Every explainer about California's new automated-decisions rules points at the same date: January 1, 2027. The requirement sitting one article over in the same regulations took effect a full year earlier, on January 1, 2026, and it already reaches whatever AI vendor you signed last quarter. If that vendor's tool scores resumes, prices a loan, or flags an insurance claim, the contract behind it has to say specific things, and most vendor contracts written before 2026 don't say any of them.
This is a builder's read, not legal advice. Your counsel decides whether you're covered. This is what to check once they tell you.
The part of the package nobody is watching
The California Privacy Protection Agency's board adopted the current round of CCPA regulations on July 24, 2025, and they became effective January 1, 2026, after the Office of Administrative Law approved them and filed them with the Secretary of State that September. Most of the attention since then has gone to Article 11, the rights around automated decisionmaking technology (ADMT), because section 7200 gives businesses using ADMT for a significant decision until January 1, 2027 to comply.
Article 4 got no such grace period. Sections 7050 and 7051, which govern what a business's contract with a service provider or contractor has to say, carry no separate operative date. They took effect with the rest of the package on January 1, 2026. If your AI vendor is a service provider or contractor under the CCPA, which most are, the contract you have with them today is already supposed to meet a bar that existed for the prior version of these rules and got sharper this year.
What the contract actually has to say
Section 7051 spells out what the written contract must do. Some of it is the CCPA's familiar purpose-limitation language: the contract has to name the specific business purpose the vendor is processing personal information for, not describe it in generic terms, and prohibit the vendor from using that information for anything else.
The part that's new to this round is narrower and more useful to an engineering team evaluating a vendor. The regulations state that the contract may require the service provider or contractor to cooperate with the business in completing its cybersecurity audit under Article 9, in conducting its risk assessment under Article 10, and in complying with its ADMT requirements under Article 11, alongside implementing reasonable security procedures under Civil Code section 1798.81.5. Read plainly: if your ADMT tool is a vendor's product, your contract has to be the mechanism that gets you the evidence your own audit and risk assessment need from them. A vendor who won't put that cooperation in writing has told you something about how the rest of the relationship will go.
| Where it comes from | What the contract has to require |
|---|---|
| Section 7051(a) | Specific, non-generic business purpose; no repurposing personal information outside it |
| Article 9 (cybersecurity audits) | Vendor cooperation and evidence production for the business's own audit |
| Article 10 (risk assessments) | Vendor cooperation and fact-sharing for the business's own risk assessment |
| Article 11 (ADMT) | Vendor cooperation with the business's ADMT compliance obligations |
| Civil Code 1798.81.5 | Reasonable security procedures appropriate to the personal information involved |
The audit right most contracts never use
Section 7051 also grants the business the right to take reasonable and appropriate steps confirming the vendor uses personal information consistently with the business's own obligations, and it names what that can look like: ongoing manual reviews, automated scans, and regular internal or third-party assessments, audits, or other technical and operational testing, at least once every 12 months.
Plenty of contracts already carry an audit-rights clause; procurement teams have negotiated some version of it for years. What changes the calculus this year is section 7050, which ties the clause to actual liability rather than paperwork. It states that whether a business conducted due diligence of its service providers factors into whether the business has reason to believe a violation is occurring, and gives an explicit example: a business that never enforces its contract terms, and never exercises its right to audit or test a vendor's systems, may not be able to claim it had no reason to believe the vendor was misusing personal information.
That's the opinion worth stating plainly: a negotiated audit clause that nobody has exercised in the last 12 months is not meaningfully different from having no clause at all, and the regulation now says so directly rather than leaving it to inference.
Subcontractors inherit the same obligation
Most AI vendors don't run their own infrastructure end to end. A hiring-tool vendor built on a foundation model API, a claims-triage startup running on a cloud provider's managed model, and a pricing engine reselling someone else's scoring service are all normal arrangements, and each one adds a link to the chain.
Section 7050(b) closes that gap on paper: a service provider or contractor that subcontracts with another party to help deliver its services has to have its own contract with that subcontractor meeting the same requirements the business imposed on it. In practice that means your ADMT vendor's contract with its own model provider needs the same purpose limitation, cooperation, and audit-rights language your contract with the vendor has. Most vendors can't show you that paperwork on request, because most vendors have never been asked for it.
A worked example
Picture a 300-person regional insurer that licenses a claims-triage model from a five-year-old startup, rather than building one in-house. The startup's tool flags claims for expedited review or additional scrutiny, which is squarely a significant decision under the ADMT rules once it affects payout timing or denial likelihood.
The insurer's 2021 vendor agreement covers the basics: data security, breach notification, standard confidentiality. It says nothing about cooperating with a cybersecurity audit, nothing about assisting a risk assessment, and its "right to audit" clause has sat unused since signature. Under the current regulations, that contract has a hole in exactly the three places section 7051 asks for cooperation, and the insurer's own risk assessment and audit are going to hit that hole the moment they need evidence only the vendor holds: what personal information the model actually reads, what safeguards run inside the vendor's system, and whether the vendor's own subprocessor (the cloud model host doing the actual inference) is bound by anything at all.
Fixing it isn't a rebuild. It's a contract amendment naming the specific cooperation obligations, an audit that actually gets scheduled and run within the next 12 months, and a one-page request to the vendor for its own subcontractor's terms. None of that touches the claims-triage model itself. All of it is the difference between an assessment the insurer can defend and one that gets challenged for resting on nothing.
What this means for your team
- Check your AI vendor contracts against the date, not just the content. A contract signed or last touched before 2026 was written for a different version of this rule.
- An audit-rights clause that has never been exercised carries the same legal exposure as no clause, under section 7050's own reasoning.
- Ask for the subcontractor paperwork before you need it in an assessment. Most vendors have never been asked and won't have it ready on short notice.
- If your legal team already runs a mature vendor-risk program that actively schedules and enforces these audits, this is not a gap you have. Plenty of the work above is exactly what an in-house privacy counsel and a security lead already do well; the risk is concentrated in companies that treated the original contract signature as the finish line.
- This sits next to, not instead of, what the ADMT rules require your own engineering team to build and what actually goes in the risk assessment those vendor cooperation clauses are supposed to feed. If you haven't scoped which of your tools count as ADMT in the first place, that question comes first.
If you're staring at a vendor contract from before 2026 and don't know what evidence it would actually get you from that vendor today, that's a short, concrete conversation. Tell us what the vendor relationship looks like and we'll tell you what's missing from the paperwork, or get in touch to talk through the specific tool.
Sources
- California Privacy Protection Agency: CCPA updates, cybersecurity audits, risk assessments, ADMT and insurance regulations
- California Privacy Protection Agency: approved regulations text (Cal. Code Regs. tit. 11, Articles 4, 9, 10 and 11)