2026-01-01 · US-CA · in force now
Conduct a risk assessment before deploying automated decision-making technology for significant decisions or training it on California residents' personal information. The requirement is now in force as of January 1, 2026.
What it requires
Before you initiate any covered processing using automated decision-making technology (ADMT) for a significant decision, or before training ADMT on personal information, you must complete a risk assessment. The assessment must happen before deployment begins. This applies whether you are using ADMT to make decisions about individuals or using their data to train the system itself. The regulation requires the assessment to occur upfront, not after launch.
Who it binds
CCPA-covered businesses that process California residents' personal information. This includes companies that collect, use, or disclose personal data of California residents and deploy automated decision-making systems. Responsibility typically lands on privacy teams, product managers, data engineers, and compliance officers who oversee technology deployment and data handling.
How to check whether you comply
Audit your systems: identify all automated decision-making tools currently in use or in development that touch California residents' data.
Verify a risk assessment document exists for each ADMT before it processed any personal information or made its first decision.
Confirm the assessment occurred before the system went live, not after, by checking timestamps and project records.
Check that your team has documented what 'significant decision' means in your business context and applied it consistently.
What teams get wrong
Teams often confuse 'risk assessment' with general AI testing or bias audits. The CCPA regulation requires a formal assessment completed before processing starts. If you deployed ADMT before January 1, 2026 without one, verify compliance immediately. Delay in starting the assessment after that date is a direct violation.
This is one of 17 dated AI obligations we track
This one is already in force. There are 16 others across the EU, UK, and US, and they do not arrive in a convenient order. The AI Compliance Deadline Radar lists every one of them with a live countdown.
Get The AI Reg Brief — free. Twice a month, three minutes. Every issue leads with a countdown to the next deadline that binds you, so the one about to land finds you rather than the other way round.
Transparency in Frontier AI Act (SB 53) — US-CA, 2026-01-01
California AI Transparency Act (SB 942) — US-CA, 2026-08-02
California AI Transparency Act (SB 942) — platform duties — US-CA, 2027-01-01
Source
Not legal advice. This summarizes a public source so you can act on it; verify against the primary text before you rely on it.
