What is California ADMT?
California’s Automated Decision-Making Technology (ADMT) regulations represent the state’s comprehensive framework for governing AI systems that make or substantially influence significant decisions about consumers. Finalized by the California Privacy Protection Agency (CPPA) in September 2025, the modified rulemaking package became effective January 1, 2026; the CPPA later clarified that ADMT-specific business compliance phases in beginning in 2027, depending on the use case.[1]
The ADMT regulations emerge from California’s broader privacy framework, the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA). While the CCPA/CPRA established foundational privacy rights, the ADMT regulations specifically address how businesses must handle AI-driven decision-making that affects consumers’ access to healthcare, employment, financial services, housing, education, and other consequential domains.[2]
Regulatory Timeline
- September 2025: CPPA finalizes ADMT regulations
- January 1, 2026: modified rulemaking package becomes effective[1]
- January 1, 2027: CPPA FAQ begins phasing in ADMT-specific business compliance for covered uses[1]
- April 1, 2028: First risk-assessment submissions cover processing begun in 2026 and 2027[2]
- Ongoing: Documentation retention for processing duration plus 5 years[2]
The regulations define Automated Decision-Making Technology broadly to include any technology that processes personal information to make decisions about consumers or provides outputs that serve as the primary basis for human decisions. This encompasses machine learning systems, AI models, algorithmic scoring tools, and automated profiling systems.[3]
Scope and applicability
The California ADMT regulations apply to businesses subject to the CCPA/CPRA that use automated decision-making technology for significant decisions. This includes any for-profit entity that does business in California and meets one or more of the following thresholds:[3]
- Gross annual revenue over $26,625,000 for the preceding calendar year under the currently adjusted CCPA threshold
- Annually buys, sells, or shares personal information of 100,000 or more California consumers
- Derives 50% or more of annual revenues from selling or sharing consumer personal information
What Constitutes a Significant Decision
The regulations focus on significant decisions, meaning those with material legal or similarly significant effects on consumers. Unlike general AI governance frameworks, ADMT specifically targets decisions that can substantially affect a person’s life circumstances:
Significant Decision Domains
| Domain | Examples | Impact |
|---|---|---|
| Healthcare | Diagnosis support, treatment recommendations, coverage decisions | Health outcomes and access to care |
| Employment | Resume screening, interview scoring, performance evaluation | Livelihood and career opportunities |
| Financial Services | Credit decisions, loan approvals, insurance underwriting | Access to capital and financial products |
| Housing | Tenant screening, rental applications, mortgage decisions | Access to housing |
| Education | Admissions scoring, financial aid, academic placement | Educational opportunities |
| Insurance | Risk assessment, claims processing, premium pricing | Coverage availability and costs |
Who Must Comply
Organizations affected by ADMT regulations include:
Direct Deployers
Businesses that use ADMT to make significant decisions about California consumers. This includes healthcare providers, employers, lenders, insurers, landlords, and educational institutions using AI systems.
AI Vendors
Service providers supplying ADMT to covered businesses have contractual and practical obligations to enable their customers’ compliance. Expect customers to demand risk assessment documentation and transparency information.
Key requirements
The California ADMT regulations establish four core compliance obligations:[2]
1. Pre-Use Notices
Before using ADMT to make significant decisions, businesses must provide consumers with clear and conspicuous notice that automated processing will occur. The pre-use notice must include:
- Description of the ADMT and its purpose
- Categories of personal information the ADMT will process
- Consumer rights including opt-out and access rights
- How to exercise those rights
Pre-use notices must be provided before the business uses ADMT to make a significant decision. A notice may be consolidated with the Notice at Collection when the combined notice meets the applicable requirements. Organizations should design notices that are accessible, understandable, and actionable for average consumers.
2. Risk Assessments
Businesses must conduct risk assessments before deploying ADMT for significant decisions. Risk assessments must be updated when material changes occur (within 45 days) and reviewed at least every three years. Details are covered in the Risk Assessments section below.
3. Consumer Opt-Out
Consumers have an opt-out right for specified ADMT processing, subject to the final rule’s scope, exceptions, and permitted alternative process. Where the right applies, businesses must provide a usable method and follow the applicable response rules; do not generalize the list below to an exempt or excepted use.
- Provide the applicable alternative process where required by the rule
- Not discriminate against consumers who exercise opt-out rights
- Process opt-out requests promptly
- Document opt-out requests and responses
4. ADMT Information Access
Consumers have the right to access information about ADMT processing, including:
- Logic: A meaningful explanation of how the ADMT reaches decisions
- Inputs: Categories of personal information used in the decision
- Outputs: The decision or recommendation produced
- Process: Whether human review occurred before the decision was finalized
Healthcare Relevance
For healthcare organizations, ADMT information access requirements create obligations analogous to explaining clinical decision support recommendations. Patients have the right to understand how AI influenced their diagnosis, treatment recommendation, or coverage decision, and to know what data drove that output.
