No Result
View All Result
SUBSCRIBE | NO FEES, NO PAYWALLS
MANAGE MY SUBSCRIPTION
NEWSLETTER
Corporate Compliance Insights
  • About
    • About CCI
    • Writing for CCI
    • NEW: CCI Press – Book Publishing
    • Advertise With Us
  • Explore Topics
    • See All Articles
    • Compliance
    • Ethics
    • Risk
    • Artificial Intelligence (AI)
    • FCPA
    • Governance
    • Fraud
    • Internal Audit
    • HR Compliance
    • Cybersecurity
    • Data Privacy
    • Financial Services
    • Well-Being at Work
    • Leadership and Career
    • Opinion
  • The Business of GRC
  • Downloads
    • Download Whitepapers & Reports
    • Download eBooks
  • Research
  • Books
    • CCI Press
    • New: Bribery Beyond Borders: The Story of the Foreign Corrupt Practices Act by Severin Wirz
    • CCI Press & Compliance Bookshelf
    • The Seven Elements Book Club
  • Podcasts
  • Webinars
  • Videos
  • Subscribe
Jump to a Section
  • At the Office
    • Ethics
    • HR Compliance
    • Leadership & Career
    • Well-Being at Work
  • Compliance & Risk
    • Compliance
    • FCPA
    • Fraud
    • Risk
  • Finserv & Audit
    • Financial Services
    • Internal Audit
  • Governance
    • ESG
    • Getting Governance Right
  • Infosec
    • Cybersecurity
    • Data Privacy
  • Opinion
    • Adam Balfour
    • Jim DeLoach
    • Mary Shirley
    • Yan Tougas
No Result
View All Result
Corporate Compliance Insights
Home Compliance

Exploring California’s Generative AI Training Data Transparency Act

AB 2013 obligations are live now, and the practical question is not whether to comply but how much to disclose

by Stephanie Sharron, Marian Waldmann Agarwal & Joshua Fattal
October 5, 2026
in Compliance
data being parsed conceptual illustration

California’s Generative Artificial Intelligence Training Data Transparency Act went into effect in January and got over the first hurdle of a constitutional challenge. Stephanie Sharron, Marian Waldmann Agarwal & Joshua Fattal of Morrison Foerster provide a practical explainer of the law, its implications and enforcement.

California AB 2013 — the Generative Artificial Intelligence Training Data Transparency Act (TDTA) — requires any developer of a generative AI system available to the California public to post on its website documentation about the data used to train that system, covering 12 specified categories. The law took effect Jan. 1, 2026, applies retroactively to systems released or substantially modified since Jan. 1, 2022, and has already survived its first constitutional challenge when a federal court denied xAI’s motion for a preliminary injunction in March.

The statute contains no standalone enforcement provision or penalty structure. Based on the legislative record, though, and specifically the California Assembly Committee on Privacy and Consumer Protection’s legislative analysis, “enforcement will likely occur on the basis of California’s Unfair Competition Law,” enabling both public enforcement by the attorney general and potentially private actions. The legal mechanism is the unfair competition law’s “unlawful prong,” which “borrows” violations of other statutes and makes them independently actionable as unfair competition, even where the predicate statute itself lacks a private right of action.

An important note of clarification: AB 2013 is frequently confused with a different California law, the California AI Transparency Act (CAITA or SB 942, as amended by AB 853). These are distinct statutes. AB 2013 requires disclosure about training data. CAITA requires providers of large generative AI systems to offer AI content detection tools and embed provenance data in AI-generated outputs. 

Statutory definitions 

Artificial Intelligence (§ 3110(a))

Defined as “an engineered or machine-based system that varies in its level of autonomy and that can, for explicit or implicit objectives, infer from the input it receives how to generate outputs that can influence physical or virtual environments.”

Developer (§ 3110(b))

Defined as “a person, partnership, state or local government agency, or corporation that designs, codes, produces, or substantially modifies an artificial intelligence system or service for use by members of the public.” The statute explicitly excludes from “members of the public” any affiliate (as defined in Cal. Civ. Code § 1799.1a(c)(1)(A)) or a hospital’s medical staff member.

This definition has business implications. This definition is notably broad. It is not limited to companies that build foundation models from scratch. Any entity that “substantially modifies” a generative AI system and makes that system available to the public may qualify. Companies that retrain or fine-tune models and deploy them to consumers should carefully evaluate whether they are covered.

