Signal SentryUpdated Oct 4, 16:30 UTCPM Drop
Laws · California

California CCPA rules on ADMT, risk assessments and cybersecurity audits

Regulations under the California Consumer Privacy Act. Businesses using automated decisionmaking technology for significant decisions about consumers must give pre-use notices and honor opt-out and access requests (from Jan 1, 2027). Businesses with high-risk processing must do risk assessments, and some must complete annual cybersecurity audits, with filings to the agency from 2028.

At a glance

In forceNext: ADMT rules apply to businesses using ADMT for significant decisions, Jan 1, 2027 (in 89 days).
Jurisdiction
California
Type
Regulation
Official title
CCPA Updates, Insurance, Cybersecurity Audits, Risk Assessments, and Automated Decisionmaking Technology (ADMT) Regulations (California Privacy Protection Agency)

What this means for you

If you build AI

  • If customers use your tool to make significant decisions about people, expect them to ask for what they need for pre-use notices, access and opt-out responses.

If you deploy AI

  • If you are a CCPA-covered business using ADMT for significant decisions, prepare pre-use notices, opt-out and access processes by Jan 1, 2027.
  • Run risk assessments for high-risk processing now; the first attestation and summary go to the agency by April 1, 2028.

If you use AI

  • From 2027 you should get notice before a covered business uses ADMT for a significant decision about you.
  • You can ask to opt out (with exceptions) and to get information about how the ADMT was used.

Key dates

  1. Jan 1, 2026PastRisk-assessment compliance beginsSource
  2. Jan 1, 2027in 89 daysADMT rules apply to businesses using ADMT for significant decisionsSource
  3. Apr 1, 2028in 545 daysRisk-assessment attestation and summary due; cybersecurity audit certification due (revenue over $100M)Source
  4. Apr 1, 2029in 910 daysCybersecurity audit certification due (revenue $50M to $100M)Source
  5. Apr 1, 2030in 1,275 daysCybersecurity audit certification due (revenue under $50M)Source

Status history

  1. Jan 1, 2026In forceAgency page also says it has no proposed regulation packages pending; later compliance dates belowSource
  2. Sep 23, 2025PassedDate the CPPA announced OAL approvalSource

In the Drops

No Drop has covered this law yet.