Home About Who We Are Team Services Startups Businesses Enterprise Case Studies Industries Commercial Real Estate Blog Guides Contact Connect with Us
Back to Guides
Legal Services 14 min read

An AI Use Policy for California Employers: The Eight Clauses That Matter

An AI Use Policy for California Employers: The Eight Clauses That Matter

Most California small businesses that use ChatGPT, Claude, or Copilot at work have no written policy governing how. That gap used to be low-risk. It stopped being low-risk on October 1, 2025, when the Civil Rights Council’s automated-decision-system (ADS) regulations took effect under the Fair Employment and Housing Act (FEHA), and it gets tighter on January 1, 2027, when the state’s automated decisionmaking technology (ADMT) rules kick in under the California Consumer Privacy Act (CCPA). A written policy is now the cheapest insurance a 5-50 person employer can buy against both. Here are the eight clauses that policy needs, and the specific rule each one answers to.

Why a written policy matters now, not eventually

A policy does two jobs. It tells employees what they can and cannot do with an AI tool, and it gives the business a paper trail if a regulator, a client, or a rejected job applicant ever asks how a decision got made. Without one, both answers default to “whatever the last person who used the tool decided,” a position nobody wants to defend.

The timing is not theoretical. The Civil Rights Council’s regulations already apply to any California employer with five or more employees. They cover automated tools used in hiring, promotion, or discipline, and they require employment records, including the data behind an automated decision, to be kept for a minimum of four years. A business with no policy has nothing to point to when asked what its process was.

The two rulesets a policy has to answer to

Two California rulesets do the heavy lifting here, and a policy should name both by date so it does not go stale.

The Civil Rights Council’s automated-decision-system regulations took effect October 1, 2025. They make it a violation of FEHA to use an automated tool that discriminates against an applicant or employee, whether the discrimination is intentional or shows up as a disparate impact. An automated tool’s output also does not replace the individualized assessment the state already requires before an employer acts on someone’s criminal history. Our companion piece on the California AI training playbook covers the full 90-day rollout these rules sit inside.

The state’s automated decisionmaking technology (ADMT) regulations arrive later, with compliance required by January 1, 2027, and they reach further than most owners expect. They define a covered “significant decision” in employment terms as hiring, work or assignment allocation, pay and incentive compensation, promotion, demotion, suspension, or termination. Once a business crosses that line, it must let the affected person opt out of the automated decision, unless the business offers an appeal path to a human reviewer with the authority to overturn it. That single sentence is the legal spine behind clause 4, below.

One thing a policy should not claim: SB 53 and AB 2013, both effective January 1, 2026, bind the companies that build AI models, not the small businesses that use them. A policy can note what a vendor discloses, not treat the law as an employer obligation.

Clause 1: The approved-tool list

Name the tools employees are allowed to use for work, by product name, not model version, since version numbers change every few months and a policy that names them goes stale on schedule. A typical list for a 5-50 person business names ChatGPT, Claude, Gemini, and Microsoft Copilot, plus any tool already licensed under a business (not personal) account.

State plainly that a tool not on the list, including a personal ChatGPT account an employee already uses at home, is off-limits for work tasks until it is reviewed and added. This is the clause that stops “shadow AI,” the free personal accounts employees adopt on their own, from becoming the business’s actual, unmanaged AI footprint.

Clause 2: Client and customer data handling

State what can and cannot go into a prompt. We recommend the safest working rule for a small business: no client name, case detail, patient information, financial account number, or any personal data covered by the CCPA goes into a consumer-tier AI tool, full stop. A business account with an enterprise data agreement, which most major AI vendors offer, can loosen this only if the agreement is read and confirmed, not assumed.

Name where the data can end up, too. If the business is CCPA-covered (worth checking; the thresholds catch many small businesses that assume they are too small), a vendor processing personal data through an AI tool is a service provider under the CCPA, and the same contractual limits apply to it as to any other data processor.

Clause 3: Confidentiality and privilege for regulated professions

A law firm, a medical or dental practice, or a CPA firm carries duties an ordinary business does not: attorney-client privilege, HIPAA, and professional-conduct rules that predate any AI regulation and do not bend for it. State specifically that privileged or protected information does not go into any AI tool not covered by the same confidentiality terms the profession already requires, and that a partner or compliance lead, not an individual associate, decides what counts as covered.

