CCPA Regulations 2026: ADMT, Risk Assessments and Audits

CCPA regulations attestation forms with a notary stamp for ADMT and risk assessment compliance

Key takeaways

  • The CCPA regulations were rewritten with effect from 1 January 2026, adding three new articles on cybersecurity audits, risk assessments and automated decisionmaking technology (ADMT), plus one on insurance companies.
  • A business already using ADMT for a significant decision about a consumer, applicant or employee must have a pre-use notice, an opt-out or a qualifying exception, and an access process in place by 1 January 2027.
  • Risk assessments are required before any new high-risk processing today. Processing that started before 2026 must be assessed by 31 December 2027, and an executive attestation reaches the agency by 1 April 2028.
  • Independent cybersecurity audits start with a first certification on 1 April 2028 for businesses above \$100 million in revenue, then 2029 and 2030 for smaller ones.
  • Every 2026 enforcement action so far punished opt-out friction or over-collection. Those are the same controls the new ADMT and risk assessment duties will test.

What the CCPA regulations are, and what changed on 1 January 2026

The CCPA regulations are the rules in Title 11 of the California Code of Regulations that turn the California Consumer Privacy Act, as amended by the CPRA, into operational duties. They are written and enforced by the California Privacy Protection Agency, which now calls itself CalPrivacy, while the Attorney General keeps a parallel enforcement role. The current version of the CCPA regulations came out of a two-year rulemaking. The Office of Administrative Law approved the package on 22 September 2025 (Latham & Watkins), the agency announced it the next day, and it took effect on 1 January 2026 (CPPA announcement). Four articles are new: Article 9 on cybersecurity audits (sections 7120 to 7124), Article 10 on risk assessments (sections 7150 to 7157), Article 11 on ADMT (sections 7200 to 7222) and Article 12 on insurance companies (approved text). The package also rewrote existing rules. Closing a cookie banner no longer counts as consent, opting out must take no more steps than opting in, and businesses must show consumers that an opt-out request, including a Global Privacy Control signal, has been honoured (Greenberg Traurig). The definition of sensitive personal information now covers neural data and the personal information of consumers the business knows are under 16. Who is covered has not changed. The CCPA regulations apply to a for-profit business that does business in California and meets one of three tests: annual gross revenue above \$26,625,000 (the figure adjusted for inflation on 1 January 2025), buying, selling or sharing the personal information of 100,000 or more consumers or households, or earning at least half its revenue from selling or sharing personal information (CalPrivacy CPI page). Since 2023, “consumer” includes employees, job applicants and business contacts, which is why an employer with no consumer app can still owe everything below. For how California’s privacy rules sit next to its AI statutes, see our California AI laws guide.

CCPA regulations by date: the 2026 to 2030 calendar

The CCPA regulations phase in over four years, and most ranking summaries were written before the first date passed. The table sorts every milestone we could verify against the regulation text and agency announcements, as of 16 September 2026. <table header-row=”true”> <tr> <td>Date</td> <td>What applies</td> <td>Who</td> </tr> <tr> <td>1 January 2026</td> <td>Revised CCPA regulations in force; risk assessment before any new high-risk processing</td> <td>Every covered business</td> </tr> <tr> <td>1 August 2026</td> <td>Registered data brokers must process DROP deletion requests at least every 45 days</td> <td>Data brokers</td> </tr> <tr> <td>1 January 2027</td> <td>ADMT pre-use notice, opt-out and access for significant decisions</td> <td>Businesses using ADMT</td> </tr> <tr> <td>1 January 2027</td> <td>Browsers must offer an opt-out preference signal (AB 566); CPI adjustment of thresholds and fines; data broker fee rises to \$9,500</td> <td>Browser makers, all businesses, brokers</td> </tr> <tr> <td>31 December 2027</td> <td>Risk assessments for processing that began before 2026 and continues</td> <td>Every covered business</td> </tr> <tr> <td>1 April 2028</td> <td>First risk assessment submission and attestation; first cybersecurity audit certification (2026 revenue above \$100 million)</td> <td>Every covered business; largest businesses</td> </tr> <tr> <td>1 April 2029</td> <td>First audit certification for 2027 revenue of \$50 million to \$100 million</td> <td>Mid-size businesses</td> </tr> <tr> <td>1 April 2030</td> <td>First audit certification for businesses below \$50 million</td> <td>Smaller businesses</td> </tr> </table> Two things follow from the table. First, 1 January 2027 is the only hard deadline this year, and it lands on the same day as the Colorado and California AI statute dates covered in our Colorado AI Act guide. Second, the risk assessment backlog and the first audit period both run through 2027, so the evidence you create next year is what gets attested in 2028.

