The California Privacy Protection Agency adopted its regulations on automated decision-making technology, risk assessments and cybersecurity audits on 24 July 2025, and they completed the administrative approval process later that year. The ADMT provisions — Article 11 of the CCPA regulations — become operative on 1 January 2027.
That is four months and eleven days from the date of this article.
The obligations themselves are not especially complex. A business using ADMT to make a significant decision about a California consumer must provide a pre-use notice, must offer a right to opt out subject to three narrow exceptions, and must honour a right to access information about the ADMT’s use. Where an exception is relied upon, additional obligations attach — including, in the human-appeal exception, an actual human appeal.
What makes this deadline difficult is not the requirements. It is the scoping. Almost every organisation that has started this work has discovered that the hard part is finding out where ADMT is already in use, and that the answer is materially different from what the AI inventory says.
What the regulations actually say
The definition of ADMT
The regulations define automated decision-making technology as “any technology that processes personal information and uses computation to replace human decisionmaking or substantially replace human decisionmaking.”
Three things about this definition deserve attention.
It does not say “artificial intelligence.” It does not say machine learning, model, neural network, or algorithm. A deterministic rule engine that automatically declines an applicant when a field falls below a threshold is ADMT. A spreadsheet-driven scoring process that a system applies without human review is ADMT. The technology’s sophistication is irrelevant.
“Substantially replace” is the operative phrase. The CPPA’s position through the rulemaking was that human involvement does not remove a system from scope unless that involvement is meaningful — a human reviewer who has the authority, competence and information to change the outcome, and who actually exercises judgment. A human who clicks “approve” on a queue of system-generated recommendations at a rate of several hundred per hour is not substantially participating in the decision. This is the single most consequential interpretive point in the entire article, and it is where most organisations’ scoping goes wrong.
It is about processing personal information. A model that never touches personal information is outside the scope regardless of what it decides.
The definition of significant decision
Article 11 attaches only where ADMT is used to make a significant decision, which the regulations define as a decision resulting in the provision or denial of:
- financial or lending services
- housing
- education enrollment or opportunities
- employment or independent contracting opportunities or compensation
- healthcare services
Two boundaries matter here.
Advertising is not a significant decision. Profiling and targeting for marketing purposes alone does not trigger Article 11. Marketing teams reading the words “automated decision-making” and preparing for the worst can largely stand down — though targeted advertising remains subject to the separate CCPA opt-out regime.
The list is closed, but it is broad within its categories. “Employment or independent contracting opportunities or compensation” covers hiring, promotion, termination, scheduling, work allocation affecting earnings, and compensation-setting. That sweeps in a considerable amount of HR technology. “Healthcare services” covers utilisation management, prior authorisation, and care-pathway triage. “Financial or lending services” covers far more than credit decisions.
The pre-use notice
Before using ADMT for a significant decision, a business must provide a notice that states the specific purpose for which the ADMT is used and how the individual may exercise the applicable rights.
Usefully, the regulations permit the pre-use notice to be incorporated into the notice at collection, and permit consolidation across multiple ADMTs used for one or more purposes. That materially reduces the implementation burden — a single well-drafted section can cover an entire category of use.
The word “pre-use” is the constraint. The notice must reach the individual before the ADMT processes their personal information for that purpose. For an employment application flow, that means at the point of application, not in an offer letter. For a lending flow, at the point of application, not at decision.
The opt-out and its three exceptions
Businesses must provide the right to opt out of ADMT used for significant decisions, with at least two methods for submitting a request, at least one of which reflects the primary way the business interacts with consumers.
There are three exceptions to the opt-out:
- The human appeal exception. The business provides the ability to appeal the decision to a qualified human reviewer who has the authority to overturn it.
- The admission, acceptance or hiring exception — for ADMT used to assess an applicant’s ability to perform, in an initial hiring or admission context, provided specified conditions are met.
- The allocation or assignment of work exception — for ADMT used to allocate or assign work, again subject to conditions.
These are narrower than they first appear, and there is a critical point that is widely missed:
Relying on an exception does not remove the notice or access obligations. Even where an exception applies, the business must still provide the full pre-use notice and must still honour access requests. The exception removes the opt-out, and nothing else.
The human appeal exception in particular is not a paperwork exercise. It requires a reviewer who is qualified, who knows how to interpret and use the ADMT’s output, and who has authority to overturn the decision. An appeals process staffed by people who cannot in practice reverse the system’s output does not qualify — and an organisation that claims the exception on that basis has both an Article 11 violation and a documented misrepresentation.
The access right
Consumers may request information about the business’s use of ADMT with respect to them: the purpose, the output, and how the business used it in making the decision. Where the business relied on an exception, the response must reflect that.
This obligation is where technical debt becomes visible. Answering “what was the output of the model with respect to this individual, and how did we use it” requires decision-level logging — retention of the specific inputs, the specific output, and the specific role that output played in the decision, tied to an identifiable person, for as long as the access right may be exercised. Very few production ML systems log at that granularity. Most log aggregate metrics and sampled predictions.
