close
close
This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

Regulations

ADMT: What You Need to Know Before January 1, 2027

Michael Ariyo - October 1, 2026

California’s Automated Decision-Making Technology (ADMT) rules have been in effect since January 2026, with more requirements coming on January 1, 2027. And yet, many privacy and business leaders I talk with still aren’t exactly sure what counts as ADMT or whether it applies to them. 

Most of the confusion comes down to an assumption that California’s ADMT regulation is an AI law. It isn’t. The final rules never use the words “artificial intelligence,” and that single fact trips up more teams than any deadline. It means some of your oldest, most ordinary tools may be in scope, while some of your newest AI tools may not.

Let’s take a look at what ADMT is, when it applies, what it covers, and what you need to do before it comes into full effect on January 1, 2027.

 

What is ADMT?

Under CCPA (California Consumer Privacy Act) articles 10 and 11, ADMT is “any technology that processes personal information and uses computation to replace, or substantially replace, human decision-making.” 

That can include AI and machine learning, but it doesn’t require them. The definition hinges on what role the technology plays in the decision process, not how advanced it is.

The rules don’t cover every automated decision, only a “significant decision,” which is defined as one that grants or denies something that shapes a person’s life. 

The CCPA names five specific significant decision types:

  1. Employment or independent contracting
  2. Lending and other financial services
  3. Housing
  4. Healthcare services
  5. Education enrollment or opportunity

The trigger is the outcome, not the industry. 

You don’t have to be a bank to fall under the lending category, or a hospital to fall under healthcare. What matters is whether a decision lands in one of these five areas and whether a non-human is effectively making it. 

The systems most likely to qualify usually aren’t your customer-facing features. They’re the back-office tools that quietly decide who gets hired, funded, housed, treated, or admitted, which is exactly why they get missed.

 

Five misunderstood ADMT rules that increase your risk

Using five everyday scenarios, we’ll surface the most common ADMT rules people get wrong  and show where the lines are drawn. 

1) ADMT is scoped by what the tool decides, not by how advanced it is.

Let’s look at a company that screens job applicants with a scoring spreadsheet someone built years ago. Using logic-based formulas, it looks at experience, ZIP code, and a “culture fit” rating, then auto-rejects anyone below a cutoff. 

The hiring manager assumes the rules don’t apply, because “ADMT is an AI law, and we don’t use AI.”

Wrong. That spreadsheet processes personal information and substantially replaces a human’s decision on who advances. Hiring is a significant decision. It’s ADMT.

2) AI without a significant decision is not ADMT.

The same company rolls out an AI chatbot that answers customer questions about order status and store hours. It’s built on a large language model. 

Leadership assumes it now needs an opt-out or appeal workflow.

It doesn’t. The chatbot isn’t making a significant decision about anyone. It’s answering questions. Being AI doesn’t put a tool in scope any more than being a spreadsheet keeps it out.

3) A human in the loop only counts if that human can actually understand, weigh, and overturn the decision.

A lender runs applications through a model that outputs an approve or deny recommendation. 

A loan officer clicks “confirm” on nearly all of them in seconds, never overriding the model.

That review doesn’t get the lender out of scope. The regulations set a real bar for meaningful human involvement, and a “rubber stamp” action doesn’t clear it. When the model is effectively making the call, the technology has substantially replaced the human, which is exactly what ADMT describes.

4) ADMT includes decisions that shape someone’s job, not just whether or not they have one.

A retailer uses software to set employee shifts, rank workers for promotion, and flag who gets fewer hours next month. 

Nobody is being hired or fired, so the team assumes employment rules don’t apply.

The employment definition is broader than hiring and firing. It includes compensation, scheduling, promotion and demotion, and how work gets allocated. Software that drives those outcomes can be ADMT.

5) The fact that a decision has “multiple inputs” doesn’t automatically rule out ADMT.

A health system uses an algorithm to help decide who gets prioritized for a care program. 

Staff describe it as “one input among several,” so they figure it falls short of the threshold.

The test is whether the technology substantially replaces human judgment. If the algorithm’s output is the factor that effectively determines the outcome, calling it “one input” doesn’t change what’s really happening. If a person actually weighs it against other information and can land somewhere else, that’s a different story.

 

Legal obligations of a business that makes use of ADMT 

ADMT compliance answers to two audiences. First, the people your systems make decisions about, who gain rights you have to honor. Second, the CPPA, which expects you to document what you’re doing before you do it and prove it afterward. Start with the person, because that’s where the rules are easiest to feel.

What a person is owed

In simplest terms, you’re required to:

Tell people you use ADMT  → Allow them to opt out or appeal to a human  →  Explain how the decision was made.

If we follow one person through an ADMT process, the requirements stop feeling like a checklist. Take a job applicant called Maya who was auto-rejected by that scoring spreadsheet I mentioned. She is owed four things:

  1. Notice.

    She must be told upfront that an automated system will weigh her application.
  2. Opt-out.

