California 2025-2026 Regular Session

California Assembly Bill AB1018 Compare Versions

OldNewDifferences
1-Amended IN Assembly May 01, 2025 Amended IN Assembly April 10, 2025 CALIFORNIA LEGISLATURE 20252026 REGULAR SESSION Assembly Bill No. 1018Introduced by Assembly Member Bauer-Kahan(Coauthors: Assembly Members Aguiar-Curry, Bryan, Ortega, and Ward)February 20, 2025An act to add Chapter 24.6 (commencing with Section 22756) to Division 8 of the Business and Professions Code, to amend Section 51 of the Civil Code, and to add Article 3 (commencing with Section 12959) to Chapter 6 of Part 2.8 of Division 3 of Title 2 of the Government Code, relating to artificial intelligence.LEGISLATIVE COUNSEL'S DIGESTAB 1018, as amended, Bauer-Kahan. Automated decision systems.The California Fair Employment and Housing Act establishes the Civil Rights Department within the Business, Consumer Services, and Housing Agency and requires the department to, among other things, bring civil actions to enforce the act.Existing law requires, on or before September 1, 2024, the Department of Technology to conduct, in coordination with other interagency bodies as it deems appropriate, a comprehensive inventory of all high-risk automated decision systems that have been proposed for use, development, or procurement by, or are being used, developed, or procured by, any state agency.This bill would generally regulate the development and deployment of an automated decision system (ADS) used to make consequential decisions, as defined. The bill would define automated decision system to mean a computational process derived from machine learning, statistical modeling, data analytics, or artificial intelligence that issues simplified output, including a score, classification, or recommendation, that is designed or used to assist or replace human discretionary decisionmaking and materially impacts natural persons.This bill would require a developer of a covered ADS, as defined, to take certain actions, including conduct performance evaluations of the covered ADS and provide deployers to whom the developer transfers the covered ADS with certain information, including the results of those performance evaluations.This bill would, beginning January 1, 2027, require a deployer of a covered ADS to take certain actions, including provide certain disclosures to a subject of a consequential decision made or facilitated by the covered ADS, provide the subject an opportunity to opt out of the use of the covered ADS, provide the subject with an opportunity to appeal the outcome of the consequential decision, and submit the covered ADS to third-party audits, as prescribed. The bill would also prescribe requirements for a third party to audit a covered ADS.This bill would require a developer, deployer, or auditor to, within 30 days of receiving a request from the Attorney General, provide an unredacted copy of the performance evaluation or disparate impact assessment prepared pursuant to the bill to the Attorney General and would exempt those records from the California Public Records Act.This bill would authorize certain public entities, including the Attorney General, to bring a specified civil action for noncompliance.Existing constitutional provisions require that a statute that limits the right of access to the meetings of public bodies or the writings of public officials and agencies be adopted with findings demonstrating the interest protected by the limitation and the need for protecting that interest.This bill would make legislative findings to that effect.Digest Key Vote: MAJORITY Appropriation: NO Fiscal Committee: YES Local Program: NO Bill TextThe people of the State of California do enact as follows:SECTION 1. Chapter 24.6 (commencing with Section 22756) is added to Division 8 of the Business and Professions Code, to read: CHAPTER 24.6. Automated Decisions Safety Act22756. As used in this chapter:(a) Artificial intelligence means an engineered or machine-based system that varies in its level of autonomy and that can, for explicit or implicit objectives, infer from the input it receives how to generate outputs that can influence physical or virtual environments.(b) (1) Automated decision system means a computational process derived from machine learning, statistical modeling, data analytics, or artificial intelligence that issues simplified output, including a score, classification, or recommendation, that is designed or used to assist or replace human discretionary decisionmaking and materially impacts natural persons.(2) Automated decision system does not mean a spam email filter, firewall, antivirus software, identity and access management tool, calculator, database, dataset, or other compilation of data.(c) Consequential decision means a decision that materially impacts the cost, terms, quality, or accessibility of any of the following to a natural person:(1) Employment-related decisions.(2) Education and vocational training as they relate to any of the following:(A) Assessment and placement.(B) Detecting student cheating and plagiarism.(C) Accreditation.(D) Certification.(E) Admissions and enrollment.(F) Discipline.(G) Evaluation.(H) Financial aid and scholarships.(I) Proctoring.(3) Housing and lodging as they relate to any of the following:(A) Rental or short-term housing and lodging.(B) Home appraisals.(C) Rental subsidies.(D) Publicly supported housing.(4) Any of the following essential utilities:(A) Electricity.(B) Heat.(C) Water.(D) Transportation.(E) Municipal trash and sewage services.(5) Family planning, adoption services, reproductive services, and assessments related to child protective services.(6) Health care and health insurance, including mental health care, dental, and vision.(7) Financial services, including a financial service provided by a mortgage company, mortgage broker, or creditor.(8) The criminal justice system with respect to pretrial release, sentencing, and alternatives to incarceration.(9) Legal services.(10) Private arbitration.(11) Mediation.(12) Elections as they relate to any of the following:(A) Voting.(B) Redistricting.(C) Voter eligibility and registration.(D) Distribution of voting information.(E) Election administration.(13) Access to government benefits or services or assignment of penalties by a government entity.(14) Places of public accommodation, as defined in Section 55.52 of the Civil Code.(15) Insurance.(16) Internet and telecommunications access.(d) Covered automated decision system or covered ADS means an automated decision system that is designed or used to make or facilitate a consequential decision.(e) Credit score means a credit score, as defined in Section 1785.15.1 of the Civil Code, from a consumer credit reporting agency, as defined in Section 1785.3 of the Civil Code.(f) Deployer means a person, partnership, state or local government agency, corporation, or developer that uses a covered ADS to make or facilitate a consequential decision, either directly or by contracting with a third party for that purpose.(g) Developer means a person, partnership, state or local government agency, corporation, or deployer that designs, codes, substantially modifies, or otherwise produces an automated decision system that makes or facilitates a consequential decision, either directly or by contracting with a third party for those purposes.(h) (1) Developer-approved use means a deployment context in which a developer intends a covered ADS to make or facilitate a consequential decision.(2) Developer-approved use includes any reasonably foreseeable fine tuning of the covered ADS.(i) Disparate impact means a differential effect on a group of individuals who share a protected characteristic.(j) Disparate treatment means differential treatment of an individual or group of individuals on the basis of a protected characteristic.(k) Employment-related decision means a decision made by an employer, either directly or through a third party, that affects wages, benefits, other compensation, hours, work schedule, performance evaluation, hiring, discipline, promotion, termination, job tasks and responsibilities, assignment of work, access to work and training opportunities, productivity requirements, workplace health and safety, or other terms or conditions of employment.(l) (1) Express consent means an affirmative written authorization that is granted in response to a notice that is all of the following:(A) Clear, meaningful, and prominent.(B) Conveyed in a manner that a natural person would notice and understand it.(C) Not contained within a more general notice, agreement, or set of terms and conditions.(2) Express consent does not mean an authorization that is either of the following:(A) Inferred from inaction.(B) Obtained through the use of a dark pattern, as defined in Section 56.18 of the Civil Code.(m) Fine-tune means to adjust the model parameters of an automated decision system through exposure to additional data.(n) Labor Commissioner means Chief of the Division of Labor Standards Enforcement.(o) Personal information has the same meaning as defined in Section 1798.140 of the Civil Code.(p) Protected characteristic means a characteristic listed in subdivision (b) of Section 51 of the Civil Code.(q) (1) Substantial modification means a new version, release, update, or other modification to a covered ADS that materially changes its uses or outputs.(2) Substantial modification does not mean a modification that results from fine tuning.(r) Trade secret has the same meaning as in Section 3426.1 of the Civil Code.(s) The definitions of disparate impact and disparate treatment provided in subdivisions (i) and (j) are intended solely for purposes of internal compliance, risk assessment, and documentation required by this chapter. These definitions shall not be construed to modify or supersede any standard, burden of proof, or element of a claim under the Unruh Civil Rights Act (Section 51 of the Civil Code), the California Fair Employment and Housing Act (Part 2.8 (commencing with Section 12900) of Division 3 of Title 2 of the Government Code), Title VII of the Civil Rights Act of 1964 (42 U.S.C. Sec. 2000e et seq.), or any other applicable civil rights law.22756.1. (a) (1) With respect to a covered ADS that was first deployed, or made available to potential deployers, before January 1, 2026, the developer of the covered ADS shall conduct an initial performance evaluation on the covered ADS before January 1, 2027, and shall additionally conduct a performance evaluation on the covered ADS under any of the following circumstances:(A) Following any substantial modification of the covered ADS by the developer.(B) Following any fine tuning of the covered ADS by the developer that materially changes the uses or outputs of the covered ADS.(C) No more than one year after the developer last conducted a performance evaluation on the covered ADS, for as long as the developer deploys the covered ADS or makes the covered ADS available to potential deployers.(2) With respect to a covered ADS that is first deployed or made available to potential deployers on or after January 1, 2026, the developer of the covered ADS shall conduct a performance evaluation on the covered ADS under any of the following circumstances:(A) Before initially deploying the covered ADS or making the covered ADS available to potential deployers.(B) Following any substantial modification of the covered ADS by the developer.(C) Following any fine tuning of the covered ADS by the developer that materially changes the uses or outputs of the covered ADS.(D) No more than one year after the developer last conducted a performance evaluation on the covered ADS, for as long as the developer deploys the covered ADS or makes the covered ADS available to potential deployers.(b) In conducting a performance evaluation on a covered ADS, a developer shall do all of the following:(1) Describe the purpose of the covered ADS.(2) List and describe all developer-approved uses of the covered ADS.(3) For each developer-approved use, evaluate the expected performance of the covered ADS and document all of the following:(A) The expected accuracy and reliability of the covered ADS.(B) Any reasonably foreseeable effects of fine tuning on the accuracy and reliability of the covered ADS.(C) Whether any disparate treatment is intended to occur and, if so, all of the following:(i) The conditions under which each disparate treatment is intended to occur.(ii) Whether each disparate treatment is necessary for a developer-approved use.(iii) Whether any alternatives not involving disparate treatment were considered.(D) Any reasonably foreseeable effects of fine tuning on disparate treatment.(E) Whether any disparate impacts are reasonably likely to occur and, if so, all of the following:(i) The conditions under which each disparate impact is reasonably likely to occur.(ii) Whether each disparate impact is necessary for a developer-approved use.(iii) Whether any alternatives not involving disparate impacts were considered.(F) Whether any measures have been taken by the developer to mitigate the risk of unanticipated disparate impacts resulting from the use of the covered ADS.(G) With respect to a covered ADS that has been deployed, whether any unanticipated disparate impacts have been reported to the developer by a deployer, and whether the developer has taken any measures to mitigate those disparate impacts.(H) Any reasonably foreseeable effects of fine tuning on disparate impacts.(4) (A) Contract with an independent third-party auditor to assess the developers compliance with this subdivision.(B) (i) Except pursuant to clause (ii), a developer that contracts with an auditor pursuant to this paragraph shall provide the auditor with any available information that is reasonably necessary for the auditor to comprehensively assess developer compliance.(ii) A developer that provides documentation to an auditor pursuant to this subparagraph may make reasonable redactions for the purpose of protecting trade secrets. To the extent that a developer withholds information, the developer shall notify the auditor and provide a basis for the withholding.(C) If the deadline for conducting a performance evaluation pursuant to subdivision (a) elapses before the audit has been completed, a developer shall not deploy the covered ADS or make the covered ADS available to potential deployers until the audit has been completed.(I)(D) A developer that receives feedback from an auditor pursuant to this paragraph shall do both of the following:(i) Consider and attempt to incorporate that feedback into the development of any subsequent version of a covered ADS.(ii) Make a high-level summary of the feedback publicly available at no cost to users of the developers internet website.(c) (1) A developer that sells, licenses, or otherwise transfers a covered ADS to a potential deployer shall provide the deployer with all of the following:(A) The results of the most recent performance evaluation conducted on the covered ADS by the developer pursuant to this chapter.(B) For each developer-approved use of the covered ADS, instructions explaining how the covered ADS should be used by the deployer to make or facilitate a consequential decision.(C) For each developer-approved use of the covered ADS, a description of whether and under what circumstances the covered ADS can be fine-tuned.(D) An explanation of the deployers responsibilities under this chapter, including a description of any circumstances under which the deployer would assume the responsibilities of a developer pursuant to subdivision (h) of Section 22756.2.(E) (i) Any technical information necessary for the deployer to comply with this chapter.(ii) A developer shall not be required to provide additional technical information to a deployer that has assumed the responsibilities of a developer pursuant to subdivision (h) of Section 22756.2.(2) (A) A developer that provides documentation to a potential deployer pursuant to this subdivision may make reasonable redactions for the purpose of protecting trade secrets.(B) To the extent that a developer withholds information pursuant to subparagraph (A), the developer shall notify the deployer and provide a basis for the withholding.(d) A developer that receives an impact assessment from an auditor of a deployed covered ADS pursuant to subdivision (b) of Section 22756.3 shall provide all of the following information to any deployer of the covered ADS:(A)(1) Any material differences between the expected accuracy of the covered ADS and the observed accuracy of the covered ADS and the deployment conditions under which those differences are reasonably likely to occur.(B)(2) Any material differences between the expected reliability of the covered ADS and the observed reliability of the covered ADS and the deployment conditions under which those differences are reasonably likely to occur.(C)(3) Any unanticipated disparate impacts resulting from the use of the covered ADS and the deployment conditions under which those disparate impacts are reasonably likely to occur.(D)(4) An explanation of any steps the deployer can take to mitigate these discrepancies.(e) A developer that receives feedback from an auditor pursuant to this chapter shall consider and attempt to incorporate that feedback into the development of any subsequent version of a covered ADS.(f) A developer that provides documentation to a deployer pursuant to this section shall ensure the documentation is all of the following:(A)(1) Transmitted directly to the deployer or otherwise made available in a manner reasonably calculated to ensure the deployer receives the documentation.(B)(2) Provided in English and in any other language the developer regularly uses to communicate with deployers.(C)(3) Presented in a manner that ensures the communication clearly and effectively conveys the required information to the deployer.(g) A developer that deploys a covered ADS or makes a covered ADS available to potential deployers shall maintain all of the following documentation in an unredacted format for as long as the developer deploys the covered ADS or makes the covered ADS available to potential deployers plus 10 years:(1) The results of any performance evaluations conducted on the covered ADS pursuant to this chapter.(2) Any documentation provided to deployers pursuant to this chapter.(3) Any documentation provided to, or received from, auditors pursuant to this chapter.(4) Records of any redactions made pursuant to this chapter.(h) It is unlawful to advertise to consumers in the state that a covered ADS is capable of performing in a manner not substantiated by the results of the most recent performance evaluation conducted on the covered ADS.(i) (1) A developer that deploys a covered ADS or makes a covered ADS available to potential deployers shall designate at least one employee to oversee the developers compliance with this chapter.(2) A developer shall require an employee designated pursuant to this subdivision to conduct a prompt and comprehensive review of any credible compliance issue raised to that employee.22756.2. (a) (1) Except as provided in paragraph (2), before a deployer finalizes a consequential decision made or facilitated by a covered ADS, the deployer shall provide any subject of that decision with a plain language written disclosure containing all of the following information:(A) A statement informing the subject that a covered ADS will be used to make or facilitate the consequential decision.(B) The name, version number, and developer of the covered ADS.(C) Whether the deployers use of the covered ADS is within the scope of a developer-approved use and a description of that use.(D) (i) The personal characteristics or attributes of the subject that the covered ADS measures or assesses to make or facilitate the consequential decision.(ii) The sources of personal information collected from the subject to make or facilitate the consequential decision.(iii) Any key parameters known to disproportionately affect the outcome of the consequential decision.(E) The structure and format of the outputs of the covered ADS and a plain language description of how those outputs are used to make or facilitate the consequential decision.(F) Whether a natural person will review either of the following before the consequential decision is finalized:(i) The outputs of the covered ADS.(ii) The outcome of the consequential decision.(G) The subjects rights under subdivisions (b) and (d) and the means and timeframe for exercising those rights.(H) (i) Contact information for the deployer.(ii) Contact information for the entity that manages the covered ADS, if that entity is not the deployer.(iii) Contact information for the entity that will interpret the results of the covered ADS, if that entity is not the deployer.(2) Paragraph (1) does not apply if the subject of the consequential decision is having a medical emergency.(b) (1) Before a deployer finalizes a consequential decision made or facilitated by a covered ADS, the deployer shall provide any subject of that decision with a reasonable opportunity to opt out of the use of the covered ADS.(2) (A) A deployer may deny a request to opt out of the use of a covered ADS if either of the following is true:(i) The deployer is subject to the federal Gramm-Leach-Bliley Act, and the covered ADS makes or facilitates a consequential decision pursuant to paragraph (7) of subdivision (c) of Section 22756.(ii) The subject of the consequential decision is having a medical emergency.(B) A deployer that denies a request to opt out of the use of a covered ADS pursuant to subparagraph (A) shall provide the subject with an explanation of the basis for the denial.(c) (1) After a deployer finalizes a consequential decision made or facilitated by a covered ADS, the deployer shall provide any subject of that decision witha plain language written disclosure containing all of the following information within five days:(A) The personal characteristics or attributes of the subject that the covered ADS used to make or facilitate the consequential decision.(B) The sources of personal information collected from the subject that were used to make or facilitate the consequential decision.(C) Any key parameters that disproportionately affected the outcome of the consequential decision.(D) The structure and format of the outputs of the covered ADS and a plain language description of how those outputs were used to make or facilitate the consequential decision.(E) The role that the ADS played in making the consequential decision and whether any human judgment was involved.(F) Contact information for the deployer.(G) Contact information for the entity that manages the covered ADS, if that entity is not the deployer.(H) Contact information for the entity that will interpret the results of the covered ADS, if that entity is not the deployer.(I) The subjects rights under subdivision (d) and the means and timeframe for exercising those rights.(2) Paragraph (1) does not apply if the subject of the consequential decision is having a medical emergency.(3) A deployer that provides documentation to a subject of a consequential decision pursuant to this subdivision shall ensure the documentation is all of the following:(A) Transmitted directly to the subject.(B) Provided in English and in any other language that the deployer regularly uses to communicate with subjects.(C) Made available in formats that are accessible to people who are blind or have other disabilities.(D) Presented in a manner that ensures the communication clearly and effectively conveys the required information to the subject.(d) After a deployer finalizes a consequential decision made or facilitated by a covered ADS, the deployer shall provide any subject of that decision with an opportunity to do both of the following within 30 business days:(1) (A) Correct any incorrect personal information used by the covered ADS to make or facilitate the consequential decision.(B) A deployer shall comply with a request to correct personal information within 30 business days of receiving the request if the request is accompanied by documentation sufficient to assess the basis for the request.(C) (i) If a deployer determines that complying with a request to correct personal information would change the outcome of the consequential decision, the deployer shall, within 30 days of making the determination, rectify the decision.(ii) If a deployer determines that complying with a request to correct personal information would not change the outcome of the consequential decision, the deployer shall, within 30 days of making the determination, inform the subject that the correction was made but that it did not alter the decision.(D) A deployer that denies a request to correct personal information shall do both of the following:(i) Provide the subject with an explanation of the basis for the denial.(ii) Provide the subject with a reasonable opportunity to request that the deployer delete the subjects personal information.(2) (A) Appeal the outcome of the consequential decision.(B) A deployer shall review a request to appeal a consequential decision within 30 business days of receiving the request if the request is accompanied by documentation sufficient to assess the basis for the request.(C) (i) If a deployer determines that the original decision was incorrect, the deployer shall, within 30 days of making the determination, rectify the decision.(ii) If a deployer determines that the original decision was correct, the deployer shall, within 30 days of making the determination, inform the subject that the consequential decision will not be altered.(D) A deployer that denies a request to appeal the outcome of a consequential decision shall provide the subject with an explanation of the basis for the denial.(e) (1) (A) A deployer that provides documentation to the subject of a consequential decision pursuant to this section may make reasonable redactions for the purpose of protecting trade secrets.(B) To the extent that a deployer withholds information pursuant to paragraph (1), the deployer shall notify the subject and provide a basis for the withholding.(2) A deployer that is required by another state or federal law to provide substantially similar notice to a subject of a consequential decision need not duplicatively provide notice to the subject under this section.(f) A deployers collection, use, retention, and sharing of personal information from a subject of a consequential decision shall be reasonably necessary and proportionate to achieve the purposes for which the personal information was collected and processed, or for another disclosed purpose that is compatible with the context in which the personal information was collected, and not further processed in a manner that is incompatible with those purposes.(g) (1) A deployer that uses a covered ADS to make or facilitate consequential decisions directly impacting more than 5,999 people in a given three-year period shall contract with an independent third-party auditor to conduct an impact assessment on the covered ADS before January 1, 2030, and every three years thereafter.(2) (A) Except pursuant to subparagraph (B), a deployer that contracts with an auditor pursuant to this subdivision shall provide the auditor with any available information that is reasonably necessary for the auditor to conduct a comprehensive impact assessment on the covered ADS.(B) A deployer that provides documentation to an auditor pursuant to this paragraph may make reasonable redactions for the purpose of protecting trade secrets. To the extent that a deployer withholds information, the developer shall notify the auditor and provide a basis for the withholding.(C) This paragraph shall not be construed to require a deployer to collect any personal information from a subject of a consequential decision beyond that which the deployer collects in the ordinary course of business or as necessary to comply with state or federal law.(3) If the deadline for conducting an audit pursuant to paragraph (1) elapses before the audit has been completed, a deployer shall not use the covered ADS to make or facilitate consequential decisions until the audit has been completed.(h) A deployer that does any of the following assumes the responsibilities of a developer under this chapter:(1) Uses a covered ADS to make or facilitate consequential decisions that directly impact more than 5,999 people in a given three-year period, if the deployer did not receive any documentation from the developer of the covered ADS pursuant to subdivision (c) of Section 22756.1 during the three-year period.(2) Uses a covered ADS to make or facilitate consequential decisions that directly impact more than 5,999 people in a given three-year period, if the deployers use of the covered ADS is outside the scope of a developer-approved use.(3) Substantially modifies an automated decision system and does either of the following:(A) Uses the substantially modified system to make or facilitate consequential decisions that directly impact more than 5999 5,999 people in a given three-year period.(B) Makes the substantially modified system available to potential deployers.(i) A deployer that uses a covered ADS to make or facilitate a consequential decision shall retain the following documentation in an unredacted format for as long as the deployer uses the covered ADS plus 10 years:(1) Any documentation received from developers pursuant to this chapter.(2) Any documentation provided pursuant to this section to subjects of consequential decisions made or facilitated by the covered ADS.(3) Any requests to correct personal information made pursuant to this section.(4) Any requests to opt out of the use of the covered ADS made pursuant to this section.(5) Any requests to appeal the outcome of a consequential decision made pursuant to this section.(6) Any documentation provided to, or received from, auditors pursuant to this chapter.(7) Records of any redactions made pursuant to this section.(j) (1) A deployer that uses a covered ADS to make or facilitate a consequential decision shall designate at least one employee to oversee the deployers compliance with this chapter.(2) A deployer shall require an employee designated pursuant to this subdivision to conduct a prompt and comprehensive review of any credible compliance issue related to the deployers use of a covered ADS that is raised to that employee.(k) In addition to the requirements of this section, a deployer that is a business subject to the California Consumer Privacy Act of 2018 (Title 1.81.5 (commencing with Section 1798.100)) is subject to any privacy-related opt-out and access regulation duly adopted by the California Privacy Protection Agency pursuant to subdivision (b) of Section 1798.199.40 of the Civil Code.(l) This section shall become operative on January 1, 2027.22756.3. (a) An auditor that conducts an impact assessment on a covered ADS pursuant to subdivision (g) of Section 22756.2 shall do all of the following:(1) (A) Request any information from the deployer of the covered ADS that is reasonably necessary for the auditor to conduct a comprehensive impact assessment.(B) This paragraph applies only to information gathered by the deployer in the ordinary course of business.(2) For each unique developer-approved use of the covered ADS by the deployer, document all of the following:(A) The observed accuracy and reliability of the covered ADS over the relevant period.(B) Whether the observed accuracy and reliability differed materially from the expected accuracy and reliability of the covered ADS, as described in documentation provided by a developer to the deployer pursuant to this chapter.(C) Whether any disparate impacts resulted from the deployers use of the covered ADS and the deployment conditions under which those disparate impacts occurred.(D) Whether each disparate impact was an anticipated disparate impact, as described in documentation provided to the deployer pursuant to this chapter.(3) Whether the deployer used the covered ADS to make or facilitate a consequential decision outside of the scope of a developer-approved use.(4) Whether the deployer assumed the responsibilities of a developer pursuant to subdivision (h) of Section 22756.2.(b) (1) After conducting an impact assessment on a covered ADS, an auditor shall do both of the following:(A) Provide the results of the impact assessment to the deployer that contracted with the auditor to perform the impact assessment.(B) Make a high-level summary of the results of the impact assessment publicly available at no cost to users of the auditors internet website.(2) The documentation required by this section shall be both of the following:(A) Provided in English and in any other language that the auditor regularly uses to communicate with deployers.(B) Presented in a manner that ensures the communication clearly and effectively conveys the required information.(3) An auditor shall not make publicly available with the personal information of a subject of a consequential decision made or facilitated by a covered ADS without first obtaining the express consent of the subject.22756.4. (a) (1) Within 30 days of receiving a request from the Attorney General for a performance evaluation or impact assessment prepared pursuant to this chapter, a developer, deployer, or auditor of a covered ADS shall provide an unredacted copy of the document to the Attorney General.(2) The Attorney General may share performance evaluations and impact assessments with other enforcement entities as necessary for enforcement purposes.(b) (1) The disclosure or sharing of a performance evaluation or impact assessment pursuant to subdivision (a) does not constitute a waiver of any attorney-client privilege, work-product protection, or trade secret protection that might otherwise exist with respect to any information contained in the performance evaluation or impact assessment.(2) A performance evaluation or impact assessment disclosed or shared pursuant to subdivision (a) is exempt from the California Public Records Act (Division 10 (commencing with Section 7920.000) of Title 1 of the Government Code).(c) Each day a covered ADS is used for which a performance evaluation or impact assessment has not been submitted to the Attorney General pursuant to this section is an additional violation of this section.22756.5. (a) Any of the following public entities may bring a civil action against a developer, deployer, or auditor who violates this chapter:(1) The Attorney General.(2) A district attorney, county counsel, or city attorney for the jurisdiction in which the violation occurred.(3) A city prosecutor in any city having a full-time city prosecutor with the consent of the district attorney.(4) The Civil Rights Department.(5) The Labor Commissioner with respect to employment-related decisions only.(b) A court may award a prevailing plaintiff who brings an action pursuant to subdivision (a) all of the following:(1) Injunctive relief.(2) Declaratory relief.(3) Reasonable attorneys fees and litigation costs.(4) A civil penalty of up to twenty-five thousand dollars ($25,000) per violation.(c) A developer or deployer who contracts with a third party to perform the developers or deployers duties under this chapter, other than those duties related to auditing, is subject to liability under this chapter for the third partys failure to perform those duties.22756.6. (a) This chapter does not apply to an automated decision system the sole purpose of which is to do either of the following:(1) Detect, protect against, or respond to cybersecurity incidents or preserve the integrity or security of computer systems.(2) Operate aircraft in the national airspace.(b) The use of a consumer credit score to inform a consequential decision does not itself create an obligation under this chapter.22756.7. (a) The rights, remedies, and penalties established by this chapter are cumulative and shall not be construed to supersede the rights, remedies, or penalties established under other laws, including, but not limited to, Chapter 6 (commencing with Section 12940) of Part 2.8 of Division 3 of Title 2 of the Government Code and Section 51 of the Civil Code.(b) This chapter does not diminish the rights, privileges, or remedies of an employee under any other federal or state law or under any employment contract or collective bargaining agreement.(c) This chapter does not authorize any use of automated decision systems that is limited, restricted, or prohibited under any other applicable law.(d) This chapter does not authorize disparate impacts or disparate treatment limited, restricted, or prohibited under any other applicable law.SEC. 2. Section 51 of the Civil Code, as amended by Section 2.5 of Chapter 779 of the Statutes of 2024, is amended to read:51. (a) This section shall be known, and may be cited, as the Unruh Civil Rights Act.(b) All persons within the jurisdiction of this state are free and equal, and no matter what their sex, race, color, religion, ancestry, national origin, disability, medical condition, genetic information, marital status, sexual orientation, citizenship, primary language, or immigration status are entitled to the full and equal accommodations, advantages, facilities, privileges, or services in all business establishments of every kind whatsoever.(c) This section shall not be construed to confer any right or privilege on a person that is conditioned or limited by law or that is applicable alike to persons of every sex, color, race, religion, ancestry, national origin, disability, medical condition, marital status, sexual orientation, citizenship, primary language, or immigration status, or to persons regardless of their genetic information.(d) Nothing in this section shall be construed to require any construction, alteration, repair, structural or otherwise, or modification of any sort whatsoever, beyond that construction, alteration, repair, or modification that is otherwise required by other provisions of law, to any new or existing establishment, facility, building, improvement, or any other structure, nor shall anything in this section be construed to augment, restrict, or alter in any way the authority of the State Architect to require construction, alteration, repair, or modifications that the State Architect otherwise possesses pursuant to other laws.(e) For purposes of this section:(1) Disability means any mental or physical disability as defined in Sections 12926 and 12926.1 of the Government Code.(2) (A) Genetic information means, with respect to any individual, information about any of the following:(i) The individuals genetic tests.(ii) The genetic tests of family members of the individual.(iii) The manifestation of a disease or disorder in family members of the individual.(B) Genetic information includes any request for, or receipt of, genetic services, or participation in clinical research that includes genetic services, by an individual or any family member of the individual.(C) Genetic information does not include information about the sex or age of any individual.(3) Medical condition has the same meaning as defined in subdivision (i) of Section 12926 of the Government Code.(4) Race is inclusive of traits associated with race, including, but not limited to, hair texture and protective hairstyles. Protective hairstyles includes, but is not limited to, such hairstyles as braids, locs, and twists.(5) Religion includes all aspects of religious belief, observance, and practice.(6) Sex includes, but is not limited to, pregnancy, childbirth, or medical conditions related to pregnancy or childbirth. Sex also includes, but is not limited to, a persons gender. Gender means sex, and includes a persons gender identity and gender expression. Gender expression means a persons gender-related appearance and behavior whether or not stereotypically associated with the persons assigned sex at birth.(7) Sex, race, color, religion, ancestry, national origin, disability, medical condition, genetic information, marital status, sexual orientation, citizenship, primary language, or immigration status includes any of the following:(A) Any combination of those characteristics.(B) A perception that the person has any particular characteristic or characteristics within the listed categories or any combination of those characteristics.(C) A perception that the person is associated with a person who has, or is perceived to have, any particular characteristic or characteristics, or any combination of characteristics, within the listed categories.(8) Sexual orientation has the same meaning as defined in subdivision (s) of Section 12926 of the Government Code.(f) A violation of the right of any individual under the federal Americans with Disabilities Act of 1990 (Public Law 101-336) shall also constitute a violation of this section.(g) Verification of immigration status and any discrimination based upon verified immigration status, where required by federal law, shall not constitute a violation of this section.(h) Nothing in this section shall be construed to require the provision of services or documents in a language other than English, beyond that which is otherwise required by other provisions of federal, state, or local law, including Section 1632.(i) In an action alleging a violation of this section in which the defendants development, modification, or use of an automated decision system, as defined in Section 22756 of the Business and Professions Code, is alleged to have caused or facilitated the violation, the extent to which the defendant complied with Chapter 25 24.6 (commencing with Section 22756) of Division 8 of the Business and Professions Code is relevant to, but not conclusive of, whether the defendant violated this section. section, and a failure to comply with Chapter 24.6 (commencing with Section 22756) of Division 8 of the Business and Professions Code shall not, by itself, give rise to a presumption of unlawful intent.SEC. 3. Article 3 (commencing with Section 12959) is added to Chapter 6 of Part 2.8 of Division 3 of Title 2 of the Government Code, to read: Article 3. Automated Decision Systems12959. In an action alleging a violation of this chapter in which the defendants development, modification, or use of an automated decision system, as defined in Section 22756 of the Business and Professions Code, is alleged to have caused or facilitated the violation, the extent to which the defendant complied with Chapter 24.6 (commencing with Section 22756) of Division 8 of the Business and Professions Code is relevant to, but not conclusive of, whether the defendant violated this chapter.SEC. 4. The Legislature finds and declares that Section 1 of this act, which adds Chapter 24.6 (commencing with Section 22756) to Division 8 of the Business and Professions Code, imposes a limitation on the publics right of access to the meetings of public bodies or the writings of public officials and agencies within the meaning of Section 3 of Article I of the California Constitution. Pursuant to that constitutional provision, the Legislature makes the following findings to demonstrate the interest protected by this limitation and the need for protecting that interest:In order to protect proprietary information, it is necessary that trade secrets disclosed in performance evaluations and impact assessments to agencies and departments pursuant to Section 1 of this act remain confidential.
1+Amended IN Assembly April 10, 2025 CALIFORNIA LEGISLATURE 20252026 REGULAR SESSION Assembly Bill No. 1018Introduced by Assembly Member Bauer-Kahan(Coauthors: Assembly Members Aguiar-Curry, Bryan, Ortega, Ward)February 20, 2025An act to add Chapter 24.6 (commencing with Section 22756) to Division 8 of the Business and Professions Code, to amend Section 51 of the Civil Code, and to add Article 3 (commencing with Section 12959) to Chapter 6 of Part 2.8 of Division 3 of Title 2 of the Government Code, relating to artificial intelligence.LEGISLATIVE COUNSEL'S DIGESTAB 1018, as amended, Bauer-Kahan. Automated decision systems.The California Fair Employment and Housing Act establishes the Civil Rights Department within the Business, Consumer Services, and Housing Agency and requires the department to, among other things, bring civil actions to enforce the act.Existing law requires, on or before September 1, 2024, the Department of Technology to conduct, in coordination with other interagency bodies as it deems appropriate, a comprehensive inventory of all high-risk automated decision systems that have been proposed for use, development, or procurement by, or are being used, developed, or procured by, any state agency.This bill would generally regulate the development and deployment of an automated decision system (ADS) used to make consequential decisions, as defined. The bill would define automated decision system to mean a computational process derived from machine learning, statistical modeling, data analytics, or artificial intelligence that issues simplified output, including a score, classification, or recommendation, that is designed or used to assist or replace human discretionary decisionmaking and materially impacts natural persons.This bill would require a developer of a covered ADS, as defined, to take certain actions, including conduct performance evaluations of the covered ADS and provide deployers to whom the developer transfers the covered ADS with certain information, including the results of those performance evaluations.This bill would, beginning January 1, 2027, require a deployer of a covered ADS to take certain actions, including provide certain disclosures to a subject of a consequential decision made or facilitated by the covered ADS, provide the subject an opportunity to opt out of the use of the covered ADS, provide the subject with an opportunity to appeal the outcome of the consequential decision, and submit the covered ADS to third-party audits, as prescribed. The bill would also prescribe requirements for a third party to audit a covered ADS.This bill would prescribe requirements for a third party to audit a covered ADS, as prescribed.This bill would require a developer, deployer, or auditor to, within 30 days of receiving a request from the Attorney General, provide an unredacted copy of the performance evaluation or disparate impact assessment prepared pursuant to the bill to the Attorney General and would exempt those records from the California Public Records Act.This bill would authorize certain public entities, including the Attorney General, to bring a specified civil action for noncompliance.Existing constitutional provisions require that a statute that limits the right of access to the meetings of public bodies or the writings of public officials and agencies be adopted with findings demonstrating the interest protected by the limitation and the need for protecting that interest.This bill would make legislative findings to that effect.Digest Key Vote: MAJORITY Appropriation: NO Fiscal Committee: YES Local Program: NO Bill TextThe people of the State of California do enact as follows:SECTION 1. Chapter 24.6 (commencing with Section 22756) is added to Division 8 of the Business and Professions Code, to read: CHAPTER 24.6. Automated Decisions Safety Act22756. As used in this chapter:(a) Artificial intelligence means an engineered or machine-based system that varies in its level of autonomy and that can, for explicit or implicit objectives, infer from the input it receives how to generate outputs that can influence physical or virtual environments.(b) (1) Automated decision system means a computational process derived from machine learning, statistical modeling, data analytics, or artificial intelligence that issues simplified output, including a score, classification, or recommendation, that is designed or used to assist or replace human discretionary decisionmaking and materially impacts natural persons.(2) Automated decision system does not mean a spam email filter, firewall, antivirus software, identity and access management tool, calculator, database, dataset, or other compilation of data.(c) Consequential decision means a decision that materially impacts the cost, terms, quality, or accessibility of any of the following to a natural person:(1) Employment-related decisions.(2) Education and vocational training as they relate to any of the following:(A) Assessment and placement.(B) Detecting student cheating and plagiarism.(C) Accreditation.(D) Certification.(E) Admissions and enrollment.(F) Discipline.(G) Evaluation.(H) Financial aid and scholarships.(I) Proctoring.(3) Housing and lodging as they relate to any of the following:(A) Rental or short-term housing and lodging.(B) Home appraisals.(C) Rental subsidies.(D) Publicly supported housing.(4) Any of the following essential utilities:(A) Electricity.(B) Heat.(C) Water.(D)Internet and telecommunications access.(E)(D) Transportation.(F)(E) Municipal trash and sewage services.(5) Family planning, adoption services, reproductive services, and assessments related to child protective services.(6) Health care and health insurance, including mental health care, dental, and vision.(7) Financial services, including a financial service provided by a mortgage company, mortgage broker, or creditor.(8) The criminal justice system with respect to pretrial release, sentencing, and alternatives to incarceration.(9) Legal services.(10) Private arbitration.(11) Mediation.(12) Elections as they relate to any of the following:(A) Voting.(B) Redistricting.(C) Voter eligibility and registration.(D) Distribution of voting information.(E) Election administration.(13) Access to government benefits or services or assignment of penalties by a government entity.(14) Places of public accommodation, as defined in Section 55.52 of the Civil Code.(15) Insurance.(16) Internet and telecommunications access.(d) Covered automated decision system or covered ADS means an automated decision system that makes or facilitates is designed or used to make or facilitate a consequential decision.(e) Credit score means a credit score, as defined in Section 1785.15.1 of the Civil Code, from a consumer credit reporting agency, as defined in Section 1785.3 of the Civil Code.(e)(f) Deployer means a person, partnership, state or local government agency, corporation, or developer that uses a covered ADS to make or facilitate a consequential decision, either directly or through by contracting with a third party. party for that purpose.(f)(g) Developer means a person, partnership, state or local government agency, corporation, or deployer that designs, codes, substantially modifies, or otherwise produces an automated decision system that makes or facilitates a consequential decision, either directly or through by contracting with a third party. party for those purposes.(g)(h) (1) Developer-approved use means a deployment context in which a developer intends a covered ADS to make or facilitate a consequential decision.(2) Developer-approved use includes any reasonably foreseeable fine tuning of the covered ADS.(h)(i) Disparate impact means a differential effect on a group of individuals who share a protected characteristic.(i)(j) Disparate treatment means differential treatment of an individual or group of individuals on the basis of a protected characteristic.(j)(k) Employment-related decision means a decision made by an employer, either directly or through a third party, that affects wages, benefits, other compensation, hours, work schedule, performance evaluation, hiring, discipline, promotion, termination, job tasks and responsibilities, assignment of work, access to work and training opportunities, productivity requirements, workplace health and safety, or other terms or conditions of employment.(k)(l) (1) Express consent means an affirmative written authorization that is granted in response to a notice that is all of the following:(A) Clear, meaningful, and prominent.(B) Conveyed in a manner that a natural person would notice and understand it.(C) Not contained within a more general notice, agreement, or set of terms and conditions.(2) Express consent does not mean an authorization that is either of the following:(A) Inferred from inaction.(B) Obtained through the use of a dark pattern, as defined in Section 56.18 of the Civil Code.(l)(m) Fine-tune means to adjust the model parameters of an automated decision system through exposure to additional data.(m)(n) Labor Commissioner means Chief of the Division of Labor Standards Enforcement.(n)(o) Personal information has the same meaning as defined in Section 1798.140 of the Civil Code.(o)(p) Protected characteristic means a characteristic listed in subdivision (b) of Section 51 of the Civil Code.(p)(q) (1) Substantial modification means a new version, release, update, or other modification to a covered ADS that materially changes its uses or outputs.(2) Substantial modification does not mean a modification that results from fine tuning.(q)(r) Trade secret has the same meaning as in Section 3426.1 of the Civil Code.22756.1. (a) (1) With respect to a covered ADS that was first deployed, or made available to potential deployers, before January 1, 2026, the developer of the covered ADS shall conduct an initial performance evaluation on the covered ADS before January 1, 2027, and shall additionally conduct a performance evaluation on the covered ADS under any of the following circumstances:(A) Following any substantial modification of the covered ADS by the developer.(B) Following any fine tuning of the covered ADS by the developer that materially changes the uses or outputs of the covered ADS.(C) No more than one year after the developer last conducted a performance evaluation on the covered ADS, for as long as the developer deploys the covered ADS or makes the covered ADS available to potential deployers.(2) With respect to a covered ADS that is first deployed or made available to potential deployers on or after January 1, 2026, the developer of the covered ADS shall conduct a performance evaluation on the covered ADS under any of the following circumstances:(A) Before initially deploying the covered ADS or making the covered ADS available to potential deployers.(B) Following any substantial modification of the covered ADS by the developer.(C) Following any fine tuning of the covered ADS by the developer that materially changes the uses or outputs of the covered ADS.(D) No more than one year after the developer last conducted a performance evaluation on the covered ADS, for as long as the developer deploys the covered ADS or makes the covered ADS available to potential deployers.(b) In conducting a performance evaluation on a covered ADS, a developer shall do all of the following:(1) Describe the purpose of the covered ADS.(2) List and describe all developer-approved uses of the covered ADS.(3) For each developer-approved use, assess evaluate the expected performance of the covered ADS and document all of the following:(A) The expected accuracy and reliability of the covered ADS.(B) Any reasonably foreseeable effects of fine tuning on the accuracy and reliability of the covered ADS.(4)For each developer-approved use, assess whether(C) Whether any disparate treatment is intended to occur and document and, if so, all of the following:(A)Whether the covered ADS is intended to treat individuals or groups of individuals differently on the basis of a protected characteristic.(B)For each disparate treatment identified under subparagraph (A), describe all of the following:(i) The conditions under which the each disparate treatment is intended to occur.(ii) Whether the each disparate treatment is necessary for a developer-approved use.(iii) Whether any alternatives not involving disparate treatment were considered.(C)(D) Any reasonably foreseeable effects of fine tuning on disparate treatment.(5)For each developer-approved use, assess whether (E) Whether any disparate impacts are reasonably likely to occur and document and, if so, all of the following:(A)Whether the covered ADS is reasonably likely to treat groups of individuals who share a protected characteristic differently.(B)For each disparate impact identified under subparagraph (A), describe all of the following:(i) The conditions under which that each disparate impact is reasonably likely to occur.(ii) Whether the each disparate impact is necessary for a developer-approved use.(iii) Whether any alternatives not involving disparate impacts were considered.(C)(F) Whether any measures have been taken by the developer to mitigate the risk of unanticipated disparate impacts resulting from the use of the covered ADS.(D)(G) With respect to a covered ADS that has been deployed, whether any unanticipated disparate impacts have been reported to the developer by a deployer, and whether the developer has taken any measures to mitigate those disparate impacts.(E)(H) Any reasonably foreseeable effects of fine tuning on disparate impacts.(6)(4) (A) Contract with an independent third-party auditor to assess the developers compliance with this subdivision.(B) (i) Except pursuant to clause (ii), a developer that contracts with an auditor pursuant to this paragraph shall provide the auditor with any available information that is reasonably necessary for the auditor to comprehensively assess developer compliance.(ii) A developer that provides documentation to an auditor pursuant to this subparagraph may make reasonable redactions for the purpose of protecting trade secrets. To the extent that a developer withholds information, the developer shall notify the auditor and provide a basis for the withholding.(C) If the deadline for conducting a performance evaluation pursuant to subdivision (a) elapses before the audit has been completed, a developer shall not deploy the covered ADS or make the covered ADS available to potential deployers until the audit has been completed.(I) A developer that receives feedback from an auditor pursuant to this paragraph shall do both of the following:(i) Consider and attempt to incorporate that feedback into the development of any subsequent version of a covered ADS.(ii) Make a high-level summary of the feedback publicly available at no cost to users of the developers internet website.(c) (1) A developer that sells, licenses, or otherwise transfers a covered ADS to a potential deployer shall provide the deployer with all of the following:(A) The results of the most recent performance evaluation conducted on the covered ADS by the developer pursuant to this chapter.(B) For each developer-approved use of the covered ADS, instructions explaining how the covered ADS should be used by the deployer to make or facilitate a consequential decision.(C) For each developer-approved use of the covered ADS, a description of whether and under what circumstances the covered ADS can be fine-tuned.(D) An explanation of the deployers responsibilities under this chapter, including a description of any circumstances under which the deployer would assume the responsibilities of a developer pursuant to subdivision (h) of Section 22756.2.(E) (i) Any technical information necessary for the deployer to comply with this chapter.(ii) A developer shall not be required to provide additional technical information to a deployer that has assumed the responsibilities of a developer pursuant to subdivision (h) of Section 22756.2.(2) (A) A developer that provides documentation to a potential deployer pursuant to this subdivision may make reasonable redactions for the purpose of protecting trade secrets.(B) To the extent that a developer withholds information pursuant to subparagraph (A), the developer shall notify the deployer and provide a basis for the withholding.(d) A developer that receives an impact assessment from an auditor of a deployed covered ADS pursuant to subdivision (b) of Section 22756.3 shall provide all of the following information to any deployer of the covered ADS:(A) Any material differences between the expected accuracy of the covered ADS and the observed accuracy of the covered ADS and the deployment conditions under which those differences are reasonably likely to occur.(B) Any material differences between the expected reliability of the covered ADS and the observed reliability of the covered ADS and the deployment conditions under which those differences are reasonably likely to occur.(C) Any unanticipated disparate impacts resulting from the use of the covered ADS and the deployment conditions under which those disparate impacts are reasonably likely to occur.(D) An explanation of any steps the deployer can take to mitigate these discrepancies.(e) A developer that receives feedback from an auditor pursuant to this chapter shall consider and attempt to incorporate that feedback into the development of any subsequent version of a covered ADS.(f) A developer that provides documentation to a deployer pursuant to this section shall ensure the documentation is all of the following:(A) Transmitted directly to the deployer or otherwise made available in a manner reasonably calculated to ensure the deployer receives the documentation.(B) Provided in English and in any other language the developer regularly uses to communicate with deployers.(C) Presented in a manner that ensures the communication clearly and effectively conveys the required information to the deployer.(g) A developer that deploys a covered ADS or makes a covered ADS available to potential deployers shall maintain all of the following documentation in an unredacted format for as long as the covered ADS remains deployed or developer deploys the covered ADS or makes the covered ADS available to potential deployers plus 10 years:(1) The results of any performance evaluations conducted on the covered ADS pursuant to this chapter.(2) Any documentation provided to deployers pursuant to this chapter.(3) Any documentation provided to, or received from, auditors pursuant to this chapter.(4) Records of any redactions made pursuant to this chapter.(h) It is unlawful to advertise to consumers in the state that a covered ADS is capable of performing in a manner not substantiated by the results of the most recent performance evaluation conducted on the covered ADS.(i) (1) A developer that deploys a covered ADS or makes a covered ADS available to potential deployers shall designate at least one employee to oversee the developers compliance with this chapter.(2) A developer shall require an employee designated pursuant to this subdivision to conduct a prompt and comprehensive review of any credible compliance issue raised to that employee.22756.2. (a) (1) Except as provided in paragraph (2), before finalizing a deployer finalizes a consequential decision made or facilitated by a covered ADS, a the deployer shall provide any subject of that decision with a plain language written disclosure containing all of the following information:(A) A statement informing the subject that a covered ADS will be used to make or facilitate the consequential decision.(B) The name, version number, and developer of the covered ADS.(C) Whether the deployers use of the covered ADS is within the scope of a developer-approved use and a description of that use.(D) (i) The personal characteristics or attributes of the subject that the covered ADS measures or assesses to make or facilitate the consequential decision.(ii) The sources of personal information collected from the subject to make or facilitate the consequential decision.(iii) Any key parameters known to disproportionately affect the outcome of the consequential decision.(E) The structure and format of the outputs of the covered ADS and a plain language description of how those outputs are used to make or facilitate the consequential decision.(F) Whether a natural person will review either of the following before the consequential decision is finalized:(i) The outputs of the covered ADS.(ii) The outcome of the consequential decision.(G) The subjects rights under subdivisions (b) and (c) (d) and the means and timeframe for exercising those rights.(H) (i) Contact information for the deployer.(ii) Contact information for the entity that manages the covered ADS, if that entity is not the deployer.(iii) Contact information for the entity that will interpret the results of the covered ADS, if that entity is not the deployer.(2) Paragraph (1) does not apply if the subject of the consequential decision is having a medical emergency.(b) (1) Before finalizing a deployer finalizes a consequential decision made or facilitated by a covered ADS, a the deployer shall provide any subject of that decision with a reasonable opportunity to opt out of the use of the covered ADS.(2) (A) A deployer may deny a request to opt out of the use of a covered ADS if either of the following is true:(i) The deployer is subject to the federal Gramm-Leach-Bliley Act, and the covered ADS makes or facilitates a consequential decision pursuant to paragraph (7) of subdivision (c) of Section 22756.(ii) The subject of the consequential decision is having a medical emergency.(B) A deployer that denies a request to opt out of the use of a covered ADS pursuant to subparagraph (A) shall provide the subject with an explanation of the basis for the denial.(c) (1) After a deployer finalizes a consequential decision is finalized, made or facilitated by a covered ADS, the deployer shall provide any subject of that decision witha plain language written disclosure shall be provided containing all of the following information within five days, and the disclosure shall include all of the information: days:(A) The personal characteristics or attributes of the subject that the covered ADS measured or assessed used to make or facilitate the consequential decision.(B) The sources of personal information collected from the subject that were used to make or facilitate the consequential decision.(C) Any key parameters that disproportionately affected the outcome of the consequential decision.(D) The structure and format of the outputs of the covered ADS and a plain language description of how those outputs were used to make or facilitate the consequential decision.(E) The role that the ADS played in making the consequential decision and whether any human judgment was involved.(F) Contact information for the deployer.(G) Contact information for the entity that manages the covered ADS, if that entity is not the deployer.(H) Contact information for the entity that will interpret the results of the covered ADS, if that entity is not the deployer.(I) The subjects rights under subdivision (d) and the means and timeframe for exercising those rights.(2) Paragraph (1) is does not applicable apply if the subject of the consequential decision is having a medical emergency.(3) A deployer that provides documentation to a subject of a consequential decision pursuant to this subdivision shall ensure the documentation is all of the following:(A) Transmitted directly to the subject.(B) Provided in English and in any other language that the deployer regularly uses to communicate with subjects.(C) Made available in formats that are accessible to people who are blind or have other disabilities.(D) Presented in a manner that ensures the communication clearly and effectively conveys the required information to the subject.(d) After finalizing a deployer finalizes a consequential decision made or facilitated by a covered ADS, a the deployer shall provide any subject of that decision with an opportunity to do both of the following within 30 business days:(1) (A) Correct any incorrect personal information used by the covered ADS to make or facilitate the consequential decision.(B) A deployer shall comply with a request to correct personal information within 30 business days of receiving the request if the request is accompanied by documentation sufficient to assess the basis for the request.(C) (i) If a deployer determines that complying with a request to correct personal information would change the outcome of the consequential decision, the deployer shall, within 30 days of making the determination, rectify the decision.(ii) If a deployer determines that complying with a request to correct personal information would not change the outcome of the consequential decision, the deployer shall, within 30 days of making the determination, inform the subject that the correction was made but that it did not alter the decision.(D) A deployer that denies a request to correct personal information shall do both of the following:(i) Provide the subject with an explanation of the basis for the denial.(ii) Provide the subject with a reasonable opportunity to request that the deployer delete the subjects personal information.(2) (A) Appeal the outcome of the consequential decision.(B) A deployer shall review a request to appeal a consequential decision within 30 business days of receiving the request. request if the request is accompanied by documentation sufficient to assess the basis for the request.(C) (i) If a deployer determines that the original decision is was incorrect, the deployer shall, within 30 days of making the determination, rectify the decision.(ii) If a deployer determines that the original decision is was correct, the deployer shall, within 30 days of making the determination, inform the subject that the consequential decision will not be altered.(D) A deployer that denies a request to appeal the outcome of a consequential decision shall provide the subject with an explanation of the basis for the denial.(e) (1) (A) A deployer that provides documentation to the subject of a consequential decision pursuant to this section may make reasonable redactions for the purpose of protecting trade secrets.(B) To the extent that a deployer withholds information pursuant to paragraph (1), the deployer shall notify the subject and provide a basis for the withholding.(2) A deployer that is required by another state or federal law to provide substantially similar notice to a subject of a consequential decision need not duplicatively provide notice to the subject under this section.(f) A deployers collection, use, retention, and sharing of personal information from a subject of a consequential decision shall be reasonably necessary and proportionate to achieve the purposes for which the personal information was collected and processed, or for another disclosed purpose that is compatible with the context in which the personal information was collected, and not further processed in a manner that is incompatible with those purposes.(g) (1) A deployer that uses a covered ADS to make or facilitate consequential decisions directly impacting more than 5999 5,999 people in a given three-year period shall contract with an independent third-party auditor to conduct an impact assessment on the covered ADS before January 1, 2030, and every three years thereafter.(2) (A) Except pursuant to subparagraph (B), a deployer that contracts with an auditor pursuant to this subdivision shall provide the auditor with any available information that is reasonably necessary for the auditor to conduct a comprehensive impact assessment on the covered ADS.(B) A deployer that provides documentation to an auditor pursuant to this paragraph may make reasonable redactions for the purpose of protecting trade secrets. To the extent that a deployer withholds information, the developer shall notify the auditor and provide a basis for the withholding.(C) This paragraph shall not be construed to require a deployer to collect any personal information from a subject of a consequential decision beyond that which the deployer collects in the ordinary course of business or as necessary to comply with state or federal law.(3) If the deadline for conducting an audit pursuant to paragraph (1) elapses before the audit has been completed, a deployer shall not use the covered ADS to make or facilitate consequential decisions until the audit has been completed.(h) A deployer that does any of the following assumes the responsibilities of a developer under this chapter:(1) Uses a covered ADS to make or facilitate consequential decisions that directly impact more than 5999 5,999 people in a given three-year period, if the deployer did not receive any documentation from the developer of the covered ADS pursuant to subdivision (c) of Section 22756.1. 22756.1 during the three-year period.(2) Uses a covered ADS to make or facilitate consequential decisions that directly impact more than 5999 5,999 people in a given three-year period, if the deployers use of the covered ADS is outside the scope of a developer-approved use.(3) Substantially modifies an automated decision system and does either of the following:(A) Uses the substantially modified system to make or facilitate consequential decisions that directly impact more than 5999 people in a given three-year period.(B) Makes the substantially modified system available to potential deployers.(i) A deployer that uses a covered ADS to make or facilitate a consequential decision shall retain the following documentation in an unredacted format for as long as the deployer uses the covered ADS remains deployed plus 10 years:(1) Any documentation received from developers pursuant to this chapter.(2) Any documentation provided pursuant to this section to subjects of consequential decisions made or facilitated by the covered ADS.(3) Any requests to correct personal information made pursuant to this section.(4) Any requests to opt out of the use of the covered ADS made pursuant to this section.(5) Any requests to appeal the outcome of a consequential decision made pursuant to this section.(6) Any documentation provided to, or received from, auditors pursuant to this chapter.(7) Records of any redactions made pursuant to this section.(j) (1) A deployer that uses a covered ADS to make or facilitate a consequential decision shall designate at least one employee to oversee the deployers compliance with this chapter.(2) A deployer shall require an employee designated pursuant to this subdivision to conduct a prompt and comprehensive review of any credible compliance issue related to the deployers use of a covered ADS that is raised to that employee.(k) In addition to the requirements of this section, a deployer that is a business subject to the California Consumer Privacy Act of 2018 (Title 1.81.5 (commencing with Section 1798.100)) is subject to any privacy-related opt-out and access regulation duly adopted by the California Privacy Protection Agency pursuant to subdivision (b) of Section 1798.199.40 of the Civil Code.(l) This section shall become operative on January 1, 2027.22756.3. (a) An auditor that conducts an impact assessment on a covered ADS pursuant to subdivision (g) of Section 22756.2 shall do all of the following:(1) (A) Request any information from the deployer of the covered ADS that is reasonably necessary for the auditor to conduct a comprehensive impact assessment.(B) This paragraph applies only to information gathered by the deployer in the ordinary course of business.(2)Document all developer-approved uses of the covered ADS that the deployer utilized during the relevant period.(3)(2) For each unique developer-approved use, use of the covered ADS by the deployer, document all of the following:(A) The observed accuracy and reliability of the covered ADS over the relevant period.(B) Whether the observed accuracy and reliability differed materially from the expected accuracy and reliability of the covered ADS, as described in documentation provided by a developer to the deployer pursuant to this chapter.(C) Whether any disparate impacts resulted from the deployers use of the covered ADS and the deployment conditions under which those disparate impacts occurred.(D) Whether each disparate impact was an anticipated disparate impact, as described in documentation provided to the deployer pursuant to this chapter.(4)(3) Whether the deployer used the covered ADS to make or facilitate a consequential decision outside of the scope of a developer-approved use.(5)(4) Whether the deployer assumed the responsibilities of a developer pursuant to subdivision (h) of Section 22756.2.(b) (1) After conducting an impact assessment on a covered ADS, an auditor shall provide the results of the impact assessment to do both of the following:(A) The Provide the results of the impact assessment to the deployer that contracted with the auditor to perform the impact assessment.(B)The developer of the covered ADS.(B) Make a high-level summary of the results of the impact assessment publicly available at no cost to users of the auditors internet website.(2) The documentation required by this section shall be both of the following:(A) Provided in English and in any other language that the auditor regularly uses to communicate with developers and deployers.(B) Presented in a manner that ensures the communication clearly and effectively conveys the required information to the developer and deployer. information.(3) An auditor shall not provide a developer make publicly available with the personal information of a subject of a consequential decision made or facilitated by a covered ADS without first obtaining the express consent of the subject.22756.4. (a) (1) Within 30 days of receiving a request from the Attorney General for a performance evaluation or impact assessment prepared pursuant to this chapter, a developer, deployer, or auditor of a covered ADS shall provide an unredacted copy of the document to the Attorney General.(2) The Attorney General may share performance evaluations and impact assessments with other enforcement entities as necessary for enforcement purposes.(b) (1) The disclosure or sharing of a performance evaluation or impact assessment pursuant to subdivision (a) does not constitute a waiver of any attorney-client privilege, work-product protection, or trade secret protection that might otherwise exist with respect to any information contained in the performance evaluation or impact assessment.(2) A performance evaluation or impact assessment disclosed or shared pursuant to subdivision (a) is exempt from the California Public Records Act (Division 10 (commencing with Section 7920.000) of Title 1 of the Government Code).(c) Each day a covered ADS is used for which a performance evaluation or impact assessment has not been submitted to the Attorney General pursuant to this section is an additional violation of this section.22756.5. (a) Any of the following public entities may bring a civil action against a developer or deployer developer, deployer, or auditor who violates this chapter:(1) The Attorney General.(2) A district attorney, county counsel, or city attorney for the jurisdiction in which the violation occurred.(3) A city prosecutor in any city having a full-time city prosecutor with the consent of the district attorney.(4) The Civil Rights Department.(5) The Labor Commissioner with respect to employment-related decisions only.(b) A court may award a prevailing plaintiff who brings an action pursuant to subdivision (a) all of the following:(1) Injunctive relief.(2) Declaratory relief.(3) Reasonable attorneys fees and litigation costs.(4) A civil penalty of up to twenty-five thousand dollars ($25,000) per violation.(c) A developer or deployer who contracts with a third party to perform the developers or deployers duties under this chapter, other than those duties related to auditing, is subject to liability under this chapter for the third partys failure to perform those duties.22756.6. (a) This chapter does not apply to an automated decision system the sole purpose of which is to do either of the following:(a)(1) Detect, protect against, or respond to cybersecurity incidents or preserve the integrity or security of computer systems.(b)(2) Operate aircraft in the national airspace.(b) The use of a consumer credit score to inform a consequential decision does not itself create an obligation under this chapter.22756.7. (a) The rights, remedies, and penalties established by this chapter are cumulative and shall not be construed to supersede the rights, remedies, or penalties established under other laws, including, but not limited to, Chapter 6 (commencing with Section 12940) of Part 2.8 of Division 3 of Title 2 of the Government Code and Section 51 of the Civil Code.(b) This chapter does not diminish the rights, privileges, or remedies of an employee under any other federal or state law or under any employment contract or collective bargaining agreement.(c) This chapter does not authorize any use of automated decision systems that is limited, restricted, or prohibited under any other applicable law.(d) This chapter does not authorize disparate impacts or disparate treatment that are limited, restricted, or prohibited under any other applicable law.22756.8.A developer or deployer who contracts with a third party to comply with duties required under this chapter, other than those duties related to auditing, is subject to liability under this chapter for the third partys failure to comply with this chapter.SEC. 2. Section 51 of the Civil Code, as amended by Section 2.5 of Chapter 779 of the Statutes of 2024, is amended to read:51. (a) This section shall be known, and may be cited, as the Unruh Civil Rights Act.(b) All persons within the jurisdiction of this state are free and equal, and no matter what their sex, race, color, religion, ancestry, national origin, disability, medical condition, genetic information, marital status, sexual orientation, citizenship, primary language, or immigration status are entitled to the full and equal accommodations, advantages, facilities, privileges, or services in all business establishments of every kind whatsoever.(c) This section shall not be construed to confer any right or privilege on a person that is conditioned or limited by law or that is applicable alike to persons of every sex, color, race, religion, ancestry, national origin, disability, medical condition, marital status, sexual orientation, citizenship, primary language, or immigration status, or to persons regardless of their genetic information.(d) Nothing in this section shall be construed to require any construction, alteration, repair, structural or otherwise, or modification of any sort whatsoever, beyond that construction, alteration, repair, or modification that is otherwise required by other provisions of law, to any new or existing establishment, facility, building, improvement, or any other structure, nor shall anything in this section be construed to augment, restrict, or alter in any way the authority of the State Architect to require construction, alteration, repair, or modifications that the State Architect otherwise possesses pursuant to other laws.(e) For purposes of this section:(1) Disability means any mental or physical disability as defined in Sections 12926 and 12926.1 of the Government Code.(2) (A) Genetic information means, with respect to any individual, information about any of the following:(i) The individuals genetic tests.(ii) The genetic tests of family members of the individual.(iii) The manifestation of a disease or disorder in family members of the individual.(B) Genetic information includes any request for, or receipt of, genetic services, or participation in clinical research that includes genetic services, by an individual or any family member of the individual.(C) Genetic information does not include information about the sex or age of any individual.(3) Medical condition has the same meaning as defined in subdivision (i) of Section 12926 of the Government Code.(4) Race is inclusive of traits associated with race, including, but not limited to, hair texture and protective hairstyles. Protective hairstyles includes, but is not limited to, such hairstyles as braids, locs, and twists.(5) Religion includes all aspects of religious belief, observance, and practice.(6) Sex includes, but is not limited to, pregnancy, childbirth, or medical conditions related to pregnancy or childbirth. Sex also includes, but is not limited to, a persons gender. Gender means sex, and includes a persons gender identity and gender expression. Gender expression means a persons gender-related appearance and behavior whether or not stereotypically associated with the persons assigned sex at birth.(7) Sex, race, color, religion, ancestry, national origin, disability, medical condition, genetic information, marital status, sexual orientation, citizenship, primary language, or immigration status includes any of the following:(A) Any combination of those characteristics.(B) A perception that the person has any particular characteristic or characteristics within the listed categories or any combination of those characteristics.(C) A perception that the person is associated with a person who has, or is perceived to have, any particular characteristic or characteristics, or any combination of characteristics, within the listed categories.(8) Sexual orientation has the same meaning as defined in subdivision (s) of Section 12926 of the Government Code.(f) A violation of the right of any individual under the federal Americans with Disabilities Act of 1990 (Public Law 101-336) shall also constitute a violation of this section.(g) Verification of immigration status and any discrimination based upon verified immigration status, where required by federal law, shall not constitute a violation of this section.(h) Nothing in this section shall be construed to require the provision of services or documents in a language other than English, beyond that which is otherwise required by other provisions of federal, state, or local law, including Section 1632.(i) In an action alleging a violation of this section in which the defendants development, modification, or use of an automated decision system, as defined in Section 22756 of the Business and Professions Code, is alleged to have committed caused or facilitated the violation, the extent to which the defendant complied with Chapter 25 (commencing with Section 22756) of Division 8 of the Business and Professions Code is relevant to, but not conclusive of, whether a the defendant violated this section.SEC. 3. Article 3 (commencing with Section 12959) is added to Chapter 6 of Part 2.8 of Division 3 of Title 2 of the Government Code, to read: Article 3. Automated Decision Systems12959. In an action alleging a violation of this chapter in which the defendants development, modification, or use of an automated decision system, as defined in Section 22756 of the Business and Professions Code, is alleged to have committed caused or facilitated the violation, the extent to which the defendant complied with Chapter 24.6 (commencing with Section 22756) of Division 8 of the Business and Professions Code is relevant to, but not conclusive of, whether a the defendant violated this chapter.SEC. 4. The Legislature finds and declares that Section 1 of this act, which adds Chapter 24.6 (commencing with Section 22756) to Division 8 of the Business and Professions Code, imposes a limitation on the publics right of access to the meetings of public bodies or the writings of public officials and agencies within the meaning of Section 3 of Article I of the California Constitution. Pursuant to that constitutional provision, the Legislature makes the following findings to demonstrate the interest protected by this limitation and the need for protecting that interest:In order to protect proprietary information, it is necessary that trade secrets disclosed in performance evaluations and impact assessments to agencies and departments pursuant to Section 1 of this act remain confidential.
