Appearance
Operationalizing the CCPA ADMT Regulations in Modulos
Modulos ships the CCPA ADMT Regulations as a paired framework (templates 1.0.32): MFF-29 produces the per-technology evidence for one ADMT, and OFF-29 establishes the organization's repeatable capabilities once. Both carry the Regulation label and the california-admt.svg icon. Requirements quote the regulation's operative text verbatim, so teams can audit against the source.
Project structure
| Template | Project type | Scope | Requirements | Distinct Controls |
|---|---|---|---|---|
MFF-29 — CCPA ADMT Regulations | AI application | One ADMT, in whichever CCPA roles the organization holds for it | 8 (MRF-489–MRF-496) | 14 (8 new, 6 shared) |
OFF-29 — CCPA ADMT Regulations | Organization | The organization's request-handling, reviewer, risk-assessment, notice-and-contract, and watch capabilities | 5 (ORF-488–ORF-492) | 11 (5 new, 6 shared) |
One MFF-29 project per ADMT. The coverage determination, the Pre-use Notice, the opt-out and any exception relied on, the access responses, the risk assessment, and the role duties are all technology-specific. The two templates' Control sets do not overlap with each other; together the 13 Requirements map to 25 distinct Controls: 13 new California-specific Controls and 12 existing Controls co-mapped as supporting evidence (see The 12 shared Controls). There is no scoping questionnaire; MRF-489 records the coverage determination inside the project, and a conclusion that the regulations do not apply is what makes the conditional Requirements not applicable.
The CCPA Role tag
Template version 1.0.32 adds one tag category, CCPA Role, with four values attached directly to the Requirements:
- Business using ADMT — a business within Civ. Code § 1798.140(d) that uses ADMT to make a significant decision about a consumer (the Article 11 duties), or that processes personal information it intends to use to train ADMT for significant decisions (the Article 10 trigger).
- Service provider or contractor — a service provider within § 1798.140(ag) (a person that processes personal information on behalf of a business and receives it from or on behalf of the business for a business purpose under a written contract with the prescribed terms) or a contractor within § 1798.140(j) (a person to whom the business makes personal information available for a business purpose under such a contract), including for personal information processed with the ADMT or intended to train it.
- Third party — a third party within § 1798.140(ai), receiving personal information that the business made available for processing with the ADMT.
- ADMT supplier — a business that makes ADMT trained using personal information available to another business, the recipient-business, to make a significant decision, and must therefore provide to the recipient-business all facts available to it that are necessary for the recipient-business's own risk assessment (§ 7153).
The roles are deliberately non-exclusive: the same organization can be a business for one technology and a service provider, contractor, third party, or supplier for another, and a service provider, contractor, or third party that independently meets the business definition carries the business duties for ADMT it uses for its own significant decisions. All 13 Requirements carry Business using ADMT; MRF-495 and MRF-496 also carry ADMT supplier; MRF-496 carries all four. Filter a project by role to see the branch that applies.
