California · Senate Bill · 2025–2026 Regular Session
SB468
California SB 468 — High-risk artificial intelligence systems: duty to protect personal information

Status ● Failed Effective N/A Passage Likelihood N/A

WHAT THIS BILL REGULATES · 1 REQUIREMENT TYPE

How Is This Bill Enforced

Enforcement Authority
No designated private right of action created by this bill. Violations constitute a deceptive trade act or practice under the Unfair Competition Law (Bus. & Prof. Code § 17200 et seq.), enforceable by the Attorney General, district attorneys, county counsel, and city attorneys. The California Privacy Protection Agency is authorized to adopt implementing regulations but is not expressly designated as the enforcement authority for violations. The UCL permits private suits by persons who have suffered injury in fact and lost money or property as a result of unfair competition, but the bill itself does not independently create a private right of action.
Private Right of Action
No private right of action. Enforcement is exclusive to the designated authority.
Penalties
Violations are enforceable as deceptive trade acts or practices under the UCL (Bus. & Prof. Code § 17200 et seq.). UCL remedies include injunctive relief and restitution. Civil penalties of up to $2,500 per violation are available to public prosecutors under the UCL. The bill does not independently specify statutory damages, punitive damages, or attorney's fees.

What This Bill Requires

Verbatim statutory text on the left; plain-language analysis and a per-section checklist on the right. Numbered markers cross-link to the matching checklist row.

Statutory Text
Analysis & Obligations
Civ. Code § 1798.91.2
Definitions

(a)–(i) For purposes of this title, the following definitions shall apply: (a) "Artificial intelligenceArtificial intelligence"Artificial intelligence" has the same meaning as that term is defined in Section 11546.45.5 of the Government Code.Civ. Code § 1798.91.2(a)" has the same meaning as that term is defined in Section 11546.45.5 of the Government Code. (b) "BusinessBusiness"Business" has the same meaning as that term is defined in Section 1798.140.Civ. Code § 1798.91.2(b)" has the same meaning as that term is defined in Section 1798.140. (c) "ConsumerConsumer"Consumer" has the same meaning as that term is defined in Section 1798.140.Civ. Code § 1798.91.2(c)" has the same meaning as that term is defined in Section 1798.140. (d) "Covered deployerCovered deployer"Covered deployer" means a business that deploys a high-risk artificial intelligence system that processes personal information.Civ. Code § 1798.91.2(d)" means a businessBusiness"Business" has the same meaning as that term is defined in Section 1798.140.Civ. Code § 1798.91.2(b) that deploysDeploy"Deploy" means to put into effect or commercialize.Civ. Code § 1798.91.2(e) a high-risk artificial intelligence systemHigh-risk artificial intelligence system"High-risk artificial intelligence system" has the same meaning as "high-risk automated decision system," as that term is defined in Section 11546.45.5 of the Government Code.Civ. Code § 1798.91.2(g) that processesProcesses"Processes" or "processing" have the same meaning as "processing," as that term is defined in Section 1798.140.Civ. Code § 1798.91.2(i) personal informationPersonal information"Personal information" has the same meaning as that term is defined in Section 1798.140.Civ. Code § 1798.91.2(h). (e) "DeployDeploy"Deploy" means to put into effect or commercialize.Civ. Code § 1798.91.2(e)" means to put into effect or commercialize. (f) "DeployerDeployer"Deployer" means a person doing business in this state that deploys a high-risk artificial intelligence system.Civ. Code § 1798.91.2(f)" means a person doing businessBusiness"Business" has the same meaning as that term is defined in Section 1798.140.Civ. Code § 1798.91.2(b) in this state that deploysDeploy"Deploy" means to put into effect or commercialize.Civ. Code § 1798.91.2(e) a high-risk artificial intelligence systemHigh-risk artificial intelligence system"High-risk artificial intelligence system" has the same meaning as "high-risk automated decision system," as that term is defined in Section 11546.45.5 of the Government Code.Civ. Code § 1798.91.2(g). (g) "High-risk artificial intelligence systemHigh-risk artificial intelligence system"High-risk artificial intelligence system" has the same meaning as "high-risk automated decision system," as that term is defined in Section 11546.45.5 of the Government Code.Civ. Code § 1798.91.2(g)" has the same meaning as "high-risk automated decision system," as that term is defined in Section 11546.45.5 of the Government Code. (h) "Personal informationPersonal information"Personal information" has the same meaning as that term is defined in Section 1798.140.Civ. Code § 1798.91.2(h)" has the same meaning as that term is defined in Section 1798.140. (i) "ProcessesProcesses"Processes" or "processing" have the same meaning as "processing," as that term is defined in Section 1798.140.Civ. Code § 1798.91.2(i)" or "processing" have the same meaning as "processing," as that term is defined in Section 1798.140.

