.
Key Takeaways
- Deletion requirements continue to tighten for data brokers and data handlers. AB 883 increases regulations for data brokers and builds out requirements related to California’s Delete Request and Opt-Out Platform (“DROP”). Previously, a data broker would have to access the delete mechanism at least once every 45 days; under AB 883, that frequency is increased to every 30 days. Certain state officials are now statutorily required to notify elected state officials and judges that they may have their personal information deleted via DROP. Beyond data brokers, SB 923 expands the California Consumer Privacy Act (CCPA) “right to delete” so that California consumers may request that a business delete personal information about the consumer that it has not only directly collected from the consumer, but also personal information collected about the consumer. Online-only businesses with direct relationships with consumers previously only had to offer an email address for consumers to submit privacy right requests. Now, they must also offer an online method, such as a web form or online portal.
- California becomes the third state to enact an Independent Verification audit law for AI. Some of the most frequently discussed bills to come out of this session, AB 1405 and SB 813, place California alongside Connecticut and Virginia in imposing a state-recognized AI auditing framework, including independent verification organizations. Organizations that rely on AI systems should monitor these developments closely, as third-party assessments, audits, and verification processes may become an increasingly important component of AI compliance programs.
- There is fluctuating litigation risk. Just as CIPA’s private right of action is weakened via SB 690’s elimination of the private right of action for alleged violations of CIPA’s pen register and trap and trace provisions, another law is entering the books that empowers and provides a private right of action for “[a] child who suffers an actual harm” or a “parent or guardian acting on behalf of that child” harmed by violations of SB 1119, which targets AI-powered companion chatbot services that interact with minors. This enforcement schema was not reflected elsewhere; all other bills grant enforcement authority to state agencies and/or the Attorney General.
- Continued focus on children’s online safety and AI transparency. Several bills from this legislative session further California’s broader technology regulation agenda by strengthening safeguards for minors and expanding transparency obligations applicable to AI systems and content providers. As described in the opening paragraphs, California lawmakers continue to refine the state’s regulatory framework governing minors’ interactions with digital services, including companion chatbots. Meanwhile, SB 1000 and AB 2713 expand the reach of the California AI Transparency Act and secures users’ access to AI system provenance information. A clear signal of urgency, SB 1000 goes into effect immediately.
- California’s executive office considers the feasibility and cost of enforcement for AI regulation. The veto memos that accompanied Governor Newsom’s three vetoes of AI- and privacy-related bills reveal how the executive office is weighing out the competing considerations for regulation such as consumer protection, regulatory feasibility, compliance costs, and enforceability. Even when Governor Newsom agreed with the intent of the bill, he vetoed the measures proposed in AB 1542, SB 903, and AB 2575 due to concerns regarding overbroad provisions and feasibility of implementation. For example, he rejected SB 903, in part, due to its imprecise definitions and potential handicapping of how psychotherapy professional could do their work. For AB 1542, which would replaced the CCPA’s heightened consent protections for the selling or sharing of sensitive personal information with a categorical prohibition, Governor Newsom questioned the unintended consequences of totally removing consumers from the process and stated that the costs to implement such a bill were not adequately addressed by California’s 2026 Budget Act.
Bellwether Bills: The Bills Signed into Law
While not comprehensive, the below list highlights and summarizes bills that establish key measures and regulations that companies and organizations should be aware of.
AI Audit and Verification Regulations
- AB 1405 creates California’s first registration framework for AI auditors. The bill requires the Government Operations Agency to establish an AI Auditor Registry and prohibits unregistered individuals or entities from offering or conducting covered AI audits in California. Beginning in 2029, AI auditors must satisfy registration, transparency, independence, recordkeeping, and operational requirements, including maintaining audit records for at least ten years. The measure reflects California’s growing focus on establishing accountability and professional standards for third-party AI assessment and assurance activities.
- SB 813 establishes a framework for independent verification organizations (“IVOs”) that evaluate AI systems and models for compliance with applicable laws and standards. Signed by Governor Newsom on September 9, 2026, the bill directs the Government Operations Agency to develop a regulatory framework governing the qualifications, independence, and operation of these entities. Together with AB 1405, SB 813 signals California’s interest in creating a formal ecosystem for independent AI governance, auditing, and verification.
Meaningful Amendments to Existing Laws for Privacy Rights and Data Brokers
- SB 923, also known as the Expanding Privacy Rights Act, amends the CCPA to expand existing deletion rights under the CCPA by requiring businesses to delete personal information collected “from or about” a consumer, rather than only information collected directly from that consumer (emphasis added). Signed by Governor Newsom on September 27, 2026, the bill also requires certain online-only businesses to provide consumers with a webform or similar mechanism to submit rights requests.
- SB 690 amends CIPA to limit private litigation under certain provisions. Responding to the wave of litigation from the plaintiff’s bar for CIPA violations, the bill removes private rights of action for claims arising under the statute’s pen register and trap-and-trace provisions in the context of websites and mobile applications, and instead authorizes the Attorney General to enforce alleged violations.