The application framework — MFF-29
| Requirement | Legal anchor (Cal. Code Regs. tit. 11 unless noted) | CCPA Role | Conditional on | Mapped Controls |
|---|---|---|---|---|
MRF-489 — Coverage determination | §§ 7001(e), (ddd), 7002, 7150(b), 7155, 7200, 7271(a); Civ. Code §§ 1798.140(d), (i), (v), 1798.145, 1798.146 | Business using ADMT | Always applicable | MCF-695 |
MRF-490 — Pre-use Notice | §§ 7003, 7010, 7011, 7012, 7200, 7220 | Business using ADMT | Use for a significant decision | MCF-696; supporting: MCF-171, MCF-167, MCF-420 |
MRF-491 — Opt-out of ADMT | §§ 7001, 7004, 7060, 7063, 7080, 7200, 7221; Civ. Code § 1798.125 | Business using ADMT | Use for a significant decision, no § 7221(b) exception relied on | MCF-697 |
MRF-492 — Human-appeal route | §§ 7001, 7003, 7004, 7021, 7060, 7080, 7200, 7220, 7221; Civ. Code §§ 1798.140(ak), 1798.145(h) | Business using ADMT | Reliance on § 7221(b)(1) in place of the opt-out | MCF-698 |
MRF-493 — Hiring and work-allocation exceptions | §§ 7001, 7152, 7220, 7221 | Business using ADMT | Reliance on § 7221(b)(2) or (b)(3) | MCF-699; supporting: MCF-437 |
MRF-494 — Access to ADMT | §§ 7021, 7060–7062, 7080, 7222; Civ. Code §§ 1798.140(ak), 1798.145(h) | Business using ADMT | Use for a significant decision, whether or not an exception is relied on | MCF-700; supporting: MCF-420 |
MRF-495 — Risk assessment for the ADMT | §§ 7001, 7150–7156 | Business using ADMT; ADMT supplier | Use for a significant decision, or processing personal information intended to train such ADMT | MCF-701; supporting: MCF-443 |
MRF-496 — Service providers, third parties and ADMT suppliers | §§ 7050–7053, 7153, 7221, 7222; Civ. Code §§ 1798.100(d), 1798.140(j)(2), (ag)(2), 1798.145(i) | All four | Each limb the organization occupies | MCF-702; supporting: MCF-444 |
Each Requirement's detail content carries the source list with the adoption, approval, and effective dates, the application and transition clocks, the obligations addressed with the operative regulatory text quoted verbatim, the key concepts, and a section headed "How this requirement is assessed" that names the Control carrying the Requirement, separates duty from practice, and states the not-applicable rule. Reliance on an opt-out exception is per use: an exception relied on for one significant decision does not excuse the opt-out for another use of the same ADMT, and every other use is resolved on its own terms.
The organization framework — OFF-29
| Requirement | Legal anchor (Cal. Code Regs. tit. 11 unless noted) | Conditional on | Mapped Controls |
|---|---|---|---|
ORF-488 — ADMT request-handling infrastructure | §§ 7004, 7011, 7020–7021, 7060–7063, 7080, 7100–7102, 7221–7222; Civ. Code §§ 1798.140(ak), 1798.145(h) | Using or planning to use ADMT for a significant decision; the opt-out limb falls away where an exception is relied on for every use, the access limb never does | OCF-385; supporting: OCF-21 |
ORF-489 — Human involvement and human-appeal capability | §§ 7001(e)(1), 7021, 7221(b)(1); Civ. Code § 1798.145(h) | Reliance on human involvement to keep a technology outside ADMT, or on the human-appeal exception; an organization relying on neither route may mark it not applicable | OCF-386; supporting: OCF-17 |
ORF-490 — Risk-assessment program and Agency submissions | §§ 7150–7157 | Conducting any § 7150(b) activity; the § 7157 filing remains due for non-ADMT activities even where the ADMT content scoring falls away | OCF-387; supporting: OCF-195, OCF-194 |
ORF-491 — Notice, purpose-compatibility and contract program | §§ 7002, 7003, 7010, 7012, 7050, 7051, 7053, 7220(e) | Any organization in scope; the Pre-use Notice wiring attaches with Article 11, § 7053 where personal information is sold or shared | OCF-388; supporting: OCF-186, OCF-189 |
ORF-492 — California ADMT regulatory watch | No binding provision; the Agency's Final Statement of Reasons; Civ. Code § 1798.199.95(d) | Readiness practice; may be marked not applicable without legal consequence | OCF-389 |
All five carry CCPA Role: Business using ADMT. ORF-492 is framed in its own text as a supporting readiness practice, not a statutory duty: its anchors bind the Agency and the Legislature, not the organization.
