California's ADMT, Risk Assessment and Cybersecurity Audit Regulations: What the Final Text Says
Key Takeaways
- The Office of Administrative Law approved the package on September 22, 2025 under OAL Matter Number 2025-0808-04, and it became effective January 1, 2026
- The package adopts nineteen new sections of title 11 of the California Code of Regulations and amends thirty existing ones
- ADMT is defined by whether technology replaces or substantially replaces human decisionmaking, and the obligations attach only to nine enumerated categories of significant decision
- Article 11's compliance date is January 1, 2027; first risk assessment submissions are due April 1, 2028; first cybersecurity audit reports fall between April 1, 2028 and April 1, 2030 by revenue
What the Agency Adopted, and When It Took Effect
The California Privacy Protection Agency Board adopted the rulemaking package titled CCPA Updates, Cyber, Risk, ADMT, and Insurance Regulations on July 24, 2025. The Office of Administrative Law approved it on September 22, 2025 under OAL Matter Number 2025-0808-04 and filed it with the Secretary of State. The Notice of Approval states that the regulatory action "becomes effective on January 1, 2026."
The action is larger than the ADMT provisions that drew most of the attention. According to the Notice of Approval, it adopts sections 7120, 7121, 7122, 7123, 7124, 7150, 7151, 7152, 7153, 7154, 7155, 7156, 7157, 7200, 7220, 7221, 7222, 7270 and 7271 of title 11 of the California Code of Regulations, and amends thirty existing sections, among them the definitions section 7001 and the request-handling sections in Articles 2 through 5. The new material is organised into three new articles: Article 9 on cybersecurity audits, Article 10 on risk assessments, and Article 11 on automated decisionmaking technology.
Each new article carries the same Note: "Authority cited: Section 1798.185, Civil Code." That is the CPRA provision directing the Agency to issue regulations, and it is where the three subjects come from in the first place.
What Counts as Automated Decisionmaking Technology
Section 7001, subsection (e) defines ADMT as "any technology that processes personal information and uses computation to replace human decisionmaking or substantially replace human decisionmaking." The operative phrase is the second one. To "substantially replace human decisionmaking" means the business "uses the technology's output to make a decision without human involvement," and human involvement is itself defined by a three-part test: the human reviewer must know how to interpret and use the output, must review and analyse the output and any other relevant information, and must have the authority to make or change the decision based on that analysis.
A reviewer who rubber-stamps an output does not satisfy the test, and the regulations return to that point repeatedly — sections 7220 and 7222 both require disclosure of what a human's role was where that role "does not meet the requirements of 'human involvement' in section 7001, subsection (e)(1)."
The definition also carries an explicit exclusion list. ADMT "does not include web hosting, domain registration, networking, caching, website-loading, data storage, firewalls, anti-virus, anti-malware, spam- and robocall-filtering, spellchecking, calculators, databases, and spreadsheets, provided that they do not replace human decisionmaking." Profiling that replaces or substantially replaces human decisionmaking is included.
Article 11 does not attach to every use of ADMT. Section 7200, subsection (a) applies it to a business that uses ADMT "to make a significant decision concerning a consumer," and section 7001, subsection (ddd) defines that term by enumeration: a decision resulting in the provision or denial of financial or lending services, housing, education enrollment or opportunities, employment or independent contracting opportunities or compensation, or healthcare services. The subdefinitions are specific — employment covers hiring, allocation or assignment of work and compensation, promotion, and demotion, suspension and termination; education covers admission or acceptance, educational credentials, and suspension and expulsion. Two exclusions sit in the text: providing or denying housing "based solely on the availability or vacancy of the housing or the successful receipt of payment" is not a significant decision, and paragraph (6) states flatly that "significant decision does not include advertising to a consumer."
Pre-Use Notice, Opt-Out and Access Under Article 11
Section 7220 requires a Pre-use Notice presented "prominently and conspicuously" at or before the point the business collects the personal information it plans to process using ADMT, or before processing begins where the information was collected earlier for a different purpose. The notice must give a plain-language explanation of the specific purpose, and the text forecloses the obvious shortcut: a business "must not describe the purpose in generic terms, such as 'to make a significant decision' without further information." It must also describe the opt-out and access rights, state that retaliation for exercising CCPA rights is prohibited, and explain how the technology processes personal information, what type of output it generates, and what the alternative process is for consumers who opt out. Subsection (d) carves out trade secrets as defined in Civil Code section 3426.1(d) and information that would compromise security, fraud prevention or physical safety.
