# California's Final ADMT Regulations for Banks and Lenders: What the CPPA Lands on Significant Decisions and What Is Due in 2027

*June 19, 2026 · 13 min read · Pranay Shetty*

> The California Privacy Protection Agency finalized its automated decisionmaking technology regulations in late 2025, with phased compliance through 2027 and 2028. The pre-use notice, the access and opt-out rights, the risk assessment attestation, and the cybersecurity audit, applied to a bank or non-bank lender's AI agent on a California consumer.

## The Second State Regime Lands on a Different Architecture Than the First

We wrote earlier this month on [Colorado SB 26-189](/blog/colorado-ai-act-banks-lenders-consequential-decisions), the statute Colorado used to replace its 2024 AI Act before that act took effect. California's framework, finalized by the California Privacy Protection Agency in November 2025 and routed through the Office of Administrative Law at the end of the year, is the other state regime a bank or non-bank lender with a California consumer book has to build against. The two frameworks reach overlapping conduct, but the deliverables a California Attorney General sweep and a CPPA enforcement action will measure the institution on are not the same as Colorado's, and a program built only against Colorado is going to come up short in California in 2027.

The California regulations sit at [Title 11, Division 6, Chapter 1 of the California Code of Regulations](https://cppa.ca.gov/regulations/) and amend the CCPA's implementing rules to add three new modules: automated decisionmaking technology, risk assessments, and cybersecurity audits. The statutory hook is [Civil Code § 1798.185(a)(15) and (16)](https://leginfo.legislature.ca.gov/faces/codes_displaySection.xhtml?lawCode=CIV&sectionNum=1798.185), which directed the Agency to write regulations on access and opt-out rights for automated decisionmaking and on risk-assessment and audit obligations. The Agency took several rulemaking cycles to land the text, narrowed the scope substantially from earlier drafts, and finalized a package in late 2025 with compliance dates phased into 2027 for the ADMT and risk-assessment modules and into 2028-2030 for the cybersecurity audit module, depending on revenue tier.

We sit on the customer surface for the bank or non-bank lender's California consumer, so the architecture has to produce the artifacts a CPPA enforcement file and a Cal AG sweep will read. The post below is the version of that architecture we are running with our customers for the January 1, 2027 turn-on.

## The ADMT Definition That Decides Whether the Agent Is in Scope

The final regulations narrowed the definition of "automated decisionmaking technology" from the broader machinery in earlier drafts. The version that landed is technology that processes personal information and uses computation to replace human decisionmaking or substantially replace human decisionmaking in a way that produces a significant decision about a California consumer. The "substantially replaces" formulation matters because it is the test that catches the underwriting recommendation a loan officer almost always accepts, the early-default risk score the servicer acts on, and the pricing engine that produces a take-it-or-leave-it offer. A program that defends its AI deployment as "human in the loop" without examining whether the human is actually exercising independent judgment is a program whose ADMT scope analysis the CPPA staff is not going to credit.

Earlier drafts of the regulations carried a "facilitates" prong that would have pulled in essentially any system feeding a human decisionmaker. The Board narrowed that language under industry comment, and the final version is closer to Colorado's "materially influences" test, although the California formulation puts the weight on whether the technology is substituting for the human rather than on whether it is shaping the human's call. The practical effect is a similar scope outcome and a slightly different test the institution's documentation has to track against.

The personal-information predicate is doing real work. The definition reaches technology that processes personal information, which the CCPA defines broadly at [Civil Code § 1798.140(v)](https://leginfo.legislature.ca.gov/faces/codes_displaySection.xhtml?lawCode=CIV&sectionNum=1798.140) and which the regulations carry through. A bank AI agent that holds the consumer's identifiers, account history, and conversation transcript is processing personal information for any decision it touches, and the agent's inputs cannot be argued out of the definition by calling them anonymized when they are tied to a logged-in account.

## What Counts as a "Significant Decision" at a Bank or Non-Bank Lender

The regulations enumerate the significant-decision domains. The list includes financial or lending services, housing, employment, education, healthcare, essential goods or services, and criminal justice. Financial or lending services and housing are the two domains every California-touching bank or mortgage lender lands in immediately. The regulatory text reaches the consumer's access to, approval for, denial of, provision or termination of, and amount or terms of the service. So underwriting eligibility, credit-limit changes, collection actions that affect provision of an account, loss-mitigation eligibility, pricing of credit, and account closures are all in scope. The exclusion the regulations carry for ordinary maintenance functions and fraud and security uses is real, but it is narrower than the institutions we work with initially read it to be, and the operating posture we recommend is to document each agent function against the carve-outs rather than to argue them in the aggregate.

