GLACIS·US state AI laws·California ADMT·Reviewed August 2026

California ADMT, the phased compliance playbook through 2030.

The CPPA’s Automated Decision-Making Technology regulations were approved by OAL on September 22, 2025 and took effect January 1, 2026. ADMT-specific business requirements begin January 1, 2027; this guide separates that compliance date from the rule’s effective date and the separate risk-assessment and cybersecurity-audit filing calendars.

By Joe Braidwood, CEO GLACIS·20 min read·Reviewed 26 August 2026

Sep 22 2025
OAL approval; filed with Secretary of State
Jan 1 2026
Rule package becomes effective
Jan 1 2027
ADMT-specific business requirements begin
2028 → 2030
First attestation (Apr 2028) + cybersecurity-audit cascade
Joe Braidwood
Joe Braidwood
CEO, GLACIS
15 min read
Status reviewed 26 August 2026

Keep the dates separate. The rule package became effective January 1, 2026. Covered businesses must comply with the ADMT-specific requirements beginning January 1, 2027. The first risk-assessment submission deadline is April 1, 2028 and covers applicable assessments from 2026 and 2027; cybersecurity-audit filing dates follow a separate revenue-based schedule.[CA-ADMT-1]

Significant-decision scope in the final regs covers finance, housing, education, employment, and healthcare. Advertising was removed from the final rule. Insurance is governed in parallel by the California Department of Insurance regulations.[CA-ADMT-2]

Federal preemption push. California has joined 35 other states in the bipartisan AG coalition opposing broad federal preemption of state AI law (March 2026). The Trump December 2025 executive order does not name California ADMT directly, but the DOJ AI Litigation Task Force is broadly empowered to challenge state AI rules.

Executive summary

The California Privacy Protection Agency (CPPA) Automated Decision-Making Technology (ADMT) regulations were approved by the Office of Administrative Law on September 22, 2025 and filed with the Secretary of State. The package became effective January 1, 2026; covered businesses must comply with the ADMT-specific requirements beginning January 1, 2027. The first risk-assessment submission deadline is April 1, 2028 for applicable assessments from 2026 and 2027, and cybersecurity-audit filing dates follow a separate schedule.[1][CA-ADMT-1]

The ADMT regulations build on the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA). Covered businesses must apply the final rule’s risk-assessment, pre-use-notice, access, and opt-out provisions to specified processing, subject to the rule’s exceptions and permitted alternatives.[2]

Key takeaway: First risk-assessment submissions are due April 2028, with documentation generally retained for the processing duration or five years after assessment completion, whichever is longer. Confirm business thresholds, data-level exemptions, processing scope, and exceptions before treating a healthcare, financial, or employment workflow as covered.

Jan 1, 2026
Rule Effective[1]
Apr 2028
First Attestations[2]
5 Years
Retention Period[2]
40M+
California Residents

In This Guide

What is California ADMT?

California’s Automated Decision-Making Technology (ADMT) regulations represent the state’s comprehensive framework for governing AI systems that make or substantially influence significant decisions about consumers. Finalized by the California Privacy Protection Agency (CPPA) in September 2025, the modified rulemaking package became effective January 1, 2026; the CPPA later clarified that ADMT-specific business compliance phases in beginning in 2027, depending on the use case.[1]

The ADMT regulations emerge from California’s broader privacy framework, the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA). While the CCPA/CPRA established foundational privacy rights, the ADMT regulations specifically address how businesses must handle AI-driven decision-making that affects consumers’ access to healthcare, employment, financial services, housing, education, and other consequential domains.[2]

Regulatory Timeline

  • September 2025: CPPA finalizes ADMT regulations
  • January 1, 2026: modified rulemaking package becomes effective[1]
  • January 1, 2027: CPPA FAQ begins phasing in ADMT-specific business compliance for covered uses[1]
  • April 1, 2028: First risk-assessment submissions cover processing begun in 2026 and 2027[2]
  • Ongoing: Documentation retention for processing duration plus 5 years[2]

The regulations define Automated Decision-Making Technology broadly to include any technology that processes personal information to make decisions about consumers or provides outputs that serve as the primary basis for human decisions. This encompasses machine learning systems, AI models, algorithmic scoring tools, and automated profiling systems.[3]

Scope and applicability

The California ADMT regulations apply to businesses subject to the CCPA/CPRA that use automated decision-making technology for significant decisions. This includes any for-profit entity that does business in California and meets one or more of the following thresholds:[3]

What Constitutes a Significant Decision

The regulations focus on significant decisions, meaning those with material legal or similarly significant effects on consumers. Unlike general AI governance frameworks, ADMT specifically targets decisions that can substantially affect a person’s life circumstances:

