Answer
What does California require when AI makes a decision about someone?
Notice before use, a route to opt out, and an explanation afterwards. The trigger is the decision, not the technology.
A pre-use notice, an opt-out route with limited exceptions, and a right to information about how the decision was made. It applies where automation substantially replaces human judgement in significant decisions.
California's privacy regulator finalised rules for automated decisionmaking technology, with compliance for businesses using it in significant decisions required from January 2027. Two definitions carry the whole thing. Automated decisionmaking technology means technology that processes personal information and uses computation to replace or substantially replace human decisionmaking. A significant decision is one affecting a person's finances, housing, education, employment or health care — and advertising is specifically excluded.
The second definition is where businesses misjudge their position, usually in the direction of assuming they are outside it. Employment is a significant decision, and that reaches hiring, promotion, discipline, allocation of work and termination. A business does not have to be running a model to be in scope; a ranking, a filter, or a rule applied automatically to a candidate pool can substantially replace the human decision, and informality is not an exemption. The correct question is not what the tool is called but whether a person would otherwise have been exercising the judgement it now exercises.
The obligations themselves are procedural and each has an operational cost. A pre-use notice has to reach the person before the technology is used on them, which means it belongs in the application flow rather than in a privacy policy. An opt-out has to be offered, subject to exceptions where a business meets defined conditions, which means there has to be an alternative path that actually exists and produces a decision. And an access right lets the person ask for information about how the technology was used in their case, which means the business has to be able to answer.
That last one is where most implementations fail, because the answer has to be constructed rather than retrieved. Being able to explain the use in a specific person's case requires knowing which version of which system processed them, on what inputs, and what it output — a record almost nobody keeps by default. It has to be designed in before the decisions start, and retrofitting it to decisions already made is not possible.
The threshold question comes first and is easily answered. The underlying privacy statute reaches businesses meeting one of several tests: annual gross revenue above twenty-five million dollars, buying, selling or sharing the personal information of a hundred thousand or more consumers or households, or deriving the majority of revenue from selling or sharing personal information. Below all three, none of this applies — and a business that assumes it is covered because it operates in California can spend a great deal on obligations it does not have.
Separately and often confused with it, California has required since well before any of this that a bot not mislead a person about being artificial in certain commercial and electoral communications. That is a disclosure obligation about identity, not about decisions, and it applies to businesses regardless of the revenue thresholds above. A business dealing with California consumers should treat the two as unrelated: one asks whether the person knew they were talking to a machine, the other asks whether a machine decided something about them.
The rules do not ask how sophisticated the system is. They ask whether a person's judgement was replaced, and a spreadsheet rule can answer yes.
Siddharth Sharma, Context Theory
Related questions
Does a human reviewing the output take us out of scope?
Only if the review is a decision rather than a ratification. The definition turns on whether computation replaces or substantially replaces human decisionmaking, so a reviewer who sees the underlying facts and reaches their own conclusion is deciding, while one who approves a recommendation in nearly every case is not — and the approval rate is visible in the system. Designing the review to be real is both the compliance answer and the reason to have a human there.
What about risk assessments?
They run on their own schedule and are a separate obligation from the notice and opt-out, with documentation ultimately submitted to the regulator. The practical significance for a business making a build decision now is that the assessment is easier to complete for a system whose inputs, outputs and logic were documented as it was built, and close to impossible for one adopted without any of that.
METHOD
Every figure below carries its source and the date it was verified. Nothing on this page is asserted.
The numbers on this page.
| What | Value | Specific to |
|---|---|---|
| SMB marketing spend as a share of gross revenue | 3–5% | Category-wide |
| Realistic monthly lead-gen software spend | $1,500–$5,000 | Category-wide |
2026 SMB marketing budget survey · a $1M business ≈ $2,500–$4,200/mo · verified
2026 real estate operating cost survey · plus $1,000–$8,000 variable · verified
What is specific to this page.
| Kind | Claim | Check it against |
|---|---|---|
| Regulation | California's rules define automated decisionmaking technology as technology processing personal information that uses computation to replace or substantially replace human decisionmaking, and limit the obligations to significant decisions about finances, housing, education, employment or health care. | The automated decisionmaking articles of the California Consumer Privacy Act regulations finalised by the state privacy agency. |
| Constraint | The obligations are a pre-use notice reaching the individual before the technology is applied to them, an opt-out subject to defined exceptions, and a right to information about how the technology was used in that person's own case. | The notice, opt-out and access provisions of the automated decisionmaking rules, checked against where the business's notice currently appears. |
| Software | Answering an individual access request about an automated decision requires knowing which version of which system processed that person, on what inputs, and what it produced, which is a record almost no deployment keeps by default and cannot be reconstructed later. | Attempting to answer, for one past decision, which model version and inputs produced it, using only records the business already holds. |
| Procurement | The underlying statute reaches businesses above a revenue test, above a consumer or household volume test, or deriving the majority of revenue from selling or sharing personal information, so a business below all three has no obligations here at all. | The applicability thresholds of the California Consumer Privacy Act, applied to the business's own revenue and processing volumes. |
Each row would be wrong on another industry's page. Where a sourced figure exists it is in the table above instead; these are the constraints that shape the work and do not happen to be numbers.
Start with the measurement.
Reading about a benchmark is not the same as knowing your own number. The audit produces yours, measured rather than estimated.
$497 · delivered in 5 business days · credited against month one