California governor Gavin Newsom signed the most aggressive package of workplace AI protections in the country on 1 October 2026, and the workers who have been screaming about algorithmic management for years have been handed the first real legal weapon of their fight. The mechanics are blunt. Bosses can no longer fire a worker on an AI judgment alone. They cannot deploy systems that predict workers’ emotional states. They cannot collect neural data — the electrical signals from brains and nerves — without consent. They cannot surveil bathroom breaks. They must tell a worker when an AI-driven layoff is the reason she is out. That is not a wish list. That is statute.
And because the substance of these bans turns on what particular systems actually do, it is worth being precise about that, because the public discussion has the misleading habit of treating “the AI” as a decision-maker. It is not one. Take the case that drew the most attention: nurses at Kaiser Permanente reporting that systems rated the tone of their voices in patient interactions. A tone-of-voice scorer does not “hear” a nurse. It converts a window of audio into a spectrogram — a representation of acoustic energy across frequency bands over time — and passes that through a classifier trained on recordings that human raters had already labelled for qualities like warmth, frustration, or empathy. The features doing the work are prosodic: fundamental frequency (pitch) and its cycle-to-cycle instability, speech rate, the distribution and length of pauses, spectral tilt, energy contours. What the classifier never receives is context. It does not know that the patient was confused, that the nurse was interrupted, that the room was loud. And its output is typically a score and a confidence interval per interaction — an HR reviewer looking at “tone risk: 0.73” is not looking at a reason. The score is an aggregate of features nobody in the room chose to weigh, applied to a situation the model cannot see. That is what California’s ban on emotional-state prediction is actually aimed at, and naming the mechanism matters, because “the AI judged my attitude” is a different grievance, and a different remedy, than “a classifier scored the pitch contour of four minutes of audio.”
The same precision applies to the bathroom-break provisions, and here the point is that no camera is pointed at the stall. The inference is a by-product. In a warehouse, the raw material is operational telemetry already deployed for other reasons: badge and RFID door reads, handheld-scanner dwell times, and the metric Amazon has called “Time Off Task,” which aggregates the seconds between scans at a station. A break is inferred when the interval between scans crosses a threshold; “compliance” is a statistic computed over the distribution of those intervals. In an office, the raw material is keystroke and mouse telemetry, screenshot capture, meeting logs, badge reads — the same signals that Meta was tracking in the program it paused in June, reportedly to train its AI models. The bathroom inference is downstream of all of it, computed from logs the employer already holds. That is what makes it cheap to deploy and hard to see: the surveillance is a re-use, not an installation, and the statute is right to regulate the re-use.
Which brings the harder question the column owes you, because the notice requirement — telling a worker an AI made the call — sits at the end of a pipeline, and the pipeline is where the damage is done. A human resources process, at its best, is a sequence with records in it: a documented performance narrative, a manager conversation, an accommodation check where disability or medical leave is in play, progressive discipline, a second reviewer, a file. Each step is an appeal point. An AI-driven layoff pipeline looks different in ways that are structural, not cosmetic. Telemetry feeds a performance score. A threshold — frequently the vendor’s default configuration, not a number anyone validated locally — turns the score into a ranking. The ranking becomes a list. What is absent at each stage is the thing a record is made of: which signals were weighted and how; whether the human who “approved” the list was shown the inputs or only the output, and whether their approval was logged as a reasoned decision or as a single boolean; whether the model version that produced the score was retained anywhere. The Meta lawsuit filed in July by dozens of employees alleges precisely the failure this design produces — that the company’s AI tools targeted workers with disability accommodations or on medical and parental leaves for layoffs. That allegation makes technical sense, because an automated performance model has no representation of accommodation. It sees a distribution, and an accommodation looks like an absence of output.
So here is the argument the technology press keeps getting wrong, stated as precisely as I can state it. Management decides to shrink a payroll. What the model supplies is not the decision but the ranking that converts the decision into something that looks like a measurement — and, in the absence of audit logs, converts it into something no one can reconstruct afterward. The model was trained, in most cases, on labels derived from past human judgments, so it encodes past practice by construction. The confidence thresholds that decide who clears the cut are configuration values. The human-in-the-loop is often a review queue, not a review. Cory Doctorow’s term for the continuous, machine-speed adjustment of prices, rankings, and wages against individuals — twiddling — is the right word for the ambient version of this, but the firing pipeline is twiddling with a severance package attached, and the legal question is not whether the algorithm wanted it. It is whether anyone can still open the file and see what the score was made of.
