Law / United States / California

California

United States law applies in California California is a state of the United States, whose 32 researched instruments are listed on the United States page, not here. The law of California, described on this page below, applies here too.
California has 4 local jurisdictions Each local jurisdiction has law of its own, on a page of its own. All 4 are listed below.

32 of 36 named instruments researched to a stage, across all six areas of law we track: 23 in force, 6 enacted but not yet in force and 3 repealed, withdrawn or blocked. As of 15 September 2026.

When they take effect30 of 32 carry a date, 2 do not. Earlier is before 2017.
Before 2017: 1 instrument (1 in force) earlier 2017: 0 instruments 2018: 0 instruments 2019: 1 instrument (1 in force) 2020: 1 instrument (1 in force) ’20 2021: 0 instruments 2022: 1 instrument (1 in force) 2023: 5 instruments (5 in force) 2024: 3 instruments (3 repealed, withdrawn or blocked) 2025: 3 instruments (3 in force) ’25 2026: 9 instruments (9 in force) 2027: 5 instruments (5 enacted but not yet in force) 2028: 0 instruments 2029: 1 instrument (1 enacted but not yet in force) ’29 today

in forceenacted but not yet in forceproposedrepealed, withdrawn or blockedcourt decision

  1. AI law 12
  2. Privacy law 6
  3. Scraping law 4
  4. Cybersecurity law 2
  5. Age gating law 6
  6. News aggregation law 2

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

AI law12 instruments, 8 in force, 2 enacted but not yet in force, 2 repealed, withdrawn or blocked

Research summary (664 words)

California has the most developed state AI-transparency regime in the country: a bot-disclosure law (SB 1001) has been in force since 2019, with a pending but not yet enacted amendment (AB 410) that would strengthen its disclosure duty and add AI-related definitions, a content-labeling law (SB 942, as amended by AB 853) became operative on 2 August 2026 with duties still phasing in through 2028, and a training-data public-disclosure duty (AB 2013) took effect 1 January 2026.

By contrast, California's two newer election-deepfake statutes have both lost in federal district court in the same case: AB 2839 was permanently enjoined and AB 2655 was struck down as preempted by Section 230, both on 29 August 2025, with the State's appeal pending before the Ninth Circuit as of the date shown (Babylon Bee, LLC v. Bonta, No. 25-6138, briefing complete 11 March 2026, no decision issued).

A third, older election-deepfake statute, AB 730 as extended by AB 972, was not a party to that litigation and remains in force with its sunset now at 1 January 2027. SB 942 is codified at Chapter 25 (commencing with Section 22757) of Division 8 of the Business and Professions Code, running through Section 22757.6, and AB 2013 at Civil Code Sections 3110 and 3111, both confirmed against the Legislature's own leginfo text.

Four further enactments and rulemakings add duties reaching private parties beyond bot and content-labeling disclosure. The Transparency in Frontier Artificial Intelligence Act (SB 53) requires large frontier AI model developers to publish safety frameworks and transparency reports and to report critical safety incidents, effective 1 January 2026.

The Companion Chatbot Safety and Accountability Act (SB 243) requires companion-chatbot operators to disclose that the chatbot is not human and to guard against self-harm content, also effective 1 January 2026. A healthcare-sector disclosure duty (AB 3030) has required generative-AI patient communications to carry an AI disclaimer since 1 January 2025.

The California Privacy Protection Agency's automated-decisionmaking-technology regulations took effect 1 January 2026 and give consumers pre-use notice, opt-out, and access rights against a business's use of ADMT in significant decisions such as credit, housing, employment, education, or healthcare, with full ADMT compliance due 1 January 2027; the Agency's own approved text places this article at Cal. Code Regs. tit. 11, Sections 7200 to 7222, not the 7040-to-7057 range sometimes cited for it.

Two further 2025-2026 measures bind only government actors and are described here rather than as separate instruments: Executive Order N-5-26 (March 30, 2026) directs state agencies to develop AI-vendor certification standards for state contracting, and SB 524 (Penal Code Section 13663) requires a California law enforcement agency's own use of generative AI to draft officer reports to be disclosed and audited, with no duty stated for a private vendor beyond a data-use restriction.

A sixth measure, SB 11, which would have required a consumer warning on AI technology capable of creating a digital replica, was vetoed by the Governor and never took effect; a successor bill on the same subject remained pending in the Legislature as of this review.

California's Civil Rights Council has also adopted employment regulations addressing automated-decision systems (2 Cal. Code Regs. Sections 11008 to 11097, as amended), confirmed to exist and to open with a definitions article at Section 11008 that already treats an employer's use of an automated decision system as an employer function under the Fair Employment and Housing Act, but the balance of that rulemaking's operative text is not reproduced in the available copy of the document and is not otherwise described here.

Two further 2026 enactments, both chaptered 9 September 2026, build the audit layer over all of this rather than adding a duty to any AI system: SB 813 lets the Government Operations Agency designate independent verification organizations and expressly requires nobody to engage one, and AB 1405 bars an unregistered person from offering or conducting a covered AI audit from 1 January 2029 and fixes what an audit report must contain. Neither carries an affirmative defense.

AI governance

AI Auditor Registry Act (AB 1405)

Cal. Gov. Code Sections 11549.80 to 11549.86 (AB 1405, Ch. 178, Stats. 2026)Chaptered bill text, California Legislative Information

In force in 831 days, effective 1 January 2029. Binds private bodies.

What this law does

This chapter regulates AI auditors, meaning any person, partnership, or corporation that assesses an AI system or model on behalf of a third party, and does not impose duties on the AI system's own developer or deployer unless that developer or deployer also offers covered AI audit services to others.

Beginning January 1, 2029, a person may not offer, sell, or conduct a covered AI audit (an audit assessing internal controls, processes, or systems implemented for an AI system or model that are necessary for compliance with state law) unless registered with the Government Operations Agency, which must itself establish the AI Auditor Registry, fix registration fees, and stand up a misconduct-reporting mechanism no later than that same date.

An auditor who registers must give the agency its business name and contact information, a list of the California laws or regulations it audits under, any relevant certifications, a description of its services, and a standard operating procedure describing the standards it applies and the basis for its accuracy and reliability claims; the agency then publishes that registration information, including the list of laws audited under, on its own website.

A registered auditor may not conduct a covered AI audit of a system, process, control, assessment, or other subject matter it materially designed, developed, implemented, or operated for the auditee, and must otherwise maintain independence, objectivity, and competence throughout the engagement.

