Home About Who We Are Team Services Startups Businesses Enterprise Case Studies Industries Commercial Real Estate Blog Guides Contact Connect with Us
Back to Guides
Legal Services 14 min read

Preparing for California's 2027 Automated Decisionmaking Rules Without an HR Department

Preparing for California's 2027 Automated Decisionmaking Rules Without an HR Department

California’s next AI-and-employment rule has a hard date: January 1, 2027. That’s when the California Privacy Protection Agency’s automated decisionmaking technology (ADMT) regulations require businesses that use software to make “significant decisions” about people, including hiring, pay, promotion, and firing, to give notice before using the tool, let people opt out or appeal, and have already completed a documented risk assessment. Here’s the part most legal alerts skip: a large share of 5-50 person California businesses won’t be covered by this specific rule, because it only reaches companies that clear a separate, unrelated privacy-law revenue or data-volume threshold. This guide covers how to find out where your business stands, what changes if you are covered, and the concrete steps an owner or office manager can take now without hiring a compliance officer.

What changes on January 1, 2027

The CPPA finalized its ADMT regulations on September 22, 2025, when the Office of Administrative Law approved the text and filed it with the Secretary of State. The regulation text became generally effective January 1, 2026, but the consumer- and employee-facing obligations (pre-use notice, opt-out, and access to information about an ADMT decision) carry a later compliance date: January 1, 2027, for any business already using ADMT for a significant decision before that date. A business that starts using a covered tool after January 1, 2027 must comply from day one, with no grace period.

“Significant decisions” is the operative term. The regulation lists seven employment categories: hiring, allocation of work or assignment, compensation, promotion, demotion, suspension, and termination. Advertising decisions are explicitly out of scope, and so is a plain grammar or spell-check tool, which the regulation names as an example of something that doesn’t count as ADMT at all.

Does the ADMT rule even apply to your business?

Before spending an hour on ADMT-specific compliance, check whether your business meets the underlying CCPA threshold, because the ADMT rules only reach businesses the CCPA already treats as a “business.” As of the CPPA’s most recent inflation adjustment (effective January 1, 2025), that means meeting at least one of:

  • Annual gross revenue above $26,625,000 (adjusted yearly for inflation from the original $25 million statutory figure; recheck the current number on cppa.ca.gov before relying on it)
  • Buying, selling, or sharing the personal information of 100,000 or more California consumers, households, or devices a year (this counts unique identifiers like cookies and device IDs, not just named customers)
  • Deriving 50% or more of annual revenue from selling or sharing personal information

A 5-50 person business with no consumer data business and no ad-tech or data-broker component almost certainly clears none of these three tests today. If that’s your business, the January 1, 2027 ADMT rule isn’t currently something you have to comply with. That doesn’t mean ignore it: growth, an acquisition, or a new product line that starts collecting consumer data (not just employee data) can put a growing business over the line, and the threshold resets each year against the prior calendar year’s numbers. Put a once-a-year reminder on the calendar, around when you close your books, to re-run this test. For a fuller walkthrough of the same threshold test, including edge cases like data handled through a payroll or scheduling vendor, see Does the CCPA Apply to My Small Business?

The rule almost every small employer already has to follow

This is where coverage of “California’s 2027 AI rules” causes the most confusion, because it isn’t the only rule in play, and it isn’t the one most small businesses need to worry about first. California’s Civil Rights Council finalized a separate set of regulations under the Fair Employment and Housing Act that took effect October 1, 2025 (covered in full in what changed for small employers that day). Those rules apply to any California employer with five or more employees, full stop, no revenue or data-volume threshold. If a business uses an automated tool, a resume screener, a scheduling algorithm, a personality-test scoring system, in hiring, promotion, or discipline, the Civil Rights Council’s rules already require recordkeeping on that automated-decision data for at least four years and hold the employer responsible for a discriminatory outcome even when a third-party vendor built and operates the tool.

The honest summary for a 5-50 person business is close to the reverse of what most headlines imply: the October 2025 civil-rights rules almost certainly already apply if you have five or more employees and use any automated hiring or performance tool, while the January 1, 2027 CPPA privacy rules probably don’t apply yet unless your business is unusually large for its headcount or handles an unusual volume of consumer data. Treat these as two separate obligations on two separate clocks, not one law with one deadline.