The scoping problem
Here is the pattern that recurs in nearly every organisation that starts this work.
The privacy team asks the AI governance team for the AI inventory. The AI inventory has somewhere between five and forty entries, mostly generative AI pilots and a handful of named models. The privacy team maps those against the significant-decision categories and concludes the exposure is small.
Then somebody asks the harder question — “what systems currently produce an outcome in one of these five categories without a human meaningfully deciding?” — and the number goes up sharply, because the answer includes:
- Applicant tracking system knockout rules and ranking. Configured by HR, never registered as AI, frequently determinative in practice.
- Automated adverse action in lending and account opening. Often a decades-old rules engine.
- Insurance utilisation management and prior authorisation logic. Squarely within “healthcare services”.
- Automated scheduling and shift allocation. Within “employment… or compensation” where it affects earnings.
- Tenant screening. Within “housing”.
- Fraud and risk scores that auto-decline. Where declining denies a financial service.
- Student placement and admissions pre-screening. Within “education enrollment or opportunities”.
- Vendor-embedded scoring inside SaaS platforms that the business bought as workflow software and never assessed as a decision system.
None of these are typically in the AI inventory. All of them can be ADMT.
Scope from the decision, not from the technology. This is the single most useful piece of advice on this deadline. Start with the five significant-decision categories, enumerate every process in your organisation that produces one of those outcomes for a Californian, and then ask what role automation plays in each. Working from the technology inventory inward will systematically miss the rules engines, and the rules engines are where the exposure is.
How this connects to the risk assessment obligation
Article 11 does not stand alone. The same rulemaking created risk assessment obligations that applied from 1 January 2026, with initial assessments due by 31 December 2027 and information about assessments conducted in 2026 and 2027 to be submitted to the CPPA by 1 April 2028.
Using ADMT for a significant decision is a processing activity that triggers the risk assessment requirement. Which means an organisation that identifies ADMT in scope for the January 2027 deadline is simultaneously identifying processing that required a risk assessment starting in January 2026.
This site covered the CCPA risk assessment and executive attestation regime earlier this year. The attestation point is worth repeating here: the submission to the CPPA must be signed by a member of executive management who has authority to bind the business and who attests to the accuracy of the submission. Scoping errors in ADMT identification therefore propagate into a document that a named executive signs.
The cybersecurity audit obligations from the same rulemaking phase in separately, with certifications due to the CPPA by 1 April 2028 for businesses over $100 million in revenue, 1 April 2029 for $50–100 million, and 1 April 2030 below $50 million.
A four-month plan
September: scope from the decision. Enumerate every process producing a significant decision about a Californian. For each, document the automation involved, the degree of human participation, and — honestly — whether that human participation is substantial under the CPPA’s meaning. Include vendor-embedded logic. This is the deliverable everything else depends on, and it will take longer than expected.
October: decide the exception posture per system. For each in-scope system, decide whether you will offer the opt-out or rely on an exception. If relying on the human appeal exception, specify who the reviewer is, what training qualifies them, and what authority they have to overturn. Document the reasoning. Remember that exceptions do not relieve notice or access.
November: build notice and rights infrastructure. Draft the pre-use notice, consolidated where possible, and place it in the flows so it precedes processing. Build at least two opt-out submission channels, one matching your primary consumer interaction mode. Extend your existing DSAR intake to route ADMT access requests. Confirm decision-level logging is capturing what an access response requires — and if it is not, that is an engineering change with a lead time.
December: test the paths end to end. Submit a test opt-out through each channel and confirm it reaches the system that must honour it. Submit a test access request and confirm the response can be assembled within the CCPA response window. Run a test appeal and confirm the reviewer can actually reverse the outcome. Confirm the pre-use notice appears before processing, on mobile as well as desktop.
Throughout: line the risk assessments up behind it. Every ADMT you identify is a risk assessment you may already owe.
Why this deadline is worth taking seriously
The CPPA has spent 2026 demonstrating that it enforces. This site has covered the CPPA enforcement wave, the first CCPA compliance audits from the new Audits Division, the $1.275 million GM/OnStar data minimisation action, and the data broker enforcement under the Delete Act. This is not an agency that publishes rules and waits.
ADMT enforcement will also be unusually easy to initiate. Unlike a data minimisation theory, which requires an investigator to reason about necessity, an ADMT failure is externally visible: either the pre-use notice is present in the application flow or it is not; either the opt-out mechanism exists or it does not. A regulator, a plaintiff’s firm, or a researcher can test compliance from outside the organisation, at scale, without a subpoena.
Four months is enough time — but only if the scoping starts now, and only if it starts from the decisions rather than from the model registry.
This article is provided for informational purposes only and does not constitute legal advice.



