Existing law makes it a crime to knowingly or willfully cause another person to engage in the unlawful manufacture of firearms or knowingly or willfully aiding, abetting, prompting, or facilitating the unlawful manufacture of firearms, including the manufacture of assault weapons or .50 BMG rifles or the manufacture of any firearm using a 3-dimensional printer, as specified. Existing law authorizes a civil action against a person who knowingly distributes or causes to be distributed any digital firearm manufacturing code to any person, except as specified. Existing law authorizes the Attorney General, county counsel, or city attorney to bring an action against this person and seek a civil penalty, as specified, for each violation, as well as injunctive relief. This bill would require the Department of Justice to check on a quarterly basis beginning no later than July 1, 2027, whether ASTM International has published industry standards for equipping 3-dimensional printers with firearm blocking technology. The bill would require, if the department determines that ASTM International has published or adopted industry standards for firearm blocking technology for 3-dimensional printers, that the department publish written guidance or regulations within 24 months after making that determination. The bill would require, among other things, the written guidance or regulations to describe minimum performance standards for 3-dimensional printer firearm blocking technology before a printer can lawfully be sold or offered for sale in the state. If, as of July 1, 2029, the department determines that ASTM International has not published industry standards for firearm blocking technology for 3-dimensional printers, the bill would relieve the department of any further responsibility to ascertain whether ASTM International has published or adopted industry standards. The bill would make it unlawful to sell, offer for sale, or transfer for consideration, a 3-dimensional printer in the State of California that is not equipped with firearm blocking technology that also meets the above-described industry standards. The bill would exempt printers used exclusively for the manufacturing of properties (props) in the entertainment industry, and would authorize the department to adopt regulations that provide for additional exceptions to these provisions. This bill would also exempt a person who distributes, or causes the distribution of, digital firearm manufacturing code, solely for the bona fide purpose of, among other things, developing, refining, and testing the functionality of a firearm blocking technology from civil liability. This bill would make these provisions severable.
Existing law charges the Labor Commissioner with enforcement of various labor laws, including investigation of employee complaints. This bill would declare it is the policy of the state that a worker providing direct patient care be free to use their professional judgment to make assessments and decisions within their scope of practice as appropriate for their patients. The bill would prohibit an employer from retaliating or discriminating against a worker providing patient care, as specified. The bill would authorize a worker who is subject to retaliation or discrimination in violation of these provisions to file a complaint with the Labor Commissioner against an employer. The bill would require the Labor Commissioner to enforce these provisions, as specified. Existing law provides that everyone is responsible not only for the result of their willful acts, but also for an injury occasioned to another by their want of ordinary care or skill in the management of their property or person. Existing law prohibits a defendant who developed, modified, or used artificial intelligence, as defined, from asserting a defense that the artificial intelligence autonomously caused the harm to the plaintiff. This bill would prohibit a defendant who developed, modified, selected, or deployed a clinical decision support system that is alleged to have harmed the plaintiff from asserting a defense that the failure of a licensed health care professional or other health care worker to override an output of the clinical decision support system is a superseding cause severing the defendant's liability for the alleged harm.
Existing law establishes the Division of Labor Standards Enforcement within the Department of Industrial Relations. Existing law authorizes the division, which is headed by the Labor Commissioner, to enforce the Labor Code and all labor laws of the state, the enforcement of which is not specifically vested in any other officer, board, or commission. This bill would, with certain exceptions, prohibit an employer from using a workplace surveillance tool that uses artificial intelligence to, among other things, collect neural data or recognize an individual's emotional state. The bill would define an employer to include a governmental entity, including, among other entities, charter cities and the University of California. This bill would authorize the Labor Commissioner or a public prosecutor to enforce the bill's provisions. The bill would subject an employer who violates the bill's provisions to a civil penalty of up to $500 for each violation. The bill would define various terms for purposes of its provisions. This bill would exempt from its provisions an employer's use of a workplace surveillance tool in specified operations where the use of a workplace surveillance tool is reasonable necessary to comply with a federal statute, federal regulation, or binding federal contract relating to the development of aircraft for use in the national airspace or the development of products or services for national security, military, space, or defense purposes. The bill would include findings that changes proposed by this bill address a matter of statewide concern rather than a municipal affair and, therefore, apply to all cities, including charter cities.
