TwinEthos homeAPI access

Law

California AB 1008 (CCPA: personal information in AI systems)

California Privacy Protection Agency / Attorney General · California (US-CA) · 1 provision encoded · verified against the official source as of 2026-10-02.

Informational data, not legal advice. Summaries and rules have not been reviewed by a lawyer: always verify official law text for decisions. A suggested guard is intended to address each rule; adding it is not a statement of compliance to that law.

AI-adjacent law General privacy or biometric law, included only where AI data flows trigger it; reported apart from AI-specific law.

Official text: leginfo.legislature.ca.gov.

Trust and provenance 6 official sources · last verified 2 Oct 2026 to 4 Oct 2026 · not reviewed by a lawyer · 1 of 1 provision audit-grade · release 2026.10.05

Where this instrument's data comes from, how current it is, and what has and has not been checked. Each provision below has its own panel.

Official sources
Lanes
Binding law — in force 1
Verification
Sources last verified 4 Oct 2026; each provision states how.
Data release
Data release 2026.10.05, data as of 4 Oct 2026, schema 0.3.10.
Legal review
None of the 1 provision has been reviewed by a lawyer; no TwinEthos rule has been legally reviewed yet. Treat each as research to check against the official text; it is not legal advice. Open questions for counsel on them: 1.
Audit standard
1 of 1 provision audit-grade. The audit standard is TwinEthos's own quality bar for provenance, dates, applicability, detectors, fixtures, remediation and licences; it is not a legal review.
Detectors
1 detector, all experimental: written from the rule's text and not yet measured for precision on real code, so treat a hit as a lead to verify. Each provision lists its detectors' known limits.
Changes
  • 2026.10.05 (5 Oct 2026): 1 provision added

Each data release records which provisions changed; the full list is on Changes.

Binding law — in force AI-adjacent law

CCPA deletion and right-to-know requests reach AI systems that can output the consumer's personal information (California AB 1008)

Cal. Civ. Code 1798.140(v)(4) · official text · In force: applies since 1 Jan 2025 · California (US-CA)

Since 2025-01-01, CCPA personal information can exist in abstract digital formats, including compressed or encrypted files, metadata, or artificial intelligence systems that are capable of outputting personal information (Cal. Civ. Code 1798.140(v)(4), added by AB 1008, Stats. 2024, ch. 802). A business that receives a verifiable consumer request to delete must delete the consumer's personal information from its records, including those formats, and notify its service providers, contractors and the third parties it sold or shared it with (1798.105(a), (c)), subject to the exceptions of 1798.105(d); a request to know reaches the specific pieces of personal information collected about the consumer in the same formats (1798.110(a)-(b)). Detect deletion handlers that skip embeddings, vector stores, chat history, agent memory and provider-held files.

Trust and provenance not reviewed by a lawyer · audit-grade · source verified 4 Oct 2026 · release 2026.10.05
Lane
Binding law — in force In force: applies since 1 Jan 2025
Official source
Cal. Civ. Code 1798.140(v)(4) · captured 4 Oct 2026 · anchor hash (SHA-256) 63363a38cda2… · 12 more anchors in the data release
Verification
Quoted text found word for word in the captured official document (4 Oct 2026). Source last verified 4 Oct 2026: checked against the captured official document.
Data release
Data release 2026.10.05, data as of 4 Oct 2026, schema 0.3.10.
Legal review
Not reviewed by a lawyer. TwinEthos derived this rule from the official text it cites: treat it as research to check against that text; it is not legal advice. No TwinEthos rule has been legally reviewed yet. Open questions for counsel on this rule: 1.
Audit standard
Audit-grade: meets all 10 checks of the TwinEthos audit standard that apply to it. The audit standard is TwinEthos's own quality bar for provenance, dates, applicability, detectors, fixtures, remediation and licences; it is not a legal review.
Detectors

1 detector (code pattern), experimental: written from the rule's text and not yet measured for precision on real code, so treat a hit as a lead to verify.

