California AB 2392

California AB 2392 — Public Postsecondary Education: Generative AI Procurement Standards and Training

United States

RAI-US-CA-AB23920-2026

AB 2392

Awaiting Entry(Awaiting Entry)

California AB 2392 is Awaiting Entry in United States, according to leginfo.legislature.ca.gov. We have not yet been able to confirm the status.

ActGovernance and OversightRisk ManagementAccountability and Documentation
Export PDF

California AB 2392 sets GenAI procurement and training rules for public colleges.

Summary

California AB 2392 creates an intersegmental framework for public postsecondary GenAI procurement, training, and reporting. It requires systemwide standards addressing safety, privacy, data governance, vendor disclosure, and role-specific training for students, faculty, and staff.

Full article

Read full text ↗

Overview

California AB 2392 adds Article 14 (commencing with Section 66098) to the Education Code to address the procurement and use of generative artificial intelligence systems in public postsecondary education. The statute applies to the office of the Chancellor of the California Community Colleges and the California State University, and it requests participation by the University of California. Its core design is intersegmental: the affected systems must jointly convene a working group, develop procurement standards and training, and then implement role-appropriate training for students, faculty, and staff. The Legislature framed the measure as a response to the practical and policy risks associated with educational use of GenAI, including harmful outputs, privacy issues, and academic integrity concerns.

The law is chaptered as Chapter 855, Statutes of 2026, and it is not an urgency statute. Under the standard constitutional effective-date rule, it takes effect on 2027-01-01. The operative duties are staged. The working group’s recommendations must be presented on or before 2028-01-01, while interim reporting duties apply before procurement standards are adopted. The statute is therefore both a governance measure and a procurement safeguard: it does not ban GenAI in higher education, but it conditions systemwide adoption on documented safety, privacy, and vendor-disclosure requirements. It also creates a continuing administrative obligation to review and update training annually and to retain proof of completion for at least four years.

Definitions

Section 66098 supplies the key definitional layer for the article. “Artificial intelligence” and “generative artificial intelligence” or “GenAI” are incorporated by reference to Government Code Section 11549.64, ensuring that the Education Code article tracks the state’s broader AI terminology. The statute also defines “sycophancy” as the tendency of a GenAI system to overly agree with, validate, or flatter a user even when the user is communicating factually inaccurate or illegal ideas or actions, when that behavior is primarily intended to optimize engagement. That definition is important because it identifies a specific model behavior as a compliance concern, not merely a product-quality issue.

The procurement and training requirements also rely on concepts that are not separately defined in the article but are operationally central. These include risk assessment, incident reporting, data retention, data minimization, training data source disclosure, and systemwide contract. The statute uses those terms in ordinary regulatory senses rather than supplying novel statutory definitions. In practice, this means institutions should treat the provisions as compliance requirements that demand documented procedures, vendor assurances, and auditable records. The law also distinguishes between required duties and requests to the University of California, making the article partly mandatory and partly aspirational as to UC, while still setting a statewide coordination model for the public higher-education systems.

Governance and Institutional Framework

AB 2392 creates a structured intersegmental governance process led by the California Community Colleges Chancellor’s office and the California State University. Those offices must jointly convene and participate in an intersegmental working group and designate a lead convener responsible for coordinating its activities. The University of California is requested to participate, reflecting the constitutional and institutional autonomy of UC while still inviting it into the statewide policy process. The working group must include privacy experts, student advocacy representatives, systemwide academic senates, community-based organizations, labor organizations representing employees of the segments, civil society groups, and academic researchers focused on responsible GenAI procurement, design, and implementation from the three segments.

The working group’s purpose is not advisory in a vague sense; it is to develop concrete responsible training protocols and procurement standards for the purchase, development, and use of GenAI systems for educational purposes, consistent with current law governing AI regulation, procurement, development, and use. The arrangement places academic governance bodies, labor voices, privacy expertise, and public-interest stakeholders into the same policy channel as administrative leadership. This design indicates that the Legislature intended procurement decisions to be informed by more than purchasing efficiency, and instead to reflect educational mission, student welfare, privacy, and labor considerations. The law therefore embeds GenAI governance within institutional coordination rather than leaving it to a single central office or to procurement staff alone.

