Existing law establishes the Department of Technology, which is supervised by the Director of Technology, within the Government Operations Agency. Existing law requires the department, in consultation with the public, the Public Utilities Commission (PUC) , and the California Broadband Council, by January 1, 2024, to develop a state digital equity plan that includes specified elements, including the identification of barriers to digital equity faced by covered populations in this state. This bill would create the Broadband and Digital Equity Commission with specified membership, and would, on July 1, 2027, repeal the California Broadband Council and establish the members of the council as a committee of the commission, as specified. The bill would provide that each member of the commission, excluding ex officio members, receive compensation of $100 per day, but not to exceed $400 for any commission business authorized by the commission during any month, and the necessary expenses incurred by the member in the performance of the member's duties. The bill would establish the Department of Broadband and Digital Equity in the Government Operations Agency for the purpose of promoting ubiquitous and universal broadband deployment in unserved and underserved areas of the state and to increase broadband adoption throughout the state for the benefit of all Californians. The bill would, on and after July 1, 2027, declare the department to be the only centralized state department for broadband and digital equity activities within the state authorized to establish rules or regulations for broadband internet access service and internet service providers, as provided. The bill would require the commission to appoint the executive director of the department, who shall serve at the pleasure of the commission, as specified, and would authorize the executive director to appoint, with the approval of the commission, necessary staff, as provided. Existing law requires the PUC to develop, implement, and administer the California Advanced Services Fund to encourage deployment of high-quality advanced communications to all Californians, as specified. Existing law establishes the Broadband Loan Loss Reserve Fund in the State Treasury, and continuously appropriates moneys in the fund to the PUC to be available to fund costs related to the financing of the deployment of broadband infrastructure by a local governmental agency or nonprofit organization, as provided. Existing law requires the PUC to maintain and update a statewide, publicly accessible, and interactive map showing the accessibility of broadband service in the state. Existing law requires the Office of Broadband and Digital Literacy to oversee the acquisition and management of contracts for the development and construction of a statewide open-access middle-mile broadband network to provide an opportunity for last-mile providers, anchor institutions, and tribal entities to connect to, and interconnect with other networks and other appropriate connections to, the statewide open-access middle-mile broadband network to facilitate high-speed broadband service. Existing law requires the office to retain a third-party administrator to manage the development, acquisition, construction, maintenance, and operation of a statewide open-access middle-mile broadband network, as specified. Existing law requires the office, with the third-party administrator, to develop and construct a statewide open-access middle-mile broadband network that prioritizes last-mile connections to unserved and underserved areas and locations. Existing law requires the office and third-party administrator to work directly with last-mile project grant awardees to ensure that network segments, including prioritized stand-alone Department of Transportation construction projects, support last-mile connections, and requires the office and the third-party administrator, to the extent feasible, to minimize disruption due to excavations, as provided. This bill would delete the provisions described in the above paragraph. The bill would, on and after July 1, 2027, require the department to assume all administrative functions of the California Advanced Services Fund and the Broadband Loan Loss Reserve Fund, and require the department to administer and maintain the interactive map showing the accessibility of broadband service in the state and the statewide open-access middle-mile broadband network, as specified. The bill would authorize the department to perform work, at the request of the commission, that the commission deems necessary to carry out its duties and responsibilities, but requires the commission to consider the expertise and resources available to the department, and specifies that the commission is not prohibited from using the services of other public or private entities. The bill would require the commission to advise and assist the department, the agency, and the Legislature in formulating and evaluating state policies and plans for broadband and digital equity programs in the state, and would authorize the commission to participate in relevant federal government rulemakings to advocate on behalf of the department and the state's interests. The bill would require the department to report to the Legislature by July 1, 2028, and at least annually thereafter, on the activities of the department and actions taken by the commission, and would require the report to include, among other things, the number of unserved and underserved households in the state, and progress toward increasing connectivity. The bill would require the department to establish a process to enable California residents, consumer advocates, and local governments to make complaints regarding any activity that may result in digital discrimination of access.
Existing law requires that a local agency that maintains an internet website for use by the public to ensure that the internet website uses a ".gov" top-level domain or a ".ca.gov" second-level domain no later than January 1, 2029. Existing law requires that a local agency that maintains public email addresses to ensure that each email address provided to its employees uses a ".gov" domain name or a ".ca.gov" domain name no later than January 1, 2029. Existing law defines "local agency" for these purposes as a city, county, or city and county. This bill would recast these provisions by instead requiring a city, county, or city and county to comply with the above-described domain requirements and by deleting the term "local agency" from the above-described provisions. The bill would also require a special district, joint powers authority, or other political subdivision to comply with similar domain requirements no later than January 1, 2031. The bill would allow a community college district or community college to use a ".edu" domain to satisfy these requirements, and would specify that these requirements do not apply to a K–12 public school district. By adding to the duties of local officials, the bill would impose a state-mandated local program. The California Constitution requires the state to reimburse local agencies and school districts for certain costs mandated by the state. Statutory provisions establish procedures for making that reimbursement. This bill would provide that, if the Commission on State Mandates determines that the bill contains costs mandated by the state, reimbursement for those costs shall be made pursuant to the statutory provisions noted above.
