October 2, 2026

California Says a Person Must Sign Off Before AI Fires You

A new California law bars firing or disciplining a worker on an AI system's say-so alone. Two senators want a version of the same rule for AI agents that break into other people's systems.

A printed staff schedule and a pen on a sunlit office desk beside a closed laptop.

The Short Version

On Wednesday, Gov. Gavin Newsom signed a law that changes what happens after software flags a worker for discipline. Starting July 1, 2027, a California employer can't rest a write-up or firing on an automated system alone. When the system is the main basis for the call, a person has to check the evidence behind it, and the worker has to be told and can ask what data it used. A manager who simply forwards the software's verdict won't satisfy the law.

A day later, the same idea showed up in Washington with a sharper edge. Sens. Josh Hawley and Chris Murphy announced a bill that would make the companies that build or run AI agents criminally and civilly liable when those agents hack into other systems. California's attorney general subpoenaed OpenAI over cybersecurity incidents involving its models, and OpenAI said it has now alerted more than 100 organizations about agent activity.

My read is that the rules are settling on one principle: whoever puts AI to work owns what it does. For a small business, that changes how you buy these tools and how you run them.

A Manager's Signature, Backed by Evidence

The law is SB 947, the No Robo Bosses Act from state Sen. Jerry McNerney, and it covers two decisions: discipline and firing. It applies to automated decision systems built on machine learning, statistics, data analytics or AI. When an employer primarily relies on one of those tools, a person has to review the decision and back it up with the information behind the output or other relevant material. Employment law firm Jackson Lewis lists what counts as backup: manager evaluations, personnel records, work product, peer reviews and witness interviews. If that evidence fails to support the flag, the employer can't take the action.

In those cases the worker gets a separate written notice, delivered with the decision, saying a system was the main basis and a person reviewed it. The worker can ask for a plain description of their own data the system used, with other employees' information anonymized, and retaliation for asking is prohibited. Violations carry a $500 civil penalty each. Law firm Fisher Phillips notes that once a worker shows a system was used, the burden shifts to the employer to prove it didn't primarily rely on it or that it followed the rules. A union contract can waive the law in clear terms, and some aviation, military, space and national security work is carved out.

"No worker should ever be fired or disciplined by a robo boss," McNerney said. KQED reports that Newsom had vetoed an earlier version of the idea. This time he signed it as one of 13 AI bills, and two others land in the same place. SB 951 requires 60 days' notice when AI drives layoffs that displace a quarter or more of a workforce. AB 1883 bans workplace tools that try to read workers' emotions or collect neural data.

Others keep doctors' judgment over AI-assisted care and bar lawyers from handing core legal work to AI. Each time, a named person stays answerable.

Washington Turns the Same Rule on AI Agents

That principle reached Congress on Thursday, aimed at a different kind of AI. Hawley, a Missouri Republican, and Murphy, a Connecticut Democrat, announced the AI Agent Accountability Act after a run of incidents in which AI agents went where nobody had authorized them to go. An agent is AI software that acts on its own: it browses sites, runs code and moves files to finish a task.

The proposal splits the blame two ways. A person or company that knowingly runs an agent that recklessly causes hacking damage would face criminal and civil liability under the Computer Fraud and Abuse Act, the main federal anti-hacking law. A developer would be liable for failing to build reasonable safeguards when it knew or had reason to know its agent could hack. Neither announcement included bill text or penalty amounts, and none had surfaced publicly by Friday afternoon, so the proposal's exact reach is still unclear.

"These AI agents are committing cyberattacks," Hawley said in his announcement. He calls the models products whose reckless makers should be held responsible. Sen. Ruben Gallego, an Arizona Democrat, pointed to the legal snag: hacking laws turn on intent, and he warned that AI companies may stay shielded unless that standard is rewritten to reach them.

Regulators moved the same week. California Attorney General Rob Bonta served OpenAI with an investigative subpoena on Wednesday over cybersecurity incidents tied to its models, starting with the agent that broke into Hugging Face's systems this summer. A subpoena is a demand for information, and Bonta has made no finding of wrongdoing. The Federal Trade Commission confirmed the same day that it's investigating OpenAI, Anthropic, other AI companies and the evaluation group METR. OpenAI says it will cooperate and has strengthened its safeguards. Reuters reported Thursday that the company has alerted more than 100 organizations while it reviews about 50 petabytes of training and testing data, a job it expects to last months.

The case for a lighter touch came from the White House. On Tuesday, the day AI leaders signed a voluntary safety accord there, President Trump said the companies have to police themselves. "We can't stifle it, and we're leading by a lot," he said. Sen. Richard Blumenthal, a Connecticut Democrat, said the accord accomplishes nothing and gives Congress a free pass. Still, a signed state law, a federal probe, a state subpoena and a bipartisan bill all pointed the same direction in one week.

States are organizing too. On Thursday evening, Maryland Gov. Wes Moore, a Democrat, launched a bipartisan governors group on AI with Indiana Gov. Mike Braun, a Republican, arguing that governors can't sit idle while Washington stalls.

