Truyo recognized in Gartner® Magic Quadrant™ for AI Governance Platforms | Download Report
California Bills for AI and Privacy
Artificial Intelligence, Privacy Enforcement, U.S. Laws & Regulations

24 Bills Later, California’s Message for AI Governance and Privacy Compliance

California’s 2026 legislative session closed with eight privacy bills and sixteen AI bills heading to Governor Newsom’s desk. The meaningful focus seems to be around regulating data and automated decision-making. While none of this is law yet, the direction is clear enough. The state is focusing on real consequences of technology that can affect critical decisions and sensitive information.

Businesses cannot abandon AI or data altogether just to avert their compliance and governance complications. The California bills are aimed at making their use intentional, explainable, and responsible. Therefore, let’s understand what the bills bring for privacy and AI governance and what the businesses can immediately prepare for even before the signatures.

California’s Privacy and AI Overhaul

For Privacy

  • Broader deletion requests: SB 923 expands the CCPA’s right to delete so it covers everything a business has collected about a consumer.
  • Mandatory online submission methods: SB 923 also requires businesses that operate exclusively online to provide a webform or portal for consumer requests, in addition to an email address. Consumers dealing with online only businesses no longer have to rely on email as their only option for exercising their rights.
  • Tighter limits on selling and sharing sensitive data: AB 1542 prohibits businesses from selling or sharing sensitive personal information with third parties unless the consumer themselves initiates or directs that disclosure. Passive or default-based sharing of sensitive data is effectively off the table, since the action now has to be consumer initiated.
  • Restrictions on pen register claims: SB 690 restricts private lawsuits under CIPA’s pen-register and trap-and-trace provisions. For violations arising from activity on websites, online applications, or mobile apps, private individuals would no longer be able to sue private businesses under these provisions. Instead, only the California Attorney General could bring such actions.
  • Traditional wiretapping claims remain: Private claims under section 631 for wiretapping and section 632 for recording are completely untouched by SB 690. So while the pen register workaround is closed, businesses still face exposure through these more established, harder to plead CIPA theories.

For AI Governance

  • Employment AI (SB 947): This bill goes after one of the more consequential uses of automated decision systems, which is firing and discipline. It doesn’t ban AI from playing a role in these decisions, but it draws a firm line against letting AI be the sole basis for them. The law requires a human to corroborate the outcome of an automated decision system to reach a disciplinary or termination decision. The employer has to send the affected employee a post use notice disclosing that an automated system was involved.
  • Healthcare AI (AB 1979, SB 503, AB 2575, SB 903): Rather than one sweeping healthcare AI law, California passed a cluster of bills that each address a different risk.
    • AB 1979 sets the boundary that if state law requires a licensed professional to perform a given clinical function, AI cannot be left to perform that function independently, which is a hard stop on full AI autonomy for anything legally reserved to a licensed human.
    • SB 503 and AB 2575 focus on a specific category of tool called “clinical decision support systems”. AI that generates predictions, recommendations, or analysis feeding into diagnosis, treatment, or care timing, and they require developers and deployers to proactively identify which of these systems carry known or reasonably foreseeable bias risk.
    • SB 903 specifically regulates AI used in or alongside psychotherapy services. The throughline across all four bills is the same: keep a human clinician in the decision loop, and force organizations to actively check their AI tools for biased outcomes rather than deploying them blind.
  • AI assurance and third-party auditing (SB 813 & AB 1405): These two bills are aimed at building the regulatory scaffolding for the people who audit AI.
    • SB 813 has the Government Operations Agency select and oversee “independent verification organizations.” Entities that have to demonstrate real expertise in assessing AI system and model risk, and whose job includes setting the actual metrics and methodologies used to judge that risk.
    • AB 1405 requires the same Agency to stand up a formal AI Auditor Registry, with its own set of requirements and obligations for who can be listed.

Before It Gets Real

The signal seems to be that consequential uses of sensitive data and AI tools need to be deliberate, accountable and defensible. Here’s how businesses can prepare for this direction that goes beyond passive compliance measures.