For each covered audit, the auditor must give the auditee a report covering the audit's scope and objectives, its results and the documentation behind them, each deficiency found and what could reasonably address it, whether the auditee followed its own internal safety standards and protocols within the audit's scope, the audit's limitations and any material gaps in the evidence available, and a signed and dated statement that the audit met this chapter's requirements.

The auditor must retain the information it gave the auditee and the documentation behind its results for at least 10 years, display its registration number on advertising for its audit services, and may not retaliate against an employee who reports suspected noncompliance.

A licensed CPA or accounting firm performing the audit under applicable AICPA and California Board of Accountancy standards is deemed to satisfy the reporting and independence requirements without separately meeting every listed element, and a violation by such an accountant is referred to the California Board of Accountancy rather than handled solely by the agency.

What it requires

Independent Verification Organizations Act (SB 813)

Cal. Gov. Code Sections 8898 to 8898.4 (SB 813, Ch. 179, Stats. 2026)California Legislative Information (leginfo.legislature.ca.gov), chaptered bill text, Ch. 179, Stats. 2026

In force in 100 days, effective 1 January 2027. Binds public and private bodies.

What this law does

SB 813 was chaptered on 9 September 2026 and carries no urgency clause, so it takes effect on 1 January 2027 under California's default operative date.

It directs the California Government Operations Agency to develop, by January 1, 2028, application requirements, suspension and termination procedures, and designation criteria for independent verification organizations (IVOs), private AI auditors the agency designates as qualified to assess the risks posed by an AI system or model, but the chapter does not require any person, partnership, or corporation that develops, deploys, or operates an AI system or model to engage an IVO or undergo a covered AI audit.

A designated IVO must submit an annual report on its standards, methodology, governance, and conflicts of interest to the agency and the Legislature, starting no sooner than 12 months after its designation, and if an audit performed to the chapter's standards is later invoked in a civil action alleging that an AI system or model caused harm, the chapter makes it relevant to, but not conclusive of, that action.

What it requires

Transparency in Frontier Artificial Intelligence Act (SB 53)

Cal. Bus. and Prof. Code Sections 22757.10 to 22757.16official California Legislative Information (leginfo) chaptered bill text

In force 9 months, effective 1 January 2026. Binds private bodies.

What this law does

California's Transparency in Frontier Artificial Intelligence Act (TFAIA) was added by SB 53, chaptered as Stats 2025 Chapter 138, and is effective 1 January 2026 per the code's own history note.

A large frontier developer (a frontier developer whose group had annual gross revenues over $500,000,000 in the preceding year) to write, implement and publish on its website a frontier AI framework describing how it defines and assesses catastrophic-risk thresholds for its frontier models (foundation models trained using more than 10^26 integer or floating-point operations) and applies mitigations, and to review that framework at least annually.

Before or when deploying a new or substantially modified frontier model, every frontier developer must publish a transparency report with baseline model information, and a large frontier developer must add summaries of its catastrophic-risk assessments and any third-party evaluator involvement.

A large frontier developer must also transmit summaries of internal-use catastrophic-risk assessments to the Office of Emergency Services on a quarterly or agreed schedule, and every frontier developer must report a critical safety incident to the Office within 15 days of discovering it, or 24 hours if it poses an imminent risk of death or serious injury.

A frontier developer may not make a materially false or misleading statement about catastrophic risk or, for a large frontier developer, about its framework compliance, and a companion whistleblower chapter (Lab.

Code Section 1107 et seq.) bars a frontier developer from retaliating against a covered employee who reports a reasonable belief of catastrophic-risk danger or a TFAIA violation, arming that employee with a private civil action and attorney's fees, separate from the chapter's own civil penalty which the Attorney General alone may bring.

What it requires

AI risk obligations

CCPA Automated Decisionmaking Technology Regulations

Cal. Code Regs. tit. 11, Sections 7200 to 7222official California Privacy Protection Agency (CPPA) approved rulemaking text

In force 9 months, effective 1 January 2026. Binds private bodies.

What this law does

Article 11 of the California Privacy Protection Agency's CCPA regulations, adopted by the Agency Board on 24 July 2025, approved by the Office of Administrative Law and filed with the Secretary of State on 22 September 2025, and effective 1 January 2026 per the Agency's own regulations page, governs a business's use of automated decisionmaking technology (ADMT) to make a 'significant decision' about a consumer, defined as a decision granting or denying financial or lending services, housing, education enrollment or opportunities, employment or independent-contracting opportunities or compensation, or healthcare services.

A business using ADMT for a significant decision must give consumers a Pre-use Notice describing the use and the consumer's rights to opt out of and access information about that use (Section 7220), must let a consumer opt out of that use except where the business offers an appeal to a human reviewer empowered to overturn the decision or another listed exception applies (Section 7221), and must respond to a consumer's request to access ADMT with a plain-language explanation of the specified information about that use (Section 7222).

A business using ADMT for a significant decision before 1 January 2027 has until that date to come into compliance with this article; a business beginning such use on or after 1 January 2027 must already be in compliance. Confirmed against the Agency's own approved regulation text, which places the automated-decisionmaking-technology article at Sections 7200 to 7222, not the 7040-to-7057 range sometimes cited for it.

What it requires

AI sector rules

Healthcare AI Patient-Communication Disclosure Act (AB 3030)

Cal. Health and Safety Code Section 1339.75official California Legislative Information (leginfo) chaptered bill text

In force since 1 January 2025. Binds public and private bodies.

What this law does

Chapter 2.13 of the Health and Safety Code, added by AB 3030 (Stats.

2024, Ch. 848) and effective 1 January 2025 per the code's own history note, requires a health facility, clinic, physician's office, or office of a group practice that uses generative artificial intelligence to generate written or verbal patient communications about clinical information to include, in each such communication, a disclaimer that it was generated by generative artificial intelligence and clear instructions for reaching a human health care provider.

The disclaimer's placement is format-specific: prominently at the start of a letter or email, displayed throughout an ongoing chat, video, or telehealth interaction, and spoken at the start and end of an audio interaction. Both duties fall away where a licensed or certified human health care provider reads and reviews the AI-generated communication before it is sent.

A violation by a licensed health facility or clinic is enforced through the same licensing-enforcement articles that already govern those facilities, and a violation by a physician falls under the jurisdiction of the Medical Board of California or the Osteopathic Medical Board of California.

