California SB 503

California SB 503 — Health Care Services: Artificial Intelligence

United States

RAI-US-CA-SB50300-2026

SB 503

Awaiting Entry(Awaiting Entry)

California SB 503 is Awaiting Entry in United States, according to leginfo.legislature.ca.gov. We have not yet been able to confirm the status.

ActFundamental RightsTransparency and DisclosureAccountability and Documentation
Export PDF

California SB 503 regulates clinical AI in health care to reduce biased impacts and require documentation and monitoring.

Summary

SB 503 adds a California Business and Professions Code chapter governing clinical decision support AI in health care, with a focus on identifying and mitigating biased impacts. It requires developers and deployers to share documentation, monitor deployment, and preserve broader anti-discrimination protections.

Full article

Read full text ↗

Overview

Senate Bill 503 adds Chapter 25.3, beginning with Section 22758, to Division 8 of the California Business and Professions Code. It regulates artificial intelligence used in clinical decision support in health care settings. The statute targets systems that produce a prediction, classification, recommendation, evaluation, or analysis that aids decisionmaking related to timing of care, diagnosis, or treatment. Its core purpose is to reduce the risk that such systems produce biased impacts in health programs or activities. In practical terms, the law requires developers and deployers to identify systems with known or reasonably foreseeable biased impacts, to exchange specific documentation, and to monitor deployment after release. The measure also clarifies that a person, partnership, state or local governmental agency, or corporation may act as both developer and deployer.

The statute is expressly additive. It does not replace other California rules governing artificial intelligence or automated decision systems, and compliance with this section is not a defense to an unlawful discrimination claim. That structure matters because the law is not a comprehensive AI code; it is a focused health-sector guardrail built around bias awareness, documentation, and ongoing monitoring. It also excludes appointment management, appointment reminders, patient education and previsit materials, and payment processing, so long as independent performance of those activities does not require a professional license. The chapter was approved and filed on September 30, 2026, and, under the California Constitution as noted, takes effect on 2027-01-01.

Definitions

The statute adopts a defined vocabulary that closely tracks operational roles in clinical AI deployment. “Artificial intelligence” has the same meaning as in Government Code Section 11546.45.5. A “clinical decision support system” is an AI system that produces a prediction, classification, recommendation, evaluation, or analysis that aids clinical decisionmaking related to timing of care, diagnosis, or treatment. “Deployer” means a health facility, clinic, physician’s office, or office of a group practice that uses such a system. “Developer” means a person, partnership, state or local governmental agency, corporation, or deployer that designs, codes, substantially modifies, or otherwise produces a clinical decision support system for commercial or public use.

The law also defines “biased impact” as an adverse impact, including diminished access to health care, quality of care, or outcomes, on an individual based on a protected characteristic. Protected characteristic adopts the meaning in Civil Code Section 51(b). The remaining definitions incorporate existing California health law: “clinic” references Health and Safety Code Sections 1200 and 1200.1, “health facility” references Section 1250 of that code, “health care provider” refers to a person licensed or certified under Division 2, “office of a group practice” refers to an office or offices in which two or more physicians are legally organized in specified forms, and “physician’s office” means a physician’s solo-practice office. These definitions anchor the statute in the state’s existing professional licensing and facility-regulation framework.

Governance and Institutional Framework

SB 503 uses a dual-responsibility governance model. The first compliance actor is the developer, who must make reasonable efforts to identify clinical decision support systems that are known, or reasonably foreseeable, to present biased impacts and then make reasonable efforts to mitigate those risks. The second is the deployer, which must regularly monitor the system and take reasonable and proportionate steps to mitigate known or reasonably foreseeable biased impacts. This division of responsibility reflects the different points at which risk can be detected and managed: developers control system design, training, and documentation; deployers control local implementation, use, and monitoring. The statute therefore creates a shared-governance obligation rather than a single-point compliance rule.

The law does not create a new licensing board, registry, or dedicated AI regulator. Instead, it fits within California’s business and professions framework and relies on the regulated health entities themselves to build internal governance processes. Developers must furnish documentation “upon request or at the time of initial sale, whichever is earlier,” and again when material updates are released. The statute also allows developers to satisfy their obligations by adhering to nationally recognized or widely adopted industry standards developed through multistakeholder consensus, or by providing regularly conducted algorithmic impact assessments using industry-accepted methodologies, to the extent those standards or assessments exist. This design encourages alignment with external technical norms while keeping legal accountability in state law.