- AB 883 strengthens California’s data broker regime by shortening the deadline for responding to deletion requests from 45 days to 30 days. The bill also creates additional notice and deletion mechanisms for public officials, including elected officials and judges, through the state’s Delete Request and Opt-Out Platform (“DROP”).
Children’s Online Safety
- AB 1709 imposes new restrictions on online platforms that are likely to be accessed by minors. The bill prohibits covered platforms from providing certain “addictive features,” including algorithmically curated feeds and autoplay functions, to users under the age of sixteen. It also establishes an e-Safety Advisory Commission within the California Department of Justice to study and advise on online harms affecting children.
- AB 2246 repeals the California Age-Appropriate Design Code Act and replaces it with a revised framework focused on preventing specified harms to children online. Instead of the broad design and impact-assessment obligations established in the prior law, the bill requires businesses providing products or services likely to be accessed by children to take reasonable steps to mitigate identified risks.
Disclosures; Transparency; AI in Advertising
- SB 1050 requires clear disclosure when audio or video advertisements use AI-generated “synthetic performers” (as statutorily defined). The bill also prohibits the continued dissemination of advertisements that fail to include the required disclosures.
- AB 2025 specifically addresses advertising in real estate, requiring disclosures when AI is used to digitally alter promotional materials related to the sale of real property. The bill is intended to improve transparency and reduce the risk that consumers are misled by AI-generated or materially altered marketing content.
- SB 1111 expands California’s existing name, image, and likeness protections, including criminal charges for false impersonation, to expressly cover AI-generated “digital replicas.”
- SB 1000 increases the scope of the California AI Transparency Act by eliminating the statute’s current 1,000,000 monthly user threshold from the definition for “covered providers.” The bill also replaces the requirement to maintain an AI detection tool with a requirement to provide a disclosure verification tool. Now that the bill is law, it is effective immediately.
AI in Employment and Specific Sectors
- SB 947 restricts employers’ use of AI-driven employment decision tools. The bill prohibits employers from relying solely on an automated decision system to discipline or terminate a worker and requires human review before any adverse employment actions are taken.
- AB 1651 directs the State Bar of California to address and disclose its use of AI. Signed on August 22, 2026, the short legislation reflects growing concern regarding the ethical and professional obligations associated with AI-assisted legal services and requires disclosures for content “developed by or at the explicit direction of the State Bar” that used AI for the content.
- AB 1979 prohibits AI systems from independently performing clinical functions that California law reserves to licensed healthcare professionals. The bill seeks to ensure that AI serves as a supporting tool rather than a substitute for professional medical judgment.
Struck Down: The Bills Vetoed
The handful of bills that Governor Newsom vetoed also provide valuable insight into how Golden State leadership is weighing out the considerations of safety, practicality, cost, and enforceability related to AI and privacy regulation. These include:
- AB 1542 was the only bill to have been vetoed prior to September 30th. It would have significantly expanded protections for sensitive personal information under the CCPA by prohibiting businesses, service providers, and contractors from selling or sharing such information to third parties. The bill also would have eliminated the CCPA’s notice-at-collection requirement for sensitive personal information because the formerly protective measure would be obsolete. Governor Newsom vetoed AB 1542 on September 27, 2026, describing a categorical prohibition on the sale or sharing of sensitive personal information as “a step too far” and pointing out that implementation and enforcement of the bill would “result in significant costs not included in the 2026 Budget Act.”
- AB 2575 would have established protections for healthcare professionals who override or decline to follow AI-generated recommendations. The legislation seeks to preserve clinician autonomy and authorized the Labor Commission determine whether an employer had retaliated against a clinician who exercised their discretion over AI. Governor Newsom vetoed AB 2575 on September 30, 2026, stating that the “bill’s anti-retaliation provisions do not protect workers as intended” and put the Labor Commissioner in a position where they would have to adjudicate the standard of care for patients—a decision that would otherwise require medical expertise and skill.
- SB 903 aimed to establish more regulations around the use of AI in providing psychotherapy services, such as requiring the patient’s informed consent before AI is used to screen individuals or transcribe sessions. It also would have prohibited the use of AI to make therapeutic decisions or assess mental states without review and approval by a licensed professional. Governor Newsom vetoed SB 903 on September 30, 2026, writing that while he supported the intent, the bill is “overly broad and would drastically limit a clinician’s use of tools that benefit the delivery of care today.”
Looking Ahead
The AI policy and regulation debate may be nearing an inflection point. Just last week, a coalition of 26 state attorneys general sent an open letter urging Congress to adopt stronger AI safeguards while not preempting state law, highlighting the continuing role that states like California have in the AI regulatory landscape. As California’s latest AI and privacy measures begin to take effect next year, entities within the laws’ scope should begin evaluating how these requirements may affect their governance, risk management, transparency, and compliance programs. As with privacy legislation before it, California’s approach may serve as a model, catalyst, and/or benchmark for other states looking to impose more AI regulation and safety guardrails as Washington signals deference to the industry for self-regulation.