California's Privacy Protection Agency has finalized rules that put your automated decision tools squarely inside CCPA's scope whenever that technology processes personal information and substantially replaces human judgment on a significant decision. The regulations take effect January 1, 2026, with ADMT obligations for significant decisions kicking in a year later. Your first move: inventory every automated decision system touching lending, housing, employment, education, or health care, then start drafting the notices and human review process the rules require.
TL;DR:
- Businesses must inventory all automated decision systems affecting lending, housing, employment, education, or health care to comply with California's new ADMT rules.
- The rules apply to any system substantially replacing human judgment, regardless of complexity, starting with notice requirements before deployment in 2026 and full compliance by 2027.
- A pre-use notice must explain the purpose, how the system works, and consumer rights, including opt-outs and appeals, which require testing and clear processes.
- Cybersecurity audits and risk assessments must be conducted periodically, with deadlines phased by revenue, and should demonstrate safeguards, purpose, and consumer risk management.
- Automated decision systems need real human review, proper logging, data minimization, and ongoing monitoring to prevent model drift and ensure compliance over time.
Table of Contents
- What Do the ADMT Rules Actually Require?
- Who Has To Comply, and On What Timeline?
- What Notices, Opt-Outs, and Appeal Rights Do You Owe Consumers?
- How Do Cybersecurity Audits and Risk Assessments Fit In?
- The Practical Compliance Playbook for IT and Privacy Teams
- Perspective: ADMT Compliance Is an Operational Program, Not a Filing
- How Mindpod Technologies Helps You Operationalize ADMT Compliance
- Where To Read the Actual Rules
- Sources
- FAQ
What Do the ADMT Rules Actually Require?
The finalized regulations define automated decisionmaking technology as any system that processes personal information using computation to replace or substantially replace human decisionmaking. Notice the wording carefully: the CPPA dropped "artificial intelligence" as a defined term entirely. The rule targets the function a system performs, not whether it runs on a neural network or a decades-old scoring rule. A basic if-then eligibility filter can qualify just as easily as a machine learning model, according to the regulation text itself.
That distinction catches a lot of businesses off guard. Many assume ADMT rules only apply to complex predictive models, but a simple resume filter or an automated rent-pricing tool can trigger the same obligations if it substantially replaces a human's judgment call.
The rules apply specifically when ADMT drives a "significant decision" affecting:
- Financial or lending services, including credit terms and loan approval
- Housing, including tenant screening and rental pricing
- Employment or independent contracting decisions, including hiring and compensation
- Education enrollment or opportunity decisions
- Health care access or treatment decisions
Once a significant decision is in play, the regulation text triggers a specific bundle of obligations: a pre-use notice before the ADMT runs, an opt-out mechanism where applicable, consumer access to information about how the ADMT was used, a right to appeal the outcome, and recordkeeping that proves you did all of it.
Who Has To Comply, and On What Timeline?

Every business already subject to CCPA needs to check whether it uses ADMT for significant decisions. There's no separate revenue threshold for the ADMT rules themselves. If you already meet CCPA's applicability test, the ADMT provisions ride along automatically once you deploy qualifying technology.
The dates that matter:
- January 1, 2026 — the broader regulatory package, including cybersecurity audit and risk assessment requirements, becomes effective.
- January 1, 2027 — businesses using ADMT for significant decisions must have full compliance in place: notices, opt-outs, access, and appeal rights.
- April 1, 2028 — first cybersecurity audit submission deadline, for businesses with over $100 million in annual revenue.
- April 1, 2029 — audit submission deadline for businesses between $50 million and $100 million in revenue.
- April 1, 2030 — audit submission deadline for businesses under $50 million in revenue.
The phased schedule isn't a courtesy; companies must treat compliance as a strategic priority, as advised by benchmarked, who build AI-native companies with the leaders who own the market. It reflects the reality that larger companies typically run more automated pipelines touching more consumer data, so they get less runway to fix problems before regulators start looking. Smaller businesses get more lead time, but "more time" doesn't mean "less obligation." Ask yourself three questions now: Does any system we run make or heavily influence a lending, housing, employment, education, or health decision? Does a human meaningfully review that outcome before it takes effect? Could we produce a written notice explaining that system today if a regulator asked? If any answer is no, you have work to do before 2027.
What Notices, Opt-Outs, and Appeal Rights Do You Owe Consumers?
Three documents need attention: your general privacy policy, your notice at collection, and a new document most businesses have never written before, the ADMT pre-use notice. The regulation text spells out what the pre-use notice must contain before ADMT is used to make a significant decision about someone.
A compliant pre-use notice should cover:
- A plain-language description of the ADMT's purpose and the significant decision it affects
- How the technology works at a level a non-technical consumer can understand
- The consumer's right to opt out, with a working link or clear instructions, where opt-out applies
- How to request access to information about the ADMT's use in their case
- How to appeal the resulting decision, including what a human reviewer will consider
Pro Tip: Build the appeal flow before you build the opt-out flow. Regulators and plaintiffs' attorneys tend to scrutinize appeals first, because a broken or cosmetic appeal process is the clearest evidence that "human review" was never real.
These ADMT rights don't replace existing CCPA rights to delete, correct, or limit use of personal information. They stack on top. A consumer denied a loan by an ADMT-assisted process can request deletion of the underlying data, correct inaccurate inputs, and appeal the decision itself, all as separate rights. Watch for the exceptions built into the rules, too. Certain fraud-prevention and security uses of ADMT get narrower notice obligations, so don't assume every automated system needs the full notice package.
How Do Cybersecurity Audits and Risk Assessments Fit In?