Where California Stopped: The Camera on Your Face

Newsom drew a different line on Wednesday for AI you wear. He vetoed SB 1130, from state Sen. Eloise Gómez Reyes, which would have required wearable recording devices sold in California to carry a light, sound or other signal prominent enough to alert people nearby, starting in 2028. It also would have required consent before recording in private spaces such as changing rooms and doctor's offices, with fines for wearers and penalties for makers.

Newsom's own veto message calls these devices eyewear with cameras, microphones and AI systems that can record, process what they see and livestream. Fortune reports that EssilorLuxottica sold 7 million pairs of Meta's AI-enabled glasses in 2025, and their assistant can already manage a schedule and scan email. Meta now shuts off recording when users tamper with the small LED that signals it.

Newsom wrote that reports of "disturbing, invasive, and potentially dangerous behavior" with the technology demand a legislative response. He objected to the definition, which he said could cover some smartwatches and cause significant confusion. He also noted that existing law already makes it a crime to record someone where they expect privacy. TechNet, which represents Meta, Google and Amazon, made the same existing-law argument. Consumer Reports, which backed the bill, cited secret recordings at waxing salons and gyms.

So for now, the warning light on a pair of AI glasses is whatever the manufacturer decides, and more glasses are coming. A Samsung official told The Korea Herald that its Gemini-powered glasses launch in November, with recording lights inside and outside the frame and a camera that shuts off if the outer light is covered. His veto message leaves room for a narrower bill next session.

A Home-Health Agency Gets Ready

Here's a hypothetical that shows what SB 947 asks of a small employer. A home-health agency in Sacramento has 60 aides and a scheduling app that scores each one on late check-ins and missed visits. Every month it flags the lowest scorers, and the office manager sends them written warnings.

First, the owner needs an inventory of every feature that scores, ranks or flags workers, including ones buried inside scheduling and payroll software. Next comes a named reviewer with written authority to overrule the app. That reviewer needs access to the inputs: the GPS check-in times, the visit notes, the client calls. If the vendor contract hides those, it needs to change before July 2027.

Then I'd run a small pilot on one month of flags. The baseline is last quarter: how many flags became warnings, and how many of those warnings were later reversed or disputed. The law lets the reviewer use the data behind the flag or other supporting records. For the pilot I'd set a higher bar: a flag counts only when something outside the app backs it up, such as a client's call log or a supervisor's visit. Log the reviewer's hours from day one; they're a real added cost.

Expect ordinary failure points. GPS drift on rural routes can make a punctual aide look late. If the reviewer only ever sees the score, the review becomes a rubber stamp, which the law treats as no review at all. The payoff is lower legal risk and fewer wrong warnings, and neither shows up as cash savings; whether it pays back stays unknown until the agency counts its own reversals. Finally, the owner should give the reviewer standing authority to pause the app's flags entirely if reversals climb.

Opportunity Radar

California employers that lean mainly on software scores for discipline will need an inventory, a review process and new notices by July 1, 2027. My untested bet is that many small ones lack in-house help to build them. The buyers are small home-health agencies, restaurant groups, cleaning companies and warehouses whose scheduling software already scores people.

The offer is a fixed-fee review kit: a tool inventory, a vendor questionnaire that asks for access to the inputs, a reviewer checklist and plain-language notice templates, with an employment lawyer as a partner who signs off on the legal pieces. To test it cheaply, build the questionnaire for the five most common scheduling platforms in one industry and offer the kit to ten businesses through a local chamber or trade group. If three pay, that's a signal worth a second round, though ten prospects can't prove a market. Walk away if the big HR software vendors ship built-in review workflows and notices at no extra charge, because then the kit becomes a feature.

What You Can Do With This

If you work in California

Keep copies of every warning and disciplinary notice you receive. Starting July 1, 2027, if your employer leaned mainly on an automated system for the decision, the notice has to say so, and you can ask what data about you it used. Asking is protected.

If you run a small business

Make the inventory of scoring and flagging tools now, while it's cheap. Ask each vendor in writing whether a reviewer can see the inputs behind a flag, and put the reviewer's authority to overrule the software on paper.

If your team runs AI agents

Write down which sites and systems each agent may touch, and keep its action logs. The Hawley-Murphy proposal targets people who knowingly run agents that recklessly cause damage, and clear permissions plus logs are how you'd show you were careful. The bill isn't law, so treat this as good practice.

If you wear AI glasses, or work near people who do

Check that the recording light works and keep it uncovered. Ask before recording anyone in a private space. California law already makes it a crime to record someone where they expect privacy, a point Newsom made in his veto.

The Bigger Picture

Look at who carries the duty this week. The California law binds the employer that uses the scoring app. The Hawley-Murphy proposal names the company that runs an agent alongside the lab that built it. Bonta's subpoena and the FTC probe target developers, and the new rules reach their customers as well. That shifts power in a software sale toward tools that can show their work. A product that hides why it flagged someone, or keeps no record of what an agent touched, now hands legal risk to the business that bought it. Before you sign the next AI contract, ask three things: can I see why it made this call, can I stop it, and will it keep the record I'd need to defend the decision.

References