CCPA Grows Up: Risk Assessments, Audits and the Right to Ask for a Human
At 1:12 am on a Wednesday, Marco finishes an application for a shift lead job at a bakery chain in Fresno. It has taken him forty minutes. He has uploaded his résumé, retyped his résumé into eleven boxes because the form did not believe his résumé, and written 300 words about "a time you showed resilience". He clicks submit, goes to put the kettle on and thinks, with some pride, that he has just demonstrated resilience.
At 1:19 am, before the kettle has boiled, an email arrives.
"Thank you for your interest. After careful review, we have decided not to move forward with your application."
Careful review. Seven minutes, at one in the morning. Either the bakery employs a night-shift recruiter with superhuman reading speed and no need for sleep, or somebody's software weighed Marco's resilience essay against an invisible checklist and said no before the water hit 100 degrees. He cannot find out which. There is no phone number on the email, only a "do not reply" address, which is a very confident thing to write on a letter that has just rejected somebody. He drinks his tea and wonders whether "resilience" was the problem.
Stop there, because that feeling is the whole subject of this article. Being rejected is ordinary. Being rejected by something you cannot see or question is newer, and California is about to regulate it.
On 22 September 2025, California's Office of Administrative Law approved a large new set of regulations under the California Consumer Privacy Act (CCPA). The California Privacy Protection Agency (CPPA) announced it the next day. The rules take effect on 1 January 2026, and they do three big things. They give people rights over "automated decisionmaking technology", or ADMT: the software that says yes or no about a job, a loan, a flat or a hospital appointment. They make many businesses write risk assessments before they process personal information in risky ways. And they make larger businesses pay for independent cybersecurity audits every year, signed off by an executive under penalty of perjury.
In 2022 I wrote an introduction to the California Consumer Privacy Act (CCPA): see your data, delete it, stop its sale. This is the CCPA's awkward teenage growth spurt, with new paperwork and a calendar that runs to 2030.
So here is the plan. We start with a rejection letter you have probably had, and work down to what sits behind it: a score, a threshold and a model trained on somebody's history. Then the exact test California uses to call that an "automated decision", which turns out to be a test about people, not software. Then the four things a business must do about it, the risk assessments that will catch a lot of marketing teams, the audits and a calendar. Finally, a (made-up) HR manager called Hazel spends a week getting her bakery chain ready.
Let's get into it.
Part 1: The Letter You Already Get
If you have ever been declined for a credit card in the United States, you have already seen a rule that reaches into automated decisions. You just didn't know it had a name.
US lenders are covered by the Equal Credit Opportunity Act, and its Regulation B says that when a creditor turns you down, it must give you a statement of specific reasons, or tell you how to get one. "Specific" is doing heavy lifting there. The regulation says that statements that you "failed to achieve a qualifying score on the creditor's credit scoring system are insufficient". The bank cannot say "the computer said no". It has to say why the computer said no: too little credit history, too much debt for your income, too many recent applications.
In 2022, the Consumer Financial Protection Bureau closed a loophole that everybody could see coming. What if the lender uses a model so complex that nobody inside the bank can say why it declined you? The Bureau's answer, in Circular 2022-03, opens with one word: "Yes." Creditors must still give the reasons. Then comes my favourite sentence in American financial regulation: "A creditor's lack of understanding of its own methods is therefore not a cognizable defense."
I would like it framed above every data science team's kettle.
So this is the first step down. You already live with a rule that says: if a machine decides something important about you, somebody must be able to explain it. Lenders already do this. Marco's bakery never had to, because Regulation B covers credit, and I know of no US rule that makes employers give reasons in the same way. His email is legal, polite and empty.
California has now addressed that gap, and not only for jobs. But first, let's open up the thing that sent Marco's email.
Part 2: What Sits Behind the Letter
Strip away the branding, and most automated decisions about people have the same three parts.
- Inputs. Facts about you: your résumé, your credit file, your address, how many hours you worked last month.
- A score. A model turns the inputs into a number. It might be a probability ("72% likely to repay"), a rank ("candidate 14 of 300") or a star rating.
- A threshold. A rule turns the number into a decision. Above the line, yes. Below it, no.