Key Focus Areas

The statute is primarily concerned with bias prevention in clinical AI. It focuses on systems that can affect diagnosis, treatment, or timing of care and that may create unequal access, quality, or outcomes for individuals based on protected characteristics. The law is therefore less about general AI explainability and more about concrete downstream effects in patient care. Its bias focus is not limited to a specific protected class; rather, it incorporates California’s broader civil rights framework through Civil Code Section 51(b). That means the law can reach disparate effects tied to race, color, ancestry, national origin, religion, disability, sex, gender identity, sexual orientation, and other protected categories recognized under state law.

The second focus area is disclosure and technical documentation. Developers must provide a statement describing intended uses and known or reasonably foreseeable risks, together with detailed documentation on training data, demographic representativeness when available, performance evaluation, limitations, mitigation of biased impacts, data governance measures, intended benefits, expected outputs, monitoring recommendations, and any other documentation reasonably necessary for deployers to understand outputs and performance. This documentation is not merely descriptive; it is meant to support responsible deployment and ongoing monitoring. The statute also reflects a practical operational boundary by excluding appointment management, reminders, patient education, previsit materials, and payment processing from the core definition when those functions do not require a professional license.

Implementation Framework

Implementation begins with developer-side identification and risk review. Developers and deployers must make reasonable efforts to identify systems with known or reasonably foreseeable biased impacts. For systems that fall within this category, developers must make reasonable efforts to mitigate those risks and supply a specified package of information to deployers. The statute gives developers flexibility in how they comply, including through industry standards or algorithmic impact assessments, but it does not eliminate the substantive obligation to address bias risks. Documentation must be provided at the point of initial sale or on request, whichever comes first, and also upon material updates. This ensures that deployers are not working from stale information when models or deployment conditions change.

Deployers are required to use the documentation in active operations. They must regularly monitor the system and take reasonable and proportionate steps to mitigate foreseeable biased impacts. The statute does not specify a formal template, certification form, or approval process, which suggests that implementation will occur through internal compliance programs, vendor management, clinical governance, and quality assurance practices. A deployer that is also a developer is exempt from generating the documentation package when the system is developed and deployed for internal use and equivalent information is readily available. That carve-out is limited and still depends on accessible transparency information. Overall, the framework is collaborative, iterative, and update-sensitive rather than front-loaded into a single pre-market review.

Monitoring and Evaluation

Monitoring is central to the statute. Deployers must regularly monitor clinical decision support systems and take reasonable and proportionate steps to mitigate known or reasonably foreseeable biased impacts. The text does not define a monitoring interval, leaving frequency to be determined by the risk profile of the system, its clinical role, the volume of use, and the characteristics of the patient population. The monitoring duty is therefore flexible, but not optional. It implies ongoing review of outputs, performance drift, and real-world effects after implementation, especially where the system influences triage, diagnosis, or treatment decisions. In addition, the developer’s documentation must include how the system was evaluated for performance, limitations, and mitigation of biased impacts, as well as recommendations for use and monitoring. This makes evaluation a continuous lifecycle obligation rather than a one-time product attribute.

The statute also permits developers to rely on nationally recognized or widely adopted industry standards developed through multistakeholder consensus, or on regularly conducted algorithmic impact assessments using industry-accepted methodologies, where available. That language is significant because it connects legal compliance to evolving technical practice. It allows health AI compliance programs to use structured evaluation tools while preserving a state-law baseline. The law does not create a state audit schedule or mandatory reporting portal, but it creates a compliance record through documentation availability, monitoring practices, and mitigation steps. In effect, evaluation is embedded in procurement, deployment, and post-deployment oversight.

Penalties, Liability, and Appeals

SB 503 does not set out its own civil penalty schedule, administrative fine structure, or appeal mechanism. Instead, it operates alongside other California laws that may already govern unlawful discrimination, health care regulation, professional licensing, or deceptive practices. The most consequential liability statement is that compliance with this section shall not be used as a defense to a claim of unlawful discrimination. That clause prevents a regulated entity from treating technical compliance with SB 503 as a shield against broader civil-rights or anti-discrimination claims. In other words, meeting documentation and monitoring duties does not necessarily satisfy all legal obligations that may arise under state or federal law.