Risk assessments
Risk assessments are the cornerstone of California ADMT compliance. Businesses must complete assessments before deploying ADMT for significant decisions, update them when material changes occur, and submit attestations to the CPPA beginning April 2028.[2]
Risk Assessment Components
A compliant risk assessment must document:
Required Risk Assessment Elements
| Element | Description |
|---|---|
| Purpose & Use Cases | Description of the ADMT, its intended purpose, and specific deployment context |
| Data Processing | Categories of personal information processed and data sources |
| Potential Harms | Identified risks to consumers from ADMT processing, including bias and discrimination |
| Safeguards | Technical and organizational measures to mitigate identified risks |
| Benefit Analysis | Assessment of whether benefits outweigh potential harms |
| Human Oversight | Description of human review processes and escalation procedures |
| Monitoring Plan | Ongoing monitoring for accuracy, bias, and unintended consequences |
Attestation Requirements
Beginning April 2028, businesses must submit attestations to the CPPA confirming they have completed required risk assessments. Attestations don’t require submitting the full assessment, but the CPPA may request assessments during investigations or audits.[2]
Documentation Retention
Risk assessment documentation must be retained for the duration of ADMT processing or five years after assessment completion, whichever is longer. This creates a substantial documentation burden. Organizations deploying ADMT in 2026 may need to maintain records through 2031 and beyond. Evidence must be:[2]
- Complete and accurate
- Readily accessible for regulatory inspection
- Sufficient to demonstrate compliance
Consumer rights
The California ADMT regulations establish robust consumer rights that go beyond typical privacy frameworks. For covered ADMT uses, those obligations sit within the phased compliance schedule the CPPA described after the January 1, 2026 effective date.[2]
Right to Opt Out
Depending on the use and any applicable exception, consumers may have a right to opt out of ADMT used to make a significant decision. When a request is made, the business should:
- Apply the applicable opt-out route or document the basis for an exception
- Where relying on a human-appeal alternative, provide a qualified reviewer with authority to overturn the decision and satisfy the rule’s conditions
- Process and document the request as required by the CCPA regulations
This creates operational challenges for fully automated decision pipelines, but the rules do not impose one universal human alternative for every ADMT use. The response path must match the applicable opt-out provision or exception.
Right to Access ADMT Information
Consumers may request information about how ADMT processed their personal information. Businesses must provide:
- Logic explanation: A meaningful description of how the ADMT reaches decisions, not the underlying algorithm, but an understandable explanation of the decision-making process
- Input disclosure: What categories of personal information were used
- Output disclosure: What decision or recommendation the ADMT produced
- Human review status: Whether a human reviewed the decision before it was finalized
Right to Correct Data
Consumers retain CCPA/CPRA rights to correct inaccurate personal information, including data used by ADMT. When data is corrected, businesses should:
- Reprocess the decision if the corrected data would materially affect the outcome
- Notify the consumer of any changes to the decision
- Document the correction and reprocessing
Healthcare implications
Healthcare is listed as a domain in which a significant decision may occur, but that does not place every healthcare organization, use, or data set in scope. The CCPA’s business thresholds and data-level exemptions still apply, including specified CMIA medical information and PHI collected by HIPAA covered entities or business associates.[2]
Covered Healthcare AI Uses
Healthcare uses that may require analysis when the business, data, ADMT, and significant-decision conditions are met include:
- Clinical decision support: AI systems that recommend diagnoses, treatments, or referrals
- Coverage decisions: Automated prior authorization, claims processing, or coverage determinations
- Risk stratification: Patient risk scoring for care management or resource allocation
- Operational decisions: Appointment scheduling, triage, or capacity management affecting patient access
HIPAA Intersection
California ADMT and HIPAA can operate in parallel, but neither applies to every healthcare organization or data set. HIPAA applies to covered entities, business associates, and PHI; CCPA includes specified healthcare data exemptions while other personal information may remain in scope:
- HIPAA governs the privacy and security of protected health information (PHI)
- California ADMT governs transparency and consumer rights regarding automated decision-making
- Both require risk assessments, documentation, and consumer/patient access rights
For healthcare organizations, this means AI governance programs must address both HIPAA Security Rule requirements and ADMT obligations, ideally through an integrated framework that satisfies both.