Cybersecurity audits and privacy risk assessments run on parallel tracks with ADMT compliance, but they feed each other. The audit requirements apply to businesses whose processing presents significant risk to consumers, with submission deadlines phased by revenue tier through 2030, as outlined in the CPPA's announcement. A privacy risk assessment becomes mandatory whenever processing, including ADMT deployment for a significant decision, creates that same significant risk.
What the risk assessment needs to show:
- The specific purpose of the ADMT and why less invasive alternatives weren't sufficient
- The categories of personal information involved and how long you retain them
- The safeguards in place, including human review points and override capacity
- An honest accounting of risks to consumers, not just risks to the business
When auditors or regulators come asking, they'll want the audit report, the risk-assessment findings, and evidence that you acted on what those documents found. A risk assessment that identifies a problem and gets filed away without a fix is arguably worse than not doing the assessment at all.
The Practical Compliance Playbook for IT and Privacy Teams
Turning these rules into daily operations comes down to six moves, in order:
- Inventory every ADMT use. Include simple rule-based automations, not just machine learning systems. A rent-scoring spreadsheet formula counts if it substantially replaces a human landlord's judgment.
- Classify each one against the significant-decision categories. Lending, housing, employment, education, health care. Anything outside those categories carries lighter obligations, but document that determination anyway.
- Run a risk assessment on anything that touches a significant decision.
- Update your privacy policy, notice at collection, and build the ADMT pre-use notice.
- Implement opt-out and appeal mechanisms, tested by someone who isn't the engineer who built them.
- Schedule your cybersecurity audit against your revenue-tier deadline, not the general 2026 effective date.
Human-in-the-loop review has to be real, not decorative. A reviewer needs to see the actual context and inputs behind the decision, hold genuine authority to override it, and log that review with a timestamp. A manager glancing at an approval screen for three seconds before clicking "confirm" won't survive regulatory scrutiny.
On the technical side, prioritize data minimization, stripping unnecessary personal information out of training pipelines, logging that supports explainability, and a rollback or kill switch for any ADMT that starts producing questionable outcomes. Stanford's Institute for Human Centered AI has noted that privacy risk in foundation models is fundamentally data driven, and recommends removing personal data from training pipelines as a core mitigation, not an afterthought. Guidance on human-in-the-loop design and risk-assessment frameworks can help engineering teams turn these principles into working review interfaces rather than checkbox exercises.
Pro Tip: Assign a named owner to each governance artifact, the ADMT register, the pre-use notice template, the risk-assessment pack, the audit evidence bundle, the same way you'd assign an owner to a budget line. Artifacts without owners rot within two quarters.
Perspective: ADMT Compliance Is an Operational Program, Not a Filing
Treating this as a one-time legal exercise is the mistake most SMBs will make. Models drift, data pipelines change, and a system compliant in January can drift out of bounds by June without anyone noticing. Build recurring checkpoints between engineering and privacy staff, not annual ones.
Smaller teams don't need every control day one. Start with inventory coverage and real human review, then layer in formal audits as deadlines approach. Track three numbers: percentage of ADMT systems inventoried, remediation rate on flagged risks, and time to close audit findings. Those three tell you more than any policy document sitting in a drawer.
— jaras
How Mindpod Technologies Helps You Operationalize ADMT Compliance
Mindpod Technologies offers services to help SMBs address these rules without hiring a compliance department. The AI Governance service maps directly to what the ADMT rules demand: policy templates, human-in-the-loop design criteria, and documented review workflows built around the systems you actually run, not generic boilerplate.

If you're not sure where your exposure sits, the Enterprise Intelligence Assessment starts with a free technology assessment that inventories your ADMT uses, flags which ones touch significant decisions, and hands you a prioritized, plain-language roadmap you own outright. For businesses that need someone coordinating engineering, privacy, and legal on this without adding a full-time executive, Fractional CTO engagements fill that gap. Deliverables include an ADMT register, pre-use notice drafts, a risk-assessment pack, and a monitored rollout plan with rollback points. Book the free assessment and get the roadmap before your 2027 deadline gets closer than it looks.
Where To Read the Actual Rules
- CPPA's official announcement on the finalized regulations
- Full text of the ADMT regulations
- Privacy for consumer-facing rights guidance
This article is general information, not a substitute for advice from a qualified lawyer. Consult a qualified legal professional about your own circumstances before acting on anything here.
Sources
- California Finalizes Regulations to Strengthen Consumers' Privacy
- Text of regulations: Title 11 — CCPA updates, ADMT and related provisions
- Data Privacy and Foundation Models: Can We Have Both? | Stanford HAI
FAQ
Does CCPA Apply to AI Systems Specifically?
CCPA doesn't single out "AI" as a defined term anymore. The finalized rules regulate any automated decisionmaking technology that substantially replaces human judgment on a significant decision, whether it runs on machine learning or a basic scoring formula, per the CPPA's regulation text.
When Do Businesses Need To Be ADMT Compliant?
The broader regulatory package took effect January 1, 2026, and full ADMT compliance for significant decisions, including notices, opt-outs, and appeal rights, is required starting January 1, 2027.
What Counts As a Significant Decision Under the New Rules?
Significant decisions include lending and financial services, housing, employment and compensation, education enrollment, and health care access. A system only triggers ADMT obligations when it substantially replaces human decisionmaking in one of these areas.
Do Small Businesses Get More Time for Cybersecurity Audits?
Yes. Audit submission deadlines phase in by revenue tier: April 1, 2028 for businesses over $100 million, April 1, 2029 for those between $50 million and $100 million, and April 1, 2030 for businesses under $50 million, according to the CPPA.
What Should a Business Do First To Prepare?
Start by inventorying every automated system that touches a significant decision, then determine whether a human genuinely reviews and can override each outcome. Mindpod Technologies' Enterprise Intelligence Assessment is built to run that inventory and hand you a prioritized roadmap.
