California Privacy Rights Act (CPRA) — AI Provisions: AI Compliance Requirements
The CPRA expanded CCPA to cover automated decisionmaking technology (ADMT). The CPPA's ADMT / risk-assessment / cybersecurity-audit regulations (11 CCR §§ 7120-7222) were approved 22-23 September 2025 and took effect 1 January 2026; businesses using ADMT for significant decisions must comply with the ADMT article (pre-use notice, opt-out, access) by 1 January 2027.
Summary of publicly-available regulatory text as of 2026-08-22. Verify against current official sources before relying on this for compliance decisions. Not legal advice.
Key Facts
January 1, 2023
$7,500 per intentional violation or violations involving consumers under 16; $2,500 per other violation (Cal. Civ. Code § 1798.155)
What Your Business Must Do
4 compliance requirements identified. Critical requirements carry the highest risk of enforcement action.
Automated Decision-Making Disclosure
CriticalProvide a prominent Pre-use Notice at or before collecting personal information that will be processed by ADMT to make a significant decision. The notice must explain the specific purpose in plain language (generic wording like "to make a significant decision" is expressly insufficient), describe the rights to opt out of and access ADMT, state that retaliation is prohibited, and explain how the ADMT works — including the categories of personal information affecting its output (11 CCR § 7220(b)-(c)).
Deadline: January 1, 2027
Cal. Civ. Code § 1798.185(a)(15); 11 CCR §§ 7200, 7220AI Opt-Out Mechanism
High PriorityProvide consumers the ability to opt out of ADMT used to make a significant decision concerning them, unless a § 7221(b) exception applies — most notably the human-appeal exception (§ 7221(b)(1)): a designated human reviewer who knows how to interpret the ADMT output, considers the consumer's submission, and has authority to overturn the decision.
Deadline: January 1, 2027
Cal. Civ. Code § 1798.185(a)(15); 11 CCR § 7221Privacy Policy — AI Section
High PriorityThe online privacy policy must describe consumers' CCPA rights including — for businesses using ADMT for significant decisions — the right to opt out of ADMT and the right to access ADMT, with an explanation of how to exercise them (11 CCR § 7011(e)). The amended privacy-policy content requirements took effect 1 January 2026.
Deadline: January 1, 2026
Cal. Civ. Code § 1798.130(a)(5); 11 CCR § 7011(e)(2)(F)-(G)Risk Assessment for High-Risk AI Processing
High PriorityConduct and document a risk assessment BEFORE initiating processing that presents significant risk — including using ADMT for a significant decision, selling/sharing personal information, processing sensitive personal information, inference-based profiling of workers/students or people in sensitive locations, and training ADMT or identity-verification/facial-recognition technology (11 CCR § 7150(b)). Weigh risks to consumers against benefits, identify safeguards, review at least every 3 years, and update within 45 days of a material change (§ 7155). Processing already under way when the regulations took effect must be assessed no later than 31 December 2027 (§ 7155(b)); first submission of assessment information to the CPPA is due 1 April 2028 (§ 7157(a)(1)), and reports must be produced to the CPPA or AG within 30 days on request.
Deadline: December 31, 2027
Cal. Civ. Code § 1798.185(a)(14); 11 CCR §§ 7150-7157Who Does This Apply To?
Applies to for-profit businesses doing business in California that meet at least one of: (1) annual gross revenues over $25M in the preceding calendar year (as adjusted per Cal. Civ. Code § 1798.199.95(d)); (2) annually buys, sells, or shares the personal information of 100,000+ consumers or households; or (3) derives 50%+ of annual revenues from selling or sharing consumers' personal information (§ 1798.140(d)). The ADMT article applies when ADMT is used to make a "significant decision" — provision or denial of financial or lending services, housing, education enrollment or opportunities, employment or independent-contracting opportunities or compensation, or healthcare services; advertising is expressly excluded (11 CCR § 7001(ddd)). California-resident nexus required — extraterritorial reach for businesses with CA customers.
Recent Enforcement Actions
Against: Sephora
California AG (Bonta) settlement with Sephora — the state's first public CCPA enforcement action. Sephora sold customer personal information (via third-party tracking/analytics tools) without the required "Do Not Sell" disclosure and did not honor Global Privacy Control opt-out signals; the AG had given a 30-day cure notice (2021-06-25) that went uncured. No AI-specific allegation in the press release — relevant to AI-driven-profiling businesses only by analogy (any behavioral-data pipeline, AI-powered or not, that shares data without disclosure risks the same "selling" characterization).
SourceAgainst: DoorDash
California AG (Bonta) settlement — the state's second public CCPA enforcement action. DoorDash sold California customers' personal information (names, addresses, order histories) to marketing cooperatives without CCPA/CalOPPA-required notice or opt-out. No AI-specific allegation in the press release — relevant to AI-data-vendor relationships only by analogy (sharing data with any downstream cooperative/vendor, AI-powered or not, without disclosure risks the same "sale" characterization).