The 13 new Controls
All thirteen carry the tag Framework: Specific; the application Controls are Scope: Project with AI System Lifecycle tags, the organization Controls Scope: Organization. Each has a guidance component (what the law requires, key considerations, what would fail the Control, relationships to other Controls, and the evidence an auditor expects), an evidence upload, and a report template.
| Control | Carries |
|---|---|
MCF-695 — CCPA ADMT coverage determination | A current, dated determination of whether the regulations reach this technology: business and consumer status (workers and students included), personal information in scope after exclusions and conditional exemptions, the ADMT test with the three-part human-involvement test in the decision flow, the significant-decision category, purpose compatibility for repurposed information, the training trigger, and the § 7200(b) timing branch; recorded as practice, not as a document Article 11 requires |
MCF-696 — Pre-use Notice | The notice presented prominently and conspicuously at or before collection (or before processing of repurposed information), in the primary interaction channel, with the specific purpose, the opt-out and access rights with how to submit each request (or, replacing the opt-out, the appeal route with instructions or the specific exception named), non-retaliation, and how the ADMT works with the alternative process absent an exception |
MCF-697 — ADMT opt-out mechanics | Two or more § 7004-compliant methods, one in the primary interaction manner and online a form via the notice link naming the opted-out use; no verification, account, or burdensome ask; fraud denial only on a documented, reasonable good-faith belief; confirmation; any granular choice alongside one option covering all significant-decision uses; a pre-initiation request barring processing; on a request after initiation from a consumer who did not opt out at the Pre-use Notice, cessation as soon as feasibly possible and no later than 15 business days from receipt, and instruction to the persons given that consumer's personal information for that ADMT to comply within the same time frame |
MCF-698 — Human-appeal route | Where § 7221(b)(1) replaces the opt-out: a designated reviewer who reviews the output and other relevant information, considers what the consumer submits, knows how to interpret and use the output, and can change the decision, reached through a clearly described, easy, minimal-step, § 7004-compliant method, with § 7003(a)–(b) communications, the § 7021 clocks, and Article 5 verification |
MCF-699 — Hiring and work-allocation exception evidence | Where § 7221(b)(2) or (b)(3) is relied on: the ADMT used solely for the permitted purpose, the business's evidence that it works for its purpose and does not unlawfully discriminate based upon protected characteristics, and the Pre-use Notice naming the exception |
MCF-700 — Access-to-ADMT response | Verified requests answered with the specific purpose, the logic, the outcome and how the output was used, and planned future use where it applies, plus non-retaliation and rights instructions; withholding from the logic and outcome elements limited to the § 7222(c) grounds; denials for a conflict with federal or state law or a CCPA exception explained under § 7222(f), and manifestly unfounded or excessive requests handled under Civ. Code § 1798.145(h)(3); Article 5 verification, secure delivery, and the § 7021 clocks |
MCF-701 — CCPA risk assessment for the ADMT | Before initiating the use (and, for pre-2026 continuing processing, by December 31, 2027), and likewise for personal information processed with intent to train such an ADMT: a § 7152 assessment with the logic-and-output element for a use, reviewed and approved by someone with authority to participate in the initiation decision; reviewed, and updated as necessary, at least every three years; updated as soon as feasibly possible and no later than 45 calendar days after a material change; retained while the processing continues or for five years after the completion of the assessment, whichever is later |
MCF-702 — Service-provider, third-party and supplier duties for the ADMT | By role: the business's § 7051(a)(5)–(9) and § 7053(a) contract terms and the § 7221(n)(2) notify-and-instruct step; the service provider's or contractor's § 7050 limits, contract compliance, direct-request handling, noticed subcontracts, and risk-assessment and access-ADMT assistance; the third-party bar under § 7052; the supplier's § 7153 facts |
