Binding law — in force AI-adjacent law
CCPA deletion and right-to-know requests reach AI systems that can output the consumer's personal information (California AB 1008)
Since 2025-01-01, CCPA personal information can exist in abstract digital formats, including compressed or encrypted files, metadata, or artificial intelligence systems that are capable of outputting personal information (Cal. Civ. Code 1798.140(v)(4), added by AB 1008, Stats. 2024, ch. 802). A business that receives a verifiable consumer request to delete must delete the consumer's personal information from its records, including those formats, and notify its service providers, contractors and the third parties it sold or shared it with (1798.105(a), (c)), subject to the exceptions of 1798.105(d); a request to know reaches the specific pieces of personal information collected about the consumer in the same formats (1798.110(a)-(b)). Detect deletion handlers that skip embeddings, vector stores, chat history, agent memory and provider-held files.
Trust and provenance not reviewed by a lawyer · audit-grade · source verified 4 Oct 2026 · release 2026.10.05
- Lane
- Binding law — in force In force: applies since 1 Jan 2025
- Official source
- Cal. Civ. Code 1798.140(v)(4) · captured 4 Oct 2026 · anchor hash (SHA-256)
63363a38cda2…· 12 more anchors in the data release - Verification
- Quoted text found word for word in the captured official document (4 Oct 2026). Source last verified 4 Oct 2026: checked against the captured official document.
- Data release
- Data release 2026.10.05, data as of 4 Oct 2026, schema 0.3.10.
- Legal review
- Not reviewed by a lawyer. TwinEthos derived this rule from the official text it cites: treat it as research to check against that text; it is not legal advice. No TwinEthos rule has been legally reviewed yet. Open questions for counsel on this rule: 1.
- Audit standard
- Audit-grade: meets all 10 checks of the TwinEthos audit standard that apply to it. The audit standard is TwinEthos's own quality bar for provenance, dates, applicability, detectors, fixtures, remediation and licences; it is not a legal review.
- Detectors
1 detector (code pattern), experimental: written from the rule's text and not yet measured for precision on real code, so treat a hit as a lead to verify.
Known limits:
- Deletion fanned out through a queue or event bus to another service
- Personal information memorised in fine-tuned model weights, which no store delete removes
- Right-to-know exports that omit AI stores (no code pattern yet)
1 more known limit in the data release.
Who it applies to
- Duty falls on: controller, processor
- CCPA businesses (1798.140(d)) holding California consumers' personal information in AI systems capable of outputting it (models, embeddings, vector stores, agent memory, chat logs), and their service providers and contractors. In force since 2025-01-01 (AB 1008; the rights themselves since 2023-01-01). The CCPA's general exemptions (1798.145, 1798.146) are not captured, and whether information memorised in model weights must be removed from the model itself is for counsel.
- Not covered:
- Deletion is not required where keeping the information is reasonably necessary to complete the transaction or perform a contract, for security and integrity, to debug, to exercise free speech or another legal right, to comply with CalECPA, for qualifying research with informed consent, for solely internal uses reasonably aligned with the consumer's expectations, or to comply with a legal obligation (1798.105(d)(1)-(8))
- Publicly available information, lawfully obtained truthful information of public concern, and deidentified or aggregate consumer information are not personal information (1798.140(v)(2)-(3))
- A deletion notice to service providers, contractors and third parties is not required where it proves impossible or involves disproportionate effort (1798.105(c)(1))
- Whether it applies depends on facts outside the code; a person has to decide.
The guard to add
Make the account-deletion handler also delete the person's vector entries, embeddings, chat history, agent memory and provider-stored files or conversations.
Extend the erasure path (DELETE /account, delete_user, the data-subject-request worker) so that after the primary records it deletes everything keyed to the person in AI stores: vector-store entries by id, metadata filter or per-user namespace, conversation and chat-history tables, agent memory and checkpoints, and files, vector-store files, threads or conversations held with the model provider. This requires writing the user id as metadata on every vector and recording every provider object id at creation, so the deletion can find them. Where a legal hold or retention exception applies, skip only the covered items and record the reason; log which stores were erased.
Where it goes: 1 application source code, 2 data models, 6 API calls and integrations.
What this provision adds:
- Treat AI systems that can output the consumer's personal information (embeddings, vector stores, memory, chat logs, fine-tuning sets) as records the deletion request reaches.
- Notify service providers and contractors (the model provider included) and every third party the data was sold or shared with to delete it, unless that proves impossible or involves disproportionate effort.
- Include the specific pieces of personal information held in those AI formats in the response to a verifiable request to know.
Example (FastAPI + Chroma + OpenAI SDK), before:
@app.delete('/account')
def delete_account(user=Depends(current_user)):
db.users.delete(user.id)
return {'status': 'deleted'}After:
@app.delete('/account')
def delete_account(user=Depends(current_user)):
db.users.delete(user.id)
collection.delete(where={'user_id': user.id}) # Chroma embeddings
db.chat_messages.delete_for_user(user.id) # conversation history
for f in db.provider_files.for_user(user.id):
client.files.delete(f.file_id) # files stored with OpenAI
for c in db.provider_conversations.for_user(user.id):
client.conversations.delete(c.conversation_id)
erasure_log.record(user.id, stores=['chroma', 'chat', 'openai_files', 'openai_conversations'])
return {'status': 'deleted'}Control: Data erasure does not reach embeddings, vector stores or AI chat history. The same guard addresses 5 items with binding law in 5 jurisdictions. Engineering guidance, not legal advice.
Rule id ca-ab1008.consumer-requests-reach-ai-systems · review status: primary source derived