Generative AI (§ 3110(c))

Defined as “artificial intelligence that can generate derived synthetic content, such as text, images, video, and audio, that emulates the structure and characteristics of the artificial intelligence’s training data.”

Substantially modifies/substantial modification (§ 3110(d))

Defined as “a new version, new release, or other update to a generative artificial intelligence system or service that materially changes its functionality or performance, including the results of retraining or fine tuning.”

Train (§ 3110(f))

Defined to include “testing, validating, or fine tuning by the developer of the artificial intelligence system or service.” This is broader than the colloquial understanding of “training.” It encompasses the full development pipeline.

Synthetic data generation (§ 3110(e))

Defined as “a process in which seed data are used to create artificial data that have some of the statistical characteristics of the seed data.”

hands raised at meeting
Ethics

AI Governance Frameworks Won’t Save You, but an Ethically Engaged Workforce Might

by Caterina Bulgarella
September 29, 2026

Read moreDetails

12 required disclosure categories

Section 3111 of the TDTA requires developers to post on their website “documentation regarding the data used by the developer to train the generative artificial intelligence system or service, including, but not be limited to” the following categories.

The phrase “including, but not be limited to” signals that the list of 12 categories is not exhaustive and leaves open the possibility that additional disclosures could be required.

Category Statutory language
Sources/owners The sources or owners of the datasets.
Purpose alignment A description of how the datasets further the intended purpose of the artificial intelligence system or service.
Number of data points The number of data points included in the datasets, which may be in general ranges, with estimated figures for dynamic datasets.
Types of data points A description of the types of data points within the datasets. For labeled datasets: the types of labels used. For unlabeled datasets: the general characteristics.
IP status Whether the datasets include any data protected by copyright, trademark or patent, or whether the datasets are entirely in the public domain.
Acquisition method Whether the datasets were purchased or licensed by the developer.
Personal information Whether the datasets include personal information, as defined in subdivision (v) of Section 1798.140 [CCPA].
Aggregate consumer info Whether the datasets include aggregate consumer information, as defined in subdivision (b) of Section 1798.140 [CCPA].
Data processing Whether there was any cleaning, processing, or other modification to the datasets by the developer, including the intended purpose of those efforts.
Collection time period The time period during which the data in the datasets were collected, including a notice if the data collection is ongoing.
First use date The dates the datasets were first used during the development of the artificial intelligence system or service.
Synthetic data Whether the system used or continuously uses synthetic data generation in its development. A developer may describe the functional need or desired purpose of the synthetic data.

Exemptions

Section 3111(b) provides three narrow exemptions. A developer is not required to post documentation for:

  1. Security and integrity systems: A generative AI system “whose sole purpose is to help ensure security and integrity.” The statute cross-references the CCPA definition (Cal. Civ. Code § 1798.140(ac)) but extends its scope from “businesses” to “any developer or user.”
  2. Aircraft operation: A system “whose sole purpose is the operation of aircraft in the national airspace.”
  3. National security/military/defense: A system “developed for national security, military, or defense purposes that is made available only to a federal entity.”

The “sole purpose” qualifier appears to be restrictive, such that a dual-use system that serves both security and commercial functions would not qualify for exemption under the plain text.

Enforcement

The statute text contains no enforcement provision, penalties section or private right of action.

The legislative record, though, indicates enforcement likely would proceed through California’s Unfair Competition Law (UCL), which allows the attorney general and other public prosecutors to bring civil actions and in some cases may also enable private enforcement.

The enforcement gap creates some ambiguity. The law is clearly operative, and non-compliance could trigger UCL claims, but the AG has not signaled enforcement priorities. Actions under the UCL can result in injunctive relief and restitution, so the law is not toothless, but some have argued that the practical enforcement risk may be lower in the near term than the statutory obligations suggest.

In contrast, the CAITA specifies civil penalties of $5,000 per violation, with each day deemed a discrete violation, and prevailing plaintiffs entitlement to attorney’s fees. The TDTA has no such explicit penalty structure.

Practical takeaways

The absence of a defined enforcement mechanism and the undefined “high-level summary” standard create strategic ambiguity that will be resolved through either AG guidance or litigation.

Litigation likely will help shape the constitutional boundaries, and federal preemption developments should be monitored. The Trump Administration’s March 2026 framework recommends preemption but is not enacted law.

