A Startup’s Guide to AI Governance in California

California now regulates how employers use artificial intelligence to make workplace decisions—and the rules are more specific, and more consequential, than many startup founders realize. In the span of five months, two separate state agencies finalized regulations that together create a dual-track compliance regime for any company deploying AI in employment, operations, or consumer-facing functions. The first set of rules, issued under the Fair Employment and Housing Act (FEHA), took effect on October 1, 2025 and makes clear that algorithmic bias in hiring, promotion, or discipline is actionable employment discrimination. The second, finalized under the California Consumer Privacy Act (CCPA), requires businesses that use automated decision-making technology (ADMT) for significant decisions—including employment decisions—to provide notice, honor opt-out rights, and conduct formal risk assessments, with ADMT compliance required by January 1, 2027.

This guide provides an overview of the regulatory frameworks for startups building products, hiring teams, and scaling operations with AI-powered tools. 

The Regulatory Landscape: Two Agencies, One Message

California’s approach to AI governance is twofold through distinct regulatory channels, each with its own scope, enforcement mechanism, and compliance timeline. Understanding the architecture matters because the obligations overlap but are not identical, and satisfying one does not discharge the other.

FEHA and Algorithmic Discrimination

On June 27, 2025, the California Office of Administrative Law approved final regulations issued by the Civil Rights Council of the California Civil Rights Department (CRD). Effective October 1, 2025, these regulations amend the existing FEHA framework to address the use of automated decision systems (ADS) in employment. An ADS is defined broadly as any computational process—including those derived from AI, machine learning, algorithms, or statistical modeling—that makes or facilitates human decision-making about an employment benefit.

The core principle is straightforward: if an AI tool produces discriminatory outcomes in hiring, promotion, compensation, discipline, or termination, the employer bears liability under FEHA, regardless of whether the employer intended to discriminate. This applies to both disparate treatment and disparate impact claims.  The regulations extend liability to an employer’s “agents,” defined to include staffing agencies, third-party vendors, and any person acting on the employer’s behalf to perform FEHA-regulated activities through an ADS. In practical terms, a startup that purchases an off-the-shelf resume-screening tool cannot outsource its FEHA obligations to the vendor that built it.

A note on the federal landscape: in April 2025, President Trump signed Executive Order 14281, “Restoring Equality of Opportunity and Meritocracy,” which directs federal agencies to deprioritize enforcement of disparate impact liability under Title VII and other federal civil rights statutes. The EEOC has since directed its staff to close pending investigations based solely on disparate impact theories. This executive order, however, does not alter California state law. FEHA’s disparate impact protections are grounded in an independent state statutory framework, and the CRD’s new ADS regulations expressly apply disparate impact analysis to automated employment decisions. Startups operating in California should not assume that the federal enforcement shift diminishes their exposure under state law. California’s regulators and courts retain full authority to pursue and adjudicate disparate impact claims involving ADS.

The regulations also introduce a meaningful evidentiary framework around anti-bias testing. In discrimination claims involving an ADS, courts and enforcement agencies may consider the quality, scope, recency, and results of any bias testing the employer conducted—as well as how the employer responded to the findings. The absence of such testing, conversely, may weigh against the employer. While the regulations do not create an affirmative legal duty to conduct bias audits, the evidentiary weight they carry creates a powerful litigation incentive to do so. Companies considering bias testing should discuss with employment counsel whether to conduct such testing under the protection of attorney-client privilege, which may allow the company to control whether and when testing results are disclosed in litigation. Employers must also retain all ADS-related records—including data inputs, outputs, scoring criteria, and audit results—for a minimum of four years.

The CCPA’s ADMT Rules

Separately, on July 24, 2025, the California Privacy Protection Agency (CPPA) Board adopted final regulations under the CCPA governing automated decision-making technology, privacy risk assessments, and cybersecurity audits. The Office of Administrative Law approved the regulations on September 23, 2025, and they took effect January 1, 2026—with ADMT-specific provisions requiring compliance by January 1, 2027.

The CCPA regulations define ADMT as technology that processes personal information and uses computation to “replace human decision-making or substantially replace human decision-making.” A decision “substantially replaces” human involvement when a business uses the technology’s output to make a decision without meaningful human review, meaning the reviewer knows how to interpret the output, affirmatively analyzes it alongside other relevant information, and has actual authority to change the decision. This is a notably narrower definition than earlier CPPA drafts, which would have captured tools that merely “facilitated” decisions. Startup founders should note, however, that even with the narrowed scope, any AI tool that drives employment, lending, insurance, educational, or healthcare decisions without genuine human override likely falls within the definition.

When ADMT is used for a “significant decision”—a category that includes employment decisions such as hiring, compensation, promotion, and termination—businesses must provide a pre-use notice to consumers (a term that under the CCPA includes employees and applicants), offer an opt-out mechanism, and provide access to information about the ADMT’s logic and how its outputs inform decisions, upon request. Businesses must also conduct written risk assessments before initiating processing activities that pose significant risk to consumer privacy, and to submit annual attestations to the CPPA that those assessments have been completed.

