← Tous les articles

AI Governance · August 21, 2026 · 5 min de lecture

California Passed Thirty AI Laws in Under an Hour. Almost Nobody Was Watching.

On August 13, California decided the fate of about thirty AI bills in a closed hearing with no debate. Here is what passed, why it matters beyond the US, and what SMEs should do about it.

If your company works with any US clients, uses a US hosted AI vendor, or simply sells software that touches American users, a piece of your compliance picture may have just been decided for you. In a closed room in Sacramento, in under an hour, with no public debate and no recorded vote for the bills that did not make it.

That happened on August 13, 2026. Not a metaphor. California's suspense file process ran the state's entire 2026 AI legislative agenda through two back to back appropriations hearings. Roughly thirty bills went in. The ones a committee chair chose to call got a vote. The ones nobody called simply went silent, no announcement, no statement, dead for the session.

What is actually happening

This is worth understanding because it is not really about California. It is about how AI regulation gets made in practice, and the pattern is instructive well beyond one state.

The bills that survived cluster around specific, narrow harms rather than "AI" as a category: chatbot safety for children (AB 2023, SB 1119, SB 867, SB 300), a copyright transparency requirement for training data (AB 412), workplace notice rules before AI driven layoffs or algorithmic management (AB 1883, SB 947, SB 951, AB 2656), and a first in the nation voluntary AI safety certification framework built from two companion bills, SB 813 and AB 1405, that only function together.

None of this regulates "artificial intelligence" as a whole. Each bill regulates one specific way AI touches a person: a child talking to a chatbot, a worker learning they were scored by an algorithm, a voice actor whose biometric data trained a model without consent, a patient whose insurance claim was denied by an automated system. Governor Newsom's own veto record backs this up. He has consistently signed transparency and disclosure bills while vetoing broader, liability expanding ones. Specificity survives. Sweeping mandates do not.

And because no company maintains a separate product for California's 39 million residents, what passes there tends to become the practical compliance floor for the rest of the US market, whether or not your own state or country ever writes an equivalent law.

The strategic reframe

Most companies watching this concluded one of two things: either "this is US news, not our problem," or "we will deal with it once something is actually enacted." Both miss what actually matters.

The real story is the mechanism, not the state. Decisions that shape how you are allowed to build and sell AI products increasingly happen in compressed, low visibility processes, decided in private conversations days before a public hearing that itself allows no testimony and no amendments. If your only method for tracking AI governance is reading headlines when a law takes effect, you are finding out months after the decisions that actually mattered were made.

This is the same blind spot MAKIA sees inside organizations. Governance gets treated as a compliance checkbox to revisit once a year, instead of a live input into adoption decisions made continuously. A vendor you selected in March may be subject to a certification requirement passed in August. A workflow you built around a chatbot may now trigger a disclosure obligation you did not know existed.

What this means in practice

For an SME or a leadership team without a legal department tracking every legislature, four things are worth doing regardless of where you operate.

First, treat AI vendor selection as an ongoing relationship, not a one time purchase decision. The vendors most exposed to this wave of law, chatbot providers, AI hiring tools, healthcare AI, are the ones whose terms of service are most likely to change under you.

Second, pay attention to what regulators are actually targeting: child safety, workplace transparency, copyright provenance, deepfake disclosure. These are a reasonable proxy for where your own internal AI policy should focus first, independent of what your jurisdiction requires today.

Third, watch the certification trend. SB 813 and AB 1405 point toward a future where "our AI vendor is independently audited" becomes a real differentiator, not a nice to have. Ask your vendors now whether they can show any third party verification of their safety or data practices.

Fourth, build a habit, not a project. A twenty minute quarterly scan of what changed in AI regulation relevant to your sector will catch more than a compliance review you run once and then forget.

None of this requires a lawyer on retainer. It requires treating regulatory awareness the same way you treat competitive awareness: something you check on a schedule, not something you discover by accident.

Try this week

Pick the AI tool your team relies on most. Spend fifteen minutes on the vendor's website looking for a trust, security, or transparency page. Note whether they mention any independent audit, safety certification, or compliance framework. If you find nothing, write down that gap. That single note is the start of a vendor governance habit, not a compliance project.

Sources

  • California AI Bills Face Final Vote Today: Chatbot Safety, Copyright, US-First Commission — Tech Times
  • AI Legislative Update: August 14, 2026 — Transparency Coalition
Partager cet articleLinkedInFil RSS