Newsom Sticks It to Trump, Signs ‘No Robo Bosses Act’ and Several Other AI Bills
Less than 24 hours after former President Donald Trump convened AI industry leaders at the White House and touted a “morally binding” pact on safety, California Governor Gavin Newsom signed a sweeping package of state AI bills. At the center is SB 947—the “No Robo Bosses Act”—a first-in-the-nation curb on firing or disciplining workers based solely on automated systems. The broader package touches workplace surveillance, health care, higher education, legal practice, and the fight against deepfakes—signaling California’s intention to set a tougher, more enforceable AI rulebook than Washington’s voluntary approach.
According to CNBC, SB 947 bars employers from relying exclusively on automated decision systems to terminate or discipline employees. If an AI tool is primarily responsible for such an action, a human must review the outcome and corroborate it with independent information, such as a manager’s evaluation, the employee’s work product, or personnel records. Workers must also receive written notice when AI played a primary role in a decision about their job status, with details on the data the system used and a real human contact who can explain the rationale. The law takes effect in July 2027.
Why this matters
For years, employers have piloted and deployed algorithmic tools to measure productivity, screen behavior, and recommend disciplinary action—often with limited transparency and uncertain accuracy. The No Robo Bosses Act hardens a human-in-the-loop standard for the most consequential HR outcomes, helping curb automation bias and errors that can creep into data-driven assessments. It also opens a narrow window into the black box by requiring disclosures to the worker, a move that could be pivotal for contesting flawed inputs or biased features.
A bill reborn—without the broadest mandates
Newsom vetoed an earlier version of the measure last year, despite broad legislative support, objecting to provisions that would have required advance notice whenever AI systems could affect working conditions, CNBC reports. When state Senator Jerry McNerney (D-Pleasanton) reintroduced the bill this year, that advance-notice requirement was removed, and protections for gig workers—opposed by rideshare platforms like Uber and Lyft—were dropped. McNerney’s rationale remained unchanged: automated systems can err and encode bias, so decisions with major, lasting consequences should remain under human control. “No worker should ever be fired or disciplined by a machine, AI or not,” he said.
Cracking down on invasive workplace AI
Additional workplace-focused bills target some of the most contentious uses of AI monitoring. As KQED reports, California will restrict tools that purport to infer employees’ emotions or collect neural data, and it will prohibit surveillance in bathrooms. Another measure requires employers to provide more detail in layoff notices when jobs are being cut due to technological displacement. Together, these rules aim to reduce overreach in monitoring practices that can blur the line between job performance and personal privacy—and that create fresh data risks in the process.
Health care: AI can assist, but not overrule clinicians
AB 1979, also signed Wednesday, confines AI’s role in clinical settings. It bars health entities from using AI in a way that substitutes for the licensed judgment of medical professionals, while explicitly allowing AI to assist with decision-making. The law extends medical confidentiality protections to health chatbots as well. “We stood up and said that A.I. must support, not replace, the clinical judgement of the nurses and other health care professionals who care for our patients,” said Sandy Reding, RN, president of the California Nurses Association, in a statement. From a cybersecurity and privacy perspective, bringing chatbots under medical confidentiality frameworks is a notable step: it narrows the risk that sensitive patient disclosures to AI tools leak into third-party systems or data lakes.
Deepfakes, provenance, and safer digital identity
The package also advances defenses against synthetic media threats. New measures strengthen protections against AI-generated deepfakes, unauthorized digital replicas, and false impersonation. California will also ratchet up requirements around digital watermarks and provenance data—controls that help platforms, publishers, and investigators verify origins or flag manipulated content. For enterprises and election officials alike, these signals are becoming a frontline defense against influence operations, CEO fraud, audio spoofing, and other high-impact social engineering attacks.
Higher ed and the legal profession: guardrails for adoption
Another bill compels California’s public higher education systems to develop AI training and procurement standards—a practical response to the explosion of classroom and back-office tools with murky data practices. In parallel, new legislation limits the ability of attorneys and legal professionals to offload core legal work entirely to AI. Both moves aim to embed accountability where AI can have outsized consequences: shaping young professionals’ norms, and influencing people’s rights and liabilities.
Building the state’s AI safety infrastructure
These laws plug into an expanding California framework for AI oversight. As previously reported by SFist, Newsom last month signed legislation to create a system for independent assessments of AI model safety and risk, establish a state registry, and set standards for AI auditors. He has also issued executive orders probing AI’s effects on workers, cybersecurity, privacy, and the unique risks posed by frontier-scale systems. While much of Washington’s posture remains voluntary, California is methodically codifying enforceable obligations—an approach likely to ripple through corporate compliance programs well beyond state lines.
A pointed contrast with Trump’s AI strategy
Newsom underscored the contrast with federal policy by directing state agencies to keep using the term “artificial intelligence,” explicitly rejecting “Super Intelligence,” the phrasing Trump ordered federal officials to adopt, according to Gizmodo. The timing was deliberate: the order came a day after Trump hosted leaders from Google, Meta, Anthropic, OpenAI, xAI, and Nvidia for a voluntary safety accord he described as “morally binding.” Newsom has been blunt about his skepticism. “What I heard in Washington DC yesterday is bullsh*t, and that should scare the hell out of everybody,” he said in a video posted after the meeting.
What this means for workers, companies, and security teams
- Human-in-the-loop by law: High-stakes HR decisions cannot be fully automated. Companies using AI in performance management and discipline will need documented human review and corroborating evidence.
- Transparency obligations: Workers must be told when AI materially influenced discipline or termination, with details on data inputs and a human point of contact—raising the bar on auditability.
- Reduced surveillance creep: Restrictions on emotion inference, neural data, and location-based surveillance in bathrooms limit invasive tracking and shrink the attack surface created by sensitive telemetry.
- Healthcare guardrails: AI can assist but not supplant clinical judgment, and chatbot interactions get confidentiality protections—curbing privacy and compliance risks.
- Content authenticity: Stronger watermark and provenance requirements help counter deepfake-driven fraud and misinformation, with downstream benefits for election integrity and enterprise security.
A real-world test bed: Andon Market
The rules are likely to intersect with experiments like San Francisco’s AI-run Andon Market, whose agent “Luna” recently executed its first employee firing—though the move was reportedly initiated by the human team behind the startup. Cases like this illustrate where California’s new standards will bite: if AI plays a primary role, a human must substantively review and validate the decision, provide written notice, and be prepared to explain the data used.
Timeline and next steps
SB 947’s core protections kick in July 2027, giving organizations time to map where AI influences HR decisions, implement human review procedures, calibrate data governance, and build documentation trails. The broader package—spanning surveillance limits, health care, provenance, higher education, and legal practice—will demand parallel updates to policies, vendor contracts, and employee training. For CISOs and privacy leaders, the immediate to-do list is clear: inventory algorithmic decision points, minimize sensitive monitoring data, and get ahead of disclosure and record-keeping requirements.
California has once again put a regulatory stake in the ground. Whether you view it as a compliance headache or a necessary counterweight to automated opacity, the message is unmistakable: in the nation’s largest labor market, algorithms won’t have the last word on people’s livelihoods—or their identities.