State guide
California AI Governance Guide for Local Governments
A practical starting point for California cities, counties, school districts, special districts, public healthcare entities, law-enforcement agencies, and other local bodies evaluating, purchasing, or using AI-enabled systems.
Disclaimer
This resource is for policy and governance education only. It is not legal advice. Local governments should consult their attorney or legal counsel before making procurement, compliance, or deployment decisions.
On this page
- State AI policy context
- At a glance
- Public records and AI-assisted work
- Local records retention
- Privacy, security, and breach response
- Civil liability and human accountability
- Employment and automated-decision systems
- AI-generated law-enforcement reports
- Schools, pupil records, and educational AI
- Healthcare communications and AI systems
- State programs — not universal mandates
- Enhanced review for high-risk uses
- California local examples
- First 90 days
- Questions for counsel, records, HR, privacy
- California-specific procurement questions
- Corrections and source updates
- Scope of this guide
- Official sources
California regulates AI through a layered set of general and use-specific rules.
As of July 27, 2026, California has not enacted one comprehensive governance code for every municipal use of artificial intelligence. A local agency’s duties depend on what the system does, who uses it, what data it handles, what records it creates, and whether the agency is acting as an employer, law-enforcement agency, school district, healthcare entity, or another regulated body.
State-agency AI programs are important policy signals, but many do not legally extend to cities and counties. Local officials should confirm the covered entity and operative date before treating any California AI rule as a municipal requirement.
State AI policy context
How California’s state AI framework reaches — and does not reach — local agencies
State AI policy context
How California’s state AI framework reaches — and does not reach — local agencies
Government Code section 11546.45.5 requires the California Department of Technology to inventory high-risk automated decision systems used, developed, or procured by defined state agencies. The statutory definition does not include cities, counties, or ordinary local agencies.[15]
The Generative Artificial Intelligence Accountability Act, SB 896, requires a state agency or department using generative AI to communicate directly with a person about government services or benefits to provide an AI disclaimer and a route to a human employee. The text does not impose that particular requirement on every local government.[16]
California’s June 2026 SITeS procurement procedures allow local government agencies to use specified pre-negotiated contracts for general-office-productivity GenAI tools. A participating local agency must use the local-government authorization form identified in the procedures and submit it to the CDT contract administrator. The procedures encourage local agencies to conduct their own internal risk assessments; they do not make the state executive-branch risk-assessment workflow a universal municipal mandate.[17]
The California AI Transparency Act becomes operative on August 2, 2026. It principally regulates covered GenAI providers; specified large online platforms and GenAI hosting platforms have duties beginning January 1, 2027, and specified capture-device manufacturers have duties beginning January 1, 2028. It does not create a general municipal AI inventory or impact-assessment requirement merely because a local agency uses an AI product.[18]
SB 53 primarily regulates frontier-model developers and preempts local rules adopted on or after January 1, 2025 that specifically regulate frontier developers’ management of catastrophic risk. That provision should not be restated as a general state takeover of municipal AI procurement or operational governance.[19]
Local-government meaning
Local governments should separate three questions:
- 01What California law directly applies to this local agency or function?
- 02What state-government policy may be useful as a voluntary model?
- 03What contract safeguards and internal governance should the agency adopt even when no AI-specific statute requires them?
At a glance
Six things California local officials should know
At a glance
Six things California local officials should know
Public-record status depends on the record's relationship to public business
The California Public Records Act defines public records to include writings relating to the conduct of the public’s business that are prepared, owned, used, or retained by a state or local agency, regardless of physical form. “Writing” is defined broadly and includes electronic forms of communication and representation.[1][2]
A covered defendant cannot use AI autonomy as a defense
Effective January 1, 2026, Civil Code section 1714.46 bars a defendant that developed, modified, or used AI alleged to have caused harm from asserting that the AI autonomously caused the harm. The statute preserves other affirmative defenses and relevant causation, foreseeability, and comparative-fault evidence.[24]
Local-government employers are covered by employment AI rules
California’s Fair Employment and Housing Act definition of employer includes the state, political and civil subdivisions, and cities. Effective October 1, 2025, California regulations clarify that using an automated-decision system can violate employment antidiscrimination law and that relevant automated-decision data may fall within employment recordkeeping requirements.[8][9]
AI-drafted law-enforcement reports now carry specific requirements
Penal Code section 13663, effective January 1, 2026, directly applies to covered state and local law-enforcement agencies using defined AI systems to draft reports. It requires an agency policy, AI disclosure, officer verification, first-draft retention, an audit trail, and limits on vendor data use.[10]
School and healthcare rules are use-specific
California requires specified terms in local educational agency contracts involving pupil records and digital educational software. It also requires disclosures and a route to a human for certain AI-generated patient clinical communications, subject to a licensed-provider review exception.[11][12][13]
State AI programs should not be mislabeled as local mandates
What applies now — 1
Public records and AI-assisted local government work
What applies now — 1
Public records and AI-assisted local government work
The California Public Records Act defines a public record as a writing containing information relating to the conduct of the public’s business that is prepared, owned, used, or retained by a state or local agency, regardless of physical form.[1]
The definition of “writing” includes words, pictures, sounds, symbols, email transmissions, and every other means of recording a communication or representation, regardless of storage method.[2]
When an identifiable, nonexempt public record is held electronically, an agency generally must make it available electronically upon request and, when applicable, in an electronic format in which it holds the information.[3]
What this may mean for AI
An AI prompt, output, transcript, recommendation, score, log, review note, or system record may qualify as a public record when it satisfies the statutory public-business and agency-use tests. That conclusion depends on the facts and is an application of general public-records law, not an AI-specific rule. Do not state that every prompt, output, or vendor log is automatically a public record.