Section 7221 requires an opt-out, subject to three exceptions. The first is a human appeal: a business need not offer an opt-out if it provides a method to appeal to a designated human reviewer who meets the same interpret-analyse-authority test and can overturn the decision. The second and third cover admission, acceptance or hiring decisions and work allocation or compensation decisions, in each case only where the ADMT is used solely for that assessment and "works for the business's purpose and does not unlawfully discriminate based upon protected characteristics."
The mechanics are prescribed in some detail. Two or more designated opt-out methods are required, at least one reflecting how the business primarily interacts with the consumer; an online business must at minimum offer an interactive form reachable from a link in the Pre-use Notice. Subsection (c)(4) rules out a common substitute: a cookie banner or cookie controls are "not by itself an acceptable method," because cookies concern collection rather than use of ADMT. A verifiable consumer request cannot be required, an account cannot be required, and where a consumer opts out after processing has begun the business has "no later than 15 business days" to stop and to instruct its service providers and contractors to do the same. Subsection (k) sets a twelve-month wait before asking a consumer who opted out to consent again.
Section 7222 governs the access right. A response must give plain-language explanations of the specific purpose, information about the logic of the ADMT sufficient to let the consumer understand how their personal information generated an output, and the outcome of the decisionmaking process — including whether the output was the sole factor and, if not, what the other factors were. The same trade-secret and security carve-outs apply.
When a Risk Assessment Is Required
Article 10 runs on a different trigger. Section 7150, subsection (a) requires a risk assessment "before initiating" processing that presents significant risk to consumers' privacy, and subsection (b) defines that by listing six processing activities: selling or sharing personal information; processing sensitive personal information; using ADMT for a significant decision; using automated processing to infer or extrapolate characteristics of applicants, students, employees or independent contractors based on systematic observation; the same inference based on a consumer's presence in a sensitive location; and processing personal information intended to train an ADMT for a significant decision or to train facial-recognition, emotion-recognition or identity-verification technology.
One narrow exemption sits inside the sensitive-information trigger: processing employees' or contractors' sensitive personal information solely for compensation payments, employment authorization, benefits administration, legally required accommodation or wage reporting does not require an assessment.
Section 7152 sets out what the assessment must identify and document, beginning with the purpose — and again barring generic descriptions such as "to improve our services" or "security purposes." Section 7155 sets the timing: before initiating the processing; reviewed and updated at least once every three years; updated within 45 calendar days of a material change; and, for processing already underway when the regulations took effect and continuing after, documented no later than December 31, 2027. Assessments are retained for as long as the processing continues or five years after completion, whichever is later.
Section 7157 is the submission provision, and it does not call for the assessment itself. What goes to the Agency is a defined set of metadata: the business's name and contact, the period covered, the number of assessments conducted or updated in total and per triggering activity, which categories of personal and sensitive personal information were involved, and an attestation signed "under penalty of perjury" by a member of the executive management team who is directly responsible for risk-assessment compliance and has authority to submit. Assessments conducted in 2026 and 2027 are reported by April 1, 2028; later years by April 1 following the year. Separately, subsection (e) provides that the Agency or the Attorney General "may require a business to submit its risk assessment reports" at any time, within 30 calendar days of the request.
Which Businesses Owe a Cybersecurity Audit
Article 9 uses revenue and volume thresholds rather than an activity list. Under section 7120, subsection (b), processing presents significant risk to consumers' security if the business meets the threshold in Civil Code section 1798.140(d)(1)(C) — the share-of-revenue prong — or meets the section 1798.140(d)(1)(A) revenue threshold and processed the personal information of 250,000 or more consumers or households, or the sensitive personal information of 50,000 or more consumers, in the preceding calendar year.
Section 7121 staggers the first audit report by size. A business whose 2026 annual gross revenue exceeded $100 million as of January 1, 2027 completes its first report by April 1, 2028, covering January 1, 2027 through January 1, 2028. Revenue between $50 million and $100 million for 2027 moves the first report to April 1, 2029. Under $50 million for 2028 moves it to April 1, 2030. After that the cycle is annual, keyed to whether the business met the section 7120 criteria on January 1 of the preceding year.
