California AI Workplace Law: A Human Must Read the Alert
A PPE alert lands in a supervisor’s queue at 10:14 on a Tuesday. Who reads it, what they write down, and whether anything happens to the person in the frame is what California’s proposed AI workplace law would govern. The detection is not the regulated act — the decision after it is.
Where SB 947 stands right now
SB 947, the No Robo Bosses Act of 2026, would add a new part to the Labor Code governing how employers use automated decision systems against workers. Senator Jerry McNerney introduced it on 2 February 2026. It has been amended eight times since, most recently on 2 July.
The bill’s history records the last three weeks precisely. It passed the Senate, went to the Assembly, and was placed on the Appropriations suspense file on 5 August 2026 — normally where a bill with a fiscal note goes to die quietly. On 13 August the Assembly suspended its own Rule 63, the committee reported it out on a 10–4 vote, and it was read a second time and ordered to third reading. On 17 August it was placed on the Assembly third reading file.
The Legislature’s session ends 31 August 2026. After that, the Governor’s action window.
That last part is the reason to read the bill rather than the headlines. Its predecessor, SB 7, passed both houses in 2025 and was vetoed on 13 October 2025. Governor Newsom’s message called the restrictions “overly broad” and the requirements unfocused, and said the state should assess the automated decisionmaking regulations already on the books before adding statute on top of them. Fisher Phillips and several other employment firms published the same reading within days.
SB 947 is the narrower answer to that veto. The most consequential change: it drops the pre-use notification duty that drew most of the fire and replaces it with a notice given after the fact.
Current as of 17 August 2026. This is a live bill with a floor vote and a possible veto still ahead of it — check the status page before relying on any date here. Nothing below is legal advice.
SB 947 Procedural History
Official California State Senate & Assembly Record
What California’s AI workplace law counts as an automated decision system
An automated decision system, in SB 947’s terms, is any computational process built on machine learning, statistical modelling, data analytics or artificial intelligence that issues a simplified output — a score, a classification, or a recommendation — used to assist or replace human discretionary decision-making, and that materially impacts natural persons.
Read that definition three times and the operative words separate out.
Simplified output. Not a report, not a dashboard, not a video clip. A score, a classification, a recommendation. A detection that returns “no hard hat, zone 4, 10:14” is a classification.
Assist or replace. This is the phrase that catches systems nobody thinks of as decision-making. The process does not have to decide anything. It only has to feed a discretionary decision that a person then makes.
Materially impacts natural persons. The output has to land on somebody.
The bill text also defines worker data broadly — any information that identifies, relates to or describes a worker, however it was collected, inferred or obtained — and defines a worker to include independent contractors, not just employees. A yard run by a labour contractor is not outside this.
So the question for anyone running safety or security analytics is not whether a camera detection is an automated decision system in the abstract. It is narrower and more answerable: is the output of that detection being used to assist a discretionary decision that lands on a worker?
For most sites, the honest answer is that nobody has ever written it down.
Automated Decision-Making Technology
Statutory Definition Block — § 1520(a)(1)
means any system, software, or process using computation that facilitates, participates in, or replaces human decision-making...
Applies across operational assessment, profiling, and programmatic analytics.
A detection is not a decision
The bill’s core duties do not attach to observing. They attach to relying.
It would prohibit an employer from relying solely on an automated decision system when making a disciplinary, termination or deactivation decision. And where an employer primarily relies on such a system’s output for one of those decisions, it would require the employer to direct a human reviewer to conduct an independent investigation and compile corroborating information supporting the decision.
A camera can report that a hard hat was missing at 10:14. It cannot report why.
Note the threshold word. Not “uses”. Not “consults”. Primarily relies. A detection that starts a conversation is in a different position from a detection that ends one, and the difference is entirely in what the organisation does with it.
There is a second set of provisions worth knowing about, because it rules out a category of product rather than a category of workflow. The bill would bar using an automated decision system to infer a worker’s protected characteristics, and to conduct predictive behaviour analysis about a worker’s conduct, beliefs or emotional state. That is a different thing from detecting whether high-visibility clothing is present in a frame. Anyone being sold worker behaviour prediction or emotion inference in California should read those provisions first.
| Instrument | Status as of 17 August 2026 | What it reaches |
|---|---|---|
| SB 947 — No Robo Bosses Act of 2026 | On the Assembly third reading file; session ends 31 Aug | Reliance on an automated decision system for discipline, termination or deactivation |
| CCPA automated decisionmaking regulations (CPPA) | In effect since 1 January 2026, with the ADMT obligations phasing in from 1 January 2027 | Use of automated decisionmaking technology for a “significant decision”, which the rules define to include employment |
| SB 7 — the 2025 predecessor | Vetoed 13 October 2025 | Nothing. Would have required notice before use |
CPPA ADMT Regulatory Scope
Formal Rulemaking Record & Governance Framework
Requirements for Businesses Using Automated Decisionmaking Technology to Conduct Risk Assessments and Provide Opt-Out Mechanisms.