Implications for Healthcare AI Vendors
Vendors providing AI systems to California healthcare organizations should expect:
- Documentation demands: Customers will require model cards, risk assessment inputs, and transparency documentation
- Contractual requirements: Business associate agreements may expand to include ADMT compliance provisions
- Evidence requests: Healthcare buyers may ask for testing, assessments, notices, operational records, and other evidence rather than relying only on a control assertion
Comparison to Colorado’s AI law
California ADMT and Colorado’s state AI law represent two distinct but complementary approaches to state-level AI governance. Colorado’s landscape changed materially in 2026: the 2024 Colorado AI Act (SB 24-205) was repealed and replaced by SB 26-189 (“Automated Decision-Making Technology”), signed May 14, 2026, which substitutes a narrower transparency and disclosure regime for the earlier reasonable-care framework. Colorado’s substantive obligations are not yet enforceable. They commence January 1, 2027. Organizations operating in both states should understand how these frameworks now align and differ:
California ADMT vs. Colorado SB 26-189 (ADMT)
| Feature | California ADMT | Colorado SB 26-189 (ADMT) |
|---|---|---|
| Effective Date | January 1, 2026 rule effective; phased business compliance begins in 2027 | Substantive compliance January 1, 2027 (SB 26-189 signed May 14, 2026; not yet enforceable) |
| Regulatory Authority | California Privacy Protection Agency (CPPA) | Colorado Attorney General |
| Primary Focus | Consumer transparency and opt-out rights | Transparency and disclosure for covered ADMT (notice, post-adverse-outcome disclosure, data correction, human review) |
| Risk Assessments | Required before deployment; attestations due April 2028 | Not required: mandatory risk-management programs and impact assessments were eliminated under SB 26-189 |
| Consumer Opt-Out | Opt-out right for specified covered ADMT processing, subject to scope, exceptions, and permitted alternatives | On request: data correction and meaningful human review/reconsideration, tied to the adverse-outcome context |
| Documentation Retention | Processing duration or 5 years, whichever is longer | Records retained at least 3 years (developers and deployers) |
| Framework Safe Harbor | Not specified | None: the NIST AI RMF / ISO 42001 safe harbor did not survive the repeal-and-replace (still useful as practice, not a legal defense) |
| Covered Domains | Significant decisions (healthcare, employment, financial, housing, education, insurance) | Consequential decisions across seven domains: education, employment, housing, financial or lending services, insurance, health-care services, and essential government services |
Key Similarities
- Risk-based approach: Both target high-stakes AI decisions affecting consumers
- Consequential-decision scope: Both focus on automated decisions in high-stakes domains such as employment, housing, finance, insurance, and healthcare
- Transparency: Both mandate disclosure to affected consumers
- Healthcare coverage: Both explicitly include healthcare as a regulated domain
Key Differences
- Opt-out emphasis: California provides an opt-out for specified covered ADMT processing, subject to exceptions and permitted alternatives; Colorado’s SB 26-189 instead gives request-based data correction and meaningful human review tied to an adverse outcome
- Framework alignment: Neither state codifies a NIST AI RMF / ISO 42001 safe harbor. Colorado’s earlier rebuttable-presumption defense was removed under SB 26-189 and not replaced; both frameworks remain valuable as practice, not as a legal defense
- Assessment model: California requires proactive risk assessments and attestations to the CPPA; Colorado eliminated mandatory risk-management programs and impact assessments, retaining documentation and recordkeeping duties (records kept at least three years)
- Retention requirements: California’s 5-year retention rule creates explicit documentation obligations
Compliance checklist
Use this checklist to track your organization’s California ADMT compliance progress:
California ADMT Readiness
ADMT Inventory
- ☐ Catalog all AI/ML systems making or influencing decisions about consumers
- ☐ Classify each system by decision domain (healthcare, employment, financial, etc.)
- ☐ Identify which systems make “significant decisions” under ADMT definitions
Pre-Use Notice Preparation
- ☐ Draft consumer notices for each ADMT system
- ☐ Document personal information categories processed
- ☐ Create delivery mechanisms (website, application, point-of-collection)
Risk Assessment Development
- ☐ Complete risk assessments for each ADMT system before deployment
- ☐ Document potential harms and safeguards
- ☐ Establish the applicable review and update schedule, including material changes and the required periodic review
- ☐ Prepare for April 2028 attestation deadline
Consumer Rights Infrastructure
- ☐ Implement opt-out request handling workflow
- ☐ Establish opt-out handling and, where the regulations require it, an alternative process
- ☐ Create ADMT information access response process
- ☐ Train customer service on consumer rights handling
Documentation & Retention
- ☐ Implement 5-year retention policy for risk assessments
- ☐ Document consumer notices, opt-out requests, and responses
- ☐ Establish evidence generation for compliance verification
Vendor Management
- ☐ Review contracts with AI vendors for ADMT compliance provisions
- ☐ Request model documentation and risk assessment inputs from vendors
- ☐ Establish ongoing vendor monitoring for ADMT compliance
Frequently asked questions
Does California ADMT apply to companies headquartered outside California?
