Existing law requires a social media platform to take various steps to prevent cyberbullying of minors on the platform, including by requiring the platform to establish a prominent mechanism within its internet-based service that allows any individual, whether or not that individual has a profile on the internet-based service, to report cyberbullying or any content that violates the existing terms of service related to cyberbullying. Existing law authorizes the State Department of Public Health to establish the Office of Suicide Prevention in the department, as prescribed. This bill would, among other things related to making a companion chatbot platform safer for users, if a reasonable person interacting with a companion chatbot would be misled to believe that the person is interacting with a human, require an operator of a companion chatbot platform to issue a clear and conspicuous notification indicating that the companion chatbot is artificially generated and not human. The bill would also require an operator to take certain actions with respect to a user the operator knows is a minor, including disclose to the user that the user is interacting with artificial intelligence. The bill would also require an operator to prevent a companion chatbot on its companion chatbot platform from engaging with users unless the operator maintains a protocol for preventing the production of suicidal ideation, suicide, or self-harm content to the user, as specified, and would require an operator to publish details on that protocol on the operator's internet website. This bill would, beginning July 1, 2027, require an operator to annually report to the Office of Suicide Prevention certain things, including protocols put in place to detect, remove, and respond to instances of suicidal ideation by users, and would require the office to post data from that report on its internet website. The bill would authorize a person who suffers injury in fact as a result of noncompliance with the bill to bring a certain civil action.
Existing law generally regulates social media platforms, including, among other laws, the Protecting Our Kids from Social Media Addiction Act that prohibits an operator of an addictive internet-based service or application, including a social media platform, from providing an addictive feed, as defined, to a minor user, except as prescribed. This bill would enact the Social Media Warning Law that would require a covered platform, as defined, to display a certain black box warning to certain users each day the user initially accesses the social media platform, again after 3 hours of cumulative active use, and thereafter at least once per hour of cumulative active use, as prescribed. This bill would specify that its provisions shall not be interpreted to serve as the basis for a private right of action, as specified. The bill would make its provisions operative on January 1, 2027, and would declare these provisions severable.
The California AI Transparency Act requires a person that creates, codes, or otherwise produces a generative artificial intelligence system that has over 1,000,000 monthly visitors or users and is publicly accessible within the geographic boundaries of the state to make available an AI detection tool at no cost to the user that, among other things, allows a user to assess whether image, video, or audio content, or content that is a combination thereof, was created or altered by that person's generative artificial intelligence system and outputs any system provenance data that is detected in the content. Existing law makes the California AI Transparency Act operative on January 1, 2026. This bill would delay the operation of the California AI Transparency Act until August 2, 2026. This bill would, beginning January 1, 2027, additionally require a large online platform, as defined, to, among other things related to the provenance of content on the platform, detect whether any provenance data that is compliant with widely adopted specifications adopted by an established standards-setting body is embedded into or attached to content distributed on the large online platform. The bill would also require, beginning January 1, 2028, a capture device manufacturer, with respect to any capture device the capture device manufacturer first produced for sale in the state on or after January 1, 2028, to, among other things, provide a user with the option to include a latent disclosure in content captured by the capture device that conveys certain information, including the name of the capture device manufacturer. The bill would define "capture device" to mean a device that can record photographs, audio, or video content, including, but not limited to, video and still photography cameras, mobile phones with built-in cameras or microphones, and voice recorders. Existing law requires a covered provider to include a latent disclosure in AI-generated image, video, or audio content, or content that is any combination thereof, created by the covered provider's GenAI system that, among other things, conveys certain information and is permanent or extraordinarily difficult to remove, to the extent it is technically feasible. This bill would, beginning January 1, 2027, prohibit a GenAI system hosting platform, as defined, from knowingly making available a GenAI system that does not place disclosures, pursuant to those provisions. This bill would declare that its provisions are severable.
