California AB 1651 creates a narrow AI disclosure rule for the State Bar of California. Its broader lesson is operational: verification and disclosure answer different questions. Routine professional work needs evidence that the output was checked and owned. A high-stakes certification gate may also need a durable record that AI participated, even after a human reviewed the result.
Evidence reviewed: 27 August 2026. This article separates the enacted law from the operational framework derived from it. It is not legal advice.
TL;DR
- Governor Gavin Newsom signed AB 1651 on 22 August 2026. The new section becomes operative on 1 January 2028.
- The law applies to specified examination and study content developed by, or at the explicit direction of, the State Bar of California.
- Examination disclosures must appear on the State Bar website 60 days before the relevant exam. Study-material disclosures must appear on the cover page.
- Human revision or review does not remove the disclosure duty.
- AB 1651 does not create a general California business disclosure rule, and its enacted text contains no express monetary penalty or private right of action.
- Organizations can generalize the control pattern with two records: a Practice Ledger for verification and accountability, and a Gate Ledger for provenance and disclosure at authority-bearing release points.
What California AB 1651 actually requires
The enacted text adds Section 6060.15 to the California Business and Professions Code. It covers three State Bar examinations: the general bar examination, the first-year law students' examination, and the attorneys' examination.
The requirements are specific:
| Control question | Enacted answer |
|---|---|
| Who is regulated? | The State Bar of California |
| Which content is in scope? | Content developed by, or at the explicit direction of, the State Bar |
| Which examination assets are covered? | Questions, performance tests, answer keys, scoring rubrics, and content used in developing or administering the examinations |
| Which study assets are covered? | Sample or practice questions, model and selected answers, outlines, explanations, and other materials prepared, published, endorsed, or distributed by the State Bar |
| What counts as AI-generated content? | Visual or textual content generated in whole or in part by generative AI |
| Does human review remove the duty? | No. The rule applies regardless of natural-person revision or review |
| Where and when is exam disclosure made? | On the State Bar website 60 days before the examination |
| Where is study-material disclosure made? | On the cover page |
| When does the section become operative? | 1 January 2028 |
California already has a broader notice rule. Business and Professions Code Section 6046.6(e), effective since 1 January 2026, requires the Committee of Bar Examiners to provide notice when AI is used to create or grade bar-exam questions. AB 1651 adds operational detail for the covered State Bar content: a 60-day website deadline, cover-page disclosure for study materials, and an explicit rule that human review does not erase the trigger.
This is a provenance disclosure rule, not a ban on AI. It also has a deliberate knowledge boundary. During committee review, the State Bar raised the difficulty of disclosing AI use inside materials it did not create and could not observe. The bill was narrowed to content developed by, or at the explicit direction of, the State Bar.
That amendment converts an impossible assurance into a bounded one. The institution must disclose activity inside the production chain it controls. It is not forced to guess about an opaque upstream process.
The enacted section contains no express fine, dedicated enforcement procedure, or private right of action. The legal obligation is still real, but the text does not supply a complete enforcement architecture. Organizations adapting this pattern need to design their own evidence, escalation, and release controls.
The 2025 failure contained two separate evidence chains
AB 1651 followed the troubled February 2025 California bar examination. The Senate Judiciary Committee analysis records that 23 of the 171 scored multiple-choice questions were developed with AI by ACS Ventures. It also says this use was not reported to the Committee of Bar Examiners, the California Supreme Court, or the public.
The California State Auditor later resolved an apparent counting discrepancy. ACS Ventures used open-source generative AI to develop 29 of the 200 questions placed on the exam; 23 remained in the final set of 171 scored questions. The audit found that 45 percent of the AI-developed questions were flagged for statistical performance issues and 21 percent were removed from scoring. It also stated that using AI was not inherently problematic. The material failures were governance failures: rushed development, weak contractual safeguards, limited expert review, concentrated vendor roles, and decisions that were not escalated to governing bodies.
The California Supreme Court later approved scoring remedies while stating that it remained concerned about the processes used to draft the questions, including the previously undisclosed use of AI. It ordered a return to the Multistate Bar Examination for the July 2025 multiple-choice component while awaiting audits.
The same exam also suffered widespread delivery problems. The State Bar's 2025 annual report describes technological, environmental, proctoring, and organizational failures, followed by refunds, waivers, stipends, scoring remedies, and a restructuring of the Office of Admissions. In July 2026, Meazure Learning agreed to pay $5.25 million and waive a $1.36 million invoice to settle the State Bar's lawsuit over exam administration.
These facts belong in separate columns:
| Evidence chain | What it establishes | What it does not establish |
|---|---|---|
| Question-development records, legislative analysis, and court materials | AI participated in some scored questions, and that participation was previously undisclosed | That AI caused the exam platform failures |
| Exam-disruption records and the Meazure settlement | The administration suffered widespread failures and generated remediation costs | That the delivery vendor created the AI-developed questions |
Combining the chains produces a dramatic story and a weak causal claim. Keeping them separate produces a useful governance model: content provenance and delivery reliability are both material, and each needs its own evidence interface.
Two ledgers for two different promises
A single AI-used field cannot carry the full governance load. It leaves two different promises mixed together.
The first promise is about acceptable work: the output was checked, corrected, and approved by an accountable professional. The second promise is about institutional provenance: an artifact used to grant status, certify competence, or represent an official position was produced under a declared method.
The Practice Ledger
The Practice Ledger supports routine production. Its central question is: can the organization prove that the final output is fit for use?