Section 1798.91.2 establishes the definitional framework for the new title. It incorporates by reference existing definitions from the CCPA (business, consumer, personal information, processing) and from Government Code § 11546.45.5 (artificial intelligence, high-risk automated decision system). The key new defined term is covered deployer — a business that deploys a high-risk AI system processing personal information — which is the entity on whom the bill's information security obligations fall.

Civ. Code § 1798.91.3
Duty to protect personal information; comprehensive information security program
Deployer

(a) 1 A covered deployerCovered deployer"Covered deployer" means a business that deploys a high-risk artificial intelligence system that processes personal information.Civ. Code § 1798.91.2(d) conducting businessBusiness"Business" has the same meaning as that term is defined in Section 1798.140.Civ. Code § 1798.91.2(b) in this state shall have a duty to protect personal informationPersonal information"Personal information" has the same meaning as that term is defined in Section 1798.140.Civ. Code § 1798.91.2(h) held by the covered deployerCovered deployer"Covered deployer" means a business that deploys a high-risk artificial intelligence system that processes personal information.Civ. Code § 1798.91.2(d) as provided by this section.

(b) 1 A covered deployerCovered deployer"Covered deployer" means a business that deploys a high-risk artificial intelligence system that processes personal information.Civ. Code § 1798.91.2(d) whose high-risk artificial intelligence systemsHigh-risk artificial intelligence system"High-risk artificial intelligence system" has the same meaning as "high-risk automated decision system," as that term is defined in Section 11546.45.5 of the Government Code.Civ. Code § 1798.91.2(g) process personal informationPersonal information"Personal information" has the same meaning as that term is defined in Section 1798.140.Civ. Code § 1798.91.2(h) shall develop, implement, and maintain a comprehensive information security program that is written in one or more readily accessible parts and contains administrative, technical, and physical safeguards that are appropriate for all of the following: (1) The covered deployerCovered deployer"Covered deployer" means a business that deploys a high-risk artificial intelligence system that processes personal information.Civ. Code § 1798.91.2(d)'s size, scope, and type of businessBusiness"Business" has the same meaning as that term is defined in Section 1798.140.Civ. Code § 1798.91.2(b). (2) The amount of resources available to the covered deployerCovered deployer"Covered deployer" means a business that deploys a high-risk artificial intelligence system that processes personal information.Civ. Code § 1798.91.2(d). (3) The amount of data stored by the covered deployerCovered deployer"Covered deployer" means a business that deploys a high-risk artificial intelligence system that processes personal information.Civ. Code § 1798.91.2(d). (4) The need for security and confidentiality of personal informationPersonal information"Personal information" has the same meaning as that term is defined in Section 1798.140.Civ. Code § 1798.91.2(h) stored by the covered deployerCovered deployer"Covered deployer" means a business that deploys a high-risk artificial intelligence system that processes personal information.Civ. Code § 1798.91.2(d).

(c)(1) 1 The comprehensive information security program required by subdivision (a) shall meet all of the following requirements: (1) The program shall incorporate safeguards that are consistent with the safeguards for the protection of personal informationPersonal information"Personal information" has the same meaning as that term is defined in Section 1798.140.Civ. Code § 1798.91.2(h) and information of a similar character under state or federal laws and regulations applicable to the covered deployerCovered deployer"Covered deployer" means a business that deploys a high-risk artificial intelligence system that processes personal information.Civ. Code § 1798.91.2(d).

(c)(2) 2 The program shall include the designation of one or more employees of the covered deployerCovered deployer"Covered deployer" means a business that deploys a high-risk artificial intelligence system that processes personal information.Civ. Code § 1798.91.2(d) to maintain the program.