The California Consumer Privacy Act of 2018 (CCPA) grants a consumer various rights with respect to personal information that is collected or sold by a business, as defined, including the right to direct a business that sells or shares personal information about the consumer to third parties not to sell or share the consumer's personal information, as specified. The California Privacy Rights Act of 2020, approved by the voters as Proposition 24 at the November 3, 2020, statewide general election, amended, added to, and reenacted the CCPA and establishes the California Privacy Protection Agency and vests the agency with full administrative power, authority, and jurisdiction to enforce the CCPA. This bill would, beginning January 1, 2027, prohibit a business from developing or maintaining a browser, as defined, that does not include functionality configurable by a consumer that enables the browser to send an opt-out preference signal, as defined, to businesses with which the consumer interacts through the browser, as prescribed. The bill would require a business that develops or maintains a browser to make clear to a consumer in its public disclosures how the opt-out preference signal works and the intended effect of the opt-out preference signal. The bill would grant a business that develops or maintains a browser that includes this functionality immunity from liability for a violation of those provisions by a business that receives the opt-out preference signal. The bill would authorize the agency to adopt regulations as necessary to implement and administer those provisions. This bill would declare that its provisions further the purposes and intent of the California Privacy Rights Act of 2020.
Existing law provides that it is the intent of the Legislature that all public schools, teaching kindergarten or any of grades 1 to 12, inclusive, operated by a school district, in cooperation with specified entities and individuals, develop a comprehensive school safety plan, as provided. Existing law provides that school districts and county offices of education are responsible for the overall development of a comprehensive school safety plan for each of its schools, as provided. Existing law requires a comprehensive school safety plan to, among other things, identify appropriate strategies and programs that will provide or maintain a high level of school safety and address the school's procedures for complying with existing laws related to school safety. Existing law requires the governing board of a school district, a county board of education, and the governing body of a charter school to, by July 1, 2026, develop and adopt a policy to limit or prohibit the use by its pupils of smartphones while the pupils are at a schoolsite or while the pupils are under the supervision and control of an employee or employees of that school district, county office of education, or charter school. Existing law, however, specifies circumstances in which a pupil may not be prohibited from possessing or using a smartphone, including, among others, in the case of an emergency or in response to a perceived threat of danger. This bill would instead authorize the prohibition on the use of a smartphone by a pupil in the case of an emergency or in response to a perceived threat of danger if that circumstance is explicitly addressed in a comprehensive school safety plan.
Existing law establishes the Department of Health Care Access and Information to oversee and administer various health programs related to health care infrastructure, such as health policy and planning, health professions development, and facilities design review and construction, among others. Existing law requires the California Health and Human Services Agency to establish the California Health and Human Services Data Exchange Framework to require the exchange of health information among health care entities and government agencies in the state, among other things. Existing law requires the agency to convene a stakeholder advisory group to advise on the development, implementation, and administration of the California Health and Human Services Data Exchange Framework. This bill would require the Department of Health Care Access and Information, on or before January 1, 2026, to take over the establishment, implementation, and all of the functions related to the California Health and Human Services Data Exchange Framework, including the data sharing agreement and policies and procedures, from the agency. The bill would expand the entities that are specifically required to execute a data sharing agreement with the California Health and Human Services Data Exchange Framework. The bill would require the department, no later than July 1, 2026, to establish a process to designate qualified health information organizations as data sharing intermediaries that have demonstrated their ability to meet requirements of the California Health and Human Services Data Exchange Framework. The bill would require the department, by July 1, 2027, and in collaboration with the stakeholder advisory group, to develop and submit a report to the Legislature on the California Health and Human Services Data Exchange Framework, including compliance with data sharing agreements. The bill would expand the membership of the stakeholder advisory group, as specified.
