California Privacy Protection Agency (“CalPrivacy”) adopted regulations under the California Consumer Privacy Act (“CCPA”), codified at California Code of Regulations, Title 11, Division 6, Chapter 1, Article 11, (effective January 1, 2026), that apply the CCPA to automated decisionmaking technologies (“ADMT”), including artificial intelligence and machine learning. As with the new regulations pertaining to cybersecurity audits and risk assessments that were also contained in the 2026 package of regulations, the ADMT regulations bring increased transparency to consumers.
What is ADMT?
The regulations define Automated Decisionmaking Technology as “any technology that processes Personal Information and uses computation to replace human decision making or substantially replace human decision making.” The breadth of this definition captures everything from artificial intelligence and machine learning technologies to recommendation algorithms to statistical modelling if that modeling when used to replace human decision making.
This builds on the concept core to responsible AI: the need for what is commonly known as "Human in the Loop."
The regulations also specifically include Profiling (as defined in 11 CCR § 7001(ii)) within the definition of ADMT if that Profiling replaces or substantially replaces human decision making. The CCPA defines Profiling as any form of automated processing of Personal Information to evaluate certain personal aspects relating to a natural person, including intelligence, ability, aptitude, predispositions, performance at work, economic situation, health (including mental health), personal preferences, interests, reliability, behavior, location, or movements.
A number of automated technologies are excluded from the definition of ADMT: “web hosting, domain registration, networking, caching, website-loading, data storage, firewalls, anti-virus, anti-malware, spam- and robocall-filtering, spellchecking, calculators, databases, and spreadsheets, provided that they do not replace human decision making.”
What requirements apply to Businesses that use ADMT?
A Business subject to the CCPA is required to (i) provide Consumers with an ADMT Pre-Notice, (ii) provide Consumers with an opportunity to opt out of the use of ADMT, subject to exceptions, and (iii) provide Consumers with a right of access to information about how the ADMT was used to make a Significant Decision about the Consumer.
The pre-notice, opt-out, and access requirements apply no later than January 1, 2027.
If a Business knows or reasonably should know that it, alone or in combination, buys, receives for its commercial purposes, sells, shares, or otherwise makes available for commercial purposes the Personal Information of 10,000,000 or more Consumers in a calendar year, the regulations require it to disclose certain metrics in its privacy policy by July 1 of each year, including the number of requests to opt out of ADMT and requests to access ADMT that it received, complied with, or denied.
Additionally, under Article 10 of the regulations (11 CCR §§ 7150–7157), the use of Personal Information to train or use an ADMT for a Significant Decision triggers a separate risk assessment requirement.
What is a “Significant Decision”?
Similar to other AI governance laws (such as the Colorado ADMT Act or the EU AI Act), the California CCPA ADMT regulations define a Significant Decision as a decision that results in the provision or denial of:
- Financial or lending services,
- Housing,
- Education enrollment or opportunities,
- Employment or Independent Contracting opportunities or compensation, or
- Healthcare services.
The regulations exclude advertising from the definition of a Significant Decision.
What is an ADMT Pre-Notice?
An ADMT Pre-Notice is a plain-language explanation of how the ADMT works that is provided to Consumers prior to a decision being made. Like CCPA-mandated privacy notices, it must not include general statements and must be specific in the required information, which includes the following:
- The specific purpose for which the Business uses the ADMT,
- A description of the right to opt out and how the Consumer can opt out of the use of ADMT,
- A description of the right to access and how the Consumer can submit a request for more information about the ADMT,
- A statement that the Business is prohibited from retaliating against the Consumer for exercising their rights;
- Information about how the ADMT works to make a Significant Decision, including
- How the ADMT processes Personal Information, including the categories of Personal Information that affect the output of the ADMT,
- The type of output generated by the ADMT and how that output is used to make a Significant Decision, and
- The alternative process for Consumers who opt out of the ADMT.
The regulations permit a Business to exclude the following information from its ADMT Pre-Notice:
- Trade secrets,
- Information that would assist a company in preventing, detecting, or investigating a security incident,
- Information that would prevent the Business from detecting and responding to malicious, deceptive, fraudulent, or illegal actions directed at the Business or its Consumers, or
- Information that would prevent physical harm to an individual.
The regulations permit a Business to use one consolidated ADMT Pre-Notice for multiple purposes.
When is a Business not required to provide an opt-out of the use of ADMT?
The regulations require a Business to provide an individual with the right to opt out of ADMT when ADMT is used to make a Significant Decision, except when:
- The Business provides a method to appeal the decision to a human reviewer;
- If, in the context of admission, acceptance, or hiring decisions, the ADMT is used solely to assess the individual’s ability to perform at work or in the educational program and the ADMT does not discriminate based on protected characteristics.
- If, for assignment of work and compensation, the ADMT is used solely for the Business’s assignment of work or compensation and the ADMT does not discriminate based on protected characteristics.
What requirements apply to opt-out mechanisms for ADMT?
The regulations require a Business to implement opt-out mechanisms for ADMT similarly to how it must allow individuals to exercise their other CCPA rights. The requirements include (i) two or more methods to make a request, (ii) verification processes, (iii) minimal steps, including not requiring an account if one is not already required, (iv) allowing use of an authorized agent, and (v) a means for the individual to confirm the Business has received the request.
After an individual exercises the right to opt out of the use of ADMT, the regulations prohibit the Business from asking that individual to allow it to use ADMT again for 12 months.
What information about the ADMT must a Business provide in a right of access?
A Consumer is entitled to information about how the ADMT works to make a Significant Decision. The information is similar to that provided in the ADMT Pre-Notice and includes:
- The specific purpose for which the Business uses the ADMT,
- Information about the logic of the ADMT, including how the ADMT used the Consumer’s Personal Information and the parameters that generated the output, as well as the specific output about the Consumer,
- The outcome of the decisionmaking process for the Consumer, including how the Significant Decision used or will use the output of the ADMT,
- A statement that the Business is prohibited from retaliating against the Consumer for exercising their rights under the CCPA, together with instructions on how the individual can exercise their other CCPA rights.
The regulations permit a Business to exclude from a right of access the same information that may be excluded from the ADMT Pre-Notice, as described above.
A right of access is, like other CCPA rights, subject to verification and may be submitted by an authorized representative. If a Business denies a Consumer’s request for information, the Business is required to explain the grounds for denial, such as preemption by federal law or an unverifiable identity. The regulations require information provided in response to a request to be transmitted securely. Service Providers and Contractors are required to assist Businesses in fulfilling these requests.
The regulations require a Business to confirm receipt of each request within 10 business days and to respond within 45 calendar days. If necessary, the Business may take up to an additional 45 calendar days if it provides notice and an explanation for the extension.
If you need someone to help you with any of these new ADMT requirements, please reach out to me at Brandi@BennettTechLaw.com for help.