What happened
California Governor Gavin Newsom signed Senate Bill 947 on 30 September 2026. The law, titled Employment: Automated Decision Systems and known as the No Robo Bosses Act, is described as the first of its kind in the United States. It takes effect on 1 July 2027.
The core rule is narrow and specific. An employer may not rely solely on an automated decision system when disciplining or terminating an employee. Where the employer relies primarily on the system's output, a human reviewer must corroborate the proposed decision by examining the data behind it or other supporting material such as supervisory evaluations, personnel files, employee work product, peer reviews or witness interviews. The reviewer has to exercise independent judgement rather than approve what the software produced.
The law also places limits on what these systems may be used for. Employers cannot use one to break labour, employment, occupational health and safety or civil rights law, to infer protected characteristics under the Fair Employment and Housing Act, or to predict whether an employee will exercise a legal right and then take adverse action on that basis. Everyday tools such as spam filters, firewalls, antivirus software and access management systems are excluded from the definition.
Employees gain two rights where a decision relies primarily on the system. They may request a meaningful, factual description of the data used, with personal information about other people anonymised first. They must also receive a stand alone written notice confirming that the system was primarily relied on, that a human reviewed and verified its output, a contact for questions, and a statement that retaliation for exercising these rights is prohibited.
Enforcement sits with the Labor Commissioner, who can issue citations and bring civil suits, and with public prosecutors. Penalties include a civil penalty of 500 dollars per violation, plus potential injunctive relief, punitive damages and legal costs. There is no express private right of action, but the burden of proof shifts to the employer once it is shown that a system was used.
Why this is a GRC story
Human oversight has to be designed, not declared. The law does not ban the tool. It bans rubber stamping, which is what many AI governance policies rely on in practice. If a reviewer cannot point to the evidence they examined and when, the oversight control fails on the facts.
It lands on the HR stack, not on a risk register. The systems in scope are typically bought by HR or embedded in a wider platform, with performance data flowing in from several teams. Mapping where automated outputs touch people decisions is an inventory exercise before it is a legal one.
Notice duties create evidence duties. Specific, timely notices and records showing what the reviewer considered become the audit trail. Without contemporaneous records, compliance is asserted rather than demonstrated.
What to watch
Watch how the Labor Commissioner defines a violation, because the statute does not say whether penalties attach per decision or per affected employee, and that question drives exposure. Watch, too, for how this sits alongside the Fair Employment and Housing Act rules that already require four years of records on automated decision systems, and alongside privacy obligations that continue to apply separately.
Attribution: Analysis based on JD Supra and related public reporting. This article is original commentary, not a repost of the source material.
