United States - California - AI Definition Act (AB 2885)
California AB 2885 — Artificial Intelligence: Unified Definition and State Agency Inventory
United States
RAI-US-CA-CA2AIXX-2024California Assembly Bill 2885 establishes the first unified legal definition of artificial intelligence in California law and mandates a comprehensive inventory of high-risk automated decision systems used by state agencies. The law defines AI as 'an engineered or machine-based system that varies in its level of autonomy' capable of generating outputs that influence environments, requiring annual reports through 2028 and deepfake impact assessments.
Summary
Read full text ↗Plain English
Overview
California Assembly Bill 2885 (Chapter 843, Statutes of 2024) establishes California's first comprehensive legal framework for defining artificial intelligence and cataloging its use within state government. Authored by Assemblymember Rebecca Bauer-Kahan and signed by Governor Gavin Newsom on September 28, 2024, the legislation addresses a critical gap in California's regulatory infrastructure by creating a unified AI definition applicable across multiple code sections. As AI technologies become increasingly embedded in government services—from benefits administration to criminal justice—the absence of consistent definitions and oversight mechanisms created regulatory fragmentation and accountability gaps. AB 2885 responds to these challenges by mandating comprehensive inventories of high-risk automated decision systems, requiring annual reporting to the Legislature, and directing evaluation of emerging threats like deepfakes. The law positions California as a leader in government AI governance, establishing precedents that may influence both federal legislation and other states' approaches to public sector AI accountability.
Definitions
AB 2885 establishes a foundational definition of artificial intelligence that applies uniformly across California law. Artificial intelligence is defined as 'an engineered or machine-based system that varies in its level of autonomy and that can, for explicit or implicit objectives, infer from the input it receives how to generate outputs that can influence physical or virtual environments.' This definition is intentionally broad, encompassing traditional rule-based expert systems, modern machine learning models, and emerging generative AI technologies. The definition acknowledges that AI systems operate along a spectrum of autonomy—from systems requiring substantial human oversight to those capable of independent operation. By focusing on the inferential capacity to generate influential outputs, the definition captures both decision-support tools and autonomous systems. High-risk automated decision system refers to AI systems used to make decisions with significant legal impacts on individuals, particularly in sensitive domains including housing, education, employment, credit, healthcare, and criminal justice. Deepfake means synthetic media created using artificial intelligence that depicts events or statements that did not occur, with particular focus on content designed to deceive viewers about its authenticity. Content authenticity refers to metadata and verification mechanisms that enable users to assess whether digital content is genuine, modified, or synthetically generated.
Governance and Institutional Framework
AB 2885 assigns primary responsibility for AI inventory and governance to the California Department of Technology (CDT), which serves as the state's central technology authority. CDT must develop inventory methodologies, coordinate with all state agencies, maintain the central registry of high-risk automated decision systems, and prepare annual reports for legislative oversight. The Government Operations Agency, through its Secretary, bears responsibility for evaluating deepfake impacts and developing content authenticity standards—reflecting recognition that synthetic media threats require executive-level attention. Individual state agencies must participate in inventory processes, document their high-risk AI systems, and implement required governance measures including performance metrics, cybersecurity controls, and contestation processes. Local agencies administering economic development subsidies face separate reporting requirements regarding AI and automation impacts on employment. The California State Auditor may review agency compliance and the accuracy of inventory submissions. Legislative oversight occurs through required reports to the Assembly Committee on Privacy and Consumer Protection and the Senate Judiciary Committee, ensuring ongoing legislative engagement with AI governance issues. The distributed governance model—with CDT as coordinator, agencies as implementers, and the Legislature as overseer—reflects the cross-cutting nature of AI technologies that affect virtually every government function.
Key Focus Areas
- Unified AI Definition: Establishes a single, comprehensive definition of artificial intelligence applicable across all California codes, eliminating inconsistencies and providing regulatory clarity for agencies and technology vendors.
- High-Risk System Inventory: Requires comprehensive cataloging of AI systems making decisions with significant legal impacts in sensitive domains including housing, education, employment, credit, healthcare, and criminal justice.
- Performance Documentation: Mandates documentation of performance metrics for each high-risk system, enabling assessment of accuracy, fairness, and reliability in consequential government decisions.
- Cybersecurity Requirements: Requires cybersecurity controls protecting AI systems from manipulation, unauthorized access, and adversarial attacks that could compromise decision-making integrity.
- Privacy Safeguards: Mandates privacy protections for data used in and generated by high-risk automated decision systems, addressing concerns about surveillance and personal information exposure.