Questions local officials should ask
- Does the material relate to the conduct of the public's business?
- Was it prepared, owned, used, or retained by the agency?
- Did it inform a recommendation, communication, employment action, enforcement action, permit, benefit, healthcare communication, school action, or other government decision?
- Is the material stored only in a vendor platform?
- Can the agency search and export it without vendor assistance?
- Is it an identifiable record in a format the agency holds?
- Does a statutory exemption or confidentiality rule apply?
- Can exempt information be segregated from disclosable information?
- Is the human reviewer's role documented?
- Can the agency preserve relevant material during litigation, an audit, an investigation, or an active records request?
Recommended governance action
Create interim internal guidance explaining:
- 01when AI-assisted work should be preserved;
- 02which office classifies the record and applies exemptions;
- 03what prompts, outputs, metadata, versions, logs, and human-review notes are needed for consequential uses;
- 04how records are searched and exported from vendor systems;
- 05how confidential, privileged, security-sensitive, and personal information is protected.
What applies now — 2
Local records retention
What applies now — 2
Local records retention
California does not establish one retention period for every AI-related record.
Government Code section 34090 generally prevents a city from destroying a city record less than two years old and establishes an approval process involving the legislative body, department head, and city attorney, subject to listed exceptions and other laws.[4]
Government Code section 26202 provides a separate framework for county records and permits destruction of certain records more than two years old when its conditions are met.[5]
Government Code section 60201 provides a separate destruction and retention-schedule framework for special districts. It preserves specified categories of records, including records subject to a pending Public Records Act request and records relating to pending claims or litigation.[25]
Other statutes, local charters, records schedules, litigation holds, audits, grants, employment rules, law-enforcement requirements, education requirements, healthcare requirements, and function-specific laws may require longer retention.
Practical implication
Do not create an arbitrary “AI records retention period” for every system.
Classify AI-related records according to:
- the public function they document;
- whether the entity is a city, county, school district, special district, law-enforcement agency, healthcare entity, or another body;
- the underlying transaction, communication, or decision;
- any use-specific statute;
- the agency's adopted retention schedule;
- litigation, investigation, audit, and public-records constraints.
Minimum inventory fields
For every AI-enabled system, record:
- records created and received;
- prompts and outputs retained;
- model and system versions;
- audit and activity logs available;
- human-review records;
- storage location;
- export formats;
- applicable schedule or retention authority;
- records owner;
- vendor responsibilities;
- legal-hold capability;
- termination, migration, and deletion process.
What applies now — 3
Privacy, security, and breach response
What applies now — 3
Privacy, security, and breach response
The California Constitution identifies privacy as an inalienable right and separately protects public access to information concerning the conduct of the public’s business. Local agencies should assess privacy, access, due process, and equal-protection questions together rather than treating transparency or privacy as an absolute answer in every case.[6]
Civil Code section 1798.29 applies its breach-notification provisions to local agencies. It requires notice when qualifying personal information in agency-owned or licensed computerized data is acquired, or reasonably believed acquired, by an unauthorized person under the statutory conditions. It also addresses agencies that maintain data they do not own and identifies covered data that can include medical information, health-insurance information, specified biometric data, and automated license-plate-recognition information.[7]
AI procurement implications
Before placing resident, employee, student, patient, public-safety, biometric, location, or other sensitive data in an AI system, determine:
- whether the data may lawfully be used for the proposed purpose;
- whether the vendor may retain or reuse it;
- whether prompts, attachments, outputs, and derived data enter model training or evaluation;
- which subcontractors and model providers receive it;
- where it is stored and processed;
- how the agency learns of unauthorized access;
- who conducts investigation, notice, remediation, and preservation;
- whether deletion requests can be executed without destroying records the agency must retain.