(1) Existing law generally regulates artificial intelligence, including by requiring, on or before January 1, 2026, and before each time thereafter, that a generative artificial intelligence system or service, or a substantial modification to a generative artificial intelligence system or service, released on or after January 1, 2022, is made publicly available to Californians for use, the developer of the system or service to post on the developer's internet website documentation regarding the data used by the developer to train the generative artificial intelligence system or service, as prescribed. This bill would enact the Transparency in Frontier Artificial Intelligence Act (TFAIA) that would, among other things related to ensuring the safety of a foundation model, as defined, developed by a frontier developer, require a large frontier developer to write, implement, and clearly and conspicuously publish on its internet website a frontier AI framework that applies to the large frontier developer's frontier models and describes how the large frontier developer approaches, among other things, incorporating national standards, international standards, and industry-consensus best practices into its frontier AI framework. The TFAIA would also require a large frontier developer to transmit to the Office of Emergency Services a summary of any assessment of catastrophic risk, as defined, resulting from internal use of its frontier models, as specified. The TFAIA would require the Office of Emergency Services to establish a mechanism to be used by a frontier developer or a member of the public to report, as prescribed, a critical safety incident, as defined, and would also require the Office of Emergency Services to establish a mechanism to be used by a large frontier developer to confidentially submit summaries of any assessments of the potential for catastrophic risk resulting from internal use of its frontier models, as prescribed. The TFAIA would exempt from the California Public Records Act a report of a critical safety incident submitted to the Office of Emergency Services, a report of assessments of catastrophic risk from internet use, and a covered employee report made pursuant to the whistleblower protections described below. The TFAIA would impose a civil penalty for noncompliance with the TFAIA to be enforced by the Attorney General, as prescribed. (2) Existing law establishes the Department of Technology within the Government Operations Agency. Existing law requires the department to conduct, in coordination with other interagency bodies as it deems appropriate, a comprehensive inventory of all high-risk automated decision systems that have been proposed for use, development, or procurement by, or are being used, developed, or procured by, any state agency. This bill would establish within the Government Operations Agency a consortium required to develop a framework for the creation of a public cloud computing cluster to be known as "CalCompute" that advances the development and deployment of artificial intelligence that is safe, ethical, equitable, and sustainable by, among other things, fostering research and innovation that benefits the public, as prescribed. The bill would require the Government Operations Agency to, on or before January 1, 2027, submit a report from the consortium to the Legislature with that framework and would dissolve the consortium upon submission of that report. The bill would make those provisions operative only upon an appropriation in a budget act, or other measure, for its purposes. (3) Existing law prohibits employers and their agents from making, adopting, or enforcing a rule, regulation, or policy preventing an employee from disclosing information to certain entities or from providing information to, or testifying before, any public body conducting an investigation, hearing, or inquiry if the employee has reasonable cause to believe that the information discloses a violation of a law, as specified, and prohibits retaliation against an employee for, among other things, exercising these rights. This bill would, among other things related to protecting whistleblowers working with foundation models, prohibit a frontier developer from making, adopting, enforcing, or entering into a rule, regulation, policy, or contract that prevents a covered employee, as defined, from disclosing, or retaliates against a covered employee for disclosing, information to the Attorney General, a federal authority, a person with authority over the covered employee, or another covered employee who has authority to investigate, discover, or correct the reported issue, if the covered employee has reasonable cause to believe that the information discloses that the frontier developer's activities pose a specific and substantial danger to the public health or safety resulting from a catastrophic risk or that the frontier developer has violated the TFAIA. This bill would require a large frontier developer to provide a certain internal process through which a covered employee may anonymously disclose information to the large frontier developer if the covered employee believes in good faith that the information indicates that the large frontier developer's activities present a specific and substantial danger to the public health or safety resulting from a catastrophic risk or that the large frontier developer violated the TFAIA. The bill would specify provisions particular to the enforcement of those whistleblower protections and would authorize attorney's fees to a plaintiff who brings a successful action for a violation. This bill would preempt any rule, regulation, code, ordinance, or other law adopted by a city, county, city and county, municipality, or local agency on or after January 1, 2025, specifically related to the regulation of frontier developers with respect to their management of catastrophic risk. Existing constitutional provisions require that a statute that limits the right of access to the meetings of public bodies or the writings of public officials and agencies be adopted with findings demonstrating the interest protected by the limitation and the need for protecting that interest. This bill would make legislative findings to that effect.