Key Focus Areas

The statute’s procurement standards identify nine minimum protections that any procured GenAI system must meet. First, the system must undergo a documented risk assessment that evaluates potential harms, misuses, abuses, and bias, and must have demonstrably effective measures to prevent harmful or illegal outputs, expressly including nonconsensual intimate imagery, suicide and suicidal ideation, disordered eating, and mental health therapy ordinarily administered by a licensed professional. Second, the system must not prioritize engagement over factual accuracy through excessive sycophancy. Third, the vendor must maintain a safety monitoring protocol that detects a user’s intent to harm themselves or others, escalates to human review, and, in cases of imminent threat or grave bodily injury or death, makes appropriate referrals to authorities.

Additional focus areas include incident reporting, data governance, and supply-chain accountability. The vendor must maintain a transparent incident reporting system for harmful outputs; written policies must govern data use, retention, third-party sharing, and deletion timelines; and the system must collect only data strictly necessary for the stated educational purpose and be subject to regular audits. The vendor must also disclose all training data sources, including whether copyrighted content, personally identifiable information, or student-generated content was used. Finally, as reasonably determinable, the vendor may not contract with entities that have unlawfully undermined privacy or civil liberties and may not use exploitative labor practices. The training side of the law is equally specific: it must address systemwide policies, academic integrity, privacy policies and links to them, and the possibility that GenAI outputs may be inaccurate, incomplete, or misleading.

Implementation Framework

Implementation is split between standard-setting, training delivery, and interim reporting. The working group must develop recommendations for procurement standards and training and submit them on or before 2028-01-01. Separately, the Chancellor’s office for the community colleges and the CSU must provide the training developed under the article to students, faculty, or staff, as applicable. The statute allows distinct versions of training tailored to the different uses, responsibilities, and policies relevant to students, faculty, and staff, and expressly states that a single uniform training is not required. That flexibility matters because the legal risks and use cases differ across student assignments, faculty instruction, and staff operations.

The law also imposes a reporting regime that operates before procurement standards are adopted. Until standards are adopted, and within 60 days following execution of a systemwide contract for a GenAI system, the affected offices must submit a written report to the Legislature and the relevant policy committees with jurisdiction over higher education and privacy and consumer protection, consistent with Government Code Section 9795. The report must describe the system procured, the vendor name, the intended use, the affected population, the evaluation and selection process, any risk assessments, competing systems considered, the resulting training, and the vendor’s data use, retention, and privacy practices. This makes early procurement transparent and gives lawmakers a visibility mechanism while the more detailed standards are still being developed.

Monitoring and Evaluation

AB 2392 requires ongoing review rather than a one-time launch. The Chancellor’s office of the California Community Colleges and CSU must review the training developed under Section 66098.1 at least once per academic year and update it as necessary to reflect changes in systemwide policy, applicable law, or the functionality or privacy practices of the GenAI system. This annual review duty is a built-in monitoring device that ensures the training remains aligned with how the technology and institutional policies evolve. Because the statute references functionality and privacy practices, the review obligation is not limited to legal updates; it also reaches the operational behavior of the vendor system.

The recordkeeping requirement is equally significant. The law requires maintenance of completed-training records for each student, faculty member, and staff member who receives training, including at minimum the individual’s name, the date of completion, and the version of the training delivered. Those records must be retained for at least four years following the completion date. In regulatory terms, this creates a verifiable compliance trail that can support internal audits, oversight inquiries, and legislative reporting. The statute does not specify a separate audit authority or external certification body, so monitoring is primarily institutional and documentary. Its enforcement model depends heavily on whether the affected offices can show that procurement, training, and documentation practices have been implemented in a repeatable and well-recorded manner.

Penalties, Liability, and Appeals

AB 2392 does not establish a standalone civil penalty schedule, administrative fine, or criminal sanction. Instead, the statute works through procurement conditions, reporting duties, and documentary compliance. If a systemwide contract for a GenAI system is executed before procurement standards are adopted, the affected offices must report to the Legislature within 60 days. Failure to comply could therefore expose institutions to legislative oversight, budgetary scrutiny, and administrative consequences, but the article itself does not prescribe a specific monetary penalty or private right of action. Likewise, the text does not create an appeal mechanism for vendors, students, or employees.

