CPPA's ADMT Rules Effective January 2026: The Notice Requirement Explained

FEHA / EEO Defense

7 mins read

7 mins read

CPPA's ADMT Rules Effective January 2026: The Notice Requirement Explained

The California Privacy Protection Agency's (CPPA) ADMT regulations took effect January 1, 2026, but the specific notice requirement isn't operative until January 1, 2027. Risk assessments have a separate compliance timeline: covered businesses must conduct them before initiating covered processing, while certain processing activities already underway receive a later deadline under the final rules.

If your compliance calendar has this marked for this year, you're either ahead of schedule or tracking the wrong deadline. Here's what the pre-use notice requires, when it applies, and what's due now versus next year.

Key Takeaways

  • The CPPA's ADMT regulatory package took effect January 1, 2026, but the notice, opt-out, and ADMT-specific access rights aren't due until January 1, 2027.

  • A "significant decision" explicitly includes employment or independent contracting opportunities and compensation, making this directly relevant to HR and hiring tools.

  • The pre-use notice must describe the ADMT's specific purpose in non-generic terms, how it works, which data it affects, what it outputs, and the alternative process available upon opting out.

  • Businesses must also explain the right to a genuine human-review appeal process, with documented contributors and approval dates.

  • This framework is separate from FEHA's Automated-Decision System regulations (effective October 1, 2025). Both can apply to the same AI hiring tool.

  • Risk assessment and notice obligations have different deadlines and should be tracked as separate compliance projects.

Two Different Deadlines Hiding in the Same Regulatory Package

The California Privacy Protection Agency's Board approved this regulatory package covering cybersecurity audits, risk assessments, and Automated Decision-Making Technology (ADMT) on July 24, 2025, with the California Office of Administrative Law giving final approval on September 22, 2025. 

The package as a whole became effective January 1, 2026. But "effective" doesn't mean every obligation inside it is due on that date:

Requirement

Timeline

Final CPPA regulations effective

January 1, 2026

Risk assessment for covered new processing

Before the processing begins

Certain existing processing activities

Initial assessment deadline extends to December 31, 2027

ADMT pre-use notice/opt-out/access requirements

January 1, 2027 for covered uses already underway

New covered ADMT use beginning January 1, 2027 or later

Compliance required when the covered use begins

If you're using ADMT for a significant decision before January 1, 2027, you need to be compliant by that date. If you start using ADMT for a significant decision on or after January 1, 2027, compliance is required immediately. There's no grace period for new deployments.

What Counts as "ADMT" and a "Significant Decision"?

ADMT covers any technology that processes personal information and uses computation to make or substantially replace human decision-making about a consumer or employee. The regulations define a "significant decision" precisely: a decision resulting in the provision or denial of financial or lending services, housing, education enrollment, employment or independent contracting opportunities or compensation, or healthcare services.

The CPPA's ADMT rules are privacy regulations, not a standalone employment-AI statute. But employment decisions are expressly included within the definition of 'significant decision.'

For employment purposes, the final definition covers hiring; allocation or assignment of work for employees; salary, hourly or per-assignment compensation, incentive compensation such as bonuses, or other benefits; promotion; and demotion, suspension, and termination.

Does the CCPA Actually Apply to Employers?

The CCPA is not automatically applicable to every California employer. The relevant question is whether the employer is a "business" covered by the CCPA and whether the individuals whose information is processed fall within the law's definition of consumer.

California's employment-related privacy exemption expired in 2023, so covered businesses can have CCPA obligations involving employee and applicant personal information. But an employer must still satisfy the CCPA's business-coverage requirements before the ADMT rules apply.

For 2026, the CCPA's revenue threshold is $26,625,000, with separate coverage triggers based on the volume of California consumers' personal information bought, sold, or shared and the percentage of revenue derived from selling or sharing personal information.

What the Pre-Use Notice Has to Say

The notice must be delivered before collecting personal information for ADMT use, or before repurposing already-collected data for it, and it has to include specific elements:

  1. The specific purpose for using the ADMT, described in non-generic terms. The CPPA specifically revised this requirement during rulemaking to prevent businesses from using vague language like "to improve hiring." The notice has to describe the actual purpose concretely.

  2. A description of how the ADMT works: what it does, in plain terms.

  3. What types of personal information affect the ADMT's outputs.

  4. What outputs the ADMT generates, and how those outputs factor into the actual decision.

  5. The alternative decision-making process available if the individual opts out: you have to describe what happens instead, not just that an opt-out exists.

The notice must appear where the relevant workflow begins, at or before data collection for that purpose, rather than be buried in a general privacy policy the applicant may never see.