The duty reaches a 'health facility' as defined in Health and Safety Code Section 1250, a definition that expressly includes government-operated facilities such as a general acute care hospital operated by the State Department of Developmental Services, the Department of Corrections and Rehabilitation, or the Department of Veterans Affairs, so the duty is not limited to privately owned providers. Confirmed against leginfo's codified text of Section 1339.75.

What it requires

AI training data

Generative AI Training Data Transparency Act (AB 2013)

Cal. Civ. Code Sections 3110 and 3111official California Legislative Information (leginfo) chaptered bill text

In force 9 months, effective 1 January 2026. Binds public and private bodies.

What this law does

A developer of a generative AI system made publicly available to Californians must post on its website, before making the system available and before any substantial modification, documentation describing the training data: a high-level summary of the datasets, their sources and owners, an approximate count and description of data points, whether the data includes copyrighted or personal information, and whether synthetic data generation was used.

The posting duty reaches systems first made publicly available on or after 1 January 2022, though it did not attach until the 1 January 2026 operative date, now past. This corrects the derived citation on record, Civil Code Section 22756 et seq., which does not exist in Civil Code; confirmed against leginfo, the correct codification is Title 15.2 (commencing with Section 3110), Sections 3110 and 3111.

What it requires

AI transparency

AB 2655, Defending Democracy from Deepfake Deception Act

Cal. Elec. Code Sections 20510 to 20520official California Legislative Information (leginfo) chaptered bill text, for the statute

Struck down: invalidated by a court, effective 17 September 2024. Binds private bodies.

What this law does

As enacted, required large online platforms to remove or, in the alternative, label materially deceptive AI-generated content about a candidate or elections official within windows around an election.

The same district judge (Mendez, E.D. Cal.) held this statute preempted by Section 230 of the Communications Decency Act and did not reach the First Amendment question, with final judgment entered 29 August 2025 alongside the AB 2839 ruling; because the holding is preemption-based rather than a discretionary injunction, struck_down is the more precise status than enjoined, though the practical enforcement posture is the same.

The State's appeal is pending in the same Ninth Circuit docket as AB 2839 (No. 25-6138), briefing complete 11 March 2026, no decision issued as of the date shown (14 August 2026). This is litigation-aware status: the statute does not bind today.

What it requires

AB 2839, election materially deceptive deepfake disclaimer law

Cal. Elec. Code Section 20012official California Legislative Information (leginfo) chaptered bill text, for the statute

Enjoined: enforcement paused by a court, effective 17 September 2024. Binds public and private bodies.

What this law does

As enacted, prohibited knowingly distributing, with actual malice, materially deceptive AI-generated election media within specified windows around an election, and required a conspicuous manipulation disclaimer for satire or parody content to qualify for that exemption.

A federal district judge (Senior District Judge John A. Mendez, E.D. Cal.) granted summary judgment for the plaintiffs on First Amendment grounds and permanently enjoined enforcement on 29 August 2025; multiple independent secondary sources (Global Freedom of Expression / Columbia, EPIC's docket summary) consistently describe the injunction as running against enforcement against the named plaintiffs (Kohls, The Babylon Bee, Rumble, X Corp.), not as an explicit facial or statewide bar, though no source reviewed quoted the order's own injunctive-relief paragraph verbatim.

The State's appeal to the Ninth Circuit (Babylon Bee, LLC v. Bonta, No. 25-6138, consolidated with the AB 2655 claims) had briefing complete as of 11 March 2026 with no decision issued as of the date shown (14 August 2026). This is litigation-aware status: the statute does not bind today.

What it requires

AB 730, as extended by AB 972, election deepfake disclosure law

Cal. Elec. Code Section 20010official California Legislative Information (leginfo) chaptered bill text, for AB 730 and its AB 972 sunset extension

In force since 1 January 2020. Binds public and private bodies.

What this law does

Prohibits, with actual malice, distributing materially deceptive audio or visual election media depicting a candidate within 60 days of an election, intending to injure the candidate's reputation or deceive a voter, unless the distributor discloses that the media has been manipulated. AB 972 extended the original 1 January 2023 sunset to 1 January 2027, confirmed against FindLaw's codified-statute history note showing the section added by Stats. 2019, c. 493 (AB 730) and amended by Stats.

2022, c. 745 (AB 972), so the disclosure-exemption structure remains in force. This statute was not a party to the litigation that enjoined AB 2839 or struck down AB 2655. The 1 January 2020 effective date follows the standard non-urgency operative date for a bill approved 3 October 2019, and is independently corroborated by multiple contemporaneous legal-press sources (Davis Wright Tremaine, Akin Gump) describing AB 730 as having taken effect January 1, 2020.

What it requires

Bolstering Online Transparency Act (SB 1001)

Cal. Bus. and Prof. Code Sections 17940 to 17943official California Legislative Information (leginfo) chaptered bill text

In force since 1 July 2019. Binds public and private bodies.

What this law does

Makes it unlawful to use a bot to communicate with a person in California with intent to mislead them about the bot's artificial identity, for the purpose of deceiving them to incentivize a commercial transaction or influence a vote. A safe harbor applies where the bot operator clearly and conspicuously discloses that the user is interacting with a bot.

No enacted amendment, repeal, or litigation affecting this statute was found; AB 410 (2025-2026 session), which would add AI-related definitions and tighten the disclosure duty to require upfront disclosure at first contact, was held under submission in the Senate Appropriations Committee as of 29 August 2025 and carried over to the 2026 session with no further enactment confirmed.

What it requires

California AI Transparency Act (SB 942, as amended by AB 853)

Cal. Bus. and Prof. Code Sections 22757 to 22757.6official California Legislative Information (leginfo) chaptered bill text, both SB 942 and its AB 853 amendment

In force 52 days, effective 2 August 2026. Binds private bodies.

What this law does

A covered provider of a generative AI system must offer a manifest disclosure option (a visible AI-generated content label), embed a latent disclosure of machine-readable provenance data in content it creates, and provide a free public AI-content detection tool. Whether a provider is covered turns on the scale test in the chapter's own definition at section 22757.1(d), recorded on this instrument as its applicability criteria.

AB 853 (2025) moved the operative date from 1 January 2026 to 2 August 2026, now past, and layered on later duties for large online platforms and GenAI hosting platforms effective 1 January 2027, and for capture device manufacturers effective 1 January 2028, neither yet in effect.