Significant Decision Domains

Domain Examples Impact
Healthcare Diagnosis support, treatment recommendations, coverage decisions Health outcomes and access to care
Employment Resume screening, interview scoring, performance evaluation Livelihood and career opportunities
Financial Services Credit decisions, loan approvals, insurance underwriting Access to capital and financial products
Housing Tenant screening, rental applications, mortgage decisions Access to housing
Education Admissions scoring, financial aid, academic placement Educational opportunities
Insurance Risk assessment, claims processing, premium pricing Coverage availability and costs

Who Must Comply

Organizations affected by ADMT regulations include:

Direct Deployers

Businesses that use ADMT to make significant decisions about California consumers. This includes healthcare providers, employers, lenders, insurers, landlords, and educational institutions using AI systems.

AI Vendors

Service providers supplying ADMT to covered businesses have contractual and practical obligations to enable their customers’ compliance. Expect customers to demand risk assessment documentation and transparency information.

Key requirements

The California ADMT regulations establish four core compliance obligations:[2]

1. Pre-Use Notices

Before using ADMT to make significant decisions, businesses must provide consumers with clear and conspicuous notice that automated processing will occur. The pre-use notice must include:

  • Description of the ADMT and its purpose
  • Categories of personal information the ADMT will process
  • Consumer rights including opt-out and access rights
  • How to exercise those rights

Pre-use notices must be provided before the business uses ADMT to make a significant decision. A notice may be consolidated with the Notice at Collection when the combined notice meets the applicable requirements. Organizations should design notices that are accessible, understandable, and actionable for average consumers.

2. Risk Assessments

Businesses must conduct risk assessments before deploying ADMT for significant decisions. Risk assessments must be updated when material changes occur (within 45 days) and reviewed at least every three years. Details are covered in the Risk Assessments section below.

3. Consumer Opt-Out

Consumers have an opt-out right for specified ADMT processing, subject to the final rule’s scope, exceptions, and permitted alternative process. Where the right applies, businesses must provide a usable method and follow the applicable response rules; do not generalize the list below to an exempt or excepted use.

4. ADMT Information Access

Consumers have the right to access information about ADMT processing, including:

Healthcare Relevance

For healthcare organizations, ADMT information access requirements create obligations analogous to explaining clinical decision support recommendations. Patients have the right to understand how AI influenced their diagnosis, treatment recommendation, or coverage decision, and to know what data drove that output.

Risk assessments

Risk assessments are the cornerstone of California ADMT compliance. Businesses must complete assessments before deploying ADMT for significant decisions, update them when material changes occur, and submit attestations to the CPPA beginning April 2028.[2]

Risk Assessment Components

A compliant risk assessment must document:

Required Risk Assessment Elements

Element Description
Purpose & Use Cases Description of the ADMT, its intended purpose, and specific deployment context
Data Processing Categories of personal information processed and data sources
Potential Harms Identified risks to consumers from ADMT processing, including bias and discrimination
Safeguards Technical and organizational measures to mitigate identified risks
Benefit Analysis Assessment of whether benefits outweigh potential harms
Human Oversight Description of human review processes and escalation procedures
Monitoring Plan Ongoing monitoring for accuracy, bias, and unintended consequences

Attestation Requirements

Beginning April 2028, businesses must submit attestations to the CPPA confirming they have completed required risk assessments. Attestations don’t require submitting the full assessment, but the CPPA may request assessments during investigations or audits.[2]

Documentation Retention

Risk assessment documentation must be retained for the duration of ADMT processing or five years after assessment completion, whichever is longer. This creates a substantial documentation burden. Organizations deploying ADMT in 2026 may need to maintain records through 2031 and beyond. Evidence must be:[2]

Consumer rights

The California ADMT regulations establish robust consumer rights that go beyond typical privacy frameworks. For covered ADMT uses, those obligations sit within the phased compliance schedule the CPPA described after the January 1, 2026 effective date.[2]

Right to Opt Out

Depending on the use and any applicable exception, consumers may have a right to opt out of ADMT used to make a significant decision. When a request is made, the business should:

This creates operational challenges for fully automated decision pipelines, but the rules do not impose one universal human alternative for every ADMT use. The response path must match the applicable opt-out provision or exception.

