California transparency law fails to regulate state government use of high-risk automated systems

California's AI law initially reported zero high-risk systems, but a follow-up found at least six. The mandate's reliance on unverified self-reporting exposes major flaws.

Categorized in: AI News Government
Published on: Jul 30, 2026
California transparency law fails to regulate state government use of high-risk automated systems

A California transparency law meant to catalog high-risk automated decision systems used by state agencies initially reported zero such systems. A follow-up inquiry then uncovered at least six systems making consequential decisions about housing, cash assistance, and medical care - a finding that underscores the law's fundamental design flaws.

Assembly Bill 302, signed three years ago, required the state's Department of Technology to publish a yearly inventory of all high-risk automated decision systems proposed or used by any state agency. The department's first report, released in 2025, found no systems that met the threshold. A public records request for the underlying data yielded a single spreadsheet with a column labeled "Is ADS used" and the word 'no' listed for every agency.

The department interviewed a handful of agencies in a subsequent cycle, and that's when six systems came to light. The process depends entirely on agencies self-reporting, with no verification mechanism and no consequences for failing to disclose a tool. The law also contains no clear definition of what qualifies as "high risk." The Department of Technology's report suggests that agencies themselves decide whether a system is reportable, a loophole that leaves the public with an incomplete picture.

The self-reporting problem

AB 302 describes high-risk systems as those that "assist or replace human discretionary decisions that have a legal or similarly significant effect," covering access to housing, education, employment, credit, health care, and criminal justice. Yet known systems like the Uniformity Assessment System, which reduces In-Home Supportive Services for disabled Californians, and the Risk Segmentation, Stratification, and Tier model used to predict Medi-Cal recipients' risk and service underutilization, were not reported. The omission suggests agencies interpret the statute's language narrowly or simply ignore the requirement.

Similar transparency bills have run into the same wall elsewhere. New York's Public Oversight of Surveillance Technology Act was meant to shed light on the NYPD's use of surveillance tech. The police department exploited legal vagueness to avoid scrutiny, describing its own capabilities in terms that undermined meaningful oversight, according to the Brennan Center for Justice. The NYPD's Inspector General and outside groups documented how the department kept technologies like robotic dogs out of the public eye.

"Community control" bills that require police to disclose their own technology have produced similar frustrations. These strategies allow agencies to frame surveillance in favorable terms, creating what University of Washington law professor Ryan Calo calls an anchoring effect: policymakers "fixate on whatever instantiation of technology" proponents "happen to put in front of them."

Transparency entrenches automated systems

The deeper flaw with regulating AI through transparency is that it starts by conceding that state agencies may adopt automated systems. Then it invests in their continued use by building public bureaucracies around their disclosure. Far from serving an oversight function, this approach normalizes and entrenches automated decision-making as a routine part of government operations. The failure of California's transparency law highlights the challenges of AI for Government oversight, where good-faith disclosure rules can be easily sidestepped.

If California wants to regulate high-risk government uses of technology, the conversation cannot end at transparency. AB 302 was an experiment that failed, and now lawmakers need to consider stronger protections that go beyond voluntary reporting.

Why this matters for Government professionals

For professionals inside government agencies, the episode reveals that transparency mandates without enforcement mechanisms are unlikely to produce accurate inventories. The incentives to underreport or classify systems as low-risk are strong, especially when disclosure carries no penalties. Agency leaders and IT staff should expect that external audits and public records requests will eventually surface what self-reporting misses. Building internal practices that treat AI accountability as a core compliance function - not just a checkbox - will become increasingly important as legislative pressure grows. Understanding the limits of transparency-only approaches is a key part of the AI Learning Path for Policy Makers, which covers governance structures that can actually hold agencies accountable.


Get Daily AI News

Your membership also unlocks:

700+ AI Courses
700+ Certifications
Personalized AI Learning Plan
6500+ AI Tools (no Ads)
Daily AI News by job industry (no Ads)