OCF-385 — ADMT request-handling infrastructure | One intake, verification, clock, records, and reporting capability for opt-out, access, and appeal requests: tested § 7004 methods; the 10-business-day and 45/90-calendar-day limits with the Civ. Code § 1798.145(h) mechanics; Article 5 verification, never for an opt-out; agents and other submitters; handler training; the 10,000,000-consumer predicates for the training policy and the July 1 metrics; 24-month records; the § 7011(e) privacy-policy content |
OCF-386 — Human involvement and human-appeal capability | Conditional on the route the organization states: reviewers in the original decision flow who meet all three parts of § 7001(e)(1), or designated appeal reviewers who meet § 7221(b)(1)(A) with a channel for the consumer's information and answers on the § 7021 clocks; not applicable where neither route is relied on |
OCF-387 — Risk-assessment program and Agency submissions | § 7152 assessments before initiation, the three-year review, the material-change update as soon as feasibly possible and within 45 calendar days, the December 31, 2027 legacy deadline, retention, the § 7157(b) information for every § 7150(b) activity from a qualifying executive by April 1, 2028 and April 1 after any later assessment year, and reports on request within 30 calendar days |
OCF-388 — Notice, purpose-compatibility and contract program | § 7003 disclosure quality with the Article 2 additions (readable format, the business's ordinary languages, accessibility for consumers with disabilities online by standards such as WCAG 2.1 and offline by alternative-format information); the Notice at Collection and privacy-policy wiring for the Pre-use Notice; § 7002's original-purpose, compatible-purpose, and consent routes with proportionality for repurposed information; the § 7051 and § 7053 contracts carrying the same-level-of-protection term |
OCF-389 — California ADMT regulatory watch | An owned watch on the five tracks below, each development routed into the affected notices, procedures, and determinations; may be marked not applicable |
The 12 shared Controls
Twelve existing Controls are co-mapped to nine of the Requirements as supporting evidence. Each carries a generic layer the California duty builds on; Evidence already attached to it counts toward the Requirement. The California-specific limbs stay in the new Control named in the last column. The Requirement's readiness signal counts every linked Control, shared ones included, so a co-mapped Control must reach a final status before the Requirement shows as ready to review. Shared Controls are framework-agnostic: a Control mapped by more than one framework states a neutral core and reads "the requirement that maps this control in your framework"; every framework-specific obligation lives in that framework's Requirement text or in a framework-exclusive Control, never in a shared Control.
| Shared Control | Also mapped by | Co-mapped to | Its Evidence covers | Stays in the new Control |
|---|---|---|---|---|
MCF-171 — Informing People Subject to AI-Assisted Decisions | EU AI Act, NIST AI RMF, Colorado SB 26-189 | MRF-490 | Disclosing to people that an AI system makes or assists in decisions about them | No platform mapping note for this co-map; the § 7220 mechanics remain in MCF-696 |
MCF-167 — Transparent Deployment at Workplace | EU AI Act, NIST AI RMF, Microsoft Supplier DPR, NYC Local Law 144 | MRF-490 | The worker branch of § 7220: consumers include employees, job applicants, independent contractors, and students, and hiring, compensation, and work allocation are significant decisions | The § 7220 mechanics (MCF-696) |
MCF-420 — Explainability Controls | GDPR, UAE Consumer AI, UAE PDPL | MRF-490, MRF-494 | The plain-language "how the ADMT works" limb of § 7220(c)(5)(A)–(B), and explanation quality for the § 7222(b)(2)–(3) logic and outcome explanations | Notice placement, conspicuousness, and language rules (MCF-696); the narrow § 7222(c) withholding grounds, verification, clocks, and delivery (MCF-700) |
MCF-437 — Automated Decision Fairness Assessment | GDPR, UAE PDPL | MRF-493 | Periodic fairness assessment and discrimination detection, as supporting evidence for the no-unlawful-discrimination limb of § 7221(b)(2)(B) and (b)(3)(B) only | Whether the ADMT works for the business's purpose, and with it the complete (b)(2)(B) and (b)(3)(B) conditions, the "solely" purpose limit, and the match between the exception relied on and the Pre-use Notice (MCF-699) |
MCF-443 — Privacy impact assessment | ISO 27701, UAE Consumer AI, UAE PDPL | MRF-495 | Conducting, documenting, and re-examining the assessment; its question already branches per governing law, and California is one more branch | The mandatory § 7150(b)(3) and (b)(6) triggers, the § 7152 content list, the weighing of risks against benefits, and the approver (MCF-701) |