Right to Access ADMT Information

Consumers may request information about how ADMT processed their personal information. Businesses must provide:

Right to Correct Data

Consumers retain CCPA/CPRA rights to correct inaccurate personal information, including data used by ADMT. When data is corrected, businesses should:

Healthcare implications

Healthcare is listed as a domain in which a significant decision may occur, but that does not place every healthcare organization, use, or data set in scope. The CCPA’s business thresholds and data-level exemptions still apply, including specified CMIA medical information and PHI collected by HIPAA covered entities or business associates.[2]

Covered Healthcare AI Uses

Healthcare uses that may require analysis when the business, data, ADMT, and significant-decision conditions are met include:

HIPAA Intersection

California ADMT and HIPAA can operate in parallel, but neither applies to every healthcare organization or data set. HIPAA applies to covered entities, business associates, and PHI; CCPA includes specified healthcare data exemptions while other personal information may remain in scope:

  • HIPAA governs the privacy and security of protected health information (PHI)
  • California ADMT governs transparency and consumer rights regarding automated decision-making
  • Both require risk assessments, documentation, and consumer/patient access rights

For healthcare organizations, this means AI governance programs must address both HIPAA Security Rule requirements and ADMT obligations, ideally through an integrated framework that satisfies both.

Implications for Healthcare AI Vendors

Vendors providing AI systems to California healthcare organizations should expect:

Comparison to Colorado’s AI law

California ADMT and Colorado’s state AI law represent two distinct but complementary approaches to state-level AI governance. Colorado’s landscape changed materially in 2026: the 2024 Colorado AI Act (SB 24-205) was repealed and replaced by SB 26-189 (“Automated Decision-Making Technology”), signed May 14, 2026, which substitutes a narrower transparency and disclosure regime for the earlier reasonable-care framework. Colorado’s substantive obligations are not yet enforceable. They commence January 1, 2027. Organizations operating in both states should understand how these frameworks now align and differ:

California ADMT vs. Colorado SB 26-189 (ADMT)

Feature California ADMT Colorado SB 26-189 (ADMT)
Effective Date January 1, 2026 rule effective; phased business compliance begins in 2027 Substantive compliance January 1, 2027 (SB 26-189 signed May 14, 2026; not yet enforceable)
Regulatory Authority California Privacy Protection Agency (CPPA) Colorado Attorney General
Primary Focus Consumer transparency and opt-out rights Transparency and disclosure for covered ADMT (notice, post-adverse-outcome disclosure, data correction, human review)
Risk Assessments Required before deployment; attestations due April 2028 Not required: mandatory risk-management programs and impact assessments were eliminated under SB 26-189
Consumer Opt-Out Opt-out right for specified covered ADMT processing, subject to scope, exceptions, and permitted alternatives On request: data correction and meaningful human review/reconsideration, tied to the adverse-outcome context
Documentation Retention Processing duration or 5 years, whichever is longer Records retained at least 3 years (developers and deployers)
Framework Safe Harbor Not specified None: the NIST AI RMF / ISO 42001 safe harbor did not survive the repeal-and-replace (still useful as practice, not a legal defense)
Covered Domains Significant decisions (healthcare, employment, financial, housing, education, insurance) Consequential decisions across seven domains: education, employment, housing, financial or lending services, insurance, health-care services, and essential government services

Key Similarities

Key Differences

Compliance checklist

Use this checklist to track your organization’s California ADMT compliance progress:

GLACIS logoGLACIS
Compliance Checklist

California ADMT Readiness

1

ADMT Inventory

  • ☐ Catalog all AI/ML systems making or influencing decisions about consumers
  • ☐ Classify each system by decision domain (healthcare, employment, financial, etc.)
  • ☐ Identify which systems make “significant decisions” under ADMT definitions
2

Pre-Use Notice Preparation

  • ☐ Draft consumer notices for each ADMT system
  • ☐ Document personal information categories processed
  • ☐ Create delivery mechanisms (website, application, point-of-collection)
3

Risk Assessment Development

  • ☐ Complete risk assessments for each ADMT system before deployment
  • ☐ Document potential harms and safeguards
  • ☐ Establish the applicable review and update schedule, including material changes and the required periodic review
  • ☐ Prepare for April 2028 attestation deadline
4

Consumer Rights Infrastructure

  • ☐ Implement opt-out request handling workflow
  • ☐ Establish opt-out handling and, where the regulations require it, an alternative process
  • ☐ Create ADMT information access response process
  • ☐ Train customer service on consumer rights handling
5

Documentation & Retention

  • ☐ Implement 5-year retention policy for risk assessments
  • ☐ Document consumer notices, opt-out requests, and responses
  • ☐ Establish evidence generation for compliance verification
6

Vendor Management

  • ☐ Review contracts with AI vendors for ADMT compliance provisions
  • ☐ Request model documentation and risk assessment inputs from vendors
  • ☐ Establish ongoing vendor monitoring for ADMT compliance

Frequently asked questions

Does California ADMT apply to companies headquartered outside California?