The abuses these laws target are not hypothetical, and they are not a fringe concern. Amazon warehouse workers have complained for years about being timed on their breaks. Kaiser Permanente nurses have reported the tone scoring described above. Meta paused its computer-activity tracking in June and faced the lawsuit in July. These are not isolated anecdotes. They are a record — and California’s legislature just legislated across the whole of it. Veena Dubal’s term for the personalized, per-worker wage manipulation that per-ride and per-task platforms enable — algorithmic wage discrimination — describes the softer version of what a per-interaction tone score makes possible at the harder end, which is being rated out of a job for how your pitch contour sounded in a room full of sick people.
Annette Bernhardt of UC Berkeley’s Labor Center described the shift directly: “Workers are increasingly part of that movement, speaking up about the fear of job loss and the dehumanizing experience of being surveilled and controlled by an algorithm.” Lorena Gonzalez, president of the California Federation of Labor Unions, AFL-CIO, called it “a turning point… the first time we’re seeing California workers showing the country that we don’t have to accept this.” She has been helping leaders in Colorado, Connecticut, Illinois, and Texas draft similar protections — narrower in scope, pointed in the same direction. Those states have already passed narrower AI workplace laws; California’s move makes them a baseline rather than a frontier.
And because California is home to most of the largest AI developers on earth, a statutory floor there behaves like a national one. Companies do not build two versions of a workplace-scoring product, one for Sacramento and one for everywhere else; they build one product and route it through compliance. The federal vacuum on AI has been the enabling condition for every bad behavior these laws now foreclose. The single biggest obstacle to AI regulation has never really been industry lobbying, fierce as that is; it has been the absence of a working model. California’s law is now that model — with a coalition, a template, and a legislature that has already survived the fight.
There are limits, and they are not small. “The bills have no private enforcement,” said Robin Feldman of the AI Law & Innovation Institute at UC Law San Francisco. “In other words: workers can’t sue. Only the government can enforce the laws.” Government enforcement of workplace AI violations requires an apparatus California has not yet built, and enforcement that has to reconstruct what a model score was made of will need exactly the audit records the statute does not yet require employers to keep. That is the gap the next session should close, and it is a bigger gap than the framing suggests: a ban without a logging requirement is a ban that can be tested only at the point of firing, not at the point where the score was generated.
Opposition is already organizing, and its strongest version deserves a hearing. Danielle Ochs, a shareholder at the employment law firm Ogletree Deakins’ San Francisco office, worries the rules amount to “10 hoops you have to jump through per tool,” and that they could inadvertently prohibit benign applications like drowsiness detection for truckers. Drowsiness detection is not emotional-state prediction — it measures a physiological variable with an obvious safety purpose — and a statute that cannot distinguish the two has a drafting problem, not just an optics problem. But the concern should not become a pretext for gutting the framework, and here the counter-argument is the oldest one in this trade: if the law only restricted things companies already wanted to do, it would not be necessary. Compliance cost is the price of the absence of a standard, and the standard is what makes the cost fall over time.
For workers, the immediate rights are concrete: to know when an AI made the call, not to be emotionally profiled, not to be brain-scanned without consent, to use the bathroom without a scan-gap statistic filed against them. None of these are radical. They are the floor that any humane employer should have offered without being forced.
There is a version of this story where the piece ends on hope, and I will not write it. What I will say is that the pattern is older than the mechanism. The playbook — extract the surplus a workforce built, lock the workforce in by raising the cost of leaving, find the next class of suppliers and do it to them — is the playbook of every leveraged-buyout operator who took a Canadian heavy-industry asset between roughly 1985 and 2005. What is new is the instrument: telemetry in place of a spreadsheet, a classifier in place of a foreman’s judgment, and the disappearance of the paper trail that used to show what the foreman decided and why. California has not ended that. It has made the first jurisdiction to require that the paper trail be kept.
The majority won a round. The rest of the work is making the round stick — in the audit logs, in the next session, and in the states that are already drafting.