Outside a regulated profession, this clause can be short: confirm no professional-conduct rule applies, and move on. Inside one, it is often the single highest-risk clause in the document, and it deserves review by whoever handles the firm’s actual malpractice or compliance exposure, not just HR.

Clause 4: Human review before an automated decision sticks

This is the clause the 2027 ADMT rule makes necessary, and it costs nothing to adopt early. If an AI tool contributes to a hiring, pay, promotion, discipline, or termination decision, a human with the authority to overturn that decision reviews it before it takes effect. Under the ADMT rules, offering that review path is what lets a business avoid building a separate opt-out mechanism: the review path itself satisfies the exception.

Write down who that human is by role, not by name, since names change. For most 5-50 person businesses, this is the owner, a partner, or whoever already signs off on hiring and termination decisions today. The clause just needs to say, in writing, that sign-off happens before the decision, not after.

Clause 5: Employee acknowledgment

A policy nobody has read protects nobody. Require every employee to sign or digitally acknowledge the policy before using an approved AI tool for work, and again whenever the policy changes materially. Keep the acknowledgment itself (a signed PDF, a checked box in an HR system, an email confirmation) for the same four-year period the state already requires for automated-decision records, so retention does not become another thing to track separately.

Clause 6: Incident reporting

Employees need one clear channel to flag something an AI tool got wrong: a factual error in a client document, a biased output in a hiring context, or an accidental disclosure of protected data. Name the channel (an email address, a form, or a specific manager) and commit to a response window. Forty-eight hours is a reasonable standard for a small business without a dedicated compliance team.

This also protects the business. A documented incident-reporting process, used even once, shows the company took its obligations seriously, a meaningful difference if a regulator ever asks what happened after something went wrong.

Clause 7: Vendor and subprocessor disclosure

List which AI vendors touch company or client data, and require any new vendor to pass the same review before adoption. This clause exists because the aiding-and-abetting language in the Civil Rights Council’s regulations can reach a vendor whose tool discriminates, which means the business choosing that vendor inherits some of that exposure. A short checklist (does the vendor publish a data-processing agreement, does it name its own subprocessors, does it support a business-tier account with enterprise data terms) turns this from a legal question into an operational one.

Clause 8: A review cadence

Put a date on the calendar, annually at minimum, to reread the whole policy against current law. California’s AI rules for employers moved twice within five months: the ADS regulations took effect, and the No Robo Bosses Act was vetoed and refiled. A policy written once and never revisited will be wrong within a year, not because it was written badly, but because the law under it kept moving.

What almost became law: the No Robo Bosses Act

Senate Bill 7, the “No Robo Bosses Act,” would have required employers to notify workers before using an automated decision system and barred them from relying solely on one for discipline, termination, or deactivation decisions. Governor Newsom vetoed it on October 13, 2025, calling its restrictions “overly broad” and the bill “unfocused” relative to the actual risks AI poses at work. The same author reintroduced a revised version, SB 947, on February 2, 2026. Neither is law today, and a policy should not describe notice-before-use or no-sole-reliance as legal requirements. Clause 4, above, gets a California employer most of the way there voluntarily, which is the more durable position regardless of how SB 947 turns out.

Rolling the policy out

A policy is only as good as the training under it. Employees who do not understand what an automated decision is will not recognize when clause 4 applies to something they are doing. A short, hands-on session on the business’s actual tools earns its cost. For California businesses with 100 or fewer employees (250 or fewer worldwide), that training is often reimbursable through the state’s Employment Training Panel at $28 per trainee hour for the Small Business Program, with a 90-day retention period attached. Our San Francisco corporate AI training hub covers how that funding pairs with a rollout like this one.

Here’s how to sequence it: write the policy first, since training without a policy to point to teaches habits with nothing backing them up. Train second, so the policy is not just a document in a drawer. Review third, on the cadence clause 8 sets.

Frequently asked questions

Does a small business in California legally need an AI use policy?

No single statute mandates a written AI use policy by name. The law requires that a business’s use of automated tools not violate the Civil Rights Council’s ADS regulations (five or more employees) or, starting 2027, the ADMT rules if it is CCPA-covered. A written policy is the practical way to meet both and to show a regulator the business had a process, rather than reconstructing one after a complaint.

