Skip to content
    August 22, 2026| Top Floor Team| 12 min read

    California's ADMT Rules: Does Your AI Make a Significant Decision?

    The trigger is not that you use AI. Under the California Privacy Protection Agency's approved CCPA regulation text, two things have to be true at once. First, the technology must process personal information and use computation to replace or substantially replace human decisionmaking (section 7001(e)). Second, the decision it drives must be a "significant decision", which section 7001(ddd) defines as a closed list: the provision or denial of financial or lending services, housing, education enrollment or opportunities, employment or independent contracting opportunities or compensation, or healthcare services. Businesses already using ADMT for such a decision must be in compliance no later than January 1, 2027 (section 7200(b)). The contrarian reading, and we think the correct one, is that most AI in most companies fails the second test outright, while a good deal of unglamorous scoring logic that nobody calls AI passes both.

    This piece works the definition in the regulation's own words, walks the five significant-decision categories, sets out what has to be live on the compliance date, covers the separate risk-assessment obligation that arrives with it, and says plainly what your existing AI governance work does and does not buy you here.

    Key takeaways

    • Two-part test: substantial replacement of human decisionmaking (section 7001(e)) plus a listed significant decision (section 7001(ddd)). Both, not either.
    • "Human involvement" has a definition. A reviewer who rubber-stamps output does not preserve it.
    • The compliance date for businesses already using ADMT for significant decisions is January 1, 2027, per section 7200(b).
    • Training a model for significant decisions, or for facial, emotion or biometric identification, is its own risk-assessment trigger under section 7150(b)(6), even before deployment.
    • Neither the NIST AI RMF nor ISO 42001 discharges any of this. They make the paperwork faster; they are not a defence.

    The definition is about human involvement, not about AI

    Section 7001(e) defines automated decisionmaking technology as any technology that processes personal information and uses computation to replace or substantially replace human decisionmaking. The word doing the work is "substantially", and the regulation refuses to leave it vague.

    To "substantially replace human decisionmaking" means the business uses the technology's output to make a decision without human involvement. Human involvement, in turn, requires the reviewer to know how to interpret and use the output, to review and analyse the output and any other relevant information, and to have the authority to make or change the decision based on that analysis.

    Read those three conditions as a design specification, because that is what they are. A recruiter who receives a ranked list and cannot deviate from it does not supply human involvement, whatever the org chart says. A loan officer who lacks the training to interpret a model score does not supply it either. The regulation is not asking whether a human is in the loop; it is asking whether that human could actually have reached a different answer.

    Section 7001(e)(2) adds that ADMT includes profiling that replaces or substantially replaces human decisionmaking. Section 7001(e)(3) carves out the infrastructure everyone worried about: web hosting, domain registration, networking, caching, website loading, data storage, firewalls, antivirus, antimalware, spam and robocall filtering, spellchecking, calculators, databases and spreadsheets, provided they do not replace human decisionmaking. Your CDN is not ADMT. Your spreadsheet might be, if you let it decide.

    Significant decision is a closed list, and it is short

    Section 7001(ddd) limits significant decisions to decisions that result in the provision or denial of financial or lending services, housing, education enrollment or opportunities, employment or independent contracting opportunities or compensation, or healthcare services.

    The subdefinitions matter. Financial or lending services means extension of credit or a loan, transmitting or exchanging funds, deposit or checking accounts, check cashing, or installment payment plans. Housing means a building or portion of one used or intended as a home, residence or sleeping place, and the regulation expressly says that using ADMT to provide or deny housing based solely on availability or vacancy, or on successful receipt of payment, is not making a significant decision.

    Run your own systems against that list honestly. A recommendation engine that ranks products is not on it. A churn model that flags accounts for a retention email is not on it. A support-ticket classifier is not on it. An automated resume screen that eliminates candidates is on it. A pricing model that sets an installment plan's terms is on it. An algorithm that routes patients to or away from a service is on it.

    The regulation supplies one illustration that lands squarely on this test. In section 7150(c)(1), a business that plans to videotape job interviews and then use emotion-recognition technology without human involvement to decide who to hire is given as an example of using ADMT for a significant decision. Read that example for its structure rather than its subject: the emotion recognition is not what makes it a significant decision, and the hiring outcome is not what makes it ADMT. Both halves have to be present.

