Skip to main content
v2026.11,858 entries · CC-BY 4.0

California’s CPPA ADMT Regulations: A Separate Regime From FEHA’s ADS Rules

Two California agencies regulate automated decision-making on two different theories, and compliance teams keep conflating them. The CPPA’s ADMT regulations — adopted July 24, 2025, effective January 1, 2026 — are consumer-privacy law: pre-use notice, an opt-out right, an access right, and a risk-assessment trigger, for ADMT used in financial, housing, education, employment, or healthcare decisions. That is a wholly separate regime from the Civil Rights Council’s FEHA automated-decision-system rules, which are anti-discrimination law enforced by a different agency on a different theory.

Written and maintained by CASRAI Editorial Board

Last updated

Last verified: September 25, 2026. Two California agencies now regulate automated decision-making, on two different legal theories, and compliance teams keep filing them under the same mental folder. They are not the same rule. The California Civil Rights Council’s automated-decision-system regulations under the Fair Employment and Housing Act (FEHA) are anti-discrimination law — they attach liability when an employer’s tool produces a disparate impact on a protected class. The California Privacy Protection Agency’s (CPPA) Automated Decisionmaking Technology (ADMT) regulations are consumer-privacy law — they give consumers a notice, an opt-out, and an access right, regardless of whether any discrimination occurred. Different agency, different statute, different remedy, different trigger. This guide covers the CPPA’s ADMT rules on their own terms; for the FEHA rules and where the two regimes actually diverge, see our comparison of NYC Local Law 144 and California’s FEHA automated-decision-system rules.

The Basics: What the ADMT Regulations Are and When They Bite

The rules are part of a single rulemaking package the CPPA titled “CCPA Updates, Cyber, Risk, Automated Decisionmaking Technology (ADMT), and Insurance Regulations.” The CPPA Board adopted the final text on July 24, 2025; the Office of Administrative Law approved it and it was filed with the Secretary of State on September 22, 2025; it took effect January 1, 2026. As of today it has been in force for nearly nine months.

The package amends Title 11, Division 6, Chapter 1 of the California Code of Regulations (the standing CCPA regulations) and adds two new articles that matter here:

  • Article 10, Risk Assessments (§ 7150 et seq.) — sets out when a business must conduct a risk assessment before processing, and lists “using ADMT for a significant decision” and “training an ADMT for a significant decision” as two of the triggers.
  • Article 11, Automated Decisionmaking Technology (§ 7200 et seq.) — the ADMT-specific consumer rights: pre-use notice, opt-out, and access.

If your source for this topic cited “§ 7150 et seq.” as the ADMT rule itself, that citation points at the risk-assessment article, not the ADMT rights article — the two are adopted together in the same package and cross-reference each other, but they are separate Articles with separate operative sections. The rights consumers actually exercise — notice, opt-out, access — live in Article 11, starting at § 7200.

There is also a phase-in most summaries skip. Under § 7200(b), a business already using ADMT for a significant decision before January 1, 2026 has until January 1, 2027 to come into compliance with Article 11. A business that starts using ADMT for a significant decision on or after January 1, 2027 must already be compliant when it starts. So “in force since January 1, 2026” is accurate for the regulation’s legal effect, but a business with a legacy ADMT deployment has a full additional year of runway before enforcement of the Article 11 duties bites on that specific use.

What Counts as “ADMT,” and What Doesn’t

Section 7001(e) defines automated decisionmaking technology as any technology that processes personal information and uses computation to replace or substantially replace human decision-making. The regulation does the real work in defining “substantially replace”: a human is not meaningfully involved unless a human reviewer (1) knows how to interpret and use the technology’s output, (2) actually reviews and analyzes that output and any other relevant information, and (3) has the authority to change the decision based on that analysis. Rubber-stamping an algorithmic output does not count as human involvement under this test — all three elements have to be genuinely present.

The definition explicitly includes profiling that replaces or substantially replaces human decision-making, and explicitly excludes web hosting, domain registration, networking, caching, firewalls, anti-virus/anti-malware, spam filtering, spell-checking, calculators, databases, and spreadsheets — provided none of those are actually doing the replacing.

What Counts as a “Significant Decision”

The regulations only apply where ADMT is used to make a “significant decision,” and § 7001(ddd) defines that narrowly by outcome, not by sector label. A significant decision is one that results in the provision or denial of:

  • Financial or lending services — extension of credit or a loan, fund transmission/exchange, deposit or checking accounts, check cashing, installment payment plans.
  • Housing — provision or denial of a home, residence, or sleeping place. Denials based solely on unit availability/vacancy or solely on whether payment was received are carved out — those are not “significant decisions” under the rule.
  • Education enrollment or opportunities — admission or acceptance into academic or vocational programs; educational credentials (degrees, diplomas, certificates); suspension and expulsion.
  • Employment or independent contracting opportunities or compensation — hiring; allocation or assignment of work, salary, hourly or per-assignment pay, incentive compensation; promotion; demotion, suspension, and termination.
  • Healthcare services — diagnosis, prevention, or treatment of disease or impairment, or assessment or care of an individual’s health.

