California's AI transparency law fails to uncover state systems
AB 302 relied on self-reporting by agencies, revealing fundamental flaws in transparency-based regulation of government technology.
California's experiment with AI transparency in state government has exposed the limitations of self-reporting frameworks. After the state's Department of Technology initially reported zero high-risk automated decision systems in 2025 under Assembly Bill 302, officials have now identified at least six such systems operating across state agencies—none of which were disclosed in the first annual report.
According to CalMatters, the systems in question make consequential decisions affecting Californians' access to cash assistance, housing, and medical care. The revelation underscores what critics have long argued: transparency requirements without enforcement mechanisms cannot adequately regulate government technology use.
Why it matters
Automated decision systems directly impact millions of Californians seeking essential services, yet the state has no reliable mechanism to identify which systems are in use or verify agency claims. This gap leaves residents unable to understand—much less challenge—how algorithms shape their access to housing, healthcare, and other critical resources.
How the law works (and doesn't)
AB 302, signed in 2023, requires the Department of Technology to inventory "high-risk automated decision systems" used by state agencies and publish annual findings. The law defines high-risk systems as those that "assist or replace human discretionary decisions" with significant legal effects, including decisions affecting housing, education, employment, credit, healthcare, and criminal justice.
Researchers Victoria Copeland and Stevie Glaberson requested the department's underlying data after the 2025 report found no high-risk systems. They received a single spreadsheet with "no" listed for each agency, with no evidence of further inquiry, according to their commentary first reported by CalMatters.
The 2026 report identified systems only after agencies voluntarily came forward. Notable omissions include the Uniformity Assessment System, which has reduced In-Home Supportive Services for disabled Californians, and the Risk Segmentation model used to predict Medi-Cal recipients' service needs.
A pattern of failed transparency laws
California's experience mirrors transparency failures nationwide. New York's Public Oversight of Surveillance Technology Act aimed to illuminate NYPD surveillance practices, but the department has exploited legal loopholes and used vague descriptions to avoid meaningful scrutiny, according to the Brennan Center for Justice.
"Community control over police surveillance" ordinances in multiple jurisdictions face similar challenges. University of Washington law professor Ryan Calo noted that these approaches allow agencies to frame technology in favorable terms, causing policymakers to "fixate on whatever instantiation of technology" proponents present.
The fundamental problem
Transparency-based regulation carries a deeper flaw: it presumes agencies may adopt automated systems and then builds public bureaucracies around their continued use. Rather than providing oversight, this approach normalizes and entrenches automated decision-making in government operations.
AB 302 lacks verification processes and imposes no consequences for non-reporting agencies. The Department of Technology's interpretation suggests agencies themselves determine whether their systems qualify as "high risk" and reportable—creating an obvious conflict of interest.
Copeland and Glaberson argue that protecting Californians from high-risk government technology requires moving beyond transparency. "AB 302 was an interesting, if failed, experiment," they write. "Now it's time for lawmakers to get serious."
This analysis was first reported by CalMatters in a commentary by Victoria Copeland, research fellow at the UCLA Center on Resilience and Digital Justice, and Stevie Glaberson, director of research and advocacy at Georgetown Law's Center on Privacy and Technology.
This is an original analysis by the Omega editorial team. Source reporting: AI Watch.
Want systems like this working for your business?
Book a Call