(c)(3) 3 The program shall require the identification and assessment of reasonably foreseeable internal and external risks to the security, confidentiality, and integrity of any electronic, paper, or other record containing personal informationPersonal information"Personal information" has the same meaning as that term is defined in Section 1798.140.Civ. Code § 1798.91.2(h), and the establishment of a process for evaluating and improving, as necessary, the effectiveness of the current safeguards for limiting those risks, including by all of the following: (A) Requiring ongoing employee and contractor education and training, including education and training for temporary employees and contractors of the covered deployerCovered deployer"Covered deployer" means a business that deploys a high-risk artificial intelligence system that processes personal information.Civ. Code § 1798.91.2(d), on the proper use of security procedures and protocols and the importance of personal informationPersonal information"Personal information" has the same meaning as that term is defined in Section 1798.140.Civ. Code § 1798.91.2(h) security. (B) Mandating employee compliance with policies and procedures established under the program. (C) Providing a means for detecting and preventing security system failures.

(c)(4)–(6) 3 The program shall include security policies for the covered deployerCovered deployer"Covered deployer" means a business that deploys a high-risk artificial intelligence system that processes personal information.Civ. Code § 1798.91.2(d)'s employees relating to the storage, access, and transportation of records containing personal informationPersonal information"Personal information" has the same meaning as that term is defined in Section 1798.140.Civ. Code § 1798.91.2(h) outside of the covered deployerCovered deployer"Covered deployer" means a business that deploys a high-risk artificial intelligence system that processes personal information.Civ. Code § 1798.91.2(d)'s physical businessBusiness"Business" has the same meaning as that term is defined in Section 1798.140.Civ. Code § 1798.91.2(b) premises. (5) The program shall provide disciplinary measures for violations of a policy or procedure established under the program. (6) The program shall include measures for preventing a terminated employee from accessing records containing personal informationPersonal information"Personal information" has the same meaning as that term is defined in Section 1798.140.Civ. Code § 1798.91.2(h).

(c)(7) 4 The program shall provide policies for the supervision of third-party service providers that include both of the following: (A) Taking reasonable steps to select and retain third-party service providers that are capable of maintaining appropriate security measures to protect personal informationPersonal information"Personal information" has the same meaning as that term is defined in Section 1798.140.Civ. Code § 1798.91.2(h) consistent with applicable law. (B) Requiring third-party service providers by contract to implement and maintain appropriate security measures for personal informationPersonal information"Personal information" has the same meaning as that term is defined in Section 1798.140.Civ. Code § 1798.91.2(h).

(c)(8)–(9) 3 The program shall provide reasonable restrictions on physical access to records containing personal informationPersonal information"Personal information" has the same meaning as that term is defined in Section 1798.140.Civ. Code § 1798.91.2(h), including by requiring the records containing the data to be stored in a locked facility, storage area, or container. (9) The program shall include regular monitoring to ensure that the program is operating in a manner reasonably calculated to prevent unauthorized access to or unauthorized use of personal informationPersonal information"Personal information" has the same meaning as that term is defined in Section 1798.140.Civ. Code § 1798.91.2(h) and, as necessary, upgrading information safeguards to limit the risk of unauthorized access to or unauthorized use of personal informationPersonal information"Personal information" has the same meaning as that term is defined in Section 1798.140.Civ. Code § 1798.91.2(h).

(c)(10) 5 The program shall require the regular review of the scope of the program's security measures that must occur subject to both of the following timeframes: (A) At least annually. (B) Whenever there is a material change in the covered deployerCovered deployer"Covered deployer" means a business that deploys a high-risk artificial intelligence system that processes personal information.Civ. Code § 1798.91.2(d)'s businessBusiness"Business" has the same meaning as that term is defined in Section 1798.140.Civ. Code § 1798.91.2(b) practices that may reasonably affect the security or integrity of records containing personal informationPersonal information"Personal information" has the same meaning as that term is defined in Section 1798.140.Civ. Code § 1798.91.2(h).

(c)(11) 6 The program shall require the documentation of responsive actions taken in connection with any incident involving a breach of security, including a mandatory postincident review of each event and the actions taken, if any, in response to that event to make changes in businessBusiness"Business" has the same meaning as that term is defined in Section 1798.140.Civ. Code § 1798.91.2(b) practices relating to protection of personal informationPersonal information"Personal information" has the same meaning as that term is defined in Section 1798.140.Civ. Code § 1798.91.2(h).