Advertising to a consumer is expressly excluded from “significant decision” regardless of how targeted or consequential it feels. This is a materially narrower gate than “any AI used in a high-stakes context” — a business can use ADMT extensively and still fall outside Article 11 if none of its uses land in one of these five outcome categories.

The Three Consumer Rights, Section by Section

Pre-use Notice (§ 7220)

Before using ADMT to make a significant decision, a business must give consumers a Pre-use Notice, presented prominently at or before the point of collection, in plain language, that: (1) states the specific purpose of the ADMT use — “to make a significant decision” alone does not satisfy this; (2) describes the opt-out right and how to exercise it, or, if the business is relying on the human-appeal exception, describes the appeal process instead; (3) describes the access right and how to exercise it; (4) confirms the business will not retaliate for exercising CCPA rights; and (5) explains, in plain language, how the ADMT processes information to reach an output, what kind of output it produces, and what the alternative decision process looks like for a consumer who opts out.

Opt-out Right (§ 7221)

Consumers get the right to opt out of a business’s use of ADMT for a significant decision concerning them, through at least two submission methods (one of which must match how the business primarily interacts with the consumer), with no account-creation requirement and no verification requirement beyond what’s needed to locate the consumer’s data. A business must comply within 15 business days of a post-processing opt-out request and must notify downstream service providers and contractors.

Three exceptions let a business skip the opt-out mechanism, each with its own conditions:

  • Human-appeal exception — the business instead offers appeal to a designated human reviewer who genuinely knows how to interpret the ADMT’s output, reviews it and any other relevant information, and has actual authority to overturn the decision.
  • Admission/acceptance/hiring exception — available only where the ADMT is used solely to assess the consumer’s ability to perform at work or in an educational program, and the tool doesn’t unlawfully discriminate on protected characteristics.
  • Work allocation/compensation exception — same structure, for ADMT used solely to allocate or assign work or set compensation.

Both merit-based exceptions carry an implicit anti-discrimination condition — this is the one place the ADMT rules and FEHA-style disparate-impact analysis actually touch, but only as an eligibility test for an opt-out exception, not as a freestanding liability theory the way the Civil Rights Council’s rules operate.

Access Right (§ 7222)

On request, a business must explain, in plain language: the specific purpose the ADMT served for that consumer; how the ADMT’s logic processed their information to produce an output (the parameters and the specific output, where feasible); the outcome and whether the output was the sole factor or one of several in the final decision; and, if the business plans to reuse that output for a future significant decision, how. Trade secrets and information that would compromise security, fraud-prevention, or physical-safety efforts are excluded from what must be disclosed.

The Risk-Assessment Obligation

Article 10 (§ 7150 et seq.) requires a business to complete a risk assessment before starting any processing that presents “significant risk” to consumers’ privacy, and § 7150(b) lists using ADMT for a significant decision, and separately, training an ADMT intended for significant-decision use, as two of the enumerated triggers. In practice, most businesses whose ADMT use falls inside Article 11’s scope will also owe an Article 10 risk assessment for that same processing — the two articles were adopted together and are meant to be read as a pair, not as alternatives.

The Regime CPPA’s ADMT Rules Are Not

The most common compliance-team error with these rules is conflating them with the California Civil Rights Council’s automated-decision-system regulations under FEHA, which took a separate path through a different agency and became effective October 1, 2025. The two regimes differ on every axis that matters for building a compliance program:

  • Agency: CPPA (an independent privacy-enforcement agency) vs. the Civil Rights Council (part of the Civil Rights Department, which enforces employment anti-discrimination law).
  • Legal basis: the California Consumer Privacy Act (consumer privacy) vs. FEHA (anti-discrimination in employment).
  • What triggers coverage: using ADMT for any of five outcome-defined significant decisions (financial, housing, education, employment, healthcare) vs. using an “automated-decision system” specifically in an employment context.
  • What the regulated business owes: notice, opt-out, and access rights to consumers, plus a risk assessment vs. anti-discrimination compliance obligations tied to disparate-impact liability for employers and covered entities.
  • What a violation looks like: failing to provide a required notice, opt-out mechanism, or access response is itself the violation under the CPPA rules, with no discriminatory effect required vs. under FEHA’s rules, liability turns on discriminatory impact or treatment, not on the mere presence or absence of a privacy notice.

A business operating in California with ADMT touching employment decisions is very plausibly subject to both regimes simultaneously on the same tool, for entirely independent reasons and with entirely independent remedies. Satisfying one does not satisfy the other, and a compliance memo that cites “California’s ADMT rule” in the singular is very likely mixing the two together. See the NYC LL 144 vs. California FEHA ADS comparison for how the FEHA side works and how it compares to New York’s disclosure-and-audit model — neither of those is the CPPA regime this guide covers.

