The California Legislature closed its 2026 session on August 31 having passed 26 AI-related bills, eight privacy bills, and additional measures targeting social media platforms, all of which now sit on Governor Gavin Newsom’s desk with a September 30 signing deadline. The legislative package spans workplace AI surveillance, chatbot safety for children, healthcare AI transparency, employer notification requirements, algorithmic pricing, name and likeness protections, AI auditor regulation, and amendments to the California Consumer Privacy Act. For businesses operating in California or serving California customers, the bills collectively represent the most concentrated single-session expansion of AI and data privacy regulation in any U.S. state to date.
Key Takeaways
- The California Legislature passed 16 AI bills, 8 privacy bills, and additional social media measures during its 2026 session, which closed August 31; Governor Newsom has until September 30 to sign or veto each bill
- AB 1709 bans social media companies from providing addictive features, including autoplay and personalized feeds, to users under 16 and creates a new e-Safety Advisory Commission
- Workplace AI legislation prohibits employers from using AI tools to collect neural data or identify workers’ emotional states; AB 1898 requires written notification to employees when AI is used in employment decisions or workplace surveillance
- AB 1542 amends the CCPA to prohibit selling or sharing sensitive personal information unless the consumer intentionally directs the disclosure; AB 2561 prohibits apps or operating systems from undoing a user’s privacy settings without consent
- Healthcare AI bills require transparency from businesses offering AI-powered health services; chatbot safety updates under SB 1119 add child protection components to existing California chatbot law
- Two of the 26 AI bills have already been signed into law; the remaining 24 await Newsom’s decision, which carries national regulatory significance ahead of a potential 2028 presidential campaign
The Workplace AI Bills Create New Compliance Requirements for Employers and HR Technology Vendors
The workplace-focused AI legislation that emerged from the 2026 session targets two areas that directly affect how companies manage employees: algorithmic decision-making in employment contexts and AI-powered workplace surveillance.
The neural data prohibition is the provision with the widest implications for enterprise technology. The bill prohibits employers from using workplace surveillance tools that employ AI to collect neural data or identify a worker’s emotional state. Neural data, as defined in the legislation, includes any information generated by measuring the activity of a person’s central or peripheral nervous system. The provision effectively draws a regulatory line around an emerging category of workplace monitoring technology that uses biometric sensors, eye-tracking cameras, and wearable devices to assess employee focus, stress, fatigue, or emotional engagement.
For HR technology vendors, the neural data prohibition means that product features designed to measure worker cognitive or emotional states through AI analysis cannot be marketed or deployed to California employers. Companies developing employee wellness platforms, productivity monitoring software, or AI-driven workforce analytics tools will need to audit their feature sets against the legislation’s definitions if Newsom signs the bill into law.
AB 1898 addresses a different dimension of workplace AI. The bill requires employers to provide written notice to employees when a workplace AI tool has been used to assist in making employment-related decisions or to conduct workplace surveillance. The notice must be delivered within a specified timeframe and must include specific information about the decisions potentially affected by the AI tool. For businesses using AI-assisted resume screening, performance evaluation tools, scheduling algorithms, or automated monitoring systems, AB 1898 creates a disclosure obligation that requires tracking which employment decisions involve AI input and communicating that information to affected workers.
The compliance burden falls most directly on mid-size and large employers that have already integrated AI tools into their HR and operations workflows. Smaller businesses that do not use AI in employment decisions are not affected, but those that have adopted commercially available HR software with embedded AI features, a category that includes many widely used applicant tracking systems and performance management platforms, will need to determine whether their tools trigger the notification requirement.
The Social Media and Child Safety Provisions Target Platform Design, Not Just Content
AB 1709 takes a design-level approach to youth protection on social media. Rather than regulating what content minors can see, the bill prohibits platforms from providing addictive features to users under 16. The specific features named in the legislation include personalized algorithmic feeds and autoplaying video, two mechanics that behavioral research has identified as primary drivers of compulsive platform usage among younger users.
