California, the world’s fourth-largest economy, has taken a decisive leap forward in regulating artificial intelligence with a series of groundbreaking laws and regulations enacted in 2025. These new rules, including the landmark frontier AI transparency law and updates to automated decision-making governance, set a practical baseline for how companies should approach AI compliance, risk assessment, and transparency. For businesses, AI developers, and users operating in or serving California, understanding these changes is critical to managing AI-related risks and meeting regulatory expectations.

California-based tech companies have created hundreds of thousands of jobs and driven innovation in the AI sector, further cementing the state’s global leadership in technology and economic impact.

This article unpacks the key provisions of the new California AI law landscape, clarifies who is covered, outlines important deadlines, and offers actionable guidance for security, privacy, and legal teams preparing for compliance. Whether you are creating AI systems, deploying AI frontier models, or simply using AI tools within your company, this overview will help you navigate the evolving regulatory environment.

Introduction to Artificial Intelligence Regulations

Artificial intelligence regulations are rapidly becoming a cornerstone of responsible technology development in the United States and around the world. As AI systems become more powerful and deeply embedded in business operations, the risks associated with their use—ranging from privacy violations to unintended bias and misuse—have grown in both scale and complexity. The federal government has recognized the need for clear regulations to guide AI development, aiming to strike a balance between fostering innovation and protecting public trust.

California has emerged as a leader in this space, setting a precedent with comprehensive laws like the Transparency in Frontier AI Act (SB-53). These regulations are designed not only to address immediate risks but also to provide a framework for the safe and ethical deployment of AI technologies. By establishing clear standards for transparency, accountability, and risk management, California’s approach is influencing how other governments and organizations think about the future of AI regulation. For businesses, understanding and adapting to these evolving requirements is essential to harnessing the benefits of AI while minimizing potential harms.


The Headline Changes in California AI Law (Plain English)

In 2025, California passed several significant measures that impact AI development and usage:

  1. SB-53: Transparency in Frontier AI (TFAIA)This new senate bill targets large developers and large frontier developers of the most advanced AI models—referred to as frontier models and new frontier models—requiring them to publish safety protocols and submit reports on critical safety incidents. The bill would apply to any person or entity that trained or operated a frontier model using significant computational resources, with thresholds based on annual gross revenues exceeding $500 million in the preceding calendar year. The law is focused on addressing risk by proactively establishing regulatory frameworks to mitigate catastrophic risk, including risks that could materially contribute to substantial harm, such as the misuse of AI to create a nuclear weapon. Examples of catastrophic risk include imminent risk of death or serious physical injury, which must be reported within 24 hours. The law also covers risks from internal use of models, not just public deployment.

Enforcement is overseen by the attorney general, who may bring a civil action against violators to recover penalties. For compliance, companies may defer to federal laws or guidance documents if they are deemed substantially equivalent to California’s requirements. Reporting requirements mandate that large frontier developers submit annual safety and incident reports, with trade secrets, cybersecurity, or national security information eligible for redaction. Risk assessments may involve third party evaluators to ensure transparency and must keep pace with technological developments in AI. The law’s scope is limited to large developers, generally excluding smaller companies. The bill is designed to align with international standards, drawing comparisons to the European Union AI Act, and sets a blueprint for responsible innovation.

The process for developing a new frontier model includes reinforcement learning and subsequent fine tuning, both of which are subject to oversight under the law. The law clarifies that a person responsible for compliance must ensure all requirements are met, and that the potential harm from incidents is not limited to direct users. Implementation is led by the California Department overseeing AI policy.

  1. CPPA Final Regulations on Automated Decision-Making Technology (ADMT), Risk Assessments & Cybersecurity AuditsThe California Privacy Protection Agency (CPPA) finalized rules that require companies using automated decision-making systems—such as AI-driven screening, profiling, or routing—to conduct risk assessments when these processes carry high-risk implications. The regulations also impose annual cybersecurity audits on certain businesses and establish consumer rights around ADMT, including access and opt-out options. These regulations take effect January 1, 2026, giving companies several months to prepare.
  2. Delete Act (SB-362) ImplementationData brokers are now mandated to integrate with California’s Delete Request Originator Platform (DROP), facilitating the processing of data deletion requests on a regular cadence. This law requires brokers to retrieve deletion requests every 45 days and report the status within the same timeframe. This provision is crucial for companies using data brokers to ensure compliance with privacy expectations and transparency requirements.
  3. Bot Disclosure (SB-1001)If your business uses bots to sell products or influence votes within California, you must clearly disclose that these interactions are automated. While this has been a law for some time, it has gained renewed importance amid the rise of conversational AI in marketing and political campaigns.
  4. Chatbot Safeguards for Minors (SB-243)Operators of AI chatbots that interact with minors in California must implement safeguards to restrict crisis-related content and establish response protocols. This law is particularly relevant for consumer-facing AI chat experiences accessible to minors, ensuring their safety and well-being.
  5. State Use of Generative AI (Executive Order N-12-23)California continues to develop frameworks for responsible use of generative AI in government operations, including risk studies and procurement guidance. Although primarily applicable to state agencies, these best practices influence the broader AI industry and technology development standards.