Who’s Covered

The ADMT rules apply to any business already subject to the CCPA — the underlying statutory thresholds are unchanged by this rulemaking. Under Civil Code § 1798.140(d), that means a for-profit entity doing business in California that either has annual gross revenue over $25 million, or buys/sells/shares the personal information of 100,000 or more California consumers or households annually, or derives 50% or more of its annual revenue from selling or sharing consumers’ personal information. There is no separate, lower revenue or scale threshold specific to ADMT use — if the business is covered by the CCPA at all and it uses ADMT for a significant decision, Article 11 applies.

Frequently Asked Questions

Is the CPPA’s ADMT regulation actually in force, or still proposed?

In force. The CPPA Board adopted the final text July 24, 2025, the Office of Administrative Law approved it September 22, 2025, and it took effect January 1, 2026. It is not a draft, a proposal, or a bill awaiting signature — it is an adopted regulation under the CCPA’s existing statutory authority.

Does § 7150 contain the ADMT consumer rights?

No. § 7150 opens Article 10 (Risk Assessments) and lists ADMT use as one of several triggers requiring a risk assessment. The consumer-facing ADMT rights — pre-use notice, opt-out, and access — are in Article 11, beginning at § 7200. The two articles were adopted in the same package and are meant to work together, but they are not the same rule.

Do the CPPA’s ADMT rules replace the FEHA automated-decision-system rules?

No. They are independent regimes from different agencies, resting on different statutes, and a business can owe obligations under both at once for the same tool. See the linked comparison for the FEHA/Civil Rights Council side.

Does a business have to offer an opt-out for every ADMT-driven significant decision?

Not if it qualifies for one of three exceptions in § 7221(b): a genuine human-appeal process with authority to overturn the decision, or, for admission/hiring or work-allocation/compensation decisions specifically, an ADMT used solely for that narrow purpose that does not unlawfully discriminate.

What has to happen before January 1, 2027 versus what already had to happen January 1, 2026?

A business that started using ADMT for a significant decision before January 1, 2026 has until January 1, 2027 to bring that specific use into compliance with Article 11 under the § 7200(b) phase-in. A business starting a new ADMT use for a significant decision after that date must already be compliant when it starts. The regulation itself has been legally effective since January 1, 2026 either way.

Sources

  • California Privacy Protection Agency, “CCPA Updates, Cyber, Risk, Automated Decisionmaking Technology (ADMT), and Insurance Regulations” — final rulemaking package, approved text, cppa.ca.gov/regulations/ and cppa.ca.gov/regulations/ccpa_updates.html.
  • California Code of Regulations, Title 11, Division 6, Chapter 1, Article 10 (§§ 7150 et seq., Risk Assessments) and Article 11 (§§ 7200–7222, Automated Decisionmaking Technology) — approved regulations text filed with the Secretary of State September 22, 2025.
  • California Civil Code § 1798.140(d) (CCPA business-coverage thresholds) and § 1798.185(a)(15) (ADMT rulemaking authority).

Related reading

Follow CASRAI

Research-administration guidance, standards updates and independent tool reviews.

Ask CASRAI · free to try

Ask about California’s CPPA ADMT Regulations: A Separate Regime From FEHA’s ADS Rules

Ask your first 2 questions free below. Subscribers get 150 a day for $29 a month.

An AI assistant specialized in research administration. It cites the sources behind every answer, labels web answers and says when it can't answer.

Answers draw on CASRAI's guides and dictionary plus the federal and funder documents we index: Federal Register, Grants.gov, Regulations.gov and UKRI.

Works on this site and inside Claude, Cursor and the AI tools you already use.

Everything CASRAI publishes — this page, the dictionary, the guides and the news — stays free to read, with no account and no card.

Referenced across the research world

University of Cambridge logoColumbia University logoCrossref logoUniversity of Edinburgh logoHarvard University logoUniversity of Oxford logoPrinceton University logoStanford School of Medicine logoUniversity College London logoORCID logoUniversity of Cambridge logoColumbia University logoCrossref logoUniversity of Edinburgh logoHarvard University logoUniversity of Oxford logoPrinceton University logoStanford School of Medicine logoUniversity College London logoORCID logo
  • University of Cambridge logo
  • Columbia University logo
  • Crossref logo
  • University of Edinburgh logo
  • Harvard University logo
  • University of Oxford logo
  • Princeton University logo
  • Stanford School of Medicine logo
  • University College London logo
  • ORCID logo

View CASRAI adoption →

Ask CASRAI · Regulatory Radar

Research-admin question? Get an answer that links its sources.

An AI assistant specialized in research administration. Every answer links its sources to check before you act. 2 questions free, no account. $29/month after.

  • Answers draw on CASRAI's guides and dictionary plus the federal and funder documents we index: Federal Register, Grants.gov, Regulations.gov and UKRI.
  • Every answer numbers its sources and links each one, so you can check the source yourself.