The bill also creates an e-Safety Advisory Commission, a new regulatory body tasked with overseeing implementation and adapting the rules as platform design evolves. The commission structure gives California ongoing regulatory capacity rather than a static set of rules that platforms could engineer around through design changes that technically comply with the letter of the law while preserving the behavioral patterns the legislation targets.
SB 1119 updates California’s existing chatbot disclosure law with additional child safety components. The original chatbot law required disclosure when a user is interacting with a bot rather than a human. The 2026 update expands the requirements to address scenarios where minors interact with AI-powered conversational interfaces, adding protections that reflect the rapid proliferation of chatbot products in educational, entertainment, and customer service contexts since the original law’s passage.
For platform operators, the combined effect of AB 1709 and SB 1119 creates a two-layered compliance requirement: the design of the platform’s feed and engagement mechanics must be differentiated for users under 16, and any chatbot or conversational AI feature must meet updated disclosure and safety standards when minors are the users. Companies that serve both adult and minor audiences will need age-verification systems robust enough to trigger the appropriate experience for each user category, a technical requirement that has its own implementation costs and privacy considerations.
Privacy Amendments Tighten Control Over Sensitive Data and User Settings
The eight privacy bills that passed alongside the AI legislation include amendments to the California Consumer Privacy Act that narrow how businesses can handle sensitive personal information. AB 1542 prohibits selling or sharing sensitive personal information to a third party unless the consumer has used or intentionally directed the business to disclose that information. The distinction between passive data collection and active consumer direction is the operative change: under the amendment, the default position shifts from permitted-unless-opted-out to prohibited-unless-actively-directed.
For businesses that collect sensitive personal information, which under the CCPA includes Social Security numbers, financial account data, precise geolocation, racial or ethnic origin, religious beliefs, health information, and biometric data, the amendment requires reviewing data-sharing agreements with third parties and ensuring that each instance of sharing is tied to an affirmative consumer action rather than a blanket consent buried in terms of service.
AB 2561 addresses a different friction point in the privacy ecosystem. The bill prohibits operating systems and applications from undoing a user’s affirmative configuration of privacy settings without the user’s consent. The provision targets a practice known as “dark pattern resetting,” where software updates, app upgrades, or operating system changes revert a user’s previously configured privacy preferences to default settings, effectively undoing opt-out decisions the user had already made.
For SaaS companies, app developers, and operating system providers, AB 2561 creates an engineering requirement: updates and version changes must preserve user privacy configurations rather than resetting them. Companies that deploy frequent updates, which includes virtually every modern software product, will need to build privacy-setting persistence into their release processes and quality assurance testing.
Healthcare AI and Algorithmic Pricing Bills Extend Regulation Into Sector-Specific Applications
The AI bills that passed in the 2026 session are not limited to horizontal platform and employment regulation. Several measures target AI use in specific industries where the consequences of algorithmic errors or opacity carry particular weight.
Healthcare AI legislation requires businesses offering AI-powered health services to meet new transparency requirements. While the specific disclosure obligations vary by bill, the general thrust is that patients and healthcare consumers must be informed when AI is involved in clinical recommendations, diagnostic support, or treatment planning. For digital health startups, telehealth platforms, and health technology companies that have integrated AI into their service delivery, the legislation adds a compliance layer that intersects with existing HIPAA requirements and California’s broader health privacy framework.
Algorithmic pricing legislation addresses the use of AI tools that coordinate or influence pricing decisions across competitors. The provision reflects a growing concern among antitrust regulators and legislators that AI-powered pricing software, particularly in sectors like rental housing, hospitality, and e-commerce, can facilitate coordinated pricing behavior that traditional antitrust doctrine was not designed to address. For businesses that use dynamic pricing algorithms, the legislation may require auditing whether their pricing tools draw on competitor data in ways that could be construed as coordinated under the new framework.