- Contestation Processes: Requires mechanisms enabling individuals to challenge automated decisions affecting their rights, ensuring human oversight and due process in AI-assisted government actions.
- Deepfake Impact Assessment: Directs evaluation of how synthetic media affects state government operations, California businesses, and residents, anticipating growing threats from AI-generated deceptive content.
- Content Authenticity Standards: Requires development of standards for verifying digital content authenticity, supporting public ability to distinguish genuine from synthetic media.
- Legislative Reporting: Mandates annual reports to legislative committees through 2029, ensuring ongoing oversight as AI technologies evolve and their government applications expand.
- Automation Employment Impact: Requires disclosure of AI and automation effects on job creation and displacement in warehouse distribution center subsidy reports, addressing economic disruption concerns.
Implementation Framework
AB 2885 establishes a phased implementation approach beginning with immediate effect upon the Governor's signature on September 28, 2024. The Department of Technology must develop inventory methodologies and coordinate initial data collection from state agencies, with the first comprehensive inventory deadline set for September 1, 2024 (retroactively, for ongoing systems). State agencies must identify all high-risk automated decision systems within their operations, document required elements including performance metrics and cybersecurity controls, and submit information to CDT for the central registry. The Secretary of Government Operations must complete the initial deepfake impact evaluation by October 1, 2024, though certain deepfake-related provisions sunset January 1, 2025, unless extended by subsequent legislation. Annual reports to the Assembly Committee on Privacy and Consumer Protection and Senate Judiciary Committee must continue through January 1, 2029, providing a five-year window for legislative oversight as AI governance matures. Local agencies administering economic development subsidies must incorporate AI and automation impact disclosures into their existing annual reporting processes. The law does not prescribe specific technical standards for AI systems or mandate particular governance structures, instead establishing outcome-based requirements that agencies must meet through appropriate means. This flexibility acknowledges the diversity of AI applications across government while ensuring minimum accountability standards apply universally. Ongoing compliance requires agencies to update inventory submissions as systems change, new high-risk applications are deployed, or governance measures are modified.
Monitoring and Evaluation
AB 2885 establishes structured monitoring through mandatory annual reporting to legislative committees, creating regular touchpoints for assessing implementation progress and identifying emerging challenges. The Department of Technology must aggregate agency submissions, analyze trends in high-risk AI deployment, and report findings to the Assembly Committee on Privacy and Consumer Protection and Senate Judiciary Committee. These reports must continue through January 1, 2029, providing a multi-year window for tracking the evolution of government AI use. The California State Auditor has implicit authority to review agency compliance with inventory requirements and the accuracy of reported information, providing independent verification beyond agency self-reporting. Legislative committees may conduct hearings, request additional information, and propose legislative amendments based on reported findings. The Government Operations Agency's deepfake evaluation creates a baseline assessment against which future synthetic media threats can be measured. However, AB 2885 does not establish formal performance metrics for the law's success, dedicated evaluation staff, or requirements for public reporting beyond legislative submissions. The sunset of certain deepfake provisions on January 1, 2025, creates a built-in evaluation point requiring legislative action to extend or modify those requirements. Academic researchers, civil society organizations, and journalists may independently assess government AI practices using information disclosed through reporting requirements, complementing official monitoring with external perspectives on implementation effectiveness and remaining gaps.
Penalties, Liability, and Appeals
AB 2885 does not establish specific penalties for non-compliance with inventory, reporting, or governance requirements. This reflects the law's focus on transparency and coordination rather than punitive enforcement. State agencies that fail to participate in inventory processes or submit required information may face scrutiny through annual legislative reports, potential State Auditor investigations, and administrative accountability through executive branch oversight. The absence of statutory penalties places compliance emphasis on administrative processes, inter-agency coordination, and reputational accountability before legislative committees. For high-risk automated decision systems affecting individuals, the required contestation processes provide appeal mechanisms for specific decisions—though AB 2885 establishes the requirement for such processes without prescribing their form. Individuals adversely affected by automated decisions may pursue existing administrative appeals, civil rights claims, or other legal remedies depending on the domain and nature of the decision. The deepfake evaluation and content authenticity standards development carry no direct enforcement mechanisms; compliance depends on executive branch commitment to complete required assessments and develop standards as directed. Future legislation may establish more specific accountability measures as the AI governance framework matures and implementation gaps become apparent. The law's approach prioritizes building foundational infrastructure—definitions, inventories, and reporting—over immediate enforcement, creating the information base needed for more targeted regulation in subsequent years.