    What has to be live on the compliance date

    Section 7200(b) is the operative sentence. A business using ADMT for a significant decision prior to January 1, 2027 must be in compliance with the Article no later than January 1, 2027. A business that starts using ADMT on or after that date must be in compliance any time it is using ADMT for a significant decision. There is no grace period on the second limb.

    Three obligations sit behind that date.

    Pre-use notice (section 7220). Before you collect the personal information you plan to process with ADMT, consumers get a notice that informs them about the use and about their rights to opt out of ADMT and to access information about it. It has to be presented prominently and conspicuously at or before the point of collection. It may live inside your Notice at Collection, provided that notice carries the required content.

    Opt-out (section 7221). A route for consumers to decline the automated path.

    Access (section 7222). A route for consumers to obtain information about how the technology was used with respect to them.

    The engineering consequence is that these are product surfaces, not policy documents. A published PDF describing your opt-out is not an opt-out. On the compliance date a consumer has to be able to exercise these rights and your systems have to honour them, which is the same lesson every organisation learns the hard way about deletion and correction requests.

    The risk assessment arrives with it, on a different clock

    Section 7150(b) lists the processing activities that present significant risk to consumers' privacy and therefore require a risk assessment before the processing begins. Four of the entries are directly relevant here.

    Using ADMT for a significant decision is one (7150(b)(3)). Using automated processing to infer or extrapolate characteristics such as intelligence, ability, aptitude, performance at work, economic situation, health, personal preferences, interests, reliability, predispositions, behaviour, location or movements, based on systematic observation of someone acting as an educational program applicant, job applicant, student, employee or independent contractor, is another (7150(b)(4)). The same inference activity based on presence in a sensitive location is a third (7150(b)(5)).

    The fourth is the one product teams miss. Section 7150(b)(6) covers processing personal information that the business intends to use to train an ADMT for a significant decision, or to train facial-recognition, emotion-recognition or other technology that verifies identity or conducts physical or biological identification or profiling. And "intends to use" is defined broadly: using, planning to use, permitting others to use, planning to permit others to use, advertising or marketing the use, or planning to advertise or market it. Training is a trigger in its own right, before anything ships.

    The regulation's own illustration for that limb is worth reading, because it involves no significant decision at all: in section 7150(c)(4), a technology provider that plans to extract faceprints from consumers' photographs to train its facial-recognition technology must conduct a risk assessment on that basis alone. Nobody is being hired, housed, lent to or treated. The processing is the trigger.

    The dates here run separately from the ADMT compliance date. Section 7155(b) requires a risk assessment for qualifying processing that began before the regulations took effect and continues afterwards to be conducted and documented no later than December 31, 2027. Section 7157(a)(1) requires the information for risk assessments conducted in 2026 and 2027 to be submitted to the Agency no later than April 1, 2028, with annual submissions by April 1 thereafter. Assessments must be reviewed and updated at least every three years, and updated within 45 calendar days of a material change (section 7155(a)).

    What your AI governance work does and does not buy you

    If you have adopted the NIST AI Risk Management Framework or are working toward ISO/IEC 42001 certification, the honest accounting is this.

    What carries across is real. Both frameworks push you to maintain an inventory of AI systems, to document intended use and limitations, to assess and record risk before deployment, and to define human oversight. Section 7152's risk-assessment content requirements and section 7220's notice requirements are much cheaper to satisfy when that inventory and documentation already exist, because the hard part of a first risk assessment is usually finding out what the company is actually running.

    What does not carry across is the legal obligation. Neither framework is referenced in the regulation, neither creates a safe harbour, and neither produces the pre-use notice, the opt-out mechanism, the access mechanism or the Agency submission. A certificate is not a compliance argument here in the way it can be in a customer conversation. Our comparison of what the EU AI Act asks of US companies makes the same point about a different regime: management-system work is infrastructure, not compliance.

    There is also a scope mismatch worth naming. ISO 42001 and the AI RMF are about AI systems. California's rule is about decisions, and it reaches decision logic that no AI governance program would ever have inventoried, because nobody involved thinks of a rules engine written in 2019 as AI.

    Where we would tell you this does not apply

    Against our own interest, since AI governance readiness is work we sell.

    If nothing you run touches financial or lending services, housing, education, employment or healthcare decisions, the ADMT article does not apply to you, and building an ADMT program is a misallocation. Say so in a memo, keep the memo, and move on. The risk-assessment article may still catch you on other grounds, particularly if you sell or share personal information or process sensitive personal information, and that is a different and usually smaller project.

