1. Which AI Role Does Your Business Actually Perform?
Developing a model, offering a public GenAI service, licensing technology, and using a vendor’s AI tool are legally different activities. A company may fall within one regulatory framework while remaining outside another.
That role-based analysis is narrower than a general AI legal compliance review, which can also involve intellectual property, advertising, contracts, and federal law.
Genai Developers Can Face Training-Data and Content-Transparency Duties
AB 2013 requires developers of covered generative AI systems or services to publish documentation about training data. The rule applies to systems, services, or substantial modifications released on or after January 1, 2022 and made publicly available for use. Required information includes a high-level summary of datasets, their sources, whether protected or personal information appears in them, and whether synthetic data was used.
The California AI Transparency Act addresses a different problem: identifying AI-generated image, video, and audio content. Covered providers include producers of publicly accessible GenAI systems with more than one million monthly users or visitors. Among other duties, they must provide qualifying detection tools and content-provenance disclosures. AB 853 moved the Act’s operative date to August 2, 2026.
Licensing a model can raise separate contractual questions about permitted use, model modifications, training data, and downstream rights. Those issues fit more directly within AI licensing agreements.
Frontier Developers Follow a Separate Safety Framework
SB 53 does not apply merely because a company develops an AI product. It defines specific categories of frontier models, frontier developers, and large frontier developers.
Large frontier developers must maintain and publish a frontier AI framework addressing catastrophic-risk assessment, mitigation, governance, cybersecurity, and critical safety incidents. Frontier developers also have transparency-reporting and specified critical-safety-incident obligations.
The distinction between a frontier developer and a large frontier developer matters because some SB 53 requirements apply only to the larger category.
2. Businesses Using AI Can Face Privacy Rules without Developing a Model

A business does not have to build an AI model to encounter AI-related privacy requirements. The updated CCPA regulations cover risk assessments and automated decisionmaking technology, or ADMT, in specified circumstances. The regulations became effective January 1, 2026.
For businesses processing personal information, these requirements often belong within an existing data privacy compliance program rather than a stand-alone AI project.
Risk Assessments and ADMT Have Different Compliance Dates
Businesses subject to the risk-assessment requirements began compliance on January 1, 2026. The regulations provide a later date for ADMT-specific duties.
Businesses using ADMT to make significant decisions must comply with the ADMT requirements beginning January 1, 2027. Those rules include pre-use notice and, where applicable, consumer rights to opt out and obtain meaningful information about how the technology functioned and affected the decision.
The difference matters when planning compliance: the regulations became effective in 2026, but not every new obligation became enforceable on the same schedule.
3. Employment AI Remains Subject to Discrimination Law
Automated hiring and employment tools operate within a separate legal framework. Regulations addressing automated-decision systems in employment took effect October 1, 2025 and clarify how existing employment discrimination law applies when employers use algorithms and AI.
The legal question is how the tool functions in an employment decision—not whether the employer or vendor markets it as “AI.”
Automated Tools Do Not Displace the Employer’S Legal Obligations
Use of an automated-decision system may violate employment discrimination law when it disadvantages an applicant or employee based on a protected characteristic. The regulations also address automated assessments that may elicit disability-related information.
Employers and other covered entities must also retain specified employment records, including automated-decision system data, for at least four years. Testing performed to identify potential discrimination can be relevant to the legal analysis, but a vendor’s claim that a product is “unbiased” does not resolve how the employer actually uses it.
4. New AI Oversight Laws Are Creating Another Review Layer
The regulatory framework expanded again in September 2026. These newer laws focus on independent assessments and AI auditing rather than replacing the transparency, privacy, employment, or frontier-model requirements already in effect.
Businesses should distinguish enacted requirements from proposals still being developed through implementation or future recommendations.
Independent Verification and AI Auditor Frameworks Are Developing
SB 813 establishes a framework for independent verification organizations that can assess AI systems and models. AB 1405 creates a state registry for AI auditors and standards addressing independence, transparency, and integrity.
A September 18 executive order directed state agencies to accelerate implementation of those laws and develop recommendations for additional frontier-AI safety measures. Some ideas discussed in the order are recommendations for possible future legal changes, not requirements that businesses should treat as already enacted.
5. Frequently Asked Questions
Does California AI regulation apply to small businesses?
It can. There is no single size test that determines coverage under every AI-related statute or regulation.
CCPA-based obligations depend on whether the organization falls within the CCPA framework, while laws governing GenAI developers, frontier developers, employment systems, or synthetic content use their own definitions and triggers. A company should therefore identify the specific activity and statute before assuming that its size places it outside the rules.
Does every business have to label AI-generated content?
No. The California AI Transparency Act imposes specified disclosure and provenance requirements on defined covered providers; it does not create a universal requirement that every business label every AI-generated output.
Other laws can impose disclosure duties in narrower settings. For example, legislation signed in September 2026 addresses certain advertisements that use AI-generated performers.
Businesses whose products or workflows cross several of these categories may need a fact-specific legal review. The central issue is identifying which obligations attach to the company’s actual role and AI use, rather than treating AI compliance as one universal checklist.
21 Sep, 2026

