Sixteen AI bills, and one of them names the bathroom
Sixteen bills, zero laws, for now
California's legislature closed its 2026 session on August 31, 2026 having passed 16 AI-related bills and 8 privacy bills. None of them are law. Every one of them is sitting on Governor Newsom's desk waiting for a signature, and he has until September 30, 2026 to decide. Each could be signed as written, amended and signed, or vetoed. Until one of those things happens, the correct sentence is "a bill that would do X has passed the legislature," not "California has banned X." That distinction matters enough that we are holding it through the rest of this piece, even where it makes the sentences longer.
The bill built specifically for workplaces
The one most relevant to what DHI does is SB 947, called the No Robo Bosses Act. As passed, it would bar employers from basing a firing or discipline decision solely on an automated decision system's output. It would require human review before that kind of decision, and it would require notifying the worker. It was sponsored by the California Federation of Labor Unions, AFL-CIO, which tells you this bill came out of organizing energy, not a think tank. It passed the Assembly on August 30, 2026 by a vote of 53 to 14, and passed the Senate the next day, August 31, 2026, by a vote of 28 to 10. If signed, it would take effect on July 1, 2027.
Read narrowly, SB 947 governs automated decisions about firing and discipline, not camera-based monitoring on its own. But a camera system that feeds an alert into a workflow that leads to discipline is exactly the kind of system a human-review requirement is aimed at. Any vendor whose output can end up in a personnel file should read this bill as describing the near future of how that output will need to be handled, signed or not.
Three other bills worth knowing by name
AB 1883 would ban AI workplace surveillance that collects neural data. That is a narrow category today, but its existence tells you legislators are already drafting for monitoring technology that goes further than anything currently deployed at scale, which is a useful signal about direction even where it does not touch current products.
AB 1331 would ban workplace surveillance in bathrooms.
SB 813 would establish independent AI verification organizations.
AB 1405 would create an AI Auditor Registry.
Each of those, again: passed the legislature, not yet signed, not yet law.
The bathroom bill is the tell
AB 1331 is worth stopping on, because a legislature does not write "workplace surveillance in bathrooms" as an abstract exercise in coverage. Bills like that get written because a specific case, a specific employer, a specific piece of installed equipment, made it into the room where the bill was drafted. We do not have that story and we are not going to invent one. But the pattern is familiar from every other cycle of monitoring regulation: the rule that sounds most extreme is usually the most literal response to something that already happened. Someone did the thing that everyone in the industry would have said, if asked in advance, was obviously off limits. The bill is the record of that.
That should worry anyone selling monitoring software, including us, more than it should reassure us. A market where one operator can do something like that and trigger legislation covering the whole category is a market where a single customer's bad judgment becomes every vendor's regulatory exposure.
The genuinely new idea in this batch
Most AI legislation restricts what a system can be used for. SB 813 and AB 1405 do something different: they would build institutions. SB 813 would establish independent AI verification organizations. AB 1405 would create a registry of AI auditors. Read together, they describe a world where verifying that an AI system does what its vendor claims is not something the vendor gets to assert on its own website. It becomes a licensed function performed by a third party who answers to a registry, the way a structural engineer's sign-off means something because the engineer is licensed and accountable, not because the building's contractor said the building was safe.
That is a bigger change than any single ban. A ban tells a vendor what it cannot do. A licensed verification function tells a vendor that its claims about what its product does have to survive an audit by someone with no financial interest in the answer.
Where DHI sits in that room
We should say plainly where this points at us. DHI runs a second-stage verification step on its own detections before an alert goes out, specifically to reduce false positives. Under a regime built around SB 813 and AB 1405, exactly that kind of component, a system that decides whether an AI output is trustworthy enough to act on, is the kind of thing that would fall under independent verification and auditor registration. That would be inconvenient. It would mean a claim we currently make about our own accuracy would need to be demonstrated to someone outside the company, on their terms, on their schedule.
We think that inconvenience is close to the actual definition of a rule with teeth. A regulation that only costs money or attention to companies that were never going to comply anyway is not doing much. One that would require us to open our own verification step to an outside auditor is a rule that would change how we operate, which is a reasonable way to tell it apart from the ones that will not.
What this is not
We are not a law firm, and this is not legal advice. We have described what these bills would do if signed as passed, not what they currently require, because right now they require nothing: they are not law. Anyone making a compliance decision based on this piece should talk to counsel and should check the bills' status against the Governor's September 30, 2026 deadline, because that status can change the week this is published.