What is an automated decision system under California’s employer regulations?

Any computational process, including an AI tool, used to make or help make an employment decision such as hiring, promotion, or discipline. The regulations effective October 1, 2025 apply the same anti-discrimination standard to these systems that already applies to a human decision-maker: a discriminatory outcome violates FEHA regardless of whether a person or a tool produced it.

Does the ADMT rule apply to a 20-person company?

It can. The rule applies to any business covered by the CCPA, and CCPA coverage depends on revenue and data-processing thresholds, not headcount. A 20-person company that processes personal data at scale, or sells or shares it, can be covered even though it feels small. Check applicability directly rather than assuming size alone rules a business out.

What happened to the No Robo Bosses Act?

Governor Newsom vetoed Senate Bill 7 on October 13, 2025, and the bill’s author reintroduced a revised version, SB 947, on February 2, 2026. Neither the original nor the refiled version is currently law. A California employer should build clause 4’s human-review practice as good policy, not because a specific statute requires it today.

Can employees paste client information into ChatGPT?

Not into a consumer-tier account, as a default rule. Client names, case details, patient information, and financial account numbers should stay out of any AI tool not covered by a business-tier data agreement the company has reviewed. Clauses 2 and 3 should spell out exactly which tools qualify.

Who is legally responsible if an AI hiring tool discriminates, the employer or the vendor?

Potentially both. The employer stays liable under FEHA for a discriminatory outcome regardless of which tool produced it, and the Civil Rights Council’s regulations also allow liability for a third party that aids and abets the discrimination through the tool’s design or sale. That shared exposure is why clause 7’s vendor-review step matters; it is not just a data-privacy check.

Does a law firm or medical practice need a different AI policy than other small businesses?

Yes, primarily around clause 3. A law firm has attorney-client privilege obligations, and a medical or dental practice has HIPAA obligations, on top of the general California rules covered here. The confidentiality clause needs sign-off from whoever manages the firm’s actual privilege or compliance exposure, not a generic HR template.

How often should an AI use policy be updated?

At minimum once a year, and after any material legal change. California’s rules here moved substantially between October 2025 and February 2026 alone: a new regulation took effect, a bill was vetoed, and a revised bill was reintroduced. Clause 8 should put an actual date on the calendar rather than leaving the review open-ended.

What should employees do if an AI tool produces something wrong or harmful?

Report it through the channel clause 6 names, logged rather than handled informally. A biased hiring recommendation, a factual error in a client-facing document, and an accidental data disclosure are different problems, but each needs the same first step: a record that the business knew and responded.

Is ETP training reimbursement connected to having an AI use policy?

Not directly. ETP reimburses the training itself, not the policy document. Businesses that write the policy first tend to get more out of the training, since employees arrive already knowing the rules rather than learning the tool and the rules at once.

Key takeaways

  • Two California rulesets govern AI at work today: the Civil Rights Council’s automated-decision regulations (effective October 1, 2025) and the state’s ADMT rules (compliance required January 1, 2027).
  • An AI use policy needs eight clauses: an approved-tool list, client and customer data handling, confidentiality and privilege for regulated professions, human review before an automated decision sticks, employee acknowledgment, incident reporting, vendor and subprocessor disclosure, and a review cadence.
  • Clause 4’s human-review requirement is not just good practice. It is the specific step the ADMT rule treats as an exception to the employee’s opt-out right.
  • The “No Robo Bosses Act” (SB 7) was vetoed October 13, 2025, and reintroduced as SB 947 in February 2026. Neither is currently law; do not write a policy as though it is.
  • Write the policy before training the team on it, and put a real date on the calendar for the annual review.

Ready to put this into practice? Book a free AI-readiness call and we will walk through what a policy and a training rollout look like for your team, or start with Team Training for the fuller picture.

Last Updated: Sep 15, 2026

DJ

Dirk Jan van Veen, PhD

SFAI Labs helps companies build AI-powered products that work. We focus on practical solutions, not hype.

Make your team fluent in AI — then automate what proves out

  • Hands-on training applied to your own documents and workflows
  • Reimbursable for many California small businesses through ETP
  • Built for 5–50 person firms with no IT department

Related articles