ADMT under the CCPA regulations: what you owe by 1 January 2027

Article 11 is the part of the CCPA regulations that most directly governs AI. Section 7200(b) is precise on timing: a business that uses ADMT for a significant decision before 1 January 2027 must comply by that date, and anything deployed later must comply before first use.

Is it ADMT? The human involvement test

ADMT means any technology that processes personal information and uses computation to replace, or substantially replace, human decisionmaking (section 7001(e)). A tool substantially replaces a human unless a reviewer meets three conditions: they know how to interpret and use the output, they review that output together with other relevant information, and they have authority to make or change the decision. A manager who clicks “approve” on a ranked shortlist without authority or context does not meet the test. Profiling counts as ADMT when it replaces human judgment. Spreadsheets, spam filters, firewalls and databases do not. The duties apply only to significant decisions: those that provide or deny financial or lending services, housing, education enrollment or opportunities, employment or contracting opportunities or compensation, and healthcare services. Employment is read broadly and covers hiring, allocation of work, pay and bonuses, promotion, demotion, suspension and termination. Advertising to a consumer is expressly excluded. This is the same territory as our guide to automated employment decision tools, and the governance design behind a real reviewer is set out in human oversight.

The pre-use notice

Section 7220 of the CCPA regulations requires a notice at or before the point of collection, or before existing data is repurposed for ADMT. It must state the specific purpose in plain language (“to make a significant decision” is not enough), explain the opt-out or the exception relied on, describe the access right and the ban on retaliation, and explain how the ADMT works: which categories of personal information affect the output, what the output is, how it feeds the decision, and what the alternative process is for people who opt out. Trade secrets and security-sensitive details may be withheld. A consolidated notice is allowed when one tool serves several purposes or several tools serve one.

The opt-out and its three exceptions

Section 7221 of the CCPA regulations gives consumers the right to opt out of ADMT for significant decisions, with at least two submission methods, one matching how the business usually interacts with them. A cookie banner is not an acceptable method. Once a request arrives, processing must stop within 15 business days, and service providers must be told to stop too. The business must wait 12 months before asking again. The opt-out can be replaced by one of three exceptions:

  1. Human appeal. The consumer can appeal to a trained reviewer who has authority to overturn the decision and must consider what the consumer submits.
  2. Admission, acceptance or hiring. The ADMT is used solely to assess ability to perform at work or in an educational programme, and it works for that purpose without unlawful discrimination.
  3. Allocation of work and compensation. The ADMT is used solely for that purpose, under the same accuracy and non-discrimination condition.

The second and third exceptions are not free. “Works for its purpose and does not unlawfully discriminate” is a factual claim, so the CCPA regulations effectively require validation and bias testing records to rely on them.

Access requests

Under section 7222 of the CCPA regulations, a consumer can ask how ADMT was used about them. The response must give the specific purpose, the logic of the ADMT in terms the person can follow (which may include the parameters and their own output), and the outcome, including whether the output was the sole factor and what any human did. If a tool was used more than four times on one person in 12 months, an aggregate answer is permitted. Vendors must help their customers answer.

Risk assessments: the backlog due 31 December 2027

Article 10 of the CCPA regulations is the obligation with the longest tail. Section 7150 lists six activities that present significant risk and require an assessment before they start:

  • selling or sharing personal information;
  • processing sensitive personal information (with a narrow carve-out for payroll, benefits and similar HR administration);
  • using ADMT for a significant decision;
  • using automated processing to infer traits such as ability, performance or health from systematic observation of applicants, students, employees or contractors;
  • inferring those traits from a consumer’s presence at a sensitive location;
  • processing personal information to train ADMT for significant decisions, or to train facial recognition, emotion recognition or other identity and biometric technology.