The threshold is often the only part a person ever chose on purpose. Somebody in a meeting said "let's only interview people above 3.5 stars", and from then on, the line did the work without anyone in the building.
Where the model learns what "good" looks like
The score comes from a model, and a model learns from examples: for hiring, usually past applicants, labelled by what happened to them. It learns what the hired people had in common. It has no idea why they were hired.
The best-known example of this going wrong is a story Reuters reported in October 2018. Amazon built an experimental tool that gave job candidates scores from one to five stars, "much like shoppers rate products on Amazon". It was trained on résumés sent to the company over ten years, and most of them came from men. So the model learned that being a man was a pattern of success. In Reuters' words, it "penalized resumes that included the word 'women's,' as in 'women's chess club captain.'" Amazon edited the programs to be neutral to those terms, but that was no guarantee against other unfair patterns, and the company eventually disbanded the team.
I wrote about how this happens in a guide to bias in AI: a model trained on a biased history does not remove the bias. It learns the bias and repeats it faster, at 1:19 am.
The detail that matters most
Here is the part of the Amazon story that most retellings skip. According to Reuters' sources, Amazon's recruiters looked at the tool's recommendations, but "never relied solely on those rankings".1
Hold on to that. If a person looks at the score and makes the decision, is that an automated decision? Most people would say "partly". European law, in Article 22 of the GDPR, gives people "the right not to be subject to a decision based solely on automated processing". The word "solely" has kept European lawyers busy for years.
California had to answer the same question. Its answer is more specific, and it is where we go next.
Part 3: What California Counts as ADMT
The regulations define automated decisionmaking technology (ADMT) as "any technology that processes personal information and uses computation to replace human decisionmaking or substantially replace human decisionmaking".2 That is section 7001(e), and the whole regime depends on it. In plain terms: software that makes a decision about a person with their data, where a human either is not involved or is not really involved.
"Replace" is easy. The software decides, and nobody looks. "Substantially replace" is where California did something clever. It means a business uses the technology's output to make a decision without human involvement. And "human involvement" has a precise, three-part definition. The human reviewer must:
- know how to interpret and use the technology's output to make the decision;
- review and analyse the output, and any other relevant information, to make or change the decision; and
- have the authority to make or change the decision based on that analysis.
All three, not one of them.
Think of the decision as a toll bridge with a gate. The software raises and lowers the gate. For a person to count as involved, there must be a clerk in the toll house who can read the machine's slip, who actually looks at the slip and the traveller, and who holds the key to open the gate anyway. A clerk who cannot read the slip is decoration. A clerk who never looks up is asleep. A clerk without a key is a spectator with a cap.
So the test is about the human, not the model. If a recruiter at Company A reads every score, checks the résumé and can invite anyone to interview, the scorer is a tool. If Company B auto-rejects everyone under 3.5 stars, the same scorer is ADMT. Same software, different clerk.
That is why Amazon's tool, as Reuters described it, might not have met California's definition at all. Whether each recruiter could read and question a star rating is a question nobody asked in 2018.
The definition also names what is not ADMT. Web hosting, networking, caching, firewalls, anti-virus, spam filtering, spellcheckers, calculators, databases and spreadsheets are out, "provided that they do not replace human decisionmaking". Your spam filter is safe. A spreadsheet that automatically rejects every tenant with a credit score below 650 is not, because the exclusion stops the moment the spreadsheet starts making the decision.
Only significant decisions count
ADMT alone does not trigger the rules. The business must use it to make a significant decision, which section 7001(ddd) defines as a decision that results in the provision or denial of:
- financial or lending services (credit, loans, deposit accounts, cheque cashing, instalment plans);
- housing;
- education enrolment or opportunities (admission, credentials, suspension and expulsion);
- employment or independent contracting opportunities or compensation (hiring, allocation of work, pay, promotion, demotion, suspension and termination); or
- healthcare services.
Two exclusions matter a lot. First, "Significant decision does not include advertising to a consumer." So the model that decides who sees an ad for your credit card is not making a significant decision, even though the model that decides who gets the credit card is. Second, a housing decision based solely on whether a unit is vacant, or whether the rent payment arrived, is not a significant decision. "Sorry, it's taken" is not a decision about you.

