Existing law prohibits the Golden Gate Bridge, Highway and Transportation District from issuing general obligation or revenue bonds, or any other form of long-term indebtedness, except to finance an interim system of buses and ferries or to finance capital improvements or modifications relating to seismic safety of the Golden Gate Bridge. This bill would authorize the district to accept contributions and loans from this state and the United States for the purpose of financing capital improvements or modifications related to seismic safety on the Golden Gate Bridge, as specified.
Existing law governs various business practices in this state, including certain laws relating to the use of technology. Existing law, commonly known as the Cartwright Act, identifies certain acts that are unlawful restraints of trade and unlawful trusts and prescribes provisions for its enforcement through civil actions. This bill, the Preventing Algorithmic Price Fixing Act, would prohibit a person from selling, licensing, providing, or using a price-setting algorithm, as defined, with the intent or reasonable expectation that it be used by 2 or more competitors, as defined, in the same market if the person knows or should know that the algorithm processes nonpublic data, as defined, to set either: (1) a price or supply level of a good or service or (2) a rent or occupancy level of rental property. The bill would provide a user of a price-setting algorithm an affirmative defense to liability if the user exercised reasonable due diligence, as specified. The bill would authorize the Attorney General or a district attorney, city attorney, or county counsel to file a civil action for violations of these provisions, as specified, including for a civil penalty of up to $1,000 per violation, as specified. This bill would declare that a contract that violates these provisions is to that extent void and that its provisions do not limit the applicability of antitrust laws.
Existing law, the K–12 Pupil Online Personal Information Protection Act (KOPIPA) , generally protects the personal information of a student enrolled in a K–12 course of instruction, defined as a "pupil," by prescribing requirements and prohibitions applicable to an operator of an internet website, online service, online application, or mobile application with actual knowledge that the site, service, or application is used primarily for K–12 school purposes and was designed and marketed for K–12 school purposes. Existing law, the Early Learning Personal Information Protection Act (ELPIPA) , generally protects the personal information of a child enrolled in a preschool or prekindergarten course of instruction, defined as a "pupil," by prescribing requirements and prohibitions applicable to an operator of an internet website, online service, online application, or mobile application with actual knowledge that the site, service, or application is used primarily for preschool or prekindergarten purposes and was designed and marketed for preschool and prekindergarten purposes. This bill would instead apply the provisions of KOPIPA and ELPIPA to an operator, or an entity working on behalf of the operator, of an internet website, online service, online application, or mobile application with actual knowledge that the site, service, or application is used for the applicable school purposes and was designed or marketed for those purposes, as specified. The bill would, among other changes to KOPIPA and ELPIPA related to protecting the personal information of students, prohibit an operator from using covered information, as defined, including persistent unique identifiers, created or gathered by the operator's site, service, or application to train a generative artificial intelligence system or service or develop an artificial intelligence system. This bill would also enact the Higher Education Student Information Protection Act (HESIPA) , which would generally protect the personal information of a student enrolled in a higher education institution, as defined, in a similar manner as KOPIPA and ELPIPA. The bill would make HESIPA operative on July 1, 2027. This bill would authorize a pupil or student actually harmed by noncompliance with KOPIPA, ELPIPA, or HESIPA to bring a civil action against the noncompliant operator, as prescribed, and would require a person bringing that action to furnish a copy of the complaint to the Attorney General within 10 days after filing the action.
