Skip to content
    Back to Regulatory Radar
    ImportantNew RegulationNovember 22, 2024

    CPPA Finalizes Automated Decision-Making, Risk Assessment, and Cyber Audit Rules

    The California Privacy Protection Agency published proposed regulations on automated decision-making technology (ADMT), risk assessments, and cybersecurity audits on November 22, 2024, opening the formal comment period. The board adopted the final package on July 24, 2025, and the Office of Administrative Law approved it on September 22, 2025. The regulations took effect January 1, 2026. Businesses using ADMT to make significant decisions about consumers must provide pre-use notices, honor opt-out rights, and provide access to information about how the technology is used, with compliance required by January 1, 2027.

    CCPASaaSFinTechHealthcare

    Key Analytics

    November 22, 2024
    Event Date
    Time Remaining
    August 24, 2026
    Last Verified
    1
    Frameworks Affected

    Impact Analysis

    These finalized regulations create some of the most prescriptive automated decision-making obligations in the United States, going beyond existing requirements in Colorado and other states. Organizations using AI or algorithms for significant decisions affecting employment, financial services, housing, education, or healthcare face transparency, opt-out, and risk assessment obligations on a phased timeline: ADMT requirements apply January 1, 2027; risk assessment attestations and summaries are due to the CPPA by April 1, 2028; and annual cybersecurity audits phase in by revenue tier starting April 1, 2028 for businesses over $100 million, 2029 for $50 million to $100 million, and 2030 for smaller covered businesses. The regulations confirm a convergence between privacy law and AI governance that organizations should anticipate across multiple jurisdictions.

    Recommended Actions

    • Inventory all uses of automated decision-making technology across business operations, identifying those that make significant decisions about consumers, and build pre-use notice and opt-out workflows before the January 1, 2027 ADMT compliance date.
    • Stand up a risk assessment program now; assessments for covered processing must be completed on an ongoing basis, with attestations and summaries due to the CPPA by April 1, 2028.
    • Determine your cybersecurity audit deadline by revenue tier (April 1, 2028, 2029, or 2030) and begin scoping the annual audit requirement, including auditor independence and board reporting obligations.

    Always verify requirements with official regulatory sources.

    Estimated Remediation Effort

    Indicative effort to address this development, broken down by your organization's current compliance posture. Select the posture that best matches where you are today.

    A partial program exists: some policies and controls are in place, but coverage, evidence, and ownership have gaps.

    Analyst estimate
    Significant80-165 hours
    Key Workstreams
    • ADMT inventory and pre-use notice preparation for January 2027
    • Risk assessment program stand-up ahead of the April 2028 attestation
    • Cybersecurity audit scoping against your revenue-tier deadline

    The Cost of Waiting

    Readiness work is dramatically cheaper before a deadline than after one. The ranges below come from the same estimate: the difference is only how prepared you are when the work starts.

    Start preparing nowSignificant · 80-165 hours
    Start cold under pressureSignificant · 180-380 hours

    Roughly 100 to 215 hours avoided by preparing early

    Effort ranges are indicative planning estimates, not quotes. Actual effort depends on organizational scope, environment complexity, and evidence maturity. Talk to us for a scoped assessment.

    Related Events