Skip to content

Published · 4 min read

California's AI Disclosure Laws: What Startups Need to Know

Part 1 of an AI Regulatory Compliance Series.

Ryan RieggRyan RieggCommercial Counsel

Everyone is talking about the EU AI Act. But before looking abroad, U.S. startups should be paying attention to California's AI disclosure rules—several of which are already in effect or becoming operative this year.

California hasn't passed one big AI law. It's built a layered regime touching model development, content outputs, automated decisions, chatbot interactions, and healthcare communications. The right question isn't "does a California AI law apply to us?"—it's which ones.

Here's a map of the obligations most likely to matter to your startup right now.

Three Levels of Disclosure Duty

California regulates AI transparency at three distinct stages: how a model was trained (AB 2013), how AI content is labeled and traced (SB 942 / AB 853), and how AI decisions and interactions are disclosed to users (CCPA's ADMT rules, chatbot law SB 243, healthcare law AB 489). Many startups that aren't model developers still have real exposure at the third level—and that's the one most companies overlook.

LawWhat It CoversWho It Applies ToEffective / Operative DatePenalty Exposure
AB 2013Training data transparencyGenerative AI developers with models available to CA users since Jan 2022January 1, 2026No explicit penalty; exposure under California's Unfair Competition Law
SB 942 / AB 853AI content watermarking and provenanceGenerative AI providers with 1M+ monthly CA users; hosting platforms from 2027August 2, 2026, delayed from Jan 1, 2026Up to $5,000 per violation, per day
CCPA ADMT rulesAutomated decisions (hiring, lending, housing, education, healthcare)Any business using ADMT for significant decisions, regardless of scaleJanuary 1, 2027Up to $7,500 per intentional violation
SB 243Companion chatbot disclosureOperators of AI companion chatbot platformsJanuary 1, 2026Private right of action, plus attorney's fees
AB 489Healthcare AI title and marketing restrictionsDevelopers or deployers of AI in healthcare contextsJanuary 1, 2026Enforcement by health care licensing boards
SB 53Frontier model safety transparencyFrontier developers (1026+ FLOPs); stricter rules above $500M revenueSigned September 29, 2025; obligations ongoingUp to $1,000,000 per violation

The Obligation Most Startups Miss: ADMT Under the CCPA

If your product uses AI to make or substantially influence significant decisions about people—hiring, lending, housing, education, healthcare—California's automated decision-making technology (ADMT) rules apply to you regardless of your scale or whether you train your own models.

Covered businesses must provide pre-use notice of the ADMT's purpose and the consumer's right to opt out, offer at least two designated opt-out methods, and conduct privacy risk assessments for high-risk processing. The compliance deadline is January 1, 2027, and enforcement fines run up to $7,500 per intentional violation. This is the California AI obligation most software companies are underprepared for.

AB2013 — Training Data Transparency

If you've trained or fine-tuned a generative AI model available to California users—free or paid, since January 1, 2022—you must publish a disclosure on your website describing, at a high level, what data you used. Required elements include data sources and categories, approximate scale, whether copyrighted or personal data was used, and whether synthetic data was involved. The disclosure must be updated with each substantial model modification.

There's no explicit penalty schedule, but noncompliance creates exposure under California's Unfair Competition Law—under which the AG needs no injury showing at all, and private plaintiffs need only show lost money or property. A pending constitutional challenge by xAI is worth watching, but OpenAI and Anthropic have already published compliant disclosures at a level of generality that doesn't appear to expose proprietary methodology. The practical standard: be specific enough to demonstrate real compliance, high-level enough to protect trade secrets, and have counsel review before you publish.

SB942 / AB 853 — Content Watermarking and Provenance

Providers of generative AI systems with over 1 million monthly California users must offer users manifest (visible) and latent (metadata) disclosures on AI-generated content, provide a free public AI detection tool, and contractually require downstream licensees to preserve those capabilities. The operative date—originally January 1, 2026—was pushed to August 2, 2026 by AB 853, and Governor Newsom's signing statement signaled further amendments are possible before then.

AB853 also added two new tiers worth noting: large online platforms (2M+ monthly users) and generative AI hosting platforms (those distributing model weights or source code) come into scope starting January 1, 2027. If you distribute open-weight models or are building a content platform at scale, that second wave applies to you.

Below those thresholds? You may still have downstream obligations. If you're building on top of a covered provider's model, check your API terms—watermarking obligations can flow through licensing agreements.

Sector-Specific Rules: Chatbots and Healthcare

SB243 requires operators of AI companion chatbots—systems designed to meet users' social needs through human-like, persistent interaction—to clearly disclose the AI nature of the interaction, with heightened requirements for minors. Standard customer service bots, virtual assistants, and business function tools are explicitly excluded.

AB489 (effective January 1, 2026) prohibits AI systems from using terms that imply a user is receiving care from a licensed health professional when no human oversight exists—including in advertising. For health-adjacent startups, this is a marketing constraint, not just a product one.

