New rules under the California Consumer Privacy Act will have a major impact on the world of data privacy and artificial intelligence.
These rules focus on three key areas: cybersecurity audits, risk assessments, and how companies use automated decision-making technology. These rules will go into effect on January 1, 2026, but companies that use ADMT to make important decisions will need to comply with ADMT requirements starting January 1, 2027.
Organizations doing business in California should consider how they protect personal data and use ADMT. Meeting any of the applicability thresholds for these new rules could mean significant changes to how risks are managed, how consumer data is protected, and how ADMT is used overall.
new rules
In November 2024, the CPPA began a rulemaking process to update existing CCPA regulations and draft new regulations regarding cybersecurity audits, risk assessments, and ADMT. This process received important feedback from technology companies, advocacy groups, and government leaders. ADMT has emerged as a major point of discussion due to concerns that the proposed rules could hinder AI innovation.
Several comments received during the rulemaking process expressed concern that the definition of ADMT is too broad and could be construed to apply to nearly all common business software, including spreadsheets, calculators, databases, routine automation tools, and technology that merely supports human decision-making. California Governor Gavin Newsom called on the CPPA to be careful not to overwhelm the industry.
The final regulations reflect these concerns and provide additional flexibility to businesses by reducing the limiting factors, including narrowing the scope of the definition of ADMT to include only technologies that replace or substantially replace human decision-making, and not requiring businesses to conduct risk assessments or comply with ADMT obligations solely for profiling consumers for behavioral advertising.
Updates and requirements
The key requirements of the final ADMT regulations are:
definition: ADMT is defined as “a technology that processes personal information and uses computing to replace or substantially replace human decision-making.” “Significantly replacing human decision making” means that decisions are made based solely on the output of the ADMT, without human involvement. Human involvement requires reviewers who can interpret and use the output, consider and analyze the output and other relevant information, and have the authority to make or change decisions.
range: This regulation applies when ADMTs are used to make “material decisions” about consumers (i.e., decisions that result in the provision or denial of financial or lending services, housing, educational admissions or opportunities, employment or independent contracting opportunities or compensation, or health care services). Tools such as firewalls, anti-malware, calculators, databases, and spreadsheets are explicitly excluded from the definition unless they replace human decision-making. Depending on your deployment, this definition may include agents and other AI technologies used by your enterprise.
Notification requirements: If a business plans to use ADMT to make important decisions, it must communicate in clear and simple language to consumers the reason for using the technology before or at the time of collecting personal information.
Consumer rights: Consumers have the right to opt out and access information about ADMT that is used to make important decisions that affect them. If a business provides consumers with a way to appeal a human reviewer who has the power to overturn a decision, or if ADMT is used for admissions, hiring, or job assignments, businesses are not required to provide consumers with the ability to opt out, unless their use would result in unlawful discrimination.
ADMT risk assessment: When companies use ADMT for important decision-making or specific training purposes, they must perform a risk assessment and document the types of personal information being processed and the logic of the system.
The CPPA suggests that regulations are likely to evolve in response to changes in technology and business practices.
For companies falling under the CCPA, now is the time to begin planning for gradual compliance with the final ADMT regulations. Companies should take inventory of the technologies they use to determine whether such technologies are considered ADMT under the regulations and whether they are being used to make critical decisions.
Companies should also focus on establishing a process for consumers to submit and comply with requests to access and opt out of ADMT use. If your company is dealing with other AI laws, such as the European Union’s AI Law or the Colorado AI Law, the ultimate goal will be to develop a strategy that can be applied to all such legal situations.
This article does not necessarily reflect the opinion of Bloomberg Law, Bloomberg Tax, Bloomberg Government, publisher Bloomberg Industry Group, Inc., or its owners.
Author information
Sharon Klein is a partner and co-chair of the Privacy, Security, and Data Protection practice at Blank Rome.
Alex Nisenbaum is a partner in Blank Rome’s Privacy, Security and Data Protection practice.
Karen Shin is an associate in Blank Rome’s privacy, security and data protection practice.
Please write to us: Author guidelines