Known limits:

  • Deletion fanned out through a queue or event bus to another service
  • Personal information memorised in fine-tuned model weights, which no store delete removes
  • Right-to-know exports that omit AI stores (no code pattern yet)

1 more known limit in the data release.

Who it applies to

  • Duty falls on: controller, processor
  • CCPA businesses (1798.140(d)) holding California consumers' personal information in AI systems capable of outputting it (models, embeddings, vector stores, agent memory, chat logs), and their service providers and contractors. In force since 2025-01-01 (AB 1008; the rights themselves since 2023-01-01). The CCPA's general exemptions (1798.145, 1798.146) are not captured, and whether information memorised in model weights must be removed from the model itself is for counsel.
  • Not covered:
    • Deletion is not required where keeping the information is reasonably necessary to complete the transaction or perform a contract, for security and integrity, to debug, to exercise free speech or another legal right, to comply with CalECPA, for qualifying research with informed consent, for solely internal uses reasonably aligned with the consumer's expectations, or to comply with a legal obligation (1798.105(d)(1)-(8))
    • Publicly available information, lawfully obtained truthful information of public concern, and deidentified or aggregate consumer information are not personal information (1798.140(v)(2)-(3))
    • A deletion notice to service providers, contractors and third parties is not required where it proves impossible or involves disproportionate effort (1798.105(c)(1))
  • Whether it applies depends on facts outside the code; a person has to decide.

The guard to add

Make the account-deletion handler also delete the person's vector entries, embeddings, chat history, agent memory and provider-stored files or conversations.

Extend the erasure path (DELETE /account, delete_user, the data-subject-request worker) so that after the primary records it deletes everything keyed to the person in AI stores: vector-store entries by id, metadata filter or per-user namespace, conversation and chat-history tables, agent memory and checkpoints, and files, vector-store files, threads or conversations held with the model provider. This requires writing the user id as metadata on every vector and recording every provider object id at creation, so the deletion can find them. Where a legal hold or retention exception applies, skip only the covered items and record the reason; log which stores were erased.

Where it goes: 1 application source code, 2 data models, 6 API calls and integrations.

What this provision adds:

  • Treat AI systems that can output the consumer's personal information (embeddings, vector stores, memory, chat logs, fine-tuning sets) as records the deletion request reaches.
  • Notify service providers and contractors (the model provider included) and every third party the data was sold or shared with to delete it, unless that proves impossible or involves disproportionate effort.
  • Include the specific pieces of personal information held in those AI formats in the response to a verifiable request to know.

Example (FastAPI + Chroma + OpenAI SDK), before:

@app.delete('/account')
def delete_account(user=Depends(current_user)):
    db.users.delete(user.id)
    return {'status': 'deleted'}

After:

@app.delete('/account')
def delete_account(user=Depends(current_user)):
    db.users.delete(user.id)
    collection.delete(where={'user_id': user.id})          # Chroma embeddings
    db.chat_messages.delete_for_user(user.id)              # conversation history
    for f in db.provider_files.for_user(user.id):
        client.files.delete(f.file_id)                      # files stored with OpenAI
    for c in db.provider_conversations.for_user(user.id):
        client.conversations.delete(c.conversation_id)
    erasure_log.record(user.id, stores=['chroma', 'chat', 'openai_files', 'openai_conversations'])
    return {'status': 'deleted'}

Control: Data erasure does not reach embeddings, vector stores or AI chat history. The same guard addresses 5 items with binding law in 5 jurisdictions. Engineering guidance, not legal advice.

Rule id ca-ab1008.consumer-requests-reach-ai-systems · review status: primary source derived

Informational data, not legal advice. Summaries are TwinEthos's own words and rules have not been reviewed by a lawyer: check the official text before relying on any of it. A guard addresses an item; adding it is not a statement that your code meets any law.