    If your significant-decision systems have genuine human involvement as section 7001(e)(1) defines it, document the reviewer's training, the information available to them, and their authority to depart from the output, and you may be outside the ADMT definition entirely. That documentation is cheaper than the compliance program, and it is worth doing first.

    And if you are a small company with one recruiting tool and no other exposure, the answer is usually a configuration change and a notice, not an engagement. Ask your vendor whether the tool can be set to advisory rather than eliminating, and whether they will say so in writing.

    Where Top Floor fits

    The first piece of work is nearly always classification, and it is the piece we would rather sell you than a program: which systems process personal information, which of those substantially replace human decisionmaking, and which of those touch a listed decision. That runs under our CCPA practice and produces a defensible in-scope or out-of-scope conclusion for each system.

    Where systems are in scope, the AI governance side runs under NIST AI RMF and ISO 42001 work, because the inventory, documentation and oversight discipline those frameworks impose is what makes the risk assessments and notices sustainable rather than a one-time scramble. The continuing operation sits under Compliance as a Service.

    We do not give legal advice, and the applicability conclusion for a genuinely marginal system belongs with privacy counsel.

    How to decide this week

    Take your list of systems that touch personal information and score each one twice: does it substantially replace human decisionmaking, and does the decision land in one of the five categories. Most organisations find this takes an afternoon and eliminates ninety percent of the list.

    For anything that scores yes twice, put January 1, 2027 in the plan and work backwards from three product surfaces: pre-use notice at the point of collection, an opt-out path, and an access path. Those are engineering tickets, and engineering tickets need a quarter.

    Then look separately at what you are training. Section 7150(b)(6) can put you inside the risk-assessment article well before any model reaches production, and the December 31, 2027 backstop in section 7155(b) covers processing you are already running today.

    Frequently asked questions

    What counts as automated decisionmaking technology under the CCPA?

    Section 7001(e) defines ADMT as any technology that processes personal information and uses computation to replace or substantially replace human decisionmaking, including profiling that does so. To substantially replace human decisionmaking means using the output to make a decision without human involvement, and human involvement requires a reviewer who knows how to interpret the output, reviews and analyses it alongside other relevant information, and has authority to make or change the decision. Infrastructure such as web hosting, networking, storage, firewalls, antivirus, spam filtering, spellchecking, calculators, databases and spreadsheets is excluded provided it does not replace human decisionmaking.

    Which decisions are significant decisions?

    Section 7001(ddd) limits significant decisions to the provision or denial of financial or lending services, housing, education enrollment or opportunities, employment or independent contracting opportunities or compensation, or healthcare services. Financial or lending services is further defined as extension of credit or a loan, transmitting or exchanging funds, deposit or checking accounts, check cashing, or installment payment plans. Denying housing based solely on availability, vacancy or receipt of payment is expressly not a significant decision. Recommendation, ranking, marketing and support systems that touch none of those categories are outside the ADMT article.

    When do the California ADMT requirements take effect?

    Section 7200(b) requires a business that was using ADMT for a significant decision before January 1, 2027 to be in compliance with the Article no later than January 1, 2027. A business that begins using ADMT on or after that date must be in compliance at any time it is doing so, with no phase-in. The related risk-assessment obligations run on their own timetable: pre-existing qualifying processing must be assessed by December 31, 2027, and assessments conducted in 2026 and 2027 must be reported to the Agency by April 1, 2028.

    Does ISO 42001 or the NIST AI RMF satisfy the ADMT rules?

    No. Neither is named in the regulation, neither creates a safe harbour, and neither produces the pre-use notice, opt-out mechanism, access mechanism or Agency submission the Article requires. What they do produce is the AI inventory, documented intended use, risk records and human-oversight design that make the required risk assessments and notices far cheaper to complete. Treat them as the infrastructure that makes compliance affordable, not as evidence of compliance.

    Share Share on LinkedIn

    Need help with your compliance program?

    Our team of senior practitioners can help you navigate complex compliance requirements and build a security program that holds up under scrutiny.

    Schedule a Free Consultation

    Get insights like this in your inbox

    Practical compliance and security guidance for teams preparing for their next audit. No spam, unsubscribe anytime.

    Ask to be added to our mailing list for practical compliance and security guidance. We add you by hand, we confirm before sending anything, and we never share your address.