What counts as automated decisionmaking technology, and what doesn’t

The CPPA defines ADMT as technology that processes personal information and uses computation to replace, or substantially replace, human decision-making. In an employment setting, that reaches application-screening software, performance-analytics dashboards, productivity-monitoring tools, and any system that scores, ranks, or recommends outcomes for hiring, scheduling, compensation, or termination.

It explicitly excludes a tool that simply corrects spelling or grammar. That distinction matters for how your team uses AI day to day: an employee using ChatGPT, Claude, or Microsoft Copilot to draft a job posting, summarize a review someone else wrote, or clean up an email isn’t using ADMT. A tool that independently scores resumes, ranks candidates, or flags an employee for discipline based on a productivity metric is much closer to what the regulation targets, especially if nobody meaningfully reviews the output before it drives the decision.

The human-review test that can keep a tool out of scope

A tool that could technically make a significant decision doesn’t automatically count as ADMT if a human meaningfully reviews the output first. The regulation’s “meaningful human involvement” standard has three parts, and a business needs all three, not just one, to rely on it:

  1. Authority. The reviewer has the actual power to override the output, not just the title to do so.
  2. Competence. The reviewer understands, at a working level, the logic the tool used, not just the final score.
  3. Review. The reviewer actively examines the logic and other relevant information, not only the bottom-line result.

Employment-law alerts have been blunt that a manager glancing at an AI-generated shortlist and clicking approve, “checking the box”, doesn’t satisfy this test. Keeping a tool out of ADMT scope means the review step has to be a real, documented habit: a hiring manager who can explain why a candidate was ranked where they were, not just confirm that a ranking exists.

The three obligations that start January 1, 2027

For a covered business, three obligations begin on that date for any ADMT already in use, and immediately for anything adopted afterward:

  1. Pre-use notice. A plain-language notice, given before the tool is used to make a significant decision, describing what the ADMT does, why it’s used, and the person’s rights to opt out, access information about the decision, or appeal it.
  2. Opt-out rights. At least two methods for a covered person to opt out of ADMT use in their significant decision, unless a specific exception applies (certain fraud-prevention or security uses, for example).
  3. Access rights. A process to respond to a request for information about how the ADMT reached a decision affecting the requester.

None of these require a dedicated software platform. For a small employer, the realistic version of “pre-use notice” is a short, plain-English paragraph added to the job application or employee handbook describing which tools are in use and how to ask a human to review a decision instead. The compliance bar here is honesty and documentation, not enterprise tooling.

Risk assessments: what they are and when they’re due

A risk assessment documents whether the benefit of using a given ADMT outweighs its risk to the people it affects: what data goes in, what the tool is used for, and what safeguards exist. The deadline depends on when the processing started:

  • Already using a given ADMT before January 1, 2026? The risk assessment for that use is due no later than December 31, 2027.
  • Starting a new ADMT on or after January 1, 2026? The risk assessment needs to be completed before you start using it, no later fixed date applies.
  • Completing risk assessments during 2026 or 2027 also means submitting a short attestation and summary to the CPPA by April 1, 2028, and annually after that.

A separate, later obligation almost certainly won’t apply here: cybersecurity audits, phased in by revenue from 2028 through 2030 with their own $25 million-plus threshold. Worth knowing it exists so it isn’t confused with the risk-assessment deadline above.

A realistic prep timeline for a business with no compliance staff

None of this requires a general counsel or a privacy platform subscription:

  1. Now: Run the three-part CCPA threshold test and write down the answer and the date checked. Meeting none of the three means ADMT-specific prep is done for this year; keep the note and revisit annually.
  2. Now, regardless of the answer: List every tool used in hiring, scheduling, performance review, or discipline that produces a score or ranking, not just a document draft. For most 5-50 person businesses this list is short: an applicant-tracking system, a scheduling tool, maybe a background-check vendor’s risk score.
  3. Within the quarter: For each tool, confirm who reviews its output before a decision is made, and whether that person could explain the logic if asked. “Nobody reviews it” is the gap to close first, for the October 2025 rules that already apply and for ADMT if covered.
  4. If covered by the CCPA threshold: Draft the plain-language notice paragraph and add it to onboarding materials and the handbook well before January 1, 2027.
  5. If covered and a scoring tool started after January 1, 2026: Complete its risk assessment before continuing to use it; December 2027 only applies to tools already in use before 2026.
  6. Ongoing: Ask each vendor whether their tool has been tested for bias and whether the contract addresses liability if it produces a discriminatory outcome. Both rule sets hold the employer responsible even when a vendor operates the tool.