Recommended contract safeguards
Require clear provisions addressing:
- 01permitted purposes;
- 02data minimization;
- 03security standards;
- 04subcontractors and model providers;
- 05model training and secondary use;
- 06incident notification and cooperation;
- 07preservation of evidence and logs;
- 08agency access and export;
- 09deletion and certified destruction;
- 10conflicts between deletion duties and government retention requirements.
What applies now — 4
Civil liability and human accountability
What applies now — 4
Civil liability and human accountability
Effective January 1, 2026, Civil Code section 1714.46 provides that, in an action against a defendant that developed, modified, or used AI alleged to have caused harm to the plaintiff, the defendant may not assert as a defense that the AI autonomously caused the harm.[24]
The section preserves other affirmative defenses, including evidence relevant to causation or foreseeability, and evidence relevant to another person’s or entity’s comparative fault.[24]
Important qualification
The section addresses a particular defense; it does not itself state a general AI cause of action or resolve whether breach, causation, damages, public-entity immunity, or another defense applies. Local counsel should analyze the statute together with the Government Claims Act, public-entity immunities, contract terms, and the facts of a particular use.
Procurement and governance implications
- Do not assume that labeling a system “autonomous” transfers responsibility away from the agency or vendor.
- Define responsibility for design, configuration, deployment, human review, monitoring, correction, suspension, and incident response.
- Preserve model, version, input, output, human-action, and audit evidence needed to evaluate causation and responsibility.
- Require vendor cooperation, insurance information, indemnity analysis, and access to relevant records, subject to counsel's review.
What applies now — 5
Employment and automated-decision systems
What applies now — 5
Employment and automated-decision systems
California’s Fair Employment and Housing Act applies to employers that include the state, political and civil subdivisions, and cities.[9]
Effective October 1, 2025, California’s Civil Rights Council regulations clarify how existing employment antidiscrimination law applies when employers or their agents use automated-decision systems. The Civil Rights Department explains that such use may violate the law when it harms applicants or employees based on protected characteristics, that disability-related assessments may constitute unlawful medical inquiries, and that relevant automated-decision data falls within employment recordkeeping obligations.[8]
Government Code section 12946 requires covered employers to preserve applications, personnel, and other listed employment records for at least four years, with longer preservation after notice of a verified complaint.[9]
Local systems requiring review
- résumé screening and applicant ranking;
- recorded or chatbot interviews;
- personality, aptitude, or game-based assessments;
- background or integrity scoring;
- promotion and succession tools;
- performance evaluation;
- productivity and activity monitoring;
- scheduling and assignment;
- discipline or termination recommendations;
- tools using voice, face, emotion, movement, location, or behavioral data.
Questions for HR, counsel, and procurement
- What employment decision does the system make or facilitate?
- Is the vendor acting as the agency's agent?
- Which inputs, proxies, scores, and classifications are used?
- How was the system tested for the agency's jobs and applicant population?
- Could the tool screen out a person because of a disability?
- What accommodation or alternative process is available?
- Can a qualified human meaningfully review and change the outcome?
- Which automated-decision data, assessments, and employment records must be retained?
- Can the agency reconstruct why a person advanced, was rejected, or received an adverse action?
- Can the vendor change the model or scoring process without agency approval?
Recommended governance action
Require legal and civil-rights review before deployment, document job-related purpose and validation evidence, provide an accommodation route, preserve required employment and automated-decision records, test outcomes, and prohibit a vendor from making material model or scoring changes without notice and review.
Do not state that the regulations create a universal notice, impact-assessment, or appeal procedure for every California local-government AI system.
What applies now — 6
AI-generated law-enforcement reports
What applies now — 6
AI-generated law-enforcement reports
Penal Code section 13663 applies to defined AI systems that automatically draft police-report narratives from audio or video recorded by in-car or dash-mounted cameras or body-worn cameras, or that analyze an officer’s dictated report to produce an automatically enhanced narrative.[10]
For covered uses, each law-enforcement agency must maintain a policy requiring:
- identification of each AI program used;
- the prescribed statement that the report was written fully or partly using AI;
- the signature of the officer or agency member verifying review and that the facts are true and correct;
- retention of the first AI-generated draft for as long as the official report;
- an audit trail retained for as long as the official report;
- identification in that audit trail of the user and the video or audio footage used, if any.
The statute also restricts a contracted vendor from sharing, selling, or otherwise using agency information except for the contracted agency’s purposes or under a court order. It permits vendor access for specified purposes including troubleshooting, bias mitigation, accuracy improvement, and system refinement.[10]
For this section, the “first draft” is the initial document or narrative produced solely by the AI system. Except for the official report, a draft created using AI does not constitute an officer’s statement.[10]
Important qualification
Section 13663 does not govern every AI tool used by law enforcement. Its AI definition is tied to the report-drafting systems described in the statute.