Section 7152 of the CCPA regulations sets the content of the report: a specific purpose, the categories and minimum necessary personal information, operational details (sources, retention, recipients, number of consumers, disclosures), for ADMT the logic and how the output is used, benefits, negative impacts across security, discrimination, economic, physical, reputational and psychological harm, safeguards, the decision to proceed, contributors, and the names of approvers who have authority over that decision. Section 7154 states the purpose bluntly: processing should be restricted or prohibited when the risks to privacy outweigh the benefits. An assessment that never changes a decision will be hard to defend. Under the CCPA regulations, assessments must be reviewed at least every three years and updated within 45 calendar days of a material change. They are kept for as long as processing continues or five years after completion, whichever is later. Two provisions reduce the work. Section 7156 allows one assessment for a comparable set of processing activities and lets you reuse an assessment written for another law, such as a data protection assessment under the Colorado, Virginia or Connecticut privacy statutes or a GDPR DPIA, if you add the missing elements. Section 7153 obliges a business that makes ADMT available to others to give its customers all the facts they need for their own assessment, which is a clause to write into every AI vendor due diligence questionnaire. The filing is where the CCPA regulations bite. By 1 April 2028, and every 1 April after that, a business submits the number of assessments by trigger, the categories of personal information involved, and an attestation, under penalty of perjury, signed by an executive directly responsible for risk assessment compliance (section 7157). The agency or the Attorney General can also demand the full reports at any time, with 30 calendar days to produce them. Our privacy impact assessment and AI impact assessment guides show how to build one template that serves all of these.

Cybersecurity audits: who, when and how independent

Article 9 of the CCPA regulations applies to businesses whose processing presents significant risk to security: those that earn half or more of their revenue from selling or sharing personal information, and those above the revenue threshold that processed the personal information of 250,000 or more consumers or households, or the sensitive personal information of 50,000 or more consumers, in the preceding year (section 7120). Under the CCPA regulations, timing depends on revenue. A business with 2026 revenue above \$100 million audits calendar year 2027 and certifies by 1 April 2028; between \$50 million and \$100 million, the first certification is due 1 April 2029; below \$50 million, 1 April 2030 (section 7121). After that the audit is annual. The independence rules in section 7122 of the CCPA regulations matter more than the dates. The auditor may be internal, but the head of internal audit must report to an executive with no responsibility for the cybersecurity programme, and that executive sets the auditor’s pay and evaluation. The auditor must not have designed or run the controls being audited. Findings cannot rest mainly on management assertions; they must rely on documents, sampling and testing. The certification in section 7124 is signed under penalty of perjury. If your AI audit function also reviews cyber controls, check its reporting line now.

Enforcement in 2026: what the fines tell you

The 2026 enforcement record under the CCPA regulations is the best guide to where the next ADMT and risk assessment cases will come from, and almost none of the ranking pages mention it.

  • Disney, \$2.75 million (Attorney General, 11 February 2026). Opt-outs applied only to one service or device, and Global Privacy Control signals were not honoured account-wide (Hunton).
  • PlayOn Sports, \$1.1 million (CalPrivacy, 3 March 2026). Students had to accept tracking to use tickets, and the order requires the company to conduct risk assessments (Hunton).
  • Ford, \$375,703 (CalPrivacy, 5 March 2026). Consumers had to confirm an email address before an opt-out was processed (CalPrivacy).
  • General Motors, \$12.75 million (Attorney General with CalPrivacy and four district attorneys, 8 May 2026). The largest CCPA settlement to date and the first data minimisation case, over driving and location data sold to data brokers (California Attorney General).
  • LocateSmarter, \$116,490 (CalPrivacy, 11 August 2026). The first action against a data broker under both the CCPA and the Delete Act, for demanding Social Security digits before an opt-out (CalPrivacy).

