Skip to content

Free tool

Does California’s automated decision rule apply to you?

Three questions, no email required. You get the obligations that attach to your systems, what each one means in engineering terms, and the date it lands on.

Most summaries of this rule are written by lawyers and stop at what the law requires. This one starts where that leaves off: what somebody has to build.

  1. 1. Coverage
  2. 2. Decisions
  3. 3. Human review
  4. 4. Result

Is your company a “business” under the CCPA?

Tick any that apply. Any one is enough — these are alternatives, not a combined test. What matters is where your applicants, customers and patients live, not where your office sits.

This is a builder’s read of the regulation, not legal advice. Your counsel decides whether you are covered and which of your decisions count. Sourced from the CCPA regulations, Title 11 Division 6 Chapter 1, effective January 1, 2026.

The California ADMT compliance timeline

Every date below traces to a numbered section of the adopted CCPA regulations. These deadlines catch different populations — presenting them as one universal date is the error most summaries make. Machine-readable copy: admt-timeline.json.

California ADMT and CCPA compliance deadlines, with the population each applies to
DateMilestoneApplies toSection
CCPA regulations take effectAll covered businesses7001
ADMT rights live: pre-use notice, opt-out, access, appealAll covered businesses using ADMT for a significant decision7200(b)
Risk assessments documentedProcessing that began before 1 January 2026 and continues past it7155
First risk-assessment filing to the CPPABusinesses with documented assessments covering 2026 and 20277157
First cybersecurity audit dueBusinesses above $100M in 2026 gross revenue7123

Common questions

Under section 7001(e) of the CCPA regulations, ADMT is any technology that processes personal information and uses computation to replace or substantially replace human decisionmaking. The definition never mentions artificial intelligence, so the test is whether a computation is replacing a human decision, not whether the system uses machine learning.

The regulations took effect on 1 January 2026. Section 7200(b) requires a business already using ADMT for a significant decision to be in compliance by 1 January 2027. Risk assessments for processing that began before 1 January 2026 must be documented by 31 December 2027 and submitted to the Agency by 1 April 2028.

Only five categories count as a "significant decision" under section 7001(ddd): financial or lending services, housing, education enrollment or opportunities, employment or independent contracting opportunities or compensation, and healthcare services. Recommendation engines, churn models, ad targeting and fraud scoring are not significant decisions under this definition.

Only if that reviewer meets all three parts of the test at section 7001(e)(1): they know how to interpret and use the output, they review the output and any other information relevant to the decision, and they have the authority to make or change the decision. A reviewer who must escalate to overturn an output does not plainly have that authority.

Sometimes. Section 7001(e)(3) lists spreadsheets among excluded technologies alongside databases, calculators, firewalls and spam filters, but every exclusion carries the same condition: provided they do not replace human decisionmaking. A spreadsheet used to organise a reviewer’s own judgement is treated differently from one whose computed output is the decision.

No. It is a builder’s read of the published regulation, intended to help engineering and product teams scope the work. Your counsel decides whether you are covered and which of your decisions count.

Once you know you’re in scope

The inventory is slower than the builds, because it moves at the speed of getting time with the people who actually run these processes. We start with a scoped readiness pass rather than a build, so you find out early which of your reviewers genuinely clear the involvement test.