Procurement and implementation questions
- Does the product fall within the statute's report-drafting definition?
- Can it place the required disclosure in the required location?
- Does the workflow require officer review and signature?
- Is the first AI-generated draft automatically preserved?
- Can the agency preserve the audit trail for the full report-retention period?
- Can the system identify the user and source video or audio?
- Does the vendor contract comply with the statutory data-use restrictions?
- How will permitted vendor access for troubleshooting or refinement be controlled, logged, and reviewed?
- Can the agency retrieve drafts and logs without vendor assistance?
- How are inaccuracies, omissions, hallucinations, and conflicting evidence flagged?
Recommended enhanced review
Treat AI-generated police reports as a high-risk use. Review accuracy, evidence integrity, discoverability, disclosure, retention, security, bias, officer training, supervisory review, incident reporting, and suspension procedures before deployment.
What applies now — 7
School districts, pupil records, and educational AI
What applies now — 7
School districts, pupil records, and educational AI
Education Code section 49073.1 applies when a local educational agency contracts with a third party for specified digital storage, management, retrieval, or educational-software services involving pupil records.[11]
The required contract provisions include:
- continued local educational agency ownership and control of pupil records;
- limits on third-party use;
- parent, guardian, or eligible-pupil review and correction procedures;
- security and confidentiality procedures;
- unauthorized-disclosure notification procedures;
- end-of-contract retention and deletion terms;
- FERPA compliance measures;
- a prohibition on targeted advertising using personally identifiable pupil-record information.
The K–12 Pupil Online Personal Information Protection Act separately restricts covered operators from targeted advertising, building profiles outside K–12 purposes, selling pupil information, and making unauthorized disclosures. It also requires reasonable security and specified deletion practices.[12]
What this may mean for AI tools
These rules can matter when a school district uses AI tutoring, writing, translation, proctoring, plagiarism detection, assessment, behavioral monitoring, counseling, scheduling, special-education, or administrative tools that access pupil records or covered information.
Do not describe these provisions as one comprehensive school AI governance code.
School-district questions
- Does the tool access pupil records or collect information directly from students?
- Are student prompts, voice recordings, images, documents, search activity, and derived profiles covered?
- Who owns and controls pupil-generated content?
- Can parents, guardians, or eligible pupils review and correct information?
- Can the vendor use data to train or improve unrelated models?
- What deidentification process is used, and can the data reasonably be reidentified?
- What advertising, profiling, or product-development uses occur?
- How are security incidents reported?
- What happens to records and accounts at contract completion?
- What human review, accessibility, language access, and correction process applies?
What applies now — 8
Healthcare communications and AI systems
What applies now — 8
Healthcare communications and AI systems
Health and Safety Code section 1339.75 applies to a health facility, clinic, physician’s office, or office of a group practice using generative AI to create written or verbal patient communications about patient clinical information.[13]
Covered communications must include:
- a format-appropriate disclaimer stating that the communication was generated by generative AI; and
- clear instructions explaining how the patient may contact a human healthcare provider, employee, or other appropriate person.
The requirement does not apply when the AI-generated communication is read and reviewed by a human licensed or certified healthcare provider before it is sent to the patient.[13]
AB 489, effective January 1, 2026, prohibits AI or GenAI functionality and advertising from using protected professional terms in a way that indicates or implies that care, advice, reports, or assessments are being provided by a natural person with the relevant healthcare license.[14]
Local-government meaning
A county hospital, public clinic, local public-health program, or other public entity should determine whether the specific facility, office, communication, and system fall within the statutory definitions. Do not state that every public-health chatbot or administrative message is covered.
Healthcare governance questions
- Does the communication concern patient clinical information or only scheduling, billing, or another administrative matter?
- Does the organization fall within a covered statutory category?
- Is the output read and reviewed by a licensed or certified provider?
- Does the disclaimer appear in the required format?
- Can the patient reach an appropriate human?
- Could the AI imply that it is a licensed professional?
- Are clinical judgment and medical-necessity decisions reserved for qualified humans where required?
- How are patient data, prompts, outputs, corrections, and incidents protected and retained?
State programs
State programs that are not universal municipal mandates
State programs
State programs that are not universal municipal mandates
State high-risk automated-decision-system inventory — Applies to defined state agencies
Government Code section 11546.45.5 requires a comprehensive inventory and annual legislative report concerning high-risk automated decision systems used or proposed by defined state agencies. The statutory definition does not include ordinary cities and counties.[15]
Local agencies may voluntarily borrow the inventory fields, but do not present the state reporting program as a current municipal requirement.