Existing law, the California Consumer Privacy Act of 2018 (CCPA) , grants a consumer various rights with respect to personal information that is collected or sold by a business. The CCPA defines various terms for these purposes. The California Privacy Rights Act of 2020 (CPRA) , approved by the voters as Proposition 24 at the November 3, 2020, statewide general election, amended, added to, and reenacted the CCPA and establishes the California Privacy Protection Agency (agency) and vests the agency with full administrative power, authority, and jurisdiction to enforce the CCPA. Existing law requires, on or before January 1, 2026, and before each time thereafter that a generative artificial intelligence system or service, as defined, or a substantial modification to a generative artificial intelligence system or service, released on or after January 1, 2022, is made available to Californians for use, regardless of whether the terms of that use include compensation, a developer of the system or service to post on the developer's internet website documentation, as specified, regarding the data used to train the generative artificial intelligence system or service. This bill would impose a duty on a covered deployer, defined as a business that deploys a high-risk artificial intelligence system that processes personal information, to protect personal information held by the covered deployer, subject to certain requirements. In this regard, the bill would require a covered deployer whose high-risk artificial intelligence systems process personal information to develop, implement, and maintain a comprehensive information security program, as specified, that contains administrative, technical, and physical safeguards that are appropriate for, among other things, the covered deployer's size, scope, and type of business. The bill would require the program described above to meet specified requirements, including, among other things, that the program incorporates safeguards that are consistent with the safeguards for the protection of personal information and information of a similar character under applicable state or federal laws and regulations. Existing law, the Unfair Competition Law, establishes a statutory cause of action for unfair competition, including any unlawful, unfair, or fraudulent business act or practice and unfair, deceptive, untrue, or misleading advertising, and establishes remedies and penalties in that regard, including injunctive relief and civil penalties. This bill would specify that a violation of the above-described provisions relating to the duty of a covered deployer to protect information, including the requirement that a covered deployer maintain the comprehensive information security program described above, constitute a deceptive trade act or practice under that law. Existing law, the Administrative Procedure Act, governs the procedure for the adoption, amendment, or repeal of regulations by state agencies and for the review of those regulatory actions by the Office of Administrative Law. This bill would authorize the agency to adopt regulations pursuant to the act to implement these provisions, and would exempt, notwithstanding that provision, any regulations adopted by the agency to establish fees from the act. The bill would define various terms for these purposes. The California Privacy Rights Act of 2020 authorizes the Legislature to amend the act to further the purposes and intent of the act by a majority vote of both houses of the Legislature, as specified. This bill would declare that its provisions further the purposes and intent of the California Privacy Rights Act of 2020.
The Confidentiality of Medical Information Act governs the disclosure of medical information by an employer, a provider of health care, a health care service plan, or a contractor, as those terms are defined. The California Consumer Privacy Act of 2018 (CCPA) authorizes a consumer to direct a business, as defined, that collects sensitive personal information about the consumer to limit its use of the consumer's sensitive personal information, as specified, and defines "sensitive personal information" to include personal information that reveals a consumer's neural data. The CCPA also authorizes a consumer to request that a business delete any personal information about the consumer which the business has collected from the consumer, as prescribed. The California Privacy Rights Act of 2020, approved by the voters as Proposition 24 at the November 3, 2020, statewide general election, amended, added to, and reenacted the CCPA and establishes the California Privacy Protection Agency and vests the agency with full administrative power, authority, and jurisdiction to enforce the CCPA. This bill would require, under the CCPA, a covered business to use neural data only for the purpose for which the neural data was collected and would require a covered business to delete neural data when the purpose for which the neural data was collected is accomplished. The bill would define "covered business" to mean a person who makes available a brain-computer interface to a person in this state and would define "brain-computer interface" to mean a system that allows direct communication and control between a person's brain and an external device. This bill would declare that its provisions further the purposes and intent of the California Privacy Rights Act of 2020.