22
3-Amended IN Assembly May 01, 2025 Amended IN Assembly April 10, 2025 CALIFORNIA LEGISLATURE 20252026 REGULAR SESSION Assembly Bill No. 1018Introduced by Assembly Member Bauer-Kahan(Coauthors: Assembly Members Aguiar-Curry, Bryan, Ortega, and Ward)February 20, 2025An act to add Chapter 24.6 (commencing with Section 22756) to Division 8 of the Business and Professions Code, to amend Section 51 of the Civil Code, and to add Article 3 (commencing with Section 12959) to Chapter 6 of Part 2.8 of Division 3 of Title 2 of the Government Code, relating to artificial intelligence.LEGISLATIVE COUNSEL'S DIGESTAB 1018, as amended, Bauer-Kahan. Automated decision systems.The California Fair Employment and Housing Act establishes the Civil Rights Department within the Business, Consumer Services, and Housing Agency and requires the department to, among other things, bring civil actions to enforce the act.Existing law requires, on or before September 1, 2024, the Department of Technology to conduct, in coordination with other interagency bodies as it deems appropriate, a comprehensive inventory of all high-risk automated decision systems that have been proposed for use, development, or procurement by, or are being used, developed, or procured by, any state agency.This bill would generally regulate the development and deployment of an automated decision system (ADS) used to make consequential decisions, as defined. The bill would define automated decision system to mean a computational process derived from machine learning, statistical modeling, data analytics, or artificial intelligence that issues simplified output, including a score, classification, or recommendation, that is designed or used to assist or replace human discretionary decisionmaking and materially impacts natural persons.This bill would require a developer of a covered ADS, as defined, to take certain actions, including conduct performance evaluations of the covered ADS and provide deployers to whom the developer transfers the covered ADS with certain information, including the results of those performance evaluations.This bill would, beginning January 1, 2027, require a deployer of a covered ADS to take certain actions, including provide certain disclosures to a subject of a consequential decision made or facilitated by the covered ADS, provide the subject an opportunity to opt out of the use of the covered ADS, provide the subject with an opportunity to appeal the outcome of the consequential decision, and submit the covered ADS to third-party audits, as prescribed. The bill would also prescribe requirements for a third party to audit a covered ADS.This bill would require a developer, deployer, or auditor to, within 30 days of receiving a request from the Attorney General, provide an unredacted copy of the performance evaluation or disparate impact assessment prepared pursuant to the bill to the Attorney General and would exempt those records from the California Public Records Act.This bill would authorize certain public entities, including the Attorney General, to bring a specified civil action for noncompliance.Existing constitutional provisions require that a statute that limits the right of access to the meetings of public bodies or the writings of public officials and agencies be adopted with findings demonstrating the interest protected by the limitation and the need for protecting that interest.This bill would make legislative findings to that effect.Digest Key Vote: MAJORITY Appropriation: NO Fiscal Committee: YES Local Program: NO
3+ Amended IN Assembly April 10, 2025 CALIFORNIA LEGISLATURE 20252026 REGULAR SESSION Assembly Bill No. 1018Introduced by Assembly Member Bauer-Kahan(Coauthors: Assembly Members Aguiar-Curry, Bryan, Ortega, Ward)February 20, 2025An act to add Chapter 24.6 (commencing with Section 22756) to Division 8 of the Business and Professions Code, to amend Section 51 of the Civil Code, and to add Article 3 (commencing with Section 12959) to Chapter 6 of Part 2.8 of Division 3 of Title 2 of the Government Code, relating to artificial intelligence.LEGISLATIVE COUNSEL'S DIGESTAB 1018, as amended, Bauer-Kahan. Automated decision systems.The California Fair Employment and Housing Act establishes the Civil Rights Department within the Business, Consumer Services, and Housing Agency and requires the department to, among other things, bring civil actions to enforce the act.Existing law requires, on or before September 1, 2024, the Department of Technology to conduct, in coordination with other interagency bodies as it deems appropriate, a comprehensive inventory of all high-risk automated decision systems that have been proposed for use, development, or procurement by, or are being used, developed, or procured by, any state agency.This bill would generally regulate the development and deployment of an automated decision system (ADS) used to make consequential decisions, as defined. The bill would define automated decision system to mean a computational process derived from machine learning, statistical modeling, data analytics, or artificial intelligence that issues simplified output, including a score, classification, or recommendation, that is designed or used to assist or replace human discretionary decisionmaking and materially impacts natural persons.This bill would require a developer of a covered ADS, as defined, to take certain actions, including conduct performance evaluations of the covered ADS and provide deployers to whom the developer transfers the covered ADS with certain information, including the results of those performance evaluations.This bill would, beginning January 1, 2027, require a deployer of a covered ADS to take certain actions, including provide certain disclosures to a subject of a consequential decision made or facilitated by the covered ADS, provide the subject an opportunity to opt out of the use of the covered ADS, provide the subject with an opportunity to appeal the outcome of the consequential decision, and submit the covered ADS to third-party audits, as prescribed. The bill would also prescribe requirements for a third party to audit a covered ADS.This bill would prescribe requirements for a third party to audit a covered ADS, as prescribed.This bill would require a developer, deployer, or auditor to, within 30 days of receiving a request from the Attorney General, provide an unredacted copy of the performance evaluation or disparate impact assessment prepared pursuant to the bill to the Attorney General and would exempt those records from the California Public Records Act.This bill would authorize certain public entities, including the Attorney General, to bring a specified civil action for noncompliance.Existing constitutional provisions require that a statute that limits the right of access to the meetings of public bodies or the writings of public officials and agencies be adopted with findings demonstrating the interest protected by the limitation and the need for protecting that interest.This bill would make legislative findings to that effect.Digest Key Vote: MAJORITY Appropriation: NO Fiscal Committee: YES Local Program: NO
44
5-Amended IN Assembly May 01, 2025 Amended IN Assembly April 10, 2025
6-
7-Amended IN Assembly May 01, 2025
85 Amended IN Assembly April 10, 2025
96
10-
7+Amended IN Assembly April 10, 2025
118
129 CALIFORNIA LEGISLATURE 20252026 REGULAR SESSION
1310
1411 Assembly Bill
1512
1613 No. 1018
1714
18-Introduced by Assembly Member Bauer-Kahan(Coauthors: Assembly Members Aguiar-Curry, Bryan, Ortega, and Ward)February 20, 2025
15+Introduced by Assembly Member Bauer-Kahan(Coauthors: Assembly Members Aguiar-Curry, Bryan, Ortega, Ward)February 20, 2025
1916
20-Introduced by Assembly Member Bauer-Kahan(Coauthors: Assembly Members Aguiar-Curry, Bryan, Ortega, and Ward)
17+Introduced by Assembly Member Bauer-Kahan(Coauthors: Assembly Members Aguiar-Curry, Bryan, Ortega, Ward)
2118 February 20, 2025
22-
23-
2419
2520 An act to add Chapter 24.6 (commencing with Section 22756) to Division 8 of the Business and Professions Code, to amend Section 51 of the Civil Code, and to add Article 3 (commencing with Section 12959) to Chapter 6 of Part 2.8 of Division 3 of Title 2 of the Government Code, relating to artificial intelligence.
2621
2722 LEGISLATIVE COUNSEL'S DIGEST
2823
2924 ## LEGISLATIVE COUNSEL'S DIGEST
3025
3126 AB 1018, as amended, Bauer-Kahan. Automated decision systems.
3227
33-The California Fair Employment and Housing Act establishes the Civil Rights Department within the Business, Consumer Services, and Housing Agency and requires the department to, among other things, bring civil actions to enforce the act.Existing law requires, on or before September 1, 2024, the Department of Technology to conduct, in coordination with other interagency bodies as it deems appropriate, a comprehensive inventory of all high-risk automated decision systems that have been proposed for use, development, or procurement by, or are being used, developed, or procured by, any state agency.This bill would generally regulate the development and deployment of an automated decision system (ADS) used to make consequential decisions, as defined. The bill would define automated decision system to mean a computational process derived from machine learning, statistical modeling, data analytics, or artificial intelligence that issues simplified output, including a score, classification, or recommendation, that is designed or used to assist or replace human discretionary decisionmaking and materially impacts natural persons.This bill would require a developer of a covered ADS, as defined, to take certain actions, including conduct performance evaluations of the covered ADS and provide deployers to whom the developer transfers the covered ADS with certain information, including the results of those performance evaluations.This bill would, beginning January 1, 2027, require a deployer of a covered ADS to take certain actions, including provide certain disclosures to a subject of a consequential decision made or facilitated by the covered ADS, provide the subject an opportunity to opt out of the use of the covered ADS, provide the subject with an opportunity to appeal the outcome of the consequential decision, and submit the covered ADS to third-party audits, as prescribed. The bill would also prescribe requirements for a third party to audit a covered ADS.This bill would require a developer, deployer, or auditor to, within 30 days of receiving a request from the Attorney General, provide an unredacted copy of the performance evaluation or disparate impact assessment prepared pursuant to the bill to the Attorney General and would exempt those records from the California Public Records Act.This bill would authorize certain public entities, including the Attorney General, to bring a specified civil action for noncompliance.Existing constitutional provisions require that a statute that limits the right of access to the meetings of public bodies or the writings of public officials and agencies be adopted with findings demonstrating the interest protected by the limitation and the need for protecting that interest.This bill would make legislative findings to that effect.
28+The California Fair Employment and Housing Act establishes the Civil Rights Department within the Business, Consumer Services, and Housing Agency and requires the department to, among other things, bring civil actions to enforce the act.Existing law requires, on or before September 1, 2024, the Department of Technology to conduct, in coordination with other interagency bodies as it deems appropriate, a comprehensive inventory of all high-risk automated decision systems that have been proposed for use, development, or procurement by, or are being used, developed, or procured by, any state agency.This bill would generally regulate the development and deployment of an automated decision system (ADS) used to make consequential decisions, as defined. The bill would define automated decision system to mean a computational process derived from machine learning, statistical modeling, data analytics, or artificial intelligence that issues simplified output, including a score, classification, or recommendation, that is designed or used to assist or replace human discretionary decisionmaking and materially impacts natural persons.This bill would require a developer of a covered ADS, as defined, to take certain actions, including conduct performance evaluations of the covered ADS and provide deployers to whom the developer transfers the covered ADS with certain information, including the results of those performance evaluations.This bill would, beginning January 1, 2027, require a deployer of a covered ADS to take certain actions, including provide certain disclosures to a subject of a consequential decision made or facilitated by the covered ADS, provide the subject an opportunity to opt out of the use of the covered ADS, provide the subject with an opportunity to appeal the outcome of the consequential decision, and submit the covered ADS to third-party audits, as prescribed. The bill would also prescribe requirements for a third party to audit a covered ADS.This bill would prescribe requirements for a third party to audit a covered ADS, as prescribed.This bill would require a developer, deployer, or auditor to, within 30 days of receiving a request from the Attorney General, provide an unredacted copy of the performance evaluation or disparate impact assessment prepared pursuant to the bill to the Attorney General and would exempt those records from the California Public Records Act.This bill would authorize certain public entities, including the Attorney General, to bring a specified civil action for noncompliance.Existing constitutional provisions require that a statute that limits the right of access to the meetings of public bodies or the writings of public officials and agencies be adopted with findings demonstrating the interest protected by the limitation and the need for protecting that interest.This bill would make legislative findings to that effect.
3429
3530 The California Fair Employment and Housing Act establishes the Civil Rights Department within the Business, Consumer Services, and Housing Agency and requires the department to, among other things, bring civil actions to enforce the act.
3631
3732 Existing law requires, on or before September 1, 2024, the Department of Technology to conduct, in coordination with other interagency bodies as it deems appropriate, a comprehensive inventory of all high-risk automated decision systems that have been proposed for use, development, or procurement by, or are being used, developed, or procured by, any state agency.
3833
3934 This bill would generally regulate the development and deployment of an automated decision system (ADS) used to make consequential decisions, as defined. The bill would define automated decision system to mean a computational process derived from machine learning, statistical modeling, data analytics, or artificial intelligence that issues simplified output, including a score, classification, or recommendation, that is designed or used to assist or replace human discretionary decisionmaking and materially impacts natural persons.
4035
4136 This bill would require a developer of a covered ADS, as defined, to take certain actions, including conduct performance evaluations of the covered ADS and provide deployers to whom the developer transfers the covered ADS with certain information, including the results of those performance evaluations.
4237
4338 This bill would, beginning January 1, 2027, require a deployer of a covered ADS to take certain actions, including provide certain disclosures to a subject of a consequential decision made or facilitated by the covered ADS, provide the subject an opportunity to opt out of the use of the covered ADS, provide the subject with an opportunity to appeal the outcome of the consequential decision, and submit the covered ADS to third-party audits, as prescribed. The bill would also prescribe requirements for a third party to audit a covered ADS.
39+
40+This bill would prescribe requirements for a third party to audit a covered ADS, as prescribed.
41+
42+
4443
4544 This bill would require a developer, deployer, or auditor to, within 30 days of receiving a request from the Attorney General, provide an unredacted copy of the performance evaluation or disparate impact assessment prepared pursuant to the bill to the Attorney General and would exempt those records from the California Public Records Act.
4645
4746 This bill would authorize certain public entities, including the Attorney General, to bring a specified civil action for noncompliance.
4847
4948 Existing constitutional provisions require that a statute that limits the right of access to the meetings of public bodies or the writings of public officials and agencies be adopted with findings demonstrating the interest protected by the limitation and the need for protecting that interest.
5049
5150 This bill would make legislative findings to that effect.
5251
5352 ## Digest Key
5453
5554 ## Bill Text
5655
57-The people of the State of California do enact as follows:SECTION 1. Chapter 24.6 (commencing with Section 22756) is added to Division 8 of the Business and Professions Code, to read: CHAPTER 24.6. Automated Decisions Safety Act22756. As used in this chapter:(a) Artificial intelligence means an engineered or machine-based system that varies in its level of autonomy and that can, for explicit or implicit objectives, infer from the input it receives how to generate outputs that can influence physical or virtual environments.(b) (1) Automated decision system means a computational process derived from machine learning, statistical modeling, data analytics, or artificial intelligence that issues simplified output, including a score, classification, or recommendation, that is designed or used to assist or replace human discretionary decisionmaking and materially impacts natural persons.(2) Automated decision system does not mean a spam email filter, firewall, antivirus software, identity and access management tool, calculator, database, dataset, or other compilation of data.(c) Consequential decision means a decision that materially impacts the cost, terms, quality, or accessibility of any of the following to a natural person:(1) Employment-related decisions.(2) Education and vocational training as they relate to any of the following:(A) Assessment and placement.(B) Detecting student cheating and plagiarism.(C) Accreditation.(D) Certification.(E) Admissions and enrollment.(F) Discipline.(G) Evaluation.(H) Financial aid and scholarships.(I) Proctoring.(3) Housing and lodging as they relate to any of the following:(A) Rental or short-term housing and lodging.(B) Home appraisals.(C) Rental subsidies.(D) Publicly supported housing.(4) Any of the following essential utilities:(A) Electricity.(B) Heat.(C) Water.(D) Transportation.(E) Municipal trash and sewage services.(5) Family planning, adoption services, reproductive services, and assessments related to child protective services.(6) Health care and health insurance, including mental health care, dental, and vision.(7) Financial services, including a financial service provided by a mortgage company, mortgage broker, or creditor.(8) The criminal justice system with respect to pretrial release, sentencing, and alternatives to incarceration.(9) Legal services.(10) Private arbitration.(11) Mediation.(12) Elections as they relate to any of the following:(A) Voting.(B) Redistricting.(C) Voter eligibility and registration.(D) Distribution of voting information.(E) Election administration.(13) Access to government benefits or services or assignment of penalties by a government entity.(14) Places of public accommodation, as defined in Section 55.52 of the Civil Code.(15) Insurance.(16) Internet and telecommunications access.(d) Covered automated decision system or covered ADS means an automated decision system that is designed or used to make or facilitate a consequential decision.(e) Credit score means a credit score, as defined in Section 1785.15.1 of the Civil Code, from a consumer credit reporting agency, as defined in Section 1785.3 of the Civil Code.(f) Deployer means a person, partnership, state or local government agency, corporation, or developer that uses a covered ADS to make or facilitate a consequential decision, either directly or by contracting with a third party for that purpose.(g) Developer means a person, partnership, state or local government agency, corporation, or deployer that designs, codes, substantially modifies, or otherwise produces an automated decision system that makes or facilitates a consequential decision, either directly or by contracting with a third party for those purposes.(h) (1) Developer-approved use means a deployment context in which a developer intends a covered ADS to make or facilitate a consequential decision.(2) Developer-approved use includes any reasonably foreseeable fine tuning of the covered ADS.(i) Disparate impact means a differential effect on a group of individuals who share a protected characteristic.(j) Disparate treatment means differential treatment of an individual or group of individuals on the basis of a protected characteristic.(k) Employment-related decision means a decision made by an employer, either directly or through a third party, that affects wages, benefits, other compensation, hours, work schedule, performance evaluation, hiring, discipline, promotion, termination, job tasks and responsibilities, assignment of work, access to work and training opportunities, productivity requirements, workplace health and safety, or other terms or conditions of employment.(l) (1) Express consent means an affirmative written authorization that is granted in response to a notice that is all of the following:(A) Clear, meaningful, and prominent.(B) Conveyed in a manner that a natural person would notice and understand it.(C) Not contained within a more general notice, agreement, or set of terms and conditions.(2) Express consent does not mean an authorization that is either of the following:(A) Inferred from inaction.(B) Obtained through the use of a dark pattern, as defined in Section 56.18 of the Civil Code.(m) Fine-tune means to adjust the model parameters of an automated decision system through exposure to additional data.(n) Labor Commissioner means Chief of the Division of Labor Standards Enforcement.(o) Personal information has the same meaning as defined in Section 1798.140 of the Civil Code.(p) Protected characteristic means a characteristic listed in subdivision (b) of Section 51 of the Civil Code.(q) (1) Substantial modification means a new version, release, update, or other modification to a covered ADS that materially changes its uses or outputs.(2) Substantial modification does not mean a modification that results from fine tuning.(r) Trade secret has the same meaning as in Section 3426.1 of the Civil Code.(s) The definitions of disparate impact and disparate treatment provided in subdivisions (i) and (j) are intended solely for purposes of internal compliance, risk assessment, and documentation required by this chapter. These definitions shall not be construed to modify or supersede any standard, burden of proof, or element of a claim under the Unruh Civil Rights Act (Section 51 of the Civil Code), the California Fair Employment and Housing Act (Part 2.8 (commencing with Section 12900) of Division 3 of Title 2 of the Government Code), Title VII of the Civil Rights Act of 1964 (42 U.S.C. Sec. 2000e et seq.), or any other applicable civil rights law.22756.1. (a) (1) With respect to a covered ADS that was first deployed, or made available to potential deployers, before January 1, 2026, the developer of the covered ADS shall conduct an initial performance evaluation on the covered ADS before January 1, 2027, and shall additionally conduct a performance evaluation on the covered ADS under any of the following circumstances:(A) Following any substantial modification of the covered ADS by the developer.(B) Following any fine tuning of the covered ADS by the developer that materially changes the uses or outputs of the covered ADS.(C) No more than one year after the developer last conducted a performance evaluation on the covered ADS, for as long as the developer deploys the covered ADS or makes the covered ADS available to potential deployers.(2) With respect to a covered ADS that is first deployed or made available to potential deployers on or after January 1, 2026, the developer of the covered ADS shall conduct a performance evaluation on the covered ADS under any of the following circumstances:(A) Before initially deploying the covered ADS or making the covered ADS available to potential deployers.(B) Following any substantial modification of the covered ADS by the developer.(C) Following any fine tuning of the covered ADS by the developer that materially changes the uses or outputs of the covered ADS.(D) No more than one year after the developer last conducted a performance evaluation on the covered ADS, for as long as the developer deploys the covered ADS or makes the covered ADS available to potential deployers.(b) In conducting a performance evaluation on a covered ADS, a developer shall do all of the following:(1) Describe the purpose of the covered ADS.(2) List and describe all developer-approved uses of the covered ADS.(3) For each developer-approved use, evaluate the expected performance of the covered ADS and document all of the following:(A) The expected accuracy and reliability of the covered ADS.(B) Any reasonably foreseeable effects of fine tuning on the accuracy and reliability of the covered ADS.(C) Whether any disparate treatment is intended to occur and, if so, all of the following:(i) The conditions under which each disparate treatment is intended to occur.(ii) Whether each disparate treatment is necessary for a developer-approved use.(iii) Whether any alternatives not involving disparate treatment were considered.(D) Any reasonably foreseeable effects of fine tuning on disparate treatment.(E) Whether any disparate impacts are reasonably likely to occur and, if so, all of the following:(i) The conditions under which each disparate impact is reasonably likely to occur.(ii) Whether each disparate impact is necessary for a developer-approved use.(iii) Whether any alternatives not involving disparate impacts were considered.(F) Whether any measures have been taken by the developer to mitigate the risk of unanticipated disparate impacts resulting from the use of the covered ADS.(G) With respect to a covered ADS that has been deployed, whether any unanticipated disparate impacts have been reported to the developer by a deployer, and whether the developer has taken any measures to mitigate those disparate impacts.(H) Any reasonably foreseeable effects of fine tuning on disparate impacts.(4) (A) Contract with an independent third-party auditor to assess the developers compliance with this subdivision.(B) (i) Except pursuant to clause (ii), a developer that contracts with an auditor pursuant to this paragraph shall provide the auditor with any available information that is reasonably necessary for the auditor to comprehensively assess developer compliance.(ii) A developer that provides documentation to an auditor pursuant to this subparagraph may make reasonable redactions for the purpose of protecting trade secrets. To the extent that a developer withholds information, the developer shall notify the auditor and provide a basis for the withholding.(C) If the deadline for conducting a performance evaluation pursuant to subdivision (a) elapses before the audit has been completed, a developer shall not deploy the covered ADS or make the covered ADS available to potential deployers until the audit has been completed.(I)(D) A developer that receives feedback from an auditor pursuant to this paragraph shall do both of the following:(i) Consider and attempt to incorporate that feedback into the development of any subsequent version of a covered ADS.(ii) Make a high-level summary of the feedback publicly available at no cost to users of the developers internet website.(c) (1) A developer that sells, licenses, or otherwise transfers a covered ADS to a potential deployer shall provide the deployer with all of the following:(A) The results of the most recent performance evaluation conducted on the covered ADS by the developer pursuant to this chapter.(B) For each developer-approved use of the covered ADS, instructions explaining how the covered ADS should be used by the deployer to make or facilitate a consequential decision.(C) For each developer-approved use of the covered ADS, a description of whether and under what circumstances the covered ADS can be fine-tuned.(D) An explanation of the deployers responsibilities under this chapter, including a description of any circumstances under which the deployer would assume the responsibilities of a developer pursuant to subdivision (h) of Section 22756.2.(E) (i) Any technical information necessary for the deployer to comply with this chapter.(ii) A developer shall not be required to provide additional technical information to a deployer that has assumed the responsibilities of a developer pursuant to subdivision (h) of Section 22756.2.(2) (A) A developer that provides documentation to a potential deployer pursuant to this subdivision may make reasonable redactions for the purpose of protecting trade secrets.(B) To the extent that a developer withholds information pursuant to subparagraph (A), the developer shall notify the deployer and provide a basis for the withholding.(d) A developer that receives an impact assessment from an auditor of a deployed covered ADS pursuant to subdivision (b) of Section 22756.3 shall provide all of the following information to any deployer of the covered ADS:(A)(1) Any material differences between the expected accuracy of the covered ADS and the observed accuracy of the covered ADS and the deployment conditions under which those differences are reasonably likely to occur.(B)(2) Any material differences between the expected reliability of the covered ADS and the observed reliability of the covered ADS and the deployment conditions under which those differences are reasonably likely to occur.(C)(3) Any unanticipated disparate impacts resulting from the use of the covered ADS and the deployment conditions under which those disparate impacts are reasonably likely to occur.(D)(4) An explanation of any steps the deployer can take to mitigate these discrepancies.(e) A developer that receives feedback from an auditor pursuant to this chapter shall consider and attempt to incorporate that feedback into the development of any subsequent version of a covered ADS.(f) A developer that provides documentation to a deployer pursuant to this section shall ensure the documentation is all of the following:(A)(1) Transmitted directly to the deployer or otherwise made available in a manner reasonably calculated to ensure the deployer receives the documentation.(B)(2) Provided in English and in any other language the developer regularly uses to communicate with deployers.(C)(3) Presented in a manner that ensures the communication clearly and effectively conveys the required information to the deployer.(g) A developer that deploys a covered ADS or makes a covered ADS available to potential deployers shall maintain all of the following documentation in an unredacted format for as long as the developer deploys the covered ADS or makes the covered ADS available to potential deployers plus 10 years:(1) The results of any performance evaluations conducted on the covered ADS pursuant to this chapter.(2) Any documentation provided to deployers pursuant to this chapter.(3) Any documentation provided to, or received from, auditors pursuant to this chapter.(4) Records of any redactions made pursuant to this chapter.(h) It is unlawful to advertise to consumers in the state that a covered ADS is capable of performing in a manner not substantiated by the results of the most recent performance evaluation conducted on the covered ADS.(i) (1) A developer that deploys a covered ADS or makes a covered ADS available to potential deployers shall designate at least one employee to oversee the developers compliance with this chapter.(2) A developer shall require an employee designated pursuant to this subdivision to conduct a prompt and comprehensive review of any credible compliance issue raised to that employee.22756.2. (a) (1) Except as provided in paragraph (2), before a deployer finalizes a consequential decision made or facilitated by a covered ADS, the deployer shall provide any subject of that decision with a plain language written disclosure containing all of the following information:(A) A statement informing the subject that a covered ADS will be used to make or facilitate the consequential decision.(B) The name, version number, and developer of the covered ADS.(C) Whether the deployers use of the covered ADS is within the scope of a developer-approved use and a description of that use.(D) (i) The personal characteristics or attributes of the subject that the covered ADS measures or assesses to make or facilitate the consequential decision.(ii) The sources of personal information collected from the subject to make or facilitate the consequential decision.(iii) Any key parameters known to disproportionately affect the outcome of the consequential decision.(E) The structure and format of the outputs of the covered ADS and a plain language description of how those outputs are used to make or facilitate the consequential decision.(F) Whether a natural person will review either of the following before the consequential decision is finalized:(i) The outputs of the covered ADS.(ii) The outcome of the consequential decision.(G) The subjects rights under subdivisions (b) and (d) and the means and timeframe for exercising those rights.(H) (i) Contact information for the deployer.(ii) Contact information for the entity that manages the covered ADS, if that entity is not the deployer.(iii) Contact information for the entity that will interpret the results of the covered ADS, if that entity is not the deployer.(2) Paragraph (1) does not apply if the subject of the consequential decision is having a medical emergency.(b) (1) Before a deployer finalizes a consequential decision made or facilitated by a covered ADS, the deployer shall provide any subject of that decision with a reasonable opportunity to opt out of the use of the covered ADS.(2) (A) A deployer may deny a request to opt out of the use of a covered ADS if either of the following is true:(i) The deployer is subject to the federal Gramm-Leach-Bliley Act, and the covered ADS makes or facilitates a consequential decision pursuant to paragraph (7) of subdivision (c) of Section 22756.(ii) The subject of the consequential decision is having a medical emergency.(B) A deployer that denies a request to opt out of the use of a covered ADS pursuant to subparagraph (A) shall provide the subject with an explanation of the basis for the denial.(c) (1) After a deployer finalizes a consequential decision made or facilitated by a covered ADS, the deployer shall provide any subject of that decision witha plain language written disclosure containing all of the following information within five days:(A) The personal characteristics or attributes of the subject that the covered ADS used to make or facilitate the consequential decision.(B) The sources of personal information collected from the subject that were used to make or facilitate the consequential decision.(C) Any key parameters that disproportionately affected the outcome of the consequential decision.(D) The structure and format of the outputs of the covered ADS and a plain language description of how those outputs were used to make or facilitate the consequential decision.(E) The role that the ADS played in making the consequential decision and whether any human judgment was involved.(F) Contact information for the deployer.(G) Contact information for the entity that manages the covered ADS, if that entity is not the deployer.(H) Contact information for the entity that will interpret the results of the covered ADS, if that entity is not the deployer.(I) The subjects rights under subdivision (d) and the means and timeframe for exercising those rights.(2) Paragraph (1) does not apply if the subject of the consequential decision is having a medical emergency.(3) A deployer that provides documentation to a subject of a consequential decision pursuant to this subdivision shall ensure the documentation is all of the following:(A) Transmitted directly to the subject.(B) Provided in English and in any other language that the deployer regularly uses to communicate with subjects.(C) Made available in formats that are accessible to people who are blind or have other disabilities.(D) Presented in a manner that ensures the communication clearly and effectively conveys the required information to the subject.(d) After a deployer finalizes a consequential decision made or facilitated by a covered ADS, the deployer shall provide any subject of that decision with an opportunity to do both of the following within 30 business days:(1) (A) Correct any incorrect personal information used by the covered ADS to make or facilitate the consequential decision.(B) A deployer shall comply with a request to correct personal information within 30 business days of receiving the request if the request is accompanied by documentation sufficient to assess the basis for the request.(C) (i) If a deployer determines that complying with a request to correct personal information would change the outcome of the consequential decision, the deployer shall, within 30 days of making the determination, rectify the decision.(ii) If a deployer determines that complying with a request to correct personal information would not change the outcome of the consequential decision, the deployer shall, within 30 days of making the determination, inform the subject that the correction was made but that it did not alter the decision.(D) A deployer that denies a request to correct personal information shall do both of the following:(i) Provide the subject with an explanation of the basis for the denial.(ii) Provide the subject with a reasonable opportunity to request that the deployer delete the subjects personal information.(2) (A) Appeal the outcome of the consequential decision.(B) A deployer shall review a request to appeal a consequential decision within 30 business days of receiving the request if the request is accompanied by documentation sufficient to assess the basis for the request.(C) (i) If a deployer determines that the original decision was incorrect, the deployer shall, within 30 days of making the determination, rectify the decision.(ii) If a deployer determines that the original decision was correct, the deployer shall, within 30 days of making the determination, inform the subject that the consequential decision will not be altered.(D) A deployer that denies a request to appeal the outcome of a consequential decision shall provide the subject with an explanation of the basis for the denial.(e) (1) (A) A deployer that provides documentation to the subject of a consequential decision pursuant to this section may make reasonable redactions for the purpose of protecting trade secrets.(B) To the extent that a deployer withholds information pursuant to paragraph (1), the deployer shall notify the subject and provide a basis for the withholding.(2) A deployer that is required by another state or federal law to provide substantially similar notice to a subject of a consequential decision need not duplicatively provide notice to the subject under this section.(f) A deployers collection, use, retention, and sharing of personal information from a subject of a consequential decision shall be reasonably necessary and proportionate to achieve the purposes for which the personal information was collected and processed, or for another disclosed purpose that is compatible with the context in which the personal information was collected, and not further processed in a manner that is incompatible with those purposes.(g) (1) A deployer that uses a covered ADS to make or facilitate consequential decisions directly impacting more than 5,999 people in a given three-year period shall contract with an independent third-party auditor to conduct an impact assessment on the covered ADS before January 1, 2030, and every three years thereafter.(2) (A) Except pursuant to subparagraph (B), a deployer that contracts with an auditor pursuant to this subdivision shall provide the auditor with any available information that is reasonably necessary for the auditor to conduct a comprehensive impact assessment on the covered ADS.(B) A deployer that provides documentation to an auditor pursuant to this paragraph may make reasonable redactions for the purpose of protecting trade secrets. To the extent that a deployer withholds information, the developer shall notify the auditor and provide a basis for the withholding.(C) This paragraph shall not be construed to require a deployer to collect any personal information from a subject of a consequential decision beyond that which the deployer collects in the ordinary course of business or as necessary to comply with state or federal law.(3) If the deadline for conducting an audit pursuant to paragraph (1) elapses before the audit has been completed, a deployer shall not use the covered ADS to make or facilitate consequential decisions until the audit has been completed.(h) A deployer that does any of the following assumes the responsibilities of a developer under this chapter:(1) Uses a covered ADS to make or facilitate consequential decisions that directly impact more than 5,999 people in a given three-year period, if the deployer did not receive any documentation from the developer of the covered ADS pursuant to subdivision (c) of Section 22756.1 during the three-year period.(2) Uses a covered ADS to make or facilitate consequential decisions that directly impact more than 5,999 people in a given three-year period, if the deployers use of the covered ADS is outside the scope of a developer-approved use.(3) Substantially modifies an automated decision system and does either of the following:(A) Uses the substantially modified system to make or facilitate consequential decisions that directly impact more than 5999 5,999 people in a given three-year period.(B) Makes the substantially modified system available to potential deployers.(i) A deployer that uses a covered ADS to make or facilitate a consequential decision shall retain the following documentation in an unredacted format for as long as the deployer uses the covered ADS plus 10 years:(1) Any documentation received from developers pursuant to this chapter.(2) Any documentation provided pursuant to this section to subjects of consequential decisions made or facilitated by the covered ADS.(3) Any requests to correct personal information made pursuant to this section.(4) Any requests to opt out of the use of the covered ADS made pursuant to this section.(5) Any requests to appeal the outcome of a consequential decision made pursuant to this section.(6) Any documentation provided to, or received from, auditors pursuant to this chapter.(7) Records of any redactions made pursuant to this section.(j) (1) A deployer that uses a covered ADS to make or facilitate a consequential decision shall designate at least one employee to oversee the deployers compliance with this chapter.(2) A deployer shall require an employee designated pursuant to this subdivision to conduct a prompt and comprehensive review of any credible compliance issue related to the deployers use of a covered ADS that is raised to that employee.(k) In addition to the requirements of this section, a deployer that is a business subject to the California Consumer Privacy Act of 2018 (Title 1.81.5 (commencing with Section 1798.100)) is subject to any privacy-related opt-out and access regulation duly adopted by the California Privacy Protection Agency pursuant to subdivision (b) of Section 1798.199.40 of the Civil Code.(l) This section shall become operative on January 1, 2027.22756.3. (a) An auditor that conducts an impact assessment on a covered ADS pursuant to subdivision (g) of Section 22756.2 shall do all of the following:(1) (A) Request any information from the deployer of the covered ADS that is reasonably necessary for the auditor to conduct a comprehensive impact assessment.(B) This paragraph applies only to information gathered by the deployer in the ordinary course of business.(2) For each unique developer-approved use of the covered ADS by the deployer, document all of the following:(A) The observed accuracy and reliability of the covered ADS over the relevant period.(B) Whether the observed accuracy and reliability differed materially from the expected accuracy and reliability of the covered ADS, as described in documentation provided by a developer to the deployer pursuant to this chapter.(C) Whether any disparate impacts resulted from the deployers use of the covered ADS and the deployment conditions under which those disparate impacts occurred.(D) Whether each disparate impact was an anticipated disparate impact, as described in documentation provided to the deployer pursuant to this chapter.(3) Whether the deployer used the covered ADS to make or facilitate a consequential decision outside of the scope of a developer-approved use.(4) Whether the deployer assumed the responsibilities of a developer pursuant to subdivision (h) of Section 22756.2.(b) (1) After conducting an impact assessment on a covered ADS, an auditor shall do both of the following:(A) Provide the results of the impact assessment to the deployer that contracted with the auditor to perform the impact assessment.(B) Make a high-level summary of the results of the impact assessment publicly available at no cost to users of the auditors internet website.(2) The documentation required by this section shall be both of the following:(A) Provided in English and in any other language that the auditor regularly uses to communicate with deployers.(B) Presented in a manner that ensures the communication clearly and effectively conveys the required information.(3) An auditor shall not make publicly available with the personal information of a subject of a consequential decision made or facilitated by a covered ADS without first obtaining the express consent of the subject.22756.4. (a) (1) Within 30 days of receiving a request from the Attorney General for a performance evaluation or impact assessment prepared pursuant to this chapter, a developer, deployer, or auditor of a covered ADS shall provide an unredacted copy of the document to the Attorney General.(2) The Attorney General may share performance evaluations and impact assessments with other enforcement entities as necessary for enforcement purposes.(b) (1) The disclosure or sharing of a performance evaluation or impact assessment pursuant to subdivision (a) does not constitute a waiver of any attorney-client privilege, work-product protection, or trade secret protection that might otherwise exist with respect to any information contained in the performance evaluation or impact assessment.(2) A performance evaluation or impact assessment disclosed or shared pursuant to subdivision (a) is exempt from the California Public Records Act (Division 10 (commencing with Section 7920.000) of Title 1 of the Government Code).(c) Each day a covered ADS is used for which a performance evaluation or impact assessment has not been submitted to the Attorney General pursuant to this section is an additional violation of this section.22756.5. (a) Any of the following public entities may bring a civil action against a developer, deployer, or auditor who violates this chapter:(1) The Attorney General.(2) A district attorney, county counsel, or city attorney for the jurisdiction in which the violation occurred.(3) A city prosecutor in any city having a full-time city prosecutor with the consent of the district attorney.(4) The Civil Rights Department.(5) The Labor Commissioner with respect to employment-related decisions only.(b) A court may award a prevailing plaintiff who brings an action pursuant to subdivision (a) all of the following:(1) Injunctive relief.(2) Declaratory relief.(3) Reasonable attorneys fees and litigation costs.(4) A civil penalty of up to twenty-five thousand dollars ($25,000) per violation.(c) A developer or deployer who contracts with a third party to perform the developers or deployers duties under this chapter, other than those duties related to auditing, is subject to liability under this chapter for the third partys failure to perform those duties.22756.6. (a) This chapter does not apply to an automated decision system the sole purpose of which is to do either of the following:(1) Detect, protect against, or respond to cybersecurity incidents or preserve the integrity or security of computer systems.(2) Operate aircraft in the national airspace.(b) The use of a consumer credit score to inform a consequential decision does not itself create an obligation under this chapter.22756.7. (a) The rights, remedies, and penalties established by this chapter are cumulative and shall not be construed to supersede the rights, remedies, or penalties established under other laws, including, but not limited to, Chapter 6 (commencing with Section 12940) of Part 2.8 of Division 3 of Title 2 of the Government Code and Section 51 of the Civil Code.(b) This chapter does not diminish the rights, privileges, or remedies of an employee under any other federal or state law or under any employment contract or collective bargaining agreement.(c) This chapter does not authorize any use of automated decision systems that is limited, restricted, or prohibited under any other applicable law.(d) This chapter does not authorize disparate impacts or disparate treatment limited, restricted, or prohibited under any other applicable law.SEC. 2. Section 51 of the Civil Code, as amended by Section 2.5 of Chapter 779 of the Statutes of 2024, is amended to read:51. (a) This section shall be known, and may be cited, as the Unruh Civil Rights Act.(b) All persons within the jurisdiction of this state are free and equal, and no matter what their sex, race, color, religion, ancestry, national origin, disability, medical condition, genetic information, marital status, sexual orientation, citizenship, primary language, or immigration status are entitled to the full and equal accommodations, advantages, facilities, privileges, or services in all business establishments of every kind whatsoever.(c) This section shall not be construed to confer any right or privilege on a person that is conditioned or limited by law or that is applicable alike to persons of every sex, color, race, religion, ancestry, national origin, disability, medical condition, marital status, sexual orientation, citizenship, primary language, or immigration status, or to persons regardless of their genetic information.(d) Nothing in this section shall be construed to require any construction, alteration, repair, structural or otherwise, or modification of any sort whatsoever, beyond that construction, alteration, repair, or modification that is otherwise required by other provisions of law, to any new or existing establishment, facility, building, improvement, or any other structure, nor shall anything in this section be construed to augment, restrict, or alter in any way the authority of the State Architect to require construction, alteration, repair, or modifications that the State Architect otherwise possesses pursuant to other laws.(e) For purposes of this section:(1) Disability means any mental or physical disability as defined in Sections 12926 and 12926.1 of the Government Code.(2) (A) Genetic information means, with respect to any individual, information about any of the following:(i) The individuals genetic tests.(ii) The genetic tests of family members of the individual.(iii) The manifestation of a disease or disorder in family members of the individual.(B) Genetic information includes any request for, or receipt of, genetic services, or participation in clinical research that includes genetic services, by an individual or any family member of the individual.(C) Genetic information does not include information about the sex or age of any individual.(3) Medical condition has the same meaning as defined in subdivision (i) of Section 12926 of the Government Code.(4) Race is inclusive of traits associated with race, including, but not limited to, hair texture and protective hairstyles. Protective hairstyles includes, but is not limited to, such hairstyles as braids, locs, and twists.(5) Religion includes all aspects of religious belief, observance, and practice.(6) Sex includes, but is not limited to, pregnancy, childbirth, or medical conditions related to pregnancy or childbirth. Sex also includes, but is not limited to, a persons gender. Gender means sex, and includes a persons gender identity and gender expression. Gender expression means a persons gender-related appearance and behavior whether or not stereotypically associated with the persons assigned sex at birth.(7) Sex, race, color, religion, ancestry, national origin, disability, medical condition, genetic information, marital status, sexual orientation, citizenship, primary language, or immigration status includes any of the following:(A) Any combination of those characteristics.(B) A perception that the person has any particular characteristic or characteristics within the listed categories or any combination of those characteristics.(C) A perception that the person is associated with a person who has, or is perceived to have, any particular characteristic or characteristics, or any combination of characteristics, within the listed categories.(8) Sexual orientation has the same meaning as defined in subdivision (s) of Section 12926 of the Government Code.(f) A violation of the right of any individual under the federal Americans with Disabilities Act of 1990 (Public Law 101-336) shall also constitute a violation of this section.(g) Verification of immigration status and any discrimination based upon verified immigration status, where required by federal law, shall not constitute a violation of this section.(h) Nothing in this section shall be construed to require the provision of services or documents in a language other than English, beyond that which is otherwise required by other provisions of federal, state, or local law, including Section 1632.(i) In an action alleging a violation of this section in which the defendants development, modification, or use of an automated decision system, as defined in Section 22756 of the Business and Professions Code, is alleged to have caused or facilitated the violation, the extent to which the defendant complied with Chapter 25 24.6 (commencing with Section 22756) of Division 8 of the Business and Professions Code is relevant to, but not conclusive of, whether the defendant violated this section. section, and a failure to comply with Chapter 24.6 (commencing with Section 22756) of Division 8 of the Business and Professions Code shall not, by itself, give rise to a presumption of unlawful intent.SEC. 3. Article 3 (commencing with Section 12959) is added to Chapter 6 of Part 2.8 of Division 3 of Title 2 of the Government Code, to read: Article 3. Automated Decision Systems12959. In an action alleging a violation of this chapter in which the defendants development, modification, or use of an automated decision system, as defined in Section 22756 of the Business and Professions Code, is alleged to have caused or facilitated the violation, the extent to which the defendant complied with Chapter 24.6 (commencing with Section 22756) of Division 8 of the Business and Professions Code is relevant to, but not conclusive of, whether the defendant violated this chapter.SEC. 4. The Legislature finds and declares that Section 1 of this act, which adds Chapter 24.6 (commencing with Section 22756) to Division 8 of the Business and Professions Code, imposes a limitation on the publics right of access to the meetings of public bodies or the writings of public officials and agencies within the meaning of Section 3 of Article I of the California Constitution. Pursuant to that constitutional provision, the Legislature makes the following findings to demonstrate the interest protected by this limitation and the need for protecting that interest:In order to protect proprietary information, it is necessary that trade secrets disclosed in performance evaluations and impact assessments to agencies and departments pursuant to Section 1 of this act remain confidential.
