Mayhem Shield
Insight

AI deployment review in California: what the CCPA ADMT rules require before January 2027.

Published

California's final CCPA regulations create specific duties for covered businesses that use automated decisionmaking technology to make significant decisions about California residents. The ADMT requirements begin January 1, 2027. Related risk-assessment rules took effect earlier, and cybersecurity-audit deadlines are phased separately.

What the ADMT rules cover.

The California Privacy Protection Agency's final CCPA rulemaking covers automated decisionmaking technology, privacy risk assessments, and cybersecurity audits. The regulations took effect on January 1, 2026, but covered businesses that use ADMT to make a significant decision have until January 1, 2027 to comply with the ADMT article.

A significant decision is one that results in the provision or denial of financial or lending services, housing, education enrollment or opportunities, employment or independent contracting opportunities or compensation, or healthcare services. The CCPA covers California residents acting as employees, job applicants, or independent contractors, not only people in a retail customer relationship. It applies only when the organization is a business or other entity covered by the CCPA. The CPPA's CCPA FAQ explains both points.

The technology label is not the test. Under the final definition, ADMT processes personal information and uses computation to replace or substantially replace human decisionmaking. Substantial replacement means the business uses the output to decide without human involvement. A rules engine can qualify. An AI-generated summary used by a reviewer who understands the output, considers other relevant information, and has authority to change the decision may not. The facts of the workflow control.

What the rules require, and when.

Notice, opt-out, and access by January 1, 2027

  • A pre-use notice that states the specific purpose, describes the right to opt out or the exception being used, explains the access right, and describes how the ADMT processes personal information and how its output is used.
  • A way to opt out, unless an exception applies. The exceptions include a qualifying human appeal process and limited uses for admission, hiring, work assignment, or compensation that meet the regulation's conditions.
  • On a verified access request, a plain-language explanation of the purpose, the logic used to produce the person's output, and how that output affected the decision.

The access response is deployment-specific. A vendor datasheet alone will not explain how the system processed one person's information, the output it produced for that person, and how the business used that output.

Documented risk assessments

A covered business must conduct and document a risk assessment before starting processing that presents significant risk. The defined categories include ADMT used for a significant decision, specified automated profiling, and personal information intended to train ADMT for significant decisions or certain identity and biometric technologies.

  • The specific purpose and the minimum personal information needed for it
  • The operational details, including collection, use, disclosure, retention, affected population, and service providers
  • For ADMT used in a significant decision, the system's logic, assumptions, limitations, output, and how the output will be used
  • The expected benefits, negative privacy impacts, and safeguards
  • Whether the business will initiate the processing, who approved that conclusion, and when

Processing already underway before January 1, 2026 must be assessed by December 31, 2027 if it continues. For assessments conducted in 2026 and 2027, the first summary submission and attestation to the CPPA are due April 1, 2028.

Cybersecurity audits

This is a parallel obligation, not a duty triggered by ADMT alone. Businesses whose processing meets the regulation's significant-risk thresholds must complete annual cybersecurity audits. First reports are due April 1, 2028 for businesses with more than $100 million in 2026 revenue, April 1, 2029 for businesses with $50 million to $100 million in 2027 revenue, and April 1, 2030 for other covered businesses that meet the audit criteria. The auditor may be internal or external but must be qualified, objective, and independent. A member of executive management must submit the annual certification.

The dates, scope, and qualifications are in the approved regulation text.

Why this lands on the buyer.

Colorado is a useful contrast. Its 2024 AI law included a deployer impact assessment and a duty of reasonable care. In May 2026, the legislature repealed and reenacted that framework through SB 26-189. Starting January 1, 2027, the replacement centers deployer duties on notice, post-adverse-outcome disclosure, data correction, and meaningful human review. The enacted summary lists those duties instead of the former general deployer impact assessment.

California's documented risk-assessment duty remains in privacy regulation. A vendor's technical documentation can be an input, but the covered business must document its own purpose, workflow, safeguards, risks, benefits, and decision to proceed. That record has to describe the buyer's use of the system, not only the product as shipped.

Where a deployment review fits.

A deployment review can supply technical and operational evidence for counsel and accountable business leaders. It should establish what the system does in the buyer's environment, what data and systems it can reach, what it retains or sends elsewhere, how people use its output, who can change or stop the workflow, and what happens when the output is wrong.

For one deployment, Mayhem Shield produces:

  • Data paths, identities, integrations, and workflows as deployed, with control points marked on a diagram
  • A findings register tied to examined evidence and mapped to the NIST AI RMF 1.0, with an OWASP Top 10 for LLM Applications ID where one fits
  • Gate conditions that state what must close before proof of concept, pilot, or production approval

The findings register can support a risk-assessment conclusion, but it does not replace the legal analysis, required approvals, or the business's own assessment. The public version of the framework is on GitHub. We are paid by buyers and do not resell or implement the products we review.

Who this is for in California.

Security, risk, audit, and privacy leaders at CCPA-covered organizations using ADMT for significant decisions about California residents. Typical contexts include lending, housing, education, employment and independent contracting, and healthcare services, subject to the CCPA's entity, data, and processing exemptions.

If you are working the Texas side as well, the TRAIGA affirmative defense for NIST AI RMF alignment is covered in AI deployment review in Texas.

Discovery calls take twenty minutes

If you have a deployment with a 2027 compliance date, a short call can establish whether a Rapid Readiness Review or a full deployment assurance review is the right starting point.

See the Rapid Readiness Review or book a scoping call.

This is not legal advice. Requirements and dates described here reflect the finalized CCPA regulations as published and are current as of September 2026. Confirm against the regulation text and your own counsel before relying on any date.

Ready to start?

Discovery calls take twenty minutes.

We confirm deployment fit, outline review scope, and match you to the right packaged offer. No engagement starts until you decide to proceed.