SB 896 state GenAI communications — Applies to state agencies and departments
Government Code section 11549.66 requires specified disclosures and a route to a human when a state agency or department uses GenAI to communicate directly with a person about government services or benefits.[16]
The policy may be a useful local model. Do not state that this exact provision governs every municipal chatbot or communication.
California AI Transparency Act — Operative August 2, 2026; primarily provider- and platform-facing
The act establishes requirements for covered GenAI providers beginning August 2, 2026; specified large online platforms and GenAI hosting platforms beginning January 1, 2027; and specified capture-device manufacturers beginning January 1, 2028. As of this guide’s July 27, 2026 verification date, the first operative date had not yet arrived.[18]
Local procurement and communications teams may ask whether a vendor supports required provenance, disclosure, and detection functions. Do not describe the act as a universal local-government AI disclosure law.
AB 1018 — Automated decision systems — Not enacted; ordered to the inactive file
AB 1018 proposed broader impact-assessment, disclosure, and appeal requirements for covered automated decision systems and would have included state and local government deployers in defined circumstances. The official history shows that it was ordered to the inactive file on September 13, 2025, with no later action listed as of July 27, 2026.[20]
Do not present AB 1018’s proposed requirements as current law. Because an inactive-file bill can be returned for further action, recheck its official history before publication or any later guide revision.
Why this section matters
California AI summaries frequently combine state-agency rules, provider regulations, pending or inactive bills, and voluntary frameworks. Local officials should verify the covered entity, operative date, and official bill or code status before treating a provision as a municipal obligation.
Governance recommendation
Recommended enhanced review for high-risk uses
Governance recommendation
Recommended enhanced review for high-risk uses
This section is a governance recommendation.
It is not a statement that California law creates one universal review procedure for every listed system.
Apply enhanced legal, records, privacy, civil-rights, security, procurement, and operational review to systems involving:
- law enforcement, intelligence, and surveillance;
- AI-generated police reports;
- facial recognition and biometric identification;
- automated license-plate readers and video analytics;
- emergency dispatch and public safety;
- hiring, promotion, evaluation, discipline, scheduling, or employee monitoring;
- benefits and access to essential services;
- child welfare and family services;
- permits, inspections, code enforcement, and fraud detection;
- housing and homelessness services;
- education and student data;
- healthcare and patient communications;
- systems whose outputs strongly influence liberty, safety, rights, services, or livelihood.
Enhanced-review questions
- What decision or communication does the system influence?
- What law applies to this agency in this role?
- What authority remains with a human official?
- Can that person meaningfully change the outcome?
- What data enters the system, and what derived data is created?
- Who may be affected?
- How was the system tested for this context and population?
- How are errors and unequal outcomes detected?
- How can a person request correction, accommodation, or human review?
- What public and confidential records are created?
- What evidence must the agency preserve?
- Can the agency suspend the system after an incident or material vendor change?
California local examples
Illustrative local practices
California local examples
Illustrative local practices
Local example — not a statewide requirement
City of San José: AI inventory and review framework
The City of San José publishes an AI inventory and explains that the inventory helps the City promote transparency and communicate the AI systems it uses to residents.[21] San José also leads the GovAI Coalition, which publishes policy and practice templates and emphasizes responsible AI governance, vendor accountability, public services, and cross-agency collaboration.[22]
Practical lessons
- maintain a public-facing inventory proportionate to system risk;
- publish understandable descriptions of system purpose and use;
- connect AI review to privacy and data governance;
- standardize vendor questions;
- share reusable templates across agencies;
- distinguish transparency from disclosure of protected or security-sensitive information.
Do not describe San José’s approach or GovAI Coalition templates as statewide legal requirements.
Local example — not a statewide requirement
Los Angeles County: GenAI governance directive
Los Angeles County’s Technology Directive TD 24-04 establishes a GenAI governance structure, guiding principles, a governance board, an impact-assessment process, vendor requirements, and review of covered county use cases. It prohibits specified uses, including fully automated decisions without meaningful human oversight that substantially affect individuals.[23]
Practical lessons
- establish a cross-functional review body;
- include counsel, privacy, information security, procurement, and program owners;
- require departments to identify GenAI features embedded in new or upgraded systems;
- use a documented risk or impact assessment;
- prohibit sensitive data from being used outside its intended purpose;
- require meaningful human oversight for consequential decisions;
- maintain an inventory of reviewed applications and use cases.
This is a county policy example, not a statewide requirement or an endorsement of every provision.
Recommended first 90 days
A practical starting sequence
Recommended first 90 days
A practical starting sequence
Days 1–30: Map systems and legal roles
- 01Inventory AI-enabled tools across departments.
