Do CCPA ADMT rules require a risk assessment?

The CCPA regulations on automated decision-making technology (ADMT) and risk assessments, finalized by the California Privacy Protection Agency, require businesses to conduct risk assessments for certain high-risk processing and give consumers rights around…

register 09 · Compliance pins· California AI Transparency
01 ·

Answer.

Named jurisdictional law · California AI Transparency.

The CCPA regulations on automated decision-making technology (ADMT) and risk assessments, finalized by the California Privacy Protection Agency, require businesses to conduct risk assessments for certain high-risk processing and give consumers rights around ADMT, with compliance phasing in (key obligations by 2027-01-01). So yes, a risk assessment is required for covered uses. Planisphere supplies behaviour evidence that can feed such an assessment; it does not perform the legal risk assessment or provide legal advice.

Cite-anchor: California AI transparency stack (AB 2013, SB 53/TFAIA, SB 942, CCPA ADMT regs) · Cal. AB 2013 (2024); SB 53 (2025); SB 942 (delayed by AB 853 to 2026-08-02); CPPA ADMT regs (final Sep. 2025)

02 ·

The mark behind the answer.

California AI Transparency is enacted (or near-enacted) law in a specific jurisdiction, with a specific obligation and a…

SB 942 + AB 2013 + SB 53 + CCPA ADMT — the CA frontier/transparency stack.

→ Full reference for California AI Transparency

Try California AI Transparency with a free test key.

Start with the free sandbox. Planisphere measures model behaviour and emits a reproducible, sha-pinned record — it does not certify, file, or give legal advice.

API ·

When California AI Transparency asks for proof, hand over records — not assurances.

record the duty · seal the receipt · verify offline

Planisphere records each duty event — an output marked, a disclosure shown, a review made — and seals it into a receipt that verifies offline against our published keys. You send hashes, never content. A record is evidence a third party can check; it is not a certification and not a legal determination.

On August 2, 2026, EU AI Act Article 50 and California SB 942 both become enforceable — disclosure and provenance duties on two continents, the same day. Article 50(2) marking carries a transitional: systems already on the market get until December 2, 2026. Audit-grade logging follows: Article 12 binds December 2, 2027 (Annex III) and August 2, 2028 (embedded AI).

See how a record is checked · See the ca-sb942 Toolkit →