CAOC Forum - September/October 2026

Technology’s Effect on Advocacy

procurement standards for AI software, and strategies to ensure that AI does not exacerbate existing educational inequities. The statute is directed primarily to state and local educational authorities and serves as a governance framework rather than a source of substantive civil liability. It does not create a private right of action, although compliance with mandatory statutory duties may, in appropriate circumstances, be compelled through traditional public law remedies such as a writ of mandate. Long before California adopted AI-specific governance initiatives, it had already recognized the need to protect student data. In 2014, it enacted the Student Online Personal Information Protection Act ("SOPIPA"), one of the first state laws in the nation specifically regulating the collection and use of students' personal information by educational technology providers. SOPIPA prohibits operators of websites, online services, and applications designed for K–12 school purposes from using covered student information for non-educational purposes, including targeted advertising. Although SOPIPA imposes direct obligations on educational technology providers, it does not create an independent private right of action; instead, compliance is generally enforced by public authorities, and violations may, in appropriate circumstances, support derivative claims such as actions under California's Unfair Competition Law or other applicable common-law theories. Education Code section 49073.1 complements these protections by requiring contracts between educational agencies and third-party educational technology providers to preserve school ownership of pupil records, restrict unauthorized uses of student information, and impose significant privacy obligations regarding the handling and retention of student data. Rather than creating an independent

cause of action, the statute regulates the contractual relationship between schools and technology vendors, with compliance enforced primarily through contractual and administrative mechanisms, including contract invalidation. Together, these statutes do more than regulate data collection. They reflect a broader legislative judgement that safeguards should be built into educational technologies before harm occurs, rather than relying exclusively on remedies after the fact. California has therefore embraced an ex ante approach to protecting children in educational settings.

The Limits of AI Autonomy as a Legal Defense

California has also addressed an issue that will likely become increasingly significant as AI systems assume more autonomous functions: responsibility. Civil Code section 1714.46 expressly provides that, in an action alleging injury caused by artificial intelligence, a defendant who developed, modified, or used the AI may not assert as a defense that the artificial intelligence autonomously caused the plaintiff's injury. Rather than creating a new cause of action, the statute operates within existing civil claims by precluding AI autonomy as a defense while preserving traditional affirmative defenses, including causation, foreseeability, and comparative fault. Accordingly, California law makes clear that increasing AI autonomy does not displace traditional principles of civil responsibility. The legal inquiry remains focused on the conduct of the human actors who develop, modify, or use AI systems.

The Real Challenge: Injunctive Relief

While California law provides significant statutory protections governing artificial intelligence and student privacy, many of those protections operate

60

Consumer Attorneys of California

FORUM September/October 2026

Made with FlippingBook - Online catalogs