- 02Include AI features added to existing software through upgrades or licenses.
- 03Identify whether the agency is acting as an employer, law-enforcement agency, educational agency, healthcare entity, benefits administrator, housing provider, or another regulated body.
- 04Record where prompts, outputs, scores, drafts, logs, recommendations, and human-review records are stored.
- 05Identify the system owner, records owner, privacy lead, security lead, and contract owner.
- 06Flag systems involving public safety, employment, education, healthcare, benefits, housing, child welfare, biometrics, or surveillance.
- 07Identify any AI-generated law-enforcement report workflow subject to Penal Code section 13663.
Days 31–60: Review records, data, and contracts
- 01Map public-record and retention requirements by function.
- 02Confirm whether vendor-held records can be searched and exported.
- 03Review employment tools under California civil-rights and recordkeeping rules.
- 04Review school contracts for Education Code section 49073.1 and pupil-data requirements.
- 05Review healthcare communications for disclosure and human-contact requirements.
- 06Review data reuse, model training, subcontractors, security, incident reporting, audit access, deletion, and termination.
- 07Identify renewals or amendments that may introduce new AI features.
- 08Review responsibility, evidence-access, and defense provisions in light of Civil Code section 1714.46.
- 09Create interim staff guidance for approved tools and sensitive information.
Days 61–90: Establish oversight
- 01Assign preliminary risk tiers.
- 02Create a cross-functional review path for high-risk systems.
- 03Establish human-review, accommodation, correction, and escalation procedures.
- 04Establish incident-reporting and suspension procedures.
- 05Prepare public-facing disclosure for relevant systems.
- 06Train staff on records, sensitive data, verification, and approved uses.
- 07Schedule an inventory refresh and contract review.
- 08Review California legal and administrative updates, including the post-August 2, 2026 operation of the California AI Transparency Act.
For counsel, records, HR, privacy, and procurement
Questions for local counsel and cross-functional staff
For counsel, records, HR, privacy, and procurement
Questions for local counsel and cross-functional staff
- 01Does each prompt, output, score, log, or review note relate to the conduct of the public's business?
- 02Was the material prepared, owned, used, or retained by the agency?
- 03What retention authority and schedule apply?
- 04What format must the agency be able to produce?
- 05What exemptions, privileges, or confidentiality provisions may apply?
- 06Does the agency's role trigger employment, law-enforcement, education, healthcare, housing, benefits, or another use-specific rule?
- 07Does an employment vendor act as the agency's agent?
- 08Does Penal Code section 13663 apply to a proposed police-report tool?
- 09Does a school contract satisfy Education Code section 49073.1?
- 10Does a patient communication fall within Health and Safety Code section 1339.75?
- 11What privacy, due-process, equal-protection, disability, language-access, labor, or civil-rights duties apply?
- 12Can the agency retrieve the evidence needed to investigate a complaint or defend a decision?
- 13What public notice or disclosure is legally required?
- 14What additional transparency or review should be adopted as policy?
- 15How do Civil Code section 1714.46, public-entity defenses, insurance, indemnity, and evidence-preservation requirements affect the proposed use?
California-specific procurement questions
Questions to work through before buying or renewing
California-specific procurement questions
Questions to work through before buying or renewing
- 01AI features — Does the product include AI, machine learning, generative AI, automated ranking, prediction, detection, transcription, report drafting, or decision-support functions? Identify every base, optional, embedded, and planned feature.
- 02Agency role and covered law — Is the agency acting as an employer, law-enforcement agency, educational agency, healthcare entity, housing provider, benefits administrator, or another regulated body?
- 03Records created — What prompts, outputs, scores, drafts, logs, recommendations, notices, corrections, signatures, and human actions does the system create or retain?
- 04Public-business records — Which materials may relate to the conduct of the public's business, and who controls them?
- 05Search and export — Can the agency search and export relevant records without vendor assistance? In what electronic formats?
- 06Retention — Can the system support the agency's adopted schedules, the four-year employment record requirement where applicable, Penal Code section 13663, legal holds, audits, investigations, and active public-records requests?
- 07Data categories — Does the system receive resident, employee, applicant, pupil, patient, public-safety, biometric, location, health, or other sensitive information?
- 08Data use and model training — Will agency, employee, student, patient, prompt, output, or derived data be used to train, fine-tune, evaluate, or improve vendor or third-party models?
- 09Subcontractors and model providers — Which cloud, model, analytics, support, and subcontractor entities receive data or provide system functions?
- 10Security and breach response — What controls, notification periods, evidence-preservation duties, cooperation requirements, and remedies apply after an incident?
- 11Employment systems — What decision does the system make or facilitate, how was it validated, what accommodations exist, and what automated-decision data will be preserved?
