Compliance2026-09-119 min read

The First US Law That Makes Human Review a Legal Requirement

SB 947, the No Robo Bosses Act, passed the California Assembly by 53 votes to 14 on 30 August 2026 and cleared the Senate 28 to 10 the next day. Governor Newsom has until 30 September to sign or veto it. If signed, it becomes the first law in the United States to impose an enforceable human review requirement on automated decision systems, and it regulates the employer deploying the system rather than the company that built the model.

The California Legislature sent SB 947, the No Robo Bosses Act of 2026, to the desk of Governor Gavin Newsom at the end of August. The Assembly passed it on 30 August 2026 by 53 votes to 14, and the Senate concurred the following day by 28 votes to 10. The governor has until 30 September 2026 to sign or veto it, and the operative provisions are set to take effect on 1 July 2027. Most of the coverage has framed this as a story about artificial intelligence firing people, which is vivid and slightly misleading. The more useful framing is that this would be the first law in the United States to put a legally enforceable human in the loop requirement around an automated system, aimed squarely at the organisation deploying it rather than at the company that built the model.

The mechanics are worth reading rather than summarising from headlines. The bill defines an automated decision system as any computational process derived from machine learning, statistical modeling, data analytics or artificial intelligence that replaces human discretion in issuing scores, recommendations or decisions that significantly affect workers. That definition is deliberately broad, and nothing in it requires something that looks like a large language model. A scoring spreadsheet with a regression in it qualifies. So does a ticket triage system that ranks agent performance, and so does a productivity dashboard that flags people for review. The central prohibition is narrow by comparison: an employer may not rely solely on such a system to discipline or terminate a worker, and must apply human review with independent corroboration before acting on the output.

Around that core sit a set of flat prohibitions and a notice regime. Employers could not use an automated decision system to conduct predictive behaviour analysis, meaning predicting the behaviour, beliefs, intentions, personality or emotional state of a worker. They could not use one to infer protected characteristics such as race, religion or gender, nor to target workers for exercising legal rights, nor to set compensation from individualised worker data unless the differences are justified by cost differentials or task related factors. Where a system is used in a discipline or termination decision, the worker gets timely written post use notice in plain language, covering what the system was, what data it used, who the human reviewer was and how to reach them, along with a statement of protections against retaliation. Workers can also request their own system related data once a year.

The enforcement design is the part that will change behaviour, and it is easy to skim past. Three separate routes exist: the state labor commissioner, public prosecutors, and private lawsuits brought by workers themselves. Civil penalties are set at five hundred dollars per violation, with punitive damages and attorney fees available on top. Five hundred dollars is not a number that frightens anyone on its own, which is exactly why the private right of action matters more than the penalty schedule does. Regulators pick their battles and move slowly. Plaintiff firms do neither, and a post use notice requirement conveniently hands every affected worker a written document describing the system that contributed to the decision. That document is a discovery exhibit the employer wrote and delivered voluntarily.

Whether this becomes law is genuinely uncertain, and the drafting history is the best evidence available. The 2025 predecessor, SB 7, passed both chambers and was vetoed. The stated objections were that it imposed unfocused notification requirements on any business using even the most innocuous tools, and that it restricted how employers could use these systems too broadly. SB 947 was reintroduced in February 2026 with both objections addressed directly. Notice moved from before use to after use, so a business running ordinary software owes nobody a disclosure, and the restrictions were narrowed from a general limitation into a specific list of prohibited scenarios. That is a bill written to be signed. It is not a guarantee, and committing budget on the assumption of either outcome would be unwise, but the narrowing was plainly done with the veto message in hand.

For the audience this site serves, the important word in all of this is deployer. Nothing here regulates Anthropic, OpenAI or Google. It regulates the employer that wired something into a people process, and the population of such systems inside a typical company is far larger than the compliance function believes. This is the same enumeration problem we raised when the OWASP Agent Control Standard introduced the Agent Bill of Materials: the systems that cause trouble are the ones nobody registered. A workforce analytics view assembled in Bolt, v0 or Lovable by an operations manager who never thought of it as a system. A performance summary generated by ChatGPT or Claude and pasted into a review template. An internal service scaffolded with Cursor or Devin that scores support tickets and quietly became an input to quarterly performance ratings. None of those arrived through a governance process, and every one of them fits the statutory definition.

The framework mapping is more favourable than it first looks, which is the good news in an otherwise tedious week. If you already treat employment decisions as high risk under the EU AI Act, the Article 14 human oversight obligations and the Annex III employment category cover most of this ground, and the Annex IV technical file work we described recently produces much of the supporting evidence. The Colorado automated decision making technology rules, now in a comment period that closes on 26 October 2026 ahead of a target of 1 January 2027, point in the same direction. So does Australian Privacy Principle 1.7 on automated decision transparency, with its December 2026 date. ISO 42001 supplies the management system, the roles and the impact assessment discipline to hang it on, and SOC 2 answers whether the human review step actually operated over a period rather than existing only in a policy. Vanta, Drata, Secureframe, Sprinto, Thoropass and Hyperproof will all hold the register and schedule the reviews once somebody populates them. None of them will find the spreadsheet in the operations team.

The work is small if it starts now and expensive if it starts after a signature. List every place an automated or statistical output feeds a decision about a person, covering hiring, scheduling, performance rating, discipline and termination, and do it by asking the managers rather than by reading the system inventory. For each one, write down whether a human currently reviews the output, and be honest about whether that review is independent corroboration or a rubber stamp on a recommendation nobody ever overrides. Draft the post use notice now, because writing it is the fastest way to discover which systems you cannot actually explain. Check whether you log the human review step at all, since a requirement you cannot evidence is a requirement you have not met, and application logs written for humans rarely survive contact with a plaintiff firm. And if you employ anyone in California, put 30 September 2026 in the calendar as a decision point rather than a deadline, because the useful outcome of the next three weeks is knowing which of your systems would be in scope, not having rebuilt them.

SB 947No Robo Bosses ActCaliforniaautomated decision systemshuman oversightEU AI ActColorado ADMTISO 42001SOC 2AI governance

Editorial note: AES Tech reviews are independent. Some outbound links are affiliate links and are marked sponsored; they never change our rankings. See our disclosure.

// Signal, not noise

Get the next post by email

One short email when something worth knowing ships. No spam, unsubscribe anytime.

Loading comments...

Add a comment

Corrections and first-hand experience are the most useful things you can leave. Comments are screened automatically and reviewed by a human; see the moderation policy.

0/4000 · plain text · links are held for review

More from the blog