Existing law requires, on or before September 1, 2024, the Department of Technology, within the Government Operations Agency, to conduct, in coordination with other interagency bodies as it deems appropriate, a comprehensive inventory of all high-risk automated decision systems that have been proposed for use, development, or procurement by, or are being used, developed, or procured by, any state agency. Existing law requires the department to annually submit a report of that comprehensive inventory to the Assembly Committee on Privacy and Consumer Protection and the Senate Committee on Governmental Organization. Existing law, the Transparency in Frontier Artificial Intelligence Act, among other things related to ensuring the safety of certain artificial intelligence models, requires a large frontier developer to write, implement, and clearly and conspicuously publish on its internet website a frontier AI framework that applies to the large frontier developer's frontier models and describes how the large frontier developer approaches, among other things, incorporating national standards, international standards, and industry-consensus best practices into its frontier AI framework. This bill would require, on or before January 1, 2028, the Government Operations Agency to take certain actions related to the selection and regulation of certain entities, defined as "independent verification organizations," designated by the agency as having demonstrated expertise in assessing the risks posed by an AI system or model and identifying the metrics and methodologies that form the basis for that assessment. The bill would require the agency to convene working groups to solicit stakeholder input in the identification of standards and the development and revision of procedures and criteria, as specified. The bill would require the agency to provide a report to the Legislature on the findings of the working groups and would require a designated IVO to submit annually, and no sooner than 12 months after initial designation as an IVO, to the agency and Legislature a report, as specified.
The California Constitution authorizes the Legislature to exempt from taxation, in whole or in part, property that is used exclusively for religious, hospital, or charitable purposes, and is owned or held in trust by a nonprofit entity. Pursuant to that authority, existing law provides for a welfare exemption under which property used exclusively for an exempt purpose and owned and operated by specified entities, including foundations, limited liability companies, or corporations meeting certain statutory requirements is exempt from taxation. This bill would specify that for the purposes of the welfare exemption provisions above, "property used exclusively for religious, hospital, scientific, or charitable purposes" shall not include property, or any portion thereof, operated as a detention facility, as defined. The bill would declare that the above provision is declarative of, and not a change in, existing law.
The California Consumer Privacy Act of 2018 (CCPA) grants to a consumer various rights with respect to personal information that is collected by a business, including the right to delete personal information. The California Privacy Rights Act of 2020, approved by the voters as Proposition 24 at the November 3, 2020, statewide general election, amended, added to, and reenacted the CCPA and establishes the California Privacy Protection Agency and vests the agency with full administrative power, authority, and jurisdiction to enforce the CCPA. The CCPA excludes from the definition of "personal information" publicly available information. Existing law defines "publicly available" for these purposes to include 3 types of information. One type is information that a business has a reasonable basis to believe is lawfully made available to the general public by the consumer or from widely distributed media. This bill would revise that part of the definition of "publicly available" by removing the condition that the business have a reasonable basis to believe the information is lawfully made available. The CCPA also includes in that definition of "publicly available" information made available by a person to whom the consumer has disclosed the information if the consumer has not restricted the information to a specific audience. This bill would delete that part of the definition of "publicly available." This bill would declare that its provisions further the purposes and intent of the California Privacy Rights Act of 2020.
This measure would urge President Donald J. Trump and Congress to protect and maintain the historic investments made possible by the Bipartisan Infrastructure Law, the CHIPS and Science Act, and the Inflation Reduction Act of 2022.
Existing law, the California Emergency Services Act, establishes the California Cybersecurity Integration Center within the Office of Emergency Services to serve as the central organizing hub of state government's cybersecurity activities and to coordinate information sharing with various entities. Existing law also requires the Technology Recovery Plan element of the State Administrative Manual to ensure the inclusion of cybersecurity strategy incident response standards for each state agency to secure its critical infrastructure controls and information, as prescribed. This bill would require, on or before July 1, 2026, an operator, defined as a state agency responsible for operating, managing, overseeing, or controlling access to critical infrastructure, that deploys a covered artificial intelligence (AI) system, as defined, to establish a human oversight mechanism that ensures a human monitors the system's operations in real time and reviews and approves any plan or action proposed by the covered AI system before execution, except as provided. The bill would require the Department of Technology to develop specialized training in AI safety protocols and risk management techniques to oversight personnel. The bill would require oversight personnel for an operator to conduct an annual assessment of its covered AI systems, as specified, and to submit a summary of the findings to the department. The bill would make findings and declarations related to its provisions. The bill would preclude disclosure of specified information by the office. Existing constitutional provisions require that a statute that limits the right of access to the meetings of public bodies or the writings of public officials and agencies be adopted with findings demonstrating the interest protected by the limitation and the need for protecting that interest. This bill would make legislative findings to that effect.
Existing law generally regulates artificial intelligence, including by requiring the Office of Emergency Services to, as appropriate, perform a risk analysis of potential threats posed by the use of generative artificial intelligence to California's critical infrastructure, including those that could lead to mass casualty events. This bill would require the Attorney General to establish and maintain a specified program to build internal expertise in artificial intelligence, including its applications, risks, regulatory implications, and civil rights impacts. The bill would require, on or before July 1, 2027, and annually thereafter, the Attorney General to submit a public report to the Legislature describing the program, key developments in artificial intelligence law and policy, and recommendations for additional state oversight or safeguards.