- 12Law-enforcement reports — Can the system support the required disclosure, officer verification, first-draft retention, audit trail, and vendor data-use restrictions?
- 13Pupil records — Does the contract address ownership, permitted use, correction, security, breach notice, end-of-contract handling, FERPA, and targeted advertising?
- 14Patient communications — Does the system support required GenAI disclosure, human contact, licensed-provider review, and restrictions on implying a professional license?
- 15Material changes — Can the vendor change the model, provider, scoring logic, data practice, output behavior, or AI features after contract signing? What notice, testing, and approval rights apply?
- 16Testing and auditability — What performance documentation, local validation, version information, logs, and audit rights are available?
- 17Unequal outcomes and accessibility — How will the agency test for discrimination, disability barriers, language-access problems, and other unequal effects?
- 18Human authority — Who retains final authority, and can that person meaningfully reject, correct, or escalate the system's output?
- 19Incidents and complaints — What must the vendor report, within what period, and what records must be preserved? Can residents, employees, students, and patients submit corrections or complaints?
- 20Suspension and rollback — Can the agency disable an AI feature, restore a prior model or workflow, and continue essential services?
- 21Termination and portability — What data and records are returned, retained, deleted, or certified as destroyed at termination?
- 22Public explanation — Can the agency accurately explain the system's purpose, limits, data, human oversight, records, and complaint process?
- 23Responsibility and civil claims — Does the contract clearly allocate responsibility for system design, configuration, use, oversight, incidents, evidence access, insurance, and indemnity without assuming that AI autonomy eliminates responsibility?
Proportionate review
Apply the most detailed review to systems with consequential or high-risk uses. Lower-risk internal tools may receive a proportionate review, but data protection, records access, employment rules, system changes, and vendor accountability should still be addressed.
Help improve this guide
Corrections and source updates
Help improve this guide
Corrections and source updates
This guide has been checked against the official sources listed below. California records professionals, procurement officials, IT leaders, HR teams, law-enforcement personnel, school-district staff, healthcare administrators, local-government attorneys, and other public-sector practitioners are invited to submit corrections, newer official sources, or implementation examples.
Disclaimer
Scope of this guide
Disclaimer
Scope of this guide
This guide provides general policy and governance information. It is not legal advice, a comprehensive statement of California law, or a substitute for review by a city, county, school-district, special-district, healthcare, law-enforcement, or agency attorney. Laws, regulations, guidance, records schedules, bill statuses, and local ordinances may change. Officials should verify current requirements and the facts of a particular use before acting.
Official sources
Where to verify each claim
Official sources
Where to verify each claim
- [1] Cal. Gov. Code § 7920.530 — Definition of public records
https://leginfo.legislature.ca.gov/faces/codes_displaySection.xhtml?lawCode=GOV§ionNum=7920.530
- [2] Cal. Gov. Code § 7920.545 — Definition of writing
https://leginfo.legislature.ca.gov/faces/codes_displaySection.xhtml?lawCode=GOV§ionNum=7920.545
- [3] Cal. Gov. Code § 7922.570 — Public records in electronic format
https://leginfo.legislature.ca.gov/faces/codes_displaySection.xhtml?lawCode=GOV§ionNum=7922.570
- [4] Cal. Gov. Code § 34090 — City records destruction and retention
https://leginfo.legislature.ca.gov/faces/codes_displaySection.xhtml?lawCode=GOV§ionNum=34090
- [5] Cal. Gov. Code § 26202 — County records destruction and retention
https://leginfo.legislature.ca.gov/faces/codes_displaySection.xhtml?lawCode=GOV§ionNum=26202
- [6] Cal. Const. art. I, §§ 1, 3 — Privacy and public access
https://leginfo.legislature.ca.gov/faces/codes_displayText.xhtml?lawCode=CONS&article=I
- [7] Cal. Civ. Code § 1798.29 — Agency data-breach notification
https://leginfo.legislature.ca.gov/faces/codes_displaySection.xhtml?lawCode=CIV§ionNum=1798.29