Minimum fields include:
| Field | Evidence produced |
|---|---|
| Work item and final artifact version | Stable link between the record and the released output |
| AI system and use scope | Which system assisted with which task |
| Source boundaries | Approved inputs, prohibited data, and authoritative references |
| Verification method | Tests, source checks, calculations, peer review, or other independent checks |
| Corrections and unresolved exceptions | Where the AI output diverged from accepted evidence |
| Accountable approver | The human who understood and accepted the result |
This matches the State Bar's 2026 practical guidance for lawyers. It requires critical review, validation, and correction of AI inputs and outputs, and states that professional judgment remains the lawyer's responsibility. The control is stronger than a generic human reviewed checkbox because it records how the review could detect an error.
The Gate Ledger
The Gate Ledger supports authority-bearing events. Its central question is: can the organization prove how a certification artifact was produced and whether its provenance was disclosed under the applicable rule?
Minimum fields include:
| Field | Evidence produced |
|---|---|
| Gate and governed artifact | Exam, audit package, model card, official benchmark, hiring assessment, or other certification point |
| AI policy mode | Prohibited, permitted with verification, or permitted with disclosure |
| AI participation scope | Generated, revised, evaluated, scored, translated, or formatted |
| Disclosure trigger and rule version | Why disclosure applies, with an effective date |
| Publication surface and deadline | Website, cover page, filing, report, or release note |
| Institutional sign-off | Which role accepted the disclosure and release |
| Retained evidence | Input provenance, version IDs, review artifacts, notice copy, and publication proof |
AB 1651 requires only a narrow public disclosure for specified State Bar content. It does not prescribe this ledger. The Gate Ledger is an engineering pattern derived from the law's logic: review may establish quality while leaving provenance unchanged.
Why human review belongs in both ledgers
The phrase human in the loop often hides several different controls.
A reviewer can:
- read the output;
- verify claims against authoritative sources;
- reproduce calculations or tests;
- edit the artifact;
- assume professional responsibility; and
- approve a required disclosure.
Only the last five steps create useful evidence, and they still answer different questions. Verification can make an output reliable enough for use. Responsibility identifies who owns the decision. Disclosure preserves the origin history required at a gate.
AB 1651 makes this separation explicit. Human revision and review can improve a question, but they do not erase the statutory disclosure trigger. The 2026 professional guidance supplies the complementary rule for daily legal work: human judgment cannot be delegated, so review must be substantive enough to support accountability.
The two-ledger model therefore avoids two bad shortcuts:
- Disclosure alone proves that AI was used, but says little about output quality.
- Human approval proves ownership only when it is backed by a verification method, and it may leave a separate provenance duty intact.
A release gate an organization can run
Start by classifying artifacts, not job titles. The same employee may produce routine work in the morning and an authority-bearing artifact in the afternoon.
Use this release sequence:
- Classify the artifact. Is it routine production, a certification gate, or both?
- Bind the rule version. Record the policy and legal snapshot used for the decision.
- Capture AI participation. Record the system, task, materiality, and upstream uncertainty.
- Run independent verification. Use a test, source check, second calculation, peer review, or controlled comparison that can actually fail.
- Assign responsibility. Name the approver who understands the output and its remaining uncertainty.
- Evaluate disclosure. Apply the gate-specific trigger even when review succeeded.
- Publish and verify the notice. Check the real website, cover page, filing, or release artifact.
- Reconcile both ledgers. Every AI-use statement in the Gate Ledger should resolve to Practice Ledger evidence. A high-risk AI contribution found in the Practice Ledger without a corresponding gate decision should block release.
This framework complements two existing control patterns. The EU AI Act Article 50 evidence contract focuses on handoffs between providers and deployers. The independent evidence plane for AI safety controls focuses on retaining logs when enforcement changes. The two-ledger model focuses on the boundary between everyday production and institutional certification.
FAQ
Does California AB 1651 ban AI in the bar exam?
No. It requires disclosure for covered State Bar content that uses AI-generated material. Other rules or procurement terms may impose separate restrictions.
Does AB 1651 apply to every California company?
No. Section 6060.15 regulates the State Bar of California and specified examination and study content. The enterprise framework in this article is an operational inference, not a statement of the law's scope.
Does human review remove the disclosure requirement?
No. The enacted text says the duty applies regardless of whether a natural person revised or reviewed the AI-generated content.
Are materials made by third-party vendors covered?
The final scope turns on control, not the vendor label. Content developed at the State Bar's explicit direction is covered. The amendment avoids requiring the State Bar to make unsupported claims about independently developed content whose internal process it cannot observe.
When does Section 6060.15 become operative?
Governor Newsom signed the bill on 22 August 2026. Section 6060.15 becomes operative on 1 January 2028.
What should an organization record about AI-assisted certification content?
At minimum, record the governed artifact, AI participation, applicable rule, verification evidence, accountable approver, disclosure decision, publication location, deadline, and proof that the notice appeared in the released artifact.
References
- California Legislative Information: chaptered text of AB 1651
- California Business and Professions Code: existing Section 6046.6 notice rule
- Governor of California: legislation signed on 22 August 2026
- California Senate Judiciary Committee: AB 1651 analysis
- State Bar of California: petition concerning the February 2025 exam
- California Supreme Court order reproduced by the State Bar
- California State Auditor: audit of the February 2025 bar exam
- State Bar of California: 2025 admissions annual report
- State Bar of California: Meazure Learning settlement
- State Bar of California: 2026 Practical Guidance for generative AI