The California Privacy Protection Agency’s regulations on automated decision-making technology went through four years of drafting and came out substantially narrower than the drafts that were widely reported. If you are assessing exposure, the definitional section is where to start, because the majority of systems people expected to be caught are not.
What counts as ADMT after the narrowing
The rulemaking authority comes from Civil Code § 1798.185(a)(15) and (16), which direct the Agency to issue regulations on access and opt-out rights relating to businesses’ use of automated decision-making technology, on risk assessments, and on cybersecurity audits. The Agency’s board adopted the final text in July 2025, the Office of Administrative Law approved it in September 2025, and the regulations took effect on 1 January 2026. The Agency publishes the adopted text and the final statement of reasons at cppa.ca.gov.
The definition that survived is narrow in a specific way. ADMT means technology that processes personal information and uses computation to replace or substantially replace human decision-making. Earlier drafts also captured technology that “substantially facilitates” human decision-making, and that phrase was removed. The final text explains what replacement means: a business substantially replaces human decision-making when it uses the output to make a significant decision without human involvement.
“Human involvement” is not satisfied by a rubber stamp. The reviewer has to know how to interpret and use the output, has to actually review it and any other relevant information, and has to have authority to change the decision. A workflow in which a person clicks approve on a queue of model outputs, at a rate that makes review impossible, is not human involvement, and designing the review step so that it is genuine is the compliance work rather than the paperwork.
This is a description of a regulation, not legal advice, and the replacement-versus-facilitation line is exactly the kind of question where the answer depends on how your reviewers actually work rather than on how the process is documented. Take advice before concluding that a workflow is out of scope.
Two further exclusions matter. Behavioural advertising, which the drafts had treated as an ADMT use, is not in the final scope as such. And the regulations separately address using automated processing to infer characteristics from an applicant, student, employee or independent contractor, and using personal information to train ADMT or certain automated systems, each with its own notice consequences.
The closed list of significant decisions
The obligations only attach where the ADMT is used to make a significant decision, defined as one resulting in the provision or denial of financial or lending services, housing, education enrolment or opportunity, employment or independent contracting opportunities or compensation, or healthcare services. Read that list carefully against the equivalent lists elsewhere: it is shorter than the one in Virginia’s CDPA, which also names insurance and criminal justice, and it is not the same as Colorado’s “consequential decision” definition either. A single model deployed nationally can be in scope in one state and out of it in the next.
“Compensation” is the entry most often overlooked. A system that allocates shifts, sets piece rates, distributes work or determines a bonus is deciding compensation, which pulls a large class of workforce-management tooling into scope that was never thought of as hiring technology.
The pre-use notice
Where the rules apply, the business must give consumers a pre-use notice before using the ADMT. It has to be in plain language, presented in the way the business ordinarily interacts with the consumer, and it has to state the specific purpose for which the ADMT will be used — not a generic purpose, and not a list of every purpose the business might one day have.
The notice must also describe the consumer’s rights to opt out and to access information about the use, explain how to exercise them, and tell the consumer that the business cannot retaliate for exercising them. Critically, the notice must offer a plain-language explanation of how the ADMT works with respect to the consumer — its logic, including the key parameters that affect the output, and how those parameters are applied to reach the decision — either in the notice or through a link. “It uses machine learning” does not satisfy that, and neither does a trade-secret assertion covering the entire explanation: the regulations contemplate that a business withholding trade secrets still has to provide enough for the consumer to understand the basis of the decision.
The opt-out and its exceptions
The default is that a consumer may opt out of the use of ADMT for a significant decision about them, and the business must provide at least two methods of submitting the request, one of which reflects how it primarily interacts with consumers. But the exceptions are where the regime is actually designed, and there are three families of them.
- The human appeal exception. A business need not offer the opt-out if it instead provides a method for the consumer to appeal to a qualified human reviewer who has authority to overturn the decision. This is a genuine choice of architecture: you can build an opt-out route or an appeal route, and for most decision systems the appeal is cheaper and more useful to the consumer than a refusal to process.
- The evaluated-use exception. For admission, acceptance or hiring decisions, for allocation of work and compensation, and for work or educational profiling, the opt-out is not required where the business uses the ADMT solely for that purpose, has evaluated it for validity, reliability and fairness, and has implemented policies and procedures to ensure it works as evaluated. The evaluation is the price of the exception, and it has to exist before you rely on it.
- Security, fraud prevention and safety. Use of ADMT solely for these purposes, where it is necessary and proportionate, does not carry the opt-out.
Note that the exceptions relieve the opt-out, not the notice. A business relying on the evaluated-use exception still tells consumers what it is doing.
The access right, and the assessment timeline
The access right is the provision with the sharpest engineering consequences. On request, a business must tell the consumer that it used ADMT to make a significant decision about them, the specific purpose, the output with respect to that consumer, how the business used the output including the role of any human, and a plain-language description of how the logic was applied to them — including the key parameters and how they applied to that consumer. Where the output is a score or a rank, the range of possible outputs and the consumer’s position within it are part of the answer.
Answering that request is a records question before it is a legal one. A per-decision record has to survive that ties the consumer to the model and model version that produced the output, the inputs and parameters used, and what a human did with it afterwards — and when a routing layer can silently move traffic between models, the version that produced a given output is only knowable if it was written down at the time. A gateway that records the model, version and parameters on every request, rather than only the aggregate, is what makes that answer reconstructable a year later; without it, the honest reply to an access request is that you do not know which model decided.
Running alongside ADMT are the risk assessment rules. A business whose processing presents significant risk to consumers’ privacy — which includes selling or sharing personal information, processing sensitive personal information, using ADMT for a significant decision, and using personal information to train ADMT or certain automated systems — must conduct and document a risk assessment before initiating the processing. The assessment must identify the purpose, the categories of personal information, the operational elements, the benefits, the negative impacts and the safeguards, and it must conclude on whether the benefits outweigh the risks as mitigated.
The timing is staged rather than immediate: assessments must be conducted for processing carried on from 2026 onward, with the first submission of attestations and abridged assessments to the Agency due in 2028, and cybersecurity audit obligations phased in by revenue over the following years. Confirm the exact dates against the adopted text, because they were amended during the rulemaking and secondary sources still circulate the draft dates.
Compliance dates in this rulemaking moved more than once between draft and adoption. Treat any date here as a prompt to check the Agency’s published text, and take advice on your own timeline.
Top comments (0)