- [8] Cal. Civil Rights Department — Employment ADS regulations (summary)
https://calcivilrights.ca.gov/2025/06/30/civil-rights-council-secures-approval-for-regulations-to-protect-against-employment-discrimination-related-to-artificial-intelligence/
- [8] Cal. Civil Rights Department — Employment ADS regulations (final text)
https://calcivilrights.ca.gov/wp-content/uploads/sites/32/2025/06/Final-Text-regulations-automated-employment-decision-systems.pdf
- [9] Cal. Gov. Code § 12926 — Employer definition
https://leginfo.legislature.ca.gov/faces/codes_displaySection.xhtml?lawCode=GOV§ionNum=12926
- [9] Cal. Gov. Code § 12946 — Employment records preservation
https://leginfo.legislature.ca.gov/faces/codes_displaySection.xhtml?lawCode=GOV§ionNum=12946
- [10] Cal. Penal Code § 13663 — AI-generated law-enforcement reports
https://leginfo.legislature.ca.gov/faces/codes_displaySection.xhtml?lawCode=PEN§ionNum=13663
- [11] Cal. Educ. Code § 49073.1 — Contracts involving pupil records
https://leginfo.legislature.ca.gov/faces/codes_displaySection.xhtml?lawCode=EDC§ionNum=49073.1
- [12] Cal. Bus. & Prof. Code § 22584 — K–12 Pupil Online Personal Information Protection Act
https://leginfo.legislature.ca.gov/faces/codes_displaySection.xhtml?lawCode=BPC§ionNum=22584
- [13] Cal. Health & Safety Code § 1339.75 — AI-generated patient communications
https://leginfo.legislature.ca.gov/faces/codes_displaySection.xhtml?lawCode=HSC§ionNum=1339.75
- [14] Cal. Bus. & Prof. Code § 4999.9 — Healthcare professions and AI
https://leginfo.legislature.ca.gov/faces/codes_displaySection.xhtml?lawCode=BPC§ionNum=4999.9
- [14] AB 489 — Healthcare professions and AI (bill text)
https://leginfo.legislature.ca.gov/faces/billTextClient.xhtml?bill_id=202520260AB489
- [15] Cal. Gov. Code § 11546.45.5 — State high-risk ADS inventory
https://leginfo.legislature.ca.gov/faces/codes_displaySection.xhtml?lawCode=GOV§ionNum=11546.45.5
- [15] CDT — High-Risk ADS FAQ
https://www.cdt.ca.gov/technology-innovation/hrads-login/faqs/
- [16] Cal. Gov. Code § 11549.66 — State GenAI communications (SB 896)
https://leginfo.legislature.ca.gov/faces/codes_displaySection.xhtml?lawCode=GOV§ionNum=11549.66
- [16] SB 896 — Generative AI Accountability Act (bill text)
https://leginfo.legislature.ca.gov/faces/billTextClient.xhtml?bill_id=202320240SB896
- [17] California Department of Technology — PS-033 SITeS GenAI procurement procedure
https://www.cdt.ca.gov/policy/announcements/ps-033-new-statewide-integrated-technology-it-shared-services-sites-procurement-process-for-genai-general-office-productivity-tools/
- [18] Cal. Bus. & Prof. Code §§ 22757–22757.6 — California AI Transparency Act
https://leginfo.legislature.ca.gov/faces/codes_displayText.xhtml?article=&chapter=25.&division=8.&lawCode=BPC&part=&title=
- [18] AB 853 — California AI Transparency Act (bill text)
https://leginfo.legislature.ca.gov/faces/billTextClient.xhtml?bill_id=202520260AB853
- [19] SB 53 — Transparency in Frontier Artificial Intelligence Act
https://leginfo.legislature.ca.gov/faces/billTextClient.xhtml?bill_id=202520260SB53
- [20] AB 1018 — Automated decision systems (bill text)
https://leginfo.legislature.ca.gov/faces/billTextClient.xhtml?bill_id=202520260AB1018
- [20] AB 1018 — Official history (inactive file)
https://leginfo.legislature.ca.gov/faces/billHistoryClient.xhtml?bill_id=202520260AB1018
- [21] City of San José — AI Reviews and Algorithm Register
https://www.sanjoseca.gov/your-government/departments-offices/information-technology/digital-privacy/ai-reviews-algorithm-register
- [22] City of San José — GovAI Coalition
https://www.sanjoseca.gov/your-government/departments-offices/information-technology/artificial-intelligence-inventory/govai-coalition
- [23] Los Angeles County — AI Policy Framework and TD 24-04
https://file.lacounty.gov/SDSInter/bos/bc/1167064_2024-9-12DevelopmentofLACounty_sArtificialIntelligencePolicyFramework_ItemNo.9_AgendaofMay7_2024_.pdf
- [24] Cal. Civ. Code § 1714.46 — AI-related defenses
https://leginfo.legislature.ca.gov/faces/codes_displaySection.xhtml?lawCode=CIV§ionNum=1714.46
- [24] AB 316 — AI-related defenses (bill text)
https://leginfo.legislature.ca.gov/faces/billTextClient.xhtml?bill_id=202520260AB316
- [25] Cal. Gov. Code § 60201 — Special-district records destruction and schedules
https://leginfo.legislature.ca.gov/faces/codes_displaySection.xhtml?lawCode=GOV§ionNum=60201
Download
California Local AI Governance Checklist
Checklist download in development.