56+The people of the State of California do enact as follows:SECTION 1. Chapter 24.6 (commencing with Section 22756) is added to Division 8 of the Business and Professions Code, to read: CHAPTER 24.6. Automated Decisions Safety Act22756. As used in this chapter:(a) Artificial intelligence means an engineered or machine-based system that varies in its level of autonomy and that can, for explicit or implicit objectives, infer from the input it receives how to generate outputs that can influence physical or virtual environments.(b) (1) Automated decision system means a computational process derived from machine learning, statistical modeling, data analytics, or artificial intelligence that issues simplified output, including a score, classification, or recommendation, that is designed or used to assist or replace human discretionary decisionmaking and materially impacts natural persons.(2) Automated decision system does not mean a spam email filter, firewall, antivirus software, identity and access management tool, calculator, database, dataset, or other compilation of data.(c) Consequential decision means a decision that materially impacts the cost, terms, quality, or accessibility of any of the following to a natural person:(1) Employment-related decisions.(2) Education and vocational training as they relate to any of the following:(A) Assessment and placement.(B) Detecting student cheating and plagiarism.(C) Accreditation.(D) Certification.(E) Admissions and enrollment.(F) Discipline.(G) Evaluation.(H) Financial aid and scholarships.(I) Proctoring.(3) Housing and lodging as they relate to any of the following:(A) Rental or short-term housing and lodging.(B) Home appraisals.(C) Rental subsidies.(D) Publicly supported housing.(4) Any of the following essential utilities:(A) Electricity.(B) Heat.(C) Water.(D)Internet and telecommunications access.(E)(D) Transportation.(F)(E) Municipal trash and sewage services.(5) Family planning, adoption services, reproductive services, and assessments related to child protective services.(6) Health care and health insurance, including mental health care, dental, and vision.(7) Financial services, including a financial service provided by a mortgage company, mortgage broker, or creditor.(8) The criminal justice system with respect to pretrial release, sentencing, and alternatives to incarceration.(9) Legal services.(10) Private arbitration.(11) Mediation.(12) Elections as they relate to any of the following:(A) Voting.(B) Redistricting.(C) Voter eligibility and registration.(D) Distribution of voting information.(E) Election administration.(13) Access to government benefits or services or assignment of penalties by a government entity.(14) Places of public accommodation, as defined in Section 55.52 of the Civil Code.(15) Insurance.(16) Internet and telecommunications access.(d) Covered automated decision system or covered ADS means an automated decision system that makes or facilitates is designed or used to make or facilitate a consequential decision.(e) Credit score means a credit score, as defined in Section 1785.15.1 of the Civil Code, from a consumer credit reporting agency, as defined in Section 1785.3 of the Civil Code.(e)(f) Deployer means a person, partnership, state or local government agency, corporation, or developer that uses a covered ADS to make or facilitate a consequential decision, either directly or through by contracting with a third party. party for that purpose.(f)(g) Developer means a person, partnership, state or local government agency, corporation, or deployer that designs, codes, substantially modifies, or otherwise produces an automated decision system that makes or facilitates a consequential decision, either directly or through by contracting with a third party. party for those purposes.(g)(h) (1) Developer-approved use means a deployment context in which a developer intends a covered ADS to make or facilitate a consequential decision.(2) Developer-approved use includes any reasonably foreseeable fine tuning of the covered ADS.(h)(i) Disparate impact means a differential effect on a group of individuals who share a protected characteristic.(i)(j) Disparate treatment means differential treatment of an individual or group of individuals on the basis of a protected characteristic.(j)(k) Employment-related decision means a decision made by an employer, either directly or through a third party, that affects wages, benefits, other compensation, hours, work schedule, performance evaluation, hiring, discipline, promotion, termination, job tasks and responsibilities, assignment of work, access to work and training opportunities, productivity requirements, workplace health and safety, or other terms or conditions of employment.(k)(l) (1) Express consent means an affirmative written authorization that is granted in response to a notice that is all of the following:(A) Clear, meaningful, and prominent.(B) Conveyed in a manner that a natural person would notice and understand it.(C) Not contained within a more general notice, agreement, or set of terms and conditions.(2) Express consent does not mean an authorization that is either of the following:(A) Inferred from inaction.(B) Obtained through the use of a dark pattern, as defined in Section 56.18 of the Civil Code.(l)(m) Fine-tune means to adjust the model parameters of an automated decision system through exposure to additional data.(m)(n) Labor Commissioner means Chief of the Division of Labor Standards Enforcement.(n)(o) Personal information has the same meaning as defined in Section 1798.140 of the Civil Code.(o)(p) Protected characteristic means a characteristic listed in subdivision (b) of Section 51 of the Civil Code.(p)(q) (1) Substantial modification means a new version, release, update, or other modification to a covered ADS that materially changes its uses or outputs.(2) Substantial modification does not mean a modification that results from fine tuning.(q)(r) Trade secret has the same meaning as in Section 3426.1 of the Civil Code.22756.1. (a) (1) With respect to a covered ADS that was first deployed, or made available to potential deployers, before January 1, 2026, the developer of the covered ADS shall conduct an initial performance evaluation on the covered ADS before January 1, 2027, and shall additionally conduct a performance evaluation on the covered ADS under any of the following circumstances:(A) Following any substantial modification of the covered ADS by the developer.(B) Following any fine tuning of the covered ADS by the developer that materially changes the uses or outputs of the covered ADS.(C) No more than one year after the developer last conducted a performance evaluation on the covered ADS, for as long as the developer deploys the covered ADS or makes the covered ADS available to potential deployers.(2) With respect to a covered ADS that is first deployed or made available to potential deployers on or after January 1, 2026, the developer of the covered ADS shall conduct a performance evaluation on the covered ADS under any of the following circumstances:(A) Before initially deploying the covered ADS or making the covered ADS available to potential deployers.(B) Following any substantial modification of the covered ADS by the developer.(C) Following any fine tuning of the covered ADS by the developer that materially changes the uses or outputs of the covered ADS.(D) No more than one year after the developer last conducted a performance evaluation on the covered ADS, for as long as the developer deploys the covered ADS or makes the covered ADS available to potential deployers.(b) In conducting a performance evaluation on a covered ADS, a developer shall do all of the following:(1) Describe the purpose of the covered ADS.(2) List and describe all developer-approved uses of the covered ADS.(3) For each developer-approved use, assess evaluate the expected performance of the covered ADS and document all of the following:(A) The expected accuracy and reliability of the covered ADS.(B) Any reasonably foreseeable effects of fine tuning on the accuracy and reliability of the covered ADS.(4)For each developer-approved use, assess whether(C) Whether any disparate treatment is intended to occur and document and, if so, all of the following:(A)Whether the covered ADS is intended to treat individuals or groups of individuals differently on the basis of a protected characteristic.(B)For each disparate treatment identified under subparagraph (A), describe all of the following:(i) The conditions under which the each disparate treatment is intended to occur.(ii) Whether the each disparate treatment is necessary for a developer-approved use.(iii) Whether any alternatives not involving disparate treatment were considered.(C)(D) Any reasonably foreseeable effects of fine tuning on disparate treatment.(5)For each developer-approved use, assess whether (E) Whether any disparate impacts are reasonably likely to occur and document and, if so, all of the following:(A)Whether the covered ADS is reasonably likely to treat groups of individuals who share a protected characteristic differently.(B)For each disparate impact identified under subparagraph (A), describe all of the following:(i) The conditions under which that each disparate impact is reasonably likely to occur.(ii) Whether the each disparate impact is necessary for a developer-approved use.(iii) Whether any alternatives not involving disparate impacts were considered.(C)(F) Whether any measures have been taken by the developer to mitigate the risk of unanticipated disparate impacts resulting from the use of the covered ADS.(D)(G) With respect to a covered ADS that has been deployed, whether any unanticipated disparate impacts have been reported to the developer by a deployer, and whether the developer has taken any measures to mitigate those disparate impacts.(E)(H) Any reasonably foreseeable effects of fine tuning on disparate impacts.(6)(4) (A) Contract with an independent third-party auditor to assess the developers compliance with this subdivision.(B) (i) Except pursuant to clause (ii), a developer that contracts with an auditor pursuant to this paragraph shall provide the auditor with any available information that is reasonably necessary for the auditor to comprehensively assess developer compliance.(ii) A developer that provides documentation to an auditor pursuant to this subparagraph may make reasonable redactions for the purpose of protecting trade secrets. To the extent that a developer withholds information, the developer shall notify the auditor and provide a basis for the withholding.(C) If the deadline for conducting a performance evaluation pursuant to subdivision (a) elapses before the audit has been completed, a developer shall not deploy the covered ADS or make the covered ADS available to potential deployers until the audit has been completed.(I) A developer that receives feedback from an auditor pursuant to this paragraph shall do both of the following:(i) Consider and attempt to incorporate that feedback into the development of any subsequent version of a covered ADS.(ii) Make a high-level summary of the feedback publicly available at no cost to users of the developers internet website.(c) (1) A developer that sells, licenses, or otherwise transfers a covered ADS to a potential deployer shall provide the deployer with all of the following:(A) The results of the most recent performance evaluation conducted on the covered ADS by the developer pursuant to this chapter.(B) For each developer-approved use of the covered ADS, instructions explaining how the covered ADS should be used by the deployer to make or facilitate a consequential decision.(C) For each developer-approved use of the covered ADS, a description of whether and under what circumstances the covered ADS can be fine-tuned.(D) An explanation of the deployers responsibilities under this chapter, including a description of any circumstances under which the deployer would assume the responsibilities of a developer pursuant to subdivision (h) of Section 22756.2.(E) (i) Any technical information necessary for the deployer to comply with this chapter.(ii) A developer shall not be required to provide additional technical information to a deployer that has assumed the responsibilities of a developer pursuant to subdivision (h) of Section 22756.2.(2) (A) A developer that provides documentation to a potential deployer pursuant to this subdivision may make reasonable redactions for the purpose of protecting trade secrets.(B) To the extent that a developer withholds information pursuant to subparagraph (A), the developer shall notify the deployer and provide a basis for the withholding.(d) A developer that receives an impact assessment from an auditor of a deployed covered ADS pursuant to subdivision (b) of Section 22756.3 shall provide all of the following information to any deployer of the covered ADS:(A) Any material differences between the expected accuracy of the covered ADS and the observed accuracy of the covered ADS and the deployment conditions under which those differences are reasonably likely to occur.(B) Any material differences between the expected reliability of the covered ADS and the observed reliability of the covered ADS and the deployment conditions under which those differences are reasonably likely to occur.(C) Any unanticipated disparate impacts resulting from the use of the covered ADS and the deployment conditions under which those disparate impacts are reasonably likely to occur.(D) An explanation of any steps the deployer can take to mitigate these discrepancies.(e) A developer that receives feedback from an auditor pursuant to this chapter shall consider and attempt to incorporate that feedback into the development of any subsequent version of a covered ADS.(f) A developer that provides documentation to a deployer pursuant to this section shall ensure the documentation is all of the following:(A) Transmitted directly to the deployer or otherwise made available in a manner reasonably calculated to ensure the deployer receives the documentation.(B) Provided in English and in any other language the developer regularly uses to communicate with deployers.(C) Presented in a manner that ensures the communication clearly and effectively conveys the required information to the deployer.(g) A developer that deploys a covered ADS or makes a covered ADS available to potential deployers shall maintain all of the following documentation in an unredacted format for as long as the covered ADS remains deployed or developer deploys the covered ADS or makes the covered ADS available to potential deployers plus 10 years:(1) The results of any performance evaluations conducted on the covered ADS pursuant to this chapter.(2) Any documentation provided to deployers pursuant to this chapter.(3) Any documentation provided to, or received from, auditors pursuant to this chapter.(4) Records of any redactions made pursuant to this chapter.(h) It is unlawful to advertise to consumers in the state that a covered ADS is capable of performing in a manner not substantiated by the results of the most recent performance evaluation conducted on the covered ADS.(i) (1) A developer that deploys a covered ADS or makes a covered ADS available to potential deployers shall designate at least one employee to oversee the developers compliance with this chapter.(2) A developer shall require an employee designated pursuant to this subdivision to conduct a prompt and comprehensive review of any credible compliance issue raised to that employee.22756.2. (a) (1) Except as provided in paragraph (2), before finalizing a deployer finalizes a consequential decision made or facilitated by a covered ADS, a the deployer shall provide any subject of that decision with a plain language written disclosure containing all of the following information:(A) A statement informing the subject that a covered ADS will be used to make or facilitate the consequential decision.(B) The name, version number, and developer of the covered ADS.(C) Whether the deployers use of the covered ADS is within the scope of a developer-approved use and a description of that use.(D) (i) The personal characteristics or attributes of the subject that the covered ADS measures or assesses to make or facilitate the consequential decision.(ii) The sources of personal information collected from the subject to make or facilitate the consequential decision.(iii) Any key parameters known to disproportionately affect the outcome of the consequential decision.(E) The structure and format of the outputs of the covered ADS and a plain language description of how those outputs are used to make or facilitate the consequential decision.(F) Whether a natural person will review either of the following before the consequential decision is finalized:(i) The outputs of the covered ADS.(ii) The outcome of the consequential decision.(G) The subjects rights under subdivisions (b) and (c) (d) and the means and timeframe for exercising those rights.(H) (i) Contact information for the deployer.(ii) Contact information for the entity that manages the covered ADS, if that entity is not the deployer.(iii) Contact information for the entity that will interpret the results of the covered ADS, if that entity is not the deployer.(2) Paragraph (1) does not apply if the subject of the consequential decision is having a medical emergency.(b) (1) Before finalizing a deployer finalizes a consequential decision made or facilitated by a covered ADS, a the deployer shall provide any subject of that decision with a reasonable opportunity to opt out of the use of the covered ADS.(2) (A) A deployer may deny a request to opt out of the use of a covered ADS if either of the following is true:(i) The deployer is subject to the federal Gramm-Leach-Bliley Act, and the covered ADS makes or facilitates a consequential decision pursuant to paragraph (7) of subdivision (c) of Section 22756.(ii) The subject of the consequential decision is having a medical emergency.(B) A deployer that denies a request to opt out of the use of a covered ADS pursuant to subparagraph (A) shall provide the subject with an explanation of the basis for the denial.(c) (1) After a deployer finalizes a consequential decision is finalized, made or facilitated by a covered ADS, the deployer shall provide any subject of that decision witha plain language written disclosure shall be provided containing all of the following information within five days, and the disclosure shall include all of the information: days:(A) The personal characteristics or attributes of the subject that the covered ADS measured or assessed used to make or facilitate the consequential decision.(B) The sources of personal information collected from the subject that were used to make or facilitate the consequential decision.(C) Any key parameters that disproportionately affected the outcome of the consequential decision.(D) The structure and format of the outputs of the covered ADS and a plain language description of how those outputs were used to make or facilitate the consequential decision.(E) The role that the ADS played in making the consequential decision and whether any human judgment was involved.(F) Contact information for the deployer.(G) Contact information for the entity that manages the covered ADS, if that entity is not the deployer.(H) Contact information for the entity that will interpret the results of the covered ADS, if that entity is not the deployer.(I) The subjects rights under subdivision (d) and the means and timeframe for exercising those rights.(2) Paragraph (1) is does not applicable apply if the subject of the consequential decision is having a medical emergency.(3) A deployer that provides documentation to a subject of a consequential decision pursuant to this subdivision shall ensure the documentation is all of the following:(A) Transmitted directly to the subject.(B) Provided in English and in any other language that the deployer regularly uses to communicate with subjects.(C) Made available in formats that are accessible to people who are blind or have other disabilities.(D) Presented in a manner that ensures the communication clearly and effectively conveys the required information to the subject.(d) After finalizing a deployer finalizes a consequential decision made or facilitated by a covered ADS, a the deployer shall provide any subject of that decision with an opportunity to do both of the following within 30 business days:(1) (A) Correct any incorrect personal information used by the covered ADS to make or facilitate the consequential decision.(B) A deployer shall comply with a request to correct personal information within 30 business days of receiving the request if the request is accompanied by documentation sufficient to assess the basis for the request.(C) (i) If a deployer determines that complying with a request to correct personal information would change the outcome of the consequential decision, the deployer shall, within 30 days of making the determination, rectify the decision.(ii) If a deployer determines that complying with a request to correct personal information would not change the outcome of the consequential decision, the deployer shall, within 30 days of making the determination, inform the subject that the correction was made but that it did not alter the decision.(D) A deployer that denies a request to correct personal information shall do both of the following:(i) Provide the subject with an explanation of the basis for the denial.(ii) Provide the subject with a reasonable opportunity to request that the deployer delete the subjects personal information.(2) (A) Appeal the outcome of the consequential decision.(B) A deployer shall review a request to appeal a consequential decision within 30 business days of receiving the request. request if the request is accompanied by documentation sufficient to assess the basis for the request.(C) (i) If a deployer determines that the original decision is was incorrect, the deployer shall, within 30 days of making the determination, rectify the decision.(ii) If a deployer determines that the original decision is was correct, the deployer shall, within 30 days of making the determination, inform the subject that the consequential decision will not be altered.(D) A deployer that denies a request to appeal the outcome of a consequential decision shall provide the subject with an explanation of the basis for the denial.(e) (1) (A) A deployer that provides documentation to the subject of a consequential decision pursuant to this section may make reasonable redactions for the purpose of protecting trade secrets.(B) To the extent that a deployer withholds information pursuant to paragraph (1), the deployer shall notify the subject and provide a basis for the withholding.(2) A deployer that is required by another state or federal law to provide substantially similar notice to a subject of a consequential decision need not duplicatively provide notice to the subject under this section.(f) A deployers collection, use, retention, and sharing of personal information from a subject of a consequential decision shall be reasonably necessary and proportionate to achieve the purposes for which the personal information was collected and processed, or for another disclosed purpose that is compatible with the context in which the personal information was collected, and not further processed in a manner that is incompatible with those purposes.(g) (1) A deployer that uses a covered ADS to make or facilitate consequential decisions directly impacting more than 5999 5,999 people in a given three-year period shall contract with an independent third-party auditor to conduct an impact assessment on the covered ADS before January 1, 2030, and every three years thereafter.(2) (A) Except pursuant to subparagraph (B), a deployer that contracts with an auditor pursuant to this subdivision shall provide the auditor with any available information that is reasonably necessary for the auditor to conduct a comprehensive impact assessment on the covered ADS.(B) A deployer that provides documentation to an auditor pursuant to this paragraph may make reasonable redactions for the purpose of protecting trade secrets. To the extent that a deployer withholds information, the developer shall notify the auditor and provide a basis for the withholding.(C) This paragraph shall not be construed to require a deployer to collect any personal information from a subject of a consequential decision beyond that which the deployer collects in the ordinary course of business or as necessary to comply with state or federal law.(3) If the deadline for conducting an audit pursuant to paragraph (1) elapses before the audit has been completed, a deployer shall not use the covered ADS to make or facilitate consequential decisions until the audit has been completed.(h) A deployer that does any of the following assumes the responsibilities of a developer under this chapter:(1) Uses a covered ADS to make or facilitate consequential decisions that directly impact more than 5999 5,999 people in a given three-year period, if the deployer did not receive any documentation from the developer of the covered ADS pursuant to subdivision (c) of Section 22756.1. 22756.1 during the three-year period.(2) Uses a covered ADS to make or facilitate consequential decisions that directly impact more than 5999 5,999 people in a given three-year period, if the deployers use of the covered ADS is outside the scope of a developer-approved use.(3) Substantially modifies an automated decision system and does either of the following:(A) Uses the substantially modified system to make or facilitate consequential decisions that directly impact more than 5999 people in a given three-year period.(B) Makes the substantially modified system available to potential deployers.(i) A deployer that uses a covered ADS to make or facilitate a consequential decision shall retain the following documentation in an unredacted format for as long as the deployer uses the covered ADS remains deployed plus 10 years:(1) Any documentation received from developers pursuant to this chapter.(2) Any documentation provided pursuant to this section to subjects of consequential decisions made or facilitated by the covered ADS.(3) Any requests to correct personal information made pursuant to this section.(4) Any requests to opt out of the use of the covered ADS made pursuant to this section.(5) Any requests to appeal the outcome of a consequential decision made pursuant to this section.(6) Any documentation provided to, or received from, auditors pursuant to this chapter.(7) Records of any redactions made pursuant to this section.(j) (1) A deployer that uses a covered ADS to make or facilitate a consequential decision shall designate at least one employee to oversee the deployers compliance with this chapter.(2) A deployer shall require an employee designated pursuant to this subdivision to conduct a prompt and comprehensive review of any credible compliance issue related to the deployers use of a covered ADS that is raised to that employee.(k) In addition to the requirements of this section, a deployer that is a business subject to the California Consumer Privacy Act of 2018 (Title 1.81.5 (commencing with Section 1798.100)) is subject to any privacy-related opt-out and access regulation duly adopted by the California Privacy Protection Agency pursuant to subdivision (b) of Section 1798.199.40 of the Civil Code.(l) This section shall become operative on January 1, 2027.22756.3. (a) An auditor that conducts an impact assessment on a covered ADS pursuant to subdivision (g) of Section 22756.2 shall do all of the following:(1) (A) Request any information from the deployer of the covered ADS that is reasonably necessary for the auditor to conduct a comprehensive impact assessment.(B) This paragraph applies only to information gathered by the deployer in the ordinary course of business.(2)Document all developer-approved uses of the covered ADS that the deployer utilized during the relevant period.(3)(2) For each unique developer-approved use, use of the covered ADS by the deployer, document all of the following:(A) The observed accuracy and reliability of the covered ADS over the relevant period.(B) Whether the observed accuracy and reliability differed materially from the expected accuracy and reliability of the covered ADS, as described in documentation provided by a developer to the deployer pursuant to this chapter.(C) Whether any disparate impacts resulted from the deployers use of the covered ADS and the deployment conditions under which those disparate impacts occurred.(D) Whether each disparate impact was an anticipated disparate impact, as described in documentation provided to the deployer pursuant to this chapter.(4)(3) Whether the deployer used the covered ADS to make or facilitate a consequential decision outside of the scope of a developer-approved use.(5)(4) Whether the deployer assumed the responsibilities of a developer pursuant to subdivision (h) of Section 22756.2.(b) (1) After conducting an impact assessment on a covered ADS, an auditor shall provide the results of the impact assessment to do both of the following:(A) The Provide the results of the impact assessment to the deployer that contracted with the auditor to perform the impact assessment.(B)The developer of the covered ADS.(B) Make a high-level summary of the results of the impact assessment publicly available at no cost to users of the auditors internet website.(2) The documentation required by this section shall be both of the following:(A) Provided in English and in any other language that the auditor regularly uses to communicate with developers and deployers.(B) Presented in a manner that ensures the communication clearly and effectively conveys the required information to the developer and deployer. information.(3) An auditor shall not provide a developer make publicly available with the personal information of a subject of a consequential decision made or facilitated by a covered ADS without first obtaining the express consent of the subject.22756.4. (a) (1) Within 30 days of receiving a request from the Attorney General for a performance evaluation or impact assessment prepared pursuant to this chapter, a developer, deployer, or auditor of a covered ADS shall provide an unredacted copy of the document to the Attorney General.(2) The Attorney General may share performance evaluations and impact assessments with other enforcement entities as necessary for enforcement purposes.(b) (1) The disclosure or sharing of a performance evaluation or impact assessment pursuant to subdivision (a) does not constitute a waiver of any attorney-client privilege, work-product protection, or trade secret protection that might otherwise exist with respect to any information contained in the performance evaluation or impact assessment.(2) A performance evaluation or impact assessment disclosed or shared pursuant to subdivision (a) is exempt from the California Public Records Act (Division 10 (commencing with Section 7920.000) of Title 1 of the Government Code).(c) Each day a covered ADS is used for which a performance evaluation or impact assessment has not been submitted to the Attorney General pursuant to this section is an additional violation of this section.22756.5. (a) Any of the following public entities may bring a civil action against a developer or deployer developer, deployer, or auditor who violates this chapter:(1) The Attorney General.(2) A district attorney, county counsel, or city attorney for the jurisdiction in which the violation occurred.(3) A city prosecutor in any city having a full-time city prosecutor with the consent of the district attorney.(4) The Civil Rights Department.(5) The Labor Commissioner with respect to employment-related decisions only.(b) A court may award a prevailing plaintiff who brings an action pursuant to subdivision (a) all of the following:(1) Injunctive relief.(2) Declaratory relief.(3) Reasonable attorneys fees and litigation costs.(4) A civil penalty of up to twenty-five thousand dollars ($25,000) per violation.(c) A developer or deployer who contracts with a third party to perform the developers or deployers duties under this chapter, other than those duties related to auditing, is subject to liability under this chapter for the third partys failure to perform those duties.22756.6. (a) This chapter does not apply to an automated decision system the sole purpose of which is to do either of the following:(a)(1) Detect, protect against, or respond to cybersecurity incidents or preserve the integrity or security of computer systems.(b)(2) Operate aircraft in the national airspace.(b) The use of a consumer credit score to inform a consequential decision does not itself create an obligation under this chapter.22756.7. (a) The rights, remedies, and penalties established by this chapter are cumulative and shall not be construed to supersede the rights, remedies, or penalties established under other laws, including, but not limited to, Chapter 6 (commencing with Section 12940) of Part 2.8 of Division 3 of Title 2 of the Government Code and Section 51 of the Civil Code.(b) This chapter does not diminish the rights, privileges, or remedies of an employee under any other federal or state law or under any employment contract or collective bargaining agreement.(c) This chapter does not authorize any use of automated decision systems that is limited, restricted, or prohibited under any other applicable law.(d) This chapter does not authorize disparate impacts or disparate treatment that are limited, restricted, or prohibited under any other applicable law.22756.8.A developer or deployer who contracts with a third party to comply with duties required under this chapter, other than those duties related to auditing, is subject to liability under this chapter for the third partys failure to comply with this chapter.SEC. 2. Section 51 of the Civil Code, as amended by Section 2.5 of Chapter 779 of the Statutes of 2024, is amended to read:51. (a) This section shall be known, and may be cited, as the Unruh Civil Rights Act.(b) All persons within the jurisdiction of this state are free and equal, and no matter what their sex, race, color, religion, ancestry, national origin, disability, medical condition, genetic information, marital status, sexual orientation, citizenship, primary language, or immigration status are entitled to the full and equal accommodations, advantages, facilities, privileges, or services in all business establishments of every kind whatsoever.(c) This section shall not be construed to confer any right or privilege on a person that is conditioned or limited by law or that is applicable alike to persons of every sex, color, race, religion, ancestry, national origin, disability, medical condition, marital status, sexual orientation, citizenship, primary language, or immigration status, or to persons regardless of their genetic information.(d) Nothing in this section shall be construed to require any construction, alteration, repair, structural or otherwise, or modification of any sort whatsoever, beyond that construction, alteration, repair, or modification that is otherwise required by other provisions of law, to any new or existing establishment, facility, building, improvement, or any other structure, nor shall anything in this section be construed to augment, restrict, or alter in any way the authority of the State Architect to require construction, alteration, repair, or modifications that the State Architect otherwise possesses pursuant to other laws.(e) For purposes of this section:(1) Disability means any mental or physical disability as defined in Sections 12926 and 12926.1 of the Government Code.(2) (A) Genetic information means, with respect to any individual, information about any of the following:(i) The individuals genetic tests.(ii) The genetic tests of family members of the individual.(iii) The manifestation of a disease or disorder in family members of the individual.(B) Genetic information includes any request for, or receipt of, genetic services, or participation in clinical research that includes genetic services, by an individual or any family member of the individual.(C) Genetic information does not include information about the sex or age of any individual.(3) Medical condition has the same meaning as defined in subdivision (i) of Section 12926 of the Government Code.(4) Race is inclusive of traits associated with race, including, but not limited to, hair texture and protective hairstyles. Protective hairstyles includes, but is not limited to, such hairstyles as braids, locs, and twists.(5) Religion includes all aspects of religious belief, observance, and practice.(6) Sex includes, but is not limited to, pregnancy, childbirth, or medical conditions related to pregnancy or childbirth. Sex also includes, but is not limited to, a persons gender. Gender means sex, and includes a persons gender identity and gender expression. Gender expression means a persons gender-related appearance and behavior whether or not stereotypically associated with the persons assigned sex at birth.(7) Sex, race, color, religion, ancestry, national origin, disability, medical condition, genetic information, marital status, sexual orientation, citizenship, primary language, or immigration status includes any of the following:(A) Any combination of those characteristics.(B) A perception that the person has any particular characteristic or characteristics within the listed categories or any combination of those characteristics.(C) A perception that the person is associated with a person who has, or is perceived to have, any particular characteristic or characteristics, or any combination of characteristics, within the listed categories.(8) Sexual orientation has the same meaning as defined in subdivision (s) of Section 12926 of the Government Code.(f) A violation of the right of any individual under the federal Americans with Disabilities Act of 1990 (Public Law 101-336) shall also constitute a violation of this section.(g) Verification of immigration status and any discrimination based upon verified immigration status, where required by federal law, shall not constitute a violation of this section.(h) Nothing in this section shall be construed to require the provision of services or documents in a language other than English, beyond that which is otherwise required by other provisions of federal, state, or local law, including Section 1632.(i) In an action alleging a violation of this section in which the defendants development, modification, or use of an automated decision system, as defined in Section 22756 of the Business and Professions Code, is alleged to have committed caused or facilitated the violation, the extent to which the defendant complied with Chapter 25 (commencing with Section 22756) of Division 8 of the Business and Professions Code is relevant to, but not conclusive of, whether a the defendant violated this section.SEC. 3. Article 3 (commencing with Section 12959) is added to Chapter 6 of Part 2.8 of Division 3 of Title 2 of the Government Code, to read: Article 3. Automated Decision Systems12959. In an action alleging a violation of this chapter in which the defendants development, modification, or use of an automated decision system, as defined in Section 22756 of the Business and Professions Code, is alleged to have committed caused or facilitated the violation, the extent to which the defendant complied with Chapter 24.6 (commencing with Section 22756) of Division 8 of the Business and Professions Code is relevant to, but not conclusive of, whether a the defendant violated this chapter.SEC. 4. The Legislature finds and declares that Section 1 of this act, which adds Chapter 24.6 (commencing with Section 22756) to Division 8 of the Business and Professions Code, imposes a limitation on the publics right of access to the meetings of public bodies or the writings of public officials and agencies within the meaning of Section 3 of Article I of the California Constitution. Pursuant to that constitutional provision, the Legislature makes the following findings to demonstrate the interest protected by this limitation and the need for protecting that interest:In order to protect proprietary information, it is necessary that trade secrets disclosed in performance evaluations and impact assessments to agencies and departments pursuant to Section 1 of this act remain confidential.
5857
5958 The people of the State of California do enact as follows:
6059
6160 ## The people of the State of California do enact as follows:
6261
63-SECTION 1. Chapter 24.6 (commencing with Section 22756) is added to Division 8 of the Business and Professions Code, to read: CHAPTER 24.6. Automated Decisions Safety Act22756. As used in this chapter:(a) Artificial intelligence means an engineered or machine-based system that varies in its level of autonomy and that can, for explicit or implicit objectives, infer from the input it receives how to generate outputs that can influence physical or virtual environments.(b) (1) Automated decision system means a computational process derived from machine learning, statistical modeling, data analytics, or artificial intelligence that issues simplified output, including a score, classification, or recommendation, that is designed or used to assist or replace human discretionary decisionmaking and materially impacts natural persons.(2) Automated decision system does not mean a spam email filter, firewall, antivirus software, identity and access management tool, calculator, database, dataset, or other compilation of data.(c) Consequential decision means a decision that materially impacts the cost, terms, quality, or accessibility of any of the following to a natural person:(1) Employment-related decisions.(2) Education and vocational training as they relate to any of the following:(A) Assessment and placement.(B) Detecting student cheating and plagiarism.(C) Accreditation.(D) Certification.(E) Admissions and enrollment.(F) Discipline.(G) Evaluation.(H) Financial aid and scholarships.(I) Proctoring.(3) Housing and lodging as they relate to any of the following:(A) Rental or short-term housing and lodging.(B) Home appraisals.(C) Rental subsidies.(D) Publicly supported housing.(4) Any of the following essential utilities:(A) Electricity.(B) Heat.(C) Water.(D) Transportation.(E) Municipal trash and sewage services.(5) Family planning, adoption services, reproductive services, and assessments related to child protective services.(6) Health care and health insurance, including mental health care, dental, and vision.(7) Financial services, including a financial service provided by a mortgage company, mortgage broker, or creditor.(8) The criminal justice system with respect to pretrial release, sentencing, and alternatives to incarceration.(9) Legal services.(10) Private arbitration.(11) Mediation.(12) Elections as they relate to any of the following:(A) Voting.(B) Redistricting.(C) Voter eligibility and registration.(D) Distribution of voting information.(E) Election administration.(13) Access to government benefits or services or assignment of penalties by a government entity.(14) Places of public accommodation, as defined in Section 55.52 of the Civil Code.(15) Insurance.(16) Internet and telecommunications access.(d) Covered automated decision system or covered ADS means an automated decision system that is designed or used to make or facilitate a consequential decision.(e) Credit score means a credit score, as defined in Section 1785.15.1 of the Civil Code, from a consumer credit reporting agency, as defined in Section 1785.3 of the Civil Code.(f) Deployer means a person, partnership, state or local government agency, corporation, or developer that uses a covered ADS to make or facilitate a consequential decision, either directly or by contracting with a third party for that purpose.(g) Developer means a person, partnership, state or local government agency, corporation, or deployer that designs, codes, substantially modifies, or otherwise produces an automated decision system that makes or facilitates a consequential decision, either directly or by contracting with a third party for those purposes.(h) (1) Developer-approved use means a deployment context in which a developer intends a covered ADS to make or facilitate a consequential decision.(2) Developer-approved use includes any reasonably foreseeable fine tuning of the covered ADS.(i) Disparate impact means a differential effect on a group of individuals who share a protected characteristic.(j) Disparate treatment means differential treatment of an individual or group of individuals on the basis of a protected characteristic.(k) Employment-related decision means a decision made by an employer, either directly or through a third party, that affects wages, benefits, other compensation, hours, work schedule, performance evaluation, hiring, discipline, promotion, termination, job tasks and responsibilities, assignment of work, access to work and training opportunities, productivity requirements, workplace health and safety, or other terms or conditions of employment.(l) (1) Express consent means an affirmative written authorization that is granted in response to a notice that is all of the following:(A) Clear, meaningful, and prominent.(B) Conveyed in a manner that a natural person would notice and understand it.(C) Not contained within a more general notice, agreement, or set of terms and conditions.(2) Express consent does not mean an authorization that is either of the following:(A) Inferred from inaction.(B) Obtained through the use of a dark pattern, as defined in Section 56.18 of the Civil Code.(m) Fine-tune means to adjust the model parameters of an automated decision system through exposure to additional data.(n) Labor Commissioner means Chief of the Division of Labor Standards Enforcement.(o) Personal information has the same meaning as defined in Section 1798.140 of the Civil Code.(p) Protected characteristic means a characteristic listed in subdivision (b) of Section 51 of the Civil Code.(q) (1) Substantial modification means a new version, release, update, or other modification to a covered ADS that materially changes its uses or outputs.(2) Substantial modification does not mean a modification that results from fine tuning.(r) Trade secret has the same meaning as in Section 3426.1 of the Civil Code.(s) The definitions of disparate impact and disparate treatment provided in subdivisions (i) and (j) are intended solely for purposes of internal compliance, risk assessment, and documentation required by this chapter. These definitions shall not be construed to modify or supersede any standard, burden of proof, or element of a claim under the Unruh Civil Rights Act (Section 51 of the Civil Code), the California Fair Employment and Housing Act (Part 2.8 (commencing with Section 12900) of Division 3 of Title 2 of the Government Code), Title VII of the Civil Rights Act of 1964 (42 U.S.C. Sec. 2000e et seq.), or any other applicable civil rights law.22756.1. (a) (1) With respect to a covered ADS that was first deployed, or made available to potential deployers, before January 1, 2026, the developer of the covered ADS shall conduct an initial performance evaluation on the covered ADS before January 1, 2027, and shall additionally conduct a performance evaluation on the covered ADS under any of the following circumstances:(A) Following any substantial modification of the covered ADS by the developer.(B) Following any fine tuning of the covered ADS by the developer that materially changes the uses or outputs of the covered ADS.(C) No more than one year after the developer last conducted a performance evaluation on the covered ADS, for as long as the developer deploys the covered ADS or makes the covered ADS available to potential deployers.(2) With respect to a covered ADS that is first deployed or made available to potential deployers on or after January 1, 2026, the developer of the covered ADS shall conduct a performance evaluation on the covered ADS under any of the following circumstances:(A) Before initially deploying the covered ADS or making the covered ADS available to potential deployers.(B) Following any substantial modification of the covered ADS by the developer.(C) Following any fine tuning of the covered ADS by the developer that materially changes the uses or outputs of the covered ADS.(D) No more than one year after the developer last conducted a performance evaluation on the covered ADS, for as long as the developer deploys the covered ADS or makes the covered ADS available to potential deployers.(b) In conducting a performance evaluation on a covered ADS, a developer shall do all of the following:(1) Describe the purpose of the covered ADS.(2) List and describe all developer-approved uses of the covered ADS.(3) For each developer-approved use, evaluate the expected performance of the covered ADS and document all of the following:(A) The expected accuracy and reliability of the covered ADS.(B) Any reasonably foreseeable effects of fine tuning on the accuracy and reliability of the covered ADS.(C) Whether any disparate treatment is intended to occur and, if so, all of the following:(i) The conditions under which each disparate treatment is intended to occur.(ii) Whether each disparate treatment is necessary for a developer-approved use.(iii) Whether any alternatives not involving disparate treatment were considered.(D) Any reasonably foreseeable effects of fine tuning on disparate treatment.(E) Whether any disparate impacts are reasonably likely to occur and, if so, all of the following:(i) The conditions under which each disparate impact is reasonably likely to occur.(ii) Whether each disparate impact is necessary for a developer-approved use.(iii) Whether any alternatives not involving disparate impacts were considered.(F) Whether any measures have been taken by the developer to mitigate the risk of unanticipated disparate impacts resulting from the use of the covered ADS.(G) With respect to a covered ADS that has been deployed, whether any unanticipated disparate impacts have been reported to the developer by a deployer, and whether the developer has taken any measures to mitigate those disparate impacts.(H) Any reasonably foreseeable effects of fine tuning on disparate impacts.(4) (A) Contract with an independent third-party auditor to assess the developers compliance with this subdivision.(B) (i) Except pursuant to clause (ii), a developer that contracts with an auditor pursuant to this paragraph shall provide the auditor with any available information that is reasonably necessary for the auditor to comprehensively assess developer compliance.(ii) A developer that provides documentation to an auditor pursuant to this subparagraph may make reasonable redactions for the purpose of protecting trade secrets. To the extent that a developer withholds information, the developer shall notify the auditor and provide a basis for the withholding.(C) If the deadline for conducting a performance evaluation pursuant to subdivision (a) elapses before the audit has been completed, a developer shall not deploy the covered ADS or make the covered ADS available to potential deployers until the audit has been completed.(I)(D) A developer that receives feedback from an auditor pursuant to this paragraph shall do both of the following:(i) Consider and attempt to incorporate that feedback into the development of any subsequent version of a covered ADS.(ii) Make a high-level summary of the feedback publicly available at no cost to users of the developers internet website.(c) (1) A developer that sells, licenses, or otherwise transfers a covered ADS to a potential deployer shall provide the deployer with all of the following:(A) The results of the most recent performance evaluation conducted on the covered ADS by the developer pursuant to this chapter.(B) For each developer-approved use of the covered ADS, instructions explaining how the covered ADS should be used by the deployer to make or facilitate a consequential decision.(C) For each developer-approved use of the covered ADS, a description of whether and under what circumstances the covered ADS can be fine-tuned.(D) An explanation of the deployers responsibilities under this chapter, including a description of any circumstances under which the deployer would assume the responsibilities of a developer pursuant to subdivision (h) of Section 22756.2.(E) (i) Any technical information necessary for the deployer to comply with this chapter.(ii) A developer shall not be required to provide additional technical information to a deployer that has assumed the responsibilities of a developer pursuant to subdivision (h) of Section 22756.2.(2) (A) A developer that provides documentation to a potential deployer pursuant to this subdivision may make reasonable redactions for the purpose of protecting trade secrets.(B) To the extent that a developer withholds information pursuant to subparagraph (A), the developer shall notify the deployer and provide a basis for the withholding.(d) A developer that receives an impact assessment from an auditor of a deployed covered ADS pursuant to subdivision (b) of Section 22756.3 shall provide all of the following information to any deployer of the covered ADS:(A)(1) Any material differences between the expected accuracy of the covered ADS and the observed accuracy of the covered ADS and the deployment conditions under which those differences are reasonably likely to occur.(B)(2) Any material differences between the expected reliability of the covered ADS and the observed reliability of the covered ADS and the deployment conditions under which those differences are reasonably likely to occur.(C)(3) Any unanticipated disparate impacts resulting from the use of the covered ADS and the deployment conditions under which those disparate impacts are reasonably likely to occur.(D)(4) An explanation of any steps the deployer can take to mitigate these discrepancies.(e) A developer that receives feedback from an auditor pursuant to this chapter shall consider and attempt to incorporate that feedback into the development of any subsequent version of a covered ADS.(f) A developer that provides documentation to a deployer pursuant to this section shall ensure the documentation is all of the following:(A)(1) Transmitted directly to the deployer or otherwise made available in a manner reasonably calculated to ensure the deployer receives the documentation.(B)(2) Provided in English and in any other language the developer regularly uses to communicate with deployers.(C)(3) Presented in a manner that ensures the communication clearly and effectively conveys the required information to the deployer.(g) A developer that deploys a covered ADS or makes a covered ADS available to potential deployers shall maintain all of the following documentation in an unredacted format for as long as the developer deploys the covered ADS or makes the covered ADS available to potential deployers plus 10 years:(1) The results of any performance evaluations conducted on the covered ADS pursuant to this chapter.(2) Any documentation provided to deployers pursuant to this chapter.(3) Any documentation provided to, or received from, auditors pursuant to this chapter.(4) Records of any redactions made pursuant to this chapter.(h) It is unlawful to advertise to consumers in the state that a covered ADS is capable of performing in a manner not substantiated by the results of the most recent performance evaluation conducted on the covered ADS.(i) (1) A developer that deploys a covered ADS or makes a covered ADS available to potential deployers shall designate at least one employee to oversee the developers compliance with this chapter.(2) A developer shall require an employee designated pursuant to this subdivision to conduct a prompt and comprehensive review of any credible compliance issue raised to that employee.22756.2. (a) (1) Except as provided in paragraph (2), before a deployer finalizes a consequential decision made or facilitated by a covered ADS, the deployer shall provide any subject of that decision with a plain language written disclosure containing all of the following information:(A) A statement informing the subject that a covered ADS will be used to make or facilitate the consequential decision.(B) The name, version number, and developer of the covered ADS.(C) Whether the deployers use of the covered ADS is within the scope of a developer-approved use and a description of that use.(D) (i) The personal characteristics or attributes of the subject that the covered ADS measures or assesses to make or facilitate the consequential decision.(ii) The sources of personal information collected from the subject to make or facilitate the consequential decision.(iii) Any key parameters known to disproportionately affect the outcome of the consequential decision.(E) The structure and format of the outputs of the covered ADS and a plain language description of how those outputs are used to make or facilitate the consequential decision.(F) Whether a natural person will review either of the following before the consequential decision is finalized:(i) The outputs of the covered ADS.(ii) The outcome of the consequential decision.(G) The subjects rights under subdivisions (b) and (d) and the means and timeframe for exercising those rights.(H) (i) Contact information for the deployer.(ii) Contact information for the entity that manages the covered ADS, if that entity is not the deployer.(iii) Contact information for the entity that will interpret the results of the covered ADS, if that entity is not the deployer.(2) Paragraph (1) does not apply if the subject of the consequential decision is having a medical emergency.(b) (1) Before a deployer finalizes a consequential decision made or facilitated by a covered ADS, the deployer shall provide any subject of that decision with a reasonable opportunity to opt out of the use of the covered ADS.(2) (A) A deployer may deny a request to opt out of the use of a covered ADS if either of the following is true:(i) The deployer is subject to the federal Gramm-Leach-Bliley Act, and the covered ADS makes or facilitates a consequential decision pursuant to paragraph (7) of subdivision (c) of Section 22756.(ii) The subject of the consequential decision is having a medical emergency.(B) A deployer that denies a request to opt out of the use of a covered ADS pursuant to subparagraph (A) shall provide the subject with an explanation of the basis for the denial.(c) (1) After a deployer finalizes a consequential decision made or facilitated by a covered ADS, the deployer shall provide any subject of that decision witha plain language written disclosure containing all of the following information within five days:(A) The personal characteristics or attributes of the subject that the covered ADS used to make or facilitate the consequential decision.(B) The sources of personal information collected from the subject that were used to make or facilitate the consequential decision.(C) Any key parameters that disproportionately affected the outcome of the consequential decision.(D) The structure and format of the outputs of the covered ADS and a plain language description of how those outputs were used to make or facilitate the consequential decision.(E) The role that the ADS played in making the consequential decision and whether any human judgment was involved.(F) Contact information for the deployer.(G) Contact information for the entity that manages the covered ADS, if that entity is not the deployer.(H) Contact information for the entity that will interpret the results of the covered ADS, if that entity is not the deployer.(I) The subjects rights under subdivision (d) and the means and timeframe for exercising those rights.(2) Paragraph (1) does not apply if the subject of the consequential decision is having a medical emergency.(3) A deployer that provides documentation to a subject of a consequential decision pursuant to this subdivision shall ensure the documentation is all of the following:(A) Transmitted directly to the subject.(B) Provided in English and in any other language that the deployer regularly uses to communicate with subjects.(C) Made available in formats that are accessible to people who are blind or have other disabilities.(D) Presented in a manner that ensures the communication clearly and effectively conveys the required information to the subject.(d) After a deployer finalizes a consequential decision made or facilitated by a covered ADS, the deployer shall provide any subject of that decision with an opportunity to do both of the following within 30 business days:(1) (A) Correct any incorrect personal information used by the covered ADS to make or facilitate the consequential decision.(B) A deployer shall comply with a request to correct personal information within 30 business days of receiving the request if the request is accompanied by documentation sufficient to assess the basis for the request.(C) (i) If a deployer determines that complying with a request to correct personal information would change the outcome of the consequential decision, the deployer shall, within 30 days of making the determination, rectify the decision.(ii) If a deployer determines that complying with a request to correct personal information would not change the outcome of the consequential decision, the deployer shall, within 30 days of making the determination, inform the subject that the correction was made but that it did not alter the decision.(D) A deployer that denies a request to correct personal information shall do both of the following:(i) Provide the subject with an explanation of the basis for the denial.(ii) Provide the subject with a reasonable opportunity to request that the deployer delete the subjects personal information.(2) (A) Appeal the outcome of the consequential decision.(B) A deployer shall review a request to appeal a consequential decision within 30 business days of receiving the request if the request is accompanied by documentation sufficient to assess the basis for the request.(C) (i) If a deployer determines that the original decision was incorrect, the deployer shall, within 30 days of making the determination, rectify the decision.(ii) If a deployer determines that the original decision was correct, the deployer shall, within 30 days of making the determination, inform the subject that the consequential decision will not be altered.(D) A deployer that denies a request to appeal the outcome of a consequential decision shall provide the subject with an explanation of the basis for the denial.(e) (1) (A) A deployer that provides documentation to the subject of a consequential decision pursuant to this section may make reasonable redactions for the purpose of protecting trade secrets.(B) To the extent that a deployer withholds information pursuant to paragraph (1), the deployer shall notify the subject and provide a basis for the withholding.(2) A deployer that is required by another state or federal law to provide substantially similar notice to a subject of a consequential decision need not duplicatively provide notice to the subject under this section.(f) A deployers collection, use, retention, and sharing of personal information from a subject of a consequential decision shall be reasonably necessary and proportionate to achieve the purposes for which the personal information was collected and processed, or for another disclosed purpose that is compatible with the context in which the personal information was collected, and not further processed in a manner that is incompatible with those purposes.(g) (1) A deployer that uses a covered ADS to make or facilitate consequential decisions directly impacting more than 5,999 people in a given three-year period shall contract with an independent third-party auditor to conduct an impact assessment on the covered ADS before January 1, 2030, and every three years thereafter.(2) (A) Except pursuant to subparagraph (B), a deployer that contracts with an auditor pursuant to this subdivision shall provide the auditor with any available information that is reasonably necessary for the auditor to conduct a comprehensive impact assessment on the covered ADS.(B) A deployer that provides documentation to an auditor pursuant to this paragraph may make reasonable redactions for the purpose of protecting trade secrets. To the extent that a deployer withholds information, the developer shall notify the auditor and provide a basis for the withholding.(C) This paragraph shall not be construed to require a deployer to collect any personal information from a subject of a consequential decision beyond that which the deployer collects in the ordinary course of business or as necessary to comply with state or federal law.(3) If the deadline for conducting an audit pursuant to paragraph (1) elapses before the audit has been completed, a deployer shall not use the covered ADS to make or facilitate consequential decisions until the audit has been completed.(h) A deployer that does any of the following assumes the responsibilities of a developer under this chapter:(1) Uses a covered ADS to make or facilitate consequential decisions that directly impact more than 5,999 people in a given three-year period, if the deployer did not receive any documentation from the developer of the covered ADS pursuant to subdivision (c) of Section 22756.1 during the three-year period.(2) Uses a covered ADS to make or facilitate consequential decisions that directly impact more than 5,999 people in a given three-year period, if the deployers use of the covered ADS is outside the scope of a developer-approved use.(3) Substantially modifies an automated decision system and does either of the following:(A) Uses the substantially modified system to make or facilitate consequential decisions that directly impact more than 5999 5,999 people in a given three-year period.(B) Makes the substantially modified system available to potential deployers.(i) A deployer that uses a covered ADS to make or facilitate a consequential decision shall retain the following documentation in an unredacted format for as long as the deployer uses the covered ADS plus 10 years:(1) Any documentation received from developers pursuant to this chapter.(2) Any documentation provided pursuant to this section to subjects of consequential decisions made or facilitated by the covered ADS.(3) Any requests to correct personal information made pursuant to this section.(4) Any requests to opt out of the use of the covered ADS made pursuant to this section.(5) Any requests to appeal the outcome of a consequential decision made pursuant to this section.(6) Any documentation provided to, or received from, auditors pursuant to this chapter.(7) Records of any redactions made pursuant to this section.(j) (1) A deployer that uses a covered ADS to make or facilitate a consequential decision shall designate at least one employee to oversee the deployers compliance with this chapter.(2) A deployer shall require an employee designated pursuant to this subdivision to conduct a prompt and comprehensive review of any credible compliance issue related to the deployers use of a covered ADS that is raised to that employee.(k) In addition to the requirements of this section, a deployer that is a business subject to the California Consumer Privacy Act of 2018 (Title 1.81.5 (commencing with Section 1798.100)) is subject to any privacy-related opt-out and access regulation duly adopted by the California Privacy Protection Agency pursuant to subdivision (b) of Section 1798.199.40 of the Civil Code.(l) This section shall become operative on January 1, 2027.22756.3. (a) An auditor that conducts an impact assessment on a covered ADS pursuant to subdivision (g) of Section 22756.2 shall do all of the following:(1) (A) Request any information from the deployer of the covered ADS that is reasonably necessary for the auditor to conduct a comprehensive impact assessment.(B) This paragraph applies only to information gathered by the deployer in the ordinary course of business.(2) For each unique developer-approved use of the covered ADS by the deployer, document all of the following:(A) The observed accuracy and reliability of the covered ADS over the relevant period.(B) Whether the observed accuracy and reliability differed materially from the expected accuracy and reliability of the covered ADS, as described in documentation provided by a developer to the deployer pursuant to this chapter.(C) Whether any disparate impacts resulted from the deployers use of the covered ADS and the deployment conditions under which those disparate impacts occurred.(D) Whether each disparate impact was an anticipated disparate impact, as described in documentation provided to the deployer pursuant to this chapter.(3) Whether the deployer used the covered ADS to make or facilitate a consequential decision outside of the scope of a developer-approved use.(4) Whether the deployer assumed the responsibilities of a developer pursuant to subdivision (h) of Section 22756.2.(b) (1) After conducting an impact assessment on a covered ADS, an auditor shall do both of the following:(A) Provide the results of the impact assessment to the deployer that contracted with the auditor to perform the impact assessment.(B) Make a high-level summary of the results of the impact assessment publicly available at no cost to users of the auditors internet website.(2) The documentation required by this section shall be both of the following:(A) Provided in English and in any other language that the auditor regularly uses to communicate with deployers.(B) Presented in a manner that ensures the communication clearly and effectively conveys the required information.(3) An auditor shall not make publicly available with the personal information of a subject of a consequential decision made or facilitated by a covered ADS without first obtaining the express consent of the subject.22756.4. (a) (1) Within 30 days of receiving a request from the Attorney General for a performance evaluation or impact assessment prepared pursuant to this chapter, a developer, deployer, or auditor of a covered ADS shall provide an unredacted copy of the document to the Attorney General.(2) The Attorney General may share performance evaluations and impact assessments with other enforcement entities as necessary for enforcement purposes.(b) (1) The disclosure or sharing of a performance evaluation or impact assessment pursuant to subdivision (a) does not constitute a waiver of any attorney-client privilege, work-product protection, or trade secret protection that might otherwise exist with respect to any information contained in the performance evaluation or impact assessment.(2) A performance evaluation or impact assessment disclosed or shared pursuant to subdivision (a) is exempt from the California Public Records Act (Division 10 (commencing with Section 7920.000) of Title 1 of the Government Code).(c) Each day a covered ADS is used for which a performance evaluation or impact assessment has not been submitted to the Attorney General pursuant to this section is an additional violation of this section.22756.5. (a) Any of the following public entities may bring a civil action against a developer, deployer, or auditor who violates this chapter:(1) The Attorney General.(2) A district attorney, county counsel, or city attorney for the jurisdiction in which the violation occurred.(3) A city prosecutor in any city having a full-time city prosecutor with the consent of the district attorney.(4) The Civil Rights Department.(5) The Labor Commissioner with respect to employment-related decisions only.(b) A court may award a prevailing plaintiff who brings an action pursuant to subdivision (a) all of the following:(1) Injunctive relief.(2) Declaratory relief.(3) Reasonable attorneys fees and litigation costs.(4) A civil penalty of up to twenty-five thousand dollars ($25,000) per violation.(c) A developer or deployer who contracts with a third party to perform the developers or deployers duties under this chapter, other than those duties related to auditing, is subject to liability under this chapter for the third partys failure to perform those duties.22756.6. (a) This chapter does not apply to an automated decision system the sole purpose of which is to do either of the following:(1) Detect, protect against, or respond to cybersecurity incidents or preserve the integrity or security of computer systems.(2) Operate aircraft in the national airspace.(b) The use of a consumer credit score to inform a consequential decision does not itself create an obligation under this chapter.22756.7. (a) The rights, remedies, and penalties established by this chapter are cumulative and shall not be construed to supersede the rights, remedies, or penalties established under other laws, including, but not limited to, Chapter 6 (commencing with Section 12940) of Part 2.8 of Division 3 of Title 2 of the Government Code and Section 51 of the Civil Code.(b) This chapter does not diminish the rights, privileges, or remedies of an employee under any other federal or state law or under any employment contract or collective bargaining agreement.(c) This chapter does not authorize any use of automated decision systems that is limited, restricted, or prohibited under any other applicable law.(d) This chapter does not authorize disparate impacts or disparate treatment limited, restricted, or prohibited under any other applicable law.