One wrinkle for lending: the CCPA does not apply to personal information handled under the federal Gramm-Leach-Bliley Act, which covers much bank data.3 So the rules will bite hardest in hiring, work allocation, housing, education and healthcare.
How the definition got narrower
The approved version is much narrower than the drafts, and the CPPA's Final Statement of Reasons says so directly. Earlier drafts covered technology that would "substantially facilitate" human decisions, which could have caught almost any score a human ever looked at. The final text says "substantially replace". The Agency says it focused the definition "on a higher-risk use of ADMT at this time, which is a use without any human involvement". It deleted its definition of "artificial intelligence" altogether, and dropped a separate trigger for profiling people for behavioural advertising.
That did not happen in a vacuum. In April 2025, Governor Gavin Newsom sent the Agency a letter. According to Fisher Phillips' summary, he warned that overly broad rules could have "unintended consequences" for innovation, and asked for regulations that are "clear, reasonable, and focused". The Board modified the draft by a unanimous vote on 1 May, and adopted it on 24 July. As StateScoop put it, every reference to "artificial intelligence" was "scrubbed" from the final text.
Critics still call it heavy: Kristian Stout of the International Center for Law and Economics said in a statement to StateScoop that "the core framework remains rigid". My view: the narrow test is easier to apply and harder to wriggle out of, because it asks a factual question about your process instead of a philosophical one about "AI". Debevoise's analysis makes the practical point: "many uses of AI that fall short of replacing human decision-making" are now outside the rules. The Agency also says it "may revisit this definition in future rulemaking packages".
How many businesses does that leave? The Agency's own estimate is that 10% of businesses, 5,233 firms, will have to comply with the ADMT rules.
Part 4: The Four Things the Rules Require

A business that uses ADMT for a significant decision must comply by 1 January 2027 (section 7200). From then on, it has four jobs. We have committed to the toll bridge, so we are staying on it: a sign before you step on, another way across, the right to ask why the gate stayed shut, and an engineer who inspected the bridge before it opened.
1. The pre-use notice: the sign before the bridge
Section 7220 requires a pre-use notice. It must reach the person "at or before the point" when the business collects the data it will feed to the ADMT (or, for data it already holds, before the automated processing starts), in the way the business mainly talks to that person.
The notice must include:
- a plain-language explanation of the specific purpose. The rule bans generic wording such as "to make a significant decision". "We use software to screen applications and reject those without a current food handler card" is specific. "We use technology to improve our hiring" is not;
- the right to opt out and how to do it (or, if an exception applies, how to appeal, or which exception the business relies on);
- the right to access information about the ADMT, and how;
- a statement that the business cannot retaliate against people who use their CCPA rights; and
- more detail about how the ADMT works: which categories of personal information affect the output, what the output is and how it is used, and what the alternative process is for people who opt out. This part can sit behind a link or a layered notice.
A business does not have to reveal trade secrets, or information that would help people get around fraud or security controls.
2. Opt-out, or the human appeal: another way across
Section 7221 gives people the right to opt out of the business's use of ADMT for a significant decision. The mechanics are detailed:
- at least two ways to opt out. Online, one must be a form linked from the pre-use notice, titled for what it does, such as "Opt-out of Automated Decisionmaking Technology";
- no account creation, and no more identity checks than needed;
- if someone opts out later, the business must stop within 15 business days at most, and tell its service providers to stop too;
- a way for the person to confirm the opt-out worked; and
- a wait of at least 12 months before asking them to opt back in.
And there is a line in section 7221(c)(4) that I would like every marketing team to read twice: "A notification or tool regarding cookies, such as a cookie banner or cookie controls, is not by itself an acceptable method for submitting requests to opt-out of the business's use of ADMT". Your consent banner collects consent for cookies. It does not cover how you make decisions about people. (If your banner is not doing its own job properly, start with consent management.)
Now the catch, and the reason the title says "ask for a human" and not "say no". The opt-out has three exceptions:
- Human appeal. The business may skip the opt-out if it offers an appeal to a human reviewer who can overturn the decision. That reviewer must meet the same three tests as the toll house clerk. The appeal must be easy, and the person must be able to send information in support of it.
