Are We Using Automated Decision making Technology (ADMT)? A 10-Question Test for California Employers

AI Governance Brief · 02 CCPA ADMT · CPPA Regulations Employment Decisions Updated 14 Sep 2026

Insights · Automated Decisionmaking

Don’t inventory AI. Inventory decisions.

California’s ADMT requirements bind on 1 January 2027. The organizations that miss it will not miss it because they lacked a policy — they will miss it because they started by asking which products contain AI.

The pattern repeats through every regulatory cycle I have worked: GDPR, CCPA, DFARS, CMMC. A requirement lands, and the organization starts with the vocabulary instead of the operations.

Legal reads the definition. Privacy opens a spreadsheet. Security inventories systems. HR emails its vendors asking whether their products contain AI, and the vendors reply with paragraphs written by their own counsel, carefully worded to commit to nothing.

Six months disappear. Nobody can answer the question that mattered on day one: where are we using automated technology to make decisions about people?

California employers need that answer by 1 January 2027.

The requirement

What the regulations require

The California Privacy Protection Agency’s amended CCPA regulations took effect on 1 January 2026, following approval by the Office of Administrative Law in September 2025. The obligations concerning automated decisionmaking technology carry their own compliance date of 1 January 2027.

ADMT is defined as technology that processes personal information and uses computation to replace or substantially replace human decisionmaking. The obligations attach where ADMT is used to make a significant decision about a consumer — and under the CCPA, “consumer” reaches employees, applicants and contractors. Employment decisions are in scope.

Where the requirements apply, an organization owes pre-use notice at the point of the decision, an opt-out subject to defined exceptions, access and explanation on request covering how the technology functioned in that person’s case, and in defined circumstances a route to human appeal.

Two timing details get missed. ADMT already in use for significant decisions must be brought into compliance by 1 January 2027. ADMT deployed after that date must comply before first use — there is no grace period on the back end.

Timing

The dates that actually bind

ADMT does not sit alone in the package. The same rulemaking introduced risk assessment obligations and phased cybersecurity audit certifications, and they interlock — using ADMT for a significant decision is itself a trigger for the risk assessment requirement.

DateObligation
1 Jan 2026Regulations effective. Risk assessment obligations begin for qualifying processing.
1 Jan 2027ADMT requirements apply. Pre-existing uses must be compliant; later deployments compliant before first use.
31 Dec 2027Risk assessments completed and documented for activities already underway.
1 Apr 2028First risk assessment submissions to the CPPA. First cybersecurity audit certifications for the largest revenue tier, with smaller tiers phasing through 2030.

Build these as three separate programs and you will end up with three contradictory descriptions of the same processing activity, depending on whose spreadsheet you open. An assessor will open all three.

1 January 2027 is a compliance date. It is not a project start date.

Scoping

Start with the decision, not the product

The instinct is to ask procurement for a list of AI tools. That list will be wrong in both directions — it will include systems that never touch a significant decision, and it will miss the systems quietly driving every one of them.

Take anything touching recruiting, employment or workforce management, and work through it:

Ten questions that scope an ADMT inventory

  1. Does it process personal information about an applicant, employee or worker?
  2. Does it produce a score, ranking, recommendation or classification about that person?
  3. Does that output influence whether the person receives an employment opportunity or benefit?
  4. Could it affect hiring, compensation, promotion, assignment, discipline or termination?
  5. Does a human make an independent judgment, or mostly ratify the output?
  6. Can the reviewer realistically disagree — do they have the information, the time and the standing?
  7. Would changing the automated output change the person’s outcome?
  8. Do you know what personal information feeds the system?
  9. Can you explain what the system did in one named individual’s case?
  10. Could you produce evidence supporting all of the above if a regulator asked on Monday?

Question ten is the governance question. It is also the one organizations leave until last, which is why it is usually the one they fail.

The same three conversations come up every time. A recruiting team says it does not use AI — then you learn the applicant tracking system ranks candidates by fit score and recruiters work the list top-down. A manager insists humans make every promotion call — then you learn managers receive a generated performance rating and depart from it in under two percent of cases. A workforce monitoring product is classified as a SaaS application by security, productivity software by HR, and a vendor by procurement. None of those classifications tells you what the technology does to the person on the other side of the decision.

Map the chain instead:

person → data → system → output → human → decision → consequence

If you can draw that chain for a use case, the legal analysis becomes tractable. If you cannot draw it, no governance platform will solve the problem. You will have purchased a more expensive place to store the confusion.

Evidence

“Human in the loop” is a measurement, not an assertion

Nearly every organization asserts human oversight as its primary control. It appears in the policy, in the vendor’s marketing, and in the answers people give on a call. It is almost never tested.

Human oversight is an empirical claim. It can be measured.

  • Override rate. Pull it from the system logs. How often does the reviewer depart from the automated output? A rate near zero indicates the technology is substantially replacing the decision, whatever the process document says.
  • Time to decision. If reviewers clear forty candidates in twenty minutes, they are not evaluating forty candidates.
  • What the reviewer sees. If the interface leads with a score and buries the underlying data three clicks away, the design has already made the decision.
  • Authority. Can the reviewer disagree without having to justify themselves upward?
  • Individual-level explainability. Not “the model weighs experience and skills.” What happened to this applicant, on this date. That is the granularity an access request demands.

Engineers know this instinctively: a control that has never been exercised has never been verified. Auditors know it too. It gets forgotten the moment the subject is AI, because the conversation turns philosophical rather than operational. It should not. The logs are right there.

Practical effect. If the override rate is effectively zero, human oversight will not carry the weight being asked of it, and the use case should be treated as in scope rather than argued over. Whatever the posture, the reviewer training, the interface design and the override data belong in the evidence file — because a description of a control and evidence that it operates are not the same artifact.