Relationship to Other Instruments
AB 2885 operates within California's expanding ecosystem of AI-related legislation and connects to broader federal and international frameworks. California AB 2013 addresses generative AI training data transparency, while California SB 942 establishes AI content detection and labeling requirements—together with AB 2885, these laws create a comprehensive framework covering AI definition, development (training data), deployment (government use), and output (content transparency). The California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA) establish privacy rights relevant to personal information processed by high-risk automated decision systems inventoried under AB 2885. California Government Code sections addressing government technology management provide the administrative framework within which CDT exercises its AB 2885 responsibilities. The Executive Order 14110 issued by President Biden in October 2023 establishes federal AI governance frameworks that may interact with state-level requirements, particularly regarding federal agencies operating in California or federal-state program intersections. The European Union AI Act provides international precedent for risk-based AI governance, with its high-risk system requirements conceptually aligned with AB 2885's focus on automated decisions with significant legal impacts. The National Institute of Standards and Technology (NIST) AI Risk Management Framework offers guidance that California agencies may reference when implementing AB 2885's governance requirements, though the law does not mandate specific framework adoption.
International Alignment
AB 2885 positions California within the emerging global landscape of government AI governance. The law's focus on high-risk automated decision systems conceptually aligns with the European Union AI Act's risk-based approach, which subjects AI systems in sensitive domains to enhanced requirements. However, AB 2885's inventory and reporting model differs from the EU's prescriptive conformity assessment requirements, reflecting distinct regulatory philosophies—California emphasizing transparency and legislative oversight, the EU emphasizing pre-market compliance verification. The law's unified AI definition addresses definitional fragmentation challenges that international bodies including the OECD have identified as barriers to coherent AI governance. By establishing a functional definition focused on inferential capacity and output generation, California takes a technology-neutral approach compatible with evolving AI capabilities. The UK's sector-based AI regulatory framework, relying on existing regulators to apply AI principles within their domains, differs from California's cross-cutting approach through a central technology authority. Canada's proposed Artificial Intelligence and Data Act (AIDA) includes high-impact system requirements conceptually similar to AB 2885's high-risk inventory, suggesting convergence toward risk-tiered approaches across jurisdictions. California's substantial economic and political influence means AB 2885's definition and inventory model may influence other U.S. states developing AI governance frameworks, potentially contributing to greater domestic harmonization even in the absence of comprehensive federal legislation. The law's focus on government AI use—rather than private sector development—distinguishes it from many international frameworks but addresses a governance gap that affects residents' rights and opportunities in consequential domains.
Implementation Timeline
| Date | Milestone |
|---|---|
| February 15, 2024 | AB 2885 introduced by Assemblymember Rebecca Bauer-Kahan |
| August 2024 | Bill passes California Senate |
| September 1, 2024 | Initial inventory deadline for high-risk automated decision systems |
| September 28, 2024 | Governor Gavin Newsom signs AB 2885 into law (Chapter 843) |
| October 1, 2024 | Deepfake impact evaluation deadline for Secretary of Government Operations |
| January 1, 2025 | Certain deepfake provisions sunset unless extended |
| 2025-2028 | Annual reporting to legislative committees continues |
| January 1, 2029 | Final annual report deadline; reporting requirements sunset |
Compliance Checklist
| Requirement | Details |
|---|---|
| Identify High-Risk Systems | State agencies must identify all automated decision systems making decisions with significant legal impacts in housing, education, employment, credit, healthcare, and criminal justice |
| Document Performance Metrics | Record accuracy rates, error patterns, and performance assessments for each high-risk system |
| Implement Cybersecurity Controls | Establish protections against manipulation, unauthorized access, and adversarial attacks on AI systems |
| Establish Privacy Safeguards | Document privacy protections for data used in and generated by automated decision systems |
| Create Contestation Processes | Develop mechanisms enabling individuals to challenge automated decisions affecting their rights |
| Submit Inventory Information | Provide required documentation to Department of Technology for central registry |
| Update Inventory Annually | Revise submissions as systems change, new applications deploy, or governance measures evolve |
| Complete Deepfake Evaluation | Government Operations Agency must assess deepfake impacts on government, businesses, and residents |
| Develop Authenticity Standards | Create standards for verifying digital content authenticity |
| Report Economic Impacts | Local agencies must disclose AI and automation effects on employment in subsidy reports |
Sources and References
| Source | Type |
|---|---|
| AB 2885 Bill Text - California Legislature | Primary Source |
| AB 2885 Bill History - California Legislature | Primary Source |
| California Department of Technology | Regulatory Authority |
| California Government Operations Agency | Regulatory Authority |
California's AB 2885 establishes the state's first unified legal definition of artificial intelligence and mandates that state agencies inventory their use of high-risk automated decision systems. This new law primarily applies to California state government entities, though local agencies administering economic development subsidies also have specific reporting duties regarding AI's impact on employment.
