Skip to content

California AI readiness

California ADMT requirements: decisions, rights and readiness

This page covers the selected CPPA ADMT provisions in the retained source. It does not determine whether a particular business, system or decision is covered.

Current as of 2026-09-26. Selected CPPA ADMT provisions; compliance begins January 1, 2027. General information, not legal advice.

California's final privacy regulations create notice, access and opt-out rights for specified uses of automated decisionmaking technology. Covered businesses using ADMT for a significant decision must comply beginning January 1, 2027. Sources: CPPA final rulemaking page; CPPA approved regulations.

What counts as ADMT?

The regulation defines ADMT as technology that processes personal information and uses computation to replace human decisionmaking or substantially replace it. Substantial replacement means the business uses the output to make a decision without qualifying human involvement. A human must know how to interpret the output, review the output and other relevant information, and have authority to make or change the decision. Sources: CPPA approved regulations.

This makes workflow evidence important. A label such as "human in the loop" proves little. The business needs to show what the reviewer sees, what the reviewer does and whether the reviewer can change the result.

Which decisions are covered?

The final regulation defines a significant decision to include specified decisions about:

  • financial or lending services
  • housing
  • education enrollment or opportunities
  • employment or independent contracting opportunities or compensation
  • healthcare services

The definition includes particular decisions within those areas and excludes advertising. Use the regulatory text rather than assuming that every consequential decision falls within it. Sources: CPPA approved regulations.

Which organizations are covered?

The ADMT article applies to a business subject to the CCPA that uses ADMT to make a significant decision concerning a consumer. Applicability depends on the regulation's defined actors, processing and decisions and on the facts of the particular use. Sources: CPPA approved regulations.

What does a covered business have to do?

Provide a pre-use notice

The notice must be prominent and provided before the covered processing. It must explain the specific purpose, the consumer's rights, how the ADMT processes personal information, the type of output and how the output affects the decision. Sources: CPPA approved regulations.

Support access requests

The business must give a verified consumer plain language information about the purpose, logic, output and role of the ADMT in the decision. The response must be specific enough to explain what happened to that consumer, subject to regulatory limits for trade secrets, security and safety. Sources: CPPA approved regulations.

Support an opt-out or a valid exception

The rule generally requires an opt-out. Exceptions include a process that allows the consumer to appeal to a qualified human reviewer who can overturn the decision, plus narrower exceptions for specified admission, hiring, work allocation and compensation decisions when the regulatory conditions are met. Sources: CPPA approved regulations.

An appeal is an operating process, not a link on a page. The reviewer needs access to relevant information, must understand the output, must consider information from the consumer and must have authority to change the decision.

Connect ADMT work to risk assessments

The separate risk assessment article covers listed processing activities and contains additional requirements for covered uses of ADMT. New covered processing started on or after January 1, 2026 requires an assessment before it begins. Continuing processing that started earlier must be assessed by December 31, 2027. Sources: CPPA approved regulations.

What should organizations do before January 1, 2027?

  1. Inventory systems used in significant decisions, including vendor features embedded in larger platforms.
  2. Confirm CCPA business status for each legal entity and record the legal analysis.
  3. Map personal information, outputs, downstream decisions and actual human involvement.
  4. Decide whether the organization will offer an opt-out, rely on a qualified human appeal or use another narrow exception.
  5. Draft notices from the real workflow and system records.
  6. Build request, verification, appeal and response processes with owners and service levels.
  7. Amend vendor terms and technical interfaces so the business can retrieve required information and carry out requests.
  8. Test the full process with sample consumers and decisions before the deadline.

This sequence is an Intelligence Coalition readiness recommendation, not text from the regulation.

Evidence to prepare

  • system and use case inventory
  • CCPA entity and applicability analysis
  • decision workflow showing the ADMT output and each human action
  • data categories and system logic documentation
  • approved pre-use notice for each purpose
  • opt-out and appeal design decisions
  • reviewer training, authority and test results
  • consumer request logs and response records
  • risk assessment and approval records
  • vendor contracts, data access terms and change notices
  • version history for the model, rules and decision process

What remains unsettled

The main uncertainty is often factual rather than textual. Organizations need to determine whether the technology actually replaces human decisionmaking, whether the decision fits the defined categories, which legal entity is the CCPA business and whether an exception's conditions operate in practice. Employment uses may also face the separate Civil Rights Council rules that took effect October 1, 2025. Sources: Civil Rights Council rulemaking actions.

Primary sources