United States - California - AI Definition Act (AB 2885)

California AB 2885 — Artificial Intelligence: Unified Definition and State Agency Inventory

United States

RAI-US-CA-CA2AIXX-2024
Effective: January 1, 2025
In Force(In Force)
ActGovernance and OversightAccountability and Documentation
Export PDF

California Assembly Bill 2885 establishes the first unified legal definition of artificial intelligence in California law and mandates a comprehensive inventory of high-risk automated decision systems used by state agencies. The law defines AI as 'an engineered or machine-based system that varies in its level of autonomy' capable of generating outputs that influence environments, requiring annual reports through 2028 and deepfake impact assessments.

Overview

California Assembly Bill 2885 (Chapter 843, Statutes of 2024) establishes California's first comprehensive legal framework for defining artificial intelligence and cataloging its use within state government. Authored by Assemblymember Rebecca Bauer-Kahan and signed by Governor Gavin Newsom on September 28, 2024, the legislation addresses a critical gap in California's regulatory infrastructure by creating a unified AI definition applicable across multiple code sections. As AI technologies become increasingly embedded in government services—from benefits administration to criminal justice—the absence of consistent definitions and oversight mechanisms created regulatory fragmentation and accountability gaps. AB 2885 responds to these challenges by mandating comprehensive inventories of high-risk automated decision systems, requiring annual reporting to the Legislature, and directing evaluation of emerging threats like deepfakes. The law positions California as a leader in government AI governance, establishing precedents that may influence both federal legislation and other states' approaches to public sector AI accountability.

Definitions

AB 2885 establishes a foundational definition of artificial intelligence that applies uniformly across California law. Artificial intelligence is defined as 'an engineered or machine-based system that varies in its level of autonomy and that can, for explicit or implicit objectives, infer from the input it receives how to generate outputs that can influence physical or virtual environments.' This definition is intentionally broad, encompassing traditional rule-based expert systems, modern machine learning models, and emerging generative AI technologies. The definition acknowledges that AI systems operate along a spectrum of autonomy—from systems requiring substantial human oversight to those capable of independent operation. By focusing on the inferential capacity to generate influential outputs, the definition captures both decision-support tools and autonomous systems. High-risk automated decision system refers to AI systems used to make decisions with significant legal impacts on individuals, particularly in sensitive domains including housing, education, employment, credit, healthcare, and criminal justice. Deepfake means synthetic media created using artificial intelligence that depicts events or statements that did not occur, with particular focus on content designed to deceive viewers about its authenticity. Content authenticity refers to metadata and verification mechanisms that enable users to assess whether digital content is genuine, modified, or synthetically generated.

Governance and Institutional Framework

AB 2885 assigns primary responsibility for AI inventory and governance to the California Department of Technology (CDT), which serves as the state's central technology authority. CDT must develop inventory methodologies, coordinate with all state agencies, maintain the central registry of high-risk automated decision systems, and prepare annual reports for legislative oversight. The Government Operations Agency, through its Secretary, bears responsibility for evaluating deepfake impacts and developing content authenticity standards—reflecting recognition that synthetic media threats require executive-level attention. Individual state agencies must participate in inventory processes, document their high-risk AI systems, and implement required governance measures including performance metrics, cybersecurity controls, and contestation processes. Local agencies administering economic development subsidies face separate reporting requirements regarding AI and automation impacts on employment. The California State Auditor may review agency compliance and the accuracy of inventory submissions. Legislative oversight occurs through required reports to the Assembly Committee on Privacy and Consumer Protection and the Senate Judiciary Committee, ensuring ongoing legislative engagement with AI governance issues. The distributed governance model—with CDT as coordinator, agencies as implementers, and the Legislature as overseer—reflects the cross-cutting nature of AI technologies that affect virtually every government function.