Yes. If your business meets CCPA/CPRA thresholds and uses ADMT for significant decisions about California consumers, you must comply, regardless of where your company is headquartered. The regulations apply based on consumer location, not business location.

How does consumer opt-out work in practice?

Where the opt-out right applies, provide the mechanism and response required by the final regulations. Section 7221 contains exceptions and a permitted alternative process, so a universal human alternative is not required for every ADMT use. Analyze the specific decision and processing path.

What if I’m already complying with HIPAA for healthcare AI?

Do not assume both apply categorically. HIPAA covers specified entities, business associates, and PHI; the CCPA regulations apply only when their business, data, and processing conditions are met, and specified CMIA medical information and HIPAA PHI receive data-level exemptions. Analyze any remaining personal information and ADMT use separately.

Do I need to comply with both California ADMT and Colorado’s AI law?

If you serve consumers in both states, plan for both, though the timelines differ. California ADMT phases in beginning in 2027; Colorado’s SB 26-189 obligations are not yet enforceable and commence January 1, 2027. Note that Colorado’s 2026 repeal-and-replace removed its NIST AI RMF / ISO 42001 safe harbor, so those frameworks are no longer a codified legal defense there. Even so, organizations that build comprehensive AI governance aligned with NIST AI RMF or ISO 42001 will find the underlying evidence and documentation practices transferable across both states, with some state-specific provisions requiring additional attention.

What are the penalties for non-compliance?

ADMT violations are enforced through CCPA mechanisms. Under the monetary thresholds effective in 2025, the CPPA may impose administrative fines of up to $2,663 for each violation or $7,988 for each intentional violation and each qualifying violation involving personal information of a consumer the violator actually knows is under 16. The Attorney General may seek adjusted civil penalties under the statute. Do not assume how an agency or court will count violations in a particular matter.

How should I prepare for the April 2028 attestation deadline?

Start risk assessments now. The April 2028 deadline applies to systems already in use, so the documentation work cannot wait for 2028. Complete risk assessments for covered deployments, use the regulation’s applicable review cadence, and update them after material changes within the required period. Build evidence that the assessments were conducted properly. The attestation is a confirmation that work has been done, not the start of compliance.

What information must I provide when consumers request ADMT access?

You must provide a meaningful explanation of the ADMT logic (how it reaches decisions), the categories of personal information used as inputs, the output (decision or recommendation), and whether human review occurred. You’re not required to disclose proprietary algorithms, but you must explain the decision-making process in terms consumers can understand.

How do I document compliance for the 5-year retention requirement?

Retain complete risk assessments, pre-use notices provided to consumers, opt-out requests and responses, ADMT information access requests and responses, and evidence of safeguards implemented. Documentation must be readily accessible for regulatory inspection, not just archived, but retrievable. Signed operational records can support integrity review for covered fields, but they do not prove control execution or compliance.

References

  1. [1] California Privacy Protection Agency. “Automated Decision-Making Technology Regulations.” Finalized September 2025. cppa.ca.gov
  2. [2] Shannon, Jennifer MD. “The Proof Gap in Healthcare AI.” GLACIS Technologies White Paper. December 2025.
  3. [3] California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA). Cal. Civ. Code § 1798.100 et seq.
  4. [4] Colorado General Assembly. “SB26-189 Automated Decision-Making Technology” (signed May 14, 2026; repeals and reenacts the 2024 Colorado AI Act, SB 24-205). leg.colorado.gov/bills/sb26-189
  5. [5] European Union. “Regulation (EU) 2024/1689 on Artificial Intelligence (AI Act).” Official Journal of the European Union, May 2024.
  6. [CA-ADMT-1] California Privacy Protection Agency, “California Finalizes Regulations to Strengthen Consumers’ Privacy” (Sep 23, 2025). cppa.ca.gov/announcements/2025/20250923.html. Phasing summarized by Skadden, “California Finalizes CPPA Regulations on Automated Decision-Making Technology, Risk Assessments, and Cybersecurity Audits” (Oct 2025); Wiley, “California Finalizes Pivotal CCPA Regulations on AI, Cyber Audits, and Risk Governance”.
  7. [CA-ADMT-2] Coblentz Law, “California Finalizes CCPA Regulations on Automated Decision-Making Technology, Risk Assessments, and Cybersecurity Audits” (Oct 2025); White & Case, “CPPA finalizes rules on ADMT, risk assessments, and cybersecurity audits requirements under the CCPA” (Sept 2025).

California ADMT

Supervision a regulator can review.

Glacis can preserve signed, scoped records from configured ADMT control paths. Those records may support a risk-assessment evidence set; they do not prove control effectiveness, complete coverage, legal compliance, or acceptance by the CPPA.

Talk to us

Related Guides