- Admission, acceptance and hiring. The business may skip the opt-out if it uses the ADMT solely to assess whether the person can do the work or the course, and the ADMT "works for the business's purpose and does not unlawfully discriminate".
- Allocation of work and pay. Same conditions, for deciding shifts, tasks and compensation.
So in practice, many people will not get a right to say no to the algorithm. They will get a right to be told about it, to ask how it treated them, and to have a qualified human look again. That is less dramatic than the headline. It may be more useful, because a human who can change the answer is exactly what Marco did not have at 1:19 am.
If you know the GDPR, this should feel familiar. Article 22(3) requires, where its exceptions apply, "at least the right to obtain human intervention". California has spelt out what that human must be able to do.
3. Access: asking why the gate stayed shut
Section 7222 gives people the right to access information about the business's use of ADMT on them. The CCPA itself asks for "meaningful information about the logic involved", and the regulations turn that into three explanations in plain language:
- the specific purpose for which the business used ADMT on this person (again, not "to improve our services");
- the logic: enough for the person to understand how the ADMT processed their information to produce an output about them. This "may include the parameters that generated the output as well as the specific output";
- the outcome: how the business used that output to make the decision, whether it was the only factor, and what any human in the process did.
The business must confirm the request within 10 business days and answer within 45 calendar days, with one 45-day extension if it explains why (section 7021). It may leave out trade secrets. If it used the ADMT on the same person more than four times in 12 months, it may give a summary instead of every result.4
Think back to Regulation B. A lender cannot say "you failed to reach a qualifying score", and under this access right a bakery will not be able to say "the system did not select you" either.

4. The risk assessment: the engineer before the bridge opens
The fourth obligation is a risk assessment, written before the ADMT starts (section 7150(b)(3)). Training ADMT, facial recognition or emotion recognition on personal information needs one too (section 7150(b)(6)). A vendor that makes ADMT trained on personal information available to other businesses must give them "all facts available" that they need for their own assessment (section 7153). If your résumé screener comes from a vendor, that sentence is your new favourite contract clause.
But the risk assessment is not only about algorithms, and that deserves its own section.
Part 5: The Part Marketers Will Miss
Here is the list of activities that require a risk assessment under section 7150(b). Read the first line slowly.
- Selling or sharing personal information.
- Processing sensitive personal information (with narrow exceptions for routine employee administration).
- Using ADMT for a significant decision.
- Inferring things about applicants, students or staff from systematic observation (productivity monitoring, badge tracking, video analysis).
- Inferring things about people from their presence at a sensitive location, such as a clinic, pharmacy, shelter or place of worship.
- Using personal information to train ADMT or identification technology, as above.
"Sharing" has a specific meaning under the CCPA. It means disclosing personal information to a third party for cross-context behavioural advertising: ads targeted at someone based on what they did on other businesses' sites and apps. That is a retargeting pixel. That is a customer list uploaded to an ad platform so it can find the same people elsewhere. For many websites with Californian visitors, that is Tuesday.
So a business that is covered by the CCPA and runs ordinary retargeting will need a written risk assessment for it. Advertising is excluded from "significant decisions", but sharing for advertising is on the risk assessment list. Those are two separate rules, and it is easy to read the first and miss the second.
What goes in the assessment
Section 7152 sets out the contents, and it is more structured than most internal "privacy impact assessments" I have seen. It must name the specific purpose ("to improve our services" is banned by name), the categories of data and the minimum needed, how the data is collected, kept and disclosed and to whom, and, for ADMT, the logic with its assumptions and limitations. It must weigh the benefits against the negative impacts, from discrimination and dark patterns to economic, reputational and psychological harm, and list the safeguards. And it must record whether the business will go ahead, and who approved it. That person must have the authority to take part in deciding whether the processing starts.
The goal is written into the statute and repeated in section 7154: to restrict or prohibit the processing "if the risks to privacy of the consumer outweigh the benefits". A risk assessment that always concludes "go ahead" is a form. The rule expects it to be able to say no.
When, and who sees it
- New processing from 1 January 2026 needs an assessment before it starts.