Liability risk may still arise indirectly under other laws or under contract law, privacy law, student discipline rules, academic integrity policies, or general public-entity responsibilities. The statute’s vendor disclosure, privacy, and harmful-output safeguards indicate a legislative expectation that institutions vet products carefully and document their decisions. However, any dispute about procurement decisions, training sufficiency, or reporting compliance would likely be handled through ordinary administrative channels unless another applicable law provides a specific remedy. The absence of express penalties is consistent with the statute’s design as a governance and procurement framework rather than a punitive enforcement regime.

Relationship to Other Instruments

The article expressly ties its definitions of artificial intelligence and generative artificial intelligence to Government Code Section 11549.64, so it should be read alongside California’s broader state AI framework. It also requires procurement standards to be consistent with current law regarding regulation, procurement, development, and use of GenAI systems, which signals a harmonizing intent rather than a standalone code. The reporting obligation must be made consistent with Government Code Section 9795, which governs legislative reports and committees. These cross-references mean AB 2392 is intended to fit into existing state legal architecture rather than duplicate it.

At the institutional level, the statute interacts with existing higher-education governance structures for the California Community Colleges, the California State University, and the University of California. It respects the different legal status of UC by requesting participation instead of mandating it. At the policy level, the law complements other state efforts to manage AI use in government and education by focusing on procurement standards and training rather than general AI deployment rules. It also preserves room for systemwide policy development, because the training must reflect systemwide policies, including academic integrity rules, and can be tailored by recipient role. The result is an instrument that is best understood as a bridge between general AI regulation and sector-specific educational administration.

National/Federal Alignment

AB 2392 is a California state statute and does not create federal obligations. Its design aligns with the broader U.S. regulatory trend toward risk-based AI governance, transparency, and consumer or user protection, but it is aimed specifically at public postsecondary education. The statute’s emphasis on documented risk assessment, harmful-output mitigation, privacy practices, and training-data disclosure is consistent with common federal themes in AI oversight, though it does not incorporate federal AI rules by reference or depend on a federal certification process. Because California generally regulates public institutions through state law, this measure fills a state-level governance gap for campus GenAI procurement and use.

The law also differs from federal frameworks in a few important ways. It is institution-specific, systemwide, and operational: it requires annual training review, record retention, and interim reporting tied to contracts. It also addresses issues such as sycophancy, student-generated content in training data, and exploitative labor practices—subjects that are not ordinarily packaged together in federal technology statutes. The result is a state procurement rule that can operate alongside federal privacy, civil-rights, and consumer-protection regimes without preempting them. For California colleges, that means compliance must be managed in parallel with any applicable federal obligations, but AB 2392 itself remains a distinct state-level requirement.

Implementation Timeline

MilestoneDateNotes
Approved by Governor and filed with Secretary of State2026-09-30Chaptered as Chapter 855, Statutes of 2026.
Statute effective date2027-01-01Non-urgency statute takes effect under the California Constitution.
Working group recommendations due2028-01-01Procurement standards and training recommendations must be presented to the respective system leaders on or before this date.
Annual training reviewOngoing each academic yearTraining must be reviewed at least once per academic year and updated as necessary.
Interim contract report deadlineWithin 60 days of systemwide GenAI contract executionApplies until procurement standards are adopted.

Compliance Checklist

CheckRequired Action
Working group convenedCCC Chancellor and CSU must jointly convene the intersegmental working group and designate a lead convener.
Stakeholder membershipInclude privacy experts, student advocates, academic senates, community groups, labor, civil society, and academic researchers.
Procurement standards draftedRequire documented risk assessment, harmful-output safeguards, anti-sycophancy measures, monitoring, reporting, data governance, disclosure, and labor/privacy checks.
Training createdPrepare role-appropriate training covering policies, privacy practices, privacy-policy links, and GenAI limitations.
Training deliveredProvide training to students, faculty, or staff, as applicable, with separate versions if needed.
Annual review completedReview and update training at least once per academic year.
Completion records retainedKeep name, completion date, and version for each recipient for at least four years.
Interim report filedWithin 60 days after any systemwide GenAI contract, file the required report until standards are adopted.

Sources and References

SourceType
Assembly Bill No. 2392, Chapter 855, Statutes of 2026 — California Legislative Informationofficial
Governor of California — signing announcement, 30 September 2026official

© Regulations.AI — created on 9 Oct 2026 using Gemini 3.6 Flash