62+SECTION 1. Chapter 24.6 (commencing with Section 22756) is added to Division 8 of the Business and Professions Code, to read: CHAPTER 24.6. Automated Decisions Safety Act22756. As used in this chapter:(a) Artificial intelligence means an engineered or machine-based system that varies in its level of autonomy and that can, for explicit or implicit objectives, infer from the input it receives how to generate outputs that can influence physical or virtual environments.(b) (1) Automated decision system means a computational process derived from machine learning, statistical modeling, data analytics, or artificial intelligence that issues simplified output, including a score, classification, or recommendation, that is designed or used to assist or replace human discretionary decisionmaking and materially impacts natural persons.(2) Automated decision system does not mean a spam email filter, firewall, antivirus software, identity and access management tool, calculator, database, dataset, or other compilation of data.(c) Consequential decision means a decision that materially impacts the cost, terms, quality, or accessibility of any of the following to a natural person:(1) Employment-related decisions.(2) Education and vocational training as they relate to any of the following:(A) Assessment and placement.(B) Detecting student cheating and plagiarism.(C) Accreditation.(D) Certification.(E) Admissions and enrollment.(F) Discipline.(G) Evaluation.(H) Financial aid and scholarships.(I) Proctoring.(3) Housing and lodging as they relate to any of the following:(A) Rental or short-term housing and lodging.(B) Home appraisals.(C) Rental subsidies.(D) Publicly supported housing.(4) Any of the following essential utilities:(A) Electricity.(B) Heat.(C) Water.(D)Internet and telecommunications access.(E)(D) Transportation.(F)(E) Municipal trash and sewage services.(5) Family planning, adoption services, reproductive services, and assessments related to child protective services.(6) Health care and health insurance, including mental health care, dental, and vision.(7) Financial services, including a financial service provided by a mortgage company, mortgage broker, or creditor.(8) The criminal justice system with respect to pretrial release, sentencing, and alternatives to incarceration.(9) Legal services.(10) Private arbitration.(11) Mediation.(12) Elections as they relate to any of the following:(A) Voting.(B) Redistricting.(C) Voter eligibility and registration.(D) Distribution of voting information.(E) Election administration.(13) Access to government benefits or services or assignment of penalties by a government entity.(14) Places of public accommodation, as defined in Section 55.52 of the Civil Code.(15) Insurance.(16) Internet and telecommunications access.(d) Covered automated decision system or covered ADS means an automated decision system that makes or facilitates is designed or used to make or facilitate a consequential decision.(e) Credit score means a credit score, as defined in Section 1785.15.1 of the Civil Code, from a consumer credit reporting agency, as defined in Section 1785.3 of the Civil Code.(e)(f) Deployer means a person, partnership, state or local government agency, corporation, or developer that uses a covered ADS to make or facilitate a consequential decision, either directly or through by contracting with a third party. party for that purpose.(f)(g) Developer means a person, partnership, state or local government agency, corporation, or deployer that designs, codes, substantially modifies, or otherwise produces an automated decision system that makes or facilitates a consequential decision, either directly or through by contracting with a third party. party for those purposes.(g)(h) (1) Developer-approved use means a deployment context in which a developer intends a covered ADS to make or facilitate a consequential decision.(2) Developer-approved use includes any reasonably foreseeable fine tuning of the covered ADS.(h)(i) Disparate impact means a differential effect on a group of individuals who share a protected characteristic.(i)(j) Disparate treatment means differential treatment of an individual or group of individuals on the basis of a protected characteristic.(j)(k) Employment-related decision means a decision made by an employer, either directly or through a third party, that affects wages, benefits, other compensation, hours, work schedule, performance evaluation, hiring, discipline, promotion, termination, job tasks and responsibilities, assignment of work, access to work and training opportunities, productivity requirements, workplace health and safety, or other terms or conditions of employment.(k)(l) (1) Express consent means an affirmative written authorization that is granted in response to a notice that is all of the following:(A) Clear, meaningful, and prominent.(B) Conveyed in a manner that a natural person would notice and understand it.(C) Not contained within a more general notice, agreement, or set of terms and conditions.(2) Express consent does not mean an authorization that is either of the following:(A) Inferred from inaction.(B) Obtained through the use of a dark pattern, as defined in Section 56.18 of the Civil Code.(l)(m) Fine-tune means to adjust the model parameters of an automated decision system through exposure to additional data.(m)(n) Labor Commissioner means Chief of the Division of Labor Standards Enforcement.(n)(o) Personal information has the same meaning as defined in Section 1798.140 of the Civil Code.(o)(p) Protected characteristic means a characteristic listed in subdivision (b) of Section 51 of the Civil Code.(p)(q) (1) Substantial modification means a new version, release, update, or other modification to a covered ADS that materially changes its uses or outputs.(2) Substantial modification does not mean a modification that results from fine tuning.(q)(r) Trade secret has the same meaning as in Section 3426.1 of the Civil Code.22756.1. (a) (1) With respect to a covered ADS that was first deployed, or made available to potential deployers, before January 1, 2026, the developer of the covered ADS shall conduct an initial performance evaluation on the covered ADS before January 1, 2027, and shall additionally conduct a performance evaluation on the covered ADS under any of the following circumstances:(A) Following any substantial modification of the covered ADS by the developer.(B) Following any fine tuning of the covered ADS by the developer that materially changes the uses or outputs of the covered ADS.(C) No more than one year after the developer last conducted a performance evaluation on the covered ADS, for as long as the developer deploys the covered ADS or makes the covered ADS available to potential deployers.(2) With respect to a covered ADS that is first deployed or made available to potential deployers on or after January 1, 2026, the developer of the covered ADS shall conduct a performance evaluation on the covered ADS under any of the following circumstances:(A) Before initially deploying the covered ADS or making the covered ADS available to potential deployers.(B) Following any substantial modification of the covered ADS by the developer.(C) Following any fine tuning of the covered ADS by the developer that materially changes the uses or outputs of the covered ADS.(D) No more than one year after the developer last conducted a performance evaluation on the covered ADS, for as long as the developer deploys the covered ADS or makes the covered ADS available to potential deployers.(b) In conducting a performance evaluation on a covered ADS, a developer shall do all of the following:(1) Describe the purpose of the covered ADS.(2) List and describe all developer-approved uses of the covered ADS.(3) For each developer-approved use, assess evaluate the expected performance of the covered ADS and document all of the following:(A) The expected accuracy and reliability of the covered ADS.(B) Any reasonably foreseeable effects of fine tuning on the accuracy and reliability of the covered ADS.(4)For each developer-approved use, assess whether(C) Whether any disparate treatment is intended to occur and document and, if so, all of the following:(A)Whether the covered ADS is intended to treat individuals or groups of individuals differently on the basis of a protected characteristic.(B)For each disparate treatment identified under subparagraph (A), describe all of the following:(i) The conditions under which the each disparate treatment is intended to occur.(ii) Whether the each disparate treatment is necessary for a developer-approved use.(iii) Whether any alternatives not involving disparate treatment were considered.(C)(D) Any reasonably foreseeable effects of fine tuning on disparate treatment.(5)For each developer-approved use, assess whether (E) Whether any disparate impacts are reasonably likely to occur and document and, if so, all of the following:(A)Whether the covered ADS is reasonably likely to treat groups of individuals who share a protected characteristic differently.(B)For each disparate impact identified under subparagraph (A), describe all of the following:(i) The conditions under which that each disparate impact is reasonably likely to occur.(ii) Whether the each disparate impact is necessary for a developer-approved use.(iii) Whether any alternatives not involving disparate impacts were considered.(C)(F) Whether any measures have been taken by the developer to mitigate the risk of unanticipated disparate impacts resulting from the use of the covered ADS.(D)(G) With respect to a covered ADS that has been deployed, whether any unanticipated disparate impacts have been reported to the developer by a deployer, and whether the developer has taken any measures to mitigate those disparate impacts.(E)(H) Any reasonably foreseeable effects of fine tuning on disparate impacts.(6)(4) (A) Contract with an independent third-party auditor to assess the developers compliance with this subdivision.(B) (i) Except pursuant to clause (ii), a developer that contracts with an auditor pursuant to this paragraph shall provide the auditor with any available information that is reasonably necessary for the auditor to comprehensively assess developer compliance.(ii) A developer that provides documentation to an auditor pursuant to this subparagraph may make reasonable redactions for the purpose of protecting trade secrets. To the extent that a developer withholds information, the developer shall notify the auditor and provide a basis for the withholding.(C) If the deadline for conducting a performance evaluation pursuant to subdivision (a) elapses before the audit has been completed, a developer shall not deploy the covered ADS or make the covered ADS available to potential deployers until the audit has been completed.(I) A developer that receives feedback from an auditor pursuant to this paragraph shall do both of the following:(i) Consider and attempt to incorporate that feedback into the development of any subsequent version of a covered ADS.(ii) Make a high-level summary of the feedback publicly available at no cost to users of the developers internet website.(c) (1) A developer that sells, licenses, or otherwise transfers a covered ADS to a potential deployer shall provide the deployer with all of the following:(A) The results of the most recent performance evaluation conducted on the covered ADS by the developer pursuant to this chapter.(B) For each developer-approved use of the covered ADS, instructions explaining how the covered ADS should be used by the deployer to make or facilitate a consequential decision.(C) For each developer-approved use of the covered ADS, a description of whether and under what circumstances the covered ADS can be fine-tuned.(D) An explanation of the deployers responsibilities under this chapter, including a description of any circumstances under which the deployer would assume the responsibilities of a developer pursuant to subdivision (h) of Section 22756.2.(E) (i) Any technical information necessary for the deployer to comply with this chapter.(ii) A developer shall not be required to provide additional technical information to a deployer that has assumed the responsibilities of a developer pursuant to subdivision (h) of Section 22756.2.(2) (A) A developer that provides documentation to a potential deployer pursuant to this subdivision may make reasonable redactions for the purpose of protecting trade secrets.(B) To the extent that a developer withholds information pursuant to subparagraph (A), the developer shall notify the deployer and provide a basis for the withholding.(d) A developer that receives an impact assessment from an auditor of a deployed covered ADS pursuant to subdivision (b) of Section 22756.3 shall provide all of the following information to any deployer of the covered ADS:(A) Any material differences between the expected accuracy of the covered ADS and the observed accuracy of the covered ADS and the deployment conditions under which those differences are reasonably likely to occur.(B) Any material differences between the expected reliability of the covered ADS and the observed reliability of the covered ADS and the deployment conditions under which those differences are reasonably likely to occur.(C) Any unanticipated disparate impacts resulting from the use of the covered ADS and the deployment conditions under which those disparate impacts are reasonably likely to occur.(D) An explanation of any steps the deployer can take to mitigate these discrepancies.(e) A developer that receives feedback from an auditor pursuant to this chapter shall consider and attempt to incorporate that feedback into the development of any subsequent version of a covered ADS.(f) A developer that provides documentation to a deployer pursuant to this section shall ensure the documentation is all of the following:(A) Transmitted directly to the deployer or otherwise made available in a manner reasonably calculated to ensure the deployer receives the documentation.(B) Provided in English and in any other language the developer regularly uses to communicate with deployers.(C) Presented in a manner that ensures the communication clearly and effectively conveys the required information to the deployer.(g) A developer that deploys a covered ADS or makes a covered ADS available to potential deployers shall maintain all of the following documentation in an unredacted format for as long as the covered ADS remains deployed or developer deploys the covered ADS or makes the covered ADS available to potential deployers plus 10 years:(1) The results of any performance evaluations conducted on the covered ADS pursuant to this chapter.(2) Any documentation provided to deployers pursuant to this chapter.(3) Any documentation provided to, or received from, auditors pursuant to this chapter.(4) Records of any redactions made pursuant to this chapter.(h) It is unlawful to advertise to consumers in the state that a covered ADS is capable of performing in a manner not substantiated by the results of the most recent performance evaluation conducted on the covered ADS.(i) (1) A developer that deploys a covered ADS or makes a covered ADS available to potential deployers shall designate at least one employee to oversee the developers compliance with this chapter.(2) A developer shall require an employee designated pursuant to this subdivision to conduct a prompt and comprehensive review of any credible compliance issue raised to that employee.22756.2. (a) (1) Except as provided in paragraph (2), before finalizing a deployer finalizes a consequential decision made or facilitated by a covered ADS, a the deployer shall provide any subject of that decision with a plain language written disclosure containing all of the following information:(A) A statement informing the subject that a covered ADS will be used to make or facilitate the consequential decision.(B) The name, version number, and developer of the covered ADS.(C) Whether the deployers use of the covered ADS is within the scope of a developer-approved use and a description of that use.(D) (i) The personal characteristics or attributes of the subject that the covered ADS measures or assesses to make or facilitate the consequential decision.(ii) The sources of personal information collected from the subject to make or facilitate the consequential decision.(iii) Any key parameters known to disproportionately affect the outcome of the consequential decision.(E) The structure and format of the outputs of the covered ADS and a plain language description of how those outputs are used to make or facilitate the consequential decision.(F) Whether a natural person will review either of the following before the consequential decision is finalized:(i) The outputs of the covered ADS.(ii) The outcome of the consequential decision.(G) The subjects rights under subdivisions (b) and (c) (d) and the means and timeframe for exercising those rights.(H) (i) Contact information for the deployer.(ii) Contact information for the entity that manages the covered ADS, if that entity is not the deployer.(iii) Contact information for the entity that will interpret the results of the covered ADS, if that entity is not the deployer.(2) Paragraph (1) does not apply if the subject of the consequential decision is having a medical emergency.(b) (1) Before finalizing a deployer finalizes a consequential decision made or facilitated by a covered ADS, a the deployer shall provide any subject of that decision with a reasonable opportunity to opt out of the use of the covered ADS.(2) (A) A deployer may deny a request to opt out of the use of a covered ADS if either of the following is true:(i) The deployer is subject to the federal Gramm-Leach-Bliley Act, and the covered ADS makes or facilitates a consequential decision pursuant to paragraph (7) of subdivision (c) of Section 22756.(ii) The subject of the consequential decision is having a medical emergency.(B) A deployer that denies a request to opt out of the use of a covered ADS pursuant to subparagraph (A) shall provide the subject with an explanation of the basis for the denial.(c) (1) After a deployer finalizes a consequential decision is finalized, made or facilitated by a covered ADS, the deployer shall provide any subject of that decision witha plain language written disclosure shall be provided containing all of the following information within five days, and the disclosure shall include all of the information: days:(A) The personal characteristics or attributes of the subject that the covered ADS measured or assessed used to make or facilitate the consequential decision.(B) The sources of personal information collected from the subject that were used to make or facilitate the consequential decision.(C) Any key parameters that disproportionately affected the outcome of the consequential decision.(D) The structure and format of the outputs of the covered ADS and a plain language description of how those outputs were used to make or facilitate the consequential decision.(E) The role that the ADS played in making the consequential decision and whether any human judgment was involved.(F) Contact information for the deployer.(G) Contact information for the entity that manages the covered ADS, if that entity is not the deployer.(H) Contact information for the entity that will interpret the results of the covered ADS, if that entity is not the deployer.(I) The subjects rights under subdivision (d) and the means and timeframe for exercising those rights.(2) Paragraph (1) is does not applicable apply if the subject of the consequential decision is having a medical emergency.(3) A deployer that provides documentation to a subject of a consequential decision pursuant to this subdivision shall ensure the documentation is all of the following:(A) Transmitted directly to the subject.(B) Provided in English and in any other language that the deployer regularly uses to communicate with subjects.(C) Made available in formats that are accessible to people who are blind or have other disabilities.(D) Presented in a manner that ensures the communication clearly and effectively conveys the required information to the subject.(d) After finalizing a deployer finalizes a consequential decision made or facilitated by a covered ADS, a the deployer shall provide any subject of that decision with an opportunity to do both of the following within 30 business days:(1) (A) Correct any incorrect personal information used by the covered ADS to make or facilitate the consequential decision.(B) A deployer shall comply with a request to correct personal information within 30 business days of receiving the request if the request is accompanied by documentation sufficient to assess the basis for the request.(C) (i) If a deployer determines that complying with a request to correct personal information would change the outcome of the consequential decision, the deployer shall, within 30 days of making the determination, rectify the decision.(ii) If a deployer determines that complying with a request to correct personal information would not change the outcome of the consequential decision, the deployer shall, within 30 days of making the determination, inform the subject that the correction was made but that it did not alter the decision.(D) A deployer that denies a request to correct personal information shall do both of the following:(i) Provide the subject with an explanation of the basis for the denial.(ii) Provide the subject with a reasonable opportunity to request that the deployer delete the subjects personal information.(2) (A) Appeal the outcome of the consequential decision.(B) A deployer shall review a request to appeal a consequential decision within 30 business days of receiving the request. request if the request is accompanied by documentation sufficient to assess the basis for the request.(C) (i) If a deployer determines that the original decision is was incorrect, the deployer shall, within 30 days of making the determination, rectify the decision.(ii) If a deployer determines that the original decision is was correct, the deployer shall, within 30 days of making the determination, inform the subject that the consequential decision will not be altered.(D) A deployer that denies a request to appeal the outcome of a consequential decision shall provide the subject with an explanation of the basis for the denial.(e) (1) (A) A deployer that provides documentation to the subject of a consequential decision pursuant to this section may make reasonable redactions for the purpose of protecting trade secrets.(B) To the extent that a deployer withholds information pursuant to paragraph (1), the deployer shall notify the subject and provide a basis for the withholding.(2) A deployer that is required by another state or federal law to provide substantially similar notice to a subject of a consequential decision need not duplicatively provide notice to the subject under this section.(f) A deployers collection, use, retention, and sharing of personal information from a subject of a consequential decision shall be reasonably necessary and proportionate to achieve the purposes for which the personal information was collected and processed, or for another disclosed purpose that is compatible with the context in which the personal information was collected, and not further processed in a manner that is incompatible with those purposes.(g) (1) A deployer that uses a covered ADS to make or facilitate consequential decisions directly impacting more than 5999 5,999 people in a given three-year period shall contract with an independent third-party auditor to conduct an impact assessment on the covered ADS before January 1, 2030, and every three years thereafter.(2) (A) Except pursuant to subparagraph (B), a deployer that contracts with an auditor pursuant to this subdivision shall provide the auditor with any available information that is reasonably necessary for the auditor to conduct a comprehensive impact assessment on the covered ADS.(B) A deployer that provides documentation to an auditor pursuant to this paragraph may make reasonable redactions for the purpose of protecting trade secrets. To the extent that a deployer withholds information, the developer shall notify the auditor and provide a basis for the withholding.(C) This paragraph shall not be construed to require a deployer to collect any personal information from a subject of a consequential decision beyond that which the deployer collects in the ordinary course of business or as necessary to comply with state or federal law.(3) If the deadline for conducting an audit pursuant to paragraph (1) elapses before the audit has been completed, a deployer shall not use the covered ADS to make or facilitate consequential decisions until the audit has been completed.(h) A deployer that does any of the following assumes the responsibilities of a developer under this chapter:(1) Uses a covered ADS to make or facilitate consequential decisions that directly impact more than 5999 5,999 people in a given three-year period, if the deployer did not receive any documentation from the developer of the covered ADS pursuant to subdivision (c) of Section 22756.1. 22756.1 during the three-year period.(2) Uses a covered ADS to make or facilitate consequential decisions that directly impact more than 5999 5,999 people in a given three-year period, if the deployers use of the covered ADS is outside the scope of a developer-approved use.(3) Substantially modifies an automated decision system and does either of the following:(A) Uses the substantially modified system to make or facilitate consequential decisions that directly impact more than 5999 people in a given three-year period.(B) Makes the substantially modified system available to potential deployers.(i) A deployer that uses a covered ADS to make or facilitate a consequential decision shall retain the following documentation in an unredacted format for as long as the deployer uses the covered ADS remains deployed plus 10 years:(1) Any documentation received from developers pursuant to this chapter.(2) Any documentation provided pursuant to this section to subjects of consequential decisions made or facilitated by the covered ADS.(3) Any requests to correct personal information made pursuant to this section.(4) Any requests to opt out of the use of the covered ADS made pursuant to this section.(5) Any requests to appeal the outcome of a consequential decision made pursuant to this section.(6) Any documentation provided to, or received from, auditors pursuant to this chapter.(7) Records of any redactions made pursuant to this section.(j) (1) A deployer that uses a covered ADS to make or facilitate a consequential decision shall designate at least one employee to oversee the deployers compliance with this chapter.(2) A deployer shall require an employee designated pursuant to this subdivision to conduct a prompt and comprehensive review of any credible compliance issue related to the deployers use of a covered ADS that is raised to that employee.(k) In addition to the requirements of this section, a deployer that is a business subject to the California Consumer Privacy Act of 2018 (Title 1.81.5 (commencing with Section 1798.100)) is subject to any privacy-related opt-out and access regulation duly adopted by the California Privacy Protection Agency pursuant to subdivision (b) of Section 1798.199.40 of the Civil Code.(l) This section shall become operative on January 1, 2027.22756.3. (a) An auditor that conducts an impact assessment on a covered ADS pursuant to subdivision (g) of Section 22756.2 shall do all of the following:(1) (A) Request any information from the deployer of the covered ADS that is reasonably necessary for the auditor to conduct a comprehensive impact assessment.(B) This paragraph applies only to information gathered by the deployer in the ordinary course of business.(2)Document all developer-approved uses of the covered ADS that the deployer utilized during the relevant period.(3)(2) For each unique developer-approved use, use of the covered ADS by the deployer, document all of the following:(A) The observed accuracy and reliability of the covered ADS over the relevant period.(B) Whether the observed accuracy and reliability differed materially from the expected accuracy and reliability of the covered ADS, as described in documentation provided by a developer to the deployer pursuant to this chapter.(C) Whether any disparate impacts resulted from the deployers use of the covered ADS and the deployment conditions under which those disparate impacts occurred.(D) Whether each disparate impact was an anticipated disparate impact, as described in documentation provided to the deployer pursuant to this chapter.(4)(3) Whether the deployer used the covered ADS to make or facilitate a consequential decision outside of the scope of a developer-approved use.(5)(4) Whether the deployer assumed the responsibilities of a developer pursuant to subdivision (h) of Section 22756.2.(b) (1) After conducting an impact assessment on a covered ADS, an auditor shall provide the results of the impact assessment to do both of the following:(A) The Provide the results of the impact assessment to the deployer that contracted with the auditor to perform the impact assessment.(B)The developer of the covered ADS.(B) Make a high-level summary of the results of the impact assessment publicly available at no cost to users of the auditors internet website.(2) The documentation required by this section shall be both of the following:(A) Provided in English and in any other language that the auditor regularly uses to communicate with developers and deployers.(B) Presented in a manner that ensures the communication clearly and effectively conveys the required information to the developer and deployer. information.(3) An auditor shall not provide a developer make publicly available with the personal information of a subject of a consequential decision made or facilitated by a covered ADS without first obtaining the express consent of the subject.22756.4. (a) (1) Within 30 days of receiving a request from the Attorney General for a performance evaluation or impact assessment prepared pursuant to this chapter, a developer, deployer, or auditor of a covered ADS shall provide an unredacted copy of the document to the Attorney General.(2) The Attorney General may share performance evaluations and impact assessments with other enforcement entities as necessary for enforcement purposes.(b) (1) The disclosure or sharing of a performance evaluation or impact assessment pursuant to subdivision (a) does not constitute a waiver of any attorney-client privilege, work-product protection, or trade secret protection that might otherwise exist with respect to any information contained in the performance evaluation or impact assessment.(2) A performance evaluation or impact assessment disclosed or shared pursuant to subdivision (a) is exempt from the California Public Records Act (Division 10 (commencing with Section 7920.000) of Title 1 of the Government Code).(c) Each day a covered ADS is used for which a performance evaluation or impact assessment has not been submitted to the Attorney General pursuant to this section is an additional violation of this section.22756.5. (a) Any of the following public entities may bring a civil action against a developer or deployer developer, deployer, or auditor who violates this chapter:(1) The Attorney General.(2) A district attorney, county counsel, or city attorney for the jurisdiction in which the violation occurred.(3) A city prosecutor in any city having a full-time city prosecutor with the consent of the district attorney.(4) The Civil Rights Department.(5) The Labor Commissioner with respect to employment-related decisions only.(b) A court may award a prevailing plaintiff who brings an action pursuant to subdivision (a) all of the following:(1) Injunctive relief.(2) Declaratory relief.(3) Reasonable attorneys fees and litigation costs.(4) A civil penalty of up to twenty-five thousand dollars ($25,000) per violation.(c) A developer or deployer who contracts with a third party to perform the developers or deployers duties under this chapter, other than those duties related to auditing, is subject to liability under this chapter for the third partys failure to perform those duties.22756.6. (a) This chapter does not apply to an automated decision system the sole purpose of which is to do either of the following:(a)(1) Detect, protect against, or respond to cybersecurity incidents or preserve the integrity or security of computer systems.(b)(2) Operate aircraft in the national airspace.(b) The use of a consumer credit score to inform a consequential decision does not itself create an obligation under this chapter.22756.7. (a) The rights, remedies, and penalties established by this chapter are cumulative and shall not be construed to supersede the rights, remedies, or penalties established under other laws, including, but not limited to, Chapter 6 (commencing with Section 12940) of Part 2.8 of Division 3 of Title 2 of the Government Code and Section 51 of the Civil Code.(b) This chapter does not diminish the rights, privileges, or remedies of an employee under any other federal or state law or under any employment contract or collective bargaining agreement.(c) This chapter does not authorize any use of automated decision systems that is limited, restricted, or prohibited under any other applicable law.(d) This chapter does not authorize disparate impacts or disparate treatment that are limited, restricted, or prohibited under any other applicable law.22756.8.A developer or deployer who contracts with a third party to comply with duties required under this chapter, other than those duties related to auditing, is subject to liability under this chapter for the third partys failure to comply with this chapter.
6463
6564 SECTION 1. Chapter 24.6 (commencing with Section 22756) is added to Division 8 of the Business and Professions Code, to read:
6665
6766 ### SECTION 1.
6867
69-CHAPTER 24.6. Automated Decisions Safety Act22756. As used in this chapter:(a) Artificial intelligence means an engineered or machine-based system that varies in its level of autonomy and that can, for explicit or implicit objectives, infer from the input it receives how to generate outputs that can influence physical or virtual environments.(b) (1) Automated decision system means a computational process derived from machine learning, statistical modeling, data analytics, or artificial intelligence that issues simplified output, including a score, classification, or recommendation, that is designed or used to assist or replace human discretionary decisionmaking and materially impacts natural persons.(2) Automated decision system does not mean a spam email filter, firewall, antivirus software, identity and access management tool, calculator, database, dataset, or other compilation of data.(c) Consequential decision means a decision that materially impacts the cost, terms, quality, or accessibility of any of the following to a natural person:(1) Employment-related decisions.(2) Education and vocational training as they relate to any of the following:(A) Assessment and placement.(B) Detecting student cheating and plagiarism.(C) Accreditation.(D) Certification.(E) Admissions and enrollment.(F) Discipline.(G) Evaluation.(H) Financial aid and scholarships.(I) Proctoring.(3) Housing and lodging as they relate to any of the following:(A) Rental or short-term housing and lodging.(B) Home appraisals.(C) Rental subsidies.(D) Publicly supported housing.(4) Any of the following essential utilities:(A) Electricity.(B) Heat.(C) Water.(D) Transportation.(E) Municipal trash and sewage services.(5) Family planning, adoption services, reproductive services, and assessments related to child protective services.(6) Health care and health insurance, including mental health care, dental, and vision.(7) Financial services, including a financial service provided by a mortgage company, mortgage broker, or creditor.(8) The criminal justice system with respect to pretrial release, sentencing, and alternatives to incarceration.(9) Legal services.(10) Private arbitration.(11) Mediation.(12) Elections as they relate to any of the following:(A) Voting.(B) Redistricting.(C) Voter eligibility and registration.(D) Distribution of voting information.(E) Election administration.(13) Access to government benefits or services or assignment of penalties by a government entity.(14) Places of public accommodation, as defined in Section 55.52 of the Civil Code.(15) Insurance.(16) Internet and telecommunications access.(d) Covered automated decision system or covered ADS means an automated decision system that is designed or used to make or facilitate a consequential decision.(e) Credit score means a credit score, as defined in Section 1785.15.1 of the Civil Code, from a consumer credit reporting agency, as defined in Section 1785.3 of the Civil Code.(f) Deployer means a person, partnership, state or local government agency, corporation, or developer that uses a covered ADS to make or facilitate a consequential decision, either directly or by contracting with a third party for that purpose.(g) Developer means a person, partnership, state or local government agency, corporation, or deployer that designs, codes, substantially modifies, or otherwise produces an automated decision system that makes or facilitates a consequential decision, either directly or by contracting with a third party for those purposes.(h) (1) Developer-approved use means a deployment context in which a developer intends a covered ADS to make or facilitate a consequential decision.(2) Developer-approved use includes any reasonably foreseeable fine tuning of the covered ADS.(i) Disparate impact means a differential effect on a group of individuals who share a protected characteristic.(j) Disparate treatment means differential treatment of an individual or group of individuals on the basis of a protected characteristic.(k) Employment-related decision means a decision made by an employer, either directly or through a third party, that affects wages, benefits, other compensation, hours, work schedule, performance evaluation, hiring, discipline, promotion, termination, job tasks and responsibilities, assignment of work, access to work and training opportunities, productivity requirements, workplace health and safety, or other terms or conditions of employment.(l) (1) Express consent means an affirmative written authorization that is granted in response to a notice that is all of the following:(A) Clear, meaningful, and prominent.(B) Conveyed in a manner that a natural person would notice and understand it.(C) Not contained within a more general notice, agreement, or set of terms and conditions.(2) Express consent does not mean an authorization that is either of the following:(A) Inferred from inaction.(B) Obtained through the use of a dark pattern, as defined in Section 56.18 of the Civil Code.(m) Fine-tune means to adjust the model parameters of an automated decision system through exposure to additional data.(n) Labor Commissioner means Chief of the Division of Labor Standards Enforcement.(o) Personal information has the same meaning as defined in Section 1798.140 of the Civil Code.(p) Protected characteristic means a characteristic listed in subdivision (b) of Section 51 of the Civil Code.(q) (1) Substantial modification means a new version, release, update, or other modification to a covered ADS that materially changes its uses or outputs.(2) Substantial modification does not mean a modification that results from fine tuning.(r) Trade secret has the same meaning as in Section 3426.1 of the Civil Code.(s) The definitions of disparate impact and disparate treatment provided in subdivisions (i) and (j) are intended solely for purposes of internal compliance, risk assessment, and documentation required by this chapter. These definitions shall not be construed to modify or supersede any standard, burden of proof, or element of a claim under the Unruh Civil Rights Act (Section 51 of the Civil Code), the California Fair Employment and Housing Act (Part 2.8 (commencing with Section 12900) of Division 3 of Title 2 of the Government Code), Title VII of the Civil Rights Act of 1964 (42 U.S.C. Sec. 2000e et seq.), or any other applicable civil rights law.22756.1. (a) (1) With respect to a covered ADS that was first deployed, or made available to potential deployers, before January 1, 2026, the developer of the covered ADS shall conduct an initial performance evaluation on the covered ADS before January 1, 2027, and shall additionally conduct a performance evaluation on the covered ADS under any of the following circumstances:(A) Following any substantial modification of the covered ADS by the developer.(B) Following any fine tuning of the covered ADS by the developer that materially changes the uses or outputs of the covered ADS.(C) No more than one year after the developer last conducted a performance evaluation on the covered ADS, for as long as the developer deploys the covered ADS or makes the covered ADS available to potential deployers.(2) With respect to a covered ADS that is first deployed or made available to potential deployers on or after January 1, 2026, the developer of the covered ADS shall conduct a performance evaluation on the covered ADS under any of the following circumstances:(A) Before initially deploying the covered ADS or making the covered ADS available to potential deployers.(B) Following any substantial modification of the covered ADS by the developer.(C) Following any fine tuning of the covered ADS by the developer that materially changes the uses or outputs of the covered ADS.(D) No more than one year after the developer last conducted a performance evaluation on the covered ADS, for as long as the developer deploys the covered ADS or makes the covered ADS available to potential deployers.(b) In conducting a performance evaluation on a covered ADS, a developer shall do all of the following:(1) Describe the purpose of the covered ADS.(2) List and describe all developer-approved uses of the covered ADS.(3) For each developer-approved use, evaluate the expected performance of the covered ADS and document all of the following:(A) The expected accuracy and reliability of the covered ADS.(B) Any reasonably foreseeable effects of fine tuning on the accuracy and reliability of the covered ADS.(C) Whether any disparate treatment is intended to occur and, if so, all of the following:(i) The conditions under which each disparate treatment is intended to occur.(ii) Whether each disparate treatment is necessary for a developer-approved use.(iii) Whether any alternatives not involving disparate treatment were considered.(D) Any reasonably foreseeable effects of fine tuning on disparate treatment.(E) Whether any disparate impacts are reasonably likely to occur and, if so, all of the following:(i) The conditions under which each disparate impact is reasonably likely to occur.(ii) Whether each disparate impact is necessary for a developer-approved use.(iii) Whether any alternatives not involving disparate impacts were considered.(F) Whether any measures have been taken by the developer to mitigate the risk of unanticipated disparate impacts resulting from the use of the covered ADS.(G) With respect to a covered ADS that has been deployed, whether any unanticipated disparate impacts have been reported to the developer by a deployer, and whether the developer has taken any measures to mitigate those disparate impacts.(H) Any reasonably foreseeable effects of fine tuning on disparate impacts.(4) (A) Contract with an independent third-party auditor to assess the developers compliance with this subdivision.(B) (i) Except pursuant to clause (ii), a developer that contracts with an auditor pursuant to this paragraph shall provide the auditor with any available information that is reasonably necessary for the auditor to comprehensively assess developer compliance.(ii) A developer that provides documentation to an auditor pursuant to this subparagraph may make reasonable redactions for the purpose of protecting trade secrets. To the extent that a developer withholds information, the developer shall notify the auditor and provide a basis for the withholding.(C) If the deadline for conducting a performance evaluation pursuant to subdivision (a) elapses before the audit has been completed, a developer shall not deploy the covered ADS or make the covered ADS available to potential deployers until the audit has been completed.(I)(D) A developer that receives feedback from an auditor pursuant to this paragraph shall do both of the following:(i) Consider and attempt to incorporate that feedback into the development of any subsequent version of a covered ADS.(ii) Make a high-level summary of the feedback publicly available at no cost to users of the developers internet website.(c) (1) A developer that sells, licenses, or otherwise transfers a covered ADS to a potential deployer shall provide the deployer with all of the following:(A) The results of the most recent performance evaluation conducted on the covered ADS by the developer pursuant to this chapter.(B) For each developer-approved use of the covered ADS, instructions explaining how the covered ADS should be used by the deployer to make or facilitate a consequential decision.(C) For each developer-approved use of the covered ADS, a description of whether and under what circumstances the covered ADS can be fine-tuned.(D) An explanation of the deployers responsibilities under this chapter, including a description of any circumstances under which the deployer would assume the responsibilities of a developer pursuant to subdivision (h) of Section 22756.2.(E) (i) Any technical information necessary for the deployer to comply with this chapter.(ii) A developer shall not be required to provide additional technical information to a deployer that has assumed the responsibilities of a developer pursuant to subdivision (h) of Section 22756.2.(2) (A) A developer that provides documentation to a potential deployer pursuant to this subdivision may make reasonable redactions for the purpose of protecting trade secrets.(B) To the extent that a developer withholds information pursuant to subparagraph (A), the developer shall notify the deployer and provide a basis for the withholding.(d) A developer that receives an impact assessment from an auditor of a deployed covered ADS pursuant to subdivision (b) of Section 22756.3 shall provide all of the following information to any deployer of the covered ADS:(A)(1) Any material differences between the expected accuracy of the covered ADS and the observed accuracy of the covered ADS and the deployment conditions under which those differences are reasonably likely to occur.(B)(2) Any material differences between the expected reliability of the covered ADS and the observed reliability of the covered ADS and the deployment conditions under which those differences are reasonably likely to occur.(C)(3) Any unanticipated disparate impacts resulting from the use of the covered ADS and the deployment conditions under which those disparate impacts are reasonably likely to occur.(D)(4) An explanation of any steps the deployer can take to mitigate these discrepancies.(e) A developer that receives feedback from an auditor pursuant to this chapter shall consider and attempt to incorporate that feedback into the development of any subsequent version of a covered ADS.(f) A developer that provides documentation to a deployer pursuant to this section shall ensure the documentation is all of the following:(A)(1) Transmitted directly to the deployer or otherwise made available in a manner reasonably calculated to ensure the deployer receives the documentation.(B)(2) Provided in English and in any other language the developer regularly uses to communicate with deployers.(C)(3) Presented in a manner that ensures the communication clearly and effectively conveys the required information to the deployer.(g) A developer that deploys a covered ADS or makes a covered ADS available to potential deployers shall maintain all of the following documentation in an unredacted format for as long as the developer deploys the covered ADS or makes the covered ADS available to potential deployers plus 10 years:(1) The results of any performance evaluations conducted on the covered ADS pursuant to this chapter.(2) Any documentation provided to deployers pursuant to this chapter.(3) Any documentation provided to, or received from, auditors pursuant to this chapter.(4) Records of any redactions made pursuant to this chapter.(h) It is unlawful to advertise to consumers in the state that a covered ADS is capable of performing in a manner not substantiated by the results of the most recent performance evaluation conducted on the covered ADS.(i) (1) A developer that deploys a covered ADS or makes a covered ADS available to potential deployers shall designate at least one employee to oversee the developers compliance with this chapter.(2) A developer shall require an employee designated pursuant to this subdivision to conduct a prompt and comprehensive review of any credible compliance issue raised to that employee.22756.2. (a) (1) Except as provided in paragraph (2), before a deployer finalizes a consequential decision made or facilitated by a covered ADS, the deployer shall provide any subject of that decision with a plain language written disclosure containing all of the following information:(A) A statement informing the subject that a covered ADS will be used to make or facilitate the consequential decision.(B) The name, version number, and developer of the covered ADS.(C) Whether the deployers use of the covered ADS is within the scope of a developer-approved use and a description of that use.(D) (i) The personal characteristics or attributes of the subject that the covered ADS measures or assesses to make or facilitate the consequential decision.(ii) The sources of personal information collected from the subject to make or facilitate the consequential decision.(iii) Any key parameters known to disproportionately affect the outcome of the consequential decision.(E) The structure and format of the outputs of the covered ADS and a plain language description of how those outputs are used to make or facilitate the consequential decision.(F) Whether a natural person will review either of the following before the consequential decision is finalized:(i) The outputs of the covered ADS.(ii) The outcome of the consequential decision.(G) The subjects rights under subdivisions (b) and (d) and the means and timeframe for exercising those rights.(H) (i) Contact information for the deployer.(ii) Contact information for the entity that manages the covered ADS, if that entity is not the deployer.(iii) Contact information for the entity that will interpret the results of the covered ADS, if that entity is not the deployer.(2) Paragraph (1) does not apply if the subject of the consequential decision is having a medical emergency.(b) (1) Before a deployer finalizes a consequential decision made or facilitated by a covered ADS, the deployer shall provide any subject of that decision with a reasonable opportunity to opt out of the use of the covered ADS.(2) (A) A deployer may deny a request to opt out of the use of a covered ADS if either of the following is true:(i) The deployer is subject to the federal Gramm-Leach-Bliley Act, and the covered ADS makes or facilitates a consequential decision pursuant to paragraph (7) of subdivision (c) of Section 22756.(ii) The subject of the consequential decision is having a medical emergency.(B) A deployer that denies a request to opt out of the use of a covered ADS pursuant to subparagraph (A) shall provide the subject with an explanation of the basis for the denial.(c) (1) After a deployer finalizes a consequential decision made or facilitated by a covered ADS, the deployer shall provide any subject of that decision witha plain language written disclosure containing all of the following information within five days:(A) The personal characteristics or attributes of the subject that the covered ADS used to make or facilitate the consequential decision.(B) The sources of personal information collected from the subject that were used to make or facilitate the consequential decision.(C) Any key parameters that disproportionately affected the outcome of the consequential decision.(D) The structure and format of the outputs of the covered ADS and a plain language description of how those outputs were used to make or facilitate the consequential decision.(E) The role that the ADS played in making the consequential decision and whether any human judgment was involved.(F) Contact information for the deployer.(G) Contact information for the entity that manages the covered ADS, if that entity is not the deployer.(H) Contact information for the entity that will interpret the results of the covered ADS, if that entity is not the deployer.(I) The subjects rights under subdivision (d) and the means and timeframe for exercising those rights.(2) Paragraph (1) does not apply if the subject of the consequential decision is having a medical emergency.(3) A deployer that provides documentation to a subject of a consequential decision pursuant to this subdivision shall ensure the documentation is all of the following:(A) Transmitted directly to the subject.(B) Provided in English and in any other language that the deployer regularly uses to communicate with subjects.(C) Made available in formats that are accessible to people who are blind or have other disabilities.(D) Presented in a manner that ensures the communication clearly and effectively conveys the required information to the subject.(d) After a deployer finalizes a consequential decision made or facilitated by a covered ADS, the deployer shall provide any subject of that decision with an opportunity to do both of the following within 30 business days:(1) (A) Correct any incorrect personal information used by the covered ADS to make or facilitate the consequential decision.(B) A deployer shall comply with a request to correct personal information within 30 business days of receiving the request if the request is accompanied by documentation sufficient to assess the basis for the request.(C) (i) If a deployer determines that complying with a request to correct personal information would change the outcome of the consequential decision, the deployer shall, within 30 days of making the determination, rectify the decision.(ii) If a deployer determines that complying with a request to correct personal information would not change the outcome of the consequential decision, the deployer shall, within 30 days of making the determination, inform the subject that the correction was made but that it did not alter the decision.(D) A deployer that denies a request to correct personal information shall do both of the following:(i) Provide the subject with an explanation of the basis for the denial.(ii) Provide the subject with a reasonable opportunity to request that the deployer delete the subjects personal information.(2) (A) Appeal the outcome of the consequential decision.(B) A deployer shall review a request to appeal a consequential decision within 30 business days of receiving the request if the request is accompanied by documentation sufficient to assess the basis for the request.(C) (i) If a deployer determines that the original decision was incorrect, the deployer shall, within 30 days of making the determination, rectify the decision.(ii) If a deployer determines that the original decision was correct, the deployer shall, within 30 days of making the determination, inform the subject that the consequential decision will not be altered.(D) A deployer that denies a request to appeal the outcome of a consequential decision shall provide the subject with an explanation of the basis for the denial.(e) (1) (A) A deployer that provides documentation to the subject of a consequential decision pursuant to this section may make reasonable redactions for the purpose of protecting trade secrets.(B) To the extent that a deployer withholds information pursuant to paragraph (1), the deployer shall notify the subject and provide a basis for the withholding.(2) A deployer that is required by another state or federal law to provide substantially similar notice to a subject of a consequential decision need not duplicatively provide notice to the subject under this section.(f) A deployers collection, use, retention, and sharing of personal information from a subject of a consequential decision shall be reasonably necessary and proportionate to achieve the purposes for which the personal information was collected and processed, or for another disclosed purpose that is compatible with the context in which the personal information was collected, and not further processed in a manner that is incompatible with those purposes.(g) (1) A deployer that uses a covered ADS to make or facilitate consequential decisions directly impacting more than 5,999 people in a given three-year period shall contract with an independent third-party auditor to conduct an impact assessment on the covered ADS before January 1, 2030, and every three years thereafter.(2) (A) Except pursuant to subparagraph (B), a deployer that contracts with an auditor pursuant to this subdivision shall provide the auditor with any available information that is reasonably necessary for the auditor to conduct a comprehensive impact assessment on the covered ADS.(B) A deployer that provides documentation to an auditor pursuant to this paragraph may make reasonable redactions for the purpose of protecting trade secrets. To the extent that a deployer withholds information, the developer shall notify the auditor and provide a basis for the withholding.(C) This paragraph shall not be construed to require a deployer to collect any personal information from a subject of a consequential decision beyond that which the deployer collects in the ordinary course of business or as necessary to comply with state or federal law.(3) If the deadline for conducting an audit pursuant to paragraph (1) elapses before the audit has been completed, a deployer shall not use the covered ADS to make or facilitate consequential decisions until the audit has been completed.(h) A deployer that does any of the following assumes the responsibilities of a developer under this chapter:(1) Uses a covered ADS to make or facilitate consequential decisions that directly impact more than 5,999 people in a given three-year period, if the deployer did not receive any documentation from the developer of the covered ADS pursuant to subdivision (c) of Section 22756.1 during the three-year period.(2) Uses a covered ADS to make or facilitate consequential decisions that directly impact more than 5,999 people in a given three-year period, if the deployers use of the covered ADS is outside the scope of a developer-approved use.(3) Substantially modifies an automated decision system and does either of the following:(A) Uses the substantially modified system to make or facilitate consequential decisions that directly impact more than 5999 5,999 people in a given three-year period.(B) Makes the substantially modified system available to potential deployers.(i) A deployer that uses a covered ADS to make or facilitate a consequential decision shall retain the following documentation in an unredacted format for as long as the deployer uses the covered ADS plus 10 years:(1) Any documentation received from developers pursuant to this chapter.(2) Any documentation provided pursuant to this section to subjects of consequential decisions made or facilitated by the covered ADS.(3) Any requests to correct personal information made pursuant to this section.(4) Any requests to opt out of the use of the covered ADS made pursuant to this section.(5) Any requests to appeal the outcome of a consequential decision made pursuant to this section.(6) Any documentation provided to, or received from, auditors pursuant to this chapter.(7) Records of any redactions made pursuant to this section.(j) (1) A deployer that uses a covered ADS to make or facilitate a consequential decision shall designate at least one employee to oversee the deployers compliance with this chapter.(2) A deployer shall require an employee designated pursuant to this subdivision to conduct a prompt and comprehensive review of any credible compliance issue related to the deployers use of a covered ADS that is raised to that employee.(k) In addition to the requirements of this section, a deployer that is a business subject to the California Consumer Privacy Act of 2018 (Title 1.81.5 (commencing with Section 1798.100)) is subject to any privacy-related opt-out and access regulation duly adopted by the California Privacy Protection Agency pursuant to subdivision (b) of Section 1798.199.40 of the Civil Code.(l) This section shall become operative on January 1, 2027.22756.3. (a) An auditor that conducts an impact assessment on a covered ADS pursuant to subdivision (g) of Section 22756.2 shall do all of the following:(1) (A) Request any information from the deployer of the covered ADS that is reasonably necessary for the auditor to conduct a comprehensive impact assessment.(B) This paragraph applies only to information gathered by the deployer in the ordinary course of business.(2) For each unique developer-approved use of the covered ADS by the deployer, document all of the following:(A) The observed accuracy and reliability of the covered ADS over the relevant period.(B) Whether the observed accuracy and reliability differed materially from the expected accuracy and reliability of the covered ADS, as described in documentation provided by a developer to the deployer pursuant to this chapter.(C) Whether any disparate impacts resulted from the deployers use of the covered ADS and the deployment conditions under which those disparate impacts occurred.(D) Whether each disparate impact was an anticipated disparate impact, as described in documentation provided to the deployer pursuant to this chapter.(3) Whether the deployer used the covered ADS to make or facilitate a consequential decision outside of the scope of a developer-approved use.(4) Whether the deployer assumed the responsibilities of a developer pursuant to subdivision (h) of Section 22756.2.(b) (1) After conducting an impact assessment on a covered ADS, an auditor shall do both of the following:(A) Provide the results of the impact assessment to the deployer that contracted with the auditor to perform the impact assessment.(B) Make a high-level summary of the results of the impact assessment publicly available at no cost to users of the auditors internet website.(2) The documentation required by this section shall be both of the following:(A) Provided in English and in any other language that the auditor regularly uses to communicate with deployers.(B) Presented in a manner that ensures the communication clearly and effectively conveys the required information.(3) An auditor shall not make publicly available with the personal information of a subject of a consequential decision made or facilitated by a covered ADS without first obtaining the express consent of the subject.22756.4. (a) (1) Within 30 days of receiving a request from the Attorney General for a performance evaluation or impact assessment prepared pursuant to this chapter, a developer, deployer, or auditor of a covered ADS shall provide an unredacted copy of the document to the Attorney General.(2) The Attorney General may share performance evaluations and impact assessments with other enforcement entities as necessary for enforcement purposes.(b) (1) The disclosure or sharing of a performance evaluation or impact assessment pursuant to subdivision (a) does not constitute a waiver of any attorney-client privilege, work-product protection, or trade secret protection that might otherwise exist with respect to any information contained in the performance evaluation or impact assessment.(2) A performance evaluation or impact assessment disclosed or shared pursuant to subdivision (a) is exempt from the California Public Records Act (Division 10 (commencing with Section 7920.000) of Title 1 of the Government Code).(c) Each day a covered ADS is used for which a performance evaluation or impact assessment has not been submitted to the Attorney General pursuant to this section is an additional violation of this section.22756.5. (a) Any of the following public entities may bring a civil action against a developer, deployer, or auditor who violates this chapter:(1) The Attorney General.(2) A district attorney, county counsel, or city attorney for the jurisdiction in which the violation occurred.(3) A city prosecutor in any city having a full-time city prosecutor with the consent of the district attorney.(4) The Civil Rights Department.(5) The Labor Commissioner with respect to employment-related decisions only.(b) A court may award a prevailing plaintiff who brings an action pursuant to subdivision (a) all of the following:(1) Injunctive relief.(2) Declaratory relief.(3) Reasonable attorneys fees and litigation costs.(4) A civil penalty of up to twenty-five thousand dollars ($25,000) per violation.(c) A developer or deployer who contracts with a third party to perform the developers or deployers duties under this chapter, other than those duties related to auditing, is subject to liability under this chapter for the third partys failure to perform those duties.22756.6. (a) This chapter does not apply to an automated decision system the sole purpose of which is to do either of the following:(1) Detect, protect against, or respond to cybersecurity incidents or preserve the integrity or security of computer systems.(2) Operate aircraft in the national airspace.(b) The use of a consumer credit score to inform a consequential decision does not itself create an obligation under this chapter.22756.7. (a) The rights, remedies, and penalties established by this chapter are cumulative and shall not be construed to supersede the rights, remedies, or penalties established under other laws, including, but not limited to, Chapter 6 (commencing with Section 12940) of Part 2.8 of Division 3 of Title 2 of the Government Code and Section 51 of the Civil Code.(b) This chapter does not diminish the rights, privileges, or remedies of an employee under any other federal or state law or under any employment contract or collective bargaining agreement.(c) This chapter does not authorize any use of automated decision systems that is limited, restricted, or prohibited under any other applicable law.(d) This chapter does not authorize disparate impacts or disparate treatment limited, restricted, or prohibited under any other applicable law.