Confirmed against leginfo, Chapter 25 (commencing with Section 22757) was added to Division 8 of the Business and Professions Code, with sections running 22757 through 22757.6 (definitions, detection tool, disclosure duties, penalties, exemptions, and operative date). A Section 22756 to 22756.6 range, sometimes cited for this chapter, does not exist.

What it requires

Companion Chatbot Safety and Accountability Act (SB 243)

Cal. Bus. and Prof. Code Sections 22601 to 22606official California Legislative Information (leginfo) chaptered bill text

In force 9 months, effective 1 January 2026. Binds public and private bodies.

What this law does

California's Companion Chatbot Safety and Accountability Act was added by SB 243, chaptered as Stats 2025 Chapter 677, and is effective 1 January 2026 per the code's own history note.

An operator of a companion chatbot platform, one providing an adaptive, human-like AI system capable of sustaining an emotionally or socially engaging relationship across multiple interactions, to issue a clear and conspicuous notification that the companion chatbot is artificially generated and not human whenever a reasonable person interacting with it could be misled otherwise.

An operator may not let a companion chatbot engage with users unless it maintains, and publishes on its website, a protocol for preventing the chatbot from producing suicidal-ideation, suicide, or self-harm content, including a crisis-service referral notification.

For a user the operator knows is a minor, the operator must disclose that the user is interacting with artificial intelligence, provide a break reminder by default at least every three hours, and take reasonable measures to keep the chatbot from producing sexually explicit visual material or urging the minor toward sexually explicit conduct; the operator must also disclose, wherever a user can access the platform, that companion chatbots may not be suitable for some minors.

Beginning 1 July 2027, an operator must report annually to the Office of Suicide Prevention on crisis-referral notifications issued and protocols in place.

A person who suffers injury in fact from a violation may bring a civil action for injunctive relief, the greater of actual damages or $1,000 per violation, and attorney's fees and costs; the chapter excludes bots used only for customer service or internal business purposes, video-game bots limited to game-related replies, and stand-alone voice-command consumer devices that do not sustain a relationship across interactions. Confirmed against leginfo's chaptered bill text.

What it requires

Privacy law6 instruments, 6 in force

Research summary (267 words)

California has no separate comprehensive privacy statute beyond the California Consumer Privacy Act as amended by the California Privacy Rights Act (CCPA/CPRA), which governs private-sector handling of personal information on a notice-and-purpose-limitation model rather than a consent-gated lawful basis, and allocates duties among business, service provider, contractor, and third-party roles.

Biometric information, including both voiceprint and faceprint identifiers, is a category of sensitive personal information carrying a right to limit its use, not a dedicated capture-consent and retention statute like Illinois's Biometric Information Privacy Act (BIPA); the publicly-available exemption expressly does not rescue a biometric identifier collected without the consumer's knowledge, even one derived from an otherwise public recording.

The California Privacy Protection Agency and the Attorney General share administrative enforcement, with a narrow private right of action under section 1798.150 limited to a data breach caused by a business's failure to maintain reasonable security.

The law is under active reform: the CPPA finalized automated decision-making technology regulations in September 2025 (filed under the ai topic per this profile's seam rule, not repeated here), and SB 446 fixed a 30-calendar-day breach notification deadline effective January 1, 2026.

The same rulemaking's cybersecurity-audit article, Cal. Code Regs. tit. 11, Sections 7120 to 7124, is carried here rather than under the ai topic, because it turns on how much personal information a business handles and not on any use of automated decisionmaking.

It requires an annual cybersecurity audit from a qualified, objective and independent auditor, internal or external, with the largest businesses certifying completion to the Agency from 1 April 2028; the audit report itself is retained for five years and is not filed.

Breach notification

California Data Breach Notification Law, as amended by SB 446

Cal. Civ. Code section 1798.82, as amended by SB 446 (2025, Ch. 319)Official codified statute text, California Legislative Information (leginfo.legislature.ca.gov)

In force 9 months, effective 1 January 2026. Binds private bodies.

What this law does

Requires a business that owns or licenses computerized personal information of a California resident to notify that resident on discovery or notification of a security breach. As amended by SB 446 (signed October 3, 2025), the statute now fixes that duty at 30 calendar days, replacing the prior open-ended most-expedient-time-possible standard, and requires notice to the Attorney General within 15 days of consumer notification where a breach affects more than 500 California residents.

What it requires

Comprehensive regime

CCPA Cybersecurity Audit Regulations

Cal. Code Regs. tit. 11, Sections 7120 to 7124official California Privacy Protection Agency (CPPA) approved rulemaking text

In force 9 months, effective 1 January 2026. Binds private bodies.

What this law does

Article 9 of the California Privacy Protection Agency's CCPA regulations, adopted by the Agency Board on July 24, 2025 and effective January 1, 2026, requires a business whose processing of personal information meets the CCPA's revenue-from-data-sales threshold, or its revenue threshold combined with processing the personal information of 250,000 or more consumers or households or the sensitive personal information of 50,000 or more consumers in the preceding calendar year, to complete a cybersecurity audit using a qualified, independent auditor, who may be internal or external to the business, and to submit a written certification of that completion to the Agency each year by April 1.

The underlying audit report is not filed with the Agency; the business and auditor must retain it for five years, and it goes only to an executive with direct responsibility for the cybersecurity program.

First certifications are due on a staggered schedule starting April 1, 2028 for businesses with 2026 annual gross revenue over $100 million, then April 1, 2029 for the $50 million to $100 million tier, and April 1, 2030 for smaller covered businesses, after which every covered business audits and certifies annually.

What it requires

California Consumer Privacy Act, as amended by the California Privacy Rights Act (Proposition 24)

Cal. Civ. Code section 1798.100 et seq. (CCPA, as amended by the CPRA)Official codified statute text, California Legislative Information (leginfo.legislature.ca.gov)

In force since 1 January 2020, effective 1 January 2023. Binds private bodies.

What this law does

Governs private-sector for-profit businesses that meet the CCPA's revenue or data-volume threshold and determine the purposes and means of processing a California consumer's personal information. Duties run on a notice-and-purpose-limitation model rather than a consent-gated lawful basis, and are allocated among four defined roles: business, service provider, contractor, and third party.

The original CCPA (AB 375) became operative January 1, 2020; the California Privacy Rights Act (Proposition 24) substantially expanded it, and the amended law now in force became operative January 1, 2023. AB 1008 (2024) separately expanded the personal-information definition to reach data held in AI systems capable of outputting it.

