California lawmakers want to stop apps and operating systems from quietly switching your privacy choices back off. In May 2026, the California State Assembly unanimously passed AB 2561, a bill that would bar apps and operating systems from undoing a privacy setting a user already turned on, without asking first (Troutman Pepper Privacy + Cyber + AI Law Blog, May 18, 2026 update). The bill still needs Senate approval and the governor’s signature before it becomes law.
What Would AB 2561 Actually Require?
AB 2561 would do two things: lock in whatever privacy setting a user picks, and require the most protective option by default. Under the bill text, an operating system or application could not change a “privacy setting” — defined as any user-configurable option governing how an app collects, uses, shares, or retains personal information — without the user’s explicit, affirmative consent first.
The default-setting requirement is the more disruptive half for ad-supported software. Right now, plenty of apps ship with tracking and ad personalization on by default and ask users to dig through a menu to turn it off. AB 2561 would flip that: the most privacy-protective configuration would have to be the starting point, with looser settings requiring an opt-in.
Why Did Lawmakers Target Privacy Setting Resets?
Lawmakers are responding to a pattern where a privacy choice a user made once doesn’t reliably stay made. A setting flipped off during an app update, a redesign that quietly restores a default, or a policy change that re-enables tracking are all forms of the same problem: the user’s original decision gets overwritten without a fresh request for permission.
This is the kind of dark pattern that’s been increasingly hard to prove without a paper trail, since there is rarely a notification when a toggle reverts. AB 2561 addresses that by making any reset without consent a violation on its face, rather than something a regulator has to reconstruct after the fact.
The bill follows a string of California enforcement actions built on the same underlying complaint: that companies treat consent as a one-time checkbox instead of an ongoing choice. AB 2561 would close that gap directly in the statute, instead of leaving it to be argued case by case after the fact.
Why This Matters Beyond California
California privacy law tends to set the floor that other states and even national vendors build to, the same way the CCPA shaped opt-out mechanisms nationwide. A “settings can’t be reset without consent” rule, if it passes the Senate, would likely push software makers to rebuild settings architecture everywhere they operate, not just for California users, since maintaining two different consent models per state is rarely worth the engineering cost.
For browser extensions specifically, the bill underscores a distinction that’s easy to miss: software that stores your preferences on a company’s server can have those preferences changed remotely, intentionally or not. Software that never leaves your device can’t.
Practical Takeaways
- Check your settings after major app updates. A reset is easiest to catch right after a redesign or version bump.
- Prefer tools with no account and no cloud sync of preferences for anything privacy-sensitive — there’s nothing for a server to revert.
- Read changelogs for “privacy” or “ads” mentions before updating apps you rely on for tracking protection.
- Watch AB 2561’s progress if you’re in California — its fate in the Senate will signal whether other states follow.