The Human Review Receipt
AI can recommend the firing. Your product proves a human actually thought before it happened.
California is about to create an oddly specific software requirement, and almost nobody is building for it.
On September 9, 2026, SB 947, the "No Robo Bosses Act of 2026," was enrolled and presented to Governor Gavin Newsom at 2 p.m. It cleared the Assembly 53-14 and the Senate 28-10. As of September 12, 2026, it isn't law. Newsom has until September 30 to sign or veto, and he vetoed a broader predecessor, SB 7, on October 13, 2025. If he signs, the new sections of the Labor Code become operative on July 1, 2027.
The enrolled text says an employer can't rely solely on an automated decision system, or ADS, to discipline or fire an employee. The more consequential clause covers the middle ground. If the employer "primarily relies upon an ADS output" to make a disciplinary or termination decision, it "shall direct a human to corroborate the decision using data that was collected or used to produce the ADS output or other relevant corroborating or supporting information." If that human can't corroborate the output, or concludes it is inaccurate, incomplete, or misleading, the employer may not use it.

The clause that creates a company sits a few lines later. When the employer informs the employee of the decision, it must hand over a separate, stand-alone written notice stating that an ADS was primarily relied upon, that a human reviewed and corroborated the output, whom to contact with questions, and that retaliation is prohibited. The employee gains the right to a "meaningful, objective description" of their own data the system used. And in an enforcement proceeding, once ADS use is demonstrated, the burden flips: the employer must prove it either didn't primarily rely on the system or complied with the corroboration and notice sections. Penalties run $500 per violation, enforced by the Labor Commissioner, the Attorney General, or local prosecutors. The bill creates no private right of action, so the exposure is regulatory.
"Human in the loop" has lived comfortably as a line in corporate AI policies for years. Under this text it becomes an evidentiary problem, and someone has to produce the proof.
The opportunity is Decision Receipt: a thin workflow layer that sits between the software recommending an adverse action and the HR system recording what eventually happened. It doesn't decide whether Sally gets fired. It proves what happened between "the system flagged Sally" and "Sally was fired." Everything about the business follows from that distinction, including why it beats building another AI governance dashboard. The short version first:
The money: Twenty adviser or embedded partners at $2,000 a month is $40,000 MRR before setup fees, and $1,500 to $3,000 readiness sprints fund the build. Nobody is selling this yet.
Inside:
• The five reviewer questions that beat a checkbox
• Hybrid pricing from $299 to $2,500 a month
• Eight-week MVP: manual receipts before code
• What to do if Newsom vetoes
The record nobody keeps
Companies are drowning in employee records. Performance reviews, attendance punches, call-center QA scores, warehouse pick rates, scheduling logs, customer ratings, fraud flags, GPS events, HR case files. Increasingly, algorithms turn those records into recommendations. What companies almost never have is a structured record of the human judgment that happened after the recommendation.
Take a workforce-management platform that flags a warehouse associate for repeated attendance violations. A manager opens the profile, sees four absences and a "recommend termination" banner, clicks approve, and forwards the case to HR. On paper that's human review. In practice it's a signature. Nobody recorded whether one absence was approved leave, whether the time clock went down that Tuesday, whether an accommodation request was pending, whether the manager looked at the raw punches or only the algorithm's summary, or whether the manager would have reached the same conclusion without the score on the screen. The software captured the result and lost the thinking, and the thinking is what Decision Receipt exists to capture.
SB 947 makes that gap expensive because the statute never says "put a person somewhere in the process." It says corroborate, using the underlying data, and stop if you can't. The worst possible implementation of this product is an "I reviewed this" checkbox. A rubber-stamp button produces a beautifully timestamped record that the company rubber-stamped the algorithm. The workflow has to make real review easier than fake review, or it produces evidence for the plaintiff.
The law got narrower, and that is the point
Newsom's SB 7 veto message complained the bill "imposes unfocused notification requirements on any business using even the most innocuous tools" and could stop employers from using systems that reward high performers. SB 947 came back with the pre-use notice stripped out and the operative language concentrated on discipline and termination. That's why it passed with room to spare, and it's the shape a founder should copy: the narrow bill survived, and the narrow product will too.

Two details in the enrolled text favor whoever builds the evidence layer. First, "primarily relies" is never defined. Employment counsel will read that ambiguity one way: document everything, because you'll be arguing about the word in front of the Labor Commissioner. Second, the burden shift means the employer's defense is literally a paper trail. An employer without contemporaneous corroboration records has no way to prove the human did the work.
The underlying problem also predates this bill. The Civil Rights Council's employment regulations on automated decision systems took effect October 1, 2025, and require covered employment records, including ADS data, to be retained for four years. Colorado rewrote its AI law on May 14, 2026; SB 26-189 takes effect January 1, 2027, requires a post-adverse-outcome disclosure within 30 days, an opportunity for "meaningful human review and reconsideration when commercially reasonable," and three years of compliance records, with penalties up to $20,000 per violation. The EU AI Act's high-risk regime for employment systems, now deferred to December 2, 2027, carries logging and human-oversight duties for deployers. Illinois took a lighter route with HB 3773, in force since January 1, 2026: notice to employees when AI is used in discipline or discharge decisions, plus civil rights liability for discriminatory effect, with no corroboration duty. The California, Colorado, and EU regimes end up demanding the same artifact, a record showing that a machine recommended and a person actually decided.
Who is already nearby
Every incumbent in the vicinity has audit logs, which is the reason audit logs can't be the moat. Credo AI sells enterprise AI inventory, policy, and audit-evidence infrastructure across models and agents. ServiceNow's employee-relations module already handles allegations, interviews, evidence, corrective actions, and approvals with case timelines. Workday is shipping AI inside HR while publishing thought leadership on why traceability matters as AI participates in workforce decisions. General workflow tools like Aproove record AI invocations, human decisions, and signatures in regulated review processes. Warden AI sells bias audits, continuous monitoring, and version-controlled audit trails aimed at hiring tools and jurisdictions like New York City and Colorado.

Look at where each of them stands relative to the decision. The governance platforms sit upstream, cataloging models. The bias auditors sit beside the model, testing outputs for disparate impact. The HRIS sits downstream, recording the outcome. Nobody owns the window in between, when a manager looks at a score and either does the corroboration or doesn't. The defensible claim is smaller and sharper than "responsible employment AI": the best adverse-employment-decision evidence protocol, mapped to changing AI employment law, packaged for the advisers and systems already in the room when the decision gets made. That protocol is the product. Who pays for it first is a question of channel.
The customer is whoever holds the risk for many employers
California had more than 1.8 million private-sector businesses in 2024, employing roughly 15.5 million people, with half of those jobs in health care and social assistance, accommodation and food service, retail, professional and technical services, and manufacturing. Those are the industries running attendance, scheduling, productivity, and QA software that produces exactly the scores and flags the bill covers. Nobody needs to invent a $50 billion TAM to justify this.
Unlock the Vault.
Join founders who spot opportunities ahead of the crowd. Actionable insights. Zero fluff.
“Intelligent, bold, minus the pretense.”
“Like discovering the cheat codes of the startup world.”
“SH is off-Broadway for founders — weird, sharp, and ahead of the curve.”