- Existing processing that started before the rules and continues after them needs an assessment by 31 December 2027.5
- Assessments must be reviewed at least every three years, and updated within 45 calendar days of a material change.
- They must be kept for as long as the processing continues, or five years, whichever is later.
- By 1 April 2028, the business must send the CPPA a summary of its 2026 and 2027 assessments, with an attestation from an executive under penalty of perjury. After that, the summary is due every 1 April.
- The CPPA or the Attorney General can ask for the full reports at any time, and the business has 30 days to hand them over.
That last point changes the document. You are writing it for a regulator who may read it after something went wrong. Write it like that.
The CPPA is already enforcing the CCPA with some energy. On the last day of September it announced its largest fine so far, US$1.35 million, against a retailer whose failures included not honouring opt-out preference signals such as Global Privacy Control, and not telling job applicants about their privacy rights.
Part 6: Cybersecurity Audits, or the Inspector Who Did Not Build the Bridge

The third part of the package has nothing to do with algorithms, and it is where most of the money goes. Section 7120 requires a cybersecurity audit from any business whose processing "presents significant risk to consumers' security". That is a business that either:
- gets 50% or more of its annual revenue from selling or sharing personal information; or
- meets the CCPA's revenue threshold (US$25 million, adjusted for inflation) and, in the previous year, processed the personal information of 250,000 or more consumers or households, or the sensitive personal information of 50,000 or more consumers.
A mid-sized online retailer can meet that without ever calling itself a data company.
The inspector's rules
The audit must be done by a "qualified, objective, independent professional" using accepted auditing standards (the rule names the AICPA, the PCAOB, ISACA and ISO). The auditor can be internal, but the independence rules are strict. The auditor must not have helped build what they audit: no developing procedures, no preparing the business's documents, no recommendations beyond the audit findings, and no running the security programme. An internal lead auditor must report to an executive who is not responsible for cybersecurity. And findings must rely primarily on evidence (documents, sampling, testing, interviews), not on "assertions or attestations by the business's management".
In bridge terms: the inspector may not have built the bridge, may not take the builder's word for it, and has to tap the timbers.
What the inspector looks at
Section 7123(c) lists 18 components the audit must assess where they apply. Some are more specific than I expected from a privacy regulation: phishing-resistant multi-factor authentication for staff and contractors; strong, unique passwords (for example, at least eight characters and not on a list of common passwords); encryption at rest and in transit; least-privilege access and privileged-access management; inventories and maps of personal information; patching and change management; penetration tests and a way for outsiders to report bugs; centralised audit logs and bot detection; annual security training; code reviews; retention schedules; and tested incident response plans and backups.
If you have read my earlier post on two-factor authentication, a lot of this list will look familiar. The difference is that someone independent now checks it, and someone senior signs for it.
The report must describe gaps and the plan to fix them, with a statement signed by the lead auditor, and the documents must be kept for five years. Each year, an executive submits a certification to the CPPA, signed under penalty of perjury, that the audit was done and that the business "has not made any attempt to influence the auditor's decisions".
An existing audit, such as one against the NIST Cybersecurity Framework 2.0, can be reused if it meets every requirement.
What it costs
The Agency's own estimate of total direct costs to businesses over ten years is US$4.835 billion, down from US$9.725 billion before the draft was narrowed. Cybersecurity audits are 71% of that. ADMT is 9%. For a small business, the Agency estimates initial costs between US$6,058 and US$36,950. That is less than many people feared.6
Part 7: The Calendar
The rules take effect on 1 January 2026, but almost nothing is due that day, which is how rules like this get forgotten. Here is the whole calendar.

The two dates people will miss are 1 January 2026, when new high-risk processing needs a risk assessment before it starts, and 31 December 2027, when every older activity needs one too.
Notice the trap in the audit dates. A business with more than US$100 million must complete its first audit report by 1 April 2028, but the audit covers the period from 1 January 2027. So the controls must be in place, and producing evidence, from the start of 2027. You cannot audit a year that has already happened without the records from it.
California is not alone
Over the same few months, other rules moved in the same direction:
- California's Civil Rights Council has employment rules on automated-decision systems in effect from 1 October 2025, including a duty to keep automated-decision data for four years.