SB53 — Frontier AI (Probably Not You, But Worth Understanding)

SB53 targets developers of frontier models above 10^26 training operations with revenues over $500M. Most startups aren't close. But all frontier model developers, regardless of revenue, must publish transparency reports at deployment. And unlike AB 2013, SB 53 includes an explicit redaction mechanism for trade secrets—which is notable, because it shows California knows how to build that protection in when it wants to. Its absence from AB 2013 is deliberate.

Where to Start

The compliance question isn't "which California AI law is the big one?" It's: where in our product lifecycle does California require us to say more than we're currently saying?

Mapping that honestly—across training data, content outputs, automated decisions, and user interactions—requires a statute-by-statute analysis, not a single AI policy. The January 1, 2027 ADMT deadline is closer than it looks, and building compliant notice and opt-out flows into a product retroactively is significantly harder than designing for them from the start.

If you'd like help working through which obligations attach to your specific product and use cases, we'd be glad to talk.

Next in the series: The EU AI Act — What to Expect.

This post is for informational purposes only and does not constitute legal advice.

Key takeaways
  • California regulates AI transparency through at least six distinct statutes, not one omnibus law: AB 2013 (training data), SB 942/AB 853 (content watermarking), the CCPA's ADMT rules (automated decisions), SB 243 (companion chatbots), AB 489 (healthcare marketing), and SB 53 (frontier model safety).
  • The CCPA's ADMT rules are the one most startups miss: they apply to any business using AI to make or substantially influence hiring, lending, housing, education, or healthcare decisions, regardless of scale, with a compliance deadline of January 1, 2027 and fines up to $7,500 per intentional violation.
  • AB 2013 requires disclosure of training data sources for any generative AI model made available to California users since January 1, 2022. OpenAI, Anthropic, and Google have already published compliant disclosures, while xAI is challenging the law's constitutionality.
  • SB 942's watermarking and provenance requirements, amended by AB 853, were delayed from January 1, 2026 to August 2, 2026, with a new hosting-platform tier taking effect January 1, 2027.
  • SB 243 requires AI companion chatbot operators to disclose the AI's non-human nature, with heightened rules for minors; standard customer service bots are excluded.
  • SB 53 targets only the largest frontier model developers, those training models above 10^26 operations with more than $500 million in revenue, and, unlike AB 2013, includes an explicit trade-secret redaction mechanism.
TL;DR
The framingCalifornia doesn't have one AI law. It has at least six overlapping statutes, each triggered by a different stage of the AI lifecycle.
AB 2013Requires disclosure of training data sources for generative AI models offered to California users since January 2022, enforced via the Unfair Competition Law rather than a set penalty.
SB 942 / AB 853Requires watermarking and provenance disclosures for AI content from large providers, delayed to August 2, 2026, with a new tier for hosting platforms starting 2027.
CCPA ADMT rulesThe obligation most startups miss: applies to any business using AI to substantially influence hiring, lending, housing, education, or healthcare decisions, regardless of scale, effective January 1, 2027.
SB 243Requires AI companion chatbots to disclose they're not human, with heightened protections for minors, while standard customer-service bots are excluded.
AB 489Bars AI systems and their marketing from implying a user is getting care from a licensed health professional when there's no real human oversight.
SB 53Targets only frontier model developers above a huge compute and revenue threshold, but includes a trade-secret redaction mechanism absent from AB 2013.
The practical taskThe real compliance question isn't which law is 'the' AI law, but which of the six apply to your product and where you owe more disclosure.
FAQs

Does California have one comprehensive AI law?

No. California regulates AI transparency through at least six separate statutes, each triggered at a different stage: training data (AB 2013), content labeling (SB 942/AB 853), automated decisions (the CCPA's ADMT rules), companion chatbots (SB 243), healthcare marketing (AB 489), and frontier model safety (SB 53). Which ones apply depends on what your product actually does.

What is ADMT, and why is it the obligation most startups miss?

ADMT stands for automated decision-making technology. Under the CCPA, any business using AI to make or substantially influence significant decisions about people, hiring, lending, housing, education, or healthcare, must comply, regardless of size or whether it trains its own models. The compliance deadline is January 1, 2027, with fines up to $7,500 per intentional violation.

Does AB 2013 apply to startups that only use someone else's AI model?

AB 2013 applies to developers who train or fine-tune generative AI models made available to California users since January 1, 2022. If you're only using a third-party model without training or fine-tuning it, AB 2013's direct obligations likely don't attach to you, though you should still confirm your specific use case with counsel.

When does SB 942's watermarking requirement actually take effect?

August 2, 2026. The original date was January 1, 2026, but AB 853 delayed it. A further tier for large online platforms and AI hosting platforms takes effect January 1, 2027.

Does SB 243's companion chatbot law apply to a standard customer support bot?

No. SB 243 explicitly excludes standard customer service bots, virtual assistants, and other business function tools. It targets AI systems designed to meet users' social needs through human-like, persistent interaction.

What does AB 489 restrict for healthcare-adjacent startups?

AB 489 prohibits AI systems from using terms or claims that imply a user is receiving care from a licensed health professional when no human oversight actually exists, including in marketing and advertising, not just in the product itself.