The pattern is consistent: friction in exercising a right, and collecting or keeping more than the purpose needs. Administrative fines are capped at \$2,663 per violation and \$7,988 per intentional violation or violation involving under-16s, but each affected consumer can count as a separate violation, which is how settlements reach seven and eight figures. More is coming. At its 6 and 7 August 2026 meeting the CalPrivacy board directed staff to prepare formal rulemaking that names Global Privacy Control in the regulations (Wilson Sonsini), and from 1 January 2027 every browser must ship an opt-out preference signal under AB 566 (CalPrivacy).

One assessment, four regimes: CCPA, GDPR, EU AI Act and other states

For a group that sells in California and Europe, the CCPA regulations overlap heavily with duties it already carries. The mapping below is how we structure controls so one piece of evidence answers several regulators. <table header-row=”true”> <tr> <td>CCPA regulations duty</td> <td>GDPR</td> <td>EU AI Act</td> <td>Other US states</td> </tr> <tr> <td>Risk assessment (sections 7150 to 7157)</td> <td>DPIA, Article 35</td> <td>Fundamental rights impact assessment, Article 27, for certain deployers from 2 December 2027</td> <td>Data protection assessments in Colorado, Virginia, Connecticut</td> </tr> <tr> <td>ADMT opt-out or human appeal (section 7221)</td> <td>Article 22 safeguards, right to human intervention</td> <td>Human oversight, Articles 14 and 26</td> <td>Colorado AI Act human review and reconsideration</td> </tr> <tr> <td>ADMT access, logic and outcome (section 7222)</td> <td>Articles 13 to 15, meaningful information about the logic</td> <td>Right to explanation, Article 86</td> <td>Colorado AI Act disclosure within 30 days of an adverse outcome</td> </tr> <tr> <td>Cybersecurity audit (sections 7120 to 7124)</td> <td>Article 32 security of processing</td> <td>Accuracy, robustness and cybersecurity, Article 15</td> <td>NYDFS Part 500 for regulated firms</td> </tr> </table> The EU dates reflect Regulation (EU) 2026/1744, which moved Annex III high-risk obligations to 2 December 2027 (EUR-Lex). The practical point is sequencing: California’s ADMT date comes eleven months before the EU high-risk date, so a notice, appeal route and logic explanation built for the CCPA regulations becomes the first draft of your EU deployer file. Our EU AI Act high-risk guide covers the classification step.

The evidence file CalPrivacy can ask for

Because the agency can demand full risk assessment reports within 30 days and both attestations are signed under penalty of perjury, the CCPA regulations are really a records obligation. Keep these producible:

  1. An inventory of ADMT uses, each tagged with the significant decision category and the date first used.
  2. Every version of each pre-use notice, with publication dates and the channels used.
  3. Opt-out and appeal logs showing receipt, the 15-business-day stop, and notices to service providers.
  4. Reviewer records for the human appeal exception: who reviews, their training, their authority, and outcomes.
  5. Validation and non-discrimination testing for any ADMT relying on the hiring or work-allocation exception.
  6. Access request templates and sample responses explaining logic and outcome.
  7. Risk assessment reports with approver names, review dates and change triggers, kept for at least five years.
  8. Vendor fact packages received under section 7153, and the contract clauses that require them.
  9. Submission receipts and the signed attestations filed with the agency.
  10. Audit reports, auditor independence records (reporting line, pay and evaluation) and the certification.

This is the structure of an AI accountability record, and it only stays current with continuous compliance monitoring rather than an annual scramble.

A 107-day plan to 1 January 2027

From 16 September 2026 there are 107 days until the ADMT duties in the CCPA regulations apply. A realistic plan:

  1. Weeks 1 to 3: inventory. List every tool that scores, ranks, filters or recommends in hiring, workforce management, lending, housing, education or healthcare. Apply the three-part human involvement test honestly.
  2. Weeks 4 to 6: choose the route per use. Opt-out with an alternative process, human appeal, or one of the two narrow exceptions. Document why.
  3. Weeks 7 to 10: build and test. Draft pre-use notices, stand up two opt-out methods, write the access response template, train reviewers, and request section 7153 facts from vendors.
  4. Weeks 11 to 15: assess and evidence. Run risk assessments for ADMT uses first, then schedule the pre-2026 backlog through 2027. Fix the internal audit reporting line if you fall under Article 9.