    She can be given the option to request that a person, not a system, make the call.
  3. Access.

    She can ask what the system looked at and how it reached its answer.
  4. Appeal.

    If she is not able to opt out, then she must be able to submit an appeal to be reviewed by a person with real authority to reverse the decision.

Note that opt-out and appeal cover the same protection at different moments. 

The company has to give Maya a way to put a person in charge of the decision, and it can do that by either: 

Letting her opt out so a human decides instead of the tool

OR 

Letting her appeal the tool’s decision to a human who can reverse it 

Offering a real appeal is enough on its own, so a business doesn’t have to provide both. Notice and access are always owed no matter what.

The example above is hiring, but the shape holds across every covered area: a family denied a lease by a tenant-screening model (housing), a borrower turned down for a loan in seconds (lending), a patient sorted out of a care program (healthcare), a student application filtered out of admissions (education).

Different system, same rights, same responsibility.

What the CPPA (CalPrivacy) expects

The person’s four rights are only half the picture. The CPPA expects three things from the business itself, whether or not anyone ever files a request.

  1. Risk assessments.

    Before deploying a covered system, document its purpose, its risks, and its safeguards.
  2. Cybersecurity audits.

    Independent annual audits, required only if your processing crosses one of these thresholds:

    1. 50%+ of annual revenue from selling or sharing personal information, at any size. 
    2. Your annual revenue exceeds the CCPA threshold (currently about $26.6 million), and in the previous year you processed either:
      1. the personal information of 250,000 or more consumers, or
      2. the sensitive personal information of 50,000 or more consumers.
  3. Regulator reporting.

    Submit summaries to the state, and produce full records if they’re ever requested.

Together, that’s the full picture. Four rights on the person’s side, and three expectations on yours, none of them mysterious once viewed this way. 

What separates defensibility from exposure is the work you do upfront. 

If an ADMT system is already in your inventory with a risk assessment attached, you can explain any decision it made, in plain language, and stand behind it on appeal. If it’s not, you’re reconstructing what happened after the clock has already started.

 

The ADMT compliance timeline

January 1, 2026 (Already in effect): The general CCPA regulations are live. If you use ADMT for a significant decision, or otherwise run high-risk processing, you are obligated to conduct and document risk assessments.

January 1, 2027: ADMT consumer rights take effect. Businesses using ADMT for a significant decision must give notice, answer access requests, and let people move the decision to a human, whether by opting out or by appealing. This is the deadline this article is built around.

December 31, 2027: The cutoff for completing risk assessments on systems already in use. Every covered ADMT running in your environment needs a documented assessment behind it by this date.

April 1, 2028: Two filings converge. Your first risk assessment summary and executive attestation are due to the CPPA (covering 2026 and 2027), and businesses over $100 million in revenue owe their first certified cybersecurity audit.

2029 to 2030: The remaining audit deadlines land by revenue tier, April 1, 2029 for businesses between $50 and $100 million, and April 1, 2030 for those under $50 million. Reporting continues on an annual rhythm.

The realistic goal for most teams by January 2027 isn’t perfection. It’s a documented, good-faith plan and a clear inventory. That’s a target you can actually hit.

 

CA’s ADMT laid the foundation, other states are building on it. 

California is first, but not alone. Colorado’s revised law lands on the same day, January 1, 2027, and is built around the same idea of automated decisions in consequential areas. 

The EU’s high-risk AI rules reach the same terrain, hiring, credit, and education, in December 2027, with product-embedded systems following in 2028. 

The specifics differ, but there’s a pattern that rewards the same groundwork:

  1. Know where automated decisions happen.
  2. Tell people.
  3. Give them a real path to a human.
  4. Document your reasoning once.

The inventory you build and the assessments you write don’t expire at the California border. Solving California gets you most of the way to solving the rest, which turns a scramble into a one-time piece of clarity rather than a forever tax.

 

How DataGrail can help

DataGrail brings the pieces you need for ADMT compliance into one AI-powered platform, with people kept firmly in control of the judgment calls the law reserves for them. Each capability below maps to an obligation you just read about.

  • Live Data Map inventories where automated decision-making happens and tags each activity by the type of significant decision, so scoping isn’t a guessing game.
  • Consent Management delivers the required ADMT notice to consumers.
  • Request Manager handles ADMT opt-out, access, and appeal requests.
  • Privacy Assessments provides an ADMT risk assessment template, and also recommends an assessment whenever an activity is tagged as ADMT for a significant decision.

If you’d like to see what that groundwork looks like in practice, request a demo. 

And if you want to keep up as ADMT rules spread state by state, join the Privacy Roundtable, our Slack community for privacy professionals.

Contact Us image

Let’s get started

Ready to level up your privacy program?

We're here to help.