California · CCPA / CPRA · CPPA rules

California never passed an AI act. Its privacy law became one.

There is no California AI Act to look up, which is exactly why this gets missed. The California Privacy Protection Agency wrote the rules into the CCPA instead: if automated decision-making technology helps make a significant decision about a Californian, you owe a pre-use notice, an opt-out and an explanation — from January 1, 2027.

Plain-language summary, not legal advice. Source: the CPPA’s CCPA regulations on automated decision-making technology, risk assessments and cybersecurity audits, finalized July 2025 and approved September 2025.

Days to comply
One date, two states.Colorado’s replacement statute takes effect the same day. If you operate in both, the work is one program proved against two sets of citations — not two programs.
The date most people read wrong

Risk assessments are not a 2028 problem

April 1, 2028 is when risk-assessment documentation is filed with the CPPA. The duty to conduct those assessments for high-risk processing applies well before that — you are meant to be doing them now.

Read 2028 as the start date and you arrive at the filing with nothing to file, because an assessment is a record of a decision made at a point in time. It cannot be back-dated, and that is the entire risk in misreading this one line.

What it asks for

Four duties, in plain words

None of them is a document you write once. Each is a record you have to be able to produce about a specific decision, about a specific person, on a specific day.

Tell people before the technology weighs in

A pre-use notice when automated decision-making technology will be used for a significant decision — financial services, housing, education, employment or healthcare — in language a consumer can act on.

In GOVERNBOX: the AI Notices generator: a website embed, a Trust Center listing and a ready-to-send letter for every AI use that touches people.

Offer a real way out

A symmetric opt-out — as easy to refuse as to accept — and the operational plumbing to honor it rather than merely publish it.

In GOVERNBOX: CCPA-NOTC-002 and CCPA-PRIV-001 as tracked controls with an owner, evidence and a review cycle, so the opt-out is a process rather than a paragraph.

Answer an access request about the logic

Meaningful information about the logic, the key parameters and the effect the technology had — for this consumer, on request.

In GOVERNBOX: the Decision Log, with the notice text frozen as it stood on the day, so an answer months later describes what actually happened rather than today's wording.

Assess the risk, and be able to file it

Risk assessments for high-risk processing are due now; the documentation goes to the CPPA in 2028. The gap between those two dates is the work.

In GOVERNBOX: a seven-section impact assessment per use case that creates risk register entries on completion — so the 2028 filing is an export, not a reconstruction.
Does it apply to you?

Two questions decide it

The CCPA turns on doing business in California and meeting one of its thresholds — not on where you are incorporated. Confirm the threshold with counsel; it is the one part of this that genuinely does depend on your size.

Question one

Do you have Californians in your data?

Customers, applicants, employees or contractors. Employee and B2B data has been in scope since 2023 — a point that still surprises people.

Question two

Does AI touch a significant decision?

Financial or lending services, housing, education, employment or compensation, or healthcare services. If AI is materially involved in one of those, assume scope.

Both yes? January 1, 2027 is your date, and the risk assessments behind it are already live. Californians but no AI decisions? The CCPA still applies — this page is about the AI-specific layer on top of it. Neither? Check Colorado, Connecticut and Texas before concluding you are clear.

What the library actually contains

15 California controls, ten domains

California is the one state whose controls span two frameworks at two plans. The ten ADMT controls come with the U.S. States jurisdiction from Starter; the five wider CCPA privacy controls sit in the CCPA framework, which is Pro. We would rather say so here than have you discover it at checkout.

ADMT · included from Starter

CCPA-NOTC-001Pre-Use Notice at Point of Collection
CCPA-NOTC-002Symmetric Opt-Out Design and Execution
CCPA-RGHT-001Verified ADMT Logic and Outcome Delivery
CCPA-ADMT-001Significant Decision Classification Mapping
CCPA-ADMT-002Meaningful Human Review Validation
CCPA-RISK-001High-Risk Processing Assessment Logging
CCPA-RISK-002Annual CPPA Submission and Triennial Updates
CCPA-AUDT-001Evidence-Based Independent Security Audit
CCPA-AUDT-002Executive Certification and Five-Year Log Retention
CCPA-VEND-001ADMT Contractual Addenda Enforcement

Wider CCPA privacy · Pro

CCPA-PRIV-001Symmetric Opt-Out of Sale, Sharing, and Targeted Advertising
CCPA-PRIV-002Downstream Service Provider Contractual Blockades
CCPA-PRIV-003Right to Limit the Use of Sensitive Personal Information (SPI)
CCPA-PRIV-004Operational Purpose Proportionality Auditing
CCPA-PRIV-005Private Right of Action Security Verification
Where to start

The California crosswalk, line by line

Each duty sits next to the document and clause in your program that answers it, so “where do you address this?” has a one-click answer — and so does “show me the assessment you conducted before you switched it on.”

Take the free scorecard →
Your coverage, sample
Pre-use notice & opt-out65%
Access requests & logic disclosure40%
Risk assessments & audit evidence25%
Sample result. Placeholder for a real product screen.
Common questions

What people ask about the California rules

No — and that is why so many organizations have missed this. California regulates AI through its privacy law. The California Privacy Protection Agency finalized regulations under the CCPA (as amended by the CPRA) covering automated decision-making technology, risk assessments and cybersecurity audits. There is no bill called the California AI Act to look up, but if AI helps make a significant decision about a Californian, you have duties with dates attached.

Find out whether this applies to you

Fifteen questions, about ten minutes, free. No account and no sales call. You get a banded score and a named list of the gaps behind it.

This page is a plain-language summary of the California Consumer Privacy Act as amended by the California Privacy Rights Act, and of the California Privacy Protection Agency’s regulations on automated decision-making technology, risk assessments and cybersecurity audits. It is not legal advice, and GOVERNBOX.ai does not promise a regulatory outcome. Check your obligations with counsel. GOVERNBOX.ai is a product of Gradient Descent LLC, an independent commercial company that is not affiliated with, endorsed by, or sponsored by the State of California, the California Privacy Protection Agency, or any U.S. government agency.