Keep the plan in the same register as your broader AI governance framework, so the next state or EU deadline adds rows rather than a new programme.

FAQ

What are the new CCPA requirements for 2026? The revised CCPA regulations took effect on 1 January 2026. They require risk assessments before high-risk processing, set ADMT notice, opt-out and access duties from 1 January 2027, and phase in independent cybersecurity audits from 2028. They also tightened consent rules, banned treating a closed cookie banner as consent, and required visible confirmation that opt-outs, including Global Privacy Control signals, were honoured. Is the CCPA still in effect? Yes. The CCPA, as amended by the CPRA, and the CCPA regulations that implement it are fully in force and enforced by both CalPrivacy and the Attorney General. Enforcement accelerated in 2026, with the \$12.75 million General Motors settlement in May and a first data broker action in August. The inflation-adjusted thresholds and fines will be updated again on 1 January 2027. Who is required to comply with the CCPA regulations? For-profit businesses doing business in California that have annual gross revenue above \$26,625,000, buy, sell or share the personal information of 100,000 or more consumers or households, or earn half their revenue from selling or sharing it. Location outside California does not exempt a business, and employees and job applicants count as consumers. What is the difference between the CCPA and the GDPR? The GDPR requires a legal basis for all processing; the CCPA mainly regulates notice, consumer rights and selling or sharing. The CCPA regulations now narrow that gap: risk assessments resemble DPIAs, and ADMT rights resemble Article 22 safeguards. The CCPA uses revenue and volume thresholds, while the GDPR applies to almost every organisation handling EU personal data. Do the ADMT rules cover generative AI and chatbots? Only when the tool is used to make, or substantially replace a human in making, a significant decision about a person, such as screening candidates or approving a loan. A customer service chatbot or a drafting assistant is not ADMT under the CCPA regulations unless its output decides one of those outcomes without real human involvement. Does a European company need to comply with the CCPA regulations? Yes, if it does business in California and meets a threshold, for example through Californian customers, a US subsidiary or Californian employees. Much of the work overlaps with GDPR DPIAs and the EU AI Act deployer duties, so a single assessment template with a California annex is usually the efficient route.

Conclusion

The CCPA regulations are no longer a proposal to monitor. They have applied since 1 January 2026, the ADMT duties arrive on 1 January 2027, and by 1 April 2028 an executive will sign, under penalty of perjury, that risk assessments exist. The 2026 fines show what enforcers test first: whether a right is easy to exercise and whether data use matches its purpose. Treat the next 107 days as the time to inventory decision tools, pick a lawful route for each, and start the evidence file that the 2028 attestation will rely on. Built once and mapped to GDPR and the EU AI Act, that file serves every regulator asking the same question in a different vocabulary. If you are scoping several jurisdictions at once, start from our overview of AI laws in 2026 and the controls that recur across them.

CCPA Regulations 2026: ADMT, Risk Assessments and Audits

The CCPA regulations in force since January 2026 add ADMT duties from 1 January 2027, risk assessment filings in 2028 and audits to 2030. Dates and evidence.

What Is Adversarial AI? Attacks, Defenses & Governance

Adversarial AI attacks ML models through poisoning, evasion and prompt injection. See the attack types, defenses, and governance controls the EU AI Act now requires.

California AI Laws: Who Must Comply, and by When

California AI laws explained by role and date: SB 53, SB 942, SB 243, CCPA ADMT, FEHA rules and the bills Newsom signed in September 2026.

TRAIGA Compliance: The Texas AI Law, Operationalized

TRAIGA has been in force since January 2026. What the Texas AI law prohibits, how the NIST AI RMF safe harbour works, and the evidence you need to rely on it.

Vendor Due Diligence for AI: 12 Questions Checklists Miss

Standard vendor due diligence was built for a pre-AI supply chain. Here are the 12 AI-specific questions to add, and the legal duty behind them.

Model Risk Management for AI and Machine Learning

Model risk management is being rewritten for AI. See how SR 26-2, the EU AI Act, ISO 42001 and NIST AI RMF reshape MRM for machine learning and GenAI.