Everyone is talking about the EU AI Act, but before looking abroad, U.S. startups should pay attention to California's AI disclosure rules, several of which are already in effect or will become operative this year.
Rather than passing one big AI law, California has built a layered regime touching model development, content outputs, automated decisions, chatbot interactions, and healthcare communications. In consequence, startups shouldn't be asking whether a California AI law applies to them, but instead, which ones. In this article, we'll take you through the obligations most likely to matter to your startup.
Three Levels of Disclosure Duty
California regulates AI transparency in the following three categories: how a model was trained (AB 2013), how AI content is labeled and traced (SB 942 / AB 853), and how AI decisions and interactions are disclosed to users (CCPA's ADMT rules, chatbot law SB 243, healthcare law AB 489). Many startups that aren't model developers overlook their disclosure obligations, thereby exposing themselves to undue regulatory risk.
Often Overlooked: ADMT Under the CCPA
No matter your company's scale or whether you train your own models, if your product uses AI to make or substantially influence significant decisions about people, such as in hiring, lending, housing, education, or healthcare, California's automated decision-making technology (ADMT) rules apply.
Covered businesses must provide pre-use notice of the ADMT's purpose and the consumer's right to opt out, offer at least two designated opt-out methods, and conduct privacy risk assessments for high-risk processing. Many software companies are underprepared for the looming compliance deadline of January 1, 2027, at which point enforcement fines will run up to $7,500 per intentional violation.
AB2013: Training Data Transparency
Regardless of if your model is free or paid, since January 1, 2022, companies training or fine-tuning a generative AI model available to California users must publish a disclosure on your website describing, at a high level, what data you used. This statute requires the disclosure of data sources and categories, approximate scale, whether copyrighted or personal data was used, and whether synthetic data was involved, as well as the regular update of the disclosure with each substantial model modification.
While there is no explicit penalty schedule, noncompliance creates exposure under California's Unfair Competition Law. Under this statute, the Attorney General needs no injury showing at all, and private plaintiffs need only demonstrate lost money or property. xAI is mounting a pending constitutional challenge, but OpenAI and Anthropic have already published compliant disclosures at a level of generality that doesn't appear to expose proprietary methodology. Companies should be specific enough to demonstrate compliance, high-level enough to protect trade secrets, and have counsel review disclosures before publishing.
SB942 / AB 853: Content Watermarking and Provenance
Providers of generative AI systems with over 1 million monthly California users must offer users manifest (visible) and latent (metadata) disclosures on AI-generated content, provide a free public AI detection tool, and contractually require downstream licensees to preserve those capabilities. Its original operative date was January 1, 2026, however, this was pushed to August 2, 2026 by AB 853. Governor Newsom's signing statement signaled further amendments are possible before then.
AB853 also added two new tiers which come into scope starting January 1, 2027: large online platforms (2M+ monthly users) and generative AI hosting platforms (those distributing model weights or source code).
Below those thresholds, you may still have downstream obligations. Licensing agreements may contain watermarking obligations, so verify your API terms if you're building on a covered provider's model.
Sector-Specific Rules on Chatbots and Healthcare
SB243 requires operators of AI companion chatbots, systems designed to meet users' social needs through human-like, persistent interaction, to clearly disclose the AI nature of the interaction, with heightened requirements for minors. Standard customer service bots, virtual assistants, and business function tools are explicitly excluded.
AB489 (effective January 1, 2026) prohibits AI systems from using terms that imply a user is receiving care from a licensed health professional when no human oversight exists, including in advertising. Beyond posing a product contraint, this is also a marketing constraint for health-adjacent startups.
SB53: Frontier AI
SB53 targets developers of frontier models above 10^26 training operations with revenues over $500M. Most startups aren't close. Nonetheless, all frontier model developers, regardless of revenue, must publish transparency reports at deployment. Unlike AB 2013, SB 53 includes an explicit redaction mechanism for trade secrets. This shows that California can implement that protection in when it wants to, making its absence from AB 2013 deliberate.
Compliance is an All-Around Audit
"Which California AI law is the big one?" is not the right question to ask because California's numerous AI disclosure laws are likely relevant to many different parts of your business. Instead, we should ask, "Where in our product lifecycle does California require us to disclose more than we currently do?" Compliance requires a statute-by-statute analysis involving cross training data, content outputs, automated decisions, and user interactions. General Legal's attorneys can help you get ahead of the January 1, 2027 ADMT deadline as legal partners in compliance, detangling compliance issues retroactively or helping advise on compliant notice and opt-out flows into a product proactively.
Need help working through which obligations attach to your specific product and use cases? We'd be glad to talk.
This post is for informational purposes only and does not constitute legal advice.
TL;DR: Rather than one comprehensive AI law, California has at least six overlapping ones, each triggered by a different part of the AI lifecycle: training data (AB 2013), content labeling (SB 942, delayed to August 2, 2026 by AB 853), automated decisions (the CCPA's ADMT rules, binding January 1, 2027, with fines up to $7,500 per intentional violation), companion chatbots (SB 243), healthcare marketing claims (AB 489), and frontier model safety (SB 53). Startups not training their own models often overlook their exposure, particularly through the CCPA's ADMT rules, which apply to any business using AI to make or substantially influence hiring, lending, housing, education, or healthcare decisions, regardless of size. It's critical to map which of California's numerous AI laws apply to your specific product, and General Legal can help you do so.
FAQs
Does California have one comprehensive AI law?
No. California regulates AI transparency through at least six separate statutes, each triggered at a different stage: training data (AB 2013), content labeling (SB 942/AB 853), automated decisions (the CCPA's ADMT rules), companion chatbots (SB 243), healthcare marketing (AB 489), and frontier model safety (SB 53). Which ones apply depends on what your product actually does.
What is ADMT, and why is it the obligation most startups miss?
ADMT stands for automated decision-making technology. Under the CCPA, any business using AI to make or substantially influence significant decisions about people, hiring, lending, housing, education, or healthcare, must comply, regardless of size or whether it trains its own models. The compliance deadline is January 1, 2027, with fines up to $7,500 per intentional violation.
Does AB 2013 apply to startups that only use someone else's AI model?
AB 2013 applies to developers who train or fine-tune generative AI models made available to California users since January 1, 2022. If you're only using a third-party model without training or fine-tuning it, AB 2013's direct obligations likely don't attach to you, though you should still confirm your specific use case with counsel.
When does SB 942's watermarking requirement actually take effect?
August 2, 2026. The original date was January 1, 2026, but AB 853 delayed it. A further tier for large online platforms and AI hosting platforms takes effect January 1, 2027.
Does SB 243's companion chatbot law apply to a standard customer support bot?
No. SB 243 explicitly excludes standard customer service bots, virtual assistants, and other business function tools. It targets AI systems designed to meet users' social needs through human-like, persistent interaction.
What does AB 489 restrict for healthcare-adjacent startups?
AB 489 prohibits AI systems from using terms or claims that imply a user is receiving care from a licensed health professional when no human oversight actually exists, including in marketing and advertising, not just in the product itself.