(c)(12) 7 The program shall, to the extent feasible, include all of the following procedures and protocols with respect to computer system security requirements or procedures and protocols providing a higher degree of security, for the protection of personal informationPersonal information"Personal information" has the same meaning as that term is defined in Section 1798.140.Civ. Code § 1798.91.2(h): (A) The use of secure user authentication protocols that include all of the following features: (i) The control of user login credentials and other identifiers. (ii) The use of a reasonably secure method of assigning and selecting passwords or using unique identifier technologies, which may include biometrics or token devices. (iii) The control of data security passwords to ensure that the passwords are kept in a location and a format that do not compromise the security of the data the passwords protect. (iv) The restriction of access to only active users and active user accounts. (v) The blocking of access to user credentials or identification after multiple unsuccessful attempts to gain access. (B) The use of secure access control measures that include both of the following: (i) The restriction of access to records and files containing personal informationPersonal information"Personal information" has the same meaning as that term is defined in Section 1798.140.Civ. Code § 1798.91.2(h) to only employees or contractors who need access to that personal informationPersonal information"Personal information" has the same meaning as that term is defined in Section 1798.140.Civ. Code § 1798.91.2(h) to perform the job duties of the employees or contractors. (ii) The assignment of a unique identification and a password to each employee or contractor with access to a computer containing personal informationPersonal information"Personal information" has the same meaning as that term is defined in Section 1798.140.Civ. Code § 1798.91.2(h), that may not be a vendor-supplied default password, or the use of another protocol reasonably designed to maintain the integrity of the security of the access controls to personal informationPersonal information"Personal information" has the same meaning as that term is defined in Section 1798.140.Civ. Code § 1798.91.2(h). (C) The encryption of both of the following: (i) Transmitted records and files containing personal informationPersonal information"Personal information" has the same meaning as that term is defined in Section 1798.140.Civ. Code § 1798.91.2(h) that will travel across public networks. (ii) Data containing personal informationPersonal information"Personal information" has the same meaning as that term is defined in Section 1798.140.Civ. Code § 1798.91.2(h) that is transmitted wirelessly. (D) The use of reasonable monitoring of systems for unauthorized use of or access to personal informationPersonal information"Personal information" has the same meaning as that term is defined in Section 1798.140.Civ. Code § 1798.91.2(h). (E) The encryption of all personal informationPersonal information"Personal information" has the same meaning as that term is defined in Section 1798.140.Civ. Code § 1798.91.2(h) stored on laptop computers or other portable devices. (F) For files containing personal informationPersonal information"Personal information" has the same meaning as that term is defined in Section 1798.140.Civ. Code § 1798.91.2(h) on a system that is connected to the internet, the use of reasonably current firewall protection and operating system security patches that are reasonably designed to maintain the integrity of the personal informationPersonal information"Personal information" has the same meaning as that term is defined in Section 1798.140.Civ. Code § 1798.91.2(h). (G) The use of both of the following: (i) A reasonably current version of system security agent software that shall include malware protection and reasonably current patches and virus definitions. (ii) A version of a system security agent software that is supportable with current patches and virus definitions, and is set to receive the most current security updates on a regular basis.

(d) A violation of this section by a covered deployerCovered deployer"Covered deployer" means a business that deploys a high-risk artificial intelligence system that processes personal information.Civ. Code § 1798.91.2(d) constitutes a deceptive trade act or practice under the Unfair Competition Law (Chapter 5 (commencing with Section 17200) of Part 2 of Division 7 of the BusinessBusiness"Business" has the same meaning as that term is defined in Section 1798.140.Civ. Code § 1798.91.2(b) and Professions Code).

Section 1798.91.3 is the operative core of the bill. Subdivision (a) establishes the general duty. Subdivision (b) requires covered deployers to develop, implement, and maintain a comprehensive written information security program with administrative, technical, and physical safeguards scaled to the deployer's size, resources, data volume, and confidentiality needs. Subdivision (c) enumerates twelve specific program requirements — from employee designation and training to encryption protocols and breach response documentation — forming a detailed, prescriptive security standard. Subdivision (d) declares that violations constitute deceptive trade acts or practices under the UCL.

The program requirements closely track Massachusetts' data security regulation (201 CMR 17.00) and impose a level of specificity unusual for AI-specific legislation — including user authentication protocols, access control measures, firewall requirements, and malware protection standards.