The California Consumer Privacy Act of 2018 (CCPA) grants a consumer various rights with respect to personal information, as defined, that is collected or sold by a business, as defined, including the right to direct a business that collects sensitive personal information, as defined, about the consumer to limit its use, as prescribed. The California Privacy Rights Act of 2020, approved by the voters as Proposition 24 at the November 3, 2020, statewide general election, amended, added to, and reenacted the CCPA. This bill would, under the CCPA, prohibit a business, service provider, or contractor from selling or sharing sensitive personal information to a third party, except as specified. This bill would declare that its provisions further the purposes and intent of the California Privacy Rights Act of 2020.
Existing law establishes various healing arts boards within the Department of Consumer Affairs that license and regulate various healing arts licensees. Existing laws, including the Licensed Marriage and Family Therapist Act, the Educational Psychologist Practice Act, the Clinical Social Worker Practice Act, and the Licensed Professional Clinical Counselor Act, make a violation of those acts a crime. Existing law regulates the use of artificial intelligence, as defined. Existing law requires a health facility, clinic, physician's office, or office of a group practice that uses generative artificial intelligence to generate written or verbal patient communications pertaining to patient clinical information to ensure those communications include a disclaimer that indicates to the patient that a communication was generated by artificial intelligence and instructions describing how a patient may contact a human health care provider, employee, or other appropriate person. This bill would regulate the use of artificial intelligence in connection with providing or facilitating psychotherapy services, as defined. The bill, among other things, would authorize an individual, corporation, or entity that provides or facilitates psychotherapy services to use artificial intelligence tools or systems only to assist in providing administrative or supplementary support in psychotherapy services, as specified. The bill would prohibit an individual, corporation, or entity from using artificial intelligence to record or transcribe psychotherapeutic communications or sessions or to triage or screen a person for the need for psychotherapy services unless the patient or client or their authorized representative is informed that artificial intelligence will be used and the purpose of the artificial intelligence tool or system, and the patient or client or their authorized representative provides consent, as specified. The bill would prohibit an individual, corporation, or entity from advertising or otherwise purporting to offer psychotherapy services when the services are provided through the use of companion chatbots. The bill would prohibit an individual, corporation, or entity from allowing artificial intelligence to perform certain acts, including making therapeutic decisions or detecting emotions or mental states, as specified, without review and approval by a licensed professional. The bill would make a violation of the bill's provisions subject to the jurisdiction of the appropriate health care professional licensing board or enforcement agency, as specified, and would authorize those boards and enforcement entities to pursue any remedies authorized by law. Existing law, the Confidentiality of Medical Information Act, generally restricts the persons and entities to whom, and the purposes for which, a health care provider, health care service plan, or contractor may release a patient's medical information. The Confidentiality of Medical Information Act additionally imposes certain disclosure requirements for the release of medical information that specifically relates to the patient's participation in outpatient treatment with a psychotherapist. In this regard, the act prohibits a health care provider, health care service plan, or contractor from releasing that information to persons or entities who have requested that information and who are otherwise authorized by specified laws to receive that information, unless the requester makes certain written disclosures to the patient and to the provider of health care, health care service plan, or contractor, as specified. Those disclosures include, among other things, the specific intended uses of the information, and the length of time during which the information will be kept before being destroyed or disposed of, as specified. Existing law makes a violation of those provisions that result in economic loss or personal injury to a patient punishable as a misdemeanor. This bill would require the use of artificial intelligence in patient or client records for psychotherapy services to comply with the confidentiality requirements of the above-described provision of the Confidentiality of Medical Information Act and would prohibit a company or entity from sharing, selling, storing, or training their models on any data obtained from psychotherapy in a manner inconsistent with any applicable law. By expanding the scope of existing crimes, the bill would impose a state-mandated local program. The California Constitution requires the state to reimburse local agencies and school districts for certain costs mandated by the state. Statutory provisions establish procedures for making that reimbursement. This bill would provide that no reimbursement is required by this act for a specified reason.
Existing law prohibits a person, other than a provider of electronic or wire communication service for specified purposes, from installing or using a pen register or a trap and trace device, as those terms are defined, without first obtaining a court order. Existing law authorizes a person who has been injured by a violation of that prohibition to bring an action against the person who committed the violation to enjoin and restrain the violation, as well as to bring an action for monetary damages, as specified. This bill would instead authorize only the Attorney General to bring that action for a violation of the above-described provision if the action is alleged to arise from conduct occurring on an internet website, online application, or mobile application. The bill would provide that this limitation applies retroactively to any pending claim in an action commenced within 2 years before the operative date of the bill. The bill would declare the severability of its provisions.
