The California CCPA Regulations (Title 11, Division 6) are the implementing regulations for the California Consumer Privacy Act, promulgated by the California Privacy Protection Agency (CPPA) in 2024 and running 127 pages. They include provisions on automated decision-making technology (ADMT) that bear directly on AI governance, regulating automated processing through privacy law rather than through AI-specific statute.
Background
The California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA), is described in the source as the most comprehensive US state privacy law. The implementing regulations were issued by the California Privacy Protection Agency, the body created to administer and enforce the statute.
Key AI-relevant provisions
The regulations define automated decision-making technology (ADMT) and establish consumer rights around automated processing that produces legal or similarly significant effects. These include a right to opt out of automated decision-making; a right to access information about the logic involved in automated decisions; pre-use notice requirements for ADMT that processes personal information; and risk assessments for ADMT processing.
The regulations also address data minimization and purpose limitation as they relate to AI development. They constrain how personal data can be used for AI training, limit the secondary use of consumer data for model development, and impose transparency requirements on data practices.
Relation to other AI governance approaches
The ADMT provisions operate as a privacy-based approach to AI governance, running in parallel with the safety-based approach of SB 53 and the anti-discrimination approach of the Colorado AI Act. The US Regulatory Approaches Compared page treats the CCPA/CPRA framework as a distinct, privacy-based regulatory approach that governs AI through the lens of personal data processing, alongside safety, discrimination, liability, and preemption approaches.
The ADMT provisions resemble the transparency and human oversight requirements that the EU AI Act applies to high-risk systems, but reach those outcomes through privacy law rather than AI-specific regulation. California Attorney General guidance, summarized in State AG AI Guidances, cites the CCPA as one of the existing laws already governing AI. The regulations are also an instance of state-level rulemaking filling a federal gap, a pattern discussed in Techno-Federalism.
Provenance
Source: California Privacy Protection Agency (CPPA), 2024; 127 pages of implementing regulations. The PDF was converted to markdown on 2026-04-13.