Compliance actions 7 items
1
Covered deployersCovered deployer"Covered deployer" means a business that deploys a high-risk artificial intelligence system that processes personal information.Civ. Code § 1798.91.2(d) must develop, implement, and maintain a comprehensive written information security program containing administrative, technical, and physical safeguards appropriate to the deployerDeployer"Deployer" means a person doing business in this state that deploys a high-risk artificial intelligence system.Civ. Code § 1798.91.2(f)'s size, scope, and type of businessBusiness"Business" has the same meaning as that term is defined in Section 1798.140.Civ. Code § 1798.91.2(b); available resources; volume of data stored; and the security and confidentiality needs of the personal informationPersonal information"Personal information" has the same meaning as that term is defined in Section 1798.140.Civ. Code § 1798.91.2(h) stored. The program must incorporate safeguards consistent with protections for personal informationPersonal information"Personal information" has the same meaning as that term is defined in Section 1798.140.Civ. Code § 1798.91.2(h) under all applicable state and federal laws and regulations.
G-01.1
2
Covered deployersCovered deployer"Covered deployer" means a business that deploys a high-risk artificial intelligence system that processes personal information.Civ. Code § 1798.91.2(d) must designate one or more employees to maintain the comprehensive information security program.
G-01.6
3
Covered deployersCovered deployer"Covered deployer" means a business that deploys a high-risk artificial intelligence system that processes personal information.Civ. Code § 1798.91.2(d) must identify and assess reasonably foreseeable internal and external risks to the security, confidentiality, and integrity of records containing personal informationPersonal information"Personal information" has the same meaning as that term is defined in Section 1798.140.Civ. Code § 1798.91.2(h), and establish a process for evaluating and improving the effectiveness of current safeguards, including: (1) ongoing employee and contractor education and training on proper use of security procedures and the importance of personal informationPersonal information"Personal information" has the same meaning as that term is defined in Section 1798.140.Civ. Code § 1798.91.2(h) security; (2) mandating employee compliance with program policies and procedures; (3) providing a means for detecting and preventing security system failures; (4) security policies for storage, access, and transportation of personal informationPersonal information"Personal information" has the same meaning as that term is defined in Section 1798.140.Civ. Code § 1798.91.2(h) records outside businessBusiness"Business" has the same meaning as that term is defined in Section 1798.140.Civ. Code § 1798.91.2(b) premises; (5) disciplinary measures for program violations; (6) measures preventing terminated employees from accessing personal informationPersonal information"Personal information" has the same meaning as that term is defined in Section 1798.140.Civ. Code § 1798.91.2(h) records; (7) reasonable restrictions on physical access to personal informationPersonal information"Personal information" has the same meaning as that term is defined in Section 1798.140.Civ. Code § 1798.91.2(h) records including locked storage; and (8) regular monitoring to ensure the program prevents unauthorized access or use, with information safeguard upgrades as necessary.
G-01.1
4
Covered deployersCovered deployer"Covered deployer" means a business that deploys a high-risk artificial intelligence system that processes personal information.Civ. Code § 1798.91.2(d) must maintain policies for the supervision of third-party service providers that include: (1) taking reasonable steps to select and retain service providers capable of maintaining appropriate security measures for personal informationPersonal information"Personal information" has the same meaning as that term is defined in Section 1798.140.Civ. Code § 1798.91.2(h) consistent with applicable law, and (2) requiring service providers by contract to implement and maintain appropriate security measures for personal informationPersonal information"Personal information" has the same meaning as that term is defined in Section 1798.140.Civ. Code § 1798.91.2(h).
G-01.1
5
Covered deployersCovered deployer"Covered deployer" means a business that deploys a high-risk artificial intelligence system that processes personal information.Civ. Code § 1798.91.2(d) must conduct regular reviews of the scope of the program's security measures at least annually and whenever there is a material change in businessBusiness"Business" has the same meaning as that term is defined in Section 1798.140.Civ. Code § 1798.91.2(b) practices that may reasonably affect the security or integrity of records containing personal informationPersonal information"Personal information" has the same meaning as that term is defined in Section 1798.140.Civ. Code § 1798.91.2(h).
G-01.2
6
Covered deployersCovered deployer"Covered deployer" means a business that deploys a high-risk artificial intelligence system that processes personal information.Civ. Code § 1798.91.2(d) must document responsive actions taken in connection with any security breach incident, including a mandatory post-incident review of each event and any changes made to businessBusiness"Business" has the same meaning as that term is defined in Section 1798.140.Civ. Code § 1798.91.2(b) practices for the protection of personal informationPersonal information"Personal information" has the same meaning as that term is defined in Section 1798.140.Civ. Code § 1798.91.2(h) in response.
G-01.3
7
Covered deployersCovered deployer"Covered deployer" means a business that deploys a high-risk artificial intelligence system that processes personal information.Civ. Code § 1798.91.2(d) must, to the extent feasible, implement technical computer system security measures including: (1) secure user authentication protocols with login credential controls, reasonably secure password or unique identifier methods, password security controls, restriction to active users and accounts, and account lockout after multiple failed access attempts; (2) secure access controls restricting personal informationPersonal information"Personal information" has the same meaning as that term is defined in Section 1798.140.Civ. Code § 1798.91.2(h) access to employees and contractors who need it and assigning unique identification and passwords; (3) encryption of personal informationPersonal information"Personal information" has the same meaning as that term is defined in Section 1798.140.Civ. Code § 1798.91.2(h) transmitted across public networks, wirelessly, or stored on laptops and portable devices; (4) reasonable monitoring for unauthorized use of or access to personal informationPersonal information"Personal information" has the same meaning as that term is defined in Section 1798.140.Civ. Code § 1798.91.2(h); (5) reasonably current firewall protection and operating system security patches for internet-connected systems; and (6) reasonably current system security agent software with malware protection, patches, and virus definitions set to receive regular updates.
G-01.1
Civ. Code § 1798.91.4
Rulemaking authority

