Back to the Blog
Cybersecurity

California’s New AI Decision-Making Rules: What CCPA’s ADMT Requirements Mean for Your Business Before April 2027

Tristen Cooper

If your business uses software to help screen job applicants, evaluate loan or credit applications, or make other decisions that materially affect people, California just gave you a deadline: April 1, 2027. That’s when the California Consumer Privacy Act’s Automated Decision-Making Technology (ADMT) requirements become fully enforceable.

The underlying regulatory updates took effect back in January 2026, but the specific ADMT obligations, including risk assessments, pre-use notices, and opt-out rights, are phased in and land fully in force by that April 2027 date. For a lot of growing businesses, especially ones that have adopted AI-assisted tools without fully mapping where they’re used, this is worth taking seriously well before then.

What ADMT actually means

Automated Decision-Making Technology, or ADMT, refers to any technology that processes personal information to make or substantially replace human decision-making. Under the CCPA’s updated rules, businesses that use ADMT to make “significant decisions” about consumers or employees take on new obligations: telling people before the system is used on them, giving them a way to opt out in most cases, and being able to explain in plain terms how the decision was reached.

“Significant decisions” has a specific meaning under these rules, not a vague catch-all one. The rules point to specific categories: employment (hiring, promotion, discipline, termination), lending and financial services, housing, insurance, healthcare, and access to essential goods and services. If your business touches any of those categories and uses software to help make those calls, this regulation is likely written with you in mind.

Why this matters for growing companies specifically

A lot of the tools that trigger ADMT obligations were bought to save time: applicant-tracking software that scores resumes, underwriting tools that flag or approve applications, scheduling or performance software that factors into promotion or termination decisions. Nobody was thinking about AI compliance risk when they signed the contract, which is exactly how gaps like this form.

For an operations leader already fielding auditor questions about documentation gaps, this is one more area where “we didn’t know we needed a policy for that” doesn’t hold up well in a review. For a founder trying to walk into a board meeting with a confident answer on the company’s compliance posture, ADMT is about to become a question worth having an answer ready for.

What businesses will need to have in place

  1. A pre-use notice. People need to be told, before an automated system is used to make a significant decision about them, that it’s happening and what it’s evaluating.
  2. An opt-out mechanism. In most cases covered by the rule, people need a way to request a human alternative instead of the automated decision.
  3. The ability to explain the decision. If someone asks why an automated system reached a particular outcome about them, the business needs to be able to answer. The underlying tool has to be explainable, and the company using it can’t treat it as a black box either.
  4. A current inventory of where ADMT is actually used. This is the step most companies skip, and it’s the one that makes every other step possible. You can’t provide a notice, honor an opt-out, or explain a decision for a tool you haven’t identified as covered.

Before full enforcement vs. after April 2027

NowAfter April 1, 2027
Notice to affected peopleOptional, informalRequired before use
Opt-out for automated decisionsNot requiredRequired in most covered cases
Explainability of the decisionNice to haveBusinesses must be able to provide it
Risk if a gap surfaces in an auditA recommendationA compliance finding

How to actually get ready before the deadline

The businesses that handle this well won’t be the ones scrambling in the first quarter of 2027. They’ll be the ones who start now, well ahead of the deadline, to do 3 things: inventory every tool that touches hiring, lending, insurance, housing, or essential services decisions; confirm with each vendor whether their tool qualifies as ADMT and what documentation they can provide; and update internal policies and any employee- or customer-facing notices long before an auditor asks about it.

This is exactly the kind of work we mean when we talk about treating compliance as a competitive advantage instead of a burden. Parachute has held SOC 2 Type 2 certification for 7 consecutive years (a credential fewer than 5% of MSPs nationwide can claim), and that same discipline around documentation, audit readiness, and closing gaps before they surface is what a regulation like ADMT calls for. We’d rather help you build the inventory and the notice process now than help you explain a gap to an auditor later.

Frequently Asked Questions

When does CCPA’s ADMT requirement take effect?

The Automated Decision-Making Technology requirements under the California Consumer Privacy Act become fully enforceable on April 1, 2027. The broader CCPA regulatory updates that introduced these rules took effect January 1, 2026, with ADMT-specific obligations phased in over the following year.

What counts as a “significant decision” under ADMT?

Significant decisions include employment decisions (hiring, promotion, discipline, termination), and decisions about lending, housing, insurance, healthcare, and access to essential goods and services, when an automated system materially informs or replaces the decision.

Does ADMT apply to small businesses?

ADMT obligations apply based on how a business uses covered technology and the CCPA’s existing applicability thresholds, not company size alone. A growing business using automated hiring or lending tools should confirm its status rather than assume it’s too small to be covered.

What should a business do first to prepare for ADMT?

The first step is building an accurate inventory of every tool currently used to make or inform significant decisions about employees or customers. Without that inventory, none of the other requirements (notice, opt-out, explainability) can be implemented correctly.

Schedule a discovery call with Parachute’s team, and let’s map out exactly where your compliance gaps are before the enforcement deadline (or your auditor) finds them for you -> https://parachute.cloud/free-consultation/.

This article is for general informational purposes and reflects our understanding of the requirements as of publication. It isn’t legal advice. Talk to your attorney about how these rules apply to your specific business.

Parachute California Local Offices

San Francisco

One Sansome Street, Suite 3500
San Francisco, CA 94104

(855) 805-4739

San Jose

3031 Tisch Way, 110 Plaza West
San Jose, CA 95128

(855) 805-4739

San Ramon

2010 Crow Canyon Pl #260
San Ramon, CA 94583

(415) 762-0720

Sacramento

333 University Ave #200
Sacramento, CA 95825

(916) 237-9310

Los Angeles

12100 Wilshire Boulevard, 8th Floor
Los Angeles, California 90025

(800) 805-0284

Irvine

530 Technology Dr., Suite 100 & 200
Irvine, California 92618

(800) 805-0284

San Diego

402 West Broadway, Suite #400
San Diego, California 92101

(800) 805-0284