What happened
In the final weeks of California's 2026 legislative session, lawmakers passed a set of privacy and artificial intelligence bills that would reshape the state's regulatory landscape if signed. Governor Gavin Newsom has until September 30, 2026 to act, and because California has no pocket veto, any measure left unsigned becomes law without his signature.
The most commercially significant is Senate Bill 690. It targets one of the theories behind the wave of California Invasion of Privacy Act litigation, the pen register and trap and trace provision. Rather than amending the prohibition itself, the bill rewrites the civil remedies provision so private plaintiffs cannot sue on that theory for conduct on a website or app, leaving the Attorney General as the sole party able to bring those civil claims. It would apply retroactively to pending claims in actions commenced within two years before the operative date, which on a January 1, 2027 operative date reaches cases filed on or after January 1, 2025.
Two details keep the bill from being a reprieve for tracking practices. It does not decide whether any particular pixel, cookie, analytics service or session replay tool is a pen register, and it does not legalise the underlying conduct or create a safe harbour for specific technologies. The prohibition and its criminal penalty remain in place. Companies lose a litigation exposure, not a compliance obligation.
The package also touches data rights and AI disclosure. Senate Bill 923 would expand the CCPA right to deletion so it covers personal information collected from or about a consumer, regardless of source. Assembly Bill 1542 would generally prohibit businesses, service providers and contractors from selling or sharing sensitive personal information with third parties, subject to narrow exceptions.
On AI, amendments to the California AI Transparency Act would revise obligations for generative AI providers and large online platforms, adding requirements around provenance, verification and disclosure of AI generated or altered content, and would remove the monthly user threshold that some providers have relied on.
Why this is a GRC story
SB 690 changes the economics of a litigation category without changing the substantive rule, which is where internal guidance drifts out of step with the law. A team that relaxes its tracking inventory because the lawsuits stop has read the bill as a permission it does not grant. The Attorney General still has the power to bring claims.
The CCPA amendments reach further into operations. An expanded deletion right and a restriction on sensitive data sharing both depend on knowing where personal information came from and where it flows, so they land on data maps, retention schedules and vendor contracts.
The AI transparency changes put provenance work in front of product and content teams. Disclosure and verification infrastructure becomes a control, and controls need evidence.
What to watch
Watch which measures are signed or vetoed by September 30, then watch how the California Privacy Protection Agency and the Attorney General translate them into regulations and enforcement priorities. Watch also how courts handle the retroactivity provision, which is the provision most likely to be challenged.
Newsom has already signed separate AI auditing requirements and child safety measures covering chatbots and social platforms, so the direction is set regardless of the fate of any single bill. The practical step now is an inventory of tracking technologies and sensitive data flows, before the compliance dates arrive.
Attribution: Analysis based on JD Supra and related public reporting. This article is original commentary, not a repost of the source material.