The fraud-and-security carve-out, in particular, has been a focal point of industry comment. The regulations allow ADMT use for fraud-prevention and security purposes without triggering the access and opt-out rights, but the carve-out does not extend to using the same ADMT for credit underwriting or for general account management. The institution that uses a single model for fraud screening and for credit-line management is the institution whose carve-out coverage is partial, and the documentation has to reflect that partial coverage at the function level. A model that does both has to be described both ways in the inventory, and the access and opt-out rights apply to the credit-line management leg whether or not they apply to the fraud leg.

The Gramm-Leach-Bliley Act preemption question that some institutions raise on the financial-services side does not, in our reading, dispose of the ADMT obligations. [GLBA § 6807](https://www.law.cornell.edu/uscode/text/15/6807) preempts state law only to the extent the state law is inconsistent and only as to the protection afforded by GLBA, and the ADMT regulations layer a transparency and rights regime that does not directly conflict with the GLBA Privacy Rule. The CPPA's posture, expressed through the rulemaking record, is that the regulations co-exist with GLBA. An institution that takes the position that GLBA preempts a CCPA ADMT obligation should be ready to argue that conflict on the specific obligation rather than as a categorical defense.

## The Pre-Use Notice the Agent Has to Render

The regulations require a business that uses ADMT for a significant decision to provide a pre-use notice to the consumer. The notice has to identify the use of ADMT, explain how the technology will be used, describe the consumer's rights under the regulations, and tell the consumer how to exercise them. The notice has to be at or before the use of the ADMT, which means a credit application that the agent will route through an underwriting model has to carry the notice before the application is submitted, not at the adverse-action stage.

The disclosure has to be in plain language at no more than an eighth-grade reading level for the consumer-facing copy and has to be conspicuous at the point of use. The institutions we work with are rendering this from the same disclosure registry that controls the [Regulation B § 1002.9](https://www.consumerfinance.gov/rules-policy/regulations/1002/9/) adverse-action notice and the [Regulation Z § 1026.18](https://www.consumerfinance.gov/rules-policy/regulations/1026/18/) credit-cost disclosures, because a parallel ADMT-only disclosure system that runs separately from the rest of the disclosure stack will eventually drift in language or in timing in ways the Cal AG and the CPPA will catch.

The voice channel is the place the pre-use notice gets compressed in ways the rule does not allow. An AI voice agent that recommends a payment plan based on a hardship model has to render the pre-use notice audibly, at the point of use, in a form the consumer can understand. We script the notice as a short audible disclosure with a callback to a written version the consumer can read at a URL or have texted, and we record the consumer's acknowledgment in the call record. The institutions we work with that ran their California voice deployment with only a written disclosure on a portal page are the institutions whose first CPPA inquiry asked specifically about the voice channel's pre-use compliance.

## The Right to Access ADMT Information

The access right under the final regulations entitles a California consumer to receive information about the business's use of ADMT in a significant decision that concerns the consumer. The disclosable information includes a plain-language description of how the technology was used, the personal information categories the technology processed, the principal parameters the technology used to make the decision, and information about the consumer's right to correct inaccurate personal information used in the decision.

The principal-parameters obligation is the one that takes the longest to operationalize. The institution that has been running an underwriting model whose feature list is locked in a vendor's contract has to renegotiate the contract or extract a parameters disclosure that the institution can repeat to the consumer in plain language. The CPPA staff's posture in the rulemaking comment cycle was that "principal parameters" does not require the institution to expose proprietary model weights, but it does require a substantive description of what the model considered. A response that lists "credit history, income, and other factors" is not, in our read, a substantive description, and it is the kind of response a consumer-advocate complaint will use to seed an enforcement inquiry.

The access right runs on the same timelines as the existing CCPA access right under [Civil Code § 1798.130](https://leginfo.legislature.ca.gov/faces/codes_displaySection.xhtml?lawCode=CIV&sectionNum=1798.130). The institution has forty-five days to respond, with a single forty-five-day extension on notice. The agent that holds the customer surface has to recognize the ADMT-access request and route it to the data-subject-rights queue with the right metadata so the queue can produce a response that covers the ADMT-specific elements rather than the standard CCPA access list. A program that puts ADMT-access requests through the same template as a generic CCPA access response will produce a template that does not address the principal parameters and will, in our experience, generate a complaint that the response was non-responsive.

