AI governance frameworks: Compare

A learning aid, not legal advice.

Depth, from 0 (least) to 3 (most)0123Under review
Frameworks to compare

Pick two or three frameworks.

Dimension
California CPPA regulations on automated decision-making technology, risk assessments and cybersecurity audits
binding law
Nature
Depth 3 of 3.

Binding regulations adopted by the California Privacy Protection Agency, approved on 2025-09-22, enforceable with civil penalties.

Cal. Code Regs. tit. 11 (approved text)
Where and to whom it applies
Depth 2 of 3.

Businesses subject to the CCPA; the ADMT rules reach technology that replaces or substantially replaces human decision-making in a significant decision about a California consumer.

§ 7001(e); § 7001(ddd)
Roles addressed
Depth 1 of 3.

Duties fall on the business that uses the technology for the significant decision; there is no separate developer role.

§§ 7200 to 7222
Risk approach
Depth 2 of 3.

Triggers rather than tiers: significant decisions for the ADMT rights; six processing activities for risk assessments, including selling or sharing personal information.

§ 7150(b); § 7001(ddd)
Inventory and documentation
Depth 2 of 3.

Risk assessment reports are kept while processing continues or five years, whichever is later; the agency receives counts and an executive attestation.

§ 7155(c); § 7157
Risk or impact assessment
Depth 3 of 3.

A documented risk assessment before starting a triggering activity; activities begun before 2026 need one by 2027-12-31.

§ 7150(b); § 7155(b)
Human oversight
Depth 2 of 3.

Human involvement takes a use outside ADMT only if the reviewer can interpret and analyse the output and has authority to change the decision; a human appeal can replace the opt-out.

§ 7001(e); § 7221
Transparency and notices
Depth 3 of 3.

Pre-use notice (purpose, opt-out, access, how the technology works); opt-out by at least two methods; access requests answered with purpose, logic, outcome and human role.

§§ 7220, 7221, 7222
Data governance
Depth 2 of 3.

Part of the CCPA: notice at collection, purpose limits and consumer rights over personal information apply to the data the technology uses.

Cal. Code Regs. tit. 11 (CCPA regulations)
Testing, robustness and security
Depth 1 of 3.

Separate cybersecurity audit rules apply, phased by revenue from 2028-04-01; no model testing duty was found.

§ 7121(a)
Monitoring and incident reporting
Depth 1 of 3.
Under review
Assurance and enforcement
Depth 3 of 3.

Agency and Attorney General enforcement; administrative fines up to USD 2,663 per violation or 7,988 if intentional or involving minors (2025 adjustment); risk assessment reports on 30 days' request.

Civil Code §§ 1798.155(a), 1798.199.90(a); § 7157(e)
Effort to implement
Depth 2 of 3.

Moderate to heavy: notices, opt-out and access processes, documented risk assessments and an executive attestation.

§§ 7150 to 7157; §§ 7220 to 7222
Key dates
Depth 3 of 3.

Effective 2026-01-01; ADMT duties for existing uses by 2027-01-01; backlog risk assessments by 2027-12-31; first submission to the agency by 2028-04-01.

§ 7200(b); § 7155(b); § 7157(a)(1)

A learning aid, not legal advice. Where AI SENTINEL is mentioned, it supports or maps to the dimension; it does not certify anything. Dates are those the official texts state on the date shown.