AMENDED IN ASSEMBLY JULY 2, 2026
AMENDED IN ASSEMBLY JUNE 11, 2026
CALIFORNIA LEGISLATURE— 2025–2026 REGULAR SESSION
97
Introduced by Senator Cabaldon
February 13, 2026
An act to amend Section 3110 of the Civil Code, and to amend Sections 11546.45.5, 11549.64 and 11549.65 of the Government Code, relating to artificial intelligence.
Vote: majority Appropriation: no Fiscal committee: yes Local program: no
LEGISLATIVE COUNSEL’S DIGEST
Existing law requires the Office of Emergency Services to, as appropriate, perform a risk analysis of potential threats posed by the use of generative artificial intelligence to California’s critical infrastructure, including those that could lead to mass casualty events. Existing law requires that risk analysis to be provided to the Governor, and, if appropriate, include recommendations reflecting changes to artificial intelligence technology, its applications, and risk management, including further private actions, administrative actions, and collaboration with the Legislature to guard against potential threats and vulnerabilities.
This bill would require that recommendations in the risk analysis reflecting changes to artificial intelligence technology include agentic artificial intelligence, as defined.
Existing law requires the Department of Technology to annually submit to certain legislative committees a report regarding a specified required comprehensive inventory of all high-risk automated decision systems that have been, or are being, used, developed, or procured by a state agency. Existing law defines “high-risk automated decision system” to mean an automated decision system that is used to assist or replace human discretionary decisions that have a legal or similarly significant effect, including decisions that materially impact access to, or approval for, housing or accommodations, education, employment, credit, health care, and criminal justice.
This bill would further require the comprehensive inventory in the report to include agentic artificial intelligence that has been, or is being, used, developed, or procured by a state agency.
The people of the State of California do enact as follows:
SECTION 1.
Section 3110 of the Civil Code is amended to read:
3110.
For purposes of this title:
(A) Optimizing toward multistep or abstract objectives using dynamic task decomposition or delegation, which may include modifying the behavior of the artificial intelligence based on outcomes rather than instructions or consent of the user or principal.
(B) Controlling or executing actions or tasks, executing code externally, using external tools, making purchases, or accessing accounts or applications requiring user authentication.
(C) Egressing the network or shell of either the artificial intelligence system or the user or principal.
(2) “Agentic artificial intelligence” does not include an artificial intelligence system that can respond only to direct task prompts and instructions from the user and does not have network egress or shell access capability.
(a) (1) “Agentic artificial intelligence” or “agentic AI” means an artificial intelligence system that can pursue multistep or abstract goals by independently breaking them into tasks or delegating them, adjusting its own behavior based on results rather than waiting for user instruction or consent, and that can act in the world, including by executing code, using external tools, making purchases, accessing accounts that require authentication, or operating outside its own.
(2) “Agentic artificial intelligence” does not include a system that only responds to direct prompts and instructions from the user and lacks network egress or shell access.
(b) “Artificial intelligence” means an engineered or machine-based system that varies in its level of autonomy and that can, for explicit or implicit objectives, infer from the input it receives how to generate outputs that can influence physical or virtual environments.
(c) “Developer” means a person, partnership, state or local government agency, or corporation that designs, codes, produces, or substantially modifies an artificial intelligence system or service for use by members of the public. For purposes of this subdivision, “members of the public” does not include an affiliate as defined in subparagraph (A) of paragraph (1) of subdivision (c) of Section 1799.1a, or a hospital’s medical staff member.
(d) “Generative artificial intelligence” means artificial intelligence that can generate derived synthetic content, such as text, images, video, and audio, that emulates the structure and characteristics of the artificial intelligence’s training data.
(e) “Substantially modifies” or “substantial modification” means a new version, new release, or other update to a generative artificial intelligence system or service that materially changes its functionality or performance, including the results of retraining or fine tuning.
(f) “Synthetic data generation” means a process in which seed data are used to create artificial data that have some of the statistical characteristics of the seed data.
(g) “Train a generative artificial intelligence system or service” includes testing, validating, or fine tuning by the developer of the artificial intelligence system or service.
SEC. 2.
Section 11546.45.5 of the Government Code is amended to read:
11546.45.5.
(a) For purposes of this section:
(1) “Agentic artificial intelligence” or “agentic AI” means an artificial intelligence system that can pursue multistep or abstract goals by independently breaking them into tasks or delegating them, adjusting its own behavior based on results rather than waiting for user instruction or consent, and that can act in the world, including by executing code, using external tools, making purchases, accessing accounts that require authentication, or operating outside its own.
(2) “Agentic artificial intelligence” does not include a system that only responds to direct prompts and instructions from the user and lacks network egress or shell access.
(3) “Artificial intelligence” means an engineered or machine-based system that varies in its level of autonomy and that can, for explicit or implicit objectives, infer from the input it receives how to generate outputs that can influence physical or virtual environments.
(4) “Automated decision system” means a computational process derived from machine learning, statistical modeling, data analytics, or artificial intelligence that issues simplified output, including a score, classification, or recommendation, that is used to assist or replace human discretionary decisionmaking and materially impacts natural persons. “Automated decision system” does not include a spam email filter, firewall, antivirus software, identity and access management tools, calculator, database, dataset, or other compilation of data.
(5) “Board” means any administrative or regulatory board, commission, committee, council, association, or authority consisting of more than one person whose members are appointed by the Governor, the Legislature, or both.