(a) Except as provided in subdivision (b), the California Privacy Protection Agency may adopt regulations pursuant to the Administrative Procedure Act (Chapter 3.5 (commencing with Section 11340) of Part 1 of Division 3 of Title 2 of the Government Code) to implement and administer this title.

(b) Notwithstanding subdivision (a), any regulation adopted by the California Privacy Protection Agency to establish fees authorized by this title shall be exempt from the Administrative Procedure Act (Chapter 3.5 (commencing with Section 11340) of Part 1 of Division 3 of Title 2 of the Government Code).

Section 1798.91.4 grants the California Privacy Protection Agency authority to adopt implementing regulations under the Administrative Procedure Act, with a carve-out exempting fee-establishing regulations from APA requirements. This is a standard delegation of rulemaking authority and does not itself impose compliance obligations on covered deployers.

Section 2
Legislative findings — CPRA furtherance

The Legislature finds and declares that this act furthers the purposes and intent of the California Privacy Rights Act of 2020 by ensuring consumersConsumer"Consumer" has the same meaning as that term is defined in Section 1798.140.Civ. Code § 1798.91.2(c)' rights, including the constitutional right to privacy, are protected by enabling and empowering Californians to request that covered deployersCovered deployer"Covered deployer" means a business that deploys a high-risk artificial intelligence system that processes personal information.Civ. Code § 1798.91.2(d) secure their high-risk artificial intelligence systemsHigh-risk artificial intelligence system"High-risk artificial intelligence system" has the same meaning as "high-risk automated decision system," as that term is defined in Section 11546.45.5 of the Government Code.Civ. Code § 1798.91.2(g) that process personal informationPersonal information"Personal information" has the same meaning as that term is defined in Section 1798.140.Civ. Code § 1798.91.2(h).

Section 2 is a legislative finding declaring that the bill furthers the purposes and intent of the California Privacy Rights Act of 2020 by enabling consumers to request that covered deployers secure their high-risk AI systems. This provision is required to authorize legislative amendment of CPRA provisions under CPRA's own amendment clause and creates no independent compliance obligation.

Passage Likelihood

Failed
Status Failed
Final action Returned to Secretary of Senate pursuant to Joint Rule 56.

Legislative History

2025-02-19 Introduced. Read first time. To Com. on RLS. for assignment. To print.
2025-02-20 From printer. May be acted upon on or after March 22.
2025-02-26 Referred to Com. on JUD.
2025-03-25 Set for hearing April 22.
2025-04-23 From committee: Do pass and re-refer to Com. on APPR. (Ayes 11. Noes 0. Page 835.) (April 22). Re-referred to Com. on APPR.
2025-04-25 Set for hearing May 5.
2025-05-05 May 5 hearing: Placed on APPR. suspense file.
2025-05-16 Set for hearing May 23.
2025-05-23 May 23 hearing: Held in committee and under submission.
2026-02-02 Returned to Secretary of Senate pursuant to Joint Rule 56.

Entry Last Reviewed

2026-05-04
AI generated