Who Is Likely Covered by California’s AI Regulations?

Understanding whether your company falls within the scope of these new regulations is essential:

  • Frontier AI Developers (SB-53): Organizations training or operating very large frontier AI models must comply with transparency and safety reporting requirements. The law specifies compute and scale thresholds to identify covered entities. Most companies creating or using AI internally or at a smaller scale are not included.
  • Mid-to-Large Businesses Handling Californian Data (CPPA Regulations): Companies that meet the California Privacy Rights Act (CPRA) applicability thresholds and use automated decision-making technology must prepare for ADMT notices, risk assessments, and possibly annual cybersecurity audits by 2026.
  • Data Brokers and Their Clients: Entities acting as data brokers or using brokers must comply with the Delete Act’s DROP integration and request processing cadence.
  • Businesses Using Bots for Sales or Political Influence: If your company uses bots in California for sales or to influence voting, clear bot disclosure is mandatory.
  • Consumer Chatbot Providers: Providers of AI chatbots accessible to minors in California must implement safety safeguards as per SB-243.

Frontier AI Policy Framework

A robust frontier AI policy framework is essential for managing the unique challenges posed by the most advanced AI systems. Frontier AI models—those at the cutting edge of capability—can offer tremendous benefits but also carry the potential to pose catastrophic risks if not properly governed. To address these concerns, California’s regulations require large frontier developers to create and publish detailed frontier AI frameworks that outline their strategies for mitigating catastrophic risks.

Key elements of a frontier AI policy framework include transparency about how AI systems are developed and deployed, clear accountability for safety resulting from their use, and strong oversight mechanisms to ensure compliance with regulations. These frameworks must also provide for regular risk assessments, documentation of safety protocols, and procedures for reporting and responding to critical safety incidents. Importantly, the framework should include protections for whistleblowers who identify substantial danger to public health or safety, ensuring that concerns can be raised without fear of retaliation.

By mandating these provisions, California’s frontier AI policy aims to address the full spectrum of risks associated with advanced AI development—from the misuse of AI technologies to create harmful tools, such as nuclear weapons, to the broader societal impacts of unchecked AI deployment. This approach not only safeguards public health and safety but also sets a benchmark for responsible AI governance worldwide.


Important Deadlines and Compliance Timeline

  • Q4 2025 (Now): SB-53 is already law. Frontier AI developers should immediately assess whether they meet the law’s thresholds and begin implementing required transparency and safety protocols.
  • January 1, 2026: CPPA’s ADMT, risk assessment, and cybersecurity audit rules take effect. Companies using automated decision-making technology should have started preparations to meet consumer rights and risk assessment requirements.
  • Throughout 2026: Data brokers must begin adhering to the Delete Act’s cadence for retrieving and processing deletion requests via DROP, with status reporting every 45 days.

Practical Implications: Controls Your Company Should Implement

1) Automated Decision-Making Technology (ADMT) Governance

By 2026, businesses using ADMT must:

  • Maintain a detailed inventory of ADMT applications, including screening, scoring, routing, and profiling systems where decisions have legal or significant effects.
  • Publish clear notices informing users of automated decision-making and provide mechanisms for access and opt-out rights.
  • Conduct comprehensive risk assessments for high-risk AI processing, documenting data inputs, decision logic, potential impacts, and mitigation strategies.
  • Prepare for annual cybersecurity audits if classified within the covered group.

2) Data Broker Compliance (Delete Act)

  • Data brokers must connect to the DROP platform, process deletion requests timely, and report status accurately.
  • Companies using data brokers should update vendor contracts to enforce DROP compliance and establish clear deletion service-level agreements.

3) Bot and Chatbot Disclosures

  • Clearly disclose the use of bots in sales or political influence activities within California.
  • Implement safeguards in consumer chatbots accessible to minors, including crisis content restrictions and escalation protocols.

4) Evidence and Documentation

To prove compliance, companies will need to maintain:

  • Policy-to-control mappings for ADMT and privacy notices.
  • Risk assessment documentation detailing inputs, testing, guardrails, and outcomes.
  • Decision logs that are human-readable, showing allowed, blocked, or warned actions and the rationale.
  • Vendor attestations and updated contracts reflecting deletion and ADMT obligations.

