US AI regulation

California Passed 24 AI and Privacy Bills in One Night — the Risk Is the Pace, Not Any Single Bill

Newsom has until Sept. 30 to act on two dozen AI and privacy bills from California's session-closing rush, as a federal preemption fight looms over the broadest ones.

California's AI Legislative Sprint People of Internet Research · US 16 AI bills passed Passed in the legislature's final … 8 Privacy bills passed Covering CCPA amendments, data bro… 28 Bills awaiting Newsom Of 30 AI bills passed this session… 2029 Auditor registry launch AB 1405 would require AI auditors … peopleofinternet.com
California's AI Legislative Sprint People of Internet Research · US 16 AI bills passed 8 Privacy bills passed 28 Bills awaiting Newsom 2029 Auditor registry launch peopleofinternet.com

Key Takeaways

A Legislative Sprint to the Deadline

California's legislature closed its 2026 session at midnight on August 31, having passed eight privacy bills and sixteen AI bills in the final push before adjournment (Stauss Firm, Sept. 1, 2026). Those two dozen bills join a session total of 30 AI-related measures — two of which Governor Gavin Newsom has already signed — with the remaining 28 now on his desk (Transparency Coalition, Aug. 31, 2026). He has until September 30 to sign or veto each one; anything he signs takes effect January 1, 2027.

What's Actually in the Stack

The bills split into recognizable buckets. On privacy: AB 1542 bars selling or sharing sensitive personal information unless the consumer affirmatively initiates the disclosure; SB 923 expands CCPA deletion rights to cover everything a business holds on a consumer and requires an online submission method; AB 883 shortens data brokers' response window from 45 days to 30. On AI: SB 867 bans companion chatbots embedded in children's toys; SB 1119 adds child-safety components to California's existing chatbot law; SB 947 stops employers from firing or disciplining workers based solely on an automated decision system; AB 1883 restricts workplace AI surveillance, including neural-data and emotion-recognition tools; and AB 1405 creates a state AI Auditor Registry, requiring anyone who conducts a "covered AI audit" to register with the state starting January 1, 2029 (California Legislative Information, AB 1405).

The Case for Each, Taken Alone

Taken individually, most of these bills target real, narrow harms. A toy that embeds a companion chatbot marketed to a six-year-old is a different product than a general-purpose assistant, and treating it differently is defensible. An employer terminating someone on the say-so of an unreviewed algorithm, with no human corroboration, is the kind of accountability gap consumer-protection law exists to close. Data brokers taking 45 days to honor a deletion request is friction that mostly serves the broker, not the consumer. None of these asks are exotic; they extend norms California and other states have already applied to other sectors. Regulators pushing this agenda have a fair point that AI-specific harms — deepfake abuse, algorithmic employment decisions, chatbots designed to maximize engagement with minors — don't fit cleanly into pre-AI statutes, and waiting for Congress to act has meant waiting indefinitely.

The Real Problem Is Compounding Volume

What's harder to defend is 24 bills landing on one desk in one signing window, each with its own effective date, its own definition of "AI system," and in some cases its own new regulatory body. AB 1405's audit registry is a useful example of the compounding effect: it doesn't take effect until 2029, but it creates a licensing-style gatekeeper for the very third-party auditors that other 2026-passed bills — and last year's SB 53 frontier-model safety law — increasingly rely on for compliance. A narrower registration requirement might have been folded into SB 53's existing framework rather than spun up as a freestanding regime with its own enforcement track through the Attorney General.

Compare the pace to the EU's AI Act, often cited by industry as the heavy-handed benchmark: its high-risk obligations were phased in over roughly two years, and California's own AI Transparency Act amendment (AB 853, signed October 2025) deliberately pushed its operative date to August 2026 to align with that EU timeline. California is now doing the opposite of what its own transparency law modeled — dropping a fresh batch of AI obligations, each on its own clock, roughly every legislative session. For a national or multi-state business, that's not one compliance project; it's a recurring one, indefinitely.

Washington Is Pulling the Other Way

This lands against a federal backdrop that's newly hostile to state AI patchworks. On December 11, 2025, President Trump signed Executive Order 14365, "Ensuring a National Policy Framework for Artificial Intelligence," which declares it federal policy to pursue a "minimally burdensome national policy framework for AI" and directs the Department of Justice to stand up an AI Litigation Task Force to challenge state AI laws it judges inconsistent with that policy — citing the "patchwork of 50 different regulatory regimes" as the core harm (The White House, Dec. 11, 2025). Notably, the order explicitly exempts child-safety protections from its preemption push. That means California's chatbot and companion-AI bills aimed at minors — SB 867, SB 1119 — sit outside the administration's target zone and will likely stand regardless of how the litigation fight goes. The bills more exposed to a federal challenge are the structural ones: the auditor registry, the employment-AI restrictions, anything that regulates how AI systems must be built or audited rather than how they treat children.

What Newsom Should Do

Newsom doesn't have to treat this as an all-or-nothing stack. He should sign the narrowly scoped consumer and child-safety bills — the data-broker timeline, the deletion-rights expansion, the chatbot child-safety updates — where the harm is concrete and the compliance lift is modest. The more architecturally ambitious measures, like the new auditor registry, deserve a harder look: not because auditing AI systems is a bad idea, but because California keeps building new standalone regulatory scaffolding instead of extending what it already has. A state that wants to keep setting the national AI-policy baseline, rather than simply generating the test cases for the DOJ's new task force, should pair enforcement with restraint on its own sprawl.

Sources & Citations

  1. Stauss Firm — California 2026 Legislative Session Closes
  2. Transparency Coalition — CA legislature passes 30 AI bills
  3. California Legislative Information — AB 1405 bill text
  4. The White House — Executive Order 14365