What it requires

Data subject rights

CCPA/CPRA Consumer Rights: Access, Deletion, Correction, and Opt-Out

Cal. Civ. Code sections 1798.100, 1798.105, 1798.106, 1798.110, 1798.115, 1798.120, 1798.125, 1798.130Official codified statute text, California Legislative Information (leginfo.legislature.ca.gov)

In force since 1 January 2020, effective 1 January 2023. Binds private bodies.

What this law does

Gives California consumers the right to know and access what personal information a business holds and its source, the right to delete it, the right to correct it, a right to a portable copy, and the right to opt out of the sale or sharing of their personal information to third parties, all exercisable against the business rather than directly against its service providers or contractors. A business may not discriminate against a consumer for exercising these rights.

What it requires

Enforcement supervision

CCPA/CPRA Enforcement: California Privacy Protection Agency and Private Right of Action

Cal. Civ. Code sections 1798.150, 1798.155, 1798.199.10, 1798.199.90Official codified statute text, California Legislative Information (leginfo.legislature.ca.gov)

In force since 1 July 2023. Binds private bodies.

What this law does

The California Privacy Protection Agency, which assumed enforcement authority July 1, 2023, and the Attorney General share administrative enforcement of the CCPA/CPRA, with civil penalties currently up to $2,663 per violation or $7,988 per intentional violation or one involving a consumer known to be under 16, inflation-adjusted for 2025 under a streamlined adjustment mechanism AB 3286 (2024) put in place.

There is no general private right of action for a CCPA violation; a narrow one exists only under section 1798.150 for a business's failure to maintain reasonable security resulting in a breach of unencrypted, unredacted personal information, carrying statutory damages of $100 to $750 per consumer per incident and a 30-day cure notice that does not excuse a breach already suffered.

What it requires

Sensitive categories

CCPA/CPRA Sensitive Personal Information and Biometric Data

Cal. Civ. Code section 1798.140(c), (ae); section 1798.121Official codified statute text, California Legislative Information (leginfo.legislature.ca.gov)

In force since 1 January 2023. Binds private bodies.

What this law does

Defines biometric information to expressly include faceprints extracted from facial imagery and voiceprints extracted from voice recordings, with no exclusion for an identifier derived from a recording, and classifies biometric information processed to uniquely identify a consumer as sensitive personal information. A consumer may direct a business to limit use of sensitive personal information, including biometric information, to what is necessary to provide the requested goods or services.

California has no dedicated biometric capture-consent or retention-and-destruction statute comparable to Illinois's Biometric Information Privacy Act (BIPA); biometric data is regulated only as a CCPA sensitive-information category, and the CCPA's private right of action does not reach this provision.

What it requires

Scraping law4 instruments, 4 in force

Research summary (249 words)

California diverges from federal scraping law chiefly on personal data and AI training-data transparency, both worth their own instruments here. The Comprehensive Computer Data Access and Fraud Act reads without permission more broadly than the federal Computer Fraud and Abuse Act (CFAA)'s without authorization, with no threshold requirement that the initial access itself be unauthorized, but California courts apply the same revocation logic once a cease-and-desist and a technical block are in place.

The CCPA's publicly-available exemption is narrower than it looks: it keys to the consumer's own act or a government source, so personal data scraped from a third party's page the consumer did not control is not automatically publicly available, and it expressly excludes biometric information collected without the consumer's knowledge.

AB 2013 is California's dedicated training-data-transparency instrument, requiring generative-AI developers to publicly document their datasets' sourcing; its citation in the older corpus was wrong (Bus. & Prof. Code, not Civil Code) and is corrected here to Civ. Code §§ 3110-3111 against the chaptered bill text.

AB 1008 amended the CCPA's personal-information format list and added a biometric carve-out, but contains no scraping-specific clause; an earlier claim that it exempts automated mass extraction from publicly-available status is not supported by its enacted text and is not repeated here. Trespass to chattels is narrower in California than the earlier federal-district trend: Intel v. Hamidi requires actual damage to or impairment of the system, not mere unwanted access. Copyright and database rights add nothing beyond the federal position already covered in the national document.

Computer misuse

Comprehensive Computer Data Access and Fraud Act (unauthorized access, broader than the federal without-authorization test)

Cal. Penal Code § 502official text, California Legislative Information (leginfo.legislature.ca.gov)

In force. Binds public and private bodies.

What this law does

Section 502(c) criminalizes knowing access without permission, textually broader than the federal Computer Fraud and Abuse Act (CFAA)'s without authorization because it carries no threshold requirement that the initial access itself be unauthorized. Facebook v. Power Ventures (844 F.3d 1058, 9th Cir. 2016) held a scraper's originally-permitted access did not violate this section, but access became without permission once Facebook sent a cease-and-desist and IP-blocked the scraper and it continued anyway.

Craigslist v. 3Taps (964 F. Supp. 2d 1178, N.D. Cal. 2013) held a cease-and-desist letter plus an IP block are sufficient notice, so circumventing the block after notice states a claim under this section. The current section was added by Stats.

1987, ch. 1499 (a legislative-history research service confirms this against the annotated statutory history), but leginfo.legislature.ca.gov's own code page carries only the most recent amendment note, not the full history back to 1987, and no located session-law or secondary source pins the specific operative date, which turns on whether the 90-day constitutional waiting period from enactment ran past January 1, 1988 (in which case the section commenced January 1, 1989 instead). The commencement date is left unset rather than guessed between those two candidates.

What it requires

Crawl signals

AI Training Data Transparency Act (AB 2013)

Cal. Civ. Code §§ 3110-3111 (AB 2013, Ch. 817, Statutes of 2024)official chaptered bill text, California Legislative Information (leginfo.legislature.ca.gov)

In force 9 months, effective 1 January 2026. Binds public and private bodies.

What this law does

AB 2013 requires developers of generative AI systems made available to Californians, released or substantially modified since January 1, 2022, to publicly post documentation of their training datasets, including whether the datasets include data protected by copyright, trademark, or patent, and whether they include personal information as defined in Civ. Code § 1798.140. The duty commences January 1, 2026 and repeats before each subsequent release or substantial modification.

The corpus previously carried this instrument's citation as Bus. & Prof. Code §§ 22756.9-22757.1; the chaptered bill text confirms AB 2013 in fact adds Title 15.2 (commencing with Section 3110) to Part 4 of Division 3 of the Civil Code, chaptered September 28, 2024 as Chapter 817, Statutes of 2024, and that correction is reflected here. A federal district court denied a preliminary injunction against enforcement in X.AI LLC v. Bonta (C.D. Cal., Mar.

