California SB 896: Generative AI Inside State Government
9 min read · updated August 11, 2026
SB 896 binds California state agencies, not companies. If you sell to one, it still decides what you will be asked for, because an agency under a statutory duty discharges it through its contracts.
From an executive order to a statute
The Generative Artificial Intelligence Accountability Act was signed on 29 September 2024 and took effect on 1 January 2025. Its content did not appear from nothing: Executive Order N-12-23, issued by Governor Newsom in September 2023, had already directed state entities to produce a report on the benefits and risks of generative AI in state government and to develop procurement and training guidelines. SB 896 takes the parts of that programme that were worth making permanent and puts them in statute, where a later governor cannot simply rescind them.
That history explains the shape of the Act. It is not a risk framework in the mould of Colorado’s AI Act, and it does not classify systems by risk tier the way the EU AI Act does. It is a set of housekeeping obligations for the executive branch: analyse, report, disclose, train. The bill as chaptered is at California Legislative Information, and the codified provisions sit in the Government Code.
What the Act actually requires
The central obligation is a joint risk analysis. The California Department of Technology, the Office of Emergency Services and the Governor’s Office of Business and Economic Development are directed to perform a risk analysis of potential threats posed by generative AI to California’s critical energy infrastructure, including threats that could lead to mass casualty events, and to keep it current. That is a narrower question than “is generative AI risky” — it is specifically about infrastructure that the state is responsible for defending.
Alongside it sit reporting and guidance duties: the state is to maintain guidance on the procurement and use of generative AI by state agencies, and to report on state use. In practice the operative documents for anyone selling into California are the CDT’s procurement guidelines and the standard contract provisions that flow from them, not the statutory text.
The disclosure duty on agency communications
The provision with the widest everyday effect is the disclosure duty: where a state agency uses generative AI to communicate with a natural person, the communication is to carry a disclaimer that it was generated by generative AI, along with a route to a human. Anyone who has read AB 3030 will recognise the pattern — the same legislature, the same year, the same two-part remedy applied to a different institution.
The comparison worth drawing is with Texas TRAIGA, whose government-AI disclosure duty is closely analogous: an agency must tell a person, clearly and in plain language, before or at the time of the interaction, that they are dealing with an AI system. Two states with very different politics converged on the same rule for their own agencies well before either was willing to impose a general one on private business. That is the structural fact about American AI regulation in this period, and it is worth noticing.
Why this reaches vendors who are not bound
A statutory duty on a purchaser becomes a contractual duty on its suppliers. If you sell a generative AI capability into a California state agency, expect the obligations to arrive as:
- Disclosure of the model. Which base model, from which provider, hosted where, and whether the agency’s inputs are used for training. An answer of “our proprietary AI” does not survive this question.
- Subprocessor and data-residency detail. The chain behind your endpoint, because the agency has to be able to describe it in its own inventory.
- Evidence rather than assurance. Model cards, an evaluation description, an incident process. See model cards as regulatory evidence for why the document you already have is usually the right artefact.
- Support for the disclosure itself. If the agency’s citizen-facing surface is your product, the disclaimer and the human-handoff are features you have to build.
The federal analogue is worth reading next: OMB memorandum M-24-10 and the GSA guidance impose a comparable inventory-and-disclosure discipline on federal agencies, and a vendor selling to both will find the questionnaires converging. See the M-24-10 page.
What it does not do
SB 896 creates no private right of action, no penalty schedule and no obligation on any private party as such. It does not prohibit a state agency from using generative AI, it does not require an impact assessment in the sense that Colorado does, and it does not regulate model developers at all — that is SB 53, a separate statute with separate thresholds.
It is also worth being precise about a common misreading. SB 896 is not California’s general AI disclosure law for business. The consumer-facing California duties come from elsewhere: the bot disclosure law SB 1001 for undisclosed bots in commercial and electoral communication, SB 942 for provenance signals on AI-generated content, and the CCPA automated decisionmaking regulations for profiling. Compliance with SB 896 tells you nothing about any of those.
For the same reason, the interesting thing to track here is not the statute but the artefacts it generates: the CDT guidance, the state inventory of AI uses, and the standard contract language. Those change on a cadence the statute does not, and they are what actually lands in a vendor’s inbox.