Skip to content
هذه ترجمة للتسهيل فقط. النسخة الإنجليزية هي النسخة الرسمية والملزمة قانونيا. عرض النسخة الإنجليزية
US-CADEEP coverage2 enforcement actions

California Privacy Rights Act (CPRA) — AI Provisions: AI Compliance Requirements

The CPRA expanded CCPA to cover automated decisionmaking technology (ADMT). The CPPA's ADMT / risk-assessment / cybersecurity-audit regulations (11 CCR §§ 7120-7222) were approved 22-23 September 2025 and took effect 1 January 2026; businesses using ADMT for significant decisions must comply with the ADMT article (pre-use notice, opt-out, access) by 1 January 2027.

Summary of publicly-available regulatory text as of 2026-08-22. Verify against current official sources before relying on this for compliance decisions. Not legal advice.

Key Facts

Effective Date

January 1, 2023

Maximum Penalty

$7,500 per intentional violation or violations involving consumers under 16; $2,500 per other violation (Cal. Civ. Code § 1798.155)

What Your Business Must Do

4 compliance requirements identified. Critical requirements carry the highest risk of enforcement action.

Automated Decision-Making Disclosure

Critical

Provide a prominent Pre-use Notice at or before collecting personal information that will be processed by ADMT to make a significant decision. The notice must explain the specific purpose in plain language (generic wording like "to make a significant decision" is expressly insufficient), describe the rights to opt out of and access ADMT, state that retaliation is prohibited, and explain how the ADMT works — including the categories of personal information affecting its output (11 CCR § 7220(b)-(c)).

Deadline: January 1, 2027

Cal. Civ. Code § 1798.185(a)(15); 11 CCR §§ 7200, 7220

AI Opt-Out Mechanism

High Priority

Provide consumers the ability to opt out of ADMT used to make a significant decision concerning them, unless a § 7221(b) exception applies — most notably the human-appeal exception (§ 7221(b)(1)): a designated human reviewer who knows how to interpret the ADMT output, considers the consumer's submission, and has authority to overturn the decision.

Deadline: January 1, 2027

Cal. Civ. Code § 1798.185(a)(15); 11 CCR § 7221

Privacy Policy — AI Section

High Priority

The online privacy policy must describe consumers' CCPA rights including — for businesses using ADMT for significant decisions — the right to opt out of ADMT and the right to access ADMT, with an explanation of how to exercise them (11 CCR § 7011(e)). The amended privacy-policy content requirements took effect 1 January 2026.

Deadline: January 1, 2026

Cal. Civ. Code § 1798.130(a)(5); 11 CCR § 7011(e)(2)(F)-(G)

Risk Assessment for High-Risk AI Processing

High Priority

Conduct and document a risk assessment BEFORE initiating processing that presents significant risk — including using ADMT for a significant decision, selling/sharing personal information, processing sensitive personal information, inference-based profiling of workers/students or people in sensitive locations, and training ADMT or identity-verification/facial-recognition technology (11 CCR § 7150(b)). Weigh risks to consumers against benefits, identify safeguards, review at least every 3 years, and update within 45 days of a material change (§ 7155). Processing already under way when the regulations took effect must be assessed no later than 31 December 2027 (§ 7155(b)); first submission of assessment information to the CPPA is due 1 April 2028 (§ 7157(a)(1)), and reports must be produced to the CPPA or AG within 30 days on request.

Deadline: December 31, 2027

Cal. Civ. Code § 1798.185(a)(14); 11 CCR §§ 7150-7157

Who Does This Apply To?

Applies to for-profit businesses doing business in California that meet at least one of: (1) annual gross revenues over $25M in the preceding calendar year (as adjusted per Cal. Civ. Code § 1798.199.95(d)); (2) annually buys, sells, or shares the personal information of 100,000+ consumers or households; or (3) derives 50%+ of annual revenues from selling or sharing consumers' personal information (§ 1798.140(d)). The ADMT article applies when ADMT is used to make a "significant decision" — provision or denial of financial or lending services, housing, education enrollment or opportunities, employment or independent-contracting opportunities or compensation, or healthcare services; advertising is expressly excluded (11 CCR § 7001(ddd)). California-resident nexus required — extraterritorial reach for businesses with CA customers.

Recent Enforcement Actions

California AG2022-08-24$1,200,000Source verified· as of 2026-08-22

Against: Sephora

California AG (Bonta) settlement with Sephora — the state's first public CCPA enforcement action. Sephora sold customer personal information (via third-party tracking/analytics tools) without the required "Do Not Sell" disclosure and did not honor Global Privacy Control opt-out signals; the AG had given a 30-day cure notice (2021-06-25) that went uncured. No AI-specific allegation in the press release — relevant to AI-driven-profiling businesses only by analogy (any behavioral-data pipeline, AI-powered or not, that shares data without disclosure risks the same "selling" characterization).

Source
California AG2024-02-21$375,000Source verified· as of 2026-08-22

Against: DoorDash

California AG (Bonta) settlement — the state's second public CCPA enforcement action. DoorDash sold California customers' personal information (names, addresses, order histories) to marketing cooperatives without CCPA/CalOPPA-required notice or opt-out. No AI-specific allegation in the press release — relevant to AI-data-vendor relationships only by analogy (sharing data with any downstream cooperative/vendor, AI-powered or not, without disclosure risks the same "sale" characterization).

