1. When Do California ADMT Regulations Apply?
The rules apply when a business subject to the CCPA uses automated decisionmaking technology to make a significant decision concerning a consumer. The analysis focuses on what the system does with personal information and whether computation replaces or substantially replaces human decisionmaking. This is narrower than the broader range of systems addressed by Artificial Intelligence Law.
ADMT under the Final Regulations
ADMT is technology that processes personal information and uses computation to replace or substantially replace human decisionmaking. A system substantially replaces human decisionmaking when the business uses its output to make a decision without the human involvement required by the regulations. Profiling also falls within the definition when it replaces or substantially replaces human decisionmaking.
When Human Involvement Changes the Analysis
A human reviewer must know how to interpret and use the system's output, review the output and other relevant information, and have authority to make or change the decision. A nominal review step is not enough if the reviewer lacks one of those functions. Businesses should therefore examine the actual workflow and decision authority rather than relying on job titles or the mere presence of a person.
2. Significant Decisions Covered by the Rules
A significant decision provides or denies financial or lending services, housing, education enrollment or opportunities, employment or independent contracting opportunities or compensation, or healthcare services. Covered employment decisions include hiring, employee work allocation or assignment, compensation, promotion, demotion, suspension, and termination. Advertising to a consumer does not qualify as a significant decision under this definition.
3. Consumer Rights for Covered ADMT
Before covered ADMT use, a business must provide a Pre-use Notice explaining the specific purpose of the ADMT and the consumer's applicable opt-out and access rights. The notice must also provide or make available information about how the ADMT processes personal information, the type of output it generates, and how that output affects the significant decision. Requests to access ADMT require additional information about the business's use of the technology with respect to that consumer, adding a distinct layer to Privacy and Data Protection.
When an Opt-Out Exception Applies
Consumers generally have a right to opt out of ADMT used for a significant decision, but the regulations provide exceptions. One applies when the business offers a qualifying appeal to a human reviewer who can overturn the decision; separate exceptions cover certain admission, hiring, work-allocation, and compensation decisions when specified conditions are met. Businesses relying on an exception should determine which regulatory conditions apply rather than assuming that human review alone eliminates the opt-out requirement.
4. ADMT and Risk Assessment Requirements
Risk-assessment duties and Article 11 consumer rights are related but separate requirements. Using ADMT for a significant decision is one type of processing that triggers a risk assessment, which compares the privacy risks of the processing with its benefits. This analysis can be coordinated with broader Data Privacy Compliance procedures without treating the two regulatory duties as interchangeable.
Risk Assessment Timing
For covered processing started on or after January 1, 2026, the business must conduct and document the risk assessment before beginning that processing. Covered processing that began before that date and continues afterward has a transition rule requiring the assessment by December 31, 2027. Information for risk assessments conducted in 2026 and 2027 must first be submitted to the CPPA by April 1, 2028.
5. What Changes on January 1, 2027?
The regulations became effective January 1, 2026, but Article 11 gives businesses additional time to implement the ADMT requirements. A business using ADMT for a significant decision before January 1, 2027, must comply by that date; covered use on or after January 1, 2027, must comply whenever the business uses the ADMT for a significant decision. The distinction separates the regulations' effective date from the ADMT compliance deadline.
6. Determining Whether a System Is Covered

The starting question is not simply whether software uses artificial intelligence. A business should identify the personal information processed, the decision the system helps make, and whether that decision falls within a regulated category before examining the role of human review. If Article 11 applies, the next questions concern notice, access, opt-out rights and exceptions, along with any separate risk-assessment duties relevant to AI Legal Compliance.
A Practical Coverage Check
- Identify the personal information processed and the decision produced by the system.
- Determine whether the decision concerns a regulated financial, housing, education, employment, contracting, compensation, or healthcare outcome.
- Determine whether a human actually reviews relevant information and has authority to make or change the decision.
- Map the applicable notice, access, opt-out, exception, and risk-assessment requirements to the correct compliance date.
07 Oct, 2026