(6) “Department” means the Department of Technology.
(7) “High-risk automated decision system” means an automated decision system that is used to assist or replace human discretionary decisions that have a legal or similarly significant effect, including decisions that materially impact access to, or approval for, housing or accommodations, education, employment, credit, health care, and criminal justice.
(8) (A) “State agency” means any of the following:
(i) Any state office, department, division, or bureau.
(ii) The California State University.
(iii) The Board of Parole Hearings.
(iv) Any board or other professional licensing and regulatory body under the administration or oversight of the Department of Consumer Affairs.
(B) “State agency” does not include the University of California, the Legislature, the judicial branch, or any board, except as provided in subparagraph (A).
(b) On or before September 1, 2024, the Department of Technology shall conduct, in coordination with other interagency bodies as it deems appropriate, a comprehensive inventory of all high-risk automated decision systems and agentic AI systems that have been proposed for use, development, or procurement by, or are being used, developed, or procured by, any state agency.
(c) The comprehensive inventory described by subdivision (b) shall include a description of all of the following:
(1) (A) Any decision the automated decision system or agentic AI system can make or support and the intended benefits of that use.
(B) The alternatives to any use described in subparagraph (A).
(2) The results of any research assessing the efficacy and relative benefits of the uses and alternatives of the automated decision system or agentic AI system described by paragraph (1).
(3) The categories of data and personal information the automated decision system uses to make its decisions.
(4) (A) The measures in place, if any, to mitigate the risks, including cybersecurity risk and the risk of inaccurate, unfairly discriminatory, or biased decisions, of the automated decision system. system or agentic AI system.
(B) Measures described by this paragraph may include, but are not limited to, any of the following:
(i) Performance metrics to gauge the accuracy of the system.
(ii) Cybersecurity controls.
(iii) Privacy controls.
(iv) Risk assessments or audits for potential risks.
(v) Measures or processes in place to contest an automated decision.
(d) (1) On or before January 1, 2025, and annually thereafter, the department shall submit a report of the comprehensive inventory described in subdivision (b) to the Assembly Committee on Privacy and Consumer Protection and the Senate Committee on Governmental Organization.
(2) The requirement for submitting a report imposed under paragraph (1) is inoperative on January 1, 2029, pursuant to Section 10231.5.
(3) A report to be submitted pursuant to paragraph (1) shall be submitted in compliance with Section 9795.
SEC. 2.SEC. 3.
Section 11549.64 of the Government Code is amended to read:
11549.64.
As used in this chapter:
(A) Optimizing toward multistep or abstract objectives using dynamic task decomposition or delegation, which may include modifying the behavior of the artificial intelligence based on outcomes rather than instructions or consent of the user or principal.
(B) Controlling or executing actions or tasks, executing code externally, using external tools, making purchases, or accessing accounts or applications requiring user authentication.
(C) Egressing the network or shell of either the artificial intelligence system or the user or principal.
(2) “Agentic artificial intelligence” does not include an artificial intelligence system that can respond only to direct task prompts and instructions from the user and does not have network egress or shell access capability.
(a) (1) “Agentic artificial intelligence” or “agentic AI” means an artificial intelligence system that can pursue multistep or abstract goals by independently breaking them into tasks or delegating them, adjusting its own behavior based on results rather than waiting for user instruction or consent, and that can act in the world, including by executing code, using external tools, making purchases, accessing accounts that require authentication, or operating outside its own.
(2) “Agentic artificial intelligence” does not include a system that only responds to direct prompts and instructions from the user and lacks network egress or shell access.
(b) “Artificial intelligence” means an engineered or machine-based system that varies in its level of autonomy and that can, for explicit or implicit objectives, infer from the input it receives how to generate outputs that can influence physical or virtual environments.
(c) “Generative artificial intelligence” or “GenAI” means an artificial intelligence system that can generate derived synthetic content, including text, images, video, and audio that emulates the structure and characteristics of the system’s training data.
(d) “Person” means a natural person.
(e) “Report” means the report to the Governor required by Executive Order No. N-12-23.
SEC. 3.SEC. 4.
Section 11549.65 of the Government Code is amended to read:
11549.65.
(a) The Department of Technology, under the guidance of the Government Operations Agency, the Office of Data and Innovation, and the Department of Human Resources, shall update the report, as needed, to respond to significant developments and shall, as appropriate, consult with academia, industry experts, and organizations that represent state exclusive employee representatives.
(b) (1) The Office of Emergency Services shall, as appropriate, perform a risk analysis of potential threats posed by the use of GenAI to California’s critical infrastructure, including those that could lead to mass casualty events.
(2) The analysis required by paragraph (1) shall be provided to the Governor, and, if appropriate, shall include recommendations reflecting changes to artificial intelligence technology, including agentic artificial intelligence, its applications, and risk management, including further private actions, administrative actions, and collaboration with the Legislature to guard against potential threats and vulnerabilities.
(3) A high-level summary of the analysis required by paragraph (1) shall be submitted annually to the Legislature.
(c) Any state agency or department shall consider procurement and enterprise use opportunities in which GenAI can improve the efficiency, effectiveness, accessibility, and equity of government operations consistent with the Government Operations Agency, the Department of General Services, and the Department of Technology’s policies for public sector GenAI procurement.
(d) Legal counsel for any state agency or department shall consider any potential impact of GenAI on regulatory issues under the respective agency’s or department’s authority and recommend necessary updates, if appropriate, as a result of this evolving technology.