68+ CHAPTER 24.6. Automated Decisions Safety Act22756. As used in this chapter:(a) Artificial intelligence means an engineered or machine-based system that varies in its level of autonomy and that can, for explicit or implicit objectives, infer from the input it receives how to generate outputs that can influence physical or virtual environments.(b) (1) Automated decision system means a computational process derived from machine learning, statistical modeling, data analytics, or artificial intelligence that issues simplified output, including a score, classification, or recommendation, that is designed or used to assist or replace human discretionary decisionmaking and materially impacts natural persons.(2) Automated decision system does not mean a spam email filter, firewall, antivirus software, identity and access management tool, calculator, database, dataset, or other compilation of data.(c) Consequential decision means a decision that materially impacts the cost, terms, quality, or accessibility of any of the following to a natural person:(1) Employment-related decisions.(2) Education and vocational training as they relate to any of the following:(A) Assessment and placement.(B) Detecting student cheating and plagiarism.(C) Accreditation.(D) Certification.(E) Admissions and enrollment.(F) Discipline.(G) Evaluation.(H) Financial aid and scholarships.(I) Proctoring.(3) Housing and lodging as they relate to any of the following:(A) Rental or short-term housing and lodging.(B) Home appraisals.(C) Rental subsidies.(D) Publicly supported housing.(4) Any of the following essential utilities:(A) Electricity.(B) Heat.(C) Water.(D)Internet and telecommunications access.(E)(D) Transportation.(F)(E) Municipal trash and sewage services.(5) Family planning, adoption services, reproductive services, and assessments related to child protective services.(6) Health care and health insurance, including mental health care, dental, and vision.(7) Financial services, including a financial service provided by a mortgage company, mortgage broker, or creditor.(8) The criminal justice system with respect to pretrial release, sentencing, and alternatives to incarceration.(9) Legal services.(10) Private arbitration.(11) Mediation.(12) Elections as they relate to any of the following:(A) Voting.(B) Redistricting.(C) Voter eligibility and registration.(D) Distribution of voting information.(E) Election administration.(13) Access to government benefits or services or assignment of penalties by a government entity.(14) Places of public accommodation, as defined in Section 55.52 of the Civil Code.(15) Insurance.(16) Internet and telecommunications access.(d) Covered automated decision system or covered ADS means an automated decision system that makes or facilitates is designed or used to make or facilitate a consequential decision.(e) Credit score means a credit score, as defined in Section 1785.15.1 of the Civil Code, from a consumer credit reporting agency, as defined in Section 1785.3 of the Civil Code.(e)(f) Deployer means a person, partnership, state or local government agency, corporation, or developer that uses a covered ADS to make or facilitate a consequential decision, either directly or through by contracting with a third party. party for that purpose.(f)(g) Developer means a person, partnership, state or local government agency, corporation, or deployer that designs, codes, substantially modifies, or otherwise produces an automated decision system that makes or facilitates a consequential decision, either directly or through by contracting with a third party. party for those purposes.(g)(h) (1) Developer-approved use means a deployment context in which a developer intends a covered ADS to make or facilitate a consequential decision.(2) Developer-approved use includes any reasonably foreseeable fine tuning of the covered ADS.(h)(i) Disparate impact means a differential effect on a group of individuals who share a protected characteristic.(i)(j) Disparate treatment means differential treatment of an individual or group of individuals on the basis of a protected characteristic.(j)(k) Employment-related decision means a decision made by an employer, either directly or through a third party, that affects wages, benefits, other compensation, hours, work schedule, performance evaluation, hiring, discipline, promotion, termination, job tasks and responsibilities, assignment of work, access to work and training opportunities, productivity requirements, workplace health and safety, or other terms or conditions of employment.(k)(l) (1) Express consent means an affirmative written authorization that is granted in response to a notice that is all of the following:(A) Clear, meaningful, and prominent.(B) Conveyed in a manner that a natural person would notice and understand it.(C) Not contained within a more general notice, agreement, or set of terms and conditions.(2) Express consent does not mean an authorization that is either of the following:(A) Inferred from inaction.(B) Obtained through the use of a dark pattern, as defined in Section 56.18 of the Civil Code.(l)(m) Fine-tune means to adjust the model parameters of an automated decision system through exposure to additional data.(m)(n) Labor Commissioner means Chief of the Division of Labor Standards Enforcement.(n)(o) Personal information has the same meaning as defined in Section 1798.140 of the Civil Code.(o)(p) Protected characteristic means a characteristic listed in subdivision (b) of Section 51 of the Civil Code.(p)(q) (1) Substantial modification means a new version, release, update, or other modification to a covered ADS that materially changes its uses or outputs.(2) Substantial modification does not mean a modification that results from fine tuning.(q)(r) Trade secret has the same meaning as in Section 3426.1 of the Civil Code.22756.1. (a) (1) With respect to a covered ADS that was first deployed, or made available to potential deployers, before January 1, 2026, the developer of the covered ADS shall conduct an initial performance evaluation on the covered ADS before January 1, 2027, and shall additionally conduct a performance evaluation on the covered ADS under any of the following circumstances:(A) Following any substantial modification of the covered ADS by the developer.(B) Following any fine tuning of the covered ADS by the developer that materially changes the uses or outputs of the covered ADS.(C) No more than one year after the developer last conducted a performance evaluation on the covered ADS, for as long as the developer deploys the covered ADS or makes the covered ADS available to potential deployers.(2) With respect to a covered ADS that is first deployed or made available to potential deployers on or after January 1, 2026, the developer of the covered ADS shall conduct a performance evaluation on the covered ADS under any of the following circumstances:(A) Before initially deploying the covered ADS or making the covered ADS available to potential deployers.(B) Following any substantial modification of the covered ADS by the developer.(C) Following any fine tuning of the covered ADS by the developer that materially changes the uses or outputs of the covered ADS.(D) No more than one year after the developer last conducted a performance evaluation on the covered ADS, for as long as the developer deploys the covered ADS or makes the covered ADS available to potential deployers.(b) In conducting a performance evaluation on a covered ADS, a developer shall do all of the following:(1) Describe the purpose of the covered ADS.(2) List and describe all developer-approved uses of the covered ADS.(3) For each developer-approved use, assess evaluate the expected performance of the covered ADS and document all of the following:(A) The expected accuracy and reliability of the covered ADS.(B) Any reasonably foreseeable effects of fine tuning on the accuracy and reliability of the covered ADS.(4)For each developer-approved use, assess whether(C) Whether any disparate treatment is intended to occur and document and, if so, all of the following:(A)Whether the covered ADS is intended to treat individuals or groups of individuals differently on the basis of a protected characteristic.(B)For each disparate treatment identified under subparagraph (A), describe all of the following:(i) The conditions under which the each disparate treatment is intended to occur.(ii) Whether the each disparate treatment is necessary for a developer-approved use.(iii) Whether any alternatives not involving disparate treatment were considered.(C)(D) Any reasonably foreseeable effects of fine tuning on disparate treatment.(5)For each developer-approved use, assess whether (E) Whether any disparate impacts are reasonably likely to occur and document and, if so, all of the following:(A)Whether the covered ADS is reasonably likely to treat groups of individuals who share a protected characteristic differently.(B)For each disparate impact identified under subparagraph (A), describe all of the following:(i) The conditions under which that each disparate impact is reasonably likely to occur.(ii) Whether the each disparate impact is necessary for a developer-approved use.(iii) Whether any alternatives not involving disparate impacts were considered.(C)(F) Whether any measures have been taken by the developer to mitigate the risk of unanticipated disparate impacts resulting from the use of the covered ADS.(D)(G) With respect to a covered ADS that has been deployed, whether any unanticipated disparate impacts have been reported to the developer by a deployer, and whether the developer has taken any measures to mitigate those disparate impacts.(E)(H) Any reasonably foreseeable effects of fine tuning on disparate impacts.(6)(4) (A) Contract with an independent third-party auditor to assess the developers compliance with this subdivision.(B) (i) Except pursuant to clause (ii), a developer that contracts with an auditor pursuant to this paragraph shall provide the auditor with any available information that is reasonably necessary for the auditor to comprehensively assess developer compliance.(ii) A developer that provides documentation to an auditor pursuant to this subparagraph may make reasonable redactions for the purpose of protecting trade secrets. To the extent that a developer withholds information, the developer shall notify the auditor and provide a basis for the withholding.(C) If the deadline for conducting a performance evaluation pursuant to subdivision (a) elapses before the audit has been completed, a developer shall not deploy the covered ADS or make the covered ADS available to potential deployers until the audit has been completed.(I) A developer that receives feedback from an auditor pursuant to this paragraph shall do both of the following:(i) Consider and attempt to incorporate that feedback into the development of any subsequent version of a covered ADS.(ii) Make a high-level summary of the feedback publicly available at no cost to users of the developers internet website.(c) (1) A developer that sells, licenses, or otherwise transfers a covered ADS to a potential deployer shall provide the deployer with all of the following:(A) The results of the most recent performance evaluation conducted on the covered ADS by the developer pursuant to this chapter.(B) For each developer-approved use of the covered ADS, instructions explaining how the covered ADS should be used by the deployer to make or facilitate a consequential decision.(C) For each developer-approved use of the covered ADS, a description of whether and under what circumstances the covered ADS can be fine-tuned.(D) An explanation of the deployers responsibilities under this chapter, including a description of any circumstances under which the deployer would assume the responsibilities of a developer pursuant to subdivision (h) of Section 22756.2.(E) (i) Any technical information necessary for the deployer to comply with this chapter.(ii) A developer shall not be required to provide additional technical information to a deployer that has assumed the responsibilities of a developer pursuant to subdivision (h) of Section 22756.2.(2) (A) A developer that provides documentation to a potential deployer pursuant to this subdivision may make reasonable redactions for the purpose of protecting trade secrets.(B) To the extent that a developer withholds information pursuant to subparagraph (A), the developer shall notify the deployer and provide a basis for the withholding.(d) A developer that receives an impact assessment from an auditor of a deployed covered ADS pursuant to subdivision (b) of Section 22756.3 shall provide all of the following information to any deployer of the covered ADS:(A) Any material differences between the expected accuracy of the covered ADS and the observed accuracy of the covered ADS and the deployment conditions under which those differences are reasonably likely to occur.(B) Any material differences between the expected reliability of the covered ADS and the observed reliability of the covered ADS and the deployment conditions under which those differences are reasonably likely to occur.(C) Any unanticipated disparate impacts resulting from the use of the covered ADS and the deployment conditions under which those disparate impacts are reasonably likely to occur.(D) An explanation of any steps the deployer can take to mitigate these discrepancies.(e) A developer that receives feedback from an auditor pursuant to this chapter shall consider and attempt to incorporate that feedback into the development of any subsequent version of a covered ADS.(f) A developer that provides documentation to a deployer pursuant to this section shall ensure the documentation is all of the following:(A) Transmitted directly to the deployer or otherwise made available in a manner reasonably calculated to ensure the deployer receives the documentation.(B) Provided in English and in any other language the developer regularly uses to communicate with deployers.(C) Presented in a manner that ensures the communication clearly and effectively conveys the required information to the deployer.(g) A developer that deploys a covered ADS or makes a covered ADS available to potential deployers shall maintain all of the following documentation in an unredacted format for as long as the covered ADS remains deployed or developer deploys the covered ADS or makes the covered ADS available to potential deployers plus 10 years:(1) The results of any performance evaluations conducted on the covered ADS pursuant to this chapter.(2) Any documentation provided to deployers pursuant to this chapter.(3) Any documentation provided to, or received from, auditors pursuant to this chapter.(4) Records of any redactions made pursuant to this chapter.(h) It is unlawful to advertise to consumers in the state that a covered ADS is capable of performing in a manner not substantiated by the results of the most recent performance evaluation conducted on the covered ADS.(i) (1) A developer that deploys a covered ADS or makes a covered ADS available to potential deployers shall designate at least one employee to oversee the developers compliance with this chapter.(2) A developer shall require an employee designated pursuant to this subdivision to conduct a prompt and comprehensive review of any credible compliance issue raised to that employee.22756.2. (a) (1) Except as provided in paragraph (2), before finalizing a deployer finalizes a consequential decision made or facilitated by a covered ADS, a the deployer shall provide any subject of that decision with a plain language written disclosure containing all of the following information:(A) A statement informing the subject that a covered ADS will be used to make or facilitate the consequential decision.(B) The name, version number, and developer of the covered ADS.(C) Whether the deployers use of the covered ADS is within the scope of a developer-approved use and a description of that use.(D) (i) The personal characteristics or attributes of the subject that the covered ADS measures or assesses to make or facilitate the consequential decision.(ii) The sources of personal information collected from the subject to make or facilitate the consequential decision.(iii) Any key parameters known to disproportionately affect the outcome of the consequential decision.(E) The structure and format of the outputs of the covered ADS and a plain language description of how those outputs are used to make or facilitate the consequential decision.(F) Whether a natural person will review either of the following before the consequential decision is finalized:(i) The outputs of the covered ADS.(ii) The outcome of the consequential decision.(G) The subjects rights under subdivisions (b) and (c) (d) and the means and timeframe for exercising those rights.(H) (i) Contact information for the deployer.(ii) Contact information for the entity that manages the covered ADS, if that entity is not the deployer.(iii) Contact information for the entity that will interpret the results of the covered ADS, if that entity is not the deployer.(2) Paragraph (1) does not apply if the subject of the consequential decision is having a medical emergency.(b) (1) Before finalizing a deployer finalizes a consequential decision made or facilitated by a covered ADS, a the deployer shall provide any subject of that decision with a reasonable opportunity to opt out of the use of the covered ADS.(2) (A) A deployer may deny a request to opt out of the use of a covered ADS if either of the following is true:(i) The deployer is subject to the federal Gramm-Leach-Bliley Act, and the covered ADS makes or facilitates a consequential decision pursuant to paragraph (7) of subdivision (c) of Section 22756.(ii) The subject of the consequential decision is having a medical emergency.(B) A deployer that denies a request to opt out of the use of a covered ADS pursuant to subparagraph (A) shall provide the subject with an explanation of the basis for the denial.(c) (1) After a deployer finalizes a consequential decision is finalized, made or facilitated by a covered ADS, the deployer shall provide any subject of that decision witha plain language written disclosure shall be provided containing all of the following information within five days, and the disclosure shall include all of the information: days:(A) The personal characteristics or attributes of the subject that the covered ADS measured or assessed used to make or facilitate the consequential decision.(B) The sources of personal information collected from the subject that were used to make or facilitate the consequential decision.(C) Any key parameters that disproportionately affected the outcome of the consequential decision.(D) The structure and format of the outputs of the covered ADS and a plain language description of how those outputs were used to make or facilitate the consequential decision.(E) The role that the ADS played in making the consequential decision and whether any human judgment was involved.(F) Contact information for the deployer.(G) Contact information for the entity that manages the covered ADS, if that entity is not the deployer.(H) Contact information for the entity that will interpret the results of the covered ADS, if that entity is not the deployer.(I) The subjects rights under subdivision (d) and the means and timeframe for exercising those rights.(2) Paragraph (1) is does not applicable apply if the subject of the consequential decision is having a medical emergency.(3) A deployer that provides documentation to a subject of a consequential decision pursuant to this subdivision shall ensure the documentation is all of the following:(A) Transmitted directly to the subject.(B) Provided in English and in any other language that the deployer regularly uses to communicate with subjects.(C) Made available in formats that are accessible to people who are blind or have other disabilities.(D) Presented in a manner that ensures the communication clearly and effectively conveys the required information to the subject.(d) After finalizing a deployer finalizes a consequential decision made or facilitated by a covered ADS, a the deployer shall provide any subject of that decision with an opportunity to do both of the following within 30 business days:(1) (A) Correct any incorrect personal information used by the covered ADS to make or facilitate the consequential decision.(B) A deployer shall comply with a request to correct personal information within 30 business days of receiving the request if the request is accompanied by documentation sufficient to assess the basis for the request.(C) (i) If a deployer determines that complying with a request to correct personal information would change the outcome of the consequential decision, the deployer shall, within 30 days of making the determination, rectify the decision.(ii) If a deployer determines that complying with a request to correct personal information would not change the outcome of the consequential decision, the deployer shall, within 30 days of making the determination, inform the subject that the correction was made but that it did not alter the decision.(D) A deployer that denies a request to correct personal information shall do both of the following:(i) Provide the subject with an explanation of the basis for the denial.(ii) Provide the subject with a reasonable opportunity to request that the deployer delete the subjects personal information.(2) (A) Appeal the outcome of the consequential decision.(B) A deployer shall review a request to appeal a consequential decision within 30 business days of receiving the request. request if the request is accompanied by documentation sufficient to assess the basis for the request.(C) (i) If a deployer determines that the original decision is was incorrect, the deployer shall, within 30 days of making the determination, rectify the decision.(ii) If a deployer determines that the original decision is was correct, the deployer shall, within 30 days of making the determination, inform the subject that the consequential decision will not be altered.(D) A deployer that denies a request to appeal the outcome of a consequential decision shall provide the subject with an explanation of the basis for the denial.(e) (1) (A) A deployer that provides documentation to the subject of a consequential decision pursuant to this section may make reasonable redactions for the purpose of protecting trade secrets.(B) To the extent that a deployer withholds information pursuant to paragraph (1), the deployer shall notify the subject and provide a basis for the withholding.(2) A deployer that is required by another state or federal law to provide substantially similar notice to a subject of a consequential decision need not duplicatively provide notice to the subject under this section.(f) A deployers collection, use, retention, and sharing of personal information from a subject of a consequential decision shall be reasonably necessary and proportionate to achieve the purposes for which the personal information was collected and processed, or for another disclosed purpose that is compatible with the context in which the personal information was collected, and not further processed in a manner that is incompatible with those purposes.(g) (1) A deployer that uses a covered ADS to make or facilitate consequential decisions directly impacting more than 5999 5,999 people in a given three-year period shall contract with an independent third-party auditor to conduct an impact assessment on the covered ADS before January 1, 2030, and every three years thereafter.(2) (A) Except pursuant to subparagraph (B), a deployer that contracts with an auditor pursuant to this subdivision shall provide the auditor with any available information that is reasonably necessary for the auditor to conduct a comprehensive impact assessment on the covered ADS.(B) A deployer that provides documentation to an auditor pursuant to this paragraph may make reasonable redactions for the purpose of protecting trade secrets. To the extent that a deployer withholds information, the developer shall notify the auditor and provide a basis for the withholding.(C) This paragraph shall not be construed to require a deployer to collect any personal information from a subject of a consequential decision beyond that which the deployer collects in the ordinary course of business or as necessary to comply with state or federal law.(3) If the deadline for conducting an audit pursuant to paragraph (1) elapses before the audit has been completed, a deployer shall not use the covered ADS to make or facilitate consequential decisions until the audit has been completed.(h) A deployer that does any of the following assumes the responsibilities of a developer under this chapter:(1) Uses a covered ADS to make or facilitate consequential decisions that directly impact more than 5999 5,999 people in a given three-year period, if the deployer did not receive any documentation from the developer of the covered ADS pursuant to subdivision (c) of Section 22756.1. 22756.1 during the three-year period.(2) Uses a covered ADS to make or facilitate consequential decisions that directly impact more than 5999 5,999 people in a given three-year period, if the deployers use of the covered ADS is outside the scope of a developer-approved use.(3) Substantially modifies an automated decision system and does either of the following:(A) Uses the substantially modified system to make or facilitate consequential decisions that directly impact more than 5999 people in a given three-year period.(B) Makes the substantially modified system available to potential deployers.(i) A deployer that uses a covered ADS to make or facilitate a consequential decision shall retain the following documentation in an unredacted format for as long as the deployer uses the covered ADS remains deployed plus 10 years:(1) Any documentation received from developers pursuant to this chapter.(2) Any documentation provided pursuant to this section to subjects of consequential decisions made or facilitated by the covered ADS.(3) Any requests to correct personal information made pursuant to this section.(4) Any requests to opt out of the use of the covered ADS made pursuant to this section.(5) Any requests to appeal the outcome of a consequential decision made pursuant to this section.(6) Any documentation provided to, or received from, auditors pursuant to this chapter.(7) Records of any redactions made pursuant to this section.(j) (1) A deployer that uses a covered ADS to make or facilitate a consequential decision shall designate at least one employee to oversee the deployers compliance with this chapter.(2) A deployer shall require an employee designated pursuant to this subdivision to conduct a prompt and comprehensive review of any credible compliance issue related to the deployers use of a covered ADS that is raised to that employee.(k) In addition to the requirements of this section, a deployer that is a business subject to the California Consumer Privacy Act of 2018 (Title 1.81.5 (commencing with Section 1798.100)) is subject to any privacy-related opt-out and access regulation duly adopted by the California Privacy Protection Agency pursuant to subdivision (b) of Section 1798.199.40 of the Civil Code.(l) This section shall become operative on January 1, 2027.22756.3. (a) An auditor that conducts an impact assessment on a covered ADS pursuant to subdivision (g) of Section 22756.2 shall do all of the following:(1) (A) Request any information from the deployer of the covered ADS that is reasonably necessary for the auditor to conduct a comprehensive impact assessment.(B) This paragraph applies only to information gathered by the deployer in the ordinary course of business.(2)Document all developer-approved uses of the covered ADS that the deployer utilized during the relevant period.(3)(2) For each unique developer-approved use, use of the covered ADS by the deployer, document all of the following:(A) The observed accuracy and reliability of the covered ADS over the relevant period.(B) Whether the observed accuracy and reliability differed materially from the expected accuracy and reliability of the covered ADS, as described in documentation provided by a developer to the deployer pursuant to this chapter.(C) Whether any disparate impacts resulted from the deployers use of the covered ADS and the deployment conditions under which those disparate impacts occurred.(D) Whether each disparate impact was an anticipated disparate impact, as described in documentation provided to the deployer pursuant to this chapter.(4)(3) Whether the deployer used the covered ADS to make or facilitate a consequential decision outside of the scope of a developer-approved use.(5)(4) Whether the deployer assumed the responsibilities of a developer pursuant to subdivision (h) of Section 22756.2.(b) (1) After conducting an impact assessment on a covered ADS, an auditor shall provide the results of the impact assessment to do both of the following:(A) The Provide the results of the impact assessment to the deployer that contracted with the auditor to perform the impact assessment.(B)The developer of the covered ADS.(B) Make a high-level summary of the results of the impact assessment publicly available at no cost to users of the auditors internet website.(2) The documentation required by this section shall be both of the following:(A) Provided in English and in any other language that the auditor regularly uses to communicate with developers and deployers.(B) Presented in a manner that ensures the communication clearly and effectively conveys the required information to the developer and deployer. information.(3) An auditor shall not provide a developer make publicly available with the personal information of a subject of a consequential decision made or facilitated by a covered ADS without first obtaining the express consent of the subject.22756.4. (a) (1) Within 30 days of receiving a request from the Attorney General for a performance evaluation or impact assessment prepared pursuant to this chapter, a developer, deployer, or auditor of a covered ADS shall provide an unredacted copy of the document to the Attorney General.(2) The Attorney General may share performance evaluations and impact assessments with other enforcement entities as necessary for enforcement purposes.(b) (1) The disclosure or sharing of a performance evaluation or impact assessment pursuant to subdivision (a) does not constitute a waiver of any attorney-client privilege, work-product protection, or trade secret protection that might otherwise exist with respect to any information contained in the performance evaluation or impact assessment.(2) A performance evaluation or impact assessment disclosed or shared pursuant to subdivision (a) is exempt from the California Public Records Act (Division 10 (commencing with Section 7920.000) of Title 1 of the Government Code).(c) Each day a covered ADS is used for which a performance evaluation or impact assessment has not been submitted to the Attorney General pursuant to this section is an additional violation of this section.22756.5. (a) Any of the following public entities may bring a civil action against a developer or deployer developer, deployer, or auditor who violates this chapter:(1) The Attorney General.(2) A district attorney, county counsel, or city attorney for the jurisdiction in which the violation occurred.(3) A city prosecutor in any city having a full-time city prosecutor with the consent of the district attorney.(4) The Civil Rights Department.(5) The Labor Commissioner with respect to employment-related decisions only.(b) A court may award a prevailing plaintiff who brings an action pursuant to subdivision (a) all of the following:(1) Injunctive relief.(2) Declaratory relief.(3) Reasonable attorneys fees and litigation costs.(4) A civil penalty of up to twenty-five thousand dollars ($25,000) per violation.(c) A developer or deployer who contracts with a third party to perform the developers or deployers duties under this chapter, other than those duties related to auditing, is subject to liability under this chapter for the third partys failure to perform those duties.22756.6. (a) This chapter does not apply to an automated decision system the sole purpose of which is to do either of the following:(a)(1) Detect, protect against, or respond to cybersecurity incidents or preserve the integrity or security of computer systems.(b)(2) Operate aircraft in the national airspace.(b) The use of a consumer credit score to inform a consequential decision does not itself create an obligation under this chapter.22756.7. (a) The rights, remedies, and penalties established by this chapter are cumulative and shall not be construed to supersede the rights, remedies, or penalties established under other laws, including, but not limited to, Chapter 6 (commencing with Section 12940) of Part 2.8 of Division 3 of Title 2 of the Government Code and Section 51 of the Civil Code.(b) This chapter does not diminish the rights, privileges, or remedies of an employee under any other federal or state law or under any employment contract or collective bargaining agreement.(c) This chapter does not authorize any use of automated decision systems that is limited, restricted, or prohibited under any other applicable law.(d) This chapter does not authorize disparate impacts or disparate treatment that are limited, restricted, or prohibited under any other applicable law.22756.8.A developer or deployer who contracts with a third party to comply with duties required under this chapter, other than those duties related to auditing, is subject to liability under this chapter for the third partys failure to comply with this chapter.
7069
71-CHAPTER 24.6. Automated Decisions Safety Act22756. As used in this chapter:(a) Artificial intelligence means an engineered or machine-based system that varies in its level of autonomy and that can, for explicit or implicit objectives, infer from the input it receives how to generate outputs that can influence physical or virtual environments.(b) (1) Automated decision system means a computational process derived from machine learning, statistical modeling, data analytics, or artificial intelligence that issues simplified output, including a score, classification, or recommendation, that is designed or used to assist or replace human discretionary decisionmaking and materially impacts natural persons.(2) Automated decision system does not mean a spam email filter, firewall, antivirus software, identity and access management tool, calculator, database, dataset, or other compilation of data.(c) Consequential decision means a decision that materially impacts the cost, terms, quality, or accessibility of any of the following to a natural person:(1) Employment-related decisions.(2) Education and vocational training as they relate to any of the following:(A) Assessment and placement.(B) Detecting student cheating and plagiarism.(C) Accreditation.(D) Certification.(E) Admissions and enrollment.(F) Discipline.(G) Evaluation.(H) Financial aid and scholarships.(I) Proctoring.(3) Housing and lodging as they relate to any of the following:(A) Rental or short-term housing and lodging.(B) Home appraisals.(C) Rental subsidies.(D) Publicly supported housing.(4) Any of the following essential utilities:(A) Electricity.(B) Heat.(C) Water.(D) Transportation.(E) Municipal trash and sewage services.(5) Family planning, adoption services, reproductive services, and assessments related to child protective services.(6) Health care and health insurance, including mental health care, dental, and vision.(7) Financial services, including a financial service provided by a mortgage company, mortgage broker, or creditor.(8) The criminal justice system with respect to pretrial release, sentencing, and alternatives to incarceration.(9) Legal services.(10) Private arbitration.(11) Mediation.(12) Elections as they relate to any of the following:(A) Voting.(B) Redistricting.(C) Voter eligibility and registration.(D) Distribution of voting information.(E) Election administration.(13) Access to government benefits or services or assignment of penalties by a government entity.(14) Places of public accommodation, as defined in Section 55.52 of the Civil Code.(15) Insurance.(16) Internet and telecommunications access.(d) Covered automated decision system or covered ADS means an automated decision system that is designed or used to make or facilitate a consequential decision.(e) Credit score means a credit score, as defined in Section 1785.15.1 of the Civil Code, from a consumer credit reporting agency, as defined in Section 1785.3 of the Civil Code.(f) Deployer means a person, partnership, state or local government agency, corporation, or developer that uses a covered ADS to make or facilitate a consequential decision, either directly or by contracting with a third party for that purpose.(g) Developer means a person, partnership, state or local government agency, corporation, or deployer that designs, codes, substantially modifies, or otherwise produces an automated decision system that makes or facilitates a consequential decision, either directly or by contracting with a third party for those purposes.(h) (1) Developer-approved use means a deployment context in which a developer intends a covered ADS to make or facilitate a consequential decision.(2) Developer-approved use includes any reasonably foreseeable fine tuning of the covered ADS.(i) Disparate impact means a differential effect on a group of individuals who share a protected characteristic.(j) Disparate treatment means differential treatment of an individual or group of individuals on the basis of a protected characteristic.(k) Employment-related decision means a decision made by an employer, either directly or through a third party, that affects wages, benefits, other compensation, hours, work schedule, performance evaluation, hiring, discipline, promotion, termination, job tasks and responsibilities, assignment of work, access to work and training opportunities, productivity requirements, workplace health and safety, or other terms or conditions of employment.(l) (1) Express consent means an affirmative written authorization that is granted in response to a notice that is all of the following:(A) Clear, meaningful, and prominent.(B) Conveyed in a manner that a natural person would notice and understand it.(C) Not contained within a more general notice, agreement, or set of terms and conditions.(2) Express consent does not mean an authorization that is either of the following:(A) Inferred from inaction.(B) Obtained through the use of a dark pattern, as defined in Section 56.18 of the Civil Code.(m) Fine-tune means to adjust the model parameters of an automated decision system through exposure to additional data.(n) Labor Commissioner means Chief of the Division of Labor Standards Enforcement.(o) Personal information has the same meaning as defined in Section 1798.140 of the Civil Code.(p) Protected characteristic means a characteristic listed in subdivision (b) of Section 51 of the Civil Code.(q) (1) Substantial modification means a new version, release, update, or other modification to a covered ADS that materially changes its uses or outputs.(2) Substantial modification does not mean a modification that results from fine tuning.(r) Trade secret has the same meaning as in Section 3426.1 of the Civil Code.(s) The definitions of disparate impact and disparate treatment provided in subdivisions (i) and (j) are intended solely for purposes of internal compliance, risk assessment, and documentation required by this chapter. These definitions shall not be construed to modify or supersede any standard, burden of proof, or element of a claim under the Unruh Civil Rights Act (Section 51 of the Civil Code), the California Fair Employment and Housing Act (Part 2.8 (commencing with Section 12900) of Division 3 of Title 2 of the Government Code), Title VII of the Civil Rights Act of 1964 (42 U.S.C. Sec. 2000e et seq.), or any other applicable civil rights law.22756.1. (a) (1) With respect to a covered ADS that was first deployed, or made available to potential deployers, before January 1, 2026, the developer of the covered ADS shall conduct an initial performance evaluation on the covered ADS before January 1, 2027, and shall additionally conduct a performance evaluation on the covered ADS under any of the following circumstances:(A) Following any substantial modification of the covered ADS by the developer.(B) Following any fine tuning of the covered ADS by the developer that materially changes the uses or outputs of the covered ADS.(C) No more than one year after the developer last conducted a performance evaluation on the covered ADS, for as long as the developer deploys the covered ADS or makes the covered ADS available to potential deployers.(2) With respect to a covered ADS that is first deployed or made available to potential deployers on or after January 1, 2026, the developer of the covered ADS shall conduct a performance evaluation on the covered ADS under any of the following circumstances:(A) Before initially deploying the covered ADS or making the covered ADS available to potential deployers.(B) Following any substantial modification of the covered ADS by the developer.(C) Following any fine tuning of the covered ADS by the developer that materially changes the uses or outputs of the covered ADS.(D) No more than one year after the developer last conducted a performance evaluation on the covered ADS, for as long as the developer deploys the covered ADS or makes the covered ADS available to potential deployers.(b) In conducting a performance evaluation on a covered ADS, a developer shall do all of the following:(1) Describe the purpose of the covered ADS.(2) List and describe all developer-approved uses of the covered ADS.(3) For each developer-approved use, evaluate the expected performance of the covered ADS and document all of the following:(A) The expected accuracy and reliability of the covered ADS.(B) Any reasonably foreseeable effects of fine tuning on the accuracy and reliability of the covered ADS.(C) Whether any disparate treatment is intended to occur and, if so, all of the following:(i) The conditions under which each disparate treatment is intended to occur.(ii) Whether each disparate treatment is necessary for a developer-approved use.(iii) Whether any alternatives not involving disparate treatment were considered.(D) Any reasonably foreseeable effects of fine tuning on disparate treatment.(E) Whether any disparate impacts are reasonably likely to occur and, if so, all of the following:(i) The conditions under which each disparate impact is reasonably likely to occur.(ii) Whether each disparate impact is necessary for a developer-approved use.(iii) Whether any alternatives not involving disparate impacts were considered.(F) Whether any measures have been taken by the developer to mitigate the risk of unanticipated disparate impacts resulting from the use of the covered ADS.(G) With respect to a covered ADS that has been deployed, whether any unanticipated disparate impacts have been reported to the developer by a deployer, and whether the developer has taken any measures to mitigate those disparate impacts.(H) Any reasonably foreseeable effects of fine tuning on disparate impacts.(4) (A) Contract with an independent third-party auditor to assess the developers compliance with this subdivision.(B) (i) Except pursuant to clause (ii), a developer that contracts with an auditor pursuant to this paragraph shall provide the auditor with any available information that is reasonably necessary for the auditor to comprehensively assess developer compliance.(ii) A developer that provides documentation to an auditor pursuant to this subparagraph may make reasonable redactions for the purpose of protecting trade secrets. To the extent that a developer withholds information, the developer shall notify the auditor and provide a basis for the withholding.(C) If the deadline for conducting a performance evaluation pursuant to subdivision (a) elapses before the audit has been completed, a developer shall not deploy the covered ADS or make the covered ADS available to potential deployers until the audit has been completed.(I)(D) A developer that receives feedback from an auditor pursuant to this paragraph shall do both of the following:(i) Consider and attempt to incorporate that feedback into the development of any subsequent version of a covered ADS.(ii) Make a high-level summary of the feedback publicly available at no cost to users of the developers internet website.(c) (1) A developer that sells, licenses, or otherwise transfers a covered ADS to a potential deployer shall provide the deployer with all of the following:(A) The results of the most recent performance evaluation conducted on the covered ADS by the developer pursuant to this chapter.(B) For each developer-approved use of the covered ADS, instructions explaining how the covered ADS should be used by the deployer to make or facilitate a consequential decision.(C) For each developer-approved use of the covered ADS, a description of whether and under what circumstances the covered ADS can be fine-tuned.(D) An explanation of the deployers responsibilities under this chapter, including a description of any circumstances under which the deployer would assume the responsibilities of a developer pursuant to subdivision (h) of Section 22756.2.(E) (i) Any technical information necessary for the deployer to comply with this chapter.(ii) A developer shall not be required to provide additional technical information to a deployer that has assumed the responsibilities of a developer pursuant to subdivision (h) of Section 22756.2.(2) (A) A developer that provides documentation to a potential deployer pursuant to this subdivision may make reasonable redactions for the purpose of protecting trade secrets.(B) To the extent that a developer withholds information pursuant to subparagraph (A), the developer shall notify the deployer and provide a basis for the withholding.(d) A developer that receives an impact assessment from an auditor of a deployed covered ADS pursuant to subdivision (b) of Section 22756.3 shall provide all of the following information to any deployer of the covered ADS:(A)(1) Any material differences between the expected accuracy of the covered ADS and the observed accuracy of the covered ADS and the deployment conditions under which those differences are reasonably likely to occur.(B)(2) Any material differences between the expected reliability of the covered ADS and the observed reliability of the covered ADS and the deployment conditions under which those differences are reasonably likely to occur.(C)(3) Any unanticipated disparate impacts resulting from the use of the covered ADS and the deployment conditions under which those disparate impacts are reasonably likely to occur.(D)(4) An explanation of any steps the deployer can take to mitigate these discrepancies.(e) A developer that receives feedback from an auditor pursuant to this chapter shall consider and attempt to incorporate that feedback into the development of any subsequent version of a covered ADS.(f) A developer that provides documentation to a deployer pursuant to this section shall ensure the documentation is all of the following:(A)(1) Transmitted directly to the deployer or otherwise made available in a manner reasonably calculated to ensure the deployer receives the documentation.(B)(2) Provided in English and in any other language the developer regularly uses to communicate with deployers.(C)(3) Presented in a manner that ensures the communication clearly and effectively conveys the required information to the deployer.(g) A developer that deploys a covered ADS or makes a covered ADS available to potential deployers shall maintain all of the following documentation in an unredacted format for as long as the developer deploys the covered ADS or makes the covered ADS available to potential deployers plus 10 years:(1) The results of any performance evaluations conducted on the covered ADS pursuant to this chapter.(2) Any documentation provided to deployers pursuant to this chapter.(3) Any documentation provided to, or received from, auditors pursuant to this chapter.(4) Records of any redactions made pursuant to this chapter.(h) It is unlawful to advertise to consumers in the state that a covered ADS is capable of performing in a manner not substantiated by the results of the most recent performance evaluation conducted on the covered ADS.(i) (1) A developer that deploys a covered ADS or makes a covered ADS available to potential deployers shall designate at least one employee to oversee the developers compliance with this chapter.(2) A developer shall require an employee designated pursuant to this subdivision to conduct a prompt and comprehensive review of any credible compliance issue raised to that employee.22756.2. (a) (1) Except as provided in paragraph (2), before a deployer finalizes a consequential decision made or facilitated by a covered ADS, the deployer shall provide any subject of that decision with a plain language written disclosure containing all of the following information:(A) A statement informing the subject that a covered ADS will be used to make or facilitate the consequential decision.(B) The name, version number, and developer of the covered ADS.(C) Whether the deployers use of the covered ADS is within the scope of a developer-approved use and a description of that use.(D) (i) The personal characteristics or attributes of the subject that the covered ADS measures or assesses to make or facilitate the consequential decision.(ii) The sources of personal information collected from the subject to make or facilitate the consequential decision.(iii) Any key parameters known to disproportionately affect the outcome of the consequential decision.(E) The structure and format of the outputs of the covered ADS and a plain language description of how those outputs are used to make or facilitate the consequential decision.(F) Whether a natural person will review either of the following before the consequential decision is finalized:(i) The outputs of the covered ADS.(ii) The outcome of the consequential decision.(G) The subjects rights under subdivisions (b) and (d) and the means and timeframe for exercising those rights.(H) (i) Contact information for the deployer.(ii) Contact information for the entity that manages the covered ADS, if that entity is not the deployer.(iii) Contact information for the entity that will interpret the results of the covered ADS, if that entity is not the deployer.(2) Paragraph (1) does not apply if the subject of the consequential decision is having a medical emergency.(b) (1) Before a deployer finalizes a consequential decision made or facilitated by a covered ADS, the deployer shall provide any subject of that decision with a reasonable opportunity to opt out of the use of the covered ADS.(2) (A) A deployer may deny a request to opt out of the use of a covered ADS if either of the following is true:(i) The deployer is subject to the federal Gramm-Leach-Bliley Act, and the covered ADS makes or facilitates a consequential decision pursuant to paragraph (7) of subdivision (c) of Section 22756.(ii) The subject of the consequential decision is having a medical emergency.(B) A deployer that denies a request to opt out of the use of a covered ADS pursuant to subparagraph (A) shall provide the subject with an explanation of the basis for the denial.(c) (1) After a deployer finalizes a consequential decision made or facilitated by a covered ADS, the deployer shall provide any subject of that decision witha plain language written disclosure containing all of the following information within five days:(A) The personal characteristics or attributes of the subject that the covered ADS used to make or facilitate the consequential decision.(B) The sources of personal information collected from the subject that were used to make or facilitate the consequential decision.(C) Any key parameters that disproportionately affected the outcome of the consequential decision.(D) The structure and format of the outputs of the covered ADS and a plain language description of how those outputs were used to make or facilitate the consequential decision.(E) The role that the ADS played in making the consequential decision and whether any human judgment was involved.(F) Contact information for the deployer.(G) Contact information for the entity that manages the covered ADS, if that entity is not the deployer.(H) Contact information for the entity that will interpret the results of the covered ADS, if that entity is not the deployer.(I) The subjects rights under subdivision (d) and the means and timeframe for exercising those rights.(2) Paragraph (1) does not apply if the subject of the consequential decision is having a medical emergency.(3) A deployer that provides documentation to a subject of a consequential decision pursuant to this subdivision shall ensure the documentation is all of the following:(A) Transmitted directly to the subject.(B) Provided in English and in any other language that the deployer regularly uses to communicate with subjects.(C) Made available in formats that are accessible to people who are blind or have other disabilities.(D) Presented in a manner that ensures the communication clearly and effectively conveys the required information to the subject.(d) After a deployer finalizes a consequential decision made or facilitated by a covered ADS, the deployer shall provide any subject of that decision with an opportunity to do both of the following within 30 business days:(1) (A) Correct any incorrect personal information used by the covered ADS to make or facilitate the consequential decision.(B) A deployer shall comply with a request to correct personal information within 30 business days of receiving the request if the request is accompanied by documentation sufficient to assess the basis for the request.(C) (i) If a deployer determines that complying with a request to correct personal information would change the outcome of the consequential decision, the deployer shall, within 30 days of making the determination, rectify the decision.(ii) If a deployer determines that complying with a request to correct personal information would not change the outcome of the consequential decision, the deployer shall, within 30 days of making the determination, inform the subject that the correction was made but that it did not alter the decision.(D) A deployer that denies a request to correct personal information shall do both of the following:(i) Provide the subject with an explanation of the basis for the denial.(ii) Provide the subject with a reasonable opportunity to request that the deployer delete the subjects personal information.(2) (A) Appeal the outcome of the consequential decision.(B) A deployer shall review a request to appeal a consequential decision within 30 business days of receiving the request if the request is accompanied by documentation sufficient to assess the basis for the request.(C) (i) If a deployer determines that the original decision was incorrect, the deployer shall, within 30 days of making the determination, rectify the decision.(ii) If a deployer determines that the original decision was correct, the deployer shall, within 30 days of making the determination, inform the subject that the consequential decision will not be altered.(D) A deployer that denies a request to appeal the outcome of a consequential decision shall provide the subject with an explanation of the basis for the denial.(e) (1) (A) A deployer that provides documentation to the subject of a consequential decision pursuant to this section may make reasonable redactions for the purpose of protecting trade secrets.(B) To the extent that a deployer withholds information pursuant to paragraph (1), the deployer shall notify the subject and provide a basis for the withholding.(2) A deployer that is required by another state or federal law to provide substantially similar notice to a subject of a consequential decision need not duplicatively provide notice to the subject under this section.(f) A deployers collection, use, retention, and sharing of personal information from a subject of a consequential decision shall be reasonably necessary and proportionate to achieve the purposes for which the personal information was collected and processed, or for another disclosed purpose that is compatible with the context in which the personal information was collected, and not further processed in a manner that is incompatible with those purposes.(g) (1) A deployer that uses a covered ADS to make or facilitate consequential decisions directly impacting more than 5,999 people in a given three-year period shall contract with an independent third-party auditor to conduct an impact assessment on the covered ADS before January 1, 2030, and every three years thereafter.(2) (A) Except pursuant to subparagraph (B), a deployer that contracts with an auditor pursuant to this subdivision shall provide the auditor with any available information that is reasonably necessary for the auditor to conduct a comprehensive impact assessment on the covered ADS.(B) A deployer that provides documentation to an auditor pursuant to this paragraph may make reasonable redactions for the purpose of protecting trade secrets. To the extent that a deployer withholds information, the developer shall notify the auditor and provide a basis for the withholding.(C) This paragraph shall not be construed to require a deployer to collect any personal information from a subject of a consequential decision beyond that which the deployer collects in the ordinary course of business or as necessary to comply with state or federal law.(3) If the deadline for conducting an audit pursuant to paragraph (1) elapses before the audit has been completed, a deployer shall not use the covered ADS to make or facilitate consequential decisions until the audit has been completed.(h) A deployer that does any of the following assumes the responsibilities of a developer under this chapter:(1) Uses a covered ADS to make or facilitate consequential decisions that directly impact more than 5,999 people in a given three-year period, if the deployer did not receive any documentation from the developer of the covered ADS pursuant to subdivision (c) of Section 22756.1 during the three-year period.(2) Uses a covered ADS to make or facilitate consequential decisions that directly impact more than 5,999 people in a given three-year period, if the deployers use of the covered ADS is outside the scope of a developer-approved use.(3) Substantially modifies an automated decision system and does either of the following:(A) Uses the substantially modified system to make or facilitate consequential decisions that directly impact more than 5999 5,999 people in a given three-year period.(B) Makes the substantially modified system available to potential deployers.(i) A deployer that uses a covered ADS to make or facilitate a consequential decision shall retain the following documentation in an unredacted format for as long as the deployer uses the covered ADS plus 10 years:(1) Any documentation received from developers pursuant to this chapter.(2) Any documentation provided pursuant to this section to subjects of consequential decisions made or facilitated by the covered ADS.(3) Any requests to correct personal information made pursuant to this section.(4) Any requests to opt out of the use of the covered ADS made pursuant to this section.(5) Any requests to appeal the outcome of a consequential decision made pursuant to this section.(6) Any documentation provided to, or received from, auditors pursuant to this chapter.(7) Records of any redactions made pursuant to this section.(j) (1) A deployer that uses a covered ADS to make or facilitate a consequential decision shall designate at least one employee to oversee the deployers compliance with this chapter.(2) A deployer shall require an employee designated pursuant to this subdivision to conduct a prompt and comprehensive review of any credible compliance issue related to the deployers use of a covered ADS that is raised to that employee.(k) In addition to the requirements of this section, a deployer that is a business subject to the California Consumer Privacy Act of 2018 (Title 1.81.5 (commencing with Section 1798.100)) is subject to any privacy-related opt-out and access regulation duly adopted by the California Privacy Protection Agency pursuant to subdivision (b) of Section 1798.199.40 of the Civil Code.(l) This section shall become operative on January 1, 2027.22756.3. (a) An auditor that conducts an impact assessment on a covered ADS pursuant to subdivision (g) of Section 22756.2 shall do all of the following:(1) (A) Request any information from the deployer of the covered ADS that is reasonably necessary for the auditor to conduct a comprehensive impact assessment.(B) This paragraph applies only to information gathered by the deployer in the ordinary course of business.(2) For each unique developer-approved use of the covered ADS by the deployer, document all of the following:(A) The observed accuracy and reliability of the covered ADS over the relevant period.(B) Whether the observed accuracy and reliability differed materially from the expected accuracy and reliability of the covered ADS, as described in documentation provided by a developer to the deployer pursuant to this chapter.(C) Whether any disparate impacts resulted from the deployers use of the covered ADS and the deployment conditions under which those disparate impacts occurred.(D) Whether each disparate impact was an anticipated disparate impact, as described in documentation provided to the deployer pursuant to this chapter.(3) Whether the deployer used the covered ADS to make or facilitate a consequential decision outside of the scope of a developer-approved use.(4) Whether the deployer assumed the responsibilities of a developer pursuant to subdivision (h) of Section 22756.2.(b) (1) After conducting an impact assessment on a covered ADS, an auditor shall do both of the following:(A) Provide the results of the impact assessment to the deployer that contracted with the auditor to perform the impact assessment.(B) Make a high-level summary of the results of the impact assessment publicly available at no cost to users of the auditors internet website.(2) The documentation required by this section shall be both of the following:(A) Provided in English and in any other language that the auditor regularly uses to communicate with deployers.(B) Presented in a manner that ensures the communication clearly and effectively conveys the required information.(3) An auditor shall not make publicly available with the personal information of a subject of a consequential decision made or facilitated by a covered ADS without first obtaining the express consent of the subject.22756.4. (a) (1) Within 30 days of receiving a request from the Attorney General for a performance evaluation or impact assessment prepared pursuant to this chapter, a developer, deployer, or auditor of a covered ADS shall provide an unredacted copy of the document to the Attorney General.(2) The Attorney General may share performance evaluations and impact assessments with other enforcement entities as necessary for enforcement purposes.(b) (1) The disclosure or sharing of a performance evaluation or impact assessment pursuant to subdivision (a) does not constitute a waiver of any attorney-client privilege, work-product protection, or trade secret protection that might otherwise exist with respect to any information contained in the performance evaluation or impact assessment.(2) A performance evaluation or impact assessment disclosed or shared pursuant to subdivision (a) is exempt from the California Public Records Act (Division 10 (commencing with Section 7920.000) of Title 1 of the Government Code).(c) Each day a covered ADS is used for which a performance evaluation or impact assessment has not been submitted to the Attorney General pursuant to this section is an additional violation of this section.22756.5. (a) Any of the following public entities may bring a civil action against a developer, deployer, or auditor who violates this chapter:(1) The Attorney General.(2) A district attorney, county counsel, or city attorney for the jurisdiction in which the violation occurred.(3) A city prosecutor in any city having a full-time city prosecutor with the consent of the district attorney.(4) The Civil Rights Department.(5) The Labor Commissioner with respect to employment-related decisions only.(b) A court may award a prevailing plaintiff who brings an action pursuant to subdivision (a) all of the following:(1) Injunctive relief.(2) Declaratory relief.(3) Reasonable attorneys fees and litigation costs.(4) A civil penalty of up to twenty-five thousand dollars ($25,000) per violation.(c) A developer or deployer who contracts with a third party to perform the developers or deployers duties under this chapter, other than those duties related to auditing, is subject to liability under this chapter for the third partys failure to perform those duties.22756.6. (a) This chapter does not apply to an automated decision system the sole purpose of which is to do either of the following:(1) Detect, protect against, or respond to cybersecurity incidents or preserve the integrity or security of computer systems.(2) Operate aircraft in the national airspace.(b) The use of a consumer credit score to inform a consequential decision does not itself create an obligation under this chapter.22756.7. (a) The rights, remedies, and penalties established by this chapter are cumulative and shall not be construed to supersede the rights, remedies, or penalties established under other laws, including, but not limited to, Chapter 6 (commencing with Section 12940) of Part 2.8 of Division 3 of Title 2 of the Government Code and Section 51 of the Civil Code.(b) This chapter does not diminish the rights, privileges, or remedies of an employee under any other federal or state law or under any employment contract or collective bargaining agreement.(c) This chapter does not authorize any use of automated decision systems that is limited, restricted, or prohibited under any other applicable law.(d) This chapter does not authorize disparate impacts or disparate treatment limited, restricted, or prohibited under any other applicable law.