At its core, the law defines AI broadly as "an engineered or machine-based system that varies in its level of autonomy" and can generate outputs influencing environments. The most significant obligation for state agencies is to identify and catalog all "high-risk automated decision systems" they use. These are AI systems making decisions with significant legal impacts on individuals, particularly in sensitive areas such as housing, education, employment, credit, healthcare, and criminal justice. For each identified system, agencies must document its performance metrics, cybersecurity controls, privacy safeguards, and establish clear processes for individuals to challenge automated decisions. The law also directs the Government Operations Agency to evaluate the impact of deepfakes and develop standards for content authenticity. Annual reports on these inventories must be submitted to the Legislature through 2028.
While the law officially takes effect on January 1, 2025, state agencies faced an initial deadline of September 1, 2024, to inventory existing high-risk systems, and the deepfake evaluation was due by October 1, 2024. A key surprise for many might be the absence of direct penalties for agencies that fail to comply with these inventory or reporting requirements. Instead, enforcement relies on legislative scrutiny, potential State Auditor reviews, and administrative accountability. This means compliance is driven more by transparency and oversight than by fines. Another practical pitfall is that certain deepfake provisions are set to expire on January 1, 2025, unless lawmakers extend them.
Plain-English rewrite by Regulations.ai — not legal advice. Verify against the official text.
What you must do — compliance checklist
0 / 13 marked completePlain-English obligations under United States - California - AI Definition Act (AB 2885). Not legal advice — verify against the official text before relying on it.
- #1ImportantImplementation Framework⏰ Sep 1, 2024
Applies to: California Department of Technology
“The Department of Technology must develop inventory methodologies and coordinate initial data collection”
- #2ImportantImplementation Framework⏰ Sep 1, 2024
Applies to: California state agencies
“State agencies must identify all high-risk automated decision systems within their operations”
- #3ImportantKey Focus Areas⏰ Sep 1, 2024
Applies to: California state agencies
“Mandates documentation of performance metrics for each high-risk system”
- #4ImportantKey Focus Areas⏰ Sep 1, 2024
Applies to: California state agencies
“Requires cybersecurity controls protecting AI systems from manipulation, unauthorized access, and adversarial attacks”
- #5ImportantKey Focus Areas⏰ Sep 1, 2024
Applies to: California state agencies
“Mandates privacy protections for data used in and generated by high-risk automated decision systems”
- #6ImportantKey Focus Areas⏰ Sep 1, 2024
Applies to: California state agencies
“Requires mechanisms enabling individuals to challenge automated decisions affecting their rights”
- #7ImportantImplementation Framework⏰ Sep 1, 2024
Applies to: California state agencies
“submit information to CDT for the central registry.”
- #8ImportantImplementation Framework⏰ Oct 1, 2024
Applies to: California Government Operations Agency
“The Secretary of Government Operations must complete the initial deepfake impact evaluation by October 1, 2024”
- #9ImportantGovernance and Institutional Framework
Applies to: California Department of Technology
“CDT must... maintain the central registry of high-risk automated decision systems”
- #10ImportantImplementation Framework
Applies to: California state agencies
“Ongoing compliance requires agencies to update inventory submissions as systems change”
- #11ImportantMonitoring and Evaluation⏰ Jan 1, 2029
Applies to: California Department of Technology
“The Department of Technology must... report findings to the Assembly Committee on Privacy and Consumer Protection and Senate Judiciary Committee.”
- #12ImportantKey Focus Areas
Applies to: California Government Operations Agency
“Requires development of standards for verifying digital content authenticity”
- #13ImportantImplementation Framework
Applies to: California local agencies administering economic development subsidies
“Local agencies... must incorporate AI and automation impact disclosures into their existing annual reporting processes.”
Related Regulations
California AI Transparency Act
California, United States92% similar
California SB 53 — Transparency in Frontier Artificial Intelligence Act (TFAIA)
United States91% similar
California AB 2655 - Defending Democracy from Deepfake Deception Act of 2024
United States91% similar
California SB 942 — California AI Transparency Act
United States90% similar
California Executive Order N-5-26 — Responsible Procurement and Deployment of Generative Artificial Intelligence
California, United States90% similar
© Regulations.AI — created on 12-Jun-2026