Existing law, the California Consumer Privacy Act of 2018 (CCPA) , grants a consumer various rights with respect to personal information that is collected or sold by a business. The CCPA defines various terms for these purposes. The California Privacy Rights Act of 2020 (CPRA) , approved by the voters as Proposition 24 at the November 3, 2020, statewide general election, amended, added to, and reenacted the CCPA and establishes the California Privacy Protection Agency (agency) and vests the agency with full administrative power, authority, and jurisdiction to enforce the CCPA. Existing law requires, on or before January 1, 2026, and before each time thereafter that a generative artificial intelligence system or service, as defined, or a substantial modification to a generative artificial intelligence system or service, released on or after January 1, 2022, is made available to Californians for use, regardless of whether the terms of that use include compensation, a developer of the system or service to post on the developer's internet website documentation, as specified, regarding the data used to train the generative artificial intelligence system or service. This bill would impose a duty on a covered deployer, defined as a business that deploys a high-risk artificial intelligence system that processes personal information, to protect personal information held by the covered deployer, subject to certain requirements. In this regard, the bill would require a covered deployer whose high-risk artificial intelligence systems process personal information to develop, implement, and maintain a comprehensive information security program, as specified, that contains administrative, technical, and physical safeguards that are appropriate for, among other things, the covered deployer's size, scope, and type of business. The bill would require the program described above to meet specified requirements, including, among other things, that the program incorporates safeguards that are consistent with the safeguards for the protection of personal information and information of a similar character under applicable state or federal laws and regulations. Existing law, the Unfair Competition Law, establishes a statutory cause of action for unfair competition, including any unlawful, unfair, or fraudulent business act or practice and unfair, deceptive, untrue, or misleading advertising, and establishes remedies and penalties in that regard, including injunctive relief and civil penalties. This bill would specify that a violation of the above-described provisions relating to the duty of a covered deployer to protect information, including the requirement that a covered deployer maintain the comprehensive information security program described above, constitute a deceptive trade act or practice under that law. Existing law, the Administrative Procedure Act, governs the procedure for the adoption, amendment, or repeal of regulations by state agencies and for the review of those regulatory actions by the Office of Administrative Law. This bill would authorize the agency to adopt regulations pursuant to the act to implement these provisions, and would exempt, notwithstanding that provision, any regulations adopted by the agency to establish fees from the act. The bill would define various terms for these purposes. The California Privacy Rights Act of 2020 authorizes the Legislature to amend the act to further the purposes and intent of the act by a majority vote of both houses of the Legislature, as specified. This bill would declare that its provisions further the purposes and intent of the California Privacy Rights Act of 2020.
Existing law requires, on or before September 1, 2024, the Department of Technology, within the Government Operations Agency, to conduct, in coordination with other interagency bodies as it deems appropriate, a comprehensive inventory of all high-risk automated decision systems that have been proposed for use, development, or procurement by, or are being used, developed, or procured by, any state agency. Existing law requires the department to annually submit a report of that comprehensive inventory to the Assembly Committee on Privacy and Consumer Protection and the Senate Committee on Governmental Organization. Existing law, the Transparency in Frontier Artificial Intelligence Act, among other things related to ensuring the safety of certain artificial intelligence models, requires a large frontier developer to write, implement, and clearly and conspicuously publish on its internet website a frontier AI framework that applies to the large frontier developer's frontier models and describes how the large frontier developer approaches, among other things, incorporating national standards, international standards, and industry-consensus best practices into its frontier AI framework. This bill would require, on or before January 1, 2028, the Government Operations Agency to take certain actions related to the selection and regulation of certain entities, defined as "independent verification organizations," designated by the agency as having demonstrated expertise in assessing the risks posed by an AI system or model and identifying the metrics and methodologies that form the basis for that assessment. The bill would require the agency to convene working groups to solicit stakeholder input in the identification of standards and the development and revision of procedures and criteria, as specified. The bill would require the agency to provide a report to the Legislature on the findings of the working groups and would require a designated IVO to submit annually, and no sooner than 12 months after initial designation as an IVO, to the agency and Legislature a report, as specified.
The California Constitution authorizes the Legislature to exempt from taxation, in whole or in part, property that is used exclusively for religious, hospital, or charitable purposes, and is owned or held in trust by a nonprofit entity. Pursuant to that authority, existing law provides for a welfare exemption under which property used exclusively for an exempt purpose and owned and operated by specified entities, including foundations, limited liability companies, or corporations meeting certain statutory requirements is exempt from taxation. This bill would specify that for the purposes of the welfare exemption provisions above, "property used exclusively for religious, hospital, scientific, or charitable purposes" shall not include property, or any portion thereof, operated as a detention facility, as defined. The bill would declare that the above provision is declarative of, and not a change in, existing law.