70+ CHAPTER 24.6. Automated Decisions Safety Act22756. As used in this chapter:(a) Artificial intelligence means an engineered or machine-based system that varies in its level of autonomy and that can, for explicit or implicit objectives, infer from the input it receives how to generate outputs that can influence physical or virtual environments.(b) (1) Automated decision system means a computational process derived from machine learning, statistical modeling, data analytics, or artificial intelligence that issues simplified output, including a score, classification, or recommendation, that is designed or used to assist or replace human discretionary decisionmaking and materially impacts natural persons.(2) Automated decision system does not mean a spam email filter, firewall, antivirus software, identity and access management tool, calculator, database, dataset, or other compilation of data.(c) Consequential decision means a decision that materially impacts the cost, terms, quality, or accessibility of any of the following to a natural person:(1) Employment-related decisions.(2) Education and vocational training as they relate to any of the following:(A) Assessment and placement.(B) Detecting student cheating and plagiarism.(C) Accreditation.(D) Certification.(E) Admissions and enrollment.(F) Discipline.(G) Evaluation.(H) Financial aid and scholarships.(I) Proctoring.(3) Housing and lodging as they relate to any of the following:(A) Rental or short-term housing and lodging.(B) Home appraisals.(C) Rental subsidies.(D) Publicly supported housing.(4) Any of the following essential utilities:(A) Electricity.(B) Heat.(C) Water.(D)Internet and telecommunications access.(E)(D) Transportation.(F)(E) Municipal trash and sewage services.(5) Family planning, adoption services, reproductive services, and assessments related to child protective services.(6) Health care and health insurance, including mental health care, dental, and vision.(7) Financial services, including a financial service provided by a mortgage company, mortgage broker, or creditor.(8) The criminal justice system with respect to pretrial release, sentencing, and alternatives to incarceration.(9) Legal services.(10) Private arbitration.(11) Mediation.(12) Elections as they relate to any of the following:(A) Voting.(B) Redistricting.(C) Voter eligibility and registration.(D) Distribution of voting information.(E) Election administration.(13) Access to government benefits or services or assignment of penalties by a government entity.(14) Places of public accommodation, as defined in Section 55.52 of the Civil Code.(15) Insurance.(16) Internet and telecommunications access.(d) Covered automated decision system or covered ADS means an automated decision system that makes or facilitates is designed or used to make or facilitate a consequential decision.(e) Credit score means a credit score, as defined in Section 1785.15.1 of the Civil Code, from a consumer credit reporting agency, as defined in Section 1785.3 of the Civil Code.(e)(f) Deployer means a person, partnership, state or local government agency, corporation, or developer that uses a covered ADS to make or facilitate a consequential decision, either directly or through by contracting with a third party. party for that purpose.(f)(g) Developer means a person, partnership, state or local government agency, corporation, or deployer that designs, codes, substantially modifies, or otherwise produces an automated decision system that makes or facilitates a consequential decision, either directly or through by contracting with a third party. party for those purposes.(g)(h) (1) Developer-approved use means a deployment context in which a developer intends a covered ADS to make or facilitate a consequential decision.(2) Developer-approved use includes any reasonably foreseeable fine tuning of the covered ADS.(h)(i) Disparate impact means a differential effect on a group of individuals who share a protected characteristic.(i)(j) Disparate treatment means differential treatment of an individual or group of individuals on the basis of a protected characteristic.(j)(k) Employment-related decision means a decision made by an employer, either directly or through a third party, that affects wages, benefits, other compensation, hours, work schedule, performance evaluation, hiring, discipline, promotion, termination, job tasks and responsibilities, assignment of work, access to work and training opportunities, productivity requirements, workplace health and safety, or other terms or conditions of employment.(k)(l) (1) Express consent means an affirmative written authorization that is granted in response to a notice that is all of the following:(A) Clear, meaningful, and prominent.(B) Conveyed in a manner that a natural person would notice and understand it.(C) Not contained within a more general notice, agreement, or set of terms and conditions.(2) Express consent does not mean an authorization that is either of the following:(A) Inferred from inaction.(B) Obtained through the use of a dark pattern, as defined in Section 56.18 of the Civil Code.(l)(m) Fine-tune means to adjust the model parameters of an automated decision system through exposure to additional data.(m)(n) Labor Commissioner means Chief of the Division of Labor Standards Enforcement.(n)(o) Personal information has the same meaning as defined in Section 1798.140 of the Civil Code.(o)(p) Protected characteristic means a characteristic listed in subdivision (b) of Section 51 of the Civil Code.(p)(q) (1) Substantial modification means a new version, release, update, or other modification to a covered ADS that materially changes its uses or outputs.(2) Substantial modification does not mean a modification that results from fine tuning.(q)(r) Trade secret has the same meaning as in Section 3426.1 of the Civil Code.22756.1. (a) (1) With respect to a covered ADS that was first deployed, or made available to potential deployers, before January 1, 2026, the developer of the covered ADS shall conduct an initial performance evaluation on the covered ADS before January 1, 2027, and shall additionally conduct a performance evaluation on the covered ADS under any of the following circumstances:(A) Following any substantial modification of the covered ADS by the developer.(B) Following any fine tuning of the covered ADS by the developer that materially changes the uses or outputs of the covered ADS.(C) No more than one year after the developer last conducted a performance evaluation on the covered ADS, for as long as the developer deploys the covered ADS or makes the covered ADS available to potential deployers.(2) With respect to a covered ADS that is first deployed or made available to potential deployers on or after January 1, 2026, the developer of the covered ADS shall conduct a performance evaluation on the covered ADS under any of the following circumstances:(A) Before initially deploying the covered ADS or making the covered ADS available to potential deployers.(B) Following any substantial modification of the covered ADS by the developer.(C) Following any fine tuning of the covered ADS by the developer that materially changes the uses or outputs of the covered ADS.(D) No more than one year after the developer last conducted a performance evaluation on the covered ADS, for as long as the developer deploys the covered ADS or makes the covered ADS available to potential deployers.(b) In conducting a performance evaluation on a covered ADS, a developer shall do all of the following:(1) Describe the purpose of the covered ADS.(2) List and describe all developer-approved uses of the covered ADS.(3) For each developer-approved use, assess evaluate the expected performance of the covered ADS and document all of the following:(A) The expected accuracy and reliability of the covered ADS.(B) Any reasonably foreseeable effects of fine tuning on the accuracy and reliability of the covered ADS.(4)For each developer-approved use, assess whether(C) Whether any disparate treatment is intended to occur and document and, if so, all of the following:(A)Whether the covered ADS is intended to treat individuals or groups of individuals differently on the basis of a protected characteristic.(B)For each disparate treatment identified under subparagraph (A), describe all of the following:(i) The conditions under which the each disparate treatment is intended to occur.(ii) Whether the each disparate treatment is necessary for a developer-approved use.(iii) Whether any alternatives not involving disparate treatment were considered.(C)(D) Any reasonably foreseeable effects of fine tuning on disparate treatment.(5)For each developer-approved use, assess whether (E) Whether any disparate impacts are reasonably likely to occur and document and, if so, all of the following:(A)Whether the covered ADS is reasonably likely to treat groups of individuals who share a protected characteristic differently.(B)For each disparate impact identified under subparagraph (A), describe all of the following:(i) The conditions under which that each disparate impact is reasonably likely to occur.(ii) Whether the each disparate impact is necessary for a developer-approved use.(iii) Whether any alternatives not involving disparate impacts were considered.(C)(F) Whether any measures have been taken by the developer to mitigate the risk of unanticipated disparate impacts resulting from the use of the covered ADS.(D)(G) With respect to a covered ADS that has been deployed, whether any unanticipated disparate impacts have been reported to the developer by a deployer, and whether the developer has taken any measures to mitigate those disparate impacts.(E)(H) Any reasonably foreseeable effects of fine tuning on disparate impacts.(6)(4) (A) Contract with an independent third-party auditor to assess the developers compliance with this subdivision.(B) (i) Except pursuant to clause (ii), a developer that contracts with an auditor pursuant to this paragraph shall provide the auditor with any available information that is reasonably necessary for the auditor to comprehensively assess developer compliance.(ii) A developer that provides documentation to an auditor pursuant to this subparagraph may make reasonable redactions for the purpose of protecting trade secrets. To the extent that a developer withholds information, the developer shall notify the auditor and provide a basis for the withholding.(C) If the deadline for conducting a performance evaluation pursuant to subdivision (a) elapses before the audit has been completed, a developer shall not deploy the covered ADS or make the covered ADS available to potential deployers until the audit has been completed.(I) A developer that receives feedback from an auditor pursuant to this paragraph shall do both of the following:(i) Consider and attempt to incorporate that feedback into the development of any subsequent version of a covered ADS.(ii) Make a high-level summary of the feedback publicly available at no cost to users of the developers internet website.(c) (1) A developer that sells, licenses, or otherwise transfers a covered ADS to a potential deployer shall provide the deployer with all of the following:(A) The results of the most recent performance evaluation conducted on the covered ADS by the developer pursuant to this chapter.(B) For each developer-approved use of the covered ADS, instructions explaining how the covered ADS should be used by the deployer to make or facilitate a consequential decision.(C) For each developer-approved use of the covered ADS, a description of whether and under what circumstances the covered ADS can be fine-tuned.(D) An explanation of the deployers responsibilities under this chapter, including a description of any circumstances under which the deployer would assume the responsibilities of a developer pursuant to subdivision (h) of Section 22756.2.(E) (i) Any technical information necessary for the deployer to comply with this chapter.(ii) A developer shall not be required to provide additional technical information to a deployer that has assumed the responsibilities of a developer pursuant to subdivision (h) of Section 22756.2.(2) (A) A developer that provides documentation to a potential deployer pursuant to this subdivision may make reasonable redactions for the purpose of protecting trade secrets.(B) To the extent that a developer withholds information pursuant to subparagraph (A), the developer shall notify the deployer and provide a basis for the withholding.(d) A developer that receives an impact assessment from an auditor of a deployed covered ADS pursuant to subdivision (b) of Section 22756.3 shall provide all of the following information to any deployer of the covered ADS:(A) Any material differences between the expected accuracy of the covered ADS and the observed accuracy of the covered ADS and the deployment conditions under which those differences are reasonably likely to occur.(B) Any material differences between the expected reliability of the covered ADS and the observed reliability of the covered ADS and the deployment conditions under which those differences are reasonably likely to occur.(C) Any unanticipated disparate impacts resulting from the use of the covered ADS and the deployment conditions under which those disparate impacts are reasonably likely to occur.(D) An explanation of any steps the deployer can take to mitigate these discrepancies.(e) A developer that receives feedback from an auditor pursuant to this chapter shall consider and attempt to incorporate that feedback into the development of any subsequent version of a covered ADS.(f) A developer that provides documentation to a deployer pursuant to this section shall ensure the documentation is all of the following:(A) Transmitted directly to the deployer or otherwise made available in a manner reasonably calculated to ensure the deployer receives the documentation.(B) Provided in English and in any other language the developer regularly uses to communicate with deployers.(C) Presented in a manner that ensures the communication clearly and effectively conveys the required information to the deployer.(g) A developer that deploys a covered ADS or makes a covered ADS available to potential deployers shall maintain all of the following documentation in an unredacted format for as long as the covered ADS remains deployed or developer deploys the covered ADS or makes the covered ADS available to potential deployers plus 10 years:(1) The results of any performance evaluations conducted on the covered ADS pursuant to this chapter.(2) Any documentation provided to deployers pursuant to this chapter.(3) Any documentation provided to, or received from, auditors pursuant to this chapter.(4) Records of any redactions made pursuant to this chapter.(h) It is unlawful to advertise to consumers in the state that a covered ADS is capable of performing in a manner not substantiated by the results of the most recent performance evaluation conducted on the covered ADS.(i) (1) A developer that deploys a covered ADS or makes a covered ADS available to potential deployers shall designate at least one employee to oversee the developers compliance with this chapter.(2) A developer shall require an employee designated pursuant to this subdivision to conduct a prompt and comprehensive review of any credible compliance issue raised to that employee.22756.2. (a) (1) Except as provided in paragraph (2), before finalizing a deployer finalizes a consequential decision made or facilitated by a covered ADS, a the deployer shall provide any subject of that decision with a plain language written disclosure containing all of the following information:(A) A statement informing the subject that a covered ADS will be used to make or facilitate the consequential decision.(B) The name, version number, and developer of the covered ADS.(C) Whether the deployers use of the covered ADS is within the scope of a developer-approved use and a description of that use.(D) (i) The personal characteristics or attributes of the subject that the covered ADS measures or assesses to make or facilitate the consequential decision.(ii) The sources of personal information collected from the subject to make or facilitate the consequential decision.(iii) Any key parameters known to disproportionately affect the outcome of the consequential decision.(E) The structure and format of the outputs of the covered ADS and a plain language description of how those outputs are used to make or facilitate the consequential decision.(F) Whether a natural person will review either of the following before the consequential decision is finalized:(i) The outputs of the covered ADS.(ii) The outcome of the consequential decision.(G) The subjects rights under subdivisions (b) and (c) (d) and the means and timeframe for exercising those rights.(H) (i) Contact information for the deployer.(ii) Contact information for the entity that manages the covered ADS, if that entity is not the deployer.(iii) Contact information for the entity that will interpret the results of the covered ADS, if that entity is not the deployer.(2) Paragraph (1) does not apply if the subject of the consequential decision is having a medical emergency.(b) (1) Before finalizing a deployer finalizes a consequential decision made or facilitated by a covered ADS, a the deployer shall provide any subject of that decision with a reasonable opportunity to opt out of the use of the covered ADS.(2) (A) A deployer may deny a request to opt out of the use of a covered ADS if either of the following is true:(i) The deployer is subject to the federal Gramm-Leach-Bliley Act, and the covered ADS makes or facilitates a consequential decision pursuant to paragraph (7) of subdivision (c) of Section 22756.(ii) The subject of the consequential decision is having a medical emergency.(B) A deployer that denies a request to opt out of the use of a covered ADS pursuant to subparagraph (A) shall provide the subject with an explanation of the basis for the denial.(c) (1) After a deployer finalizes a consequential decision is finalized, made or facilitated by a covered ADS, the deployer shall provide any subject of that decision witha plain language written disclosure shall be provided containing all of the following information within five days, and the disclosure shall include all of the information: days:(A) The personal characteristics or attributes of the subject that the covered ADS measured or assessed used to make or facilitate the consequential decision.(B) The sources of personal information collected from the subject that were used to make or facilitate the consequential decision.(C) Any key parameters that disproportionately affected the outcome of the consequential decision.(D) The structure and format of the outputs of the covered ADS and a plain language description of how those outputs were used to make or facilitate the consequential decision.(E) The role that the ADS played in making the consequential decision and whether any human judgment was involved.(F) Contact information for the deployer.(G) Contact information for the entity that manages the covered ADS, if that entity is not the deployer.(H) Contact information for the entity that will interpret the results of the covered ADS, if that entity is not the deployer.(I) The subjects rights under subdivision (d) and the means and timeframe for exercising those rights.(2) Paragraph (1) is does not applicable apply if the subject of the consequential decision is having a medical emergency.(3) A deployer that provides documentation to a subject of a consequential decision pursuant to this subdivision shall ensure the documentation is all of the following:(A) Transmitted directly to the subject.(B) Provided in English and in any other language that the deployer regularly uses to communicate with subjects.(C) Made available in formats that are accessible to people who are blind or have other disabilities.(D) Presented in a manner that ensures the communication clearly and effectively conveys the required information to the subject.(d) After finalizing a deployer finalizes a consequential decision made or facilitated by a covered ADS, a the deployer shall provide any subject of that decision with an opportunity to do both of the following within 30 business days:(1) (A) Correct any incorrect personal information used by the covered ADS to make or facilitate the consequential decision.(B) A deployer shall comply with a request to correct personal information within 30 business days of receiving the request if the request is accompanied by documentation sufficient to assess the basis for the request.(C) (i) If a deployer determines that complying with a request to correct personal information would change the outcome of the consequential decision, the deployer shall, within 30 days of making the determination, rectify the decision.(ii) If a deployer determines that complying with a request to correct personal information would not change the outcome of the consequential decision, the deployer shall, within 30 days of making the determination, inform the subject that the correction was made but that it did not alter the decision.(D) A deployer that denies a request to correct personal information shall do both of the following:(i) Provide the subject with an explanation of the basis for the denial.(ii) Provide the subject with a reasonable opportunity to request that the deployer delete the subjects personal information.(2) (A) Appeal the outcome of the consequential decision.(B) A deployer shall review a request to appeal a consequential decision within 30 business days of receiving the request. request if the request is accompanied by documentation sufficient to assess the basis for the request.(C) (i) If a deployer determines that the original decision is was incorrect, the deployer shall, within 30 days of making the determination, rectify the decision.(ii) If a deployer determines that the original decision is was correct, the deployer shall, within 30 days of making the determination, inform the subject that the consequential decision will not be altered.(D) A deployer that denies a request to appeal the outcome of a consequential decision shall provide the subject with an explanation of the basis for the denial.(e) (1) (A) A deployer that provides documentation to the subject of a consequential decision pursuant to this section may make reasonable redactions for the purpose of protecting trade secrets.(B) To the extent that a deployer withholds information pursuant to paragraph (1), the deployer shall notify the subject and provide a basis for the withholding.(2) A deployer that is required by another state or federal law to provide substantially similar notice to a subject of a consequential decision need not duplicatively provide notice to the subject under this section.(f) A deployers collection, use, retention, and sharing of personal information from a subject of a consequential decision shall be reasonably necessary and proportionate to achieve the purposes for which the personal information was collected and processed, or for another disclosed purpose that is compatible with the context in which the personal information was collected, and not further processed in a manner that is incompatible with those purposes.(g) (1) A deployer that uses a covered ADS to make or facilitate consequential decisions directly impacting more than 5999 5,999 people in a given three-year period shall contract with an independent third-party auditor to conduct an impact assessment on the covered ADS before January 1, 2030, and every three years thereafter.(2) (A) Except pursuant to subparagraph (B), a deployer that contracts with an auditor pursuant to this subdivision shall provide the auditor with any available information that is reasonably necessary for the auditor to conduct a comprehensive impact assessment on the covered ADS.(B) A deployer that provides documentation to an auditor pursuant to this paragraph may make reasonable redactions for the purpose of protecting trade secrets. To the extent that a deployer withholds information, the developer shall notify the auditor and provide a basis for the withholding.(C) This paragraph shall not be construed to require a deployer to collect any personal information from a subject of a consequential decision beyond that which the deployer collects in the ordinary course of business or as necessary to comply with state or federal law.(3) If the deadline for conducting an audit pursuant to paragraph (1) elapses before the audit has been completed, a deployer shall not use the covered ADS to make or facilitate consequential decisions until the audit has been completed.(h) A deployer that does any of the following assumes the responsibilities of a developer under this chapter:(1) Uses a covered ADS to make or facilitate consequential decisions that directly impact more than 5999 5,999 people in a given three-year period, if the deployer did not receive any documentation from the developer of the covered ADS pursuant to subdivision (c) of Section 22756.1. 22756.1 during the three-year period.(2) Uses a covered ADS to make or facilitate consequential decisions that directly impact more than 5999 5,999 people in a given three-year period, if the deployers use of the covered ADS is outside the scope of a developer-approved use.(3) Substantially modifies an automated decision system and does either of the following:(A) Uses the substantially modified system to make or facilitate consequential decisions that directly impact more than 5999 people in a given three-year period.(B) Makes the substantially modified system available to potential deployers.(i) A deployer that uses a covered ADS to make or facilitate a consequential decision shall retain the following documentation in an unredacted format for as long as the deployer uses the covered ADS remains deployed plus 10 years:(1) Any documentation received from developers pursuant to this chapter.(2) Any documentation provided pursuant to this section to subjects of consequential decisions made or facilitated by the covered ADS.(3) Any requests to correct personal information made pursuant to this section.(4) Any requests to opt out of the use of the covered ADS made pursuant to this section.(5) Any requests to appeal the outcome of a consequential decision made pursuant to this section.(6) Any documentation provided to, or received from, auditors pursuant to this chapter.(7) Records of any redactions made pursuant to this section.(j) (1) A deployer that uses a covered ADS to make or facilitate a consequential decision shall designate at least one employee to oversee the deployers compliance with this chapter.(2) A deployer shall require an employee designated pursuant to this subdivision to conduct a prompt and comprehensive review of any credible compliance issue related to the deployers use of a covered ADS that is raised to that employee.(k) In addition to the requirements of this section, a deployer that is a business subject to the California Consumer Privacy Act of 2018 (Title 1.81.5 (commencing with Section 1798.100)) is subject to any privacy-related opt-out and access regulation duly adopted by the California Privacy Protection Agency pursuant to subdivision (b) of Section 1798.199.40 of the Civil Code.(l) This section shall become operative on January 1, 2027.22756.3. (a) An auditor that conducts an impact assessment on a covered ADS pursuant to subdivision (g) of Section 22756.2 shall do all of the following:(1) (A) Request any information from the deployer of the covered ADS that is reasonably necessary for the auditor to conduct a comprehensive impact assessment.(B) This paragraph applies only to information gathered by the deployer in the ordinary course of business.(2)Document all developer-approved uses of the covered ADS that the deployer utilized during the relevant period.(3)(2) For each unique developer-approved use, use of the covered ADS by the deployer, document all of the following:(A) The observed accuracy and reliability of the covered ADS over the relevant period.(B) Whether the observed accuracy and reliability differed materially from the expected accuracy and reliability of the covered ADS, as described in documentation provided by a developer to the deployer pursuant to this chapter.(C) Whether any disparate impacts resulted from the deployers use of the covered ADS and the deployment conditions under which those disparate impacts occurred.(D) Whether each disparate impact was an anticipated disparate impact, as described in documentation provided to the deployer pursuant to this chapter.(4)(3) Whether the deployer used the covered ADS to make or facilitate a consequential decision outside of the scope of a developer-approved use.(5)(4) Whether the deployer assumed the responsibilities of a developer pursuant to subdivision (h) of Section 22756.2.(b) (1) After conducting an impact assessment on a covered ADS, an auditor shall provide the results of the impact assessment to do both of the following:(A) The Provide the results of the impact assessment to the deployer that contracted with the auditor to perform the impact assessment.(B)The developer of the covered ADS.(B) Make a high-level summary of the results of the impact assessment publicly available at no cost to users of the auditors internet website.(2) The documentation required by this section shall be both of the following:(A) Provided in English and in any other language that the auditor regularly uses to communicate with developers and deployers.(B) Presented in a manner that ensures the communication clearly and effectively conveys the required information to the developer and deployer. information.(3) An auditor shall not provide a developer make publicly available with the personal information of a subject of a consequential decision made or facilitated by a covered ADS without first obtaining the express consent of the subject.22756.4. (a) (1) Within 30 days of receiving a request from the Attorney General for a performance evaluation or impact assessment prepared pursuant to this chapter, a developer, deployer, or auditor of a covered ADS shall provide an unredacted copy of the document to the Attorney General.(2) The Attorney General may share performance evaluations and impact assessments with other enforcement entities as necessary for enforcement purposes.(b) (1) The disclosure or sharing of a performance evaluation or impact assessment pursuant to subdivision (a) does not constitute a waiver of any attorney-client privilege, work-product protection, or trade secret protection that might otherwise exist with respect to any information contained in the performance evaluation or impact assessment.(2) A performance evaluation or impact assessment disclosed or shared pursuant to subdivision (a) is exempt from the California Public Records Act (Division 10 (commencing with Section 7920.000) of Title 1 of the Government Code).(c) Each day a covered ADS is used for which a performance evaluation or impact assessment has not been submitted to the Attorney General pursuant to this section is an additional violation of this section.22756.5. (a) Any of the following public entities may bring a civil action against a developer or deployer developer, deployer, or auditor who violates this chapter:(1) The Attorney General.(2) A district attorney, county counsel, or city attorney for the jurisdiction in which the violation occurred.(3) A city prosecutor in any city having a full-time city prosecutor with the consent of the district attorney.(4) The Civil Rights Department.(5) The Labor Commissioner with respect to employment-related decisions only.(b) A court may award a prevailing plaintiff who brings an action pursuant to subdivision (a) all of the following:(1) Injunctive relief.(2) Declaratory relief.(3) Reasonable attorneys fees and litigation costs.(4) A civil penalty of up to twenty-five thousand dollars ($25,000) per violation.(c) A developer or deployer who contracts with a third party to perform the developers or deployers duties under this chapter, other than those duties related to auditing, is subject to liability under this chapter for the third partys failure to perform those duties.22756.6. (a) This chapter does not apply to an automated decision system the sole purpose of which is to do either of the following:(a)(1) Detect, protect against, or respond to cybersecurity incidents or preserve the integrity or security of computer systems.(b)(2) Operate aircraft in the national airspace.(b) The use of a consumer credit score to inform a consequential decision does not itself create an obligation under this chapter.22756.7. (a) The rights, remedies, and penalties established by this chapter are cumulative and shall not be construed to supersede the rights, remedies, or penalties established under other laws, including, but not limited to, Chapter 6 (commencing with Section 12940) of Part 2.8 of Division 3 of Title 2 of the Government Code and Section 51 of the Civil Code.(b) This chapter does not diminish the rights, privileges, or remedies of an employee under any other federal or state law or under any employment contract or collective bargaining agreement.(c) This chapter does not authorize any use of automated decision systems that is limited, restricted, or prohibited under any other applicable law.(d) This chapter does not authorize disparate impacts or disparate treatment that are limited, restricted, or prohibited under any other applicable law.22756.8.A developer or deployer who contracts with a third party to comply with duties required under this chapter, other than those duties related to auditing, is subject to liability under this chapter for the third partys failure to comply with this chapter.
7271
7372 CHAPTER 24.6. Automated Decisions Safety Act
7473
7574 CHAPTER 24.6. Automated Decisions Safety Act
7675
77-##### CHAPTER 24.6. Automated Decisions Safety Act
76+22756. As used in this chapter:(a) Artificial intelligence means an engineered or machine-based system that varies in its level of autonomy and that can, for explicit or implicit objectives, infer from the input it receives how to generate outputs that can influence physical or virtual environments.(b) (1) Automated decision system means a computational process derived from machine learning, statistical modeling, data analytics, or artificial intelligence that issues simplified output, including a score, classification, or recommendation, that is designed or used to assist or replace human discretionary decisionmaking and materially impacts natural persons.(2) Automated decision system does not mean a spam email filter, firewall, antivirus software, identity and access management tool, calculator, database, dataset, or other compilation of data.(c) Consequential decision means a decision that materially impacts the cost, terms, quality, or accessibility of any of the following to a natural person:(1) Employment-related decisions.(2) Education and vocational training as they relate to any of the following:(A) Assessment and placement.(B) Detecting student cheating and plagiarism.(C) Accreditation.(D) Certification.(E) Admissions and enrollment.(F) Discipline.(G) Evaluation.(H) Financial aid and scholarships.(I) Proctoring.(3) Housing and lodging as they relate to any of the following:(A) Rental or short-term housing and lodging.(B) Home appraisals.(C) Rental subsidies.(D) Publicly supported housing.(4) Any of the following essential utilities:(A) Electricity.(B) Heat.(C) Water.(D)Internet and telecommunications access.(E)(D) Transportation.(F)(E) Municipal trash and sewage services.(5) Family planning, adoption services, reproductive services, and assessments related to child protective services.(6) Health care and health insurance, including mental health care, dental, and vision.(7) Financial services, including a financial service provided by a mortgage company, mortgage broker, or creditor.(8) The criminal justice system with respect to pretrial release, sentencing, and alternatives to incarceration.(9) Legal services.(10) Private arbitration.(11) Mediation.(12) Elections as they relate to any of the following:(A) Voting.(B) Redistricting.(C) Voter eligibility and registration.(D) Distribution of voting information.(E) Election administration.(13) Access to government benefits or services or assignment of penalties by a government entity.(14) Places of public accommodation, as defined in Section 55.52 of the Civil Code.(15) Insurance.(16) Internet and telecommunications access.(d) Covered automated decision system or covered ADS means an automated decision system that makes or facilitates is designed or used to make or facilitate a consequential decision.(e) Credit score means a credit score, as defined in Section 1785.15.1 of the Civil Code, from a consumer credit reporting agency, as defined in Section 1785.3 of the Civil Code.(e)(f) Deployer means a person, partnership, state or local government agency, corporation, or developer that uses a covered ADS to make or facilitate a consequential decision, either directly or through by contracting with a third party. party for that purpose.(f)(g) Developer means a person, partnership, state or local government agency, corporation, or deployer that designs, codes, substantially modifies, or otherwise produces an automated decision system that makes or facilitates a consequential decision, either directly or through by contracting with a third party. party for those purposes.(g)(h) (1) Developer-approved use means a deployment context in which a developer intends a covered ADS to make or facilitate a consequential decision.(2) Developer-approved use includes any reasonably foreseeable fine tuning of the covered ADS.(h)(i) Disparate impact means a differential effect on a group of individuals who share a protected characteristic.(i)(j) Disparate treatment means differential treatment of an individual or group of individuals on the basis of a protected characteristic.(j)(k) Employment-related decision means a decision made by an employer, either directly or through a third party, that affects wages, benefits, other compensation, hours, work schedule, performance evaluation, hiring, discipline, promotion, termination, job tasks and responsibilities, assignment of work, access to work and training opportunities, productivity requirements, workplace health and safety, or other terms or conditions of employment.(k)(l) (1) Express consent means an affirmative written authorization that is granted in response to a notice that is all of the following:(A) Clear, meaningful, and prominent.(B) Conveyed in a manner that a natural person would notice and understand it.(C) Not contained within a more general notice, agreement, or set of terms and conditions.(2) Express consent does not mean an authorization that is either of the following:(A) Inferred from inaction.(B) Obtained through the use of a dark pattern, as defined in Section 56.18 of the Civil Code.(l)(m) Fine-tune means to adjust the model parameters of an automated decision system through exposure to additional data.(m)(n) Labor Commissioner means Chief of the Division of Labor Standards Enforcement.(n)(o) Personal information has the same meaning as defined in Section 1798.140 of the Civil Code.(o)(p) Protected characteristic means a characteristic listed in subdivision (b) of Section 51 of the Civil Code.(p)(q) (1) Substantial modification means a new version, release, update, or other modification to a covered ADS that materially changes its uses or outputs.(2) Substantial modification does not mean a modification that results from fine tuning.(q)(r) Trade secret has the same meaning as in Section 3426.1 of the Civil Code.
7877
79-22756. As used in this chapter:(a) Artificial intelligence means an engineered or machine-based system that varies in its level of autonomy and that can, for explicit or implicit objectives, infer from the input it receives how to generate outputs that can influence physical or virtual environments.(b) (1) Automated decision system means a computational process derived from machine learning, statistical modeling, data analytics, or artificial intelligence that issues simplified output, including a score, classification, or recommendation, that is designed or used to assist or replace human discretionary decisionmaking and materially impacts natural persons.(2) Automated decision system does not mean a spam email filter, firewall, antivirus software, identity and access management tool, calculator, database, dataset, or other compilation of data.(c) Consequential decision means a decision that materially impacts the cost, terms, quality, or accessibility of any of the following to a natural person:(1) Employment-related decisions.(2) Education and vocational training as they relate to any of the following:(A) Assessment and placement.(B) Detecting student cheating and plagiarism.(C) Accreditation.(D) Certification.(E) Admissions and enrollment.(F) Discipline.(G) Evaluation.(H) Financial aid and scholarships.(I) Proctoring.(3) Housing and lodging as they relate to any of the following:(A) Rental or short-term housing and lodging.(B) Home appraisals.(C) Rental subsidies.(D) Publicly supported housing.(4) Any of the following essential utilities:(A) Electricity.(B) Heat.(C) Water.(D) Transportation.(E) Municipal trash and sewage services.(5) Family planning, adoption services, reproductive services, and assessments related to child protective services.(6) Health care and health insurance, including mental health care, dental, and vision.(7) Financial services, including a financial service provided by a mortgage company, mortgage broker, or creditor.(8) The criminal justice system with respect to pretrial release, sentencing, and alternatives to incarceration.(9) Legal services.(10) Private arbitration.(11) Mediation.(12) Elections as they relate to any of the following:(A) Voting.(B) Redistricting.(C) Voter eligibility and registration.(D) Distribution of voting information.(E) Election administration.(13) Access to government benefits or services or assignment of penalties by a government entity.(14) Places of public accommodation, as defined in Section 55.52 of the Civil Code.(15) Insurance.(16) Internet and telecommunications access.(d) Covered automated decision system or covered ADS means an automated decision system that is designed or used to make or facilitate a consequential decision.(e) Credit score means a credit score, as defined in Section 1785.15.1 of the Civil Code, from a consumer credit reporting agency, as defined in Section 1785.3 of the Civil Code.(f) Deployer means a person, partnership, state or local government agency, corporation, or developer that uses a covered ADS to make or facilitate a consequential decision, either directly or by contracting with a third party for that purpose.(g) Developer means a person, partnership, state or local government agency, corporation, or deployer that designs, codes, substantially modifies, or otherwise produces an automated decision system that makes or facilitates a consequential decision, either directly or by contracting with a third party for those purposes.(h) (1) Developer-approved use means a deployment context in which a developer intends a covered ADS to make or facilitate a consequential decision.(2) Developer-approved use includes any reasonably foreseeable fine tuning of the covered ADS.(i) Disparate impact means a differential effect on a group of individuals who share a protected characteristic.(j) Disparate treatment means differential treatment of an individual or group of individuals on the basis of a protected characteristic.(k) Employment-related decision means a decision made by an employer, either directly or through a third party, that affects wages, benefits, other compensation, hours, work schedule, performance evaluation, hiring, discipline, promotion, termination, job tasks and responsibilities, assignment of work, access to work and training opportunities, productivity requirements, workplace health and safety, or other terms or conditions of employment.(l) (1) Express consent means an affirmative written authorization that is granted in response to a notice that is all of the following:(A) Clear, meaningful, and prominent.(B) Conveyed in a manner that a natural person would notice and understand it.(C) Not contained within a more general notice, agreement, or set of terms and conditions.(2) Express consent does not mean an authorization that is either of the following:(A) Inferred from inaction.(B) Obtained through the use of a dark pattern, as defined in Section 56.18 of the Civil Code.(m) Fine-tune means to adjust the model parameters of an automated decision system through exposure to additional data.(n) Labor Commissioner means Chief of the Division of Labor Standards Enforcement.(o) Personal information has the same meaning as defined in Section 1798.140 of the Civil Code.(p) Protected characteristic means a characteristic listed in subdivision (b) of Section 51 of the Civil Code.(q) (1) Substantial modification means a new version, release, update, or other modification to a covered ADS that materially changes its uses or outputs.(2) Substantial modification does not mean a modification that results from fine tuning.(r) Trade secret has the same meaning as in Section 3426.1 of the Civil Code.(s) The definitions of disparate impact and disparate treatment provided in subdivisions (i) and (j) are intended solely for purposes of internal compliance, risk assessment, and documentation required by this chapter. These definitions shall not be construed to modify or supersede any standard, burden of proof, or element of a claim under the Unruh Civil Rights Act (Section 51 of the Civil Code), the California Fair Employment and Housing Act (Part 2.8 (commencing with Section 12900) of Division 3 of Title 2 of the Government Code), Title VII of the Civil Rights Act of 1964 (42 U.S.C. Sec. 2000e et seq.), or any other applicable civil rights law.
78+
8079
8180 22756. As used in this chapter:
82-
83-###### 22756.
8481
8582 (a) Artificial intelligence means an engineered or machine-based system that varies in its level of autonomy and that can, for explicit or implicit objectives, infer from the input it receives how to generate outputs that can influence physical or virtual environments.
8683
8784 (b) (1) Automated decision system means a computational process derived from machine learning, statistical modeling, data analytics, or artificial intelligence that issues simplified output, including a score, classification, or recommendation, that is designed or used to assist or replace human discretionary decisionmaking and materially impacts natural persons.
8885
8986 (2) Automated decision system does not mean a spam email filter, firewall, antivirus software, identity and access management tool, calculator, database, dataset, or other compilation of data.
9087
9188 (c) Consequential decision means a decision that materially impacts the cost, terms, quality, or accessibility of any of the following to a natural person:
9289
9390 (1) Employment-related decisions.
9491
9592 (2) Education and vocational training as they relate to any of the following:
9693
9794 (A) Assessment and placement.
9895
9996 (B) Detecting student cheating and plagiarism.
10097
10198 (C) Accreditation.
10299
103100 (D) Certification.
104101
105102 (E) Admissions and enrollment.
106103
107104 (F) Discipline.
108105
109106 (G) Evaluation.
110107
111108 (H) Financial aid and scholarships.
112109
113110 (I) Proctoring.
114111
115112 (3) Housing and lodging as they relate to any of the following:
116113
117114 (A) Rental or short-term housing and lodging.
118115
119116 (B) Home appraisals.
120117
121118 (C) Rental subsidies.
122119
123120 (D) Publicly supported housing.
124121
125122 (4) Any of the following essential utilities:
126123
127124 (A) Electricity.
128125
129126 (B) Heat.
130127
131128 (C) Water.
132129
130+(D)Internet and telecommunications access.
131+
132+
133+
134+(E)
135+
136+
137+
133138 (D) Transportation.
139+
140+(F)
141+
142+
134143
135144 (E) Municipal trash and sewage services.
136145
137146 (5) Family planning, adoption services, reproductive services, and assessments related to child protective services.
138147
139148 (6) Health care and health insurance, including mental health care, dental, and vision.
140149
141150 (7) Financial services, including a financial service provided by a mortgage company, mortgage broker, or creditor.
142151
143152 (8) The criminal justice system with respect to pretrial release, sentencing, and alternatives to incarceration.
144153
145154 (9) Legal services.
146155
147156 (10) Private arbitration.
148157
149158 (11) Mediation.
150159
151160 (12) Elections as they relate to any of the following:
152161
153162 (A) Voting.
154163
155164 (B) Redistricting.
156165
157166 (C) Voter eligibility and registration.
158167
159168 (D) Distribution of voting information.
160169
161170 (E) Election administration.
162171
163172 (13) Access to government benefits or services or assignment of penalties by a government entity.
164173
165174 (14) Places of public accommodation, as defined in Section 55.52 of the Civil Code.
166175
167176 (15) Insurance.
168177
169178 (16) Internet and telecommunications access.
170179
171-(d) Covered automated decision system or covered ADS means an automated decision system that is designed or used to make or facilitate a consequential decision.
180+(d) Covered automated decision system or covered ADS means an automated decision system that makes or facilitates is designed or used to make or facilitate a consequential decision.
172181
173182 (e) Credit score means a credit score, as defined in Section 1785.15.1 of the Civil Code, from a consumer credit reporting agency, as defined in Section 1785.3 of the Civil Code.
174183
175-(f) Deployer means a person, partnership, state or local government agency, corporation, or developer that uses a covered ADS to make or facilitate a consequential decision, either directly or by contracting with a third party for that purpose.
184+(e)
176185
177-(g) Developer means a person, partnership, state or local government agency, corporation, or deployer that designs, codes, substantially modifies, or otherwise produces an automated decision system that makes or facilitates a consequential decision, either directly or by contracting with a third party for those purposes.
186+
187+
188+(f) Deployer means a person, partnership, state or local government agency, corporation, or developer that uses a covered ADS to make or facilitate a consequential decision, either directly or through by contracting with a third party. party for that purpose.
189+
190+(f)
191+
192+
193+
194+(g) Developer means a person, partnership, state or local government agency, corporation, or deployer that designs, codes, substantially modifies, or otherwise produces an automated decision system that makes or facilitates a consequential decision, either directly or through by contracting with a third party. party for those purposes.
195+
196+(g)
197+
198+
178199
179200 (h) (1) Developer-approved use means a deployment context in which a developer intends a covered ADS to make or facilitate a consequential decision.
180201
181202 (2) Developer-approved use includes any reasonably foreseeable fine tuning of the covered ADS.
182203
204+(h)
205+
206+
207+
183208 (i) Disparate impact means a differential effect on a group of individuals who share a protected characteristic.
209+
210+(i)
211+
212+
184213
185214 (j) Disparate treatment means differential treatment of an individual or group of individuals on the basis of a protected characteristic.
186215
216+(j)
217+
218+
219+
187220 (k) Employment-related decision means a decision made by an employer, either directly or through a third party, that affects wages, benefits, other compensation, hours, work schedule, performance evaluation, hiring, discipline, promotion, termination, job tasks and responsibilities, assignment of work, access to work and training opportunities, productivity requirements, workplace health and safety, or other terms or conditions of employment.
221+
222+(k)
223+
224+
188225
189226 (l) (1) Express consent means an affirmative written authorization that is granted in response to a notice that is all of the following:
190227
191228 (A) Clear, meaningful, and prominent.
192229
193230 (B) Conveyed in a manner that a natural person would notice and understand it.
194231
195232 (C) Not contained within a more general notice, agreement, or set of terms and conditions.
196233
197234 (2) Express consent does not mean an authorization that is either of the following:
198235
199236 (A) Inferred from inaction.
200237
201238 (B) Obtained through the use of a dark pattern, as defined in Section 56.18 of the Civil Code.
202239
240+(l)
241+
242+
243+
203244 (m) Fine-tune means to adjust the model parameters of an automated decision system through exposure to additional data.
245+
246+(m)
247+
248+
204249
205250 (n) Labor Commissioner means Chief of the Division of Labor Standards Enforcement.
206251
252+(n)
253+
254+
255+
207256 (o) Personal information has the same meaning as defined in Section 1798.140 of the Civil Code.
208257
258+(o)
259+
260+
261+
209262 (p) Protected characteristic means a characteristic listed in subdivision (b) of Section 51 of the Civil Code.
263+
264+(p)
265+
266+
210267
211268 (q) (1) Substantial modification means a new version, release, update, or other modification to a covered ADS that materially changes its uses or outputs.
212269
213270 (2) Substantial modification does not mean a modification that results from fine tuning.
214271
272+(q)
273+
274+
275+
215276 (r) Trade secret has the same meaning as in Section 3426.1 of the Civil Code.
216277
217-(s) The definitions of disparate impact and disparate treatment provided in subdivisions (i) and (j) are intended solely for purposes of internal compliance, risk assessment, and documentation required by this chapter. These definitions shall not be construed to modify or supersede any standard, burden of proof, or element of a claim under the Unruh Civil Rights Act (Section 51 of the Civil Code), the California Fair Employment and Housing Act (Part 2.8 (commencing with Section 12900) of Division 3 of Title 2 of the Government Code), Title VII of the Civil Rights Act of 1964 (42 U.S.C. Sec. 2000e et seq.), or any other applicable civil rights law.
278+22756.1. (a) (1) With respect to a covered ADS that was first deployed, or made available to potential deployers, before January 1, 2026, the developer of the covered ADS shall conduct an initial performance evaluation on the covered ADS before January 1, 2027, and shall additionally conduct a performance evaluation on the covered ADS under any of the following circumstances:(A) Following any substantial modification of the covered ADS by the developer.(B) Following any fine tuning of the covered ADS by the developer that materially changes the uses or outputs of the covered ADS.(C) No more than one year after the developer last conducted a performance evaluation on the covered ADS, for as long as the developer deploys the covered ADS or makes the covered ADS available to potential deployers.(2) With respect to a covered ADS that is first deployed or made available to potential deployers on or after January 1, 2026, the developer of the covered ADS shall conduct a performance evaluation on the covered ADS under any of the following circumstances:(A) Before initially deploying the covered ADS or making the covered ADS available to potential deployers.(B) Following any substantial modification of the covered ADS by the developer.(C) Following any fine tuning of the covered ADS by the developer that materially changes the uses or outputs of the covered ADS.(D) No more than one year after the developer last conducted a performance evaluation on the covered ADS, for as long as the developer deploys the covered ADS or makes the covered ADS available to potential deployers.(b) In conducting a performance evaluation on a covered ADS, a developer shall do all of the following:(1) Describe the purpose of the covered ADS.(2) List and describe all developer-approved uses of the covered ADS.(3) For each developer-approved use, assess evaluate the expected performance of the covered ADS and document all of the following:(A) The expected accuracy and reliability of the covered ADS.(B) Any reasonably foreseeable effects of fine tuning on the accuracy and reliability of the covered ADS.(4)For each developer-approved use, assess whether(C) Whether any disparate treatment is intended to occur and document and, if so, all of the following:(A)Whether the covered ADS is intended to treat individuals or groups of individuals differently on the basis of a protected characteristic.(B)For each disparate treatment identified under subparagraph (A), describe all of the following:(i) The conditions under which the each disparate treatment is intended to occur.(ii) Whether the each disparate treatment is necessary for a developer-approved use.(iii) Whether any alternatives not involving disparate treatment were considered.(C)(D) Any reasonably foreseeable effects of fine tuning on disparate treatment.(5)For each developer-approved use, assess whether (E) Whether any disparate impacts are reasonably likely to occur and document and, if so, all of the following:(A)Whether the covered ADS is reasonably likely to treat groups of individuals who share a protected characteristic differently.(B)For each disparate impact identified under subparagraph (A), describe all of the following:(i) The conditions under which that each disparate impact is reasonably likely to occur.(ii) Whether the each disparate impact is necessary for a developer-approved use.(iii) Whether any alternatives not involving disparate impacts were considered.(C)(F) Whether any measures have been taken by the developer to mitigate the risk of unanticipated disparate impacts resulting from the use of the covered ADS.(D)(G) With respect to a covered ADS that has been deployed, whether any unanticipated disparate impacts have been reported to the developer by a deployer, and whether the developer has taken any measures to mitigate those disparate impacts.(E)(H) Any reasonably foreseeable effects of fine tuning on disparate impacts.(6)(4) (A) Contract with an independent third-party auditor to assess the developers compliance with this subdivision.(B) (i) Except pursuant to clause (ii), a developer that contracts with an auditor pursuant to this paragraph shall provide the auditor with any available information that is reasonably necessary for the auditor to comprehensively assess developer compliance.(ii) A developer that provides documentation to an auditor pursuant to this subparagraph may make reasonable redactions for the purpose of protecting trade secrets. To the extent that a developer withholds information, the developer shall notify the auditor and provide a basis for the withholding.(C) If the deadline for conducting a performance evaluation pursuant to subdivision (a) elapses before the audit has been completed, a developer shall not deploy the covered ADS or make the covered ADS available to potential deployers until the audit has been completed.(I) A developer that receives feedback from an auditor pursuant to this paragraph shall do both of the following:(i) Consider and attempt to incorporate that feedback into the development of any subsequent version of a covered ADS.(ii) Make a high-level summary of the feedback publicly available at no cost to users of the developers internet website.(c) (1) A developer that sells, licenses, or otherwise transfers a covered ADS to a potential deployer shall provide the deployer with all of the following:(A) The results of the most recent performance evaluation conducted on the covered ADS by the developer pursuant to this chapter.(B) For each developer-approved use of the covered ADS, instructions explaining how the covered ADS should be used by the deployer to make or facilitate a consequential decision.(C) For each developer-approved use of the covered ADS, a description of whether and under what circumstances the covered ADS can be fine-tuned.(D) An explanation of the deployers responsibilities under this chapter, including a description of any circumstances under which the deployer would assume the responsibilities of a developer pursuant to subdivision (h) of Section 22756.2.(E) (i) Any technical information necessary for the deployer to comply with this chapter.(ii) A developer shall not be required to provide additional technical information to a deployer that has assumed the responsibilities of a developer pursuant to subdivision (h) of Section 22756.2.(2) (A) A developer that provides documentation to a potential deployer pursuant to this subdivision may make reasonable redactions for the purpose of protecting trade secrets.(B) To the extent that a developer withholds information pursuant to subparagraph (A), the developer shall notify the deployer and provide a basis for the withholding.(d) A developer that receives an impact assessment from an auditor of a deployed covered ADS pursuant to subdivision (b) of Section 22756.3 shall provide all of the following information to any deployer of the covered ADS:(A) Any material differences between the expected accuracy of the covered ADS and the observed accuracy of the covered ADS and the deployment conditions under which those differences are reasonably likely to occur.(B) Any material differences between the expected reliability of the covered ADS and the observed reliability of the covered ADS and the deployment conditions under which those differences are reasonably likely to occur.(C) Any unanticipated disparate impacts resulting from the use of the covered ADS and the deployment conditions under which those disparate impacts are reasonably likely to occur.(D) An explanation of any steps the deployer can take to mitigate these discrepancies.(e) A developer that receives feedback from an auditor pursuant to this chapter shall consider and attempt to incorporate that feedback into the development of any subsequent version of a covered ADS.(f) A developer that provides documentation to a deployer pursuant to this section shall ensure the documentation is all of the following:(A) Transmitted directly to the deployer or otherwise made available in a manner reasonably calculated to ensure the deployer receives the documentation.(B) Provided in English and in any other language the developer regularly uses to communicate with deployers.(C) Presented in a manner that ensures the communication clearly and effectively conveys the required information to the deployer.(g) A developer that deploys a covered ADS or makes a covered ADS available to potential deployers shall maintain all of the following documentation in an unredacted format for as long as the covered ADS remains deployed or developer deploys the covered ADS or makes the covered ADS available to potential deployers plus 10 years:(1) The results of any performance evaluations conducted on the covered ADS pursuant to this chapter.(2) Any documentation provided to deployers pursuant to this chapter.(3) Any documentation provided to, or received from, auditors pursuant to this chapter.(4) Records of any redactions made pursuant to this chapter.(h) It is unlawful to advertise to consumers in the state that a covered ADS is capable of performing in a manner not substantiated by the results of the most recent performance evaluation conducted on the covered ADS.(i) (1) A developer that deploys a covered ADS or makes a covered ADS available to potential deployers shall designate at least one employee to oversee the developers compliance with this chapter.(2) A developer shall require an employee designated pursuant to this subdivision to conduct a prompt and comprehensive review of any credible compliance issue raised to that employee.