Existing law prohibits a person or business, as defined, from collecting, using, disclosing, or retaining the personal information of a person who is physically located at, or within a precise geolocation of, a family planning center, as defined, except as necessary to perform the services or provide the goods requested and prohibits a person or business from selling or sharing this personal information. Existing law authorizes an aggrieved person or entity to institute and prosecute a civil action against a person or business for a violation of these provisions and specifies the damages and costs authorized to be recovered. This bill would recast the above-described provisions, and instead prohibit the collection, use, disclosure, sale, sharing, or retention of the personal information of a natural person who is physically located at, or within a precise geolocation of, a family planning center, except under certain circumstances, including, among others, for the collection or use as necessary to perform the services or provide the goods requested. The bill would also provide that these provisions do not alter applicable law regarding use by a law enforcement agency, as defined, of personal information generated by an electronic monitoring device. The bill would authorize an aggrieved person to institute and prosecute a civil action against a natural person, association, proprietorship, corporation, trust, foundation, partnership, or any other organization or group of people acting in concert for a violation of these provisions. The bill would also make other nonsubstantive changes. This bill would, subject to specified exceptions, prohibit geofencing, or selling or sharing personal information with a third party to geofence, as defined, an entity that provides in-person health care services in California for specified purposes, and would prohibit the use of personal information obtained in violation of this provision. The bill would provide that violators are subject to an injunction and liable for a civil penalty assessed and recovered in a civil action brought by the Attorney General, and deposited in the California Reproductive Justice and Freedom Fund. The bill would require those penalties to be awarded by the State Department of Public Health for grants to implement a program or to fund an existing program that provides and promotes medically accurate and comprehensive reproductive and sexual health education, as provided. The bill would also provide that a statement signed under penalty of perjury, as specified, that the personal information will not be used for selling or sharing personal information in violation of these geofencing provisions is prima facie evidence that the personal information was not sold or shared in violation of these geofencing provisions. By expanding the crime of perjury, this bill would impose a state-mandated local program. Existing law, the Confidentiality of Medical Information Act (CMIA) , generally prohibits a provider of health care, a health care service plan, or a contractor from disclosing medical information regarding a patient, enrollee, or subscriber without first obtaining an authorization, unless a specified exception applies. The CMIA prohibits a provider of health care, a health care service plan, a contractor, or an employer from releasing medical information that would identify an individual or related to an individual seeking or obtaining an abortion in response to a subpoena or a request or to law enforcement if that subpoena, request, or the purpose of law enforcement for the medical information is based on, or for the purpose of enforcement of, either another state's laws that interfere with a person's rights to choose or obtain an abortion or a foreign penal civil action. This bill would, similar to the provisions of the CMIA, prohibit the release of research records, in a personally identifying form, developed or acquired by a person in the course of conducting research relating to anyone seeking or obtaining health care services, or relating to personal information, in response to a subpoena or a request or to law enforcement if that subpoena, request, or the purpose of law enforcement for the medical information is based on, or for the purpose of enforcement of, either another state's laws that interfere with a person's rights to choose or obtain an abortion or a foreign penal civil action. The California Constitution requires the state to reimburse local agencies and school districts for certain costs mandated by the state. Statutory provisions establish procedures for making that reimbursement. This bill would provide that no reimbursement is required by this act for a specified reason.
