CPPA Finalizes Automated Decision-Making, Risk Assessment, and Cyber Audit Rules
The California Privacy Protection Agency published proposed regulations on automated decision-making technology (ADMT), risk assessments, and cybersecurity audits on November 22, 2024, opening the formal comment period. The board adopted the final package on July 24, 2025, and the Office of Administrative Law approved it on September 22, 2025. The regulations took effect January 1, 2026. Businesses using ADMT to make significant decisions about consumers must provide pre-use notices, honor opt-out rights, and provide access to information about how the technology is used, with compliance required by January 1, 2027.
Key Analytics
Impact Analysis
These finalized regulations create some of the most prescriptive automated decision-making obligations in the United States, going beyond existing requirements in Colorado and other states. Organizations using AI or algorithms for significant decisions affecting employment, financial services, housing, education, or healthcare face transparency, opt-out, and risk assessment obligations on a phased timeline: ADMT requirements apply January 1, 2027; risk assessment attestations and summaries are due to the CPPA by April 1, 2028; and annual cybersecurity audits phase in by revenue tier starting April 1, 2028 for businesses over $100 million, 2029 for $50 million to $100 million, and 2030 for smaller covered businesses. The regulations confirm a convergence between privacy law and AI governance that organizations should anticipate across multiple jurisdictions.
Recommended Actions
- Inventory all uses of automated decision-making technology across business operations, identifying those that make significant decisions about consumers, and build pre-use notice and opt-out workflows before the January 1, 2027 ADMT compliance date.
- Stand up a risk assessment program now; assessments for covered processing must be completed on an ongoing basis, with attestations and summaries due to the CPPA by April 1, 2028.
- Determine your cybersecurity audit deadline by revenue tier (April 1, 2028, 2029, or 2030) and begin scoping the annual audit requirement, including auditor independence and board reporting obligations.
Always verify requirements with official regulatory sources.
Estimated Remediation Effort
Indicative effort to address this development, broken down by your organization's current compliance posture. Select the posture that best matches where you are today.
A partial program exists: some policies and controls are in place, but coverage, evidence, and ownership have gaps.
- ›ADMT inventory and pre-use notice preparation for January 2027
- ›Risk assessment program stand-up ahead of the April 2028 attestation
- ›Cybersecurity audit scoping against your revenue-tier deadline
The Cost of Waiting
Readiness work is dramatically cheaper before a deadline than after one. The ranges below come from the same estimate: the difference is only how prepared you are when the work starts.
Roughly 100 to 215 hours avoided by preparing early
Effort ranges are indicative planning estimates, not quotes. Actual effort depends on organizational scope, environment complexity, and evidence maturity. Talk to us for a scoped assessment.