Key Focus Areas

  • Unified AI Definition: Establishes a single, comprehensive definition of artificial intelligence applicable across all California codes, eliminating inconsistencies and providing regulatory clarity for agencies and technology vendors.
  • High-Risk System Inventory: Requires comprehensive cataloging of AI systems making decisions with significant legal impacts in sensitive domains including housing, education, employment, credit, healthcare, and criminal justice.
  • Performance Documentation: Mandates documentation of performance metrics for each high-risk system, enabling assessment of accuracy, fairness, and reliability in consequential government decisions.
  • Cybersecurity Requirements: Requires cybersecurity controls protecting AI systems from manipulation, unauthorized access, and adversarial attacks that could compromise decision-making integrity.
  • Privacy Safeguards: Mandates privacy protections for data used in and generated by high-risk automated decision systems, addressing concerns about surveillance and personal information exposure.
  • Contestation Processes: Requires mechanisms enabling individuals to challenge automated decisions affecting their rights, ensuring human oversight and due process in AI-assisted government actions.
  • Deepfake Impact Assessment: Directs evaluation of how synthetic media affects state government operations, California businesses, and residents, anticipating growing threats from AI-generated deceptive content.
  • Content Authenticity Standards: Requires development of standards for verifying digital content authenticity, supporting public ability to distinguish genuine from synthetic media.
  • Legislative Reporting: Mandates annual reports to legislative committees through 2029, ensuring ongoing oversight as AI technologies evolve and their government applications expand.
  • Automation Employment Impact: Requires disclosure of AI and automation effects on job creation and displacement in warehouse distribution center subsidy reports, addressing economic disruption concerns.

Implementation Framework

AB 2885 establishes a phased implementation approach beginning with immediate effect upon the Governor's signature on September 28, 2024. The Department of Technology must develop inventory methodologies and coordinate initial data collection from state agencies, with the first comprehensive inventory deadline set for September 1, 2024 (retroactively, for ongoing systems). State agencies must identify all high-risk automated decision systems within their operations, document required elements including performance metrics and cybersecurity controls, and submit information to CDT for the central registry. The Secretary of Government Operations must complete the initial deepfake impact evaluation by October 1, 2024, though certain deepfake-related provisions sunset January 1, 2025, unless extended by subsequent legislation. Annual reports to the Assembly Committee on Privacy and Consumer Protection and Senate Judiciary Committee must continue through January 1, 2029, providing a five-year window for legislative oversight as AI governance matures. Local agencies administering economic development subsidies must incorporate AI and automation impact disclosures into their existing annual reporting processes. The law does not prescribe specific technical standards for AI systems or mandate particular governance structures, instead establishing outcome-based requirements that agencies must meet through appropriate means. This flexibility acknowledges the diversity of AI applications across government while ensuring minimum accountability standards apply universally. Ongoing compliance requires agencies to update inventory submissions as systems change, new high-risk applications are deployed, or governance measures are modified.

Monitoring and Evaluation

AB 2885 establishes structured monitoring through mandatory annual reporting to legislative committees, creating regular touchpoints for assessing implementation progress and identifying emerging challenges. The Department of Technology must aggregate agency submissions, analyze trends in high-risk AI deployment, and report findings to the Assembly Committee on Privacy and Consumer Protection and Senate Judiciary Committee. These reports must continue through January 1, 2029, providing a multi-year window for tracking the evolution of government AI use. The California State Auditor has implicit authority to review agency compliance with inventory requirements and the accuracy of reported information, providing independent verification beyond agency self-reporting. Legislative committees may conduct hearings, request additional information, and propose legislative amendments based on reported findings. The Government Operations Agency's deepfake evaluation creates a baseline assessment against which future synthetic media threats can be measured. However, AB 2885 does not establish formal performance metrics for the law's success, dedicated evaluation staff, or requirements for public reporting beyond legislative submissions. The sunset of certain deepfake provisions on January 1, 2025, creates a built-in evaluation point requiring legislative action to extend or modify those requirements. Academic researchers, civil society organizations, and journalists may independently assess government AI practices using information disclosed through reporting requirements, complementing official monitoring with external perspectives on implementation effectiveness and remaining gaps.

Penalties, Liability, and Appeals

AB 2885 does not establish specific penalties for non-compliance with inventory, reporting, or governance requirements. This reflects the law's focus on transparency and coordination rather than punitive enforcement. State agencies that fail to participate in inventory processes or submit required information may face scrutiny through annual legislative reports, potential State Auditor investigations, and administrative accountability through executive branch oversight. The absence of statutory penalties places compliance emphasis on administrative processes, inter-agency coordination, and reputational accountability before legislative committees. For high-risk automated decision systems affecting individuals, the required contestation processes provide appeal mechanisms for specific decisions—though AB 2885 establishes the requirement for such processes without prescribing their form. Individuals adversely affected by automated decisions may pursue existing administrative appeals, civil rights claims, or other legal remedies depending on the domain and nature of the decision. The deepfake evaluation and content authenticity standards development carry no direct enforcement mechanisms; compliance depends on executive branch commitment to complete required assessments and develop standards as directed. Future legislation may establish more specific accountability measures as the AI governance framework matures and implementation gaps become apparent. The law's approach prioritizes building foundational infrastructure—definitions, inventories, and reporting—over immediate enforcement, creating the information base needed for more targeted regulation in subsequent years.

