A practical map of California's layered AI regime — who each rule applies to, what it requires, and when it bites.

This article is educational guidance, not legal advice. AI law in the United States is changing quickly and varies by state and sector. Confirm current statutory text, effective dates, and rulemaking with primary sources and qualified counsel before making compliance decisions.

California did not pass one AI law; it passed a stack of them. Rather than a single omnibus statute, the state layers frontier-model safety rules, generative-AI transparency mandates, and privacy-driven automated-decision rules on top of one another. Each targets a different actor and carries its own effective date. This article maps the four instruments that matter most for product, engineering, and compliance teams operating in California through 2026 and into 2027.

Law Who it targets Key date
SB 53 (TFAIA) Developers of frontier (very large compute) models Effective Jan 1, 2026
AB 2013 Developers of public generative AI systems Effective Jan 1, 2026
SB 942 (as amended by AB 853) Large consumer GenAI providers (>1M users) Operative Aug 2, 2026
CPPA ADMT / CCPA regs Businesses using ADMT for significant decisions Rules in force Jan 1, 2026; ADMT duties from Apr 1, 2027

1. SB 53 — the Transparency in Frontier Artificial Intelligence Act (TFAIA)

Signed September 29, 2025 and effective January 1, 2026, SB 53 is the first US state law aimed squarely at frontier AI safety. It targets a small number of very large model developers and focuses on transparency about catastrophic risk rather than everyday product harms.

Who is covered

  • Frontier model: a foundation model trained using more than 10^26 integer or floating-point operations (including cumulative compute from fine-tuning and modifications).
  • Frontier developer: any person that has trained, or begun training, a frontier model.
  • Large frontier developer: a frontier developer whose group had annual gross revenues exceeding $500 million in the preceding calendar year. This subset carries the heaviest obligations.

What it requires

  • Transparency report: before or at deployment of a new or substantially modified frontier model, publish a report with details such as release date, supported modalities/languages, and intended uses.
  • Frontier AI framework (large developers): write, implement, and conspicuously publish a framework describing how the developer incorporates national/international standards and industry best practices to assess and mitigate catastrophic risk.
  • Critical safety incident reporting: report defined incidents to the California Office of Emergency Services.
  • Whistleblower protections for employees who raise catastrophic-risk concerns.
  • CalCompute: the law directs creation of a state public-cloud compute resource to broaden access.

Enforcement is by the California Attorney General, with civil penalties up to $1 million per violation. Most teams are not frontier developers — but if you fine-tune or heavily modify a frontier base model, check whether cumulative compute and your revenue pull you into scope.

2. AB 2013 — generative AI training-data transparency

Signed September 28, 2024 and effective January 1, 2026, AB 2013 applies to developers of generative AI systems or services made publicly available to Californians (free or paid) that were released on or after January 1, 2022. “Developer” includes anyone who designs, codes, produces, or substantially modifies such a system.

Covered developers must post on their website a high-level summary of the datasets used to train the system, including:

  • The sources or owners of the datasets and a description of how they were used;
  • Whether the datasets include data protected by copyright, trademark, or patent, or data in the public domain;
  • Whether the datasets include personal information or aggregate consumer information;
  • Whether the developer purchased or licensed data, and the time period during which data was collected.

Disclosure must be posted before the system is made available and updated on substantial modification. Certain systems are exempt (for example, those used solely for security/integrity, national airspace, or national security/defense). AB 2013 is generally understood to be enforceable through California's Unfair Competition Law, which raises private-litigation exposure. The statute is being challenged in court (by xAI) on trade-secret/Takings grounds, so watch for rulings that narrow it.

3. SB 942 — the California AI Transparency Act

SB 942 targets consumer-facing generative AI at scale. As amended by AB 853 (signed October 13, 2025), its operative date moved from January 1, 2026 to August 2, 2026, deliberately aligning with the EU AI Act's transparency milestone.

It applies to a “covered provider” — a person that creates a publicly accessible generative AI system with more than 1,000,000 monthly visitors or users in California. Core obligations, operative August 2, 2026:

  • Provide a free, publicly accessible AI-detection tool that lets users check whether content was created or altered by the provider's system;
  • Offer manifest disclosure (a clear, visible label) for AI-generated content on request;
  • Embed latent disclosure (provenance metadata) in AI-generated image, video, or audio content.

From January 1, 2027, the requirements expand to reach large generative-AI hosting platforms, not just developers.

4. CPPA ADMT and CCPA regulations

California's privacy regulator, the CPPA, finalized regulations under the CCPA covering automated decisionmaking technology (ADMT), risk assessments, and cybersecurity audits. The Office of Administrative Law approved them in September 2025. The regulations are in force from January 1, 2026, but the ADMT-specific consumer rights and duties phase in later.

“ADMT” is defined narrowly: technology that processes personal information and uses computation to replace or substantially replace human decisionmaking. It applies to “significant decisions” affecting finances, housing, education, employment, or health care.

Requirement Compliance start
ADMT pre-use notice + risk assessment for significant decisions; access/opt-out rights April 1, 2027
Risk assessments (staggered by revenue) Phased from 2027 onward
Businesses $50M–$100M 2027 revenue April 1, 2029
Businesses under $50M 2028 revenue April 1, 2030
The CPPA ADMT rules and Colorado's SB 26-189 both hang consumer rights (notice, opt-out or human review, access) on “significant/consequential decisions” in the same life domains. If you build one compliant workflow — notice, explanation, human review, data correction — you can largely reuse it across both states.

Putting it together: who needs to worry about what

  • Frontier model builders (very large compute, $500M+ revenue): SB 53 transparency report + frontier AI framework.
  • Anyone shipping a public GenAI system to Californians: AB 2013 training-data summary now; SB 942 detection tool and provenance labeling if you exceed 1M monthly users (by Aug 2, 2026).
  • Businesses using AI to make significant decisions (hiring, lending, housing, health): CPPA ADMT notice/opt-out and risk assessments phasing in from April 2027.
A federal executive order signed December 11, 2025 directs the DOJ to challenge some state AI laws and could affect enforcement. California's laws remain in effect and enforceable today; do not treat the federal effort as a reason to pause compliance. See our US federal AI landscape article for detail.