Sequence

The readiness sequence

Work backward from 1 January. Finding the systems is harder than writing the policy. Finding the owners is harder than finding the systems. Getting a straight answer from a vendor is harder than all of it.

  1. Find the use cases. Do not circulate a survey asking whether departments use ADMT; most people genuinely will not know. Go and look at recruiting, screening, performance management, workforce analytics, compensation, scheduling, monitoring and termination workflows.
  2. Map each decision. Input, processing, output, human involvement, final decision, consequence.
  3. Classify. Not every automation is a significant decision. Getting this line right is what keeps the program proportionate.
  4. Identify the data. What enters the process, where it came from, whether sensitive personal information is involved, what is inferred rather than collected.
  5. Document human involvement with evidence, not with the phrase “human in the loop.”
  6. Review vendor contracts for what the vendor can actually explain about system operation and what assistance it provides when an individual exercises a right. Start early; renegotiation takes months.
  7. Build the notice path. A notice in a policy library that never reaches the affected person is not a control.
  8. Operationalize opt-out, access and appeal — real intake, routing, service levels and records.
  9. Connect ADMT to the risk assessment. Same activity, one description.
  10. Test one end to end in the first quarter, not the fourth. Ask the organization to demonstrate the control rather than describe it.

Regulatory change risk

On federal preemption

A sentence is circulating in compliance conversations: maybe the federal government preempts this anyway.

Maybe. That is not a control.

The December 2025 executive order directed the Department of Justice to establish an AI Litigation Task Force to challenge state AI laws, and that task force was stood up in January 2026. In March 2026 the White House released a National Policy Framework for Artificial Intelligence — nonbinding recommendations to Congress, not a statute. As of this writing no federal AI act has been enacted, and no court has struck down California’s ADMT regulations.

Proposed preemption is not enacted preemption. Holding that distinction is the job.

Three questions separate the issue cleanly. What law applies today? What obligation carries a future compliance date? What specific legal event would change that obligation? A press release is not that event. An introduced bill is not that event. An executive policy preference is not necessarily that event. The event is enacted legislation, a controlling judicial ruling, or a valid regulatory action.

None of which means ignoring Washington. It means carrying preemption on the risk register as regulatory change risk — monitored, owned, reviewed — rather than letting it drift into an unwritten compliance assumption.

It also argues against building a California-specific bureaucracy. The durable capabilities are the same ones every credible regime asks for: an inventory of automated systems, named system and business owners, data flow documentation, decision mapping, vendor governance, risk assessment, testing, change management, rights workflows, and evidence that the controls operate. If Congress builds a national framework, you need those. If California’s rules stand, you need those. If Colorado or New York imposes something different, those become the baseline you map the difference against.

So does federal preemption move the 1 January 2027 deadline? Not on the current state of the law. Watch Washington, and have counsel assess actual developments as they occur. But I have never found a way to document hoping a requirement goes away as an operating control.

References

Primary sources for this brief

  • California Privacy Protection Agency — CCPA updates rulemaking package on ADMT, risk assessments and cybersecurity audits; approved by the Office of Administrative Law, September 2025
  • Approved regulations text — ADMT definition, significant decision scope, pre-use notice, opt-out, access and appeal requirements
  • Approved regulations text — risk assessment triggers, documentation deadlines and CPPA submission schedule
  • Executive Order, “Ensuring a National Policy Framework for Artificial Intelligence,” 11 December 2025; White House National Policy Framework for AI, 20 March 2026

FAQ

Common questions

Does this apply to us if we only use vendor tools and built nothing ourselves?

Yes. The obligations attach to the business using ADMT to make significant decisions, not to whoever built the technology. Using a third-party product makes the vendor conversation harder, not the obligation smaller.

Our applicant tracking system just ranks candidates. Is that ADMT?

It depends on whether the ranking substantially replaces the human decision in practice, which is a question about how recruiters actually work the list rather than about the product’s feature description. Measure the override behaviour before deciding.

We are not in California. Does this reach us?

It reaches businesses making significant decisions about California residents, including remote employees and applicants. Beyond the legal question, the underlying evidence — inventory, decision mapping, impact assessment, human oversight records — is the same evidence Colorado, the EU AI Act and ISO/IEC 42001 ask for.

Can we wait to see whether federal preemption resolves this?

The obligation exists now and the work is slow. An organization that starts in late 2026 will spend most of the runway finding systems and owners, which is the part that cannot be compressed.

Who owns this internally?

In practice it lands across legal, privacy, HR, security and the business owner of each system, which is why it stalls. Someone has to own the inventory and the evidence chain specifically, with authority to require both from the functions that generate them.

Do you know which of your systems are in scope?

Our free assessment scores your AI governance against the EU AI Act, ISO/IEC 42001 and the NIST AI RMF, and shows the gaps an assessor would find first. Twenty to thirty questions, about ten minutes, no signup.

Take the assessment  ·  Book a 30-minute call

This brief reflects published information as of 14 September 2026 and describes regulations effective 1 January 2026 with phased compliance dates through 2030. Agency guidance and interpretation may develop — verify the current regulation text and CPPA guidance before relying on them. Advisory content, not legal advice.

Nabiha Sofia Herradi
Nabiha Sofia Herradi
PRINCIPAL · AI GRC ADVISORY
Nabiha advises regulated organizations on AI governance, risk and compliance — EU AI Act readiness, ISO/IEC 42001, and NIST AI RMF programs built to produce evidence rather than documents. She holds a law degree along with CISM, CISA, CIPP/E, CIPP/US and CMMC-CCP, and 15+ years in GRC.

AI GRC Advisory · Insights · AI Governance Brief 02 · 14 Sep 2026