The UCL private-action pathway is a litigation risk worth flagging. Although no private actions have been filed under AB 2013 to date, theoretical exposure appears to exist.

Companies that are engaged in designing, developing or substantially modifying models should audit training data provenance. This extends to third-party models that have been substantially modified. The retroactivity to January 2022 makes this harder for companies with incomplete historical records.

Evaluate whether your company qualifies as a “developer” under the statute. Companies that fine-tune open-source or third-party models for public deployment may be in scope.

Tags: Artificial Intelligence (AI)
Previous Post

AI Meeting Assistants Raise Eavesdropping Concerns & Discovery Headaches

Stephanie Sharron, Marian Waldmann Agarwal & Joshua Fattal

Stephanie Sharron, Marian Waldmann Agarwal & Joshua Fattal

Stephanie Sharron is a partner in the Palo Alto office of Morrison Foerster. She represents both private and public companies, from emerging growth through the Fortune 50. For over 25 years, her practice has focused on helping companies that leverage data through technology.
Marian Waldmann Agarwal is a partner in the data, cyber and privacy group at Morrison Foerster. She also co-leads the firm’s AI group and is a member of the global ESG responsible tech committee.
Joshua Fattal is an associate in Morrison Foerster’s Washington, D.C., office, advising clients across industries on data protection best practices, with a focus on emerging issues at the intersection of data privacy, security and new technologies.

Related Posts

ai notetaker robot on zoom call

AI Meeting Assistants Raise Eavesdropping Concerns & Discovery Headaches

by Patrick E. Zeller
October 5, 2026

A federal court has allowed wiretap and privacy claims against an AI notetaker to proceed

data abstract vintage

Company Leaders Wary Over AI-Related Labor Issues

by Staff and Wire Reports
October 1, 2026

Plus: Most companies experienced a cyberattack recently; C-suite rift revealed on business disruption

robot showing records to employees collage

That AI-Drafted Termination Memo Could Become Evidence

by Hekim Colpan and Phillip Wikes
September 29, 2026

AI reproduces subjective phrasing across files, so language that looks neutral in one record can reveal a pattern across a...

hands raised at meeting

AI Governance Frameworks Won’t Save You, but an Ethically Engaged Workforce Might

by Caterina Bulgarella
September 29, 2026

The frameworks and safeguards that make boards feel AI risk is handled usually leave out the one defense that actually...

GGR sq
No Result
View All Result

Privacy Policy | AI Policy

Founded in 2010, CCI is the web’s premier global independent news source for compliance, ethics, risk and information security. 

Got a news tip? Get in touch. Want a weekly round-up in your inbox? Sign up for free. No subscription fees, no paywalls. 

Follow Us

Browse Topics:

  • CCI Press
  • Compliance
  • Compliance Podcasts
  • Cybersecurity
  • Data Privacy
  • eBooks Published by CCI
  • Ethics
  • FCPA
  • Featured
  • Financial Services
  • Fraud
  • Governance
  • GRC Vendor News
  • HR Compliance
  • Internal Audit
  • Leadership and Career
  • On Demand Webinars
  • Opinion
  • Research
  • Resource Library
  • Risk
  • Uncategorized
  • Videos
  • Webinars
  • Well-Being
  • Whitepapers

© 2026 Corporate Compliance Insights

No Result
View All Result
  • About
    • About CCI
    • Writing for CCI
    • NEW: CCI Press – Book Publishing
    • Advertise With Us
  • Explore Topics
    • See All Articles
    • Compliance
    • Ethics
    • Risk
    • Artificial Intelligence (AI)
    • FCPA
    • Governance
    • Fraud
    • Internal Audit
    • HR Compliance
    • Cybersecurity
    • Data Privacy
    • Financial Services
    • Well-Being at Work
    • Leadership and Career
    • Opinion
  • The Business of GRC
  • Downloads
    • Download Whitepapers & Reports
    • Download eBooks
  • Research
  • Books
    • CCI Press
    • New: Bribery Beyond Borders: The Story of the Foreign Corrupt Practices Act by Severin Wirz
    • CCI Press & Compliance Bookshelf
    • The Seven Elements Book Club
  • Podcasts
  • Webinars
  • Videos
  • Subscribe

© 2026 Corporate Compliance Insights