Citizen Portal
Sign In

Get Full Government Meeting Transcripts, Videos, & Alerts Forever!

Get email alerts on the Ai Security topic

No spam. Unsubscribe anytime.

Panel hears SB 468 to require information-security programs for businesses using high-risk AI systems that process personal data

3095176 · April 22, 2025
AI-Generated Content: All content on this page was generated by AI to highlight key points from the meeting. For complete details and context, we recommend watching the full video. so we can fix them.

Summary

SB 468 would require businesses that deploy high‑risk AI systems using Californians' personal data to maintain a written information-security program based on industry best practices.

Senator Becker presented SB 468, a bill that would require businesses using high‑risk artificial intelligence systems that process personal data to maintain a written information security program that follows industry best practices. Becker said AI systems bring novel security vulnerabilities—such as data‑poisoning and model inversion—so the bill would set clearer security expectations and authorize the California Privacy Protection Agency (CPPA) to treat violations under the unfair competition law.

Supporters included the Transparency Coalition (technical adviser Steve Wimmer) and civil-society groups. Wimmer argued the bill applies established information-security frameworks—HIPAA and SOC 2 analogs—to AI systems, recommending testing and validation so models behave as intended and to reduce risks such as hallucinations and data extraction. "These are common sense best practices that do not represent an undue burden on the deployers of these powerful systems," Wimmer said.

Questions from the committee focused on scope and overlap with existing rules. Senator Nielo asked whether hospitals and HIPAA-covered entities would be exempt; Becker said the bill was not meant to cover entities already governed by HIPAA and that discussions were ongoing. Committee members also queried whether a private right of action should be included; Becker said enforcement by the CPPA was the primary focus but remained open to negotiation.

There was no opposition at the hearing. Becker said she would continue to negotiate regulatory scope and noted CPPA would be empowered to adopt regulations to keep standards current.

Why this matters: As AI systems are increasingly used for decisions affecting employment, housing and other critical domains, security and transparency gaps raise risks for privacy and public safety. SB 468 would set state-level baseline security obligations for deployers of high-risk AI systems handling personal data and add an enforcement pathway through existing consumer-protection law.