4, 2026, secondary-sourced), finding no likelihood of success on trade-secret or constitutional claims without reaching the law's ultimate validity, so the law remains in effect subject to that ongoing litigation.

What it requires

Personal data

California Consumer Privacy Act, publicly-available-information exemption (as amended by AB 1008)

Cal. Civ. Code § 1798.140(v)official text, California Legislative Information (leginfo.legislature.ca.gov)

In force since 1 January 2025. Binds private bodies.

What this law does

Section 1798.140(v) defines publicly available narrowly: lawfully available government records, information a business has a reasonable basis to believe the consumer themselves lawfully made available to the public or through widely distributed media, or information made available by a person to whom the consumer disclosed it without restricting the audience, and it expressly excludes biometric information a business collected about a consumer without the consumer's knowledge.

Because the exemption keys to the consumer's own act or a government source, personal data scraped from an aggregator, directory site, or re-poster the consumer did not control is not automatically publicly available, so a scraper meeting CCPA's revenue or volume thresholds becomes a regulated business over that data.

AB 1008 (2024) amended this section to add AI systems capable of outputting personal information to the list of formats personal information can take, and added the biometric carve-out; its enacted text contains no clause addressing automated mass extraction or web scraping by name, and a claim that it does is unsupported and is not carried here.

What it requires

Unfair competition

Unfair Competition Law (predicate vehicle for scraping claims)

Cal. Bus. & Prof. Code § 17200official text, California Legislative Information (leginfo.legislature.ca.gov)

In force. Binds private bodies.

What this law does

Section 17200 reaches any unlawful, unfair, or fraudulent business act or practice, is broader than the federal FTC Act because it carries a private right of action, borrows violations of any other law under its unlawful prong, and has no interstate-commerce gate. It is the standard vehicle for scraping-adjacent claims in California, including hiQ Labs' eventual state-law liability alongside trespass to chattels once its Computer Fraud and Abuse Act (CFAA) win did not resolve the dispute.

Trespass to chattels itself is narrower in California than the earlier federal-district trend: Intel Corp. v. Hamidi (30 Cal. 4th 1342, 2003) requires actual damage to, or impairment of the functioning of, the computer system, so an unwanted crawl causing no measurable server harm is not trespass to chattels under California law. Section 17200 was added by Stats.

1977, ch. 299, which moved the former Civil Code § 3369 unfair-competition provisions into the Business and Professions Code; a contemporaneous law review article and a legislative-history research service both confirm the citation, but neither leginfo.legislature.ca.gov nor any other located source carries the chapter's specific operative date, so the commencement date is left unset rather than assumed from California's general January-1-following-enactment default.

What it requires

Cybersecurity law2 instruments, 2 in force

Research summary (569 words)

California's product-security and cyber-resilience posture rests on two enacted state statutes, layered over the federal-level regimes already researched as this jurisdiction's national row and not repeated here.

Civil Code sections 1798.91.04 through 1798.91.06 (Title 1.81.26, Security of Connected Devices, added in 2018 by identical companion bills AB 1906 and SB 327, operative since January 1, 2020, and amended by AB 2392 (2022) to add a NIST-conforming labeling scheme safe harbor, effective January 1, 2023) require a manufacturer of a connected device, a device or other physical object capable of connecting to the internet, directly or indirectly, and assigned an internet protocol or Bluetooth address, sold or offered for sale in California, to equip the device with a reasonable security feature appropriate to its nature, function, and the information it may handle.

The duty reaches the device's own hardware, firmware, and pre-installed software, but the statute expressly disclaims any duty over unaffiliated third-party software or apps a user chooses to add, and over an app store's or marketplace's review of compliance, so it does not by itself reach a developer who publishes only an app or other software with no connected device of its own.

Civil Code section 1798.81.5, as amended by AB 825 (2021) and effective January 1, 2022, requires a business that owns, licenses, or maintains personal information about a California resident, and by contract any nonaffiliated third party the business discloses that information to, to implement and maintain reasonable security procedures and practices appropriate to the nature of the information; it exempts a health care provider or plan already regulated by the Confidentiality of Medical Information Act, a financial institution subject to the California Financial Information Privacy Act, a Health Insurance Portability and Accountability Act (HIPAA) covered entity as to HIPAA-regulated activity, and a business already subject to state or federal law that provides greater protection on the same subject, deemed compliant with this duty instead.

Civil Code section 1798.84(b), within the same Customer Records title as section 1798.81.5, gives a customer injured by a violation of that title, the reasonable-security duty included, a civil action to recover damages, with no statutory cap of its own; the $500 to $3,000 per-violation civil penalty in section 1798.84(c) is scoped by its own text to a violation of section 1798.83's separate Shine the Light disclosure duty and does not reach a violation of the reasonable-security duty.

The connected-device statute creates no private right of action of its own; the Attorney General, a city attorney, a county counsel, or a district attorney have the exclusive authority to enforce it.

No California cyber-resilience regime binding a class of entity by sector, criticality, or size, comparable to NIS2 or DORA, was located that reaches a digital service this corpus can currently flag against; section 1798.81.5(e)(2) itself points to the California Financial Information Privacy Act (Financial Code section 4050 et seq.) as governing a financial institution's handling of the same information instead, not independently researched here.

California's data-breach notification duty, Civil Code section 1798.82 as amended by SB 446 (2025), and the CCPA/CPRA's own statutory-damages private right of action for a breach of nonencrypted or nonredacted personal information caused by a failure to implement reasonable security, Civil Code section 1798.150, are both already this jurisdiction's privacy row rather than repeated here: the breach-notice duty and the section 1798.150 remedy attach to the exposure of personal data, while the reasonable-security duty they both build on is the security-baseline instrument below.

Product security requirements

Security of Connected Devices

Cal. Civ. Code sections 1798.91.04-1798.91.06 (Title 1.81.26, added by Stats. 2018, Ch. 860 (AB 1906) and Ch. 886 (SB 327); sections 1798.91.04 and 1798.91.05 amended by Stats. 2022, Ch. 785 (AB 2392))Official statute text, California Legislative Information, Civil Code Title 1.81.26

In force since 1 January 2023. Binds private bodies.