What Rights Apply After an ADMT-Assisted Decision?

The notice requirement isn't the only ADMT obligation tied to significant decisions. California residents also have the right to request an explanation of how the ADMT arrived at a significant decision about them, including the inputs used and the reasoning applied. 

Businesses must also provide an appeal process that includes genuine human review, with defined response timelines. That review has to be real: a manager clicking "approve" on a system's output without independently evaluating the underlying facts doesn't satisfy the standard. The regulations also require documenting who contributed to and approved the ADMT-assisted decision, with dates, which becomes part of your compliance record if a request or claim ever surfaces.

This Is a Different Framework Than FEHA's AI Rules

If you've been tracking California's other AI-related employment regulations, it's worth being precise about which framework you're actually dealing with, since employers frequently conflate the two:

Aspects

CPPA ADMT

FEHA ADS

Primary purpose

Privacy and automated-decision rights

Employment discrimination

Regulator

CPPA

CRD / Civil Rights Council

Legal framework

CPPA

FEHA

Effective date

Jan. 1, 2026; ADMT compliance Jan. 1, 2027

Oct. 1, 2025

Employment relevance

Significant employment decisions by covered businesses

Employment decisions using automated systems

Core risk

Notice, access, opt-out, risk assessment

Disparate treatment/disparate impact, recordkeeping, prohibited discrimination

Both frameworks can apply to the same AI hiring tool simultaneously, but they impose different obligations for different reasons. Our guide on California's AI hiring regulations and FEHA compliance for automated decision systems covers the FEHA side of this in depth. Read it alongside this piece if your business uses AI in hiring, since you likely need to satisfy both frameworks, not just one.

What Employers and HR Teams Are Worried About

A useful discussion in r/humanresources featured a hiring manager explaining that their organization used a structured screening process and reviewed and ranked applications by humans rather than filtering them with an automated system.

The thread shows the practical distinction between a genuine human evaluation process and assumptions about automated screening.

There is also a recent discussion about who bears responsibility when an employer uses AI to screen applicants, and the system allegedly discriminates.

The employer-side takeaway is straightforward: outsourcing the technology does not necessarily outsource the employer's employment-law risk.

How to Build Your Notice Now

  1. Confirm whether your business is covered at all. The CCPA generally applies to for-profit businesses that do business in California and meet at least one statutory threshold, including annual gross revenue exceeding $26,625,000, adjusted for inflation.

  2. Inventory every tool that could touch a "significant decision": hiring, termination, promotion, compensation, disciplinary action, not just tools explicitly marketed as "AI."

  3. Draft your pre-use notice with the five required elements, written in specific, non-generic language rather than a boilerplate privacy statement.

  4. Design your opt-out alternative process now. You need a genuine, documented alternative decision-making path for anyone who opts out. This can't be an afterthought built in the week before the deadline.

  5. Build your human-review and appeal process with real documentation standards: who reviewed, what they considered, and what they decided.

  6. Separate your risk assessment work from your notice work. They run on different deadlines, and treating them as one project risks missing the earlier risk-assessment obligation while over-preparing for the later notice requirement.

If your business uses AI-assisted hiring or evaluation tools and you're not sure whether this framework covers you, FEHA's rules, or both, that's exactly the kind of overlapping compliance question worth resolving now. 

Our FEHA/EEO Defense team reviews AI hiring and evaluation tools against both regulatory frameworks, since most employers using these tools need to satisfy each for different reasons.

Conclusion

The CPPA's ADMT regulatory package took effect on January 1, 2026, but the pre-use notice, opt-out, and access rights specific to Automated Decision-Making Technology aren't due until January 1, 2027. Risk assessments have a separate compliance timeline.

Don't let the "2026" date on this regulatory package create a false sense of urgency around the wrong obligation, and don't let the "2027" date on the notice requirement create a false sense of extra time. The risk assessment work is due now, and the notice infrastructure needs to be built well before the 2027 deadline, not in the weeks leading up to it.

If your business needs its AI-assisted employment tools reviewed against both the CPPA's ADMT rules and FEHA's separate ADS regulations, DefendMyBiz offers a paid 1-hour consultation. Book a call with our employer defense team today.

Frequently Asked Questions

What are the rules for ADMT under California law?

Is the ADMT notice requirement due in 2026 or 2027?

What must a CPPA pre-use notice include?

Is this the same as California's FEHA AI hiring rules?

What counts as a "significant decision" under the ADMT rules?

Disclaimer: The above content is for informational purposes only. This is not legal or tax advice. Laws, IRS guidance, and withholding requirements can change, and outcomes depend on specific facts. You are advised to contact a qualified attorney for any legal advice.