(1) Existing law prohibits, except as required by state or federal law or as required to administer a state or federally supported educational program, school officials and employees of a school district, county office of education, or charter school from collecting information or documents regarding citizenship or immigration status of pupils or their family members. Existing law requires the superintendent of a school district, the superintendent of a county office of education, and the principal of a charter school, as applicable, to report to the respective governing board or body of the local educational agency in a timely manner any requests for information or access to a schoolsite by an officer or employee of a law enforcement agency for the purpose of enforcing the immigration laws in a manner that ensures the confidentiality and privacy of any potentially identifying information. This bill would prohibit school officials and employees of a local educational agency from allowing an officer or employee of an agency conducting immigration enforcement to enter a nonpublic area of a schoolsite, as defined, for any purpose without being presented with a valid judicial warrant, judicial subpoena, or a court order. The bill would require school officials and employees of a local educational agency, to the extent practicable, to request valid identification of any officer or employee of an agency conducting immigration enforcement seeking to enter a nonpublic area of a schoolsite. The bill would also prohibit a local educational agency and its personnel from disclosing or providing, in writing, verbally, or in any other manner, the education records of or any information about a pupil or a pupil's family and household without the pupil's parents' or guardians' written consent, a school employee, or a teacher to an officer or employee of an agency conducting immigration enforcement without a valid judicial warrant or judicial subpoena, or court order directing the local educational agency or its personnel to do so. By imposing additional duties on local educational agencies, the bill would impose a state-mandated local program. (2) Existing law requires the Attorney General, by April 1, 2018, in consultation with the appropriate stakeholders, to publish model policies limiting assistance with immigration enforcement at public schools, to the fullest extent possible consistent with federal and state law, and ensuring that public schools remain safe and accessible to all California residents, regardless of immigration status, as provided. Existing law requires local educational agencies, by July 1, 2018, to adopt those model policies developed by the Attorney General or equivalent policies. This bill would require the Attorney General, by December 1, 2025, to update those model policies to ensure that the policies align with the above-described prohibitions on school officials and employees of local educational agencies allowing an officer or employee of an agency conducting immigration enforcement to enter a nonpublic area of a schoolsite without a valid judicial warrant or judicial subpoena, or a court order and from disclosing or providing certain information to those officers or employees, as provided. The bill also would require a local educational agency to update its model policy by March 1, 2026, and to make the policy available to the State Department of Education upon request. By imposing additional duties on local educational agencies, the bill would impose a state-mandated local program. (3) This bill would make these provisions severable. (4) The California Constitution requires the state to reimburse local agencies and school districts for certain costs mandated by the state. Statutory provisions establish procedures for making that reimbursement. This bill would provide that, if the Commission on State Mandates determines that the bill contains costs mandated by the state, reimbursement for those costs shall be made pursuant to the statutory provisions noted above. (5) This bill would declare that it is to take effect immediately as an urgency statute.
Existing law establishes the Attorney General as the head of the Department of Justice, with charge of all legal matters in which the state is interested, except as specified. Existing law imposes various responsibilities on the Attorney General related to consumer protection, including, among others, the supervision of charitable trusts and the enforcement of antitrust laws. Existing law, commonly known as the Cartwright Act, identifies certain acts that are unlawful restraints of trade and unlawful trusts and prescribes provisions for its enforcement through civil actions. This bill would enact the California Preventing Algorithmic Collusion Act of 2025, to prohibit a person, as described, from distributing or making recommendations based on the use of a pricing algorithm to 2 or more competitors, as defined, under specified circumstances, if the person knows or should know that the pricing algorithm processes competitor data, as defined. This bill would also prohibit a person from using the recommendation of a pricing algorithm that processes competitor data, as specified, if the person knows or should know that the pricing algorithm uses or incorporates competitor data. The bill would establish an affirmative defense to liability under this prohibition for a person who demonstrates by a preponderance of evidence that they exercised reasonable due diligence before using the recommendations of a pricing algorithm, as specified. The bill would specify when the use, recommendation, or distribution of a pricing algorithm constitutes separate violations. The bill would declare that these provisions do not apply if all of the competitor data processed by the pricing algorithm was collected more than one year before the use, recommendation, or distribution of the pricing algorithm. The bill would declare that a contract that violates these provisions is to that extent void. This bill would authorize the Attorney General, a district attorney, a county counsel, or a city attorney to bring a civil action for violation of the above-described provisions to seek restitution, punitive damages, a civil penalty of up to $25,000 per violation, and other appropriate relief, as provided. The bill would declare that its provisions shall not impair or limit the applicability of antitrust laws, as defined. The bill would exempt from its provisions the development, distribution, output, or use of a credit score or other computational tool either subject to specified law or provided by a commercial credit reporting agency, as specified.