What this law does

A manufacturer of a connected device, any device or other physical object capable of connecting to the internet, directly or indirectly, and assigned an internet protocol or Bluetooth address, that is sold or offered for sale in California, must equip the device with a reasonable security feature or features appropriate to the device's nature and function and to the information it may collect, contain, or transmit, designed to protect the device and any information in it from unauthorized access, destruction, use, modification, or disclosure.

Where a connected device authenticates outside a local area network, the statute deems that duty met if the device's preprogrammed password is unique to each unit manufactured, or the device requires the user to generate a new means of authentication before first use; a manufacturer may instead satisfy the duty by meeting or exceeding the baseline criteria of a NIST-conforming Internet of Things cybersecurity labeling scheme and completing that scheme's conformity assessment.

The duty does not reach unaffiliated third-party software or applications a user chooses to add to someone else's connected device. It also imposes no duty on an app store, gateway, or marketplace to review or enforce compliance, nor on the manufacturer to prevent a user from modifying the device's own software or firmware. The title does not apply to a connected device already subject to security requirements under federal law, regulation, or federal agency guidance.

It also does not apply to a covered entity, health care provider, health plan, business associate, contractor, or employer as to an activity already regulated by Health Insurance Portability and Accountability Act (HIPAA) or California's Confidentiality of Medical Information Act. The statute creates no private right of action; the Attorney General, a city attorney, a county counsel, or a district attorney have the exclusive authority to enforce it, and the statute names no penalty amount of its own.

What it requires

Security baseline statutes

Customer Records Act, Reasonable Security Procedures

Cal. Civ. Code section 1798.81.5, as amended by AB 825 (2021, Ch. 527)Official statute text, California Legislative Information, Civil Code Title 1.81

In force since 1 January 2022. Binds private bodies.

What this law does

A business that owns, licenses, or maintains personal information about a California resident must implement and maintain reasonable security procedures and practices appropriate to the nature of the information, to protect it from unauthorized access, destruction, use, modification, or disclosure; where the business instead discloses that information to a nonaffiliated third party by contract, it must require the same standard of the third party by contract.

Covered personal information reaches a California resident's name paired with a Social Security, driver's license, state identification, passport, military identification, or tax identification number, a financial account or payment card number together with its access code, medical information, health insurance information, unique biometric data used to authenticate a specific individual, genetic data, or a username or email address paired with a password or security question that would permit access to an online account.

The duty exempts a health care provider, health plan, or contractor already regulated by the Confidentiality of Medical Information Act, a financial institution subject to the California Financial Information Privacy Act, a Health Insurance Portability and Accountability Act (HIPAA) covered entity as to HIPAA-regulated medical privacy and security rules, an entity receiving Vehicle Code confidentiality-protected information, and a business already subject to state or federal law that provides greater protection to personal information on the same subject, which is deemed compliant instead.

Civil Code section 1798.84(b), within the same Customer Records title, gives a customer injured by a violation of this duty a civil action to recover damages, with no statutory cap of its own. The $500 to $3,000 per-violation civil penalty that section 1798.84(c) provides is reserved, by its own terms, for a violation of section 1798.83's Shine the Light disclosure duty rather than a violation of this section.

Where the violation is a breach of nonencrypted or nonredacted personal information, the CCPA/CPRA's own statutory-damages private right of action, Civil Code section 1798.150, is a further and separate remedy, already researched as this jurisdiction's privacy row.

What it requires

Age gating law6 instruments, 1 in force, 4 enacted but not yet in force, 1 repealed, withdrawn or blocked

Research summary (233 words)

California has enacted six major age-gating and minor online safety statutes. The Age-Appropriate Design Code Act (AB 2273, 2022) remains substantially enjoined after a March 2026 Ninth Circuit ruling that left its data protection impact assessment requirement enjoined, upheld the injunction on its data use and dark patterns provisions on vagueness grounds, and lifted the injunction on its coverage definition and age estimation requirement while remanding for further severability analysis.

The Protecting Our Kids from Social Media Addiction Act (SB 976, 2024) is largely in effect after a September 2025 Ninth Circuit ruling, except for its default setting that hides like and share counts, which the court ordered enjoined; its age verification component does not take effect until 2027.

The Digital Age Assurance Act (AB 1043, 2025) requires device level age signals starting January 1, 2027, and AB 56 (2025) requires mental health warning labels for users under 18 on addictive platforms starting the same day.

AB 1709 (2026), barring addictive feed and autoplay features for users under 16, and AB 1856 (2026), which amends the Digital Age Assurance Act's operating system and application store duties rather than extending them to browsers or websites, were both signed September 10, 2026 as Chapters 183 and 184, Statutes of 2026, effective January 1, 2027. California has no adult content age verification law in effect; a 2024 attempt, AB 3080, died in the Senate Appropriations Committee.

Age-appropriate design code

AB 2273 (2022), California Age-Appropriate Design Code Act

Cal. Civ. Code §§ 1798.99.28-1798.99.40official Civil Code text and the Ninth Circuit's opinion in NetChoice, LLC v. Bonta

Enjoined: enforcement paused by a court, effective 1 July 2024. Binds private bodies.

What this law does

Requires businesses providing an online service, product, or feature likely to be accessed by children under 18 to complete data protection impact assessments, configure default settings for high privacy and safety, and avoid dark patterns and profiling of minors.

Note and primary source

App store age verification (AV)

AB 1043 (2025), Digital Age Assurance Act

Cal. Civ. Code §§ 1798.500-1798.505official Civil Code text, chaptered bill

In force in 100 days, effective 1 January 2027. Binds private bodies.

What this law does

Requires operating system providers to ask account holders for a birth date or age at device setup and to send a real time age bracket signal (under 13, 13 to under 16, 16 to under 18, or 18 and older) to app developers, without requiring government ID or biometric data.

Note and primary source

AB 1856 (2026), Digital Age Assurance Act amendments (operating systems and application stores)

2026 Cal. Stats. ch. 184 (AB 1856), amending Cal. Civ. Code §§ 1798.500-1798.504official chaptered bill text, California Legislative Information

In force in 100 days, effective 1 January 2027. Binds private bodies.

What this law does

AB 1856, enacted as 2026 Cal. Stats. ch. 184, amends the Digital Age Assurance Act (Civil Code Sections 1798.500 to 1798.504) rather than extending it to browsers or websites: it applies the age-signal duty to any operating system that operates on a device and has an account setup feature, removes the prior definition tying the protected 'user' to a child, and requires the signal be sent to a covered application store or to an application developer.