Scope encompasses systematic observation, workplace monitoring thresholds, and algorithmic governance controls.
The middle row is the one people miss. The California Privacy Protection Agency’s regulations are not a proposal. They took effect on 1 January 2026, they treat employment decisions as significant decisions, and they turn on a concept called meaningful human involvement: a person who interprets the output, analyses it, and holds the authority to reach a different conclusion. Two different California agencies, arriving at the same requirement from opposite directions.
Why “a human looks at it” is not the answer
Every operations manager asked about this says the same thing, and they are not being evasive. Nobody has automated discipline. A supervisor reads the alert. A human is in the loop. On most floors that is literally true.
It is also not what either instrument asks for. Three gaps open up under pressure.
The duty is not satisfied by presence. A supervisor who opens the alert, agrees with it, and issues a written warning has read the system’s output. They have not investigated independently of it. The bill’s language is about an independent investigation producing corroborating information — a second source, not a second opinion.
Nothing survives the review. The obligations described here all produce documents: corroborating information, a written notice to the worker, and a data package if the worker asks for one. A workflow that runs through a group chat and a supervisor’s memory produces none of them. Six months later there is no way to demonstrate what was actually done, which is the same problem as not having done it.
The alert queue has no owner. Ask who is authorised to act on a forklift-proximity alert on the night shift and most sites cannot answer with one name. If nobody owns the decision, nobody is accountable for how it was made — and the record of it is whatever each shift improvised.
Be fair about the counterargument: this is a bill, not a law. It may be vetoed a second time, and the same industry groups that beat SB 7 are still in the room. But the automated decisionmaking regulations are already in force, and the workflow question is identical under both. Building the review step now costs a policy document and a form. Building it after a claim, a citation or a regulator’s request costs considerably more.
What the workflow needs to look like
None of this is a technology change. Every item below is a decision about who does what, written down before the alert arrives.
Separate the detection record from the decision record
A detection log and a personnel file are two different systems with two different retention profiles, two different audiences, and two different legal exposures. When they are the same spreadsheet, every hazard observation becomes a potential piece of employment evidence, and the whole log inherits the sensitivity of its worst row.
Keep the hazard record about conditions: zone, time, what was observed, what was done to fix it. Anything that becomes a personnel matter gets escalated into a separate file, deliberately, by a named person.
Name who is allowed to act on an alert
One name per detection type per shift. Not a role, not a distribution list — a person, and a named deputy. The point is not bureaucracy. It is that “primarily relies” is a factual question about a specific decision, and a decision with no author cannot be defended.
Make corroboration produce an artefact
For a camera alert, corroboration means something the camera did not produce. A supervisor’s own observation, written the same day. The shift’s PPE issue log. The toolbox talk record. The worker’s own account of what happened, recorded before any decision.
The test is simple and worth applying to your current process: could you hand the file to someone who has not seen the clip, and would they reach the same conclusion? If the answer is no, the clip is the decision and the review was a formality.
Draft the notice before you need one
The post-use notice attaches at the moment the employer informs the worker of the decision — not a week later. Under the bill it would state that an automated decision system was primarily relied on, that a human reviewer conducted an independent investigation, where to direct questions, how to obtain the underlying data, and that retaliation is prohibited. That is a template, and a template written under time pressure on the day of a termination is a template written badly.
Decide the data-access question now
SB 947 would let a worker request a copy of the most recent twelve months of their own data primarily used by the system in reaching the decision, once a year. That is a retention question disguised as a privacy right, and it points in the opposite direction to most video policy. If your recorder holds thirty days, you cannot produce twelve months. If you retain twelve months of everything to be safe, you have created a much larger disclosure surface than you had before.
The resolution is not more storage. It is deciding, in advance, which detection metadata is retained long enough to substantiate a decision and which video is not retained at all — a design choice, made once, rather than a default inherited from a recorder’s disk size.
