privacy

California AB 2013: What It Means for Your Personal Data

California's AI training data transparency law took effect January 2026. Here's what it requires companies to disclose — and what it still doesn't protect.

A new California law quietly took effect at the start of this year that, for the first time, requires companies building generative AI to publicly disclose what data they used to train their models. If your photos, documents, or personal content were scraped and fed into an AI system, the company responsible is now supposed to tell you — at least in broad strokes.

The law is California Assembly Bill 2013, formally called the Generative AI Training Data Transparency Act (TDTA). It’s not the sweeping privacy shield some hoped for, but it establishes a meaningful floor: users can now look up what categories of data trained the AI tools they use every day.

Here’s what it actually requires, where it falls short, and what you can do with the information it creates.

What AB 2013 Requires

The law applies to any developer of a “generative AI system or service” that is made available to the public and was trained using data collected after January 1, 2022. That covers the vast majority of AI products currently in use.

Covered companies must publish a high-level summary of their training datasets on their website. That summary must include:

  • The sources of the training data (was it web-scraped? licensed? user-contributed?)
  • The general categories of data used (text, images, audio, video, personal information)
  • Whether copyrighted material was included
  • Whether personal information — as defined under existing California law — was included
  • If personal information was used, a general description of the types involved

The disclosure must be posted before the AI system is made publicly available, and updated whenever a “substantial modification” is made to the model.

Why This Matters for Personal Photos and Files

Personal photos and documents are “personal information” under California law. Under AB 2013, if a company trained an AI model on user-uploaded images — say, photos users added to a cloud storage service — they are now supposed to disclose that personal information was included in training data.

This creates, for the first time, a mechanism for asking a direct question: did this company use my personal content to train their AI?

Before AB 2013, most terms of service were written to be permissive (“we may use your content to improve our services”) without ever explicitly stating that personal photos were included in AI training data. The disclosure requirement doesn’t stop that practice, but it forces companies to confirm or deny it in writing on their own website — a statement they’re legally accountable for.

What It Doesn’t Do

AB 2013 is a transparency law, not a consent law. Understanding the distinction matters.

It doesn’t require consent. Companies can still train on your personal information as long as they disclose it. The law doesn’t create a right to opt out of AI training, a right to have your data removed from a trained model, or a right to compensation for data use.

The disclosures are high-level. “Personal information” might appear in a disclosure, but the law doesn’t require the company to say how much, which users’ data, or what specific information was extracted. A company can disclose that personal information was used without specifying that it was your face used to improve their facial recognition system.

Enforcement is uncertain. California’s Attorney General is the primary enforcement mechanism. The law has no private right of action — individuals can’t sue directly for violations. Enforcement depends on regulatory priorities and resources.

xAI is already challenging it. Elon Musk’s AI company filed a federal lawsuit against the California Attorney General, arguing that the disclosure requirements constitute compelled speech and require revealing trade secrets in violation of the Fifth Amendment. If the challenge succeeds — which is far from certain but possible — the law’s reach could be narrowed before it has time to take effect meaningfully.

How to Use the Disclosures

Despite the limitations, AB 2013 creates actionable information for anyone paying attention.

Step 1: Find the disclosure. Every covered company should now have a training data transparency page somewhere on their website. Search for “[company name] AI training data disclosure” or look in the privacy policy section of the company’s site. Many have published dedicated pages under headings like “Transparency Report” or “AI Data Practices.”

Step 2: Look for personal information. If the disclosure mentions that personal information was used in training — particularly image data or user-generated content — that’s a signal worth investigating further.

Step 3: Check the dates. The disclosure requirement covers training data collected since January 1, 2022. If you’ve been a user of a platform since before that date, any data collection predating 2022 may not appear in disclosures. But if you’ve uploaded photos or documents to a service in the past few years, the relevant window is covered.

Step 4: File a complaint if the disclosure is missing or misleading. You can file a complaint with the California Attorney General’s office if a covered company hasn’t published the required disclosure, or if the disclosure appears materially incomplete. This isn’t a fast remedy, but complaints create a record.

What Other States Are Doing

California isn’t alone. A similar law took effect in New York, and Colorado and Texas have statutes requiring algorithmic disclosures that overlap with training data transparency in some contexts. The patchwork of state laws is pushing more companies toward publishing consistent national disclosures rather than maintaining state-by-state policies.

At the federal level, no equivalent law exists yet — though the American Privacy Rights Act, which has circulated in various drafts, includes AI training provisions. If a federal law passes, it would likely preempt or supersede the state laws, potentially raising or lowering the floor depending on the final text.

For now, California’s law is the most concrete transparency obligation in effect for AI training data in the United States.

What This Means When Choosing Where to Store Your Files

AB 2013 creates transparency obligations for companies that build AI products. It doesn’t create obligations for companies that simply store your files.

The more fundamental question isn’t “what does this AI company disclose?” — it’s “does the company holding my files ever share them with AI training pipelines?”

A storage service’s privacy policy is where this question gets answered. Look for explicit language about whether your content is used to train AI systems, whether it’s shared with third parties for model development, and whether opting out of AI features also opts you out of training data collection.

daftei’s position on this is explicit: your stored content is never used to train third-party AI models and is never sold to any party. That’s a policy commitment that sits outside the scope of AB 2013 — it’s not a disclosure about past training, it’s a current operational practice. The distinction matters because transparency laws tell you what happened; operational policies tell you what is happening now.

A Tool, Not a Shield

AB 2013 is worth taking seriously as a consumer tool. It’s the first law in the United States to require explicit disclosure of whether personal information was included in AI training data, and the disclosures it creates — if accurate and enforced — give users meaningful information they didn’t have before.

But transparency without consent is limited. Knowing your photos were used to train a model doesn’t un-train it, doesn’t remove your images from the dataset, and doesn’t create a financial claim. What it does create is accountability — and a basis for making more informed decisions about which services you continue to use.

If a company’s AB 2013 disclosure confirms that personal photos uploaded to their platform were included in AI training data, you now know that. What you do with that information is up to you.

Your memories deserve better than an ad platform.

Try daftei free →
← All posts