A developer must request a signal when an application is downloaded and launched, must treat the signal as the primary indicator of a user's age absent clear and convincing contrary information, and may not request more information than the minimum needed; nobody may request a signal unless required by this title or other applicable law.

For a device or application already set up or downloaded before January 1, 2027, the operating system provider or developer must request or provide the signal by July 1, 2027.

The Act carries forward the Digital Age Assurance Act's existing Attorney General civil enforcement (up to $2,500 per affected child for a negligent violation or $7,500 for an intentional violation) and adds good faith compliance defenses and a nondiscrimination duty barring an operating system or application store from using compliance data anticompetitively. Approved by the Governor and chaptered September 10, 2026, effective January 1, 2027.

Note and primary source

Social media and minors

AB 1709 (2026), minimum age for addictive social media features

2026 Cal. Stats. ch. 183 (AB 1709), adding Bus. & Prof. Code ch. 22.9 (§ 22682 et seq.) and Gov. Code ch. 5.4 (§ 11530 et seq.)official chaptered bill text, California Legislative Information

In force in 100 days, effective 1 January 2027. Binds private bodies.

What this law does

Bars users under 16 from accessing addictive feeds, autoplay, and similar engagement features on covered platforms, using age determinations from the Digital Age Assurance Act or Health and Safety Code Section 27001, and creates an e-Safety Advisory Commission within the Department of Justice. Passed the Assembly and Senate, was enrolled and presented to the Governor on September 9, 2026, and was approved and chaptered as Chapter 183, Statutes of 2026 on September 10, 2026.

Note and primary source

AB 56 (2025), social media warning labels for minors

Cal. Health & Safety Code §§ 28000-28002official Health and Safety Code text, chaptered bill

In force in 100 days, effective 1 January 2027. Binds private bodies.

What this law does

Requires covered addictive platforms to display a prescribed black box warning, attributed to the Surgeon General, to users under 18: for at least 10 seconds covering at least 25 percent of the screen on first daily access, and for at least 30 seconds covering at least 75 percent of the screen after 3 hours of cumulative daily use and each hour thereafter. Approved by the Governor October 13, 2025; operative January 1, 2027.

Note and primary source

SB 976 (2024), Protecting Our Kids from Social Media Addiction Act

Cal. Health & Safety Code §§ 27000-27007official Health and Safety Code text and the Ninth Circuit's opinion in NetChoice, LLC v. Bonta

In force since 1 January 2025. Binds private bodies.

What this law does

Bars addictive feeds, most nighttime and school hour notifications, and non default privacy settings for users a platform knows are minors, without verifiable parental consent. A separate age verification requirement is not effective until January 1, 2027.

Note and primary source

News aggregation law2 instruments, 2 in force

Research summary (274 words)

California has no enacted statute creating an EU-style press-publisher right or mandatory platform-to-publisher bargaining code.

The California Journalism Preservation Act (AB 886, 2023-2024) would have imposed journalism usage fees on large digital platforms for accessing California news content, but died in the California Senate on November 30, 2024 after Governor Newsom, the Legislature, and Google reached a voluntary News Transformation Fund agreement providing approximately $250 million over five years to California newsrooms.

A central legal obstacle to AB 886 was federal Copyright Act §301 preemption: because article snippets and headlines fall within the subject matter of copyright, a state law granting publishers equivalent exclusive payment rights risks displacement by federal law, a risk Assemblymember Wicks publicly cited when accepting the voluntary deal over years of likely litigation.

California recognizes a common-law misappropriation (hot-news) doctrine under Balboa Insurance Co. v. Trans Global Equities (Cal. Ct. App. 1990), but federal preemption under §301 has substantially narrowed it for copyrightable news content, and the Ninth Circuit has confirmed that inline linking and embedding generally do not infringe display rights.

For AI training data, AB 2013 (2024, effective January 1, 2026) requires generative AI developers to disclose training-data sources including copyrighted material, creating indirect transparency pressure on news-content scraping, though a December 2025 federal executive order created uncertainty about its enforceability.

In place of the failed bill, a voluntary non-statutory arrangement announced 21 August 2024 established a News Transformation Fund of roughly $125 million over five years (Google contributing at least $55 million and California $70 million), administered by UC Berkeley's journalism school. It creates no legal obligation and is recorded here as context, not as an instrument.

Hot news misappropriation

Balboa Insurance Co. v. Trans Global Equities

Balboa Ins. Co. v. Trans Global Equities, 218 Cal.App.3d 1327 (Cal. Ct. App. 1990)CourtListener full-text mirror of 218 Cal.App.3d 1327 (this instrument's url)

Decided 21 March 1990 by the California Court of Appeal. Binds public and private bodies.

What this court held

California Court of Appeal decision establishing the state's common-law misappropriation doctrine, requiring a plaintiff to show: (1) substantial investment of time and money in developing an intangible asset; (2) defendant's appropriation at little or no cost; and (3) resulting injury to plaintiff.

This doctrine underpins California hot-news misappropriation claims for time-sensitive news content, but its scope is substantially curtailed by 17 U.S.C. §301 federal copyright preemption whenever the misappropriated material falls within the subject matter of copyright, leaving only a narrow residual category for facts or time-sensitive information not themselves independently copyrightable.

Note and primary source

Text and data mining (TDM) opt-out

Generative Artificial Intelligence Training Data Transparency Act (AB 2013)

Cal. Assemb. B. 2013, 2023-2024 Reg. Sess. (chaptered Sept. 28, 2024)California Legislature

In force 9 months, effective 1 January 2026. Binds public and private bodies.

What this law does

Signed September 28, 2024, this law requires developers of generative AI systems to publish on their websites summaries of training data used, disclosing copyright status, data ownership, and whether personal information or third-party copyrighted content (including news) was included; compliance required by January 1, 2026. The law does not grant publishers an explicit opt-out or compensation right but creates de facto disclosure pressure on AI developers who scraped news content for training.

A December 2025 federal executive order directed review of state AI regulations for conflict with federal policy, creating some enforceability uncertainty.

Note and primary source

Law in local jurisdictions4 with pages

Each has a page of its own; the number is how many of its instruments are researched to a stage.

This page covers the instruments LexLint has researched to a stage. Instruments named in the corpus but not yet researched are counted in the head and are not listed here. Every entry carries its own primary source on its note page. This is a research index, not legal advice.