AI governance frameworks: Compare
A learning aid, not legal advice.
| Dimension | California CPPA regulations on automated decision-making technology, risk assessments and cybersecurity audits binding law |
|---|---|
| Nature | Depth 3 of 3. Binding regulations adopted by the California Privacy Protection Agency, approved on 2025-09-22, enforceable with civil penalties. Cal. Code Regs. tit. 11 (approved text) |
| Where and to whom it applies | Depth 2 of 3. Businesses subject to the CCPA; the ADMT rules reach technology that replaces or substantially replaces human decision-making in a significant decision about a California consumer. § 7001(e); § 7001(ddd) |
| Roles addressed | Depth 1 of 3. Duties fall on the business that uses the technology for the significant decision; there is no separate developer role. §§ 7200 to 7222 |
| Risk approach | Depth 2 of 3. Triggers rather than tiers: significant decisions for the ADMT rights; six processing activities for risk assessments, including selling or sharing personal information. § 7150(b); § 7001(ddd) |
| Inventory and documentation | Depth 2 of 3. Risk assessment reports are kept while processing continues or five years, whichever is later; the agency receives counts and an executive attestation. § 7155(c); § 7157 |
| Risk or impact assessment | Depth 3 of 3. A documented risk assessment before starting a triggering activity; activities begun before 2026 need one by 2027-12-31. § 7150(b); § 7155(b) |
| Human oversight | Depth 2 of 3. Human involvement takes a use outside ADMT only if the reviewer can interpret and analyse the output and has authority to change the decision; a human appeal can replace the opt-out. § 7001(e); § 7221 |
| Transparency and notices | Depth 3 of 3. Pre-use notice (purpose, opt-out, access, how the technology works); opt-out by at least two methods; access requests answered with purpose, logic, outcome and human role. §§ 7220, 7221, 7222 |
| Data governance | Depth 2 of 3. Part of the CCPA: notice at collection, purpose limits and consumer rights over personal information apply to the data the technology uses. Cal. Code Regs. tit. 11 (CCPA regulations) |
| Testing, robustness and security | Depth 1 of 3. Separate cybersecurity audit rules apply, phased by revenue from 2028-04-01; no model testing duty was found. § 7121(a) |
| Monitoring and incident reporting | Depth 1 of 3. Under review |
| Assurance and enforcement | Depth 3 of 3. Agency and Attorney General enforcement; administrative fines up to USD 2,663 per violation or 7,988 if intentional or involving minors (2025 adjustment); risk assessment reports on 30 days' request. Civil Code §§ 1798.155(a), 1798.199.90(a); § 7157(e) |
| Effort to implement | Depth 2 of 3. Moderate to heavy: notices, opt-out and access processes, documented risk assessments and an executive attestation. §§ 7150 to 7157; §§ 7220 to 7222 |
| Key dates | Depth 3 of 3. Effective 2026-01-01; ADMT duties for existing uses by 2027-01-01; backlog risk assessments by 2027-12-31; first submission to the agency by 2028-04-01. § 7200(b); § 7155(b); § 7157(a)(1) |
A learning aid, not legal advice. Where AI SENTINEL is mentioned, it supports or maps to the dimension; it does not certify anything. Dates are those the official texts state on the date shown.