218279
219-22756.1. (a) (1) With respect to a covered ADS that was first deployed, or made available to potential deployers, before January 1, 2026, the developer of the covered ADS shall conduct an initial performance evaluation on the covered ADS before January 1, 2027, and shall additionally conduct a performance evaluation on the covered ADS under any of the following circumstances:(A) Following any substantial modification of the covered ADS by the developer.(B) Following any fine tuning of the covered ADS by the developer that materially changes the uses or outputs of the covered ADS.(C) No more than one year after the developer last conducted a performance evaluation on the covered ADS, for as long as the developer deploys the covered ADS or makes the covered ADS available to potential deployers.(2) With respect to a covered ADS that is first deployed or made available to potential deployers on or after January 1, 2026, the developer of the covered ADS shall conduct a performance evaluation on the covered ADS under any of the following circumstances:(A) Before initially deploying the covered ADS or making the covered ADS available to potential deployers.(B) Following any substantial modification of the covered ADS by the developer.(C) Following any fine tuning of the covered ADS by the developer that materially changes the uses or outputs of the covered ADS.(D) No more than one year after the developer last conducted a performance evaluation on the covered ADS, for as long as the developer deploys the covered ADS or makes the covered ADS available to potential deployers.(b) In conducting a performance evaluation on a covered ADS, a developer shall do all of the following:(1) Describe the purpose of the covered ADS.(2) List and describe all developer-approved uses of the covered ADS.(3) For each developer-approved use, evaluate the expected performance of the covered ADS and document all of the following:(A) The expected accuracy and reliability of the covered ADS.(B) Any reasonably foreseeable effects of fine tuning on the accuracy and reliability of the covered ADS.(C) Whether any disparate treatment is intended to occur and, if so, all of the following:(i) The conditions under which each disparate treatment is intended to occur.(ii) Whether each disparate treatment is necessary for a developer-approved use.(iii) Whether any alternatives not involving disparate treatment were considered.(D) Any reasonably foreseeable effects of fine tuning on disparate treatment.(E) Whether any disparate impacts are reasonably likely to occur and, if so, all of the following:(i) The conditions under which each disparate impact is reasonably likely to occur.(ii) Whether each disparate impact is necessary for a developer-approved use.(iii) Whether any alternatives not involving disparate impacts were considered.(F) Whether any measures have been taken by the developer to mitigate the risk of unanticipated disparate impacts resulting from the use of the covered ADS.(G) With respect to a covered ADS that has been deployed, whether any unanticipated disparate impacts have been reported to the developer by a deployer, and whether the developer has taken any measures to mitigate those disparate impacts.(H) Any reasonably foreseeable effects of fine tuning on disparate impacts.(4) (A) Contract with an independent third-party auditor to assess the developers compliance with this subdivision.(B) (i) Except pursuant to clause (ii), a developer that contracts with an auditor pursuant to this paragraph shall provide the auditor with any available information that is reasonably necessary for the auditor to comprehensively assess developer compliance.(ii) A developer that provides documentation to an auditor pursuant to this subparagraph may make reasonable redactions for the purpose of protecting trade secrets. To the extent that a developer withholds information, the developer shall notify the auditor and provide a basis for the withholding.(C) If the deadline for conducting a performance evaluation pursuant to subdivision (a) elapses before the audit has been completed, a developer shall not deploy the covered ADS or make the covered ADS available to potential deployers until the audit has been completed.(I)(D) A developer that receives feedback from an auditor pursuant to this paragraph shall do both of the following:(i) Consider and attempt to incorporate that feedback into the development of any subsequent version of a covered ADS.(ii) Make a high-level summary of the feedback publicly available at no cost to users of the developers internet website.(c) (1) A developer that sells, licenses, or otherwise transfers a covered ADS to a potential deployer shall provide the deployer with all of the following:(A) The results of the most recent performance evaluation conducted on the covered ADS by the developer pursuant to this chapter.(B) For each developer-approved use of the covered ADS, instructions explaining how the covered ADS should be used by the deployer to make or facilitate a consequential decision.(C) For each developer-approved use of the covered ADS, a description of whether and under what circumstances the covered ADS can be fine-tuned.(D) An explanation of the deployers responsibilities under this chapter, including a description of any circumstances under which the deployer would assume the responsibilities of a developer pursuant to subdivision (h) of Section 22756.2.(E) (i) Any technical information necessary for the deployer to comply with this chapter.(ii) A developer shall not be required to provide additional technical information to a deployer that has assumed the responsibilities of a developer pursuant to subdivision (h) of Section 22756.2.(2) (A) A developer that provides documentation to a potential deployer pursuant to this subdivision may make reasonable redactions for the purpose of protecting trade secrets.(B) To the extent that a developer withholds information pursuant to subparagraph (A), the developer shall notify the deployer and provide a basis for the withholding.(d) A developer that receives an impact assessment from an auditor of a deployed covered ADS pursuant to subdivision (b) of Section 22756.3 shall provide all of the following information to any deployer of the covered ADS:(A)(1) Any material differences between the expected accuracy of the covered ADS and the observed accuracy of the covered ADS and the deployment conditions under which those differences are reasonably likely to occur.(B)(2) Any material differences between the expected reliability of the covered ADS and the observed reliability of the covered ADS and the deployment conditions under which those differences are reasonably likely to occur.(C)(3) Any unanticipated disparate impacts resulting from the use of the covered ADS and the deployment conditions under which those disparate impacts are reasonably likely to occur.(D)(4) An explanation of any steps the deployer can take to mitigate these discrepancies.(e) A developer that receives feedback from an auditor pursuant to this chapter shall consider and attempt to incorporate that feedback into the development of any subsequent version of a covered ADS.(f) A developer that provides documentation to a deployer pursuant to this section shall ensure the documentation is all of the following:(A)(1) Transmitted directly to the deployer or otherwise made available in a manner reasonably calculated to ensure the deployer receives the documentation.(B)(2) Provided in English and in any other language the developer regularly uses to communicate with deployers.(C)(3) Presented in a manner that ensures the communication clearly and effectively conveys the required information to the deployer.(g) A developer that deploys a covered ADS or makes a covered ADS available to potential deployers shall maintain all of the following documentation in an unredacted format for as long as the developer deploys the covered ADS or makes the covered ADS available to potential deployers plus 10 years:(1) The results of any performance evaluations conducted on the covered ADS pursuant to this chapter.(2) Any documentation provided to deployers pursuant to this chapter.(3) Any documentation provided to, or received from, auditors pursuant to this chapter.(4) Records of any redactions made pursuant to this chapter.(h) It is unlawful to advertise to consumers in the state that a covered ADS is capable of performing in a manner not substantiated by the results of the most recent performance evaluation conducted on the covered ADS.(i) (1) A developer that deploys a covered ADS or makes a covered ADS available to potential deployers shall designate at least one employee to oversee the developers compliance with this chapter.(2) A developer shall require an employee designated pursuant to this subdivision to conduct a prompt and comprehensive review of any credible compliance issue raised to that employee.
280+
220281
221282 22756.1. (a) (1) With respect to a covered ADS that was first deployed, or made available to potential deployers, before January 1, 2026, the developer of the covered ADS shall conduct an initial performance evaluation on the covered ADS before January 1, 2027, and shall additionally conduct a performance evaluation on the covered ADS under any of the following circumstances:
222-
223-###### 22756.1.
224283
225284 (A) Following any substantial modification of the covered ADS by the developer.
226285
227286 (B) Following any fine tuning of the covered ADS by the developer that materially changes the uses or outputs of the covered ADS.
228287
229288 (C) No more than one year after the developer last conducted a performance evaluation on the covered ADS, for as long as the developer deploys the covered ADS or makes the covered ADS available to potential deployers.
230289
231290 (2) With respect to a covered ADS that is first deployed or made available to potential deployers on or after January 1, 2026, the developer of the covered ADS shall conduct a performance evaluation on the covered ADS under any of the following circumstances:
232291
233292 (A) Before initially deploying the covered ADS or making the covered ADS available to potential deployers.
234293
235294 (B) Following any substantial modification of the covered ADS by the developer.
236295
237296 (C) Following any fine tuning of the covered ADS by the developer that materially changes the uses or outputs of the covered ADS.
238297
239298 (D) No more than one year after the developer last conducted a performance evaluation on the covered ADS, for as long as the developer deploys the covered ADS or makes the covered ADS available to potential deployers.
240299
241300 (b) In conducting a performance evaluation on a covered ADS, a developer shall do all of the following:
242301
243302 (1) Describe the purpose of the covered ADS.
244303
245304 (2) List and describe all developer-approved uses of the covered ADS.
246305
247-(3) For each developer-approved use, evaluate the expected performance of the covered ADS and document all of the following:
306+(3) For each developer-approved use, assess evaluate the expected performance of the covered ADS and document all of the following:
248307
249308 (A) The expected accuracy and reliability of the covered ADS.
250309
251310 (B) Any reasonably foreseeable effects of fine tuning on the accuracy and reliability of the covered ADS.
252311
253-(C) Whether any disparate treatment is intended to occur and, if so, all of the following:
312+(4)For each developer-approved use, assess whether
254313
255-(i) The conditions under which each disparate treatment is intended to occur.
256314
257-(ii) Whether each disparate treatment is necessary for a developer-approved use.
315+
316+(C) Whether any disparate treatment is intended to occur and document and, if so, all of the following:
317+
318+(A)Whether the covered ADS is intended to treat individuals or groups of individuals differently on the basis of a protected characteristic.
319+
320+
321+
322+(B)For each disparate treatment identified under subparagraph (A), describe all of the following:
323+
324+
325+
326+(i) The conditions under which the each disparate treatment is intended to occur.
327+
328+(ii) Whether the each disparate treatment is necessary for a developer-approved use.
258329
259330 (iii) Whether any alternatives not involving disparate treatment were considered.
260331
332+(C)
333+
334+
335+
261336 (D) Any reasonably foreseeable effects of fine tuning on disparate treatment.
262337
263-(E) Whether any disparate impacts are reasonably likely to occur and, if so, all of the following:
338+(5)For each developer-approved use, assess whether
264339
265-(i) The conditions under which each disparate impact is reasonably likely to occur.
266340
267-(ii) Whether each disparate impact is necessary for a developer-approved use.
341+
342+(E) Whether any disparate impacts are reasonably likely to occur and document and, if so, all of the following:
343+
344+(A)Whether the covered ADS is reasonably likely to treat groups of individuals who share a protected characteristic differently.
345+
346+
347+
348+(B)For each disparate impact identified under subparagraph (A), describe all of the following:
349+
350+
351+
352+(i) The conditions under which that each disparate impact is reasonably likely to occur.
353+
354+(ii) Whether the each disparate impact is necessary for a developer-approved use.
268355
269356 (iii) Whether any alternatives not involving disparate impacts were considered.
270357
358+(C)
359+
360+
361+
271362 (F) Whether any measures have been taken by the developer to mitigate the risk of unanticipated disparate impacts resulting from the use of the covered ADS.
363+
364+(D)
365+
366+
272367
273368 (G) With respect to a covered ADS that has been deployed, whether any unanticipated disparate impacts have been reported to the developer by a deployer, and whether the developer has taken any measures to mitigate those disparate impacts.
274369
370+(E)
371+
372+
373+
275374 (H) Any reasonably foreseeable effects of fine tuning on disparate impacts.
375+
376+(6)
377+
378+
276379
277380 (4) (A) Contract with an independent third-party auditor to assess the developers compliance with this subdivision.
278381
279382 (B) (i) Except pursuant to clause (ii), a developer that contracts with an auditor pursuant to this paragraph shall provide the auditor with any available information that is reasonably necessary for the auditor to comprehensively assess developer compliance.
280383
281384 (ii) A developer that provides documentation to an auditor pursuant to this subparagraph may make reasonable redactions for the purpose of protecting trade secrets. To the extent that a developer withholds information, the developer shall notify the auditor and provide a basis for the withholding.
282385
283386 (C) If the deadline for conducting a performance evaluation pursuant to subdivision (a) elapses before the audit has been completed, a developer shall not deploy the covered ADS or make the covered ADS available to potential deployers until the audit has been completed.
284387
285-(I)
286-
287-(D) A developer that receives feedback from an auditor pursuant to this paragraph shall do both of the following:
388+(I) A developer that receives feedback from an auditor pursuant to this paragraph shall do both of the following:
288389
289390 (i) Consider and attempt to incorporate that feedback into the development of any subsequent version of a covered ADS.
290391
291392 (ii) Make a high-level summary of the feedback publicly available at no cost to users of the developers internet website.
292393
293394 (c) (1) A developer that sells, licenses, or otherwise transfers a covered ADS to a potential deployer shall provide the deployer with all of the following:
294395
295396 (A) The results of the most recent performance evaluation conducted on the covered ADS by the developer pursuant to this chapter.
296397
297398 (B) For each developer-approved use of the covered ADS, instructions explaining how the covered ADS should be used by the deployer to make or facilitate a consequential decision.
298399
299400 (C) For each developer-approved use of the covered ADS, a description of whether and under what circumstances the covered ADS can be fine-tuned.
300401
301402 (D) An explanation of the deployers responsibilities under this chapter, including a description of any circumstances under which the deployer would assume the responsibilities of a developer pursuant to subdivision (h) of Section 22756.2.
302403
303404 (E) (i) Any technical information necessary for the deployer to comply with this chapter.
304405
305406 (ii) A developer shall not be required to provide additional technical information to a deployer that has assumed the responsibilities of a developer pursuant to subdivision (h) of Section 22756.2.
306407
307408 (2) (A) A developer that provides documentation to a potential deployer pursuant to this subdivision may make reasonable redactions for the purpose of protecting trade secrets.
308409
309410 (B) To the extent that a developer withholds information pursuant to subparagraph (A), the developer shall notify the deployer and provide a basis for the withholding.
310411
311412 (d) A developer that receives an impact assessment from an auditor of a deployed covered ADS pursuant to subdivision (b) of Section 22756.3 shall provide all of the following information to any deployer of the covered ADS:
312413
313-(A)
414+(A) Any material differences between the expected accuracy of the covered ADS and the observed accuracy of the covered ADS and the deployment conditions under which those differences are reasonably likely to occur.
314415
315-(1) Any material differences between the expected accuracy of the covered ADS and the observed accuracy of the covered ADS and the deployment conditions under which those differences are reasonably likely to occur.
416+(B) Any material differences between the expected reliability of the covered ADS and the observed reliability of the covered ADS and the deployment conditions under which those differences are reasonably likely to occur.
316417
317-(B)
418+(C) Any unanticipated disparate impacts resulting from the use of the covered ADS and the deployment conditions under which those disparate impacts are reasonably likely to occur.
318419
319-(2) Any material differences between the expected reliability of the covered ADS and the observed reliability of the covered ADS and the deployment conditions under which those differences are reasonably likely to occur.
320-
321-(C)
322-
323-(3) Any unanticipated disparate impacts resulting from the use of the covered ADS and the deployment conditions under which those disparate impacts are reasonably likely to occur.
324-
325-(D)
326-
327-(4) An explanation of any steps the deployer can take to mitigate these discrepancies.
420+(D) An explanation of any steps the deployer can take to mitigate these discrepancies.
328421
329422 (e) A developer that receives feedback from an auditor pursuant to this chapter shall consider and attempt to incorporate that feedback into the development of any subsequent version of a covered ADS.
330423
331424 (f) A developer that provides documentation to a deployer pursuant to this section shall ensure the documentation is all of the following:
332425
333-(A)
426+(A) Transmitted directly to the deployer or otherwise made available in a manner reasonably calculated to ensure the deployer receives the documentation.
334427
335-(1) Transmitted directly to the deployer or otherwise made available in a manner reasonably calculated to ensure the deployer receives the documentation.
428+(B) Provided in English and in any other language the developer regularly uses to communicate with deployers.
336429
337-(B)
430+(C) Presented in a manner that ensures the communication clearly and effectively conveys the required information to the deployer.
338431
339-(2) Provided in English and in any other language the developer regularly uses to communicate with deployers.
340-
341-(C)
342-
343-(3) Presented in a manner that ensures the communication clearly and effectively conveys the required information to the deployer.
344-
345-(g) A developer that deploys a covered ADS or makes a covered ADS available to potential deployers shall maintain all of the following documentation in an unredacted format for as long as the developer deploys the covered ADS or makes the covered ADS available to potential deployers plus 10 years:
432+(g) A developer that deploys a covered ADS or makes a covered ADS available to potential deployers shall maintain all of the following documentation in an unredacted format for as long as the covered ADS remains deployed or developer deploys the covered ADS or makes the covered ADS available to potential deployers plus 10 years:
346433
347434 (1) The results of any performance evaluations conducted on the covered ADS pursuant to this chapter.
348435
349436 (2) Any documentation provided to deployers pursuant to this chapter.
350437
351438 (3) Any documentation provided to, or received from, auditors pursuant to this chapter.
352439
353440 (4) Records of any redactions made pursuant to this chapter.
354441
355442 (h) It is unlawful to advertise to consumers in the state that a covered ADS is capable of performing in a manner not substantiated by the results of the most recent performance evaluation conducted on the covered ADS.
356443
357444 (i) (1) A developer that deploys a covered ADS or makes a covered ADS available to potential deployers shall designate at least one employee to oversee the developers compliance with this chapter.
358445
359446 (2) A developer shall require an employee designated pursuant to this subdivision to conduct a prompt and comprehensive review of any credible compliance issue raised to that employee.
360447
361-22756.2. (a) (1) Except as provided in paragraph (2), before a deployer finalizes a consequential decision made or facilitated by a covered ADS, the deployer shall provide any subject of that decision with a plain language written disclosure containing all of the following information:(A) A statement informing the subject that a covered ADS will be used to make or facilitate the consequential decision.(B) The name, version number, and developer of the covered ADS.(C) Whether the deployers use of the covered ADS is within the scope of a developer-approved use and a description of that use.(D) (i) The personal characteristics or attributes of the subject that the covered ADS measures or assesses to make or facilitate the consequential decision.(ii) The sources of personal information collected from the subject to make or facilitate the consequential decision.(iii) Any key parameters known to disproportionately affect the outcome of the consequential decision.(E) The structure and format of the outputs of the covered ADS and a plain language description of how those outputs are used to make or facilitate the consequential decision.(F) Whether a natural person will review either of the following before the consequential decision is finalized:(i) The outputs of the covered ADS.(ii) The outcome of the consequential decision.(G) The subjects rights under subdivisions (b) and (d) and the means and timeframe for exercising those rights.(H) (i) Contact information for the deployer.(ii) Contact information for the entity that manages the covered ADS, if that entity is not the deployer.(iii) Contact information for the entity that will interpret the results of the covered ADS, if that entity is not the deployer.(2) Paragraph (1) does not apply if the subject of the consequential decision is having a medical emergency.(b) (1) Before a deployer finalizes a consequential decision made or facilitated by a covered ADS, the deployer shall provide any subject of that decision with a reasonable opportunity to opt out of the use of the covered ADS.(2) (A) A deployer may deny a request to opt out of the use of a covered ADS if either of the following is true:(i) The deployer is subject to the federal Gramm-Leach-Bliley Act, and the covered ADS makes or facilitates a consequential decision pursuant to paragraph (7) of subdivision (c) of Section 22756.(ii) The subject of the consequential decision is having a medical emergency.(B) A deployer that denies a request to opt out of the use of a covered ADS pursuant to subparagraph (A) shall provide the subject with an explanation of the basis for the denial.(c) (1) After a deployer finalizes a consequential decision made or facilitated by a covered ADS, the deployer shall provide any subject of that decision witha plain language written disclosure containing all of the following information within five days:(A) The personal characteristics or attributes of the subject that the covered ADS used to make or facilitate the consequential decision.(B) The sources of personal information collected from the subject that were used to make or facilitate the consequential decision.(C) Any key parameters that disproportionately affected the outcome of the consequential decision.(D) The structure and format of the outputs of the covered ADS and a plain language description of how those outputs were used to make or facilitate the consequential decision.(E) The role that the ADS played in making the consequential decision and whether any human judgment was involved.(F) Contact information for the deployer.(G) Contact information for the entity that manages the covered ADS, if that entity is not the deployer.(H) Contact information for the entity that will interpret the results of the covered ADS, if that entity is not the deployer.(I) The subjects rights under subdivision (d) and the means and timeframe for exercising those rights.(2) Paragraph (1) does not apply if the subject of the consequential decision is having a medical emergency.(3) A deployer that provides documentation to a subject of a consequential decision pursuant to this subdivision shall ensure the documentation is all of the following:(A) Transmitted directly to the subject.(B) Provided in English and in any other language that the deployer regularly uses to communicate with subjects.(C) Made available in formats that are accessible to people who are blind or have other disabilities.(D) Presented in a manner that ensures the communication clearly and effectively conveys the required information to the subject.(d) After a deployer finalizes a consequential decision made or facilitated by a covered ADS, the deployer shall provide any subject of that decision with an opportunity to do both of the following within 30 business days:(1) (A) Correct any incorrect personal information used by the covered ADS to make or facilitate the consequential decision.(B) A deployer shall comply with a request to correct personal information within 30 business days of receiving the request if the request is accompanied by documentation sufficient to assess the basis for the request.(C) (i) If a deployer determines that complying with a request to correct personal information would change the outcome of the consequential decision, the deployer shall, within 30 days of making the determination, rectify the decision.(ii) If a deployer determines that complying with a request to correct personal information would not change the outcome of the consequential decision, the deployer shall, within 30 days of making the determination, inform the subject that the correction was made but that it did not alter the decision.(D) A deployer that denies a request to correct personal information shall do both of the following:(i) Provide the subject with an explanation of the basis for the denial.(ii) Provide the subject with a reasonable opportunity to request that the deployer delete the subjects personal information.(2) (A) Appeal the outcome of the consequential decision.(B) A deployer shall review a request to appeal a consequential decision within 30 business days of receiving the request if the request is accompanied by documentation sufficient to assess the basis for the request.(C) (i) If a deployer determines that the original decision was incorrect, the deployer shall, within 30 days of making the determination, rectify the decision.(ii) If a deployer determines that the original decision was correct, the deployer shall, within 30 days of making the determination, inform the subject that the consequential decision will not be altered.(D) A deployer that denies a request to appeal the outcome of a consequential decision shall provide the subject with an explanation of the basis for the denial.(e) (1) (A) A deployer that provides documentation to the subject of a consequential decision pursuant to this section may make reasonable redactions for the purpose of protecting trade secrets.(B) To the extent that a deployer withholds information pursuant to paragraph (1), the deployer shall notify the subject and provide a basis for the withholding.(2) A deployer that is required by another state or federal law to provide substantially similar notice to a subject of a consequential decision need not duplicatively provide notice to the subject under this section.(f) A deployers collection, use, retention, and sharing of personal information from a subject of a consequential decision shall be reasonably necessary and proportionate to achieve the purposes for which the personal information was collected and processed, or for another disclosed purpose that is compatible with the context in which the personal information was collected, and not further processed in a manner that is incompatible with those purposes.(g) (1) A deployer that uses a covered ADS to make or facilitate consequential decisions directly impacting more than 5,999 people in a given three-year period shall contract with an independent third-party auditor to conduct an impact assessment on the covered ADS before January 1, 2030, and every three years thereafter.(2) (A) Except pursuant to subparagraph (B), a deployer that contracts with an auditor pursuant to this subdivision shall provide the auditor with any available information that is reasonably necessary for the auditor to conduct a comprehensive impact assessment on the covered ADS.(B) A deployer that provides documentation to an auditor pursuant to this paragraph may make reasonable redactions for the purpose of protecting trade secrets. To the extent that a deployer withholds information, the developer shall notify the auditor and provide a basis for the withholding.(C) This paragraph shall not be construed to require a deployer to collect any personal information from a subject of a consequential decision beyond that which the deployer collects in the ordinary course of business or as necessary to comply with state or federal law.(3) If the deadline for conducting an audit pursuant to paragraph (1) elapses before the audit has been completed, a deployer shall not use the covered ADS to make or facilitate consequential decisions until the audit has been completed.(h) A deployer that does any of the following assumes the responsibilities of a developer under this chapter:(1) Uses a covered ADS to make or facilitate consequential decisions that directly impact more than 5,999 people in a given three-year period, if the deployer did not receive any documentation from the developer of the covered ADS pursuant to subdivision (c) of Section 22756.1 during the three-year period.(2) Uses a covered ADS to make or facilitate consequential decisions that directly impact more than 5,999 people in a given three-year period, if the deployers use of the covered ADS is outside the scope of a developer-approved use.(3) Substantially modifies an automated decision system and does either of the following:(A) Uses the substantially modified system to make or facilitate consequential decisions that directly impact more than 5999 5,999 people in a given three-year period.(B) Makes the substantially modified system available to potential deployers.(i) A deployer that uses a covered ADS to make or facilitate a consequential decision shall retain the following documentation in an unredacted format for as long as the deployer uses the covered ADS plus 10 years:(1) Any documentation received from developers pursuant to this chapter.(2) Any documentation provided pursuant to this section to subjects of consequential decisions made or facilitated by the covered ADS.(3) Any requests to correct personal information made pursuant to this section.(4) Any requests to opt out of the use of the covered ADS made pursuant to this section.(5) Any requests to appeal the outcome of a consequential decision made pursuant to this section.(6) Any documentation provided to, or received from, auditors pursuant to this chapter.(7) Records of any redactions made pursuant to this section.(j) (1) A deployer that uses a covered ADS to make or facilitate a consequential decision shall designate at least one employee to oversee the deployers compliance with this chapter.(2) A deployer shall require an employee designated pursuant to this subdivision to conduct a prompt and comprehensive review of any credible compliance issue related to the deployers use of a covered ADS that is raised to that employee.(k) In addition to the requirements of this section, a deployer that is a business subject to the California Consumer Privacy Act of 2018 (Title 1.81.5 (commencing with Section 1798.100)) is subject to any privacy-related opt-out and access regulation duly adopted by the California Privacy Protection Agency pursuant to subdivision (b) of Section 1798.199.40 of the Civil Code.(l) This section shall become operative on January 1, 2027.
448+22756.2. (a) (1) Except as provided in paragraph (2), before finalizing a deployer finalizes a consequential decision made or facilitated by a covered ADS, a the deployer shall provide any subject of that decision with a plain language written disclosure containing all of the following information:(A) A statement informing the subject that a covered ADS will be used to make or facilitate the consequential decision.(B) The name, version number, and developer of the covered ADS.(C) Whether the deployers use of the covered ADS is within the scope of a developer-approved use and a description of that use.(D) (i) The personal characteristics or attributes of the subject that the covered ADS measures or assesses to make or facilitate the consequential decision.(ii) The sources of personal information collected from the subject to make or facilitate the consequential decision.(iii) Any key parameters known to disproportionately affect the outcome of the consequential decision.(E) The structure and format of the outputs of the covered ADS and a plain language description of how those outputs are used to make or facilitate the consequential decision.(F) Whether a natural person will review either of the following before the consequential decision is finalized:(i) The outputs of the covered ADS.(ii) The outcome of the consequential decision.(G) The subjects rights under subdivisions (b) and (c) (d) and the means and timeframe for exercising those rights.(H) (i) Contact information for the deployer.(ii) Contact information for the entity that manages the covered ADS, if that entity is not the deployer.(iii) Contact information for the entity that will interpret the results of the covered ADS, if that entity is not the deployer.(2) Paragraph (1) does not apply if the subject of the consequential decision is having a medical emergency.(b) (1) Before finalizing a deployer finalizes a consequential decision made or facilitated by a covered ADS, a the deployer shall provide any subject of that decision with a reasonable opportunity to opt out of the use of the covered ADS.(2) (A) A deployer may deny a request to opt out of the use of a covered ADS if either of the following is true:(i) The deployer is subject to the federal Gramm-Leach-Bliley Act, and the covered ADS makes or facilitates a consequential decision pursuant to paragraph (7) of subdivision (c) of Section 22756.(ii) The subject of the consequential decision is having a medical emergency.(B) A deployer that denies a request to opt out of the use of a covered ADS pursuant to subparagraph (A) shall provide the subject with an explanation of the basis for the denial.(c) (1) After a deployer finalizes a consequential decision is finalized, made or facilitated by a covered ADS, the deployer shall provide any subject of that decision witha plain language written disclosure shall be provided containing all of the following information within five days, and the disclosure shall include all of the information: days:(A) The personal characteristics or attributes of the subject that the covered ADS measured or assessed used to make or facilitate the consequential decision.(B) The sources of personal information collected from the subject that were used to make or facilitate the consequential decision.(C) Any key parameters that disproportionately affected the outcome of the consequential decision.(D) The structure and format of the outputs of the covered ADS and a plain language description of how those outputs were used to make or facilitate the consequential decision.(E) The role that the ADS played in making the consequential decision and whether any human judgment was involved.(F) Contact information for the deployer.(G) Contact information for the entity that manages the covered ADS, if that entity is not the deployer.(H) Contact information for the entity that will interpret the results of the covered ADS, if that entity is not the deployer.(I) The subjects rights under subdivision (d) and the means and timeframe for exercising those rights.(2) Paragraph (1) is does not applicable apply if the subject of the consequential decision is having a medical emergency.(3) A deployer that provides documentation to a subject of a consequential decision pursuant to this subdivision shall ensure the documentation is all of the following:(A) Transmitted directly to the subject.(B) Provided in English and in any other language that the deployer regularly uses to communicate with subjects.(C) Made available in formats that are accessible to people who are blind or have other disabilities.(D) Presented in a manner that ensures the communication clearly and effectively conveys the required information to the subject.(d) After finalizing a deployer finalizes a consequential decision made or facilitated by a covered ADS, a the deployer shall provide any subject of that decision with an opportunity to do both of the following within 30 business days:(1) (A) Correct any incorrect personal information used by the covered ADS to make or facilitate the consequential decision.(B) A deployer shall comply with a request to correct personal information within 30 business days of receiving the request if the request is accompanied by documentation sufficient to assess the basis for the request.(C) (i) If a deployer determines that complying with a request to correct personal information would change the outcome of the consequential decision, the deployer shall, within 30 days of making the determination, rectify the decision.(ii) If a deployer determines that complying with a request to correct personal information would not change the outcome of the consequential decision, the deployer shall, within 30 days of making the determination, inform the subject that the correction was made but that it did not alter the decision.(D) A deployer that denies a request to correct personal information shall do both of the following:(i) Provide the subject with an explanation of the basis for the denial.(ii) Provide the subject with a reasonable opportunity to request that the deployer delete the subjects personal information.(2) (A) Appeal the outcome of the consequential decision.(B) A deployer shall review a request to appeal a consequential decision within 30 business days of receiving the request. request if the request is accompanied by documentation sufficient to assess the basis for the request.(C) (i) If a deployer determines that the original decision is was incorrect, the deployer shall, within 30 days of making the determination, rectify the decision.(ii) If a deployer determines that the original decision is was correct, the deployer shall, within 30 days of making the determination, inform the subject that the consequential decision will not be altered.(D) A deployer that denies a request to appeal the outcome of a consequential decision shall provide the subject with an explanation of the basis for the denial.(e) (1) (A) A deployer that provides documentation to the subject of a consequential decision pursuant to this section may make reasonable redactions for the purpose of protecting trade secrets.(B) To the extent that a deployer withholds information pursuant to paragraph (1), the deployer shall notify the subject and provide a basis for the withholding.(2) A deployer that is required by another state or federal law to provide substantially similar notice to a subject of a consequential decision need not duplicatively provide notice to the subject under this section.(f) A deployers collection, use, retention, and sharing of personal information from a subject of a consequential decision shall be reasonably necessary and proportionate to achieve the purposes for which the personal information was collected and processed, or for another disclosed purpose that is compatible with the context in which the personal information was collected, and not further processed in a manner that is incompatible with those purposes.(g) (1) A deployer that uses a covered ADS to make or facilitate consequential decisions directly impacting more than 5999 5,999 people in a given three-year period shall contract with an independent third-party auditor to conduct an impact assessment on the covered ADS before January 1, 2030, and every three years thereafter.(2) (A) Except pursuant to subparagraph (B), a deployer that contracts with an auditor pursuant to this subdivision shall provide the auditor with any available information that is reasonably necessary for the auditor to conduct a comprehensive impact assessment on the covered ADS.(B) A deployer that provides documentation to an auditor pursuant to this paragraph may make reasonable redactions for the purpose of protecting trade secrets. To the extent that a deployer withholds information, the developer shall notify the auditor and provide a basis for the withholding.(C) This paragraph shall not be construed to require a deployer to collect any personal information from a subject of a consequential decision beyond that which the deployer collects in the ordinary course of business or as necessary to comply with state or federal law.(3) If the deadline for conducting an audit pursuant to paragraph (1) elapses before the audit has been completed, a deployer shall not use the covered ADS to make or facilitate consequential decisions until the audit has been completed.(h) A deployer that does any of the following assumes the responsibilities of a developer under this chapter:(1) Uses a covered ADS to make or facilitate consequential decisions that directly impact more than 5999 5,999 people in a given three-year period, if the deployer did not receive any documentation from the developer of the covered ADS pursuant to subdivision (c) of Section 22756.1. 22756.1 during the three-year period.(2) Uses a covered ADS to make or facilitate consequential decisions that directly impact more than 5999 5,999 people in a given three-year period, if the deployers use of the covered ADS is outside the scope of a developer-approved use.(3) Substantially modifies an automated decision system and does either of the following:(A) Uses the substantially modified system to make or facilitate consequential decisions that directly impact more than 5999 people in a given three-year period.(B) Makes the substantially modified system available to potential deployers.(i) A deployer that uses a covered ADS to make or facilitate a consequential decision shall retain the following documentation in an unredacted format for as long as the deployer uses the covered ADS remains deployed plus 10 years:(1) Any documentation received from developers pursuant to this chapter.(2) Any documentation provided pursuant to this section to subjects of consequential decisions made or facilitated by the covered ADS.(3) Any requests to correct personal information made pursuant to this section.(4) Any requests to opt out of the use of the covered ADS made pursuant to this section.(5) Any requests to appeal the outcome of a consequential decision made pursuant to this section.(6) Any documentation provided to, or received from, auditors pursuant to this chapter.(7) Records of any redactions made pursuant to this section.(j) (1) A deployer that uses a covered ADS to make or facilitate a consequential decision shall designate at least one employee to oversee the deployers compliance with this chapter.(2) A deployer shall require an employee designated pursuant to this subdivision to conduct a prompt and comprehensive review of any credible compliance issue related to the deployers use of a covered ADS that is raised to that employee.(k) In addition to the requirements of this section, a deployer that is a business subject to the California Consumer Privacy Act of 2018 (Title 1.81.5 (commencing with Section 1798.100)) is subject to any privacy-related opt-out and access regulation duly adopted by the California Privacy Protection Agency pursuant to subdivision (b) of Section 1798.199.40 of the Civil Code.(l) This section shall become operative on January 1, 2027.
362449
363-22756.2. (a) (1) Except as provided in paragraph (2), before a deployer finalizes a consequential decision made or facilitated by a covered ADS, the deployer shall provide any subject of that decision with a plain language written disclosure containing all of the following information:
364450
365-###### 22756.2.
451+
452+22756.2. (a) (1) Except as provided in paragraph (2), before finalizing a deployer finalizes a consequential decision made or facilitated by a covered ADS, a the deployer shall provide any subject of that decision with a plain language written disclosure containing all of the following information:
366453
367454 (A) A statement informing the subject that a covered ADS will be used to make or facilitate the consequential decision.
368455
369456 (B) The name, version number, and developer of the covered ADS.
370457
371458 (C) Whether the deployers use of the covered ADS is within the scope of a developer-approved use and a description of that use.
372459
373460 (D) (i) The personal characteristics or attributes of the subject that the covered ADS measures or assesses to make or facilitate the consequential decision.
374461
375462 (ii) The sources of personal information collected from the subject to make or facilitate the consequential decision.
376463
377464 (iii) Any key parameters known to disproportionately affect the outcome of the consequential decision.
378465
379466 (E) The structure and format of the outputs of the covered ADS and a plain language description of how those outputs are used to make or facilitate the consequential decision.
380467
381468 (F) Whether a natural person will review either of the following before the consequential decision is finalized:
382469
383470 (i) The outputs of the covered ADS.
384471
385472 (ii) The outcome of the consequential decision.
386473
387-(G) The subjects rights under subdivisions (b) and (d) and the means and timeframe for exercising those rights.
474+(G) The subjects rights under subdivisions (b) and (c) (d) and the means and timeframe for exercising those rights.
388475
389476 (H) (i) Contact information for the deployer.
390477
391478 (ii) Contact information for the entity that manages the covered ADS, if that entity is not the deployer.
392479
393480 (iii) Contact information for the entity that will interpret the results of the covered ADS, if that entity is not the deployer.
394481
395482 (2) Paragraph (1) does not apply if the subject of the consequential decision is having a medical emergency.
396483
397-(b) (1) Before a deployer finalizes a consequential decision made or facilitated by a covered ADS, the deployer shall provide any subject of that decision with a reasonable opportunity to opt out of the use of the covered ADS.
484+(b) (1) Before finalizing a deployer finalizes a consequential decision made or facilitated by a covered ADS, a the deployer shall provide any subject of that decision with a reasonable opportunity to opt out of the use of the covered ADS.
398485
399486 (2) (A) A deployer may deny a request to opt out of the use of a covered ADS if either of the following is true:
400487
401488 (i) The deployer is subject to the federal Gramm-Leach-Bliley Act, and the covered ADS makes or facilitates a consequential decision pursuant to paragraph (7) of subdivision (c) of Section 22756.
402489
403490 (ii) The subject of the consequential decision is having a medical emergency.
404491
405492 (B) A deployer that denies a request to opt out of the use of a covered ADS pursuant to subparagraph (A) shall provide the subject with an explanation of the basis for the denial.
406493
407-(c) (1) After a deployer finalizes a consequential decision made or facilitated by a covered ADS, the deployer shall provide any subject of that decision witha plain language written disclosure containing all of the following information within five days:
494+(c) (1) After a deployer finalizes a consequential decision is finalized, made or facilitated by a covered ADS, the deployer shall provide any subject of that decision witha plain language written disclosure shall be provided containing all of the following information within five days, and the disclosure shall include all of the information: days:
408495
409-(A) The personal characteristics or attributes of the subject that the covered ADS used to make or facilitate the consequential decision.
496+(A) The personal characteristics or attributes of the subject that the covered ADS measured or assessed used to make or facilitate the consequential decision.
410497
411498 (B) The sources of personal information collected from the subject that were used to make or facilitate the consequential decision.
412499
413500 (C) Any key parameters that disproportionately affected the outcome of the consequential decision.
414501
415502 (D) The structure and format of the outputs of the covered ADS and a plain language description of how those outputs were used to make or facilitate the consequential decision.
416503
417504 (E) The role that the ADS played in making the consequential decision and whether any human judgment was involved.
418505
419506 (F) Contact information for the deployer.
420507
421508 (G) Contact information for the entity that manages the covered ADS, if that entity is not the deployer.
422509
423510 (H) Contact information for the entity that will interpret the results of the covered ADS, if that entity is not the deployer.
424511
425512 (I) The subjects rights under subdivision (d) and the means and timeframe for exercising those rights.
426513
427-(2) Paragraph (1) does not apply if the subject of the consequential decision is having a medical emergency.
514+(2) Paragraph (1) is does not applicable apply if the subject of the consequential decision is having a medical emergency.
428515
429516 (3) A deployer that provides documentation to a subject of a consequential decision pursuant to this subdivision shall ensure the documentation is all of the following:
430517
431518 (A) Transmitted directly to the subject.
432519
433520 (B) Provided in English and in any other language that the deployer regularly uses to communicate with subjects.
434521
435522 (C) Made available in formats that are accessible to people who are blind or have other disabilities.
436523
437524 (D) Presented in a manner that ensures the communication clearly and effectively conveys the required information to the subject.
438525
439-(d) After a deployer finalizes a consequential decision made or facilitated by a covered ADS, the deployer shall provide any subject of that decision with an opportunity to do both of the following within 30 business days:
526+(d) After finalizing a deployer finalizes a consequential decision made or facilitated by a covered ADS, a the deployer shall provide any subject of that decision with an opportunity to do both of the following within 30 business days:
440527
441528 (1) (A) Correct any incorrect personal information used by the covered ADS to make or facilitate the consequential decision.
442529
443530 (B) A deployer shall comply with a request to correct personal information within 30 business days of receiving the request if the request is accompanied by documentation sufficient to assess the basis for the request.
444531
445532 (C) (i) If a deployer determines that complying with a request to correct personal information would change the outcome of the consequential decision, the deployer shall, within 30 days of making the determination, rectify the decision.
446533
447534 (ii) If a deployer determines that complying with a request to correct personal information would not change the outcome of the consequential decision, the deployer shall, within 30 days of making the determination, inform the subject that the correction was made but that it did not alter the decision.
448535
449536 (D) A deployer that denies a request to correct personal information shall do both of the following:
450537
451538 (i) Provide the subject with an explanation of the basis for the denial.
452539
453540 (ii) Provide the subject with a reasonable opportunity to request that the deployer delete the subjects personal information.
454541
455542 (2) (A) Appeal the outcome of the consequential decision.
456543
457-(B) A deployer shall review a request to appeal a consequential decision within 30 business days of receiving the request if the request is accompanied by documentation sufficient to assess the basis for the request.
544+(B) A deployer shall review a request to appeal a consequential decision within 30 business days of receiving the request. request if the request is accompanied by documentation sufficient to assess the basis for the request.
458545
459-(C) (i) If a deployer determines that the original decision was incorrect, the deployer shall, within 30 days of making the determination, rectify the decision.
546+(C) (i) If a deployer determines that the original decision is was incorrect, the deployer shall, within 30 days of making the determination, rectify the decision.
460547
461-(ii) If a deployer determines that the original decision was correct, the deployer shall, within 30 days of making the determination, inform the subject that the consequential decision will not be altered.
548+(ii) If a deployer determines that the original decision is was correct, the deployer shall, within 30 days of making the determination, inform the subject that the consequential decision will not be altered.
462549
463550 (D) A deployer that denies a request to appeal the outcome of a consequential decision shall provide the subject with an explanation of the basis for the denial.
464551
465552 (e) (1) (A) A deployer that provides documentation to the subject of a consequential decision pursuant to this section may make reasonable redactions for the purpose of protecting trade secrets.
466553
467554 (B) To the extent that a deployer withholds information pursuant to paragraph (1), the deployer shall notify the subject and provide a basis for the withholding.
468555
469556 (2) A deployer that is required by another state or federal law to provide substantially similar notice to a subject of a consequential decision need not duplicatively provide notice to the subject under this section.
470557
471558 (f) A deployers collection, use, retention, and sharing of personal information from a subject of a consequential decision shall be reasonably necessary and proportionate to achieve the purposes for which the personal information was collected and processed, or for another disclosed purpose that is compatible with the context in which the personal information was collected, and not further processed in a manner that is incompatible with those purposes.
472559
473-(g) (1) A deployer that uses a covered ADS to make or facilitate consequential decisions directly impacting more than 5,999 people in a given three-year period shall contract with an independent third-party auditor to conduct an impact assessment on the covered ADS before January 1, 2030, and every three years thereafter.
560+(g) (1) A deployer that uses a covered ADS to make or facilitate consequential decisions directly impacting more than 5999 5,999 people in a given three-year period shall contract with an independent third-party auditor to conduct an impact assessment on the covered ADS before January 1, 2030, and every three years thereafter.
474561
475562 (2) (A) Except pursuant to subparagraph (B), a deployer that contracts with an auditor pursuant to this subdivision shall provide the auditor with any available information that is reasonably necessary for the auditor to conduct a comprehensive impact assessment on the covered ADS.
476563
477564 (B) A deployer that provides documentation to an auditor pursuant to this paragraph may make reasonable redactions for the purpose of protecting trade secrets. To the extent that a deployer withholds information, the developer shall notify the auditor and provide a basis for the withholding.
478565
479566 (C) This paragraph shall not be construed to require a deployer to collect any personal information from a subject of a consequential decision beyond that which the deployer collects in the ordinary course of business or as necessary to comply with state or federal law.
480567
481568 (3) If the deadline for conducting an audit pursuant to paragraph (1) elapses before the audit has been completed, a deployer shall not use the covered ADS to make or facilitate consequential decisions until the audit has been completed.
482569
483570 (h) A deployer that does any of the following assumes the responsibilities of a developer under this chapter:
484571
485-(1) Uses a covered ADS to make or facilitate consequential decisions that directly impact more than 5,999 people in a given three-year period, if the deployer did not receive any documentation from the developer of the covered ADS pursuant to subdivision (c) of Section 22756.1 during the three-year period.
572+(1) Uses a covered ADS to make or facilitate consequential decisions that directly impact more than 5999 5,999 people in a given three-year period, if the deployer did not receive any documentation from the developer of the covered ADS pursuant to subdivision (c) of Section 22756.1. 22756.1 during the three-year period.
486573
487-(2) Uses a covered ADS to make or facilitate consequential decisions that directly impact more than 5,999 people in a given three-year period, if the deployers use of the covered ADS is outside the scope of a developer-approved use.
574+(2) Uses a covered ADS to make or facilitate consequential decisions that directly impact more than 5999 5,999 people in a given three-year period, if the deployers use of the covered ADS is outside the scope of a developer-approved use.
488575
489576 (3) Substantially modifies an automated decision system and does either of the following:
490577
491-(A) Uses the substantially modified system to make or facilitate consequential decisions that directly impact more than 5999 5,999 people in a given three-year period.
578+(A) Uses the substantially modified system to make or facilitate consequential decisions that directly impact more than 5999 people in a given three-year period.
492579
493580 (B) Makes the substantially modified system available to potential deployers.
494581
495-(i) A deployer that uses a covered ADS to make or facilitate a consequential decision shall retain the following documentation in an unredacted format for as long as the deployer uses the covered ADS plus 10 years:
582+(i) A deployer that uses a covered ADS to make or facilitate a consequential decision shall retain the following documentation in an unredacted format for as long as the deployer uses the covered ADS remains deployed plus 10 years:
496583
497584 (1) Any documentation received from developers pursuant to this chapter.
498585
499586 (2) Any documentation provided pursuant to this section to subjects of consequential decisions made or facilitated by the covered ADS.
500587
501588 (3) Any requests to correct personal information made pursuant to this section.
502589
503590 (4) Any requests to opt out of the use of the covered ADS made pursuant to this section.
504591
505592 (5) Any requests to appeal the outcome of a consequential decision made pursuant to this section.
506593
507594 (6) Any documentation provided to, or received from, auditors pursuant to this chapter.
508595
509596 (7) Records of any redactions made pursuant to this section.
510597
511598 (j) (1) A deployer that uses a covered ADS to make or facilitate a consequential decision shall designate at least one employee to oversee the deployers compliance with this chapter.
512599
513600 (2) A deployer shall require an employee designated pursuant to this subdivision to conduct a prompt and comprehensive review of any credible compliance issue related to the deployers use of a covered ADS that is raised to that employee.
514601
515602 (k) In addition to the requirements of this section, a deployer that is a business subject to the California Consumer Privacy Act of 2018 (Title 1.81.5 (commencing with Section 1798.100)) is subject to any privacy-related opt-out and access regulation duly adopted by the California Privacy Protection Agency pursuant to subdivision (b) of Section 1798.199.40 of the Civil Code.
516603
517604 (l) This section shall become operative on January 1, 2027.
518605
519-22756.3. (a) An auditor that conducts an impact assessment on a covered ADS pursuant to subdivision (g) of Section 22756.2 shall do all of the following:(1) (A) Request any information from the deployer of the covered ADS that is reasonably necessary for the auditor to conduct a comprehensive impact assessment.(B) This paragraph applies only to information gathered by the deployer in the ordinary course of business.(2) For each unique developer-approved use of the covered ADS by the deployer, document all of the following:(A) The observed accuracy and reliability of the covered ADS over the relevant period.(B) Whether the observed accuracy and reliability differed materially from the expected accuracy and reliability of the covered ADS, as described in documentation provided by a developer to the deployer pursuant to this chapter.(C) Whether any disparate impacts resulted from the deployers use of the covered ADS and the deployment conditions under which those disparate impacts occurred.(D) Whether each disparate impact was an anticipated disparate impact, as described in documentation provided to the deployer pursuant to this chapter.(3) Whether the deployer used the covered ADS to make or facilitate a consequential decision outside of the scope of a developer-approved use.(4) Whether the deployer assumed the responsibilities of a developer pursuant to subdivision (h) of Section 22756.2.(b) (1) After conducting an impact assessment on a covered ADS, an auditor shall do both of the following:(A) Provide the results of the impact assessment to the deployer that contracted with the auditor to perform the impact assessment.(B) Make a high-level summary of the results of the impact assessment publicly available at no cost to users of the auditors internet website.(2) The documentation required by this section shall be both of the following:(A) Provided in English and in any other language that the auditor regularly uses to communicate with deployers.(B) Presented in a manner that ensures the communication clearly and effectively conveys the required information.(3) An auditor shall not make publicly available with the personal information of a subject of a consequential decision made or facilitated by a covered ADS without first obtaining the express consent of the subject.
606+22756.3. (a) An auditor that conducts an impact assessment on a covered ADS pursuant to subdivision (g) of Section 22756.2 shall do all of the following:(1) (A) Request any information from the deployer of the covered ADS that is reasonably necessary for the auditor to conduct a comprehensive impact assessment.(B) This paragraph applies only to information gathered by the deployer in the ordinary course of business.(2)Document all developer-approved uses of the covered ADS that the deployer utilized during the relevant period.(3)(2) For each unique developer-approved use, use of the covered ADS by the deployer, document all of the following:(A) The observed accuracy and reliability of the covered ADS over the relevant period.(B) Whether the observed accuracy and reliability differed materially from the expected accuracy and reliability of the covered ADS, as described in documentation provided by a developer to the deployer pursuant to this chapter.(C) Whether any disparate impacts resulted from the deployers use of the covered ADS and the deployment conditions under which those disparate impacts occurred.(D) Whether each disparate impact was an anticipated disparate impact, as described in documentation provided to the deployer pursuant to this chapter.(4)(3) Whether the deployer used the covered ADS to make or facilitate a consequential decision outside of the scope of a developer-approved use.(5)(4) Whether the deployer assumed the responsibilities of a developer pursuant to subdivision (h) of Section 22756.2.(b) (1) After conducting an impact assessment on a covered ADS, an auditor shall provide the results of the impact assessment to do both of the following:(A) The Provide the results of the impact assessment to the deployer that contracted with the auditor to perform the impact assessment.(B)The developer of the covered ADS.(B) Make a high-level summary of the results of the impact assessment publicly available at no cost to users of the auditors internet website.(2) The documentation required by this section shall be both of the following:(A) Provided in English and in any other language that the auditor regularly uses to communicate with developers and deployers.(B) Presented in a manner that ensures the communication clearly and effectively conveys the required information to the developer and deployer. information.(3) An auditor shall not provide a developer make publicly available with the personal information of a subject of a consequential decision made or facilitated by a covered ADS without first obtaining the express consent of the subject.