The statute also states that it is in addition to and does not supplant or replace any other applicable provision of state law regulating artificial intelligence or automated decision systems. Because the chapter is embedded in the Business and Professions Code, enforcement may occur through existing legal theories, contract arrangements, professional duties, or general regulatory powers rather than a dedicated SB 503 enforcement office. The text does not describe a private right of action, appeal from agency action, or specific remedial process. For that reason, the practical risk exposure lies in the intersection of this chapter with the broader California discrimination, professional responsibility, and consumer protection landscape.

Relationship to Other Instruments

The statute expressly incorporates external legal and technical references. It borrows the definition of artificial intelligence from Government Code Section 11546.45.5 and uses several health-law definitions already present in the Health and Safety Code and Civil Code. That cross-referencing keeps SB 503 harmonized with existing California terminology rather than creating an isolated regulatory vocabulary. It also means that the statute’s reach depends on how those incorporated provisions are interpreted and amended over time. The law’s statement that it does not replace other AI or automated decision-system laws preserves overlap with other state measures, including broader privacy, consumer protection, and anti-discrimination rules.

On the technical side, SB 503 allows compliance through nationally recognized or widely adopted industry standards developed through multistakeholder consensus and through algorithmic impact assessments. That makes the statute compatible with external frameworks for AI governance, model evaluation, and clinical oversight, without mandating a single benchmark. The statute sits in a health-care-specific niche: it is narrower than a general AI bill, but more operational than a pure policy statement. It therefore complements, rather than displaces, documentation and risk-management approaches used in clinical procurement, quality improvement, and professional governance. Its anti-defense clause is especially important because it preserves the independent force of other instruments even when an entity follows SB 503 to the letter.

National/Federal Alignment

At the federal level, there is no single comprehensive statute governing clinical decision support AI across all health care contexts. SB 503 fills that gap at the state level by creating obligations for risk identification, documentation, monitoring, and mitigation focused on bias in health programs or activities. It aligns with broader U.S. policy trends emphasizing transparency, risk management, and accountability in AI, but it goes further than most federal guidance by imposing binding duties on health care deployers and developers. The statute’s use of “reasonable efforts,” “reasonable and proportionate steps,” and documentation-based compliance also resembles emerging governance models that prioritize lifecycle oversight over one-time approvals.

The law differs from federal medical-device or general technology regulation in two key ways. First, it is not limited to devices cleared or regulated as medical devices; it covers clinical decision support systems defined by function and use in health care decisionmaking. Second, it directly addresses discriminatory impact and protected characteristics, which places it closer to civil-rights governance than to product-safety regulation alone. By stating that compliance is not a defense to unlawful discrimination, the statute preserves the role of federal and state anti-discrimination law. In that sense, SB 503 is complementary to federal law rather than preemptive. It adds a California-specific compliance layer for AI used in care delivery and supports alignment with federal priorities on safety, fairness, and explainability without relying on a national AI statute.

Implementation Timeline

MilestoneDateNotes
Introduced2025-02-19Bill introduced in the 2025-2026 Regular Session.
Chaptered by Secretary of State2026-09-30Chapter 857, Statutes of 2026.
Approved by Governor2026-09-30Approved and filed the same day.
General effective date2027-01-01Non-urgency statute effective date under the California Constitution.

Compliance Checklist

CheckRequired Action
Identify covered systemsDetermine whether the AI system produces predictions, classifications, recommendations, evaluations, or analyses used for diagnosis or treatment.
Assess bias riskMake reasonable efforts to identify systems with known or reasonably foreseeable biased impacts.
Prepare developer statementDescribe intended uses and known or reasonably foreseeable risks associated with the system.
Provide required documentationDisclose training-data summaries, representativeness when available, performance evaluation, limitations, data governance, intended benefits, outputs, risks, mitigation efforts, and monitoring recommendations.
Deliver documentation timelyMake documentation available upon request or at initial sale, whichever is earlier, and again upon material updates.
Monitor deploymentRegularly monitor system performance and take reasonable and proportionate mitigation steps.
Maintain internal recordsRetain supporting evidence for mitigation efforts, monitoring, and any standards or impact assessments used.

Sources and References

SourceType
Senate Bill No. 503, Chapter 857, Statutes of 2026 — California Legislative Informationofficial
Governor of California — signing announcement, 30 September 2026official

© Regulations.AI — created on 9 Oct 2026 using Gemini 3.6 Flash