Source

Recent Regulatory Guidance

rulemaking2025-09-23

CPPA ADMT Regulations Finalized (CCPA Updates Package)

California Privacy Protection Agency FINALIZED its regulations on Automated Decision-Making Technology (ADMT). The CCPA-updates package (ADMT + risk assessments + cybersecurity audits) was approved by the Office of Administrative Law on 22 September 2025 and filed with the Secretary of State on 23 September 2025; the regulations took effect 1 January 2026. The ADMT rules require: pre-use opt-out notice for ADMT used in significant decisions, the right to opt out, the right to human review, and detailed privacy-notice amendments. Businesses subject to the ADMT requirements must comply by 1 January 2027 — build the notice, opt-out, and human-review flows ahead of that date.

Source
rulemaking2025-07-24

CPPA Board Votes to Finalize ADMT, Risk Assessment & Cybersecurity Audit Regulations

The CPPA Board unanimously voted to finalize the full CCPA-updates rulemaking package (ADMT, risk assessments, and cybersecurity audits) on 2025-07-24 — the Board-level finalization step that preceded the Office of Administrative Law's formal approval (2025-09-22/23) and 2026-01-01 effective date. Risk assessments must document processing purpose, categories of personal/sensitive information, and benefits/risks weighed with safeguards (11 CCR §§ 7150-7157); cybersecurity-audit certifications are staggered by revenue: 2028 (>$100M), 2029 ($50-100M), 2030 (<$50M).

Source

Key Case Law & Precedent

California v. Sephora USA (CCPA/CPRA Enforcement)

California AG settlement (no litigated court judgment — pre-suit settlement) · 2022

The state's first public CCPA enforcement action, establishing that sharing customer data with third-party ad-tech/analytics tools without disclosure or Global Privacy Control honor constitutes "selling" personal information. No AI-specific allegation in the underlying press release — relevant to AI-data-pipeline businesses by analogy only, not as AI-specific precedent.

Outcome: Settlement: $1.2M penalty (announced 2022-08-24) + injunctive relief (compliance program, GPC honor, contract review).

Case reference

Quarterly Enforcement Digest

Q2 2026: CPPA ADMT regulations are FINALIZED — the CCPA-updates package (ADMT + risk assessments + cybersecurity audits) was Board-finalized 24 July 2025 and approved by the Office of Administrative Law on 22 September 2025, taking effect 1 January 2026. The operative ADMT compliance deadline (pre-use notice, opt-out, and human review for significant automated decisions) is 1 January 2027. Risk-assessment and cybersecurity-audit obligations are in force from 1 January 2026 (risk-assessment documentation to the CPPA by 1 April 2028; cybersecurity-audit certifications phased 1 April 2028/2029/2030 by revenue). CYCLE 10 CORRECTION: the prior line "DoorDash enforcement ($375K) confirmed AI-driven ad targeting triggers CPRA sharing obligations" was fabricated framing — the AG's DoorDash press release (read this cycle) contains no AI allegation at all; it is a generic marketing-cooperative data-sale case, relevant to AI-data-vendor relationships only by analogy. Also fixed: DoorDash was a California AG action (not CPPA-brought), announced 2024-02-21 (not 03-15); Sephora was announced 2022-08-24 (not 2023-08-24, a full year off) — both corrected in enforcementActions/caseCitations above. Businesses should build the ADMT notice, opt-out, and human-review flows ahead of the 1 January 2027 deadline.

Digest covers enforcement actions, guidance, and regulatory developments. Last verified: 2026-08-22.

Industry Playbooks covering California Privacy Rights Act (CPRA) — AI Provisions

These industry playbooks include jurisdiction-specific checklist items and guidance for California Privacy Rights Act (CPRA) — AI Provisions.

Frequently Asked Questions

Does California Privacy Rights Act (CPRA) — AI Provisions apply to my business?

The CPRA expanded CCPA to cover automated decisionmaking technology (ADMT). The CPPA's ADMT / risk-assessment / cybersecurity-audit regulations (11 CCR §§ 7120-7222) were approved 22-23 September 2025 and took effect 1 January 2026; businesses using… Use Aegis Firma's free scanner to get a personalized assessment in under 5 minutes.

What is the penalty for non-compliance?

The maximum penalty under California Privacy Rights Act (CPRA) — AI Provisions is: $7,500 per intentional violation or violations involving consumers under 16; $2,500 per other violation (Cal. Civ. Code § 1798.155). Fines are typically scaled by company size, severity of violation, and whether violations were willful or accidental.

How do I comply with California Privacy Rights Act (CPRA) — AI Provisions?

The 4 requirements above cover the core obligations. The fastest path to compliance is: (1) conduct an AI risk assessment, (2) document your AI systems, (3) implement transparency disclosures where required. Aegis Firma generates all required documents automatically.

Official Source

https://leginfo.legislature.ca.gov/faces/codes_displaySection.xhtml?lawCode=CIV&sectionNum=1798.185.

Last updated: 2026-08-22 — verify at source before relying on this information.

Don't leave compliance to chance

Aegis Firma scans your AI tools, tells you exactly which regulations apply, and generates all required documents — in 30 minutes.

Start your free compliance scan