Relationship to Other Instruments

AB 2885 operates within California's expanding ecosystem of AI-related legislation and connects to broader federal and international frameworks. California AB 2013 addresses generative AI training data transparency, while California SB 942 establishes AI content detection and labeling requirements—together with AB 2885, these laws create a comprehensive framework covering AI definition, development (training data), deployment (government use), and output (content transparency). The California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA) establish privacy rights relevant to personal information processed by high-risk automated decision systems inventoried under AB 2885. California Government Code sections addressing government technology management provide the administrative framework within which CDT exercises its AB 2885 responsibilities. The Executive Order 14110 issued by President Biden in October 2023 establishes federal AI governance frameworks that may interact with state-level requirements, particularly regarding federal agencies operating in California or federal-state program intersections. The European Union AI Act provides international precedent for risk-based AI governance, with its high-risk system requirements conceptually aligned with AB 2885's focus on automated decisions with significant legal impacts. The National Institute of Standards and Technology (NIST) AI Risk Management Framework offers guidance that California agencies may reference when implementing AB 2885's governance requirements, though the law does not mandate specific framework adoption.

International Alignment

AB 2885 positions California within the emerging global landscape of government AI governance. The law's focus on high-risk automated decision systems conceptually aligns with the European Union AI Act's risk-based approach, which subjects AI systems in sensitive domains to enhanced requirements. However, AB 2885's inventory and reporting model differs from the EU's prescriptive conformity assessment requirements, reflecting distinct regulatory philosophies—California emphasizing transparency and legislative oversight, the EU emphasizing pre-market compliance verification. The law's unified AI definition addresses definitional fragmentation challenges that international bodies including the OECD have identified as barriers to coherent AI governance. By establishing a functional definition focused on inferential capacity and output generation, California takes a technology-neutral approach compatible with evolving AI capabilities. The UK's sector-based AI regulatory framework, relying on existing regulators to apply AI principles within their domains, differs from California's cross-cutting approach through a central technology authority. Canada's proposed Artificial Intelligence and Data Act (AIDA) includes high-impact system requirements conceptually similar to AB 2885's high-risk inventory, suggesting convergence toward risk-tiered approaches across jurisdictions. California's substantial economic and political influence means AB 2885's definition and inventory model may influence other U.S. states developing AI governance frameworks, potentially contributing to greater domestic harmonization even in the absence of comprehensive federal legislation. The law's focus on government AI use—rather than private sector development—distinguishes it from many international frameworks but addresses a governance gap that affects residents' rights and opportunities in consequential domains.

Implementation Timeline

DateMilestone
February 15, 2024AB 2885 introduced by Assemblymember Rebecca Bauer-Kahan
August 2024Bill passes California Senate
September 1, 2024Initial inventory deadline for high-risk automated decision systems
September 28, 2024Governor Gavin Newsom signs AB 2885 into law (Chapter 843)
October 1, 2024Deepfake impact evaluation deadline for Secretary of Government Operations
January 1, 2025Certain deepfake provisions sunset unless extended
2025-2028Annual reporting to legislative committees continues
January 1, 2029Final annual report deadline; reporting requirements sunset

Compliance Checklist

RequirementDetails
Identify High-Risk SystemsState agencies must identify all automated decision systems making decisions with significant legal impacts in housing, education, employment, credit, healthcare, and criminal justice
Document Performance MetricsRecord accuracy rates, error patterns, and performance assessments for each high-risk system
Implement Cybersecurity ControlsEstablish protections against manipulation, unauthorized access, and adversarial attacks on AI systems
Establish Privacy SafeguardsDocument privacy protections for data used in and generated by automated decision systems
Create Contestation ProcessesDevelop mechanisms enabling individuals to challenge automated decisions affecting their rights
Submit Inventory InformationProvide required documentation to Department of Technology for central registry
Update Inventory AnnuallyRevise submissions as systems change, new applications deploy, or governance measures evolve
Complete Deepfake EvaluationGovernment Operations Agency must assess deepfake impacts on government, businesses, and residents
Develop Authenticity StandardsCreate standards for verifying digital content authenticity
Report Economic ImpactsLocal agencies must disclose AI and automation effects on employment in subsidy reports

Sources and References

SourceType
AB 2885 Bill Text - California LegislaturePrimary Source
AB 2885 Bill History - California LegislaturePrimary Source
California Department of TechnologyRegulatory Authority
California Government Operations AgencyRegulatory Authority
Plain English

California's AB 2885 establishes the state's first unified legal definition of artificial intelligence and mandates that state agencies inventory their use of high-risk automated decision systems. This new law primarily applies to California state government entities, though local agencies administering economic development subsidies also have specific reporting duties regarding AI's impact on employment.