The Legislative Signal: What the No Robo Bosses Veto Tells Startups

On October 13, 2025, Governor Newsom vetoed SB 7, the “No Robo Bosses Act,” which had passed both chambers of the California legislature. The bill would have prohibited employers from relying solely on automated decision systems for discipline, termination, or deactivation decisions, and would have imposed pre-use and post-use notice requirements for any ADS used in employment decisions.

Newsom’s veto letter is worth reading closely. The Governor did not reject the premise that AI in employment requires regulation. Rather, he concluded that SB 7 was “overly broad,” imposing notification obligations on employers using routine tools like basic scheduling software. He also pointed to the CPPA’s forthcoming ADMT regulations as already “partially covering” the territory SB 7 sought to occupy. The message for now is that California intends to regulate AI in the workplace, but through targeted, risk-calibrated rules rather than blanket prohibitions. A revised bill is widely expected in 2026.

For startups, the veto is not a reprieve. It is a signal about regulatory trajectory. The FEHA regulations and CCPA ADMT rules remain fully in force, and the legislature’s willingness to pass SB 7 by wide margins demonstrates sustained political momentum.

Why Governance Matters More for Startups Than for Enterprises

A common misconception among founders is that AI governance is an enterprise concern—something for companies with dedicated compliance teams and regulatory affairs departments. The opposite may be true. Startups face structurally higher governance risk for several reasons.

Speed of adoption outpaces diligence. Startups integrate third-party AI tools rapidly, often selecting vendors based on functionality and cost rather than compliance posture. A resume-screening API, a customer-service chatbot, a performance-analytics dashboard—each may introduce ADS or ADMT into the organization’s operations without anyone recognizing the regulatory implications. Under both the FEHA regulations and the CCPA’s ADMT rules, both the employer and its agents bear liability for ADS-driven discrimination. Under the CCPA’s ADMT rules, the business deploying the technology carries the compliance obligations. In either framework, a startup cannot transfer its legal exposure by contracting with a vendor.

Investor and acquirer scrutiny is increasing. Due diligence processes now routinely probe how a company uses AI, what governance structures exist, and whether the company can demonstrate compliance with applicable regulations. A startup that cannot articulate its AI governance framework—or worse, that has never inventoried the AI tools it uses—creates risk that shows up in valuations, deal terms, and sometimes in whether a transaction closes at all.

Talent expectations have shifted. Engineers, product managers, and data scientists increasingly evaluate prospective employers on responsible AI practices. A startup that treats governance as an afterthought may find it harder to recruit the people it needs to build the product in the first place.

Building a Governance Framework That Works

Effective AI governance does not require a hundred-page policy manual or a new C-suite hire. It requires a structured, repeatable process that matches the company’s current stage and adapts as the company scales. The following elements form the core of a defensible framework.

Internal AI Use Policy

A written AI use policy establishes the organizational ground rules for how AI tools are adopted, deployed, and monitored. At a minimum, the policy should address which roles have authority to procure or deploy AI tools, what approval process applies before an AI system is used in decisions that affect employees or consumers, how employees may and may not use generative AI in their work, and what confidentiality and data-handling obligations apply when interacting with AI systems. The policy need not be lengthy, but it should be specific enough that employees understand the boundaries and leadership can enforce them. A well-drafted AI use policy also signals to investors and regulators that the company takes governance seriously as an operational discipline.

AI Use Inventory

Governance starts with visibility. A startup cannot assess risk it has not identified. An AI use inventory documents every AI or algorithmic tool the company uses, which business functions it supports, whether it was built internally or purchased, what decisions it influences, and what data it processes. Under both the FEHA and CCPA regulatory frameworks, this inventory is the factual foundation of compliance. The FEHA’s four-year record-retention requirement and the CCPA’s risk assessment obligations both depend on the company knowing what AI systems it operates.

Risk and Impact Assessment

Not every AI tool carries the same legal exposure. A chatbot answering product FAQs presents a fundamentally different risk profile than an algorithm that screens job applicants or determines employee compensation. Governance frameworks should classify AI systems by the nature and severity of the decisions they influence, prioritizing systems that affect employment, lending, insurance, education, or healthcare—the categories California’s ADMT regulations identify as “significant decisions.” For employment-related ADS, the FEHA regulations add a further layer: the employer should assess whether the tool’s design, training data, or implementation creates risks of disparate impact on protected classes.

Human Oversight and Accountability

Both the FEHA and CCPA frameworks place a premium on meaningful human involvement in automated decisions. Under the CCPA’s ADMT rules, a decision is only “substantially replacing” human judgment—and thus triggering the full suite of ADMT obligations—if the technology’s output drives the decision without a human reviewer who understands the output, evaluates it alongside other information, and has authority to change the result. Startups that can demonstrate this level of human oversight may narrow their ADMT exposure. But the oversight must be genuine, not performative. A manager who rubber-stamps algorithmic recommendations without independent analysis does not satisfy the standard.

