2027-01-01 · US-CA · 141 days from today
Businesses covered by the CCPA and using automated decision-making technology (ADMT) for significant decisions about California residents must achieve full compliance by January 1, 2027. Those deploying ADMT after that date must comply immediately.
What it requires
If your business currently uses automated decision-making to make significant decisions affecting California residents, you must bring your systems into compliance with CCPA regulations by January 1, 2027. Any new deployment of ADMT after that date must comply from day one. The obligation applies whether ADMT is used in hiring, credit decisions, content moderation, or other material choices. Compliance means meeting whatever ADMT-specific requirements the regulations establish—typically transparency, human review, and rights notification.
Who it binds
This deadline binds CCPA-covered businesses—generally those collecting California residents' personal information and meeting revenue or data-volume thresholds. Compliance responsibilities land on privacy teams, legal counsel, product managers overseeing automated systems, and data governance leads. Any organization using algorithmic decision-making for significant life outcomes (employment, finance, services) must act.
How to check whether you comply
Audit your technology stack: list every system using machine learning, rules engines, or algorithms to make or materially influence decisions about individuals.
Map each system to a business outcome (hiring, lending, access, pricing) and confirm whether it qualifies as 'significant' under CCPA definitions.
Review the CCPA regulations text and the California Attorney General's guidance on ADMT compliance to identify specific requirements your systems must satisfy.
Assess your current state against those requirements and create a remediation plan with target completion before January 1, 2027.
What teams get wrong
This obligation is confirmed. The most common mistake is treating ADMT compliance as a one-time audit rather than an ongoing governance requirement. Teams often underestimate the scope—automated decisions include ranking algorithms and filtering systems, not just binary deny/approve outputs. Verify you understand the California regulations' definition of 'significant decision' before January 1; it may be narrower or broader than your internal classification.
This is one of 17 dated AI obligations we track
You have 141 days on this one. There are 16 others across the EU, UK, and US, and they do not arrive in a convenient order. The AI Compliance Deadline Radar lists every one of them with a live countdown.
Get The AI Reg Brief — free. Twice a month, three minutes. Every issue leads with a countdown to the next deadline that binds you, so the one about to land finds you rather than the other way round.
California AI Transparency Act (SB 942) — platform duties — US-CA, 2027-01-01
CCPA regulations — ADMT consumer rights — US-CA, 2027-04-01
California AI Transparency Act (SB 942) — US-CA, 2026-08-02
Source
Not legal advice. This summarizes a public source so you can act on it; verify against the primary text before you rely on it.
