California’s ADMT regulations reshape the Artificial Intelligence business landscape

California’s finalized ADMT rules under the California Consumer Privacy Act establish notice, consumer rights, and risk assessment obligations for businesses using Automated Decision-Making Technology for significant decisions, and they will shape deployments of Artificial Intelligence that replace or substantially replace human decisionmaking.

California has finalized new regulations under the California Consumer Privacy Act that address cybersecurity audits, risk assessments, and Automated Decision-Making Technology (ADMT). The California Privacy Protection Agency began rulemaking in November 2024 and set an effective date of Jan. 1, 2026 for the rules generally. Businesses that use ADMT to make significant decisions must comply with ADMT-specific requirements beginning Jan. 1, 2027. The rulemaking drew extensive feedback from tech companies, advocacy groups, and government leaders; concerns that an overly broad ADMT definition would hinder innovation prompted the final regulations to narrow the scope.

The regulations define ADMT as any technology that processes personal information and uses computation to replace or substantially replace human decisionmaking. “Significant decision” is limited to outcomes such as the provision or denial of financial or lending services, housing, education enrollment or opportunities, employment or independent contracting opportunities or compensation, and healthcare services. The rules expressly exclude tools such as firewalls, anti-malware, calculators, databases, and spreadsheets when they do not replace human decisionmaking. When businesses plan to use ADMT for a significant decision they must notify consumers before or at the time of collection and explain, in clear and simple terms, why the technology is being used.

Consumers gain rights to access information about and opt out of ADMT used for significant decisions, though businesses may avoid an opt-out obligation by providing an appeals process to a human reviewer with authority to overturn decisions. The rules require businesses to perform documented risk assessments for ADMT used in significant decisions or specific training purposes and to record the types of personal information processed and the system’s logic. The CPPA expects the regulations to evolve as technology and business practices change. Businesses subject to the CCPA should inventory technologies, establish processes for consumer requests, and consider cross-jurisdictional strategies that align with the European Union’s Artificial Intelligence Act and the Colorado Artificial Intelligence Act.

68

Impact Score

Global regulatory trends on the use of generative artificial intelligence

Governments in the EU, Japan, the United States, and the United Kingdom are moving quickly to regulate generative artificial intelligence, using a mix of binding laws, guidelines, and standards. Diverging philosophies and timelines are making cross-border compliance planning increasingly complex for companies.

Perplexity launches Computer to orchestrate many Artificial Intelligence models

Perplexity is rolling out Computer, a cloud-based agent that coordinates 19 Artificial Intelligence models for complex workflows, as it pivots toward high-value enterprise users and deep research. The launch underscores a broader bet on multi-model orchestration, custom benchmarks and a boutique business strategy over mass adoption.

Contact Us

Got questions? Use the form to contact us.

Contact Form

Clicking next sends a verification code to your email. After verifying, you can enter your message.