AI Regulation Tracker · California CPPA · Regulation

What does CPPA ADMT, risk-assessment and cybersecurity-audit regulations say about AI in banking?

Published Sep 22, 2025 · Last reviewed Sep 1, 2026

Adopted by the California Privacy Protection Agency board on July 24, 2025, approved by the Office of Administrative Law on September 22, 2025 and operative January 1, 2026, this package adds three articles to the CCPA regulations: annual cybersecurity audits (Article 9), risk assessments (Article 10) and automated decisionmaking technology (Article 11). A business that uses ADMT to make a significant decision — one that results in the provision or denial of financial or lending services, housing, education, employment or health care — must from January 1, 2027 give a pre-use notice, honor an opt-out or instead offer an appeal to a qualified human reviewer, and on request explain the logic, output and use of the technology. Risk assessments must be completed before such processing starts, with attestations and summaries submitted to the Agency by April 1, 2028; cybersecurity-audit certifications phase in from April 1, 2028 by revenue.

DocumentCPPA ADMT, risk-assessment and cybersecurity-audit regulationsCCPA Updates, Cybersecurity Audits, Risk Assessments, Automated Decisionmaking Technology, and Insurance Companies — approved regulation text (11 CCR Division 6)
Issued byCalifornia — Privacy Protection Agency (CCPA/CPRA automated decisionmaking, risk-assessment and cybersecurity-audit regulations), Attorney General, and Civil Rights Council
TypeRegulation
StatusIn force
PublishedSep 22, 2025
EffectiveJan 1, 2026
Applies toBusinesses subject to the CCPA — for banks and lenders, personal information not subject to GLBA or the California Financial Information Privacy Act, notably employee and applicant data, marketing and prospect data, and model-training data
Official sourcecppa.ca.gov
Use casesCredit scoring & underwriting · Fair lending & discrimination · Data & privacy · Cybersecurity · AI governance (general)

What are the key points of CPPA ADMT, risk-assessment and cybersecurity-audit regulations?

  • 'ADMT' means technology that processes personal information and uses computation to replace or substantially replace human decisionmaking; a human who knows how to interpret the output, actually reviews it and has authority to change the decision takes the process outside the definition
  • 'Financial or lending services' — the first-listed significant decision — covers extending credit or a loan, transmitting or exchanging funds, deposit or checking accounts, check cashing and installment payment plans; behavioral advertising was dropped from the final text
  • ADMT obligations from January 1, 2027: pre-use notice describing purpose and how the technology works; a right to opt out, which the business may replace with a human-appeal route staffed by a reviewer able to overturn the decision; and an access right to the logic, key parameters, output and its role in the decision
  • Risk assessments required before selling or sharing personal information, processing sensitive personal information, using ADMT for a significant decision, or training ADMT for such use; attestation and summary due to the CPPA by April 1, 2028 for 2026–27 activities, then annually
  • Cybersecurity audits for businesses over the size thresholds, certified to the Agency by April 1, 2028 (revenue over $100M), April 1, 2029 ($50–100M) or April 1, 2030 (under $50M), then annually
  • The Agency declined to add an entity-level exemption for financial institutions: the CCPA already exempts GLBA- and CalFIPA-covered information at the data level (Civil Code §1798.145(e)), a point the Final Statement of Reasons makes explicit
  • Employee, applicant and contractor personal information has been fully inside the CCPA since January 1, 2023, so hiring, promotion and compensation decisions at a bank are squarely covered

What did CPPA ADMT, risk-assessment and cybersecurity-audit regulations change for banks?

California turned its privacy statute into the state's operative AI rule for consequential decisions without passing an AI statute. For banks the practical effect is a two-track programme: GLBA-covered credit and account data are largely outside the ADMT article, while HR screening tools, marketing models, non-GLBA products and any model trained on Californians' non-exempt data need notices, appeal channels, risk assessments and, above the thresholds, audited security by 2028.

When must businesses comply with California's ADMT rules?

January 1, 2027 for ADMT used to make significant decisions; businesses that start using ADMT after that date must comply from first use. Risk-assessment attestations are due April 1, 2028.

Is a credit model 'ADMT' if an underwriter reviews its output?

Not if the human involvement is real: the reviewer must know how to interpret the output, actually review it, and have the authority to change the decision. A rubber-stamp review does not take the model outside the definition.

Does the GLBA exemption take a bank out of the ADMT rules?

It takes GLBA-covered information out, not the institution. Data outside GLBA — employee and applicant data, marketing data, training data — remains subject to the rules.

DateDocumentStatus
Jun 27, 2025Civil Rights Council ADS employment regulationsModifications to Employment Regulations Regarding Automated-Decision Systems (Fair Employment and Housing Act regulations, 2 CCR)In force
Jan 13, 2025California AG legal advisory on AI (Jan 2025)Legal Advisory: Application of Existing California Laws to Artificial IntelligenceFinal
Jun 28, 2018Cal. Civ. Code §1798.145 (CCPA exemptions, incl. GLBA data)California Consumer Privacy Act — exemptions, including the data-level exemption for information subject to the Gramm-Leach-Bliley Act and the California Financial Information Privacy Act (Civil Code §1798.145)In force
Aug 11, 2026Colorado AG proposed ADMT rulesProposed Automated Decision-Making Technology and Conversational AI Service Rules (Notice of Rulemaking Hearing)Comment period open
Jul 24, 2026Regulation (EU) 2026/1744 (Digital Omnibus on AI)Regulation (EU) 2026/1744 amending Regulation (EU) 2024/1689 as regards the simplification of the implementation of harmonised rules on artificial intelligence (Digital Omnibus on AI)In force
May 19, 2026Draft Commission guidelines on high-risk classificationDraft Commission Guidelines on the classification of high-risk AI systems under Article 6 of the AI ActProposed

Follow every document these regulators publish

6 curated AI stories for banking executives · Every morning · Free

Subscribe to BankingNewsAI →