On September 30, 2026, California Governor Gavin Newsom signed a number of privacy and AI bills. The AI bills place guardrails on the development, deployment, and use of AI across employment, health care, legal services, higher education, government and technology. The common theme is that AI can assist, but accountability remains with the developer, deployer or user of the AI or automated decision system.

Below are key highlights of the signed AI bills and how they may affect compliance obligations. (A forthcoming alert will discuss the signed privacy bills.)

AI in the Workplace

Automated Decision Systems in Employment

Beginning July 1, 2027, under SB 947, employers may not use an automated decision system (ADS) to violate labor, safety, employment or civil rights laws, to infer an employee’s protected status, or to predict or take adverse action against employees for exercising their legal rights. Employers also may not rely solely on an ADS for disciplinary or termination decisions. Where an employer relies primarily on an ADS for such decisions, a human must meaningfully review and verify the output, and the employer must give the affected employee written notice describing the data the ADS used.

Workplace Surveillance Tools

AB 1883 and AB 1331 limit an employer’s use of workplace surveillance tools.

  • Under AB 1883, employers may not use an AI-enabled workplace surveillance tool to recognize or infer an individual’s emotional state, or to collect neural data (information generated by measuring activity of an employee’s central or peripheral nervous system, and not inferred from nonneural information). Employers using such tools as reasonably necessary to comply with legal obligations or binding contracts for national security, military, space or defense purposes are exempt.
  • AB 1331 prohibits employers from using workplace surveillance tools to monitor employees in workplace bathrooms. Workplace surveillance is defined broadly to include video or audio surveillance, continuous incremental time-tracking, geolocation, electromagnetic and photoelectronic tracking, photo-optical systems and other means.

AI for Lawyers

Under SB 574, the practice of law cannot be delegated to AI. Attorneys may not accept AI outputs at face value and must take reasonable steps to verify AI-assisted work product, including checking citations and correcting hallucinations, and may not enter confidential client information into public AI tools. Arbitrators likewise may not delegate decision making to AI, should independently verify AI outputs, and must disclose to the parties any reliance on AI-generated information outside the record.

Health Care and AI

Clinical Decision Making

AB 1979 limits how AI may be used in clinical decisions, and SB 503 targets developers and deployers of AI systems that support clinical decisions.

  • Under AB 1979, health facilities, clinics and physicians’ offices must ensure licensed providers exercise independent professional judgment whenever AI informs patient care. AI may not independently direct, guide or supervise clinical functions that the law requires a licensed professional to perform, but may still be used for administrative functions such as documentation, appointment reminders and responding to patient information requests.
  • Under SB 503, deployers of AI clinical decision support systems must regularly monitor those systems and take reasonable steps to mitigate known or reasonably foreseeable risks of biased impacts. Developers must describe the system’s intended uses and provide documentation, including a high-level summary of the training data types and how the system was evaluated for performance, limitations and mitigation of biased impacts.

Changes to the California AI Transparency Act

Compliance and Disclosure Requirements

SB 1000 and AB 2713 amend the California AI Transparency Act by revising compliance obligations and updating disclosure requirements for AI-generated content.

  • Previously, the act applied to covered providers of publicly accessible generative AI systems with over 1,000,000 monthly visitors or users. SB 1000 deletes that threshold, excludes certain systems (such as products or services intended to facilitate accessibility for individuals with disabilities), replaces the term “AI detection tool” with “disclosure verification tool,” and eliminates the requirement that covered providers give users the option to include a manifest disclosure in AI-generated content.
  • AB 2713 changes the AI-related obligations for large online platforms. In particular, it clarifies that large online platforms do not need to take any action or inspect system provenance data that is not compliant or interoperable with widely adopted industry standards.

AI-Generated Digital Replicas

Under SB 1111, publicity protections extend to computer-generated digital replicas readily identifiable as a person’s voice or visual likeness in which the person did not actually perform or appear, or they did perform or appear but their performance or appearance was materially altered. Organizations using AI-generated content depicting identifiable individuals should confirm consent and publicity-right requirements before commercial use.

AI in Education and Government

Higher Education Standards

AB 2392 requires California’s public higher education system to join an intersegmental working group tasked with developing standards for the adoption of generative AI systems and providing AI training programs for students, faculty and staff.

Government Engagement

Under SB 1159, individuals may use AI systems, such as assistive technologies, to engage with government, but AI systems, robots and agents may not independently participate in governmental processes reserved for natural persons or legal entities.

Next Steps

Organizations should evaluate how AI is developed, deployed and used across their operations and whether updates to policies, practices and compliance programs are needed. In particular, organizations should consider:

  • Reviewing AI-driven employment and workplace monitoring practices.
  • Evaluating whether AI use by professionals, especially in law and health care, keeps human judgment central.
  • Assessing whether existing AI governance identifies, mitigates and documents actual and potential risks.
  • Reviewing policies on AI-generated content and transparency obligations.

For help determining how these new California AI bills may impact your business, please contact Chiara Portner or Bushra Samimi, or your regular Lathrop GPM attorney.