California

California AI Regulations

No single California AI statute — instead, automated decision-making rules from the state's privacy regulator, generative AI disclosure laws, and AI-specific amendments to existing employment law, all moving on independent timelines.

Multiple tracks in force
Compliance counsel reviewing California automated decision-making rules
Photo: Sherwin Ker via Unsplash
Governome Editorial Team2 min readHow we source and review this content.

California doesn't have one AI statute you can point to the way Colorado has SB 205 — it regulates AI through several parallel regulatory tracks, each moving on its own timeline, which makes California one of the more operationally complex jurisdictions to track even though no single law here is as sweeping as the EU AI Act.

Automated decision-making technology (ADMT) rules

The California Privacy Protection Agency, the regulator created by the California Privacy Rights Act, has rulemaking authority over automated decision-making technology used to make significant decisions about consumers — employment, lending, housing, healthcare, and similar categories, closely mirroring the "consequential decision" concept used in other states' AI-specific statutes. These rules give consumers rights to notice and, in many cases, the ability to opt out of purely automated decision-making or request access to the logic involved.

Generative AI disclosure requirements

Separate statutes address generative AI specifically — requiring disclosure when content is AI-generated in certain contexts, and imposing training-data transparency obligations on developers of generative AI systems made available to Californians.

Employment-specific rules

California's existing employment discrimination framework has been extended to explicitly address automated decision systems used in hiring and employment, layering AI-specific expectations on top of the state's already-robust employment law rather than creating a standalone AI-employment statute.

The practical challenge

Because these obligations come from several sources rather than one bill, a compliance program built around "did we satisfy the California AI law" is asking the wrong question — the right question is "which of California's several AI-relevant regulatory tracks does this specific system touch," since a system can clear one track's requirements while still being fully exposed under another.

How this compares to Colorado

Colorado's single comprehensive statute is generally easier to build a compliance checklist against; California's fragmented approach requires tracking CPPA rulemaking, generative AI statutes, and employment law amendments as separate, independently evolving obligations. See our Colorado coverage for the contrast.