SourceRecent Regulatory Guidance
CPPA ADMT Regulations Finalized (CCPA Updates Package)
California Privacy Protection Agency FINALIZED its regulations on Automated Decision-Making Technology (ADMT). The CCPA-updates package (ADMT + risk assessments + cybersecurity audits) was approved by the Office of Administrative Law on 22 September 2025 and filed with the Secretary of State on 23 September 2025; the regulations took effect 1 January 2026. The ADMT rules require: pre-use opt-out notice for ADMT used in significant decisions, the right to opt out, the right to human review, and detailed privacy-notice amendments. Businesses subject to the ADMT requirements must comply by 1 January 2027 — build the notice, opt-out, and human-review flows ahead of that date.
SourceCPPA Board Votes to Finalize ADMT, Risk Assessment & Cybersecurity Audit Regulations
The CPPA Board unanimously voted to finalize the full CCPA-updates rulemaking package (ADMT, risk assessments, and cybersecurity audits) on 2025-07-24 — the Board-level finalization step that preceded the Office of Administrative Law's formal approval (2025-09-22/23) and 2026-01-01 effective date. Risk assessments must document processing purpose, categories of personal/sensitive information, and benefits/risks weighed with safeguards (11 CCR §§ 7150-7157); cybersecurity-audit certifications are staggered by revenue: 2028 (>$100M), 2029 ($50-100M), 2030 (<$50M).
SourceKey Case Law & Precedent
California v. Sephora USA (CCPA/CPRA Enforcement)
California AG settlement (no litigated court judgment — pre-suit settlement) · 2022The state's first public CCPA enforcement action, establishing that sharing customer data with third-party ad-tech/analytics tools without disclosure or Global Privacy Control honor constitutes "selling" personal information. No AI-specific allegation in the underlying press release — relevant to AI-data-pipeline businesses by analogy only, not as AI-specific precedent.
Outcome: Settlement: $1.2M penalty (announced 2022-08-24) + injunctive relief (compliance program, GPC honor, contract review).
Case referenceQuarterly Enforcement Digest
Q2 2026: CPPA ADMT regulations are FINALIZED — the CCPA-updates package (ADMT + risk assessments + cybersecurity audits) was Board-finalized 24 July 2025 and approved by the Office of Administrative Law on 22 September 2025, taking effect 1 January 2026. The operative ADMT compliance deadline (pre-use notice, opt-out, and human review for significant automated decisions) is 1 January 2027. Risk-assessment and cybersecurity-audit obligations are in force from 1 January 2026 (risk-assessment documentation to the CPPA by 1 April 2028; cybersecurity-audit certifications phased 1 April 2028/2029/2030 by revenue). CYCLE 10 CORRECTION: the prior line "DoorDash enforcement ($375K) confirmed AI-driven ad targeting triggers CPRA sharing obligations" was fabricated framing — the AG's DoorDash press release (read this cycle) contains no AI allegation at all; it is a generic marketing-cooperative data-sale case, relevant to AI-data-vendor relationships only by analogy. Also fixed: DoorDash was a California AG action (not CPPA-brought), announced 2024-02-21 (not 03-15); Sephora was announced 2022-08-24 (not 2023-08-24, a full year off) — both corrected in enforcementActions/caseCitations above. Businesses should build the ADMT notice, opt-out, and human-review flows ahead of the 1 January 2027 deadline.
Digest covers enforcement actions, guidance, and regulatory developments. Last verified: 2026-08-22.
Industry Playbooks covering California Privacy Rights Act (CPRA) — AI Provisions
These industry playbooks include jurisdiction-specific checklist items and guidance for California Privacy Rights Act (CPRA) — AI Provisions.
Frequently Asked Questions
Does California Privacy Rights Act (CPRA) — AI Provisions apply to my business?
The CPRA expanded CCPA to cover automated decisionmaking technology (ADMT). The CPPA's ADMT / risk-assessment / cybersecurity-audit regulations (11 CCR §§ 7120-7222) were approved 22-23 September 2025 and took effect 1 January 2026; businesses using… Use Aegis Firma's free scanner to get a personalized assessment in under 5 minutes.
What is the penalty for non-compliance?
The maximum penalty under California Privacy Rights Act (CPRA) — AI Provisions is: $7,500 per intentional violation or violations involving consumers under 16; $2,500 per other violation (Cal. Civ. Code § 1798.155). Fines are typically scaled by company size, severity of violation, and whether violations were willful or accidental.
How do I comply with California Privacy Rights Act (CPRA) — AI Provisions?
The 4 requirements above cover the core obligations. The fastest path to compliance is: (1) conduct an AI risk assessment, (2) document your AI systems, (3) implement transparency disclosures where required. Aegis Firma generates all required documents automatically.
Official Source
https://leginfo.legislature.ca.gov/faces/codes_displaySection.xhtml?lawCode=CIV§ionNum=1798.185.Last updated: 2026-08-22 — verify at source before relying on this information.
Don't leave compliance to chance
Aegis Firma scans your AI tools, tells you exactly which regulations apply, and generates all required documents — in 30 minutes.
Start your free compliance scan