The fight over California’s AB 2624 is not really about one YouTuber or one news cycle; it is a test of whether modern anti-doxxing and privacy statutes can be drafted tightly enough to protect people at risk without criminalizing or chilling the publication of truthful, lawfully obtained information—a category the First Amendment has long put at the core of public discourse.
The Short Version
- AB 2624 expands California’s Safe at Home address-confidentiality program and adds new online privacy protections for people who provide immigration-related services.
- A federal lawsuit led by Nick Shirley challenges AB 2624 as content-based, viewpoint-discriminatory, overbroad, and vague, arguing it chills lawful reporting about public-interest subjects.
- Legislative analyses frame the law as a targeted response to doxxing, with an intent-to-harm focus and an operative date in 2027, not as a blanket gag on journalism.
- The constitutional question sits on familiar First Amendment fault lines: when does a safety rule aimed at harassment become a speech restriction on newsworthy, true information?
What AB 2624 actually does, according to the record
On its face, AB 2624 has two pillars. First, it extends the state’s Safe at Home program—an address-confidentiality mechanism originally designed for survivors of domestic violence and other vulnerable groups—to designated immigration support services providers, employees, and volunteers who fear for their safety. Second, it extends existing online privacy protections by restricting the public posting or distribution of program participants’ personal information or images on websites and social media. These are not characterizations from campaign literature; they come from the Assembly and Senate committee analyses and the chaptered-bill summary. The law was chaptered in August 2026, with the address-confidentiality component slated to begin October 1, 2027.
That official framing matters for two reasons. It anchors the state’s case that the statute targets doxxing and the secondary effects of harassment, rather than suppressing disfavored viewpoints. And it sets the evidentiary table for litigation: courts start with text and legislative history, not slogans. The Los Angeles Times’ contemporaneous report, echoing the committee materials, emphasized shielding home addresses from public records and barring posts intended to incite violence against workers and volunteers at immigrant-aid organizations.
Why the law is being challenged as unconstitutional
Nick Shirley’s complaint in the Eastern District of California (Shirley v. Bonta) attacks the statute on four classic First Amendment grounds: content discrimination, viewpoint discrimination, overbreadth, and vagueness. Bloomberg Law’s summary distills the thrust: AB 2624 purportedly restricts speech based on subject matter (speech about a favored class of people and organizations), does so in a way that disfavors critics, sweeps in truthful, lawfully obtained information, and leaves speakers guessing what triggers liability. The filing also argues the chill extends to material already published and creates civil exposure for posting personal data like home addresses, phone numbers, employment history, and financial information about individuals associated with designated immigration-service organizations.
These are not idle labels. American courts have repeatedly treated content-based regulations of truthful publication with skepticism; even well-meaning privacy rules can falter if they punish the reporting of newsworthy facts absent a narrow, intent-focused tether to unprotected conduct such as true threats or incitement. Scholarly surveys of first-wave anti-doxxing laws conclude that many fail under established doctrine because they criminalize the dissemination of truthful information or hinge on vague standards that invite arbitrary enforcement.
The doctrinal hinge: intent, tailoring, and the scope of “personal information”
AB 2624’s fate will likely turn on three drafting choices. First, the statute’s mens rea—what must a plaintiff prove about the speaker’s intent? If liability attaches only when a defendant posts personal information with the specific purpose of causing imminent violence or serious harassment, the state’s case strengthens; if the standard is laxer or uses amorphous terms divorced from imminent harm, strict scrutiny becomes difficult to survive. The state’s public framing leans on an intent-to-incite-violence narrative, which, if reflected in the operative text and proven in application, is the narrow path such laws must walk.
Second, the definition of covered information. Address-confidentiality programs are uncontroversial when they shield home addresses in government files; they are constitutionally delicate when they penalize journalists or citizens for later truthfully publishing lawfully obtained data about people engaged in public-service or publicly funded work. The complaint characterizes covered “personal information” broadly—home addresses, phone numbers, employment history, financial data—raising the specter that ordinary watchdog reporting could trigger civil suits. Whether that breadth appears in the enacted definitions, and whether exemptions or safe harbors exist, is dispositive.
How we got here: the modern anti-doxxing impulse meets First Amendment bedrock
States are responding to real harms. Doxxing campaigns can escalate from online intimidation to physical danger, particularly for people tied to polarizing public functions. Legislatures have reached for speech restrictions because the harassers’ leverage is information itself. But the Supreme Court’s protection for the publication of truthful, lawfully obtained information—especially when it concerns matters of public concern—runs deep. The academic literature now chronicles a split response: some argue carefully drafted laws, aimed at the conduct of harassment via disclosure and calibrated by intent, can survive; others warn that even narrow statutes tend to sweep too broadly in practice, chilling investigative reporting and critical commentary about public institutions and their agents.
AB 2624 reflects this tension. Committee analyses describe a targeted program expansion for a defined class, with online posting limits keyed to safety; press-freedom critics fear that, in the real world, the combination of designation, expansive personal-data categories, and private rights of action will be deployed against journalists and activists scrutinizing organizations that receive public funds or shape public policy. Both dynamics are plausible; which one predominates depends on the text a court construes and how the state enforces it.
Where the evidence is strong—and where it is thin
On the state’s side, the record is specific: official committee analyses and a chaptered summary detail the program’s scope and timing, tying the bill to the Safe at Home infrastructure and to online privacy protections for a delineated cohort. That is credible, citable legislative evidence. On the challenger’s side, the complaint squarely alleges overbreadth, vagueness, and viewpoint bias and claims the law reaches truthful, lawfully obtained information; Bloomberg’s coverage captures those claims with fidelity. But at this phase, they are allegations, not findings; the suit has not yet generated a merits ruling or a preliminary injunction that would validate or reject those theories.
One empirical claim benefits from independent treatment: whether the law truly restricts publishing images and data irrespective of harmful intent. The state’s public-facing explanation emphasizes an intent-to-incite-violence element; if the text does the same, courts will scrutinize whether that intent requirement is real, provable, and cabined, not a malleable label that collapses into viewpoint policing. Conversely, if the complaint is right that coverage includes broad categories of truthful information with vague triggers, the statute is vulnerable under the very doctrines that have doomed earlier anti-doxxing efforts.
🚨 California just made it harder to follow the money—and easier to hide from scrutiny.
Nick Shirley is doing what journalists used to do: pulling public records, showing up at facilities, and asking whether taxpayer-funded “immigrant service” operations are clean.
AB 2624… https://t.co/ibneToY8tA
— Texas Ricky (@rmacdon627) September 5, 2026
What to watch as the case proceeds
Three developments will separate rhetoric from law. First, the precise enacted definitions, exceptions, and mens rea: the narrower and more incitement-like the trigger, the stronger the state’s defense; the broader and more ambiguous the sweep, the stronger the challenger’s overbreadth and vagueness claims. Second, the presence (or absence) of explicit safe harbors for journalism, academic research, and commentary on matters of public concern—either in the text or via construction by the courts. Third, the state’s enforcement posture before the operative date: cease-and-desist letters, takedown demands, or private suits will demonstrate whether the statute functions as a shield against targeted harassment or as a sword against watchdog speech.
Sources:
reclaimthenet.org, nypost.com, news.bloomberglaw.com, aflegal.org, rsc-pfluger.house.gov, spsf.senate.ca.gov, trackbill.com



