RatedWithAI

RatedWithAI

Accessibility scanner

Privacy LawJuly 25, 2026

CCPA Risk Assessment Requirement for AI 2026: What Businesses Must Document Now

Most California privacy programs are built around consumer-facing mechanics — notices, opt-out links, deletion requests. The CPPA's risk assessment rules are different: they require internal documentation, written before the processing happens, for a set of AI activities that companies have been running for years without writing anything down.

Jan 1, 2026
Triggering activities from this date forward need assessments
3 years
Maximum interval before an assessment must be reviewed and updated
On request
Full assessments must be produced to the CPPA or Attorney General

The Filing Deadline Is Not the Compliance Deadline

The most expensive mistake here is a calendar error. Teams see a submission date well out in the future and schedule the work accordingly. But the obligation attaches to the processing, not the filing: activities conducted from the start of 2026 forward require a completed assessment, and the later submission simply reports on them.

A business that starts this work when the filing date approaches is reconstructing a year or more of assessments from memory, for models that have since been retrained and vendors that have since been swapped. Regulators read backdated documentation exactly the way you would expect them to.

Which AI Activities Trigger an Assessment

Assessment Required
  • ADMT used for a significant decision (credit, housing, employment, healthcare, essential services)
  • Training an ADMT or AI model on personal information
  • Training a model capable of identity verification or physical/biological identification
  • Processing sensitive personal information
  • Selling or sharing personal information
  • Automated processing to infer characteristics from work, school, or public-space monitoring
Generally Outside
  • Purely internal analytics on de-identified aggregate data
  • Spell-check, formatting, and non-evaluative productivity AI
  • Security and fraud monitoring within the narrow permitted-purpose carve-outs
  • Vendor tooling that never receives personal information

What Has to Be In the Document

A compliant assessment is not a one-page memo. It has to identify the specific processing purpose, the categories of personal information involved, the operational elements including retention periods and the technology used, the parties with access, the benefits to the business and to consumers, and the negative impacts to consumer privacy — then explain the safeguards and articulate why the benefits are not outweighed by the risks. Where automated decisionmaking is involved, it also has to describe the logic, including key parameters, and the consumer's opt-out and appeal mechanics.

That last piece is where AI-heavy businesses stall. "Describe the logic and key parameters" is straightforward for a rules engine and genuinely hard for an ensemble model touched by three vendors. Solving it requires model documentation your data science team may never have produced, which is why this belongs on an engineering roadmap and not only a legal one.

Reusing a GDPR DPIA Without Getting Burned

The regulations expressly allow leveraging an assessment prepared for another jurisdiction, provided it satisfies every California-specific content element. In practice that means keeping the DPIA as the base narrative and bolting on a California addendum covering the elements a DPIA typically lacks: the ADMT logic description, the opt-out and appeal path, the explicit benefits-versus-negative-impacts weighing framed under the CCPA standard, and the identity of the individuals who prepared and approved it. Submitting a European document unaltered is the fastest way to convert a defensible program into a finding.

Risk Assessment Readiness Checklist

Do This Now

  • Inventory every model and automated system touching California personal information
  • Flag which ones inform significant decisions about consumers
  • Identify any model trained on sensitive personal information
  • Confirm whether any activity constitutes selling or sharing

Build Before Filing

  • A template covering every required content element, not a generic DPIA
  • Model documentation good enough to describe logic and key parameters
  • Named preparer and approver for each assessment
  • A material-change trigger tied to retraining and new data sources
  • Retention and retrieval process for producing assessments on request

Frequently Asked Questions

Which AI activities trigger a CCPA risk assessment?

Using automated decisionmaking technology for a significant decision, training an ADMT or AI model on personal information, training a model capable of identity verification, processing sensitive personal information, and selling or sharing personal information.

When does the obligation actually start?

It attaches to the processing, not the filing. Triggering activities conducted from January 1, 2026 forward require completed assessments; the CPPA submission comes later and reports on them. Starting at the filing date means backdating a year of documentation.

Is our GDPR DPIA enough?

Only as a foundation. The regulations allow reuse if the document meets all California-specific content elements — which usually requires a California addendum covering ADMT logic, opt-out mechanics, and the benefits-versus-impacts weighing under the CCPA standard.

Do we submit the whole assessment to the CPPA?

No. Routine submission is a summary and attestation. The full assessment is retained and produced to the CPPA or Attorney General on request, so it has to be written for regulator review rather than internal box-checking.

How often must assessments be updated?

At least every three years, and immediately on any material change — new model, new data source, new decision informed, new vendor. Retraining on a materially different dataset is the trigger teams most often miss.

We're a small SaaS company. Does the CCPA even apply to us?

Check the thresholds before assuming it doesn't. The revenue threshold is one route in, but so is buying, selling, or sharing the personal information of 100,000 or more California consumers or households — a bar that consumer-facing apps and adtech-heavy products clear more easily than their revenue suggests.

The Inventory Is the Hard Part

Writing one risk assessment is a week of work. Knowing which forty systems need one is a quarter of work, and it's the step that determines whether the program holds up. Start the inventory now so the assessments describe processing as it happens rather than as someone remembers it.

While you're mapping consumer-facing systems, check what your public site exposes. Run a free compliance scan to see how your pages hold up.