Existing law, the California Consumer Privacy Act of 2018 (CCPA) , grants to a consumer various rights with respect to personal information that is collected by a business. Among those rights, the CCPA includes the right to request that a business delete personal information that the business has collected from the consumer. This bill would expand that right to include requesting the deletion of any personal information that the business has collected about the consumer. If the business did not obtain the personal information from the consumer, the bill would allow the business to retain a record of the deletion request and the minimum data necessary to ensure the consumer's personal information remains deleted from its records and is not being used for any other purpose. The bill would make findings and declarations relating to these provisions. Existing law generally requires businesses to make certain methods of communication available for consumers to submit personal information requests, including requests for deletion and correction. If a business operates exclusively online and has a direct relationship with the consumer from whom it collects personal information, existing law requires the business to provide consumers an email address for submitting personal information requests. This bill would also require that business to make an online method, such as a web form or online portal, available to consumers for submitting personal information requests. Existing law, the California Privacy Rights Act of 2020, an initiative measure approved by the voters as Proposition 24 at the November 3, 2020, statewide general election, amended, added to, and reenacted the CCPA. This bill would declare that its provisions further the purposes and intent of the California Privacy Rights Act of 2020.
Existing law requires the Public Utilities Commission to appoint a chief internal auditor who holds office at the pleasure of the commission. Existing law makes the chief internal auditor responsible for the oversight of the internal audit unit. Existing law requires the chief internal auditor to plan, initiate, and perform audits of key financial, management, operational, and information technology functions within the commission to improve accountability and transparency to executive and state management, and to report their findings and recommendations directly to an audit subcommittee of the commission. This bill would instead require the Governor to appoint an Inspector General, subject to Senate confirmation, to be responsible for the oversight of the internal audit unit and would instead require the Inspector General to plan, initiate, and perform audits of key financial, management, operational, and information technology functions within the commission to improve accountability and transparency to executive and state management. The bill would also require the Inspector General to ensure, among other things, that the commission administers funds and programs in a prescribed manner, fulfills mandated requirements, develops an annual audit plan, administers an effective enterprise risk management program, and monitors reporting compliance. The bill would provide for the appointment and removal of the Inspector General, as specified. The bill would authorize the Inspector General to access and examine all records, files, documents, accounts, reports, correspondence, or other property of the commission and public utilities, and would require other entities that are regulated by the commission and participate in programs administered by the commission, upon request of the Inspector General, to provide or make available to the Inspector General for examination all relevant records, files, documents, accounts, reports, correspondence, or other property pertaining to participation in those programs, as specified. The bill would require the Inspector General to report specified information to the Governor and the Legislature, as provided.
Existing law, the California Consumer Privacy Act of 2018 (CCPA) , grants a consumer various rights with respect to personal information that is collected or sold by a business, as defined, including the right to direct a business that sells or shares personal information about the consumer to third parties not to sell or share the consumer's personal information, as specified. Existing law, the California Privacy Rights Act of 2020, approved by the voters as Proposition 24 at the November 3, 2020, statewide general election, amended, added to, and reenacted the CCPA and establishes the California Privacy Protection Agency and vests the agency with full administrative power, authority, and jurisdiction to enforce those provisions. Existing law requires a retail grocery store or grocery department within a general retail merchandise store that uses a point-of-sale system to have a clearly readable price indicated on 85% of the total number of packaged consumer commodities offered for sale, subject to specified exemptions. This bill would, subject to certain exceptions, prohibit a retailer from engaging in surveillance pricing. The bill would define "surveillance pricing" to mean offering or setting a customized price for a good for a specific consumer or group of consumers, based, in whole or in part, on personally identifiable information, as specified, and determined in whole or in part through the use of any technology, software, program, machine-based system, or computational process that uses statistical modeling, data analytics, artificial intelligence, or other data processing techniques. The bill would also define "surveillance pricing" to mean random variations in prices to different consumers using a website, mobile application, or comparable online technology. The bill would provide that its provisions do not limit or impair any consumer right or remedy available under any other state or federal law. The bill would declare that any waiver of these provisions is against public policy and is void and unenforceable. This bill would declare that its provisions further the purposes and intent of the California Privacy Rights Act of 2020.