Existing law, the California Emergency Services Act, establishes the California Cybersecurity Integration Center within the Office of Emergency Services to serve as the central organizing hub of state government's cybersecurity activities and to coordinate information sharing with various entities. Existing law also requires the Technology Recovery Plan element of the State Administrative Manual to ensure the inclusion of cybersecurity strategy incident response standards for each state agency to secure its critical infrastructure controls and information, as prescribed. This bill would require, on or before July 1, 2026, an operator, defined as a state agency responsible for operating, managing, overseeing, or controlling access to critical infrastructure, that deploys a covered artificial intelligence (AI) system, as defined, to establish a human oversight mechanism that ensures a human monitors the system's operations in real time and reviews and approves any plan or action proposed by the covered AI system before execution, except as provided. The bill would require the Department of Technology to develop specialized training in AI safety protocols and risk management techniques to oversight personnel. The bill would require oversight personnel for an operator to conduct an annual assessment of its covered AI systems, as specified, and to submit a summary of the findings to the department. The bill would make findings and declarations related to its provisions. The bill would preclude disclosure of specified information by the office. Existing constitutional provisions require that a statute that limits the right of access to the meetings of public bodies or the writings of public officials and agencies be adopted with findings demonstrating the interest protected by the limitation and the need for protecting that interest. This bill would make legislative findings to that effect.
Existing law generally regulates artificial intelligence, including by requiring the Office of Emergency Services to, as appropriate, perform a risk analysis of potential threats posed by the use of generative artificial intelligence to California's critical infrastructure, including those that could lead to mass casualty events. This bill would require the Attorney General to establish and maintain a specified program to build internal expertise in artificial intelligence, including its applications, risks, regulatory implications, and civil rights impacts. The bill would require, on or before July 1, 2027, and annually thereafter, the Attorney General to submit a public report to the Legislature describing the program, key developments in artificial intelligence law and policy, and recommendations for additional state oversight or safeguards.
Existing law requires a health facility, clinic, physician's office, or office of a group practice that uses generative artificial intelligence to generate written or verbal patient communications pertaining to patient clinical information, as defined, to ensure that those communications include both (1) a disclaimer that indicates to the patient that a communication was generated by generative artificial intelligence, as specified, and (2) clear instructions describing how a patient may contact a human health care provider, employee, or other appropriate person. Existing law exempts from this requirement a communication read and reviewed by a human licensed or certified health care provider. This bill would require developers and deployers, as defined, of an artificial intelligence system that produces a prediction, classification, recommendation, evaluation, or analysis that aids decisionmaking related to diagnosis or treatment, known as a clinical decision support system, to make reasonable efforts to identify clinical decision support systems developed for use by deployers that are known or have a reasonably foreseeable risk for biased impacts resulting from deployment of the system in health programs or activities. The bill would require developers to make a statement describing the intended uses and known or reasonably foreseeable risks associated with the use of the clinical decision support system and certain documentation available to deployers, as specified. The bill would require developers to make reasonable efforts to mitigate known or reasonably foreseeable risk for biased impacts resulting from use of the clinical decision support system in health programs or activities. The bill would require deployers to regularly monitor clinical decision support systems and take reasonable and proportionate steps to mitigate known or reasonably foreseeable risk of biased impacts. The bill would specify that a person, partnership, state or local governmental agency, or corporation may be both a developer and a deployer.
Existing law makes it unlawful for any person to use a bot to communicate or interact with another person in this state online with the intent to mislead the other person about its artificial identity for the purposes of knowingly deceiving the person about the content of the communication in order to incentivize a purchase or sale of goods or services in a commercial transaction or to influence a vote in an election, unless the person using the bot discloses that it is a bot. Existing law defines a "bot" as an automated online account where all or substantially all of the actions or posts of that account are not the result of a person. This bill would require a person who uses a bot to autonomously communicate with another to ensure that the bot discloses to any person with whom the bot communicates when the bot first communicates with the person that the bot is a bot and not a human being, answers truthfully any query from a person regarding its identity as a bot or a human, and refrains from attempting to mislead a person regarding its identity as a bot. The bill would redefine "bot" to mean an automated online account or application that a reasonable person could believe is a human being and with respect to which substantially all of the actions or posts of that account or application are the outputs of generative artificial intelligence, as defined. The bill would exempt from its provisions a person who uses a bot that is required to comply with a more prescriptive disclosure scheme. This bill would authorize the Attorney General, a district attorney, a county counsel, a city attorney, or a city prosecutor to bring a civil action to punish noncompliance, as prescribed.