MCF-444 — Contracts with PII processors | ISO 27701 | MRF-496 | That written contracts with processors, and the oversight behind them, exist | The § 7051(a)(5)–(9) terms, the § 7053(a) third-party contracts, the role-by-role duties, the § 7050(a) limits, and the § 7153 supplier facts (MCF-702) |
OCF-21 — Easy Access to Explanation | UAE AI Ethics, Microsoft Supplier DPR | ORF-488 | An easily accessible, user-friendly explanation, supporting the § 7222(d) ease-of-use standard and the § 7004 method-quality rules; its "free of charge" element is narrower than Civ. Code § 1798.145(h), which permits a fee for a manifestly unfounded or excessive request, so it supports the duty rather than carrying it | Intake, verification, clocks, and records (OCF-385) |
OCF-17 — Decision Challenge empowerment | UAE AI Ethics, Microsoft Supplier DPR | ORF-489 | The challenge route, independent reviewers, and tracked cases, which is the § 7221(b)(1)(A) human-appeal limb only; a post-decision challenge never satisfies the § 7001(e)(1) human-involvement test | Both limbs, scored against the route the organization relies on (OCF-386) |
OCF-195 — DPIA Triggers and Review | GDPR | ORF-490 | Documented trigger criteria, verification that triggered processing is assessed, the update-versus-new rule, the periodic scan, and recorded decisions: the program layer behind intake before initiation, the § 7155(a)(2) three-year review calendar, and the § 7155(a)(3) material-change list | The § 7152 content, retention, and the § 7157 filings (OCF-387) |
OCF-194 — DPIA Methodology | GDPR | ORF-490 | The structured methodology behind the § 7156(a) comparable-set assessment and the § 7156(b) reuse of an assessment prepared for another purpose (secondary) | The California-specific content (OCF-387) |
OCF-186 — Transparency Framework | GDPR | ORF-491 | What information goes to whom and when, the formats and channels, verification that it was implemented, and review against changes in processing: the notice-and-communication machinery § 7003 and § 7012 depend on | The California notice content (OCF-388) |
OCF-189 — Processor Management System | GDPR, UAE Consumer AI, UAE PDPL | ORF-491 | Selection criteria, assistance and sub-processing clauses, due diligence, and ongoing oversight: the contract-estate limb | The §§ 7051 and 7053 same-level term and the § 7002 purpose-compatibility analysis (OCF-388) |
MRF-489, MRF-491, MRF-492, and ORF-492 map only to their new Control. The platform's mapping notes record six reuses considered and rejected: MCF-16 Risk Tiering (the § 7200(a) coverage determination is a conjunctive legal conclusion, not a tiering exercise), MCF-419 Automated Decision-Making Safeguards (only one sentence of it touches an opt-out), OCF-19 Critical Decision Opt-out (its criteria let the organization decide when an opt-out is feasible, where § 7221(a) makes it mandatory absent a listed exception), OCF-97 Risk assessment process (the ISO clause 6.1.2 management-system assessment), OCF-352 Govern consumer human review, complaints, and redress for AI decisions (written to the CBUAE guidance note and the UAE Consumer Protection Regulation), and OCF-363 Regulatory Instrument Watch and Readiness (built for pending implementing instruments that complete an existing law's obligations). The California duties themselves remain specific in content, trigger, and clock: a Pre-use Notice with two timing branches and two substitutions, an opt-out that may not be verified, that bars initiation when requested beforehand, and that, on a request after initiation from a consumer who did not opt out at the Pre-use Notice, must stop processing as soon as feasibly possible and no later than 15 business days with recipient instruction, an appeal route with five reviewer conditions, two exceptions that hold only while a purpose limitation and an outcome condition stay true, an access response with four mandatory explanations and a narrow aggregate option, and a risk assessment with a prescribed logic-and-output element for uses of ADMT for a significant decision, an approver with authority to participate in the initiation decision, and an executive-attested filing. No existing Control carries any of them, and the coverage determination is a conjunctive legal conclusion rather than risk tiering, so the shared risk-tiering Control was not reused either. Nothing was edited in other frameworks; the co-maps add the CCPA Requirements to the shared Controls' link lists without changing their text or tags.
