There is no California AI Act to look up, which is exactly why this gets missed. The California Privacy Protection Agency wrote the rules into the CCPA instead: if automated decision-making technology helps make a significant decision about a Californian, you owe a pre-use notice, an opt-out and an explanation — from January 1, 2027.
Plain-language summary, not legal advice. Source: the CPPA’s CCPA regulations on automated decision-making technology, risk assessments and cybersecurity audits, finalized July 2025 and approved September 2025.
April 1, 2028 is when risk-assessment documentation is filed with the CPPA. The duty to conduct those assessments for high-risk processing applies well before that — you are meant to be doing them now.
Read 2028 as the start date and you arrive at the filing with nothing to file, because an assessment is a record of a decision made at a point in time. It cannot be back-dated, and that is the entire risk in misreading this one line.
None of them is a document you write once. Each is a record you have to be able to produce about a specific decision, about a specific person, on a specific day.
A pre-use notice when automated decision-making technology will be used for a significant decision — financial services, housing, education, employment or healthcare — in language a consumer can act on.
A symmetric opt-out — as easy to refuse as to accept — and the operational plumbing to honor it rather than merely publish it.
Meaningful information about the logic, the key parameters and the effect the technology had — for this consumer, on request.
Risk assessments for high-risk processing are due now; the documentation goes to the CPPA in 2028. The gap between those two dates is the work.
The CCPA turns on doing business in California and meeting one of its thresholds — not on where you are incorporated. Confirm the threshold with counsel; it is the one part of this that genuinely does depend on your size.
Customers, applicants, employees or contractors. Employee and B2B data has been in scope since 2023 — a point that still surprises people.
Financial or lending services, housing, education, employment or compensation, or healthcare services. If AI is materially involved in one of those, assume scope.
Both yes? January 1, 2027 is your date, and the risk assessments behind it are already live. Californians but no AI decisions? The CCPA still applies — this page is about the AI-specific layer on top of it. Neither? Check Colorado, Connecticut and Texas before concluding you are clear.
California is the one state whose controls span two frameworks at two plans. The ten ADMT controls come with the U.S. States jurisdiction from Starter; the five wider CCPA privacy controls sit in the CCPA framework, which is Pro. We would rather say so here than have you discover it at checkout.
ADMT · included from Starter
Wider CCPA privacy · Pro
Each duty sits next to the document and clause in your program that answers it, so “where do you address this?” has a one-click answer — and so does “show me the assessment you conducted before you switched it on.”
Take the free scorecard →Fifteen questions, about ten minutes, free. No account and no sales call. You get a banded score and a named list of the gaps behind it.
This page is a plain-language summary of the California Consumer Privacy Act as amended by the California Privacy Rights Act, and of the California Privacy Protection Agency’s regulations on automated decision-making technology, risk assessments and cybersecurity audits. It is not legal advice, and GOVERNBOX.ai does not promise a regulatory outcome. Check your obligations with counsel. GOVERNBOX.ai is a product of Gradient Descent LLC, an independent commercial company that is not affiliated with, endorsed by, or sponsored by the State of California, the California Privacy Protection Agency, or any U.S. government agency.