- Mobley v. Workday, an age discrimination case about AI screening, was preliminarily certified as a collective action in May 2025.
- Colorado's AI Act was pushed back in August 2025 to 30 June 2026.
- Here in Australia, privacy policies must describe substantially automated decisions with a significant effect from 10 December 2026: transparency only, with no opt-out or access right. (Background in Australia's privacy law overhaul.) The California inventory will do most of the Australian work for you.
Part 8: Hazel's Week at the Bakery

Meet Hazel. Hazel runs people operations for a chain of 40 bakeries across California's Central Valley. It has 700 staff and sells, by her own estimate, an alarming number of muffins. (Hazel and her bakeries are made up. The muffins are an act of faith.) It is the bakery that rejected Marco. In late September 2025 her general counsel forwards her the CPPA announcement with one line: "Are we ready for this?"
Hazel has until 1 January 2027 for the ADMT rules. She decides to find out this week what she is dealing with.
Monday: list every decision software makes about people
Hazel lists every system that touches applicants and staff and asks one question of each: does it say yes or no to a person, or does it help a person say yes or no?
- Applicant tracking system. Scores applications and sends an automatic rejection to anyone without a current food handler card, or with a score under 60. That is how Marco got his email at 1:19 am.
- Shift scheduling tool. Assigns weekly shifts based on availability, past sales and a "reliability" score. Managers can edit the schedule, but most do not.
- Payroll. Calculates pay from hours worked, using rules a human set.
- The marketing team's website. Has a retargeting pixel and uploads customer lists to two ad platforms.
Tuesday: run the clerk test on each one
For each system, she asks the three questions from section 7001(e). Can the human read the output? Do they actually review it, with other information? Can they change the decision?
- Applicant tracking, automatic rejections: no human at all. ADMT, making a significant decision (hiring). In scope.
- Applicant tracking, candidates above the line: a recruiter reads every one and decides who to interview. Probably not ADMT for that step.
- Scheduling: managers can edit, so on paper there is a human. But Hazel pulls the edit logs and finds that 94% of weekly schedules go out unchanged, and few managers know what the reliability score means. The first and second tests are shaky. She treats it as ADMT for allocation of work, which is a significant decision.
- Payroll: a calculator in the sense of the exclusion, applying human rules. Not ADMT.
The records matter. The tracking system logs the score and the rule that fired, but not which features pushed the score down. The scheduler logs every edit with the manager's name, which is the evidence of human involvement, or of its absence.
Wednesday: start the risk assessments
Hazel opens three risk assessments: automatic rejections, scheduling, and, to her surprise, the marketing team's retargeting, because that is sharing under the CCPA and the bakery is a covered business. The retargeting started years ago, so its deadline is 31 December 2027. Any new high-risk processing from 1 January 2026 needs its assessment first.
She emails both vendors and quotes section 7153: please send the facts we need for our risk assessment, including the logic and its limitations. For the rejection rule, she asks the question the rule makes her answer: what is the benefit, and does it outweigh the risk that a good applicant, like a man who wrote 300 thoughtful words about resilience at one in the morning, is rejected unseen?
Thursday: draft the notice and choose opt-out or appeal
She drafts a pre-use notice for the job application page, above the first box, not in the footer:
We use software to check that applicants hold a current California food handler card, and to score applications against the job requirements. Applications without a card, or with a score below our threshold, are rejected automatically. You can ask a person to review your application instead [link], and you can ask us how the software assessed your application [link].
The hiring exception needs her to show the tool does not unlawfully discriminate, and she cannot yet. So she chooses the human appeal: a recruiter who can read the score, look at the whole application and override it. For scheduling, she offers an opt-out, with its own link and a phone number for store staff. Not the cookie banner.
Friday: test the access response on herself
Hazel submits an application under her own name, lets it be rejected, and then asks for an access response as if she were an applicant. The first draft from the vendor says "Your application did not meet the minimum score." That is exactly the sentence Regulation B has banned for lenders for years. The second draft names the three factors that lowered her score, gives her score and the threshold, and says a recruiter would have reviewed it on appeal. That one she keeps.