Prepare For Privacy

  • Map data flows: Businesses should maintain an accurate picture of what personal and sensitive information they collect, where it originates, which internal systems hold it, which vendors or third parties receive it, and what happens to it afterward. That mapping should extend trackers, APIs, SDKs, tag managers, and other technologies are actually doing.
  • Strengthen deletion: Deletion workflows should be capable of finding and removing all information associated with a consumer across relevant systems. Businesses should identify systems where deletion cannot be automated, establish responsibilities for manual remediation, account for applicable exceptions, and maintain records showing that requests were actually completed.
  • Simplify rights requests: Consumer-rights mechanisms should be treated as operational infrastructure rather than a privacy-policy requirement. Businesses should provide accessible submission methods, reliably route requests to the right teams and systems, track statutory deadlines, verify completion, and periodically test the process end-to-end so a request does not disappear between the webform and the backend.
  • Review sensitive sharing: Businesses should identify every instance where sensitive personal information is sold, shared, or otherwise disclosed to third parties and determine exactly what causes that disclosure. Flows triggered automatically through default settings, page loads, trackers, or preconfigured integrations deserve particular attention as California continues moving toward requiring more deliberate consumer involvement.
  • Audit website tracking: SB 690 may reduce one litigation route, but businesses should not interpret that as reduced website-tracking risk. Inventory pixels, session-replay tools, chat technologies, advertising trackers, and similar technologies. Companies should also determine what information they collect and transmit and verify that disclosures and consent mechanisms match actual behavior.
  • Preserve evidence: Businesses should retain evidence showing what consumers were told, what choices they were presented with, what consent or opt-out signals were received, what technologies were active at the time, and how requests were fulfilled. When litigation or regulatory scrutiny arrives months later, the ability to reconstruct what actually happened can be as important as having the right policy.

Prepare For AI Governance

  • Inventory AI use: Businesses need visibility beyond officially approved AI systems. Inventory internally developed models, third-party applications, embedded AI features, employee-adopted tools, and AI agents, and connect each system to its owner, purpose, users, affected individuals, data sources, vendor, and the decisions or business processes it influences.
  • Classify consequential uses: Not every AI system requires the same controls. Businesses should identify use cases that influence employment, healthcare, eligibility, access, or other consequential outcomes and subject them to greater scrutiny. The assessment should consider what the AI actually does in the decision process.
  • Assess bias proactively: Organizations should identify systems where biased outcomes are known or reasonably foreseeable and establish appropriate testing before and after deployment. That means understanding relevant training or input data, affected populations, potential discriminatory outcomes, vendor testing, known limitations, and whether performance changes once the system encounters real-world users and conditions.
  • Scrutinize vendors: Buying AI does not outsource governance responsibility. Businesses should understand what third-party systems do, what data they process, how models are tested, what limitations vendors disclose, how significant changes are communicated, and what evidence the vendor can provide during an assessment, audit, incident, or regulatory inquiry.
  • Document decisions: Maintain evidence of why an AI system was approved, what risks were identified, which controls were required, who accepted residual risks, what testing occurred, and what human oversight applies. As independent AI auditing develops, organizations should expect governance claims increasingly to be tested against evidence rather than accepted because a policy or assessment exists.
  • Monitor continuously: AI governance should not end with the initial assessment. Models change, vendors release updates, employees find new uses, data inputs evolve, and systems can gradually take on more consequential roles. Businesses should periodically reassess deployed AI, detect material changes, monitor emerging risks and incidents, and trigger review when a system moves beyond the conditions under which it was originally approved.
  • Prepare for assurance: California’s movement toward independent verification organizations and registered AI auditors is a signal to build governance that another party can actually examine. Organizations should standardize assessments, risk classifications, testing evidence, approvals, monitoring records, and remediation history now, rather than trying to assemble an audit trail after an auditor or regulator asks for it.

Truyo can help businesses with a broader approach for privacy compliance and AI governance that aligns with California’s direction. Truyo Privacy helps businesses operationalize consumer rights, understand data flows, manage consent and sensitive-data sharing, monitor website technologies, and maintain evidence that privacy controls are actually working.

Truyo AI Governance extends the same discipline to AI by helping organizations discover and inventory AI, assess use cases and vendors, document risks and controls, establish governance workflows, and maintain the testing and evidence increasingly expected from mature AI programs. Together, they allow organizations to put all of these moving pieces into repeatable workflows and manage them at scale.

Businesses Have Homework

Businesses cannot wait for Governor Newsom’s signature to start preparing. The common thread across both sets of bills, broader consumer control over sensitive data and mandatory human oversight of consequential AI decisions, points to a California that expects deliberate, documented, and defensible practices rather than policies that exist mainly on paper. Whether it’s a deletion request, a bias assessment, or an auditor’s inquiry, the businesses in the best position won’t be the ones scrambling to reconstruct what they did after the fact. They’ll be the ones who already have the answer on file.


Author

Dan Clarke
Dan Clarke
President, Truyo
September 2, 2026

Let Truyo Be Your Guide Towards Safer AI Adoption

Connect with us today