At its core, the law defines AI broadly as "an engineered or machine-based system that varies in its level of autonomy" and can generate outputs influencing environments. The most significant obligation for state agencies is to identify and catalog all "high-risk automated decision systems" they use. These are AI systems making decisions with significant legal impacts on individuals, particularly in sensitive areas such as housing, education, employment, credit, healthcare, and criminal justice. For each identified system, agencies must document its performance metrics, cybersecurity controls, privacy safeguards, and establish clear processes for individuals to challenge automated decisions. The law also directs the Government Operations Agency to evaluate the impact of deepfakes and develop standards for content authenticity. Annual reports on these inventories must be submitted to the Legislature through 2028.

While the law officially takes effect on January 1, 2025, state agencies faced an initial deadline of September 1, 2024, to inventory existing high-risk systems, and the deepfake evaluation was due by October 1, 2024. A key surprise for many might be the absence of direct penalties for agencies that fail to comply with these inventory or reporting requirements. Instead, enforcement relies on legislative scrutiny, potential State Auditor reviews, and administrative accountability. This means compliance is driven more by transparency and oversight than by fines. Another practical pitfall is that certain deepfake provisions are set to expire on January 1, 2025, unless lawmakers extend them.

Plain-English rewrite by Regulations.ai — not legal advice. Verify against the official text.

What you must do — compliance checklist

0 / 13 marked complete

Plain-English obligations under United States - California - AI Definition Act (AB 2885). Not legal advice — verify against the official text before relying on it.

  1. #1ImportantImplementation FrameworkSep 1, 2024

    Applies to: California Department of Technology

    The Department of Technology must develop inventory methodologies and coordinate initial data collection
  2. #2ImportantImplementation FrameworkSep 1, 2024

    Applies to: California state agencies

    State agencies must identify all high-risk automated decision systems within their operations
  3. #3ImportantKey Focus AreasSep 1, 2024

    Applies to: California state agencies

    Mandates documentation of performance metrics for each high-risk system
  4. #4ImportantKey Focus AreasSep 1, 2024

    Applies to: California state agencies

    Requires cybersecurity controls protecting AI systems from manipulation, unauthorized access, and adversarial attacks
  5. #5ImportantKey Focus AreasSep 1, 2024

    Applies to: California state agencies

    Mandates privacy protections for data used in and generated by high-risk automated decision systems
  6. #6ImportantKey Focus AreasSep 1, 2024

    Applies to: California state agencies

    Requires mechanisms enabling individuals to challenge automated decisions affecting their rights
  7. #7ImportantImplementation FrameworkSep 1, 2024

    Applies to: California state agencies

    submit information to CDT for the central registry.
  8. #8ImportantImplementation FrameworkOct 1, 2024

    Applies to: California Government Operations Agency

    The Secretary of Government Operations must complete the initial deepfake impact evaluation by October 1, 2024
  9. #9ImportantGovernance and Institutional Framework

    Applies to: California Department of Technology

    CDT must... maintain the central registry of high-risk automated decision systems
  10. #10ImportantImplementation Framework

    Applies to: California state agencies

    Ongoing compliance requires agencies to update inventory submissions as systems change
  11. #11ImportantMonitoring and EvaluationJan 1, 2029

    Applies to: California Department of Technology

    The Department of Technology must... report findings to the Assembly Committee on Privacy and Consumer Protection and Senate Judiciary Committee.
  12. #12ImportantKey Focus Areas

    Applies to: California Government Operations Agency

    Requires development of standards for verifying digital content authenticity
  13. #13ImportantImplementation Framework

    Applies to: California local agencies administering economic development subsidies

    Local agencies... must incorporate AI and automation impact disclosures into their existing annual reporting processes.

© Regulations.AI — created on 12-Jun-2026