## The Right to Opt-Out and the Exceptions That Matter

The opt-out right under the regulations allows a California consumer to direct the business not to use ADMT to make a significant decision about them. The right is more limited than its initial drafts suggested. The regulations carry exceptions for security, fraud prevention, safety, and for the provision of a good or service that the consumer specifically requested, and they carry a "human appeal" model for institutions that maintain a meaningful human review process the consumer can invoke instead of opting out of the ADMT in the first instance.

The human-appeal exception is the practical path most banks and lenders will operate under. The exception requires the institution to provide a method by which the consumer can appeal the ADMT-driven decision to a qualified human reviewer who has the authority to overturn the decision and the information necessary to assess it. The reviewer's qualification, authority, and information access are the three operational tests, and a program that routes appeals to a representative whose only option is to confirm the model output fails all three. The CPPA staff has signaled in the rulemaking record that the human-appeal regime will be tested on whether the appeals actually change outcomes at a non-trivial rate, which means the institution has to instrument the appeal process and report on its results internally even if the regulations do not yet require an external filing.

The fraud and security exception is the one institutions will want to lean on, and the leaning has to be earned. The exception applies to the use of ADMT for fraud prevention or for security, not to the use of ADMT for credit underwriting that happens to consider fraud indicators alongside ability-to-repay variables. The institution that runs an underwriting model with a fraud signal as one feature is not using the model for fraud prevention; it is using the model for underwriting and consulting a fraud signal. The exception does not reach that case. The institution that runs a separate fraud-screening model whose output drives a fraud disposition is using the model for fraud prevention and the exception applies. The architectural separation matters more than the model science.

## The Risk Assessment and the Attestation the CPPA Will Read

The regulations require a business that uses ADMT for a significant decision to conduct and document a risk assessment before initiating the use. The assessment has to identify the purpose of the processing, describe the categories of personal information processed, describe the benefits to the business and to the consumer, identify the negative impacts on consumer privacy, and document the safeguards the business has implemented to mitigate the negative impacts. The assessment has to be retained for the duration of the processing plus an additional period the regulations specify, and the business has to be prepared to produce the assessment to the Agency on request.

The regulations also impose an annual attestation obligation. The business has to submit an attestation to the CPPA confirming that the required risk assessments have been conducted and are retained, on the timeline the regulations specify and on the form the Agency will publish. The attestation is signed by a senior officer of the business and carries the standard penalties for false statements. The first attestation cycle aligns with the 2027 compliance turn-on, and the institutions we work with are building the assessment-to-attestation pipeline now so the senior officer signing the first attestation is not signing for a regime that was assembled in the preceding two weeks.

The risk-assessment deliverable for an AI agent is the place the institution's model-risk file and the CPPA's risk-assessment file have to align. We run our customers' [SR 11-7 model-risk file](/blog/model-risk-management-ai-agents-sr-11-7-nist-rmf) and the CCPA risk assessment as two views on the same underlying inventory, with the model-risk file carrying the technical validation work and the CCPA assessment carrying the consumer-impact and rights-mitigation analysis. A program that runs the two as separate documents with separate inventories is a program whose first CPPA inquiry will produce two versions of the same model's risk story with different controls listed.

## The Cybersecurity Audit and the Revenue-Tier Phasing

The cybersecurity audit module of the regulations requires a business that meets the threshold to undergo an annual independent cybersecurity audit, with the audit report retained and made available to the Agency on request. The threshold is tied to revenue and to whether the business processes the personal information of a significant number of California residents. The phasing of the audit obligation runs through 2028 to 2030 depending on the institution's revenue tier, with the largest businesses on the earliest timeline.

For an AI program at a bank, the audit's coverage has to reach the AI surface specifically. The institutions we work with are scoping the audit to include the AI agent's access to personal information, the model-vendor's data handling, the validator and tool-gating controls, the retrieval-grounding architecture, the prompt-injection defenses, the incident-detection telemetry, and the integration with the bank's broader cyber program. A program that scopes the audit to the legacy stack and treats the AI program as out of scope will produce an audit report whose first qualified opinion is on the gap, and the institution will then have to engage a supplemental audit before the next cycle. The cost of running the audit on the AI surface from the first cycle is meaningfully lower than the cost of running it twice.

## How California's Framework Differs from Colorado's

The two state regimes look similar at the descriptive level and diverge in ways that matter when an institution has to build a single program that covers both.

