California Governor Gavin Newsom signed Assembly Bill 1159 into law on September 10, 2026, prohibiting education technology companies from using identifiable student data to train generative AI systems and extending student privacy protections from preschool through higher education. The measure, authored by Assemblymember Dawn Addis and sponsored by the Privacy Rights Clearinghouse, passed the Assembly with 70 ayes and 4 noes and the Senate unanimously, 32-0.
What the law does
AB 1159 amends California's K-12 Pupil Online Personal Information Protection Act (KOPIPA), originally enacted in 2014, and the Early Learning Personal Information Protection Act (ELPIPA). The core change is a new prohibition: operators cannot use 'covered information' to train a generative AI system or develop an AI system. Covered information includes a broad list of data types: email, name, home address, telephone number, demographics, discipline records, test results, grades, medical records, social security number, biometric data, disabilities, socioeconomic information, political affiliations, religious information, text messages, documents, search activity, photographs, voice recordings, and geolocation.
The bill also prevents operators from collecting or disclosing information about a pupil's reproductive or sexual health, immigration status, or sexual orientation or gender identity. It requires data minimization, meaning information can be retained only as long as reasonably necessary for the specific purpose it was collected. Students harmed by a violation may bring a civil action against the noncompliant operator, and must provide a copy of the complaint to the Attorney General within 10 days of filing.
A loophole closed
A key change in AB 1159 is the revision of how 'operator' is defined. Under existing law, according to the Legislative Counsel's Digest, an operator had to have actual knowledge that a site or service 'is used primarily for K-12 school purposes and was designed and marketed for K-12 school purposes.' AB 1159 removes the word 'primarily' and changes 'designed and marketed' to 'designed or marketed,' and also covers entities working on behalf of the operator. CalMatters reported that the earlier language allowed general-audience platforms like Google or YouTube to argue they were not primarily for students, even though their tools were widely used in classrooms. The new law is expected to affect major ed-tech providers such as Canvas and Duolingo, according to CalMatters.
Extending privacy to higher education
AB 1159 creates the Higher Education Student Information Protection Act (HESIPA), which applies KOPIPA-style and ELPIPA-style protections to students enrolled in higher education institutions. HESIPA becomes operative on July 1, 2027. The overall law takes effect January 1, 2027.
What the law does not do
The bill does not prohibit operators from using deidentified pupil information to improve educational products or demonstrate product effectiveness. It does not limit the ability of operators to use pupil data for adaptive learning or customized learning. General-audience websites not designed or marketed for school purposes remain exempt. The deidentification standards in the bill are consistent with those required under the federal Family Educational Rights and Privacy Act (FERPA).
The contested question of AI tools
Whether the new law will hinder AI-enabled educational tools is disputed. The Assembly Privacy and Consumer Protection Committee analysis reported that the College Board argued the prohibition on training generative AI with covered information would effectively bar California students and educators from access to educational tools that responsibly incorporate AI features. The committee's own analysis countered that the bill does not prohibit use of deidentified personal information for AI training, and questioned why that limitation would bar such tools.
The Privacy Rights Clearinghouse, the bill's sponsor, argued that once a company feeds student information into an AI model, the model has already learned from it and the data cannot be taken back, making AI training an irreversible data use that justifies prohibition.
How the law fits into existing frameworks
California's SB 1177, signed in 2014, was the first state law in the country to regulate ed-tech companies' use of student data. It prohibited targeted advertising, profiling, selling student information, and unauthorized disclosure, and required data security measures. AB 1159 expands that framework. The Assembly Privacy and Consumer Protection Committee analysis noted that the California Consumer Privacy Act (CCPA) provides additional protections for consumers of all ages regarding personal data collected by large for-profit businesses, but that CCPA, KOPIPA, and ELPIPA contain gaps and loopholes as technology advances. Federal COPPA requires companies to obtain parental consent for collecting personal information from children under 13, but does not address AI training or extend to higher education.