By Friday afternoon she has a list, a clear answer for each system, three risk assessments started and a draft notice. She has also changed one thing that no regulation required: the automatic rejection email now waits until 9 am. Nobody needs to be rejected before their kettle boils.
What to Do This Week
- Check that you are a CCPA "business". The statute's thresholds: revenue over US$25 million (adjusted for inflation), the data of 100,000 or more consumers or households bought, sold or shared, or half your revenue from selling or sharing.
- List every system that says yes or no to a person about money, housing, education, work or healthcare. Include vendor tools: applicant tracking, scheduling, tenant screening, credit checks, patient triage.
- Run the three-part human test honestly on each one. Pull the override logs. A human who approves every output and cannot explain the score is not "human involvement".
- List everything that counts as selling or sharing: pixels, conversion APIs, customer list uploads, data partnerships. Each one needs a risk assessment, by 31 December 2027 for existing activity, or before launch for new activity from 1 January 2026.
- Ask your vendors for their section 7153 facts now: the logic, its limitations and the output of every ADMT tool. Put it in the renewal contract.
- Decide opt-out or human appeal for each significant decision. If appeal, name the reviewers and train them to read the output. If opt-out, build two methods and a confirmation. Not the cookie banner.
- Draft pre-use notices with a specific purpose, and one access response for a real case. If either would fit any other company, or says "did not meet the score", start again.
- Check whether you need a cybersecurity audit (the 250,000 and 50,000 thresholds). Over US$100 million, your first audited year starts on 1 January 2027. Choose an independent auditor early.
- Name the executive who will sign under penalty of perjury, and tell them now. It concentrates the mind.
- Fix opt-out preference signals while you are there. The CPPA's largest fine to date included failures to honour Global Privacy Control, and the new rules say a business "must display" whether it has processed the signal.
Final Thoughts
Think back to Marco, drinking his tea at 1:20 am and wondering whether "resilience" was the problem.
From 1 January 2027, if the bakery's software makes that decision alone, he will have been told before he applied that software would screen him, and why. He will have a link to ask for a person instead, or to appeal to one who can change the answer. And he will be able to ask what the software looked at, and get more than "careful review". None of that stops a business using software to screen applicants. It stops the software being the only one in the room.
That is the one idea to take away. California's test does not ask how clever your model is. It asks whether a real person can read it, check it and overrule it. If the answer is yes, most of the ADMT rules stay quiet. If the answer is no, you owe people a notice, an alternative, an explanation and a written assessment of the risk. And separately, if you share data for ads or hold a lot of it, you owe a risk assessment or an audit whether or not an algorithm is involved.
So this week, make the list. Every system that says yes or no to a person, and who, if anyone, holds the key.
Now, if you'll excuse me, my kettle has boiled. Nobody has rejected me yet, which I choose to take as a good sign.
Notes
-
Amazon told Reuters in 2018 that its experimental recruiting tool "was never used by Amazon recruiters to evaluate candidates". It did not dispute that recruiters had looked at the tool's recommendations. ↩
-
The CPPA writes "decisionmaking" as one word throughout its regulations. I keep that spelling in quotes and in the defined term "automated decisionmaking technology", and use "decision-making" in my own sentences. ↩
-
Section 1798.145(e) of the California Civil Code excludes personal information collected, processed, sold or disclosed under the Gramm-Leach-Bliley Act or the California Financial Information Privacy Act. The exclusion covers the data, not the whole company, so a bank's marketing website can still be in scope. ↩
-
The regulations also allow, but do not require, extra context in an access response, such as the five most common outputs of the ADMT and the share of people who received each one last year. It is a rare regulation that suggests a leaderboard. ↩
-
In the text filed on 22 September 2025, section 7155(b) still reads "[OAL to fill in the effective date of these regulations]" where a date should be. The Office of Administrative Law's approval notice sets the effective date as 1 January 2026, so that is the date the placeholder stands for. ↩
-
I drink about 1,820 cups of tea a year. I have never written a risk assessment for it, because the benefits so clearly outweigh the risks, and because nobody has asked me to sign one under penalty of perjury. ↩