Protections for Whistleblowers

Whistleblower protections are a critical component of effective AI governance, especially as organizations navigate the complexities of AI development and risk assessment. The Transparency in Frontier AI Act (SB-53) recognizes that employees are often the first to spot potential risks or unsafe practices related to frontier AI models. To encourage a culture of accountability, the law requires companies to establish secure, anonymous channels for reporting concerns about AI systems that may pose significant risks.

These protections extend to all covered employees involved in AI development and risk assessment, ensuring that individuals can report issues without fear of retaliation. Companies must demonstrate reasonable cause for any adverse action taken against an employee who raises a concern, reinforcing the importance of transparency and ethical conduct. By embedding whistleblower protections into the regulatory framework, California is empowering employees to play an active role in identifying and addressing risks, ultimately strengthening the safety and integrity of AI systems.


Preventing Catastrophic Risks

Preventing catastrophic risks is at the heart of California’s approach to frontier AI regulation. Advanced AI models have the potential to cause significant harm, from enabling the creation of dangerous technologies like nuclear weapons to triggering incidents that result in widespread bodily injury. To address these threats, companies developing frontier AI are required to publish comprehensive frontier AI frameworks that detail their strategies for identifying, testing, and mitigating catastrophic risks.

These frameworks must include rigorous testing protocols to assess the potential for catastrophic harm, as well as safeguards to prevent such outcomes. In the event of a critical safety incident, companies are obligated to report immediately to emergency services, such as the California Office of Emergency Services, ensuring a rapid and coordinated response. Additionally, information sharing is encouraged to support the development of new technologies and best practices that can further reduce the likelihood of catastrophic events.

By embedding these requirements into regulation, California is setting a high bar for AI safety, emphasizing proactive risk management and cross-sector collaboration. This approach not only protects public safety but also supports the responsible advancement of AI technologies in a way that benefits society as a whole.

Shared Checklist for Security, Privacy, and Legal Teams

This Quarter:

  • Build a comprehensive ADMT register detailing where automated decision-making is used, its purpose, data involved, and human oversight mechanisms.
  • Identify high-risk AI use cases and initiate risk assessments.
  • Map consumer rights related to ADMT access and opt-out to user experience flows.
  • Confirm whether your company or key vendors qualify as data brokers and align on DROP operations.
  • Add bot disclosures where applicable and review chatbot safety measures for minors.

Next Quarter:

  • Implement control telemetry at AI usage points (e.g., browser-based guardrails) to generate clear evidence for audits.
  • Finalize ADMT notices and develop internal playbooks for redress, exceptions, and human escalation.
  • Update vendor data processing agreements with ADMT and deletion clauses and test deletion request workflows end-to-end.

Do You Need to Re-Platform Your AI Systems?

For most companies, compliance with California’s AI laws is primarily a governance challenge rather than a technical one. The key steps involve:

  • Gaining visibility into where AI work occurs, including prompts and data uploads.
  • Translating policy requirements into enforceable guardrails that allow, warn, or block actions with human-readable logging.
  • Connecting these logs to risk assessments and consumer rights management processes.

Re-platforming or major engineering overhauls are unlikely necessary if these governance controls are effectively implemented.


A Light Product Note: Simplifying Compliance with Govnr

For organizations seeking a no-code solution to implement AI governance guardrails and evidence generation, Govnr offers a practical toolset:

  • Upload AI policies as PDF or DOC files without programming.
  • Review suggested enforcement rules powered by built-in Regex detectors.
  • Publish enforcement controls via a browser extension for real-time monitoring.
  • Export CSV logs with plain-English fields mapped to common compliance frameworks.

This streamlined approach supports companies in meeting California AI law requirements efficiently.


FAQs About California AI Law

Does SB-53 apply to us?
Only if you are a frontier AI developer meeting the law’s compute and scale thresholds. Most enterprise users and businesses are not directly covered. gov.ca.gov

When do the CPPA rules take effect?
They are final and effective January 1, 2026, with some phased obligations such as audits and risk assessments. Early preparation is recommended. California Privacy Protection Agency

What is the Delete Act’s main requirement?
Data brokers must retrieve and process deletion requests from the DROP platform every 45 days and report status accordingly. Companies using brokers must ensure vendor compliance. California Privacy Protection Agency

Do we need to disclose bots?
Yes, if your bot sells products or influences votes in California, clear and conspicuous disclosure is mandatory. Perkins Coie


California’s new AI regulations mark a significant step in addressing the risks associated with artificial intelligence, especially frontier AI models that pose catastrophic risks. By embracing transparency, risk assessment, and meaningful human oversight, California is setting a global example for responsible AI development and deployment. Companies operating in this evolving landscape should prioritize compliance to safeguard public trust, mitigate legal risks, and foster innovation within a framework of accountability.

No responses yet

Leave a Reply

Latest Comments

No comments to show.

Discover more from Govnr AI Governance

Subscribe now to keep reading and get access to the full archive.

Continue reading