CCPA/CPRA's ADMT and Risk-Assessment Rules: What to Do Now
California's finalized rules on automated decision-making technology and risk assessments, what is in effect today, and what phases in during 2027.
8 min read
California has finalized new regulations covering automated decision-making technology (ADMT) and risk assessments, adopted by the California Privacy Protection Agency and approved in late 2025. They are among the first US rules to directly address how businesses use automation and AI on personal information, and they arrive on a staggered timeline, so what you have to do now differs from what lands later.
What Is in Effect Now
The risk-assessment requirement is in effect as of the start of 2026. Businesses must assess processing that presents a significant risk to consumers' privacy, including certain uses of automated decision-making and sensitive data, weighing the benefits against the risks and documenting the analysis. Under the rules, businesses have until the end of 2027 to complete and document assessments for processing that was already underway, so the obligation is live now even though the documentation deadline is later.
What Phases In During 2027
The ADMT consumer-rights bundle phases in during 2027. When a business uses automated decision-making technology to make a significant decision about a consumer, the rules add:
- A pre-use notice explaining the use of ADMT.
- A right to opt out of that automated decision-making.
- A right to access information about how the ADMT was used in a decision about them.
Trackers currently differ on the exact 2027 effective date for this bundle, so confirm the current date with the CPPA before you commit to one in a policy or notice.
What to Do About It
- Inventory where you use automated decisions on personal data, especially anything that affects access to a service, price, or an opportunity.
- Run and document risk assessments for higher-risk processing now; the obligation does not wait for the 2027 deadline.
- Prepare the notice-and-opt-out mechanics for the consumer-rights bundle so you are ready when it takes effect.
How Concord Fits
The foundation these rules assume is knowing what data you process and for what purpose. Concord Privacy's data mapping gives you that inventory, and privacy impact and risk assessments are available as a paid add-on on top, so the documentation is produced from your live data rather than assembled by hand. Treat the specific dates above as items to re-verify, since this area is still settling.