California’s late-session privacy and AI agenda is moving quickly. In the past 30 days, Governor Gavin Newsom has signed several technology bills addressing AI accountability, child online safety, and targeted privacy protections, while other significant measures remain on his desk. Because the Legislature adjourned at the end of August, the Governor has until September 30, 2026 to sign or veto final-session bills; if he does neither, they become law without his signature. Please expect another update as we approach or pass the September 30 deadline.
The most prominent recent AI enactments are SB 813 and AB 1405, signed September 9. The Governor’s office described them as first-in-the-nation safeguards for third-party audits and independent AI assessments. SB 813 creates a framework for independent verification organizations, while AB 1405 creates a state registry for AI auditors and imposes independence, transparency, and integrity requirements. Together, the bills build AI compliance and risk-management infrastructure rather than imposing direct obligations on every AI deployer.
The Governor followed on September 10 with a child-safety package combining AI regulation, social-media design limits, and privacy protections for minors. The package includes companion-chatbot safeguards under SB 1119 and SB 867, restrictions on addictive social-media features and minor access under AB 1709 and AB 302, age-verification and children’s privacy measures under AB 1856 and AB 2246, CSAM and child-exploitation reporting and enforcement measures under AB 1946 and SB 1276, school technology and digital-wellness provisions under AB 1159, AB 2071, SB 1128, and AB 2298, and expanded child-injury liability under AB 2. It reflects California’s increasingly integrated approach to privacy, AI safety, product design, and youth online harms.
Another recent enactment, AB 1651, signed August 22, concerns the State Bar of California’s use of AI in developing and administering the bar examination. Although narrower than the September measures, it signals legislative interest in how public and quasi-public bodies disclose and govern their own AI use.
SB 1000, SB 947, SB 951, SB 574, SB 923, SB 1159, and SB 690 are key measures still awaiting the Governor’s action. SB 1000 would tighten AI-generated content disclosure rules; SB 947 and SB 951 address workplace AI and automation-related displacement; SB 574 covers generative AI use in legal and arbitration proceedings; SB 923 would expand CCPA deletion rights to personal information collected about a consumer, including from third parties, and require online-only businesses with a direct consumer relationship to provide an online request method in addition to email; SB 1159 would impose AI governance requirements on public agencies; and SB 690 would limit certain private CIPA pen-register/trap-and-trace claims involving websites and apps.
SB 690 deserves separate attention because of its litigation implications. Authored by Senator Anna Caballero, the bill was enrolled and presented to the Governor on September 4. It would amend CIPA’s remedies provision for alleged pen-register and trap-and-trace violations arising from websites, online applications, or mobile apps by allowing only the Attorney General to sue private actors. The limitation would also apply retroactively to pending Section 638.51 claims in actions commenced within two years before the bill’s operative date (January 1, 2027). SB 690 would not broadly exempt ordinary website analytics, cookies, pixels, or tracking technologies from CIPA.
For businesses, SB 690 could reduce one category of private CIPA claims but would not eliminate broader web-tracking risk. Section 638.51 claims are beginning to disappear from complaints. Claims under CIPA Sections 631 and 632 would remain intact, as would claims under California Penal Code Section 502 and the federal Electronic Communications Privacy Act. Plaintiffs may therefore continue to reframe website-tracking allegations as wiretapping, eavesdropping, ECPA, CDAFA, or unfair-competition claims, including allegations that a defective consent-management platform failed to capture, honor, or transmit valid consent signals. Cookie banners, consent records, vendor configurations, and opt-out implementation therefore remain important.
The bottom line is that California’s technology agenda remains active and unsettled. Signed measures show continued momentum around AI audits, child safety, and targeted transparency, while pending bills could expand obligations for provenance disclosures, workplace decision systems, legal-service AI use, government governance, and CIPA litigation reform. Companies should monitor the Governor’s bill actions through September 30 and update compliance roadmaps once the final package is clear.