Vendor Due Diligence

The FEHA regulations make explicit what many startups overlook: employer liability for ADS-driven discrimination extends to the employer’s agents, including third-party vendors. A startup that deploys a vendor’s AI hiring tool inherits the discrimination risk embedded in that tool’s training data, model architecture, and validation methodology. Governance frameworks should require, at a minimum, that vendor contracts address how the vendor tested for bias and disparate impact, what ongoing monitoring and retraining protocols exist, how the vendor handles model updates, and what audit rights the startup retains over the tool’s performance and outputs.

Documentation and Continuous Monitoring

California’s regulatory framework rewards companies that document their governance practices and penalizes those that do not. The FEHA regulations allow employers to present anti-bias testing as evidence in discrimination defense—and note that the absence of such evidence may cut the other way. The CCPA’s risk assessment rules require businesses to retain assessments for the longer of the processing activity’s duration or five years after completion. Startups should document risk assessments, bias-testing results, remediation steps, decision-making criteria, and monitoring logs as an ongoing practice. Because these records may become discoverable in litigation, companies should consider conducting bias testing and preparing compliance documentation in coordination with outside counsel under attorney-client privilege. This approach allows the company to build a defensible record while preserving the ability to make strategic decisions about disclosure.

Common Mistakes That Create Exposure

The governance failures that generate the most legal risk for startups tend to follow predictable patterns. AI tools are assumed to be neutral because they are automated. Vendors are assumed to have handled compliance because they are sophisticated. Legal counsel is brought in after a complaint rather than during implementation. Governance is treated as a policy document filed away rather than an operational discipline woven into product development and HR processes.

Perhaps the most consequential mistake is the assumption that compliance with one regulatory framework satisfies all obligations. A startup may conduct a thorough risk assessment under the CCPA’s ADMT rules and conclude that its governance obligations are met. But if the same AI tool is used in hiring decisions, the FEHA regulations impose distinct requirements around anti-bias testing, record retention, reasonable accommodation, and agent liability that the CCPA risk assessment does not address. The two frameworks must be satisfied independently.

AI Governance as Competitive Advantage

For startups inclined to view governance purely as a compliance cost, it is worth considering the alternative framing. In a market where regulators, investors, and customers are all scrutinizing how AI is used, governance is a differentiator. A startup that can demonstrate a rigorous, documented governance framework signals operational maturity that accelerates fundraising conversations, reduces friction in enterprise sales cycles, and positions the company ahead of regulatory deadlines rather than perpetually reacting to them.

The companies that will navigate California’s evolving AI landscape most effectively are those that treat governance not as a set of rules imposed from outside, but as the internal discipline that makes responsible innovation possible.

Considerations for Startups

The compliance timeline is not theoretical. FEHA’s ADS regulations are already in effect. The CCPA’s ADMT rules require compliance by January 1, 2027, with risk assessment obligations that began January 1, 2026. Startups should consider:

  • Conducting a comprehensive AI use inventory that identifies every automated tool deployed across hiring, HR, operations, and customer-facing functions, with particular attention to third-party tools that may qualify as ADS or ADMT under California’s definitions.
  • Adopting a written internal AI use policy that establishes approval processes, permissible uses, and accountability structures before AI tools become deeply embedded in operations
  • Classifying each AI system by risk tier based on the nature of the decisions it influences, prioritizing employment-related tools for immediate FEHA compliance and consumer-facing tools for CCPA ADMT readiness.
  • Engaging employment and privacy counsel to evaluate vendor contracts for adequate bias-testing, transparency, audit, and indemnification provisions—recognizing that both the startup and its vendor may bear regulatory liability under FEHA’s agent provisions.
  • Implementing documented anti-bias testing protocols for any ADS used in employment decisions, ideally under the direction of outside counsel to preserve attorney-client privilege over testing methodology and results, and retaining all related data for a minimum of four years as FEHA requires.
  • Designing meaningful human oversight processes that meet the CCPA’s standard for genuine human involvement—a reviewer who understands the AI output, evaluates it alongside other relevant information, and has actual authority to change the decision.
  • Building a risk assessment framework that satisfies the CCPA’s requirements and can be updated as AI tools evolve, with documentation sufficient to support the annual attestation the CPPA will require.
  • Monitoring legislative developments, including the expected 2026 successor to the vetoed No Robo Bosses Act and the federal administration’s evolving posture on disparate impact enforcement, and adjusting governance practices as the regulatory landscape continues to evolve.

California’s AI regulatory framework is no longer a forecast. It is here, it is specific, and it carries real consequences for startups that are not prepared. The companies that invest in governance now—before a complaint, before a due diligence request, before a regulatory inquiry—will be the ones best positioned to use AI as the competitive advantage it should be.

Grey Ocean Law advises startups and growth-stage companies on AI governance, employment