607+
608+
520609
521610 22756.3. (a) An auditor that conducts an impact assessment on a covered ADS pursuant to subdivision (g) of Section 22756.2 shall do all of the following:
522-
523-###### 22756.3.
524611
525612 (1) (A) Request any information from the deployer of the covered ADS that is reasonably necessary for the auditor to conduct a comprehensive impact assessment.
526613
527614 (B) This paragraph applies only to information gathered by the deployer in the ordinary course of business.
528615
529-(2) For each unique developer-approved use of the covered ADS by the deployer, document all of the following:
616+(2)Document all developer-approved uses of the covered ADS that the deployer utilized during the relevant period.
617+
618+
619+
620+(3)
621+
622+
623+
624+(2) For each unique developer-approved use, use of the covered ADS by the deployer, document all of the following:
530625
531626 (A) The observed accuracy and reliability of the covered ADS over the relevant period.
532627
533628 (B) Whether the observed accuracy and reliability differed materially from the expected accuracy and reliability of the covered ADS, as described in documentation provided by a developer to the deployer pursuant to this chapter.
534629
535630 (C) Whether any disparate impacts resulted from the deployers use of the covered ADS and the deployment conditions under which those disparate impacts occurred.
536631
537632 (D) Whether each disparate impact was an anticipated disparate impact, as described in documentation provided to the deployer pursuant to this chapter.
538633
634+(4)
635+
636+
637+
539638 (3) Whether the deployer used the covered ADS to make or facilitate a consequential decision outside of the scope of a developer-approved use.
639+
640+(5)
641+
642+
540643
541644 (4) Whether the deployer assumed the responsibilities of a developer pursuant to subdivision (h) of Section 22756.2.
542645
543-(b) (1) After conducting an impact assessment on a covered ADS, an auditor shall do both of the following:
646+(b) (1) After conducting an impact assessment on a covered ADS, an auditor shall provide the results of the impact assessment to do both of the following:
544647
545-(A) Provide the results of the impact assessment to the deployer that contracted with the auditor to perform the impact assessment.
648+(A) The Provide the results of the impact assessment to the deployer that contracted with the auditor to perform the impact assessment.
649+
650+(B)The developer of the covered ADS.
651+
652+
546653
547654 (B) Make a high-level summary of the results of the impact assessment publicly available at no cost to users of the auditors internet website.
548655
549656 (2) The documentation required by this section shall be both of the following:
550657
551-(A) Provided in English and in any other language that the auditor regularly uses to communicate with deployers.
658+(A) Provided in English and in any other language that the auditor regularly uses to communicate with developers and deployers.
552659
553-(B) Presented in a manner that ensures the communication clearly and effectively conveys the required information.
660+(B) Presented in a manner that ensures the communication clearly and effectively conveys the required information to the developer and deployer. information.
554661
555-(3) An auditor shall not make publicly available with the personal information of a subject of a consequential decision made or facilitated by a covered ADS without first obtaining the express consent of the subject.
662+(3) An auditor shall not provide a developer make publicly available with the personal information of a subject of a consequential decision made or facilitated by a covered ADS without first obtaining the express consent of the subject.
556663
557664 22756.4. (a) (1) Within 30 days of receiving a request from the Attorney General for a performance evaluation or impact assessment prepared pursuant to this chapter, a developer, deployer, or auditor of a covered ADS shall provide an unredacted copy of the document to the Attorney General.(2) The Attorney General may share performance evaluations and impact assessments with other enforcement entities as necessary for enforcement purposes.(b) (1) The disclosure or sharing of a performance evaluation or impact assessment pursuant to subdivision (a) does not constitute a waiver of any attorney-client privilege, work-product protection, or trade secret protection that might otherwise exist with respect to any information contained in the performance evaluation or impact assessment.(2) A performance evaluation or impact assessment disclosed or shared pursuant to subdivision (a) is exempt from the California Public Records Act (Division 10 (commencing with Section 7920.000) of Title 1 of the Government Code).(c) Each day a covered ADS is used for which a performance evaluation or impact assessment has not been submitted to the Attorney General pursuant to this section is an additional violation of this section.
558665
666+
667+
559668 22756.4. (a) (1) Within 30 days of receiving a request from the Attorney General for a performance evaluation or impact assessment prepared pursuant to this chapter, a developer, deployer, or auditor of a covered ADS shall provide an unredacted copy of the document to the Attorney General.
560-
561-###### 22756.4.
562669
563670 (2) The Attorney General may share performance evaluations and impact assessments with other enforcement entities as necessary for enforcement purposes.
564671
565672 (b) (1) The disclosure or sharing of a performance evaluation or impact assessment pursuant to subdivision (a) does not constitute a waiver of any attorney-client privilege, work-product protection, or trade secret protection that might otherwise exist with respect to any information contained in the performance evaluation or impact assessment.
566673
567674 (2) A performance evaluation or impact assessment disclosed or shared pursuant to subdivision (a) is exempt from the California Public Records Act (Division 10 (commencing with Section 7920.000) of Title 1 of the Government Code).
568675
569676 (c) Each day a covered ADS is used for which a performance evaluation or impact assessment has not been submitted to the Attorney General pursuant to this section is an additional violation of this section.
570677
571-22756.5. (a) Any of the following public entities may bring a civil action against a developer, deployer, or auditor who violates this chapter:(1) The Attorney General.(2) A district attorney, county counsel, or city attorney for the jurisdiction in which the violation occurred.(3) A city prosecutor in any city having a full-time city prosecutor with the consent of the district attorney.(4) The Civil Rights Department.(5) The Labor Commissioner with respect to employment-related decisions only.(b) A court may award a prevailing plaintiff who brings an action pursuant to subdivision (a) all of the following:(1) Injunctive relief.(2) Declaratory relief.(3) Reasonable attorneys fees and litigation costs.(4) A civil penalty of up to twenty-five thousand dollars ($25,000) per violation.(c) A developer or deployer who contracts with a third party to perform the developers or deployers duties under this chapter, other than those duties related to auditing, is subject to liability under this chapter for the third partys failure to perform those duties.
678+22756.5. (a) Any of the following public entities may bring a civil action against a developer or deployer developer, deployer, or auditor who violates this chapter:(1) The Attorney General.(2) A district attorney, county counsel, or city attorney for the jurisdiction in which the violation occurred.(3) A city prosecutor in any city having a full-time city prosecutor with the consent of the district attorney.(4) The Civil Rights Department.(5) The Labor Commissioner with respect to employment-related decisions only.(b) A court may award a prevailing plaintiff who brings an action pursuant to subdivision (a) all of the following:(1) Injunctive relief.(2) Declaratory relief.(3) Reasonable attorneys fees and litigation costs.(4) A civil penalty of up to twenty-five thousand dollars ($25,000) per violation.(c) A developer or deployer who contracts with a third party to perform the developers or deployers duties under this chapter, other than those duties related to auditing, is subject to liability under this chapter for the third partys failure to perform those duties.
572679
573-22756.5. (a) Any of the following public entities may bring a civil action against a developer, deployer, or auditor who violates this chapter:
574680
575-###### 22756.5.
681+
682+22756.5. (a) Any of the following public entities may bring a civil action against a developer or deployer developer, deployer, or auditor who violates this chapter:
576683
577684 (1) The Attorney General.
578685
579686 (2) A district attorney, county counsel, or city attorney for the jurisdiction in which the violation occurred.
580687
581688 (3) A city prosecutor in any city having a full-time city prosecutor with the consent of the district attorney.
582689
583690 (4) The Civil Rights Department.
584691
585692 (5) The Labor Commissioner with respect to employment-related decisions only.
586693
587694 (b) A court may award a prevailing plaintiff who brings an action pursuant to subdivision (a) all of the following:
588695
589696 (1) Injunctive relief.
590697
591698 (2) Declaratory relief.
592699
593700 (3) Reasonable attorneys fees and litigation costs.
594701
595702 (4) A civil penalty of up to twenty-five thousand dollars ($25,000) per violation.
596703
597704 (c) A developer or deployer who contracts with a third party to perform the developers or deployers duties under this chapter, other than those duties related to auditing, is subject to liability under this chapter for the third partys failure to perform those duties.
598705
599-22756.6. (a) This chapter does not apply to an automated decision system the sole purpose of which is to do either of the following:(1) Detect, protect against, or respond to cybersecurity incidents or preserve the integrity or security of computer systems.(2) Operate aircraft in the national airspace.(b) The use of a consumer credit score to inform a consequential decision does not itself create an obligation under this chapter.
706+22756.6. (a) This chapter does not apply to an automated decision system the sole purpose of which is to do either of the following:(a)(1) Detect, protect against, or respond to cybersecurity incidents or preserve the integrity or security of computer systems.(b)(2) Operate aircraft in the national airspace.(b) The use of a consumer credit score to inform a consequential decision does not itself create an obligation under this chapter.
707+
708+
600709
601710 22756.6. (a) This chapter does not apply to an automated decision system the sole purpose of which is to do either of the following:
602711
603-###### 22756.6.
712+(a)
713+
714+
604715
605716 (1) Detect, protect against, or respond to cybersecurity incidents or preserve the integrity or security of computer systems.
717+
718+(b)
719+
720+
606721
607722 (2) Operate aircraft in the national airspace.
608723
609724 (b) The use of a consumer credit score to inform a consequential decision does not itself create an obligation under this chapter.
610725
611-22756.7. (a) The rights, remedies, and penalties established by this chapter are cumulative and shall not be construed to supersede the rights, remedies, or penalties established under other laws, including, but not limited to, Chapter 6 (commencing with Section 12940) of Part 2.8 of Division 3 of Title 2 of the Government Code and Section 51 of the Civil Code.(b) This chapter does not diminish the rights, privileges, or remedies of an employee under any other federal or state law or under any employment contract or collective bargaining agreement.(c) This chapter does not authorize any use of automated decision systems that is limited, restricted, or prohibited under any other applicable law.(d) This chapter does not authorize disparate impacts or disparate treatment limited, restricted, or prohibited under any other applicable law.
726+22756.7. (a) The rights, remedies, and penalties established by this chapter are cumulative and shall not be construed to supersede the rights, remedies, or penalties established under other laws, including, but not limited to, Chapter 6 (commencing with Section 12940) of Part 2.8 of Division 3 of Title 2 of the Government Code and Section 51 of the Civil Code.(b) This chapter does not diminish the rights, privileges, or remedies of an employee under any other federal or state law or under any employment contract or collective bargaining agreement.(c) This chapter does not authorize any use of automated decision systems that is limited, restricted, or prohibited under any other applicable law.(d) This chapter does not authorize disparate impacts or disparate treatment that are limited, restricted, or prohibited under any other applicable law.
727+
728+
612729
613730 22756.7. (a) The rights, remedies, and penalties established by this chapter are cumulative and shall not be construed to supersede the rights, remedies, or penalties established under other laws, including, but not limited to, Chapter 6 (commencing with Section 12940) of Part 2.8 of Division 3 of Title 2 of the Government Code and Section 51 of the Civil Code.
614-
615-###### 22756.7.
616731
617732 (b) This chapter does not diminish the rights, privileges, or remedies of an employee under any other federal or state law or under any employment contract or collective bargaining agreement.
618733
619734 (c) This chapter does not authorize any use of automated decision systems that is limited, restricted, or prohibited under any other applicable law.
620735
621-(d) This chapter does not authorize disparate impacts or disparate treatment limited, restricted, or prohibited under any other applicable law.
736+(d) This chapter does not authorize disparate impacts or disparate treatment that are limited, restricted, or prohibited under any other applicable law.
622737
623-SEC. 2. Section 51 of the Civil Code, as amended by Section 2.5 of Chapter 779 of the Statutes of 2024, is amended to read:51. (a) This section shall be known, and may be cited, as the Unruh Civil Rights Act.(b) All persons within the jurisdiction of this state are free and equal, and no matter what their sex, race, color, religion, ancestry, national origin, disability, medical condition, genetic information, marital status, sexual orientation, citizenship, primary language, or immigration status are entitled to the full and equal accommodations, advantages, facilities, privileges, or services in all business establishments of every kind whatsoever.(c) This section shall not be construed to confer any right or privilege on a person that is conditioned or limited by law or that is applicable alike to persons of every sex, color, race, religion, ancestry, national origin, disability, medical condition, marital status, sexual orientation, citizenship, primary language, or immigration status, or to persons regardless of their genetic information.(d) Nothing in this section shall be construed to require any construction, alteration, repair, structural or otherwise, or modification of any sort whatsoever, beyond that construction, alteration, repair, or modification that is otherwise required by other provisions of law, to any new or existing establishment, facility, building, improvement, or any other structure, nor shall anything in this section be construed to augment, restrict, or alter in any way the authority of the State Architect to require construction, alteration, repair, or modifications that the State Architect otherwise possesses pursuant to other laws.(e) For purposes of this section:(1) Disability means any mental or physical disability as defined in Sections 12926 and 12926.1 of the Government Code.(2) (A) Genetic information means, with respect to any individual, information about any of the following:(i) The individuals genetic tests.(ii) The genetic tests of family members of the individual.(iii) The manifestation of a disease or disorder in family members of the individual.(B) Genetic information includes any request for, or receipt of, genetic services, or participation in clinical research that includes genetic services, by an individual or any family member of the individual.(C) Genetic information does not include information about the sex or age of any individual.(3) Medical condition has the same meaning as defined in subdivision (i) of Section 12926 of the Government Code.(4) Race is inclusive of traits associated with race, including, but not limited to, hair texture and protective hairstyles. Protective hairstyles includes, but is not limited to, such hairstyles as braids, locs, and twists.(5) Religion includes all aspects of religious belief, observance, and practice.(6) Sex includes, but is not limited to, pregnancy, childbirth, or medical conditions related to pregnancy or childbirth. Sex also includes, but is not limited to, a persons gender. Gender means sex, and includes a persons gender identity and gender expression. Gender expression means a persons gender-related appearance and behavior whether or not stereotypically associated with the persons assigned sex at birth.(7) Sex, race, color, religion, ancestry, national origin, disability, medical condition, genetic information, marital status, sexual orientation, citizenship, primary language, or immigration status includes any of the following:(A) Any combination of those characteristics.(B) A perception that the person has any particular characteristic or characteristics within the listed categories or any combination of those characteristics.(C) A perception that the person is associated with a person who has, or is perceived to have, any particular characteristic or characteristics, or any combination of characteristics, within the listed categories.(8) Sexual orientation has the same meaning as defined in subdivision (s) of Section 12926 of the Government Code.(f) A violation of the right of any individual under the federal Americans with Disabilities Act of 1990 (Public Law 101-336) shall also constitute a violation of this section.(g) Verification of immigration status and any discrimination based upon verified immigration status, where required by federal law, shall not constitute a violation of this section.(h) Nothing in this section shall be construed to require the provision of services or documents in a language other than English, beyond that which is otherwise required by other provisions of federal, state, or local law, including Section 1632.(i) In an action alleging a violation of this section in which the defendants development, modification, or use of an automated decision system, as defined in Section 22756 of the Business and Professions Code, is alleged to have caused or facilitated the violation, the extent to which the defendant complied with Chapter 25 24.6 (commencing with Section 22756) of Division 8 of the Business and Professions Code is relevant to, but not conclusive of, whether the defendant violated this section. section, and a failure to comply with Chapter 24.6 (commencing with Section 22756) of Division 8 of the Business and Professions Code shall not, by itself, give rise to a presumption of unlawful intent.
738+
739+
740+A developer or deployer who contracts with a third party to comply with duties required under this chapter, other than those duties related to auditing, is subject to liability under this chapter for the third partys failure to comply with this chapter.
741+
742+
743+
744+SEC. 2. Section 51 of the Civil Code, as amended by Section 2.5 of Chapter 779 of the Statutes of 2024, is amended to read:51. (a) This section shall be known, and may be cited, as the Unruh Civil Rights Act.(b) All persons within the jurisdiction of this state are free and equal, and no matter what their sex, race, color, religion, ancestry, national origin, disability, medical condition, genetic information, marital status, sexual orientation, citizenship, primary language, or immigration status are entitled to the full and equal accommodations, advantages, facilities, privileges, or services in all business establishments of every kind whatsoever.(c) This section shall not be construed to confer any right or privilege on a person that is conditioned or limited by law or that is applicable alike to persons of every sex, color, race, religion, ancestry, national origin, disability, medical condition, marital status, sexual orientation, citizenship, primary language, or immigration status, or to persons regardless of their genetic information.(d) Nothing in this section shall be construed to require any construction, alteration, repair, structural or otherwise, or modification of any sort whatsoever, beyond that construction, alteration, repair, or modification that is otherwise required by other provisions of law, to any new or existing establishment, facility, building, improvement, or any other structure, nor shall anything in this section be construed to augment, restrict, or alter in any way the authority of the State Architect to require construction, alteration, repair, or modifications that the State Architect otherwise possesses pursuant to other laws.(e) For purposes of this section:(1) Disability means any mental or physical disability as defined in Sections 12926 and 12926.1 of the Government Code.(2) (A) Genetic information means, with respect to any individual, information about any of the following:(i) The individuals genetic tests.(ii) The genetic tests of family members of the individual.(iii) The manifestation of a disease or disorder in family members of the individual.(B) Genetic information includes any request for, or receipt of, genetic services, or participation in clinical research that includes genetic services, by an individual or any family member of the individual.(C) Genetic information does not include information about the sex or age of any individual.(3) Medical condition has the same meaning as defined in subdivision (i) of Section 12926 of the Government Code.(4) Race is inclusive of traits associated with race, including, but not limited to, hair texture and protective hairstyles. Protective hairstyles includes, but is not limited to, such hairstyles as braids, locs, and twists.(5) Religion includes all aspects of religious belief, observance, and practice.(6) Sex includes, but is not limited to, pregnancy, childbirth, or medical conditions related to pregnancy or childbirth. Sex also includes, but is not limited to, a persons gender. Gender means sex, and includes a persons gender identity and gender expression. Gender expression means a persons gender-related appearance and behavior whether or not stereotypically associated with the persons assigned sex at birth.(7) Sex, race, color, religion, ancestry, national origin, disability, medical condition, genetic information, marital status, sexual orientation, citizenship, primary language, or immigration status includes any of the following:(A) Any combination of those characteristics.(B) A perception that the person has any particular characteristic or characteristics within the listed categories or any combination of those characteristics.(C) A perception that the person is associated with a person who has, or is perceived to have, any particular characteristic or characteristics, or any combination of characteristics, within the listed categories.(8) Sexual orientation has the same meaning as defined in subdivision (s) of Section 12926 of the Government Code.(f) A violation of the right of any individual under the federal Americans with Disabilities Act of 1990 (Public Law 101-336) shall also constitute a violation of this section.(g) Verification of immigration status and any discrimination based upon verified immigration status, where required by federal law, shall not constitute a violation of this section.(h) Nothing in this section shall be construed to require the provision of services or documents in a language other than English, beyond that which is otherwise required by other provisions of federal, state, or local law, including Section 1632.(i) In an action alleging a violation of this section in which the defendants development, modification, or use of an automated decision system, as defined in Section 22756 of the Business and Professions Code, is alleged to have committed caused or facilitated the violation, the extent to which the defendant complied with Chapter 25 (commencing with Section 22756) of Division 8 of the Business and Professions Code is relevant to, but not conclusive of, whether a the defendant violated this section.
624745
625746 SEC. 2. Section 51 of the Civil Code, as amended by Section 2.5 of Chapter 779 of the Statutes of 2024, is amended to read:
626747
627748 ### SEC. 2.
628749
629-51. (a) This section shall be known, and may be cited, as the Unruh Civil Rights Act.(b) All persons within the jurisdiction of this state are free and equal, and no matter what their sex, race, color, religion, ancestry, national origin, disability, medical condition, genetic information, marital status, sexual orientation, citizenship, primary language, or immigration status are entitled to the full and equal accommodations, advantages, facilities, privileges, or services in all business establishments of every kind whatsoever.(c) This section shall not be construed to confer any right or privilege on a person that is conditioned or limited by law or that is applicable alike to persons of every sex, color, race, religion, ancestry, national origin, disability, medical condition, marital status, sexual orientation, citizenship, primary language, or immigration status, or to persons regardless of their genetic information.(d) Nothing in this section shall be construed to require any construction, alteration, repair, structural or otherwise, or modification of any sort whatsoever, beyond that construction, alteration, repair, or modification that is otherwise required by other provisions of law, to any new or existing establishment, facility, building, improvement, or any other structure, nor shall anything in this section be construed to augment, restrict, or alter in any way the authority of the State Architect to require construction, alteration, repair, or modifications that the State Architect otherwise possesses pursuant to other laws.(e) For purposes of this section:(1) Disability means any mental or physical disability as defined in Sections 12926 and 12926.1 of the Government Code.(2) (A) Genetic information means, with respect to any individual, information about any of the following:(i) The individuals genetic tests.(ii) The genetic tests of family members of the individual.(iii) The manifestation of a disease or disorder in family members of the individual.(B) Genetic information includes any request for, or receipt of, genetic services, or participation in clinical research that includes genetic services, by an individual or any family member of the individual.(C) Genetic information does not include information about the sex or age of any individual.(3) Medical condition has the same meaning as defined in subdivision (i) of Section 12926 of the Government Code.(4) Race is inclusive of traits associated with race, including, but not limited to, hair texture and protective hairstyles. Protective hairstyles includes, but is not limited to, such hairstyles as braids, locs, and twists.(5) Religion includes all aspects of religious belief, observance, and practice.(6) Sex includes, but is not limited to, pregnancy, childbirth, or medical conditions related to pregnancy or childbirth. Sex also includes, but is not limited to, a persons gender. Gender means sex, and includes a persons gender identity and gender expression. Gender expression means a persons gender-related appearance and behavior whether or not stereotypically associated with the persons assigned sex at birth.(7) Sex, race, color, religion, ancestry, national origin, disability, medical condition, genetic information, marital status, sexual orientation, citizenship, primary language, or immigration status includes any of the following:(A) Any combination of those characteristics.(B) A perception that the person has any particular characteristic or characteristics within the listed categories or any combination of those characteristics.(C) A perception that the person is associated with a person who has, or is perceived to have, any particular characteristic or characteristics, or any combination of characteristics, within the listed categories.(8) Sexual orientation has the same meaning as defined in subdivision (s) of Section 12926 of the Government Code.(f) A violation of the right of any individual under the federal Americans with Disabilities Act of 1990 (Public Law 101-336) shall also constitute a violation of this section.(g) Verification of immigration status and any discrimination based upon verified immigration status, where required by federal law, shall not constitute a violation of this section.(h) Nothing in this section shall be construed to require the provision of services or documents in a language other than English, beyond that which is otherwise required by other provisions of federal, state, or local law, including Section 1632.(i) In an action alleging a violation of this section in which the defendants development, modification, or use of an automated decision system, as defined in Section 22756 of the Business and Professions Code, is alleged to have caused or facilitated the violation, the extent to which the defendant complied with Chapter 25 24.6 (commencing with Section 22756) of Division 8 of the Business and Professions Code is relevant to, but not conclusive of, whether the defendant violated this section. section, and a failure to comply with Chapter 24.6 (commencing with Section 22756) of Division 8 of the Business and Professions Code shall not, by itself, give rise to a presumption of unlawful intent.
750+51. (a) This section shall be known, and may be cited, as the Unruh Civil Rights Act.(b) All persons within the jurisdiction of this state are free and equal, and no matter what their sex, race, color, religion, ancestry, national origin, disability, medical condition, genetic information, marital status, sexual orientation, citizenship, primary language, or immigration status are entitled to the full and equal accommodations, advantages, facilities, privileges, or services in all business establishments of every kind whatsoever.(c) This section shall not be construed to confer any right or privilege on a person that is conditioned or limited by law or that is applicable alike to persons of every sex, color, race, religion, ancestry, national origin, disability, medical condition, marital status, sexual orientation, citizenship, primary language, or immigration status, or to persons regardless of their genetic information.(d) Nothing in this section shall be construed to require any construction, alteration, repair, structural or otherwise, or modification of any sort whatsoever, beyond that construction, alteration, repair, or modification that is otherwise required by other provisions of law, to any new or existing establishment, facility, building, improvement, or any other structure, nor shall anything in this section be construed to augment, restrict, or alter in any way the authority of the State Architect to require construction, alteration, repair, or modifications that the State Architect otherwise possesses pursuant to other laws.(e) For purposes of this section:(1) Disability means any mental or physical disability as defined in Sections 12926 and 12926.1 of the Government Code.(2) (A) Genetic information means, with respect to any individual, information about any of the following:(i) The individuals genetic tests.(ii) The genetic tests of family members of the individual.(iii) The manifestation of a disease or disorder in family members of the individual.(B) Genetic information includes any request for, or receipt of, genetic services, or participation in clinical research that includes genetic services, by an individual or any family member of the individual.(C) Genetic information does not include information about the sex or age of any individual.(3) Medical condition has the same meaning as defined in subdivision (i) of Section 12926 of the Government Code.(4) Race is inclusive of traits associated with race, including, but not limited to, hair texture and protective hairstyles. Protective hairstyles includes, but is not limited to, such hairstyles as braids, locs, and twists.(5) Religion includes all aspects of religious belief, observance, and practice.(6) Sex includes, but is not limited to, pregnancy, childbirth, or medical conditions related to pregnancy or childbirth. Sex also includes, but is not limited to, a persons gender. Gender means sex, and includes a persons gender identity and gender expression. Gender expression means a persons gender-related appearance and behavior whether or not stereotypically associated with the persons assigned sex at birth.(7) Sex, race, color, religion, ancestry, national origin, disability, medical condition, genetic information, marital status, sexual orientation, citizenship, primary language, or immigration status includes any of the following:(A) Any combination of those characteristics.(B) A perception that the person has any particular characteristic or characteristics within the listed categories or any combination of those characteristics.(C) A perception that the person is associated with a person who has, or is perceived to have, any particular characteristic or characteristics, or any combination of characteristics, within the listed categories.(8) Sexual orientation has the same meaning as defined in subdivision (s) of Section 12926 of the Government Code.(f) A violation of the right of any individual under the federal Americans with Disabilities Act of 1990 (Public Law 101-336) shall also constitute a violation of this section.(g) Verification of immigration status and any discrimination based upon verified immigration status, where required by federal law, shall not constitute a violation of this section.(h) Nothing in this section shall be construed to require the provision of services or documents in a language other than English, beyond that which is otherwise required by other provisions of federal, state, or local law, including Section 1632.(i) In an action alleging a violation of this section in which the defendants development, modification, or use of an automated decision system, as defined in Section 22756 of the Business and Professions Code, is alleged to have committed caused or facilitated the violation, the extent to which the defendant complied with Chapter 25 (commencing with Section 22756) of Division 8 of the Business and Professions Code is relevant to, but not conclusive of, whether a the defendant violated this section.
630751
631-51. (a) This section shall be known, and may be cited, as the Unruh Civil Rights Act.(b) All persons within the jurisdiction of this state are free and equal, and no matter what their sex, race, color, religion, ancestry, national origin, disability, medical condition, genetic information, marital status, sexual orientation, citizenship, primary language, or immigration status are entitled to the full and equal accommodations, advantages, facilities, privileges, or services in all business establishments of every kind whatsoever.(c) This section shall not be construed to confer any right or privilege on a person that is conditioned or limited by law or that is applicable alike to persons of every sex, color, race, religion, ancestry, national origin, disability, medical condition, marital status, sexual orientation, citizenship, primary language, or immigration status, or to persons regardless of their genetic information.(d) Nothing in this section shall be construed to require any construction, alteration, repair, structural or otherwise, or modification of any sort whatsoever, beyond that construction, alteration, repair, or modification that is otherwise required by other provisions of law, to any new or existing establishment, facility, building, improvement, or any other structure, nor shall anything in this section be construed to augment, restrict, or alter in any way the authority of the State Architect to require construction, alteration, repair, or modifications that the State Architect otherwise possesses pursuant to other laws.(e) For purposes of this section:(1) Disability means any mental or physical disability as defined in Sections 12926 and 12926.1 of the Government Code.(2) (A) Genetic information means, with respect to any individual, information about any of the following:(i) The individuals genetic tests.(ii) The genetic tests of family members of the individual.(iii) The manifestation of a disease or disorder in family members of the individual.(B) Genetic information includes any request for, or receipt of, genetic services, or participation in clinical research that includes genetic services, by an individual or any family member of the individual.(C) Genetic information does not include information about the sex or age of any individual.(3) Medical condition has the same meaning as defined in subdivision (i) of Section 12926 of the Government Code.(4) Race is inclusive of traits associated with race, including, but not limited to, hair texture and protective hairstyles. Protective hairstyles includes, but is not limited to, such hairstyles as braids, locs, and twists.(5) Religion includes all aspects of religious belief, observance, and practice.(6) Sex includes, but is not limited to, pregnancy, childbirth, or medical conditions related to pregnancy or childbirth. Sex also includes, but is not limited to, a persons gender. Gender means sex, and includes a persons gender identity and gender expression. Gender expression means a persons gender-related appearance and behavior whether or not stereotypically associated with the persons assigned sex at birth.(7) Sex, race, color, religion, ancestry, national origin, disability, medical condition, genetic information, marital status, sexual orientation, citizenship, primary language, or immigration status includes any of the following:(A) Any combination of those characteristics.(B) A perception that the person has any particular characteristic or characteristics within the listed categories or any combination of those characteristics.(C) A perception that the person is associated with a person who has, or is perceived to have, any particular characteristic or characteristics, or any combination of characteristics, within the listed categories.(8) Sexual orientation has the same meaning as defined in subdivision (s) of Section 12926 of the Government Code.(f) A violation of the right of any individual under the federal Americans with Disabilities Act of 1990 (Public Law 101-336) shall also constitute a violation of this section.(g) Verification of immigration status and any discrimination based upon verified immigration status, where required by federal law, shall not constitute a violation of this section.(h) Nothing in this section shall be construed to require the provision of services or documents in a language other than English, beyond that which is otherwise required by other provisions of federal, state, or local law, including Section 1632.(i) In an action alleging a violation of this section in which the defendants development, modification, or use of an automated decision system, as defined in Section 22756 of the Business and Professions Code, is alleged to have caused or facilitated the violation, the extent to which the defendant complied with Chapter 25 24.6 (commencing with Section 22756) of Division 8 of the Business and Professions Code is relevant to, but not conclusive of, whether the defendant violated this section. section, and a failure to comply with Chapter 24.6 (commencing with Section 22756) of Division 8 of the Business and Professions Code shall not, by itself, give rise to a presumption of unlawful intent.
752+51. (a) This section shall be known, and may be cited, as the Unruh Civil Rights Act.(b) All persons within the jurisdiction of this state are free and equal, and no matter what their sex, race, color, religion, ancestry, national origin, disability, medical condition, genetic information, marital status, sexual orientation, citizenship, primary language, or immigration status are entitled to the full and equal accommodations, advantages, facilities, privileges, or services in all business establishments of every kind whatsoever.(c) This section shall not be construed to confer any right or privilege on a person that is conditioned or limited by law or that is applicable alike to persons of every sex, color, race, religion, ancestry, national origin, disability, medical condition, marital status, sexual orientation, citizenship, primary language, or immigration status, or to persons regardless of their genetic information.(d) Nothing in this section shall be construed to require any construction, alteration, repair, structural or otherwise, or modification of any sort whatsoever, beyond that construction, alteration, repair, or modification that is otherwise required by other provisions of law, to any new or existing establishment, facility, building, improvement, or any other structure, nor shall anything in this section be construed to augment, restrict, or alter in any way the authority of the State Architect to require construction, alteration, repair, or modifications that the State Architect otherwise possesses pursuant to other laws.(e) For purposes of this section:(1) Disability means any mental or physical disability as defined in Sections 12926 and 12926.1 of the Government Code.(2) (A) Genetic information means, with respect to any individual, information about any of the following:(i) The individuals genetic tests.(ii) The genetic tests of family members of the individual.(iii) The manifestation of a disease or disorder in family members of the individual.(B) Genetic information includes any request for, or receipt of, genetic services, or participation in clinical research that includes genetic services, by an individual or any family member of the individual.(C) Genetic information does not include information about the sex or age of any individual.(3) Medical condition has the same meaning as defined in subdivision (i) of Section 12926 of the Government Code.(4) Race is inclusive of traits associated with race, including, but not limited to, hair texture and protective hairstyles. Protective hairstyles includes, but is not limited to, such hairstyles as braids, locs, and twists.(5) Religion includes all aspects of religious belief, observance, and practice.(6) Sex includes, but is not limited to, pregnancy, childbirth, or medical conditions related to pregnancy or childbirth. Sex also includes, but is not limited to, a persons gender. Gender means sex, and includes a persons gender identity and gender expression. Gender expression means a persons gender-related appearance and behavior whether or not stereotypically associated with the persons assigned sex at birth.(7) Sex, race, color, religion, ancestry, national origin, disability, medical condition, genetic information, marital status, sexual orientation, citizenship, primary language, or immigration status includes any of the following:(A) Any combination of those characteristics.(B) A perception that the person has any particular characteristic or characteristics within the listed categories or any combination of those characteristics.(C) A perception that the person is associated with a person who has, or is perceived to have, any particular characteristic or characteristics, or any combination of characteristics, within the listed categories.(8) Sexual orientation has the same meaning as defined in subdivision (s) of Section 12926 of the Government Code.(f) A violation of the right of any individual under the federal Americans with Disabilities Act of 1990 (Public Law 101-336) shall also constitute a violation of this section.(g) Verification of immigration status and any discrimination based upon verified immigration status, where required by federal law, shall not constitute a violation of this section.(h) Nothing in this section shall be construed to require the provision of services or documents in a language other than English, beyond that which is otherwise required by other provisions of federal, state, or local law, including Section 1632.(i) In an action alleging a violation of this section in which the defendants development, modification, or use of an automated decision system, as defined in Section 22756 of the Business and Professions Code, is alleged to have committed caused or facilitated the violation, the extent to which the defendant complied with Chapter 25 (commencing with Section 22756) of Division 8 of the Business and Professions Code is relevant to, but not conclusive of, whether a the defendant violated this section.
632753
633-51. (a) This section shall be known, and may be cited, as the Unruh Civil Rights Act.(b) All persons within the jurisdiction of this state are free and equal, and no matter what their sex, race, color, religion, ancestry, national origin, disability, medical condition, genetic information, marital status, sexual orientation, citizenship, primary language, or immigration status are entitled to the full and equal accommodations, advantages, facilities, privileges, or services in all business establishments of every kind whatsoever.(c) This section shall not be construed to confer any right or privilege on a person that is conditioned or limited by law or that is applicable alike to persons of every sex, color, race, religion, ancestry, national origin, disability, medical condition, marital status, sexual orientation, citizenship, primary language, or immigration status, or to persons regardless of their genetic information.(d) Nothing in this section shall be construed to require any construction, alteration, repair, structural or otherwise, or modification of any sort whatsoever, beyond that construction, alteration, repair, or modification that is otherwise required by other provisions of law, to any new or existing establishment, facility, building, improvement, or any other structure, nor shall anything in this section be construed to augment, restrict, or alter in any way the authority of the State Architect to require construction, alteration, repair, or modifications that the State Architect otherwise possesses pursuant to other laws.(e) For purposes of this section:(1) Disability means any mental or physical disability as defined in Sections 12926 and 12926.1 of the Government Code.(2) (A) Genetic information means, with respect to any individual, information about any of the following:(i) The individuals genetic tests.(ii) The genetic tests of family members of the individual.(iii) The manifestation of a disease or disorder in family members of the individual.(B) Genetic information includes any request for, or receipt of, genetic services, or participation in clinical research that includes genetic services, by an individual or any family member of the individual.(C) Genetic information does not include information about the sex or age of any individual.(3) Medical condition has the same meaning as defined in subdivision (i) of Section 12926 of the Government Code.(4) Race is inclusive of traits associated with race, including, but not limited to, hair texture and protective hairstyles. Protective hairstyles includes, but is not limited to, such hairstyles as braids, locs, and twists.(5) Religion includes all aspects of religious belief, observance, and practice.(6) Sex includes, but is not limited to, pregnancy, childbirth, or medical conditions related to pregnancy or childbirth. Sex also includes, but is not limited to, a persons gender. Gender means sex, and includes a persons gender identity and gender expression. Gender expression means a persons gender-related appearance and behavior whether or not stereotypically associated with the persons assigned sex at birth.(7) Sex, race, color, religion, ancestry, national origin, disability, medical condition, genetic information, marital status, sexual orientation, citizenship, primary language, or immigration status includes any of the following:(A) Any combination of those characteristics.(B) A perception that the person has any particular characteristic or characteristics within the listed categories or any combination of those characteristics.(C) A perception that the person is associated with a person who has, or is perceived to have, any particular characteristic or characteristics, or any combination of characteristics, within the listed categories.(8) Sexual orientation has the same meaning as defined in subdivision (s) of Section 12926 of the Government Code.(f) A violation of the right of any individual under the federal Americans with Disabilities Act of 1990 (Public Law 101-336) shall also constitute a violation of this section.(g) Verification of immigration status and any discrimination based upon verified immigration status, where required by federal law, shall not constitute a violation of this section.(h) Nothing in this section shall be construed to require the provision of services or documents in a language other than English, beyond that which is otherwise required by other provisions of federal, state, or local law, including Section 1632.(i) In an action alleging a violation of this section in which the defendants development, modification, or use of an automated decision system, as defined in Section 22756 of the Business and Professions Code, is alleged to have caused or facilitated the violation, the extent to which the defendant complied with Chapter 25 24.6 (commencing with Section 22756) of Division 8 of the Business and Professions Code is relevant to, but not conclusive of, whether the defendant violated this section. section, and a failure to comply with Chapter 24.6 (commencing with Section 22756) of Division 8 of the Business and Professions Code shall not, by itself, give rise to a presumption of unlawful intent.
754+51. (a) This section shall be known, and may be cited, as the Unruh Civil Rights Act.(b) All persons within the jurisdiction of this state are free and equal, and no matter what their sex, race, color, religion, ancestry, national origin, disability, medical condition, genetic information, marital status, sexual orientation, citizenship, primary language, or immigration status are entitled to the full and equal accommodations, advantages, facilities, privileges, or services in all business establishments of every kind whatsoever.(c) This section shall not be construed to confer any right or privilege on a person that is conditioned or limited by law or that is applicable alike to persons of every sex, color, race, religion, ancestry, national origin, disability, medical condition, marital status, sexual orientation, citizenship, primary language, or immigration status, or to persons regardless of their genetic information.(d) Nothing in this section shall be construed to require any construction, alteration, repair, structural or otherwise, or modification of any sort whatsoever, beyond that construction, alteration, repair, or modification that is otherwise required by other provisions of law, to any new or existing establishment, facility, building, improvement, or any other structure, nor shall anything in this section be construed to augment, restrict, or alter in any way the authority of the State Architect to require construction, alteration, repair, or modifications that the State Architect otherwise possesses pursuant to other laws.(e) For purposes of this section:(1) Disability means any mental or physical disability as defined in Sections 12926 and 12926.1 of the Government Code.(2) (A) Genetic information means, with respect to any individual, information about any of the following:(i) The individuals genetic tests.(ii) The genetic tests of family members of the individual.(iii) The manifestation of a disease or disorder in family members of the individual.(B) Genetic information includes any request for, or receipt of, genetic services, or participation in clinical research that includes genetic services, by an individual or any family member of the individual.(C) Genetic information does not include information about the sex or age of any individual.(3) Medical condition has the same meaning as defined in subdivision (i) of Section 12926 of the Government Code.(4) Race is inclusive of traits associated with race, including, but not limited to, hair texture and protective hairstyles. Protective hairstyles includes, but is not limited to, such hairstyles as braids, locs, and twists.(5) Religion includes all aspects of religious belief, observance, and practice.(6) Sex includes, but is not limited to, pregnancy, childbirth, or medical conditions related to pregnancy or childbirth. Sex also includes, but is not limited to, a persons gender. Gender means sex, and includes a persons gender identity and gender expression. Gender expression means a persons gender-related appearance and behavior whether or not stereotypically associated with the persons assigned sex at birth.(7) Sex, race, color, religion, ancestry, national origin, disability, medical condition, genetic information, marital status, sexual orientation, citizenship, primary language, or immigration status includes any of the following:(A) Any combination of those characteristics.(B) A perception that the person has any particular characteristic or characteristics within the listed categories or any combination of those characteristics.(C) A perception that the person is associated with a person who has, or is perceived to have, any particular characteristic or characteristics, or any combination of characteristics, within the listed categories.(8) Sexual orientation has the same meaning as defined in subdivision (s) of Section 12926 of the Government Code.(f) A violation of the right of any individual under the federal Americans with Disabilities Act of 1990 (Public Law 101-336) shall also constitute a violation of this section.(g) Verification of immigration status and any discrimination based upon verified immigration status, where required by federal law, shall not constitute a violation of this section.(h) Nothing in this section shall be construed to require the provision of services or documents in a language other than English, beyond that which is otherwise required by other provisions of federal, state, or local law, including Section 1632.(i) In an action alleging a violation of this section in which the defendants development, modification, or use of an automated decision system, as defined in Section 22756 of the Business and Professions Code, is alleged to have committed caused or facilitated the violation, the extent to which the defendant complied with Chapter 25 (commencing with Section 22756) of Division 8 of the Business and Professions Code is relevant to, but not conclusive of, whether a the defendant violated this section.
755+
756+
634757
635758 51. (a) This section shall be known, and may be cited, as the Unruh Civil Rights Act.
636-
637-###### 51.
638759
639760 (b) All persons within the jurisdiction of this state are free and equal, and no matter what their sex, race, color, religion, ancestry, national origin, disability, medical condition, genetic information, marital status, sexual orientation, citizenship, primary language, or immigration status are entitled to the full and equal accommodations, advantages, facilities, privileges, or services in all business establishments of every kind whatsoever.
640761
641762 (c) This section shall not be construed to confer any right or privilege on a person that is conditioned or limited by law or that is applicable alike to persons of every sex, color, race, religion, ancestry, national origin, disability, medical condition, marital status, sexual orientation, citizenship, primary language, or immigration status, or to persons regardless of their genetic information.
642763
643764 (d) Nothing in this section shall be construed to require any construction, alteration, repair, structural or otherwise, or modification of any sort whatsoever, beyond that construction, alteration, repair, or modification that is otherwise required by other provisions of law, to any new or existing establishment, facility, building, improvement, or any other structure, nor shall anything in this section be construed to augment, restrict, or alter in any way the authority of the State Architect to require construction, alteration, repair, or modifications that the State Architect otherwise possesses pursuant to other laws.
644765
645766 (e) For purposes of this section:
646767
647768 (1) Disability means any mental or physical disability as defined in Sections 12926 and 12926.1 of the Government Code.
648769
649770 (2) (A) Genetic information means, with respect to any individual, information about any of the following:
650771
651772 (i) The individuals genetic tests.
652773
653774 (ii) The genetic tests of family members of the individual.
654775
655776 (iii) The manifestation of a disease or disorder in family members of the individual.
656777
657778 (B) Genetic information includes any request for, or receipt of, genetic services, or participation in clinical research that includes genetic services, by an individual or any family member of the individual.
658779
659780 (C) Genetic information does not include information about the sex or age of any individual.
660781
661782 (3) Medical condition has the same meaning as defined in subdivision (i) of Section 12926 of the Government Code.
662783
663784 (4) Race is inclusive of traits associated with race, including, but not limited to, hair texture and protective hairstyles. Protective hairstyles includes, but is not limited to, such hairstyles as braids, locs, and twists.
664785
665786 (5) Religion includes all aspects of religious belief, observance, and practice.
666787
667788 (6) Sex includes, but is not limited to, pregnancy, childbirth, or medical conditions related to pregnancy or childbirth. Sex also includes, but is not limited to, a persons gender. Gender means sex, and includes a persons gender identity and gender expression. Gender expression means a persons gender-related appearance and behavior whether or not stereotypically associated with the persons assigned sex at birth.
668789
669790 (7) Sex, race, color, religion, ancestry, national origin, disability, medical condition, genetic information, marital status, sexual orientation, citizenship, primary language, or immigration status includes any of the following:
670791
671792 (A) Any combination of those characteristics.
672793
673794 (B) A perception that the person has any particular characteristic or characteristics within the listed categories or any combination of those characteristics.
674795
675796 (C) A perception that the person is associated with a person who has, or is perceived to have, any particular characteristic or characteristics, or any combination of characteristics, within the listed categories.
676797
677798 (8) Sexual orientation has the same meaning as defined in subdivision (s) of Section 12926 of the Government Code.
678799
679800 (f) A violation of the right of any individual under the federal Americans with Disabilities Act of 1990 (Public Law 101-336) shall also constitute a violation of this section.
680801
681802 (g) Verification of immigration status and any discrimination based upon verified immigration status, where required by federal law, shall not constitute a violation of this section.
682803
683804 (h) Nothing in this section shall be construed to require the provision of services or documents in a language other than English, beyond that which is otherwise required by other provisions of federal, state, or local law, including Section 1632.
684805
685-(i) In an action alleging a violation of this section in which the defendants development, modification, or use of an automated decision system, as defined in Section 22756 of the Business and Professions Code, is alleged to have caused or facilitated the violation, the extent to which the defendant complied with Chapter 25 24.6 (commencing with Section 22756) of Division 8 of the Business and Professions Code is relevant to, but not conclusive of, whether the defendant violated this section. section, and a failure to comply with Chapter 24.6 (commencing with Section 22756) of Division 8 of the Business and Professions Code shall not, by itself, give rise to a presumption of unlawful intent.
806+(i) In an action alleging a violation of this section in which the defendants development, modification, or use of an automated decision system, as defined in Section 22756 of the Business and Professions Code, is alleged to have committed caused or facilitated the violation, the extent to which the defendant complied with Chapter 25 (commencing with Section 22756) of Division 8 of the Business and Professions Code is relevant to, but not conclusive of, whether a the defendant violated this section.
686807
687-SEC. 3. Article 3 (commencing with Section 12959) is added to Chapter 6 of Part 2.8 of Division 3 of Title 2 of the Government Code, to read: Article 3. Automated Decision Systems12959. In an action alleging a violation of this chapter in which the defendants development, modification, or use of an automated decision system, as defined in Section 22756 of the Business and Professions Code, is alleged to have caused or facilitated the violation, the extent to which the defendant complied with Chapter 24.6 (commencing with Section 22756) of Division 8 of the Business and Professions Code is relevant to, but not conclusive of, whether the defendant violated this chapter.
808+SEC. 3. Article 3 (commencing with Section 12959) is added to Chapter 6 of Part 2.8 of Division 3 of Title 2 of the Government Code, to read: Article 3. Automated Decision Systems12959. In an action alleging a violation of this chapter in which the defendants development, modification, or use of an automated decision system, as defined in Section 22756 of the Business and Professions Code, is alleged to have committed caused or facilitated the violation, the extent to which the defendant complied with Chapter 24.6 (commencing with Section 22756) of Division 8 of the Business and Professions Code is relevant to, but not conclusive of, whether a the defendant violated this chapter.
688809
689810 SEC. 3. Article 3 (commencing with Section 12959) is added to Chapter 6 of Part 2.8 of Division 3 of Title 2 of the Government Code, to read:
690811
691812 ### SEC. 3.
692813
693-Article 3. Automated Decision Systems12959. In an action alleging a violation of this chapter in which the defendants development, modification, or use of an automated decision system, as defined in Section 22756 of the Business and Professions Code, is alleged to have caused or facilitated the violation, the extent to which the defendant complied with Chapter 24.6 (commencing with Section 22756) of Division 8 of the Business and Professions Code is relevant to, but not conclusive of, whether the defendant violated this chapter.
814+ Article 3. Automated Decision Systems12959. In an action alleging a violation of this chapter in which the defendants development, modification, or use of an automated decision system, as defined in Section 22756 of the Business and Professions Code, is alleged to have committed caused or facilitated the violation, the extent to which the defendant complied with Chapter 24.6 (commencing with Section 22756) of Division 8 of the Business and Professions Code is relevant to, but not conclusive of, whether a the defendant violated this chapter.
694815
695-Article 3. Automated Decision Systems12959. In an action alleging a violation of this chapter in which the defendants development, modification, or use of an automated decision system, as defined in Section 22756 of the Business and Professions Code, is alleged to have caused or facilitated the violation, the extent to which the defendant complied with Chapter 24.6 (commencing with Section 22756) of Division 8 of the Business and Professions Code is relevant to, but not conclusive of, whether the defendant violated this chapter.
816+ Article 3. Automated Decision Systems12959. In an action alleging a violation of this chapter in which the defendants development, modification, or use of an automated decision system, as defined in Section 22756 of the Business and Professions Code, is alleged to have committed caused or facilitated the violation, the extent to which the defendant complied with Chapter 24.6 (commencing with Section 22756) of Division 8 of the Business and Professions Code is relevant to, but not conclusive of, whether a the defendant violated this chapter.
696817
697818 Article 3. Automated Decision Systems
698819
699820 Article 3. Automated Decision Systems
700821
701-##### Article 3. Automated Decision Systems
822+12959. In an action alleging a violation of this chapter in which the defendants development, modification, or use of an automated decision system, as defined in Section 22756 of the Business and Professions Code, is alleged to have committed caused or facilitated the violation, the extent to which the defendant complied with Chapter 24.6 (commencing with Section 22756) of Division 8 of the Business and Professions Code is relevant to, but not conclusive of, whether a the defendant violated this chapter.
702823
703-12959. In an action alleging a violation of this chapter in which the defendants development, modification, or use of an automated decision system, as defined in Section 22756 of the Business and Professions Code, is alleged to have caused or facilitated the violation, the extent to which the defendant complied with Chapter 24.6 (commencing with Section 22756) of Division 8 of the Business and Professions Code is relevant to, but not conclusive of, whether the defendant violated this chapter.
704824
705-12959. In an action alleging a violation of this chapter in which the defendants development, modification, or use of an automated decision system, as defined in Section 22756 of the Business and Professions Code, is alleged to have caused or facilitated the violation, the extent to which the defendant complied with Chapter 24.6 (commencing with Section 22756) of Division 8 of the Business and Professions Code is relevant to, but not conclusive of, whether the defendant violated this chapter.
706825
707-###### 12959.
826+12959. In an action alleging a violation of this chapter in which the defendants development, modification, or use of an automated decision system, as defined in Section 22756 of the Business and Professions Code, is alleged to have committed caused or facilitated the violation, the extent to which the defendant complied with Chapter 24.6 (commencing with Section 22756) of Division 8 of the Business and Professions Code is relevant to, but not conclusive of, whether a the defendant violated this chapter.
708827
709828 SEC. 4. The Legislature finds and declares that Section 1 of this act, which adds Chapter 24.6 (commencing with Section 22756) to Division 8 of the Business and Professions Code, imposes a limitation on the publics right of access to the meetings of public bodies or the writings of public officials and agencies within the meaning of Section 3 of Article I of the California Constitution. Pursuant to that constitutional provision, the Legislature makes the following findings to demonstrate the interest protected by this limitation and the need for protecting that interest:In order to protect proprietary information, it is necessary that trade secrets disclosed in performance evaluations and impact assessments to agencies and departments pursuant to Section 1 of this act remain confidential.
710829
711830 SEC. 4. The Legislature finds and declares that Section 1 of this act, which adds Chapter 24.6 (commencing with Section 22756) to Division 8 of the Business and Professions Code, imposes a limitation on the publics right of access to the meetings of public bodies or the writings of public officials and agencies within the meaning of Section 3 of Article I of the California Constitution. Pursuant to that constitutional provision, the Legislature makes the following findings to demonstrate the interest protected by this limitation and the need for protecting that interest:In order to protect proprietary information, it is necessary that trade secrets disclosed in performance evaluations and impact assessments to agencies and departments pursuant to Section 1 of this act remain confidential.
712831
713832 SEC. 4. The Legislature finds and declares that Section 1 of this act, which adds Chapter 24.6 (commencing with Section 22756) to Division 8 of the Business and Professions Code, imposes a limitation on the publics right of access to the meetings of public bodies or the writings of public officials and agencies within the meaning of Section 3 of Article I of the California Constitution. Pursuant to that constitutional provision, the Legislature makes the following findings to demonstrate the interest protected by this limitation and the need for protecting that interest:
714833
715834 ### SEC. 4.
716835
717836 In order to protect proprietary information, it is necessary that trade secrets disclosed in performance evaluations and impact assessments to agencies and departments pursuant to Section 1 of this act remain confidential.