Yes. If your business meets CCPA/CPRA thresholds and uses ADMT for significant decisions about California consumers, you must comply, regardless of where your company is headquartered. The regulations apply based on consumer location, not business location.
How does consumer opt-out work in practice?
Where the opt-out right applies, provide the mechanism and response required by the final regulations. Section 7221 contains exceptions and a permitted alternative process, so a universal human alternative is not required for every ADMT use. Analyze the specific decision and processing path.
What if I’m already complying with HIPAA for healthcare AI?
Do not assume both apply categorically. HIPAA covers specified entities, business associates, and PHI; the CCPA regulations apply only when their business, data, and processing conditions are met, and specified CMIA medical information and HIPAA PHI receive data-level exemptions. Analyze any remaining personal information and ADMT use separately.
Do I need to comply with both California ADMT and Colorado’s AI law?
If you serve consumers in both states, plan for both, though the timelines differ. California ADMT phases in beginning in 2027; Colorado’s SB 26-189 obligations are not yet enforceable and commence January 1, 2027. Note that Colorado’s 2026 repeal-and-replace removed its NIST AI RMF / ISO 42001 safe harbor, so those frameworks are no longer a codified legal defense there. Even so, organizations that build comprehensive AI governance aligned with NIST AI RMF or ISO 42001 will find the underlying evidence and documentation practices transferable across both states, with some state-specific provisions requiring additional attention.
What are the penalties for non-compliance?
ADMT violations are enforced through CCPA mechanisms. Under the monetary thresholds effective in 2025, the CPPA may impose administrative fines of up to $2,663 for each violation or $7,988 for each intentional violation and each qualifying violation involving personal information of a consumer the violator actually knows is under 16. The Attorney General may seek adjusted civil penalties under the statute. Do not assume how an agency or court will count violations in a particular matter.
How should I prepare for the April 2028 attestation deadline?
Start risk assessments now. The April 2028 deadline applies to systems already in use, so the documentation work cannot wait for 2028. Complete risk assessments for covered deployments, use the regulation’s applicable review cadence, and update them after material changes within the required period. Build evidence that the assessments were conducted properly. The attestation is a confirmation that work has been done, not the start of compliance.
What information must I provide when consumers request ADMT access?
You must provide a meaningful explanation of the ADMT logic (how it reaches decisions), the categories of personal information used as inputs, the output (decision or recommendation), and whether human review occurred. You’re not required to disclose proprietary algorithms, but you must explain the decision-making process in terms consumers can understand.
How do I document compliance for the 5-year retention requirement?
Retain complete risk assessments, pre-use notices provided to consumers, opt-out requests and responses, ADMT information access requests and responses, and evidence of safeguards implemented. Documentation must be readily accessible for regulatory inspection, not just archived, but retrievable. Signed operational records can support integrity review for covered fields, but they do not prove control execution or compliance.
References
- [1] California Privacy Protection Agency. “Automated Decision-Making Technology Regulations.” Finalized September 2025. cppa.ca.gov
- [2] Shannon, Jennifer MD. “The Proof Gap in Healthcare AI.” GLACIS Technologies White Paper. December 2025.
- [3] California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA). Cal. Civ. Code § 1798.100 et seq.
- [4] Colorado General Assembly. “SB26-189 Automated Decision-Making Technology” (signed May 14, 2026; repeals and reenacts the 2024 Colorado AI Act, SB 24-205). leg.colorado.gov/bills/sb26-189
- [5] European Union. “Regulation (EU) 2024/1689 on Artificial Intelligence (AI Act).” Official Journal of the European Union, May 2024.
- [CA-ADMT-1] California Privacy Protection Agency, “California Finalizes Regulations to Strengthen Consumers’ Privacy” (Sep 23, 2025). cppa.ca.gov/announcements/2025/20250923.html. Phasing summarized by Skadden, “California Finalizes CPPA Regulations on Automated Decision-Making Technology, Risk Assessments, and Cybersecurity Audits” (Oct 2025); Wiley, “California Finalizes Pivotal CCPA Regulations on AI, Cyber Audits, and Risk Governance”.
- [CA-ADMT-2] Coblentz Law, “California Finalizes CCPA Regulations on Automated Decision-Making Technology, Risk Assessments, and Cybersecurity Audits” (Oct 2025); White & Case, “CPPA finalizes rules on ADMT, risk assessments, and cybersecurity audits requirements under the CCPA” (Sept 2025).