An AI-application project that already carries another framework and adds MFF-29 therefore gains the 8 new Controls and links 6 existing ones where the other framework already maps them. Evidence on those shared Controls counts toward the CCPA Requirement; Evidence on the other framework's remaining Controls does not serve the new ones. Separate per-technology projects keep separate Control instances and Evidence libraries.
The watch — five tracks
ORF-492 and OCF-389 carry five greppable watch markers, each naming what it feeds; the dated status of each item lives in OCF-389, and ORF-492 points to it:
| Marker | What it watches | Feeds |
|---|---|---|
CA-WATCH-AGENCY-RULES | Future Agency rulemaking or guidance on ADMT; in its Final Statement of Reasons the Agency said it may revisit the ADMT definition (§ 7001(e)), the significant-decision definition (§ 7001(ddd)), and the Article 11 applicability provision (§ 7200) | MRF-489 and every Article 11 Requirement |
CA-WATCH-AB1018 | AB 1018, a California bill that would add a separate regime with its own defined terms (an automated decision system, a covered ADS, a consequential decision, a developer and a deployer); its duty set has shifted with each amendment, the August 21, 2026 floor amendment removed its assessment regime, it was on second reading in the Senate as of that date, and as of August 2026 it is not law | Whether a second California regime arrives |
CA-WATCH-SB947 | SB 947, a California bill that would place Labor Code limits on employers' use of an automated decision system in disciplinary and termination decisions; as of August 21, 2026 it had been read a third time and amended in the Assembly, and as of August 2026 it is not law | Workforce uses |
CA-WATCH-THRESHOLDS | The odd-year adjustment of the CCPA monetary thresholds for any increase in the Consumer Price Index (Civ. Code § 1798.199.95(d)), next effective January 1, 2027, the same day the Article 11 transitional deadline falls | MRF-489 business status |
CA-WATCH-FEDERAL-PREEMPTION | Proposals that would displace California privacy law; CalPrivacy opposed the federal SECURE Data Act in April and June 2026; no enacted federal law changes the duties | Every Requirement |
Modulos updates the framework content if the Agency revisits the ADMT provisions or a bill becomes law; framework versioning notifies affected projects. The two bills are watch items only: as of August 2026 neither is law, this framework does not implement them, and their vocabulary is theirs, not the regulation's. The watch has a known expiry: both bills faced the August 31, 2026 deadline for each house to pass bills, and a bill passed before September 1, 2026 and in the Governor's possession on or after that date becomes a statute if it is not returned on or before September 30, 2026 (Cal. Const. art. IV, § 10(b)(2)), so both items resolve by early October 2026. The status stated here is as of August 21, 2026.