Additional bills address name, image, and likeness rights in the context of AI-generated content, and establish a regulatory framework for AI auditors, creating standards for the professionals and firms that businesses will increasingly rely on to assess their AI systems’ compliance with California law.
Newsom’s Decisions Carry Weight Beyond California’s Borders
Governor Newsom has until September 30 to sign or veto each of the 24 bills awaiting his action. Two AI-related bills from the 2026 session have already been signed into law. Newsom’s track record on AI legislation has been mixed: in 2025, the governor vetoed SB 1047, a high-profile frontier AI safety bill that would have imposed safety testing and kill-switch requirements on developers of large-scale AI models, citing concerns about the bill’s potential to drive AI companies out of California.
The 2026 bills are generally more targeted than SB 1047, addressing specific applications of AI in employment, healthcare, social media, and consumer privacy rather than attempting to regulate the foundational models themselves. That narrower scope may make individual bills more politically viable, but the cumulative compliance burden of 26 AI-related measures signed into law in a single session would be substantial for companies operating across multiple affected areas.
California’s regulatory decisions on technology have historically influenced policy frameworks in other states and at the federal level. The CCPA served as the template for consumer privacy legislation adopted in more than a dozen states. If Newsom signs a significant portion of the 2026 AI package into law, the specific compliance requirements, particularly around workplace AI notification, neural data collection, and platform design for minors, are likely to become reference points for legislators in other states drafting their own AI governance frameworks.
For businesses, the practical implication is that waiting for the September 30 deadline before beginning compliance planning carries risk. Companies that operate in California or serve California customers across the affected categories, including HR technology, social media, healthcare AI, SaaS, and consumer data processing, should be mapping the legislation’s requirements against their current operations now, so that implementation timelines are realistic if Newsom signs the bills into law.
Frequently Asked Questions
How Many AI Bills Did the California Legislature Pass in 2026?
The legislature passed 26 AI-related bills during its 2026 session, which closed on August 31. Of those, two have already been signed into law. The remaining 24 are on Governor Newsom’s desk, and the governor has until September 30 to sign or veto each one. The legislature also passed eight privacy bills and additional social media measures during the same session.
What Does the Workplace AI Legislation Require?
One bill prohibits employers from using AI-powered surveillance tools to collect neural data or identify a worker’s emotional state. AB 1898 requires employers to provide written notice to employees when a workplace AI tool is used in employment-related decisions or workplace surveillance. The notice must be delivered within a specified timeframe and include details about which decisions were potentially affected by the AI tool.
What Does AB 1709 Do Regarding Social Media and Minors?
AB 1709 prohibits social media companies from providing addictive features, including personalized algorithmic feeds and autoplaying video, to users under 16 years old. The bill also creates an e-Safety Advisory Commission to oversee implementation. SB 1119 separately updates California’s existing chatbot law with additional child safety components.
How Do the Privacy Bills Affect Businesses?
AB 1542 amends the CCPA to prohibit selling or sharing sensitive personal information to third parties unless the consumer intentionally directs the disclosure. AB 2561 prohibits operating systems and applications from undoing a user’s privacy settings without consent. Businesses collecting sensitive data or deploying software updates that could reset user preferences will need to review their data-sharing agreements and engineering processes for compliance.
When Will Governor Newsom Decide on the Bills?
Governor Newsom has until September 30, 2026, to sign or veto each of the 24 AI and privacy bills currently on his desk. The governor’s decisions are expected to carry national significance given California’s history of setting regulatory precedents that other states adopt, and given Newsom’s positioning ahead of a potential 2028 presidential campaign.
Which Businesses Are Most Affected by the Legislation?
The bills have direct implications for HR technology vendors, social media platforms, SaaS companies, healthcare AI providers, app developers, operating system providers, AI auditing firms, and any business that uses dynamic pricing algorithms, collects sensitive personal data, or employs AI in hiring, performance evaluation, or workplace monitoring. Companies operating in or serving customers in California across any of these categories should assess the legislation’s requirements against their current operations.