Keep the safety case and the performance case apart
This item does the most work and needs the least technology. Route safety detections to hazard removal, not to individual performance scoring. A blocked-exit alert should reach whoever can move the pallet. A forklift-proximity alert should reach whoever can re-mark the aisle or change the traffic pattern.
That is better safety practice on its own terms — it is what real-time physical safety monitoring on cameras you own is actually for, and it is the posture an inspector rewards under OSHA’s warehouse national emphasis program, which now runs to 2031. It also happens to keep the great majority of safety alerting outside the reach of a statute about disciplinary decisions, because no disciplinary decision is being made.
Where Nsightify fits
An Nsightify detection reports that a condition exists at a place and a time. PPE compliance, forklift–pedestrian proximity, restricted-area dwell, blocked exit, person down — each produces a real-time alert that a state was observed, on the IP and CCTV cameras a site already operates. It issues no score about a person, ranks nobody, and takes no action. The discretionary decision stays where SB 947 would put it: with a human who has to look.
The limit has to be stated plainly. Nothing in that design stops a supervisor from treating an alert as a verdict. The moment a detection becomes the primary basis for a written warning, the employer is inside the workflow this bill regulates, and no vendor architecture changes that. The control is the employer’s written policy and the sequence people actually follow. Using Nsightify resolves no obligation under SB 947, and nothing here is legal advice.
The technical constraints matter for the same reason. Camera-based detection depends on sightlines, lighting, and where a camera was mounted — which was almost never for analytics. Occlusion behind racking is real. A missing-vest classification is a statement about pixels in a frame, which is precisely why it belongs in a hazard workflow as an observation, and not in a personnel file as a finding. Working out what your existing cameras can already tell you is a separate question from deciding who is allowed to act on it.
Questions operators are asking
Can AI fire your employees in California?
Not on its own, if SB 947 becomes law. The bill would prohibit an employer from relying solely on an automated decision system to make a disciplinary, termination or deactivation decision, and would require an independent human investigation wherever such a system is the primary basis for one. As of 17 August 2026 the bill sits on the Assembly third reading file and has not been signed.
Does California require human review of AI decisions?
SB 947 would. It would bar sole reliance on an automated decision system for discipline, termination or deactivation, and require an independent human investigation where such a system is the primary basis. Separately, the California Privacy Protection Agency’s automated decisionmaking regulations, effective 1 January 2026, treat meaningful human involvement as the thing that takes a technology outside their scope. Confirm your own obligations with counsel.
What counts as an automated decision system?
Under SB 947, any computational process built on machine learning, statistical modelling, data analytics or artificial intelligence that issues a simplified output — a score, a classification or a recommendation — used to assist or replace human discretionary decision-making, and that materially impacts people. The word assist carries the weight: a system does not have to decide anything to be inside the definition.
Can my employer use camera footage to discipline me?
Nothing in SB 947 would prohibit that. What the bill would change is the sequence. Where an automated system’s output is the primary basis for a disciplinary decision, a human reviewer would have to conduct an independent investigation and compile corroborating information, and the employer would have to state in writing, at the time it informs the worker of the decision, that it primarily relied on such a system.
Do I have to tell employees about workplace monitoring in California?
SB 947 is not the instrument that answers that. Its notice duty is post-use: it attaches at the moment an employer informs a worker of a disciplinary, termination or deactivation decision, not at the moment monitoring begins. Notice obligations for the collection of employee personal information sit under the CCPA and its regulations instead. Confirm your own position with counsel.
What to write down this week
None of the above waits on a floor vote. Take one detection type you already run — PPE is the usual candidate — and answer four questions on one page. Who receives the alert on each shift. Who is authorised to escalate it into a personnel matter. What corroboration that person must gather before they do. How long the underlying record is kept, and where.
That page is the difference between an observation and a decision, and it is the artefact both California instruments are ultimately asking to see. If the honest answer to any of the four is “it depends who is on”, the gap is in the workflow rather than in the statute — and it is the same gap that makes an incident review two years later impossible to run.
If continuous visibility on floor conditions is the part you are missing, talk to us about Physical Safety.
Keep reading:
More on this from Nsightify: PPE detection and hazard-zone monitoring.
See Nsightify in Action
We're onboarding a limited number of pilot partners. If you're an operations or security leader in construction, warehousing, or manufacturing — let's talk.