Rollout sequence
- Determine coverage for each technology (
MRF-489): run the conjunctive test, apply the exemptions on their conditions, test human involvement in the original decision flow, place the decision on the closed significant-decision list, determine the training limb, and record which § 7200(b) branch the use is on. - Assess before you initiate (
MRF-495,ORF-490): a newly covered use or training activity needs its § 7152 assessment, reviewed and approved by someone with authority to participate in the initiation decision, before it starts; continuing pre-2026 processing needs it by December 31, 2027. Name the executive who will file under § 7157(c) and build the register behind the per-activity counts for the April 1, 2028 filing. - Stand up the organization capabilities (
ORF-488,ORF-491): the request intake with tested § 7004 methods, the § 7021 clocks, Article 5 verification for access and appeals, 24-month records, and the privacy-policy content; the notice templates meeting § 7003, the Notice at Collection wiring, the purpose-compatibility analysis for repurposed information, and the contract estate with the same-protection term. - Decide the opt-out posture per use (
MRF-491,MRF-492,MRF-493,ORF-489): offer the opt-out, or rely on an exception on its conditions. A human-appeal route needs designated reviewers meeting all five conditions and a channel for the consumer's information; the hiring and work-allocation exceptions need the "solely" purpose limitation kept true and the outcome evidence in hand. Where human involvement is claimed to keep a technology outside ADMT, the reviewers in the decision flow must meet all three parts of § 7001(e)(1). - Publish the Pre-use Notice and wire the access response (
MRF-490,MRF-494): the notice at or before collection, in the primary channel, with the right opt-out paragraph or substitution and the how-it-works layer; the four-explanation access response on the § 7021 clocks with the verification tier by account status. A use begun before January 1, 2027 has until that date; a use begun on or after it has no grace period. - Settle the role duties (
MRF-496): confirm the contract terms; on a post-initiation opt-out from a consumer who did not opt out at the Pre-use Notice, cease as soon as feasibly possible and no later than 15 business days and instruct the persons given that consumer's personal information for that ADMT to comply within the same time frame; and, as a supplier of ADMT trained using personal information, give each recipient-business all facts available to you that its own assessment needs. - Own the watch (
ORF-492): assign the five tracks; as each development lands, reconcile the notices, the privacy policy, the request procedures, the assessment templates, and the contract terms against the new text, and re-run the coverage determination where the ADMT definition, the significant-decision definition, or the applicability threshold moved.
Each Requirement is evidenced through its linked Control; the Requirement Owner reviews the completed Control and marks the Requirement as Fulfilled.
What the framework deliberately does not include
- Vocabulary from other regimes. No controller, processor, data subject, or "solely automated" decision from the GDPR; no consequential decision, adverse outcome, developer, or deployer from Colorado SB 26-189 or AB 1018. The regulations' terms are the only ones the Requirements use.
- AB 1018 and SB 947 as duties. Both were pending bills as of August 2026, tracked under the watch with its September 2026 backstop; neither is implemented.
- The Civil Rights Council's employment regulations on automated-decision systems, a separate California regime under a different statute.
- The other § 7150(b) activities' assessment content. The framework scores the ADMT use and training limbs; the counts for the other activities belong in the § 7157 filing, their content does not belong here.
- A prescribed test for the exceptions' outcome condition. The regulations set the condition that an ADMT "works for the business's purpose and does not unlawfully discriminate based upon protected characteristics" and leave the showing to the business; the framework records the evidence relied on and claims nothing beyond that.
Where to go next
CCPA ADMT Regulations overview
What the regulations require, who is covered, the clocks, enforcement, and the pending developments
Coverage and roles
The conjunctive test, the human-involvement test, the closed list, exemptions, the training trigger — MRF-489; the four roles defined
Pre-use Notice, opt-out, and access
The Article 11 duties and the request machinery — MRF-490–494, ORF-488, ORF-489
Risk assessments and Agency submissions
Article 10 for ADMT and the April 1 filings — MRF-495, ORF-490
Service providers and ADMT suppliers
Contracts, the opt-out flow-down, and the supplier's fact duty — MRF-496, ORF-491
Disclaimer
This page is for general informational purposes and does not constitute legal advice. The Agency has said it may revisit the ADMT provisions in future rulemaking, and AB 1018 and SB 947 were pending bills, not law, as of August 2026 (see the watch above for the September 2026 backstop). Always verify against the current published text and consult qualified advisers.