Colorado's SB 26-189 is a disclosure-and-recourse statute enforced by the Colorado Attorney General with no private right of action and no rulemaking authority for an administrative agency to add to it. California's framework is a regulatory regime under a standalone privacy authority with both administrative enforcement and the existing private-right-of-action structure under the CCPA for certain claims, and the CPPA has demonstrated through the rulemaking cycle that it will refine the regulations over time. A program that takes the position that the California regulations are fixed at the November 2025 text is a program whose next revision cycle it will not have prepared for.

Colorado's pre-decision notice runs at the point of interaction. California's pre-use notice runs at or before the use of the ADMT, which can be earlier in the consumer journey than the point of decision. The institution's disclosure infrastructure has to produce both, and the architectures we run treat the California pre-use notice as a layered obligation that fires at the earliest point the ADMT engages with the consumer's personal information.

Colorado's adverse-outcome explanation runs within thirty days of the adverse outcome. California's access right runs within forty-five days of the consumer's request, which can be made at any time, and the California risk-assessment regime adds an upfront documentation obligation Colorado does not carry. The institution that builds two separate disclosure templates will produce two disclosures that disagree in language and in factual detail; the institution that runs one canonical decision-explanation document and renders it to the respective state under each state's timing rules produces a coherent file.

Colorado does not require a senior-officer attestation. California does. The first California attestation cycle is a board-level event for the institutions we work with, and the preparation for it starts a full quarter before the filing window opens.

## The Architecture an AI Agent Program Has to Produce

The program runs against six artifacts, and the agent is the source system for most of them.

The first is the ADMT inventory, which lists every significant-decision use of ADMT in the institution, the personal-information categories each one processes, the principal parameters each one considers, the human review or appeal path each one offers, and the exception (if any) the institution relies on. The inventory updates on each material change and is the spine the risk assessments and the attestation hang off.

The second is the pre-use notice, rendered at the point of use in the channel the consumer is in, with a logged consumer acknowledgment where the channel supports it. The notice library is versioned and the agent renders the current version at the moment the ADMT engages.

The third is the access-response template, which the data-subject-rights queue uses to respond to ADMT-access requests with the four elements the regulations require. The template ties back to the ADMT inventory so the principal-parameters disclosure is the canonical institution position rather than a one-off response.

The fourth is the opt-out flow, with the exception logic built into the routing so a consumer who opts out is routed to the human appeal path or to the alternative provision the exception allows. The flow is logged at the consumer level so the institution can demonstrate it honored the opt-out within the time the regulations allow.

The fifth is the risk assessment, drafted before each ADMT use commences and updated on each material change. The assessment cites the model-risk file's technical validation as the basis for the safeguards section and addresses the consumer-impact analysis in its own voice.

The sixth is the cybersecurity audit's AI scope, prepared in advance of the audit window and including the agent's access surface, the vendor stack, and the controls integrated with the bank's broader cyber program. The audit report is retained on the cycle the regulations require and is the artifact a CPPA inquiry will ask for first.

## The Honest Limit

The regulations are new, the first compliance turn-on is January 1, 2027, and the Agency's enforcement posture will develop through the first cycles. The institutions we work with that are reading the regulations narrowly today and waiting for enforcement to mark the edges are the institutions whose first enforcement letter will be longer than the institutions that took the regulations as written and built against them. There is also genuine ambiguity in the principal-parameters disclosure standard, in the boundary of the fraud-and-security exception when a single model serves multiple purposes, and in the level of specificity the access response has to carry on a model the institution did not build. We are working through each of these with the customers' legal and compliance teams as the rulemaking record and the first enforcement signals develop.

The right way to think about the California framework is the same way we wrote about Colorado: the AI agent on the bank's customer surface is the closest sensor to the decision the regulations care about, and the architecture has to instrument the agent so the disclosure, the access response, the opt-out routing, and the risk-assessment record are produced as a byproduct of normal operation rather than reconstructed from logs at audit time. The institutions whose California program is a separate retrofit are the institutions whose first CPPA inquiry will produce more findings than the inquiry was scoped for. The institutions that built the regulations into the agent's design at the function level will pass the first cycle and use the file from each cycle to refine the controls for the next one.

---

_Source: [https://www.seiright.com/blog/california-cppa-admt-banks-lenders-significant-decisions](https://www.seiright.com/blog/california-cppa-admt-banks-lenders-significant-decisions) · Sei AI_