(1) Existing law, the Digital Financial Assets Law, prohibits a person, on or after July 1, 2026, from engaging in digital financial asset business activity, or holding itself out as being able to engage in digital financial asset business activity, with, or on behalf of, a resident, unless any of certain criteria are met, including that the person is licensed with the Department of Financial Protection and Innovation, as prescribed, or the person submits an application on or before July 1, 2026, and is awaiting approval or denial of that application. This bill would revise the above-described latter criterion to specify that the person submits a completed application, as provided. The Digital Financial Assets Law authorizes the Commissioner of Financial Protection and Innovation to issue a conditional license to an applicant who holds or maintains a license to conduct virtual currency business activity in the State of New York, as specified, provided the license was issued or approved no later than January 1, 2023. This bill would revise the above-described authorization to require that the license be issued or approved no later than January 1, 2025. (2) The Digital Financial Assets Law defines "digital financial asset business activity" to mean any of specified activities, including, among others, exchanging, transferring, or storing a digital financial asset, as specified, or exchanging one or more digital representations of value used within one or more online games, game platforms, or family of games, as provided. This bill would remove exchanging one or more digital representations of value used within one or more online games, game platforms, or family of games from the definition of "digital financial business activity." The bill would specify that a "digital financial asset" does not include, among other things, a transaction in which a merchant grants digital representations of value that primarily relate to an affinity or rewards program, as provided, or a digital representation of value issued by or on behalf of a publisher and used primarily within online games or game platforms and that is not otherwise a digital financial asset. The Digital Financial Assets Law declares that its provisions do not apply to specified activity, including by a person who does not receive compensation for providing digital financial asset products or services or for conducting financial asset business activity or that is engaged in testing products or services with the person's own funds. This bill would specify that the above-described exclusion includes a person who merely retains the ability to terminate, suspend, or interrupt a digital financial transaction solely to prevent unauthorized or fraudulent activity and who is not compensated for that service. The Digital Financial Assets Law prohibits a covered person from exchanging, transferring, or storing a digital financial asset that is a stablecoin or engaging in digital financial asset administration of a stablecoin, as specified, unless certain conditions are met. However, existing law authorizes a covered person to exchange, transfer, or store a stablecoin or engage in digital financial asset administration of that stablecoin, as specified, if the stablecoin is approved by the commissioner and complies with certain requirements, restrictions, or prohibitions established by the commissioner. This bill would repeal the above-described provisions related to stablecoins. (3) The Digital Financial Assets Law requires a licensee to submit an annual report, as provided, containing specified information, including a description of any data security breach or cybersecurity event of the licensee. Existing law requires a licensee to file with the department, as applicable, a report of, among other things, a change in the licensee's business for the conduct of its digital financial asset business activity with, or on behalf of, a resident that meets one of specified criteria, including that the proposed change might raise safety and soundness or operational concerns. This bill would revise the above-described annual report to instead include a description of any material data security breach or cybersecurity event of the licensee. The bill would revise the specified criteria in the requirement to file the above-described report of a change in the licensee's business to instead include that the proposed change might raise material safety and soundness or operational concerns. Before engaging in digital financial asset business activity with a resident, the Digital Financial Assets Law requires a covered person, defined as a person required to obtain a license pursuant to that law, to disclose, as provided, certain information, including the resident's right to at least 14 days' prior notice of specified changes that have a material impact on digital financial asset business activity with the resident, or the policies applicable to the resident's account. Existing law requires a covered exchange, as provided, to certify on a form provided by the department that the covered exchange has taken specified actions, except for any digital financial asset approved for listing on or before January 1, 2023. In a transaction for or with a resident, existing law prohibits the covered exchange from interjecting a third party between the covered exchange and the best market for the digital financial asset in a manner inconsistent with specified requirements. This bill would prohibit the 14-day notice requirement from applying to changes in terms, conditions, or policies that are reasonably necessary to address a risk of loss to the resident or covered person, to the extent that the change does not relate to the fee schedule. The bill would instead exclude from the above-described certification requirement a digital financial asset approved for listing on or before January 1, 2025. The bill would require a covered person to provide and make available an up-to-date description of the order execution practices of the covered person, as specified. The bill would exempt a transaction in which a resident receives stablecoin, as defined, in exchange for legal tender or bank or credit union credit from the above-described prohibition against interjecting a third party. The Digital Financial Assets Law requires an applicant, as provided, to create, and during licensure, maintain in a record specified policies and procedures. Existing law requires these policies and procedures be disclosed separately from other disclosures made available to a resident, as specified, except for, among other things, an adopted information security program or an operational security program. This bill would instead exclude from the above-described requirement to disclose separately from other disclosures programs with information that is sensitive to potential security risks, as specified. This bill would declare that it is to take effect immediately as an urgency statute.