Section 7122 requires "a qualified, objective, independent professional" using procedures and standards accepted in the profession of auditing. Section 7124 requires a written certification to the Agency by April 1 following each audit year, signed by an executive-management member, attesting under penalty of perjury that the information is true and correct "and that the business has not made any attempt to influence the auditor's decisions or assessments regarding the cybersecurity audit."
The Dates Written Into the Package
| Date | What the regulations attach to it | Provision |
|---|---|---|
| January 1, 2026 | The regulations become effective | OAL Notice of Approval |
| January 1, 2027 | Compliance deadline for Article 11 (ADMT notice, opt-out, access) | § 7200(b) |
| December 31, 2027 | Risk assessments documented for processing already underway when the rules took effect | § 7155(b) |
| April 1, 2028 | First risk assessment submission, covering assessments conducted in 2026 and 2027 | § 7157(a)(1) |
| April 1, 2028 | First cybersecurity audit report, 2026 revenue over $100 million | § 7121(a)(1) |
| April 1, 2029 | First cybersecurity audit report, 2027 revenue between $50 million and $100 million | § 7121(a)(2) |
| April 1, 2030 | First cybersecurity audit report, 2028 revenue under $50 million | § 7121(a)(3) |
How the Rules Sit Against the Statute They Implement
Civil Code section 1798.185, subdivision (a)(14) directs the Agency to issue regulations requiring businesses whose processing presents significant risk to consumers' privacy or security to "[p]erform a cybersecurity audit on an annual basis, including defining the scope of the audit and establishing a process to ensure that audits are thorough and independent," and to submit risk assessments to the Agency on a regular basis. Subdivision (a)(15) directs regulations "governing access and opt-out rights with respect to a business' use of automated decisionmaking technology, including profiling and requiring a business' response to access requests to include meaningful information about the logic involved in those decisionmaking processes, as well as a description of the likely outcome of the process with respect to the consumer."
The mapping is close on its face. Section 7222's "information about the logic of the ADMT" tracks the statute's "meaningful information about the logic involved," and section 7157's metadata-plus-attestation model is one reading of the statutory instruction to "[s]ubmit … a risk assessment … on a regular basis." Where the regulations go further than the statutory text — the exclusion list in the ADMT definition, the enumerated categories of significant decision, the fifteen-business-day opt-out deadline — the source is the rulemaking record rather than the statute, and the Final Statement of Reasons published with the package is where those choices are explained.
The package is complete as a matter of administrative process. The Agency's own rulemaking page records the status as "The rulemaking is complete," with the regulations approved by the Office of Administrative Law and filed with the Secretary of State on September 22, 2025.
Background
For the underlying law rather than this development: California privacy law, Technology & SaaS privacy law.
Frequently Asked Questions
When do California's ADMT regulations actually require compliance?
Does the CPPA definition of ADMT cover any use of artificial intelligence?
What has to be sent to the Agency for a risk assessment, and when?
Which businesses fall within the cybersecurity audit requirement?
Does a cookie banner satisfy the ADMT opt-out requirement?
Sources
Everything above is reported from these documents. Follow them to verify.
- California Privacy Protection Agency — approved text, CCPA Updates, Cyber, Risk, ADMT, and Insurance Regulations (Cal. Code Regs. tit. 11, div. 6) (September 22, 2025) regulation
- California Office of Administrative Law — Notice of Approval of Regulatory Action, OAL Matter No. 2025-0808-04 (September 22, 2025) agency release
- California Privacy Protection Agency — rulemaking package page and status, CCPA Updates, Cybersecurity Audits, Risk Assessments, ADMT, and Insurance Regulations (September 22, 2025) agency guidance
- California Civil Code § 1798.185 — Agency rulemaking authority, including subdivisions (a)(14) and (a)(15) statute
Reporting, not legal advice. This article reports on developments in privacy law using publicly available primary sources, which are linked throughout and listed at the end. It is not legal advice, it is not written or reviewed by an attorney, and it does not assess how any law applies to your situation. Privacy law changes frequently and differs by jurisdiction. Reading this does not create an attorney-client relationship. To find out where you or your business stands, consult a licensed attorney. How we report.