California ADMT compliance guide
California’s ADMT rules may affect businesses subject to the CCPA that use automated decisionmaking technology for significant decisions about consumers. Stacksona may help when an AI agent action needs pre-execution review, reviewer context, decision records, and exportable evidence, but it is not a complete CCPA compliance program or legal determination engine.
Direct answer
California’s ADMT rules may affect businesses subject to the CCPA that use automated decisionmaking technology for significant decisions about consumers. Stacksona may help when an AI agent action needs pre-execution review, reviewer context, decision records, and exportable evidence, but it is not a complete CCPA compliance program or legal determination engine.
Source: CPPA CCPA updates, cybersecurity audits, risk assessments, and ADMT regulations; California Privacy Protection Agency regulations page
Regulatory summary
California Consumer Privacy Act regulations for automated decisionmaking technology (ADMT), risk assessments, and cybersecurity audits applies in California with status: Final regulations approved; phased compliance for ADMT obligations. The practical compliance question is whether the organization, system, decision, and use case fit the covered scope.
Relevant sectors and businesses
These broad categories may need to review the guide when AI agents support covered or sensitive decisions.
Who may be affected
- Businesses subject to the CCPA/CPRA thresholds.
- Service providers, contractors, and vendors may be implicated through contracts and operational controls.
- Teams using AI or rules-based systems to substantially facilitate important consumer decisions should review coverage with counsel.
Covered technology
- Automated decisionmaking technology used to make or substantially facilitate significant decisions.
- Systems that evaluate consumers for access to, cost of, or terms of employment, housing, education, lending, insurance, healthcare, or similar opportunities.
- Agentic workflows that can update records, send notices, recommend outcomes, or trigger downstream decisions.
Covered decisions
- Employment, independent contracting, compensation, allocation, or termination decisions.
- Financial, lending, insurance, housing, education, criminal justice, or healthcare decisions.
- Other significant decisions where automated processing may materially affect a consumer.
Main requirements
- Provide required notices and consumer-facing disclosures where ADMT is used in covered ways.
- Perform and maintain risk assessments for covered processing activities.
- Support access, opt-out, and appeal-related workflows where required.
- Maintain records showing how automated decisions were reviewed, governed, and changed over time.
Human-review implications
Human review matters because an appeal or exception process is only meaningful if the reviewer can see the proposed action, context, policy reason, affected consumer, and final outcome before or around execution.
Record requirement: Keep risk assessments, notices, reviewer decisions, timestamps, policy versions, and evidence of how requests were handled.
Self-assessment questions
- Does the workflow involve a covered organization, consumer, patient, employee, applicant, or similarly protected person?
- Does software make, recommend, or materially influence a decision?
- Can the action be paused before execution for qualified human review?
- What evidence would prove what the reviewer saw and decided?
Practical workflow example
- An AI workflow proposes a denial-related notice or account action.
- A policy routes the request to a qualified reviewer before execution.
- The reviewer sees the consumer impact, source data, model/tool output, policy reason, and proposed payload.
- Stacksona records approval, rejection, notes, timestamps, and execution outcome for later review.
When Stacksona may be relevant
Stacksona is relevant when a regulated or sensitive AI-agent action needs an approval step, reviewer context, and a decision record before the action runs.
Requirement-to-capability table
| Compliance need | Stacksona capability |
|---|---|
| Identify a proposed action | Show what the agent wants to do before execution. |
| Pause and route for review | Send covered actions to the right reviewer or team. |
| Preserve reviewer evidence | Store approval, rejection, comments, timestamps, and outcome. |
| Export a decision record | Help teams share records with legal, risk, operations, or compliance. |
When Stacksona is not the complete solution
Stacksona does not replace legal advice, policy design, required notices, impact assessments, model validation, clinical judgment, anti-discrimination testing, vendor management, or full regulatory reporting.
Pending questions or rulemaking
- Monitor CPPA guidance, enforcement examples, and any clarifications on ADMT scope, profiling, consumer rights mechanics, and risk-assessment submission formats.
Official sources
Update history
- 2026-07-14: Initial Stacksona guide published using final-regulation status and public agency materials.
Informational disclaimer
This guide is for general informational purposes only. It is not legal advice and does not create an attorney-client relationship. Consult qualified counsel for advice about your obligations.
Use this guide to plan AI approval controls
When a compliance review points to human oversight, Stacksona can help teams test the approval path before an AI agent sends a message, changes a record, exports data, or triggers another sensitive action.