How this connects to AI training

Almost none of the above requires new software. It requires knowing which existing tools score or rank people, having someone who can explain those scores, and writing down a short, honest notice. Training fits upstream of all of it: a team that understands the difference between using ChatGPT, Claude, or Copilot to draft a job posting (not ADMT) and relying on an automated ranking to make the hiring call (potentially ADMT, already covered by the October 2025 rules either way) makes fewer compliance mistakes than a team improvising tool by tool.

Hands-on AI training applied to a team’s own documents and workflows is often reimbursable through California’s ETP Small Business Program, separate from any compliance costs here. Delivery format depends on where the team is based; see the corporate AI training guide for the relevant city. Market rates for a facilitated workshop run $2,000-$15,000, and are included on larger engagements when paired with a broader automation project.

For the fuller picture of how AI training, ETP funding, and California’s employment rules fit together, the California AI training playbook and the Los Angeles corporate AI training guide cover the funding mechanics and delivery details this article doesn’t repeat.

Businesses that want to see whether their own hiring and performance tools would count as ADMT, and where training fits into getting ready, can book a free AI-readiness call or start with the Team Training overview.

Frequently Asked Questions

Does the CPPA’s January 1, 2027 ADMT rule apply to a business with fewer than 50 employees?

Not automatically. Coverage depends on CCPA revenue and data-volume thresholds, not employee count: roughly $26.6 million in annual gross revenue (adjusts yearly; check cppa.ca.gov), 100,000+ consumers’/households’/devices’ personal information bought, sold, or shared a year, or 50%+ of revenue from selling or sharing personal information. Most small employers meet none of the three.

If the 2027 rule doesn’t apply to my business, am I off the hook for AI hiring rules?

No. The Civil Rights Council’s separate automated-decision-system regulations under FEHA took effect October 1, 2025 and apply to any California employer with five or more employees, no revenue test. An automated hiring, promotion, or discipline tool likely already falls under that rule regardless of the CCPA threshold answer.

What is a “significant decision” under the ADMT regulations?

One of seven defined employment categories: hiring, allocation of work or assignment, compensation, promotion, demotion, suspension, or termination. Advertising decisions are explicitly excluded.

Does using ChatGPT or Claude to write a job description count as ADMT?

No. The regulation targets tools that replace or substantially replace a human decision about a person, not drafting assistance, and explicitly excludes tools that simply correct spelling or grammar. A tool that independently ranks or scores candidates or employees is a different matter.

What does “meaningful human involvement” mean?

The three-part test, authority to override, competence to understand the tool’s logic, and active review of that logic rather than just the output, that can keep a tool out of ADMT scope. A manager who reviews and can explain a ranking meets it; one who approves a shortlist without reviewing the reasoning, “checking the box,” does not.

When exactly is a risk assessment due?

For ADMT already in use before January 1, 2026: by December 31, 2027. For ADMT starting on or after January 1, 2026: before that use begins. Assessments completed in 2026 or 2027 also require a short attestation and summary to the CPPA by April 1, 2028.

Do cybersecurity audits apply to a small business too?

Almost certainly not. Those obligations phase in by prior-year revenue from 2028 through 2030, with their own $25 million-plus-data-volume threshold well above a 5-50 person business.

If a vendor’s software makes the hiring decision, is the vendor responsible instead of my business?

No. Both the October 2025 rules and the CPPA’s ADMT framework place the compliance and liability burden on the employer using the tool. A short vendor questionnaire about bias testing, data use, and contract liability language is a reasonable, low-effort way to manage that exposure.

Was there a California law requiring notice before using AI at work?

Almost. SB 7, the “No Robo Bosses Act,” would have added notice and restriction requirements ahead of the CPPA’s own timeline. Governor Newsom vetoed it on October 13, 2025, citing overly broad restrictions. A revised version is expected to be reintroduced, so this is worth rechecking.

What’s the single most useful thing a 5-50 person business can do this year?

Run the CCPA threshold test, then list every tool touching hiring, scheduling, or performance review that produces a score or ranking rather than just a document. Those two steps show which rule, if either, applies, and exactly where the human-review gap needs closing first.

Last Updated: Sep 15, 2026

DJ

Dirk Jan van Veen, PhD

SFAI Labs helps companies build AI-powered products that work. We focus on practical solutions, not hype.

Make your team fluent in AI — then automate what proves out

  • Hands-on training applied to your own documents and workflows
  • Reimbursable for many California small businesses through ETP
  • Built for 5–50 person firms with no IT department

Related articles