← Back to articles
Governance5 MIN READ

California's AI Decision Rules: What SMBs Must Do Now

California's ADMT rules took effect in 2025 with key deadlines before 2027. If you use software to hire, screen tenants, or score employees, here's what compliance actually requires.

Alex Followell
Alex Followell
2026-07-16 · 5 min read
TL;DR

California's Automated Decisionmaking Technology (ADMT) regulations are already in effect, and businesses that use software to screen applicants, approve tenants, evaluate employees, or score loan candidates now have real compliance obligations. This is not a future concern. The rules finalized in late 2025 require covered businesses to provide notice, offer opt-out rights, and in some cases conduct impact assessments before using ADMT systems. SMBs that rely on off-the-shelf HR, property management, or lending software are likely covered and may not know it yet.

What exactly are California's ADMT rules and who do they cover?

California's Automated Decisionmaking Technology regulations, finalized under the California Privacy Protection Agency in late 2025, apply to any business that uses automated systems to make or substantially influence decisions about people in consequential areas: employment, housing, credit, and education. If your ATS ranks applicants, your property management software scores tenants, or your HR platform flags performance issues, you are likely covered.

The rules do not require that a decision be fully automated. "Substantially influences" is the key phrase. A system that generates a score a human then rubber-stamps almost certainly qualifies. The CPPA has been explicit that the rules are designed to catch exactly that kind of human-in-the-loop-by-name-only setup.

Coverage thresholds matter. Businesses subject to the California Consumer Privacy Act (CCPA) that meet revenue or data-volume thresholds are the primary targets, but the practical reach is broader than most SMB operators assume.

What do the rules actually require businesses to do?

There are three core obligations most SMBs will hit immediately.

1. Pre-use notice. Before deploying ADMT in a covered context, you must inform affected individuals that automated technology is being used and explain the purpose. This has to be plain language, not buried in a privacy policy.

2. Opt-out rights. Individuals generally have the right to opt out of ADMT in employment and housing contexts. You need a working mechanism to receive and honor those requests, and you need a documented process for what happens when someone opts out.

3. Access and correction rights. Affected individuals can request information about how the system works and, in some cases, contest the outcome. This means your vendor needs to be able to explain the logic, not just produce a score.

"If you can't explain how your software made the decision, you cannot legally rely on that decision in California."

For higher-risk uses, including employment decisions affecting more than 100 people, the rules add a fourth obligation: a risk assessment documenting the purpose, data inputs, potential for discrimination, and safeguards in place. This is not a one-time checkbox. Assessments must be reviewed when the system changes.

Which software categories are most likely to trigger compliance?

Here is a practical breakdown of common SMB tools and their ADMT exposure:

| Software Type | Example Use Case | Likely Covered? | |---|---|---| | Applicant Tracking Systems (ATS) | Resume scoring, candidate ranking | Yes | | Property Management Platforms | Tenant screening, credit scoring | Yes | | Performance Management Tools | Employee ratings, PIP triggers | Yes | | Payroll / Scheduling Software | Automated shift assignments | Possibly | | CRM / Sales Tools | Lead scoring (internal only) | Likely no | | Customer Support AI | Chatbots, ticket routing | Likely no |

The risk is concentrated in HR tech, tenant screening, and lending. If your business uses any third-party vendor in these categories, the obligation does not transfer to the vendor. You remain responsible. Vendor contracts need to be reviewed.

What is the 2027 deadline and what happens before it?

The regulations took effect in 2025, which means the notice and opt-out obligations are not theoretical. They are current. The 2027 reference in most coverage relates to full enforcement ramp-up and the phased timeline for risk assessment requirements on covered high-volume uses.

The CPPA has enforcement authority and has signaled it intends to use it. California's privacy enforcement history, including CCPA fines issued against Sephora in 2022 for opt-out violations totaling $1.2 million, suggests regulators are willing to make examples of businesses that treat compliance as optional.

Waiting until 2026 to start is not a safe strategy. Risk assessments for larger operations take time to complete properly, vendor contracts need renegotiating, and internal processes need documentation. SMBs that start now have runway. SMBs that wait do not.

How should a small business actually approach this?

Most SMBs do not have a legal team and are not going to hire a privacy attorney to audit every software tool. Here is a realistic starting point.

First, inventory your tools. Make a list of every software product that touches hiring, performance evaluation, tenant screening, or credit decisions. Include tools that generate scores, rankings, or recommendations, even if a human makes the final call.

Second, ask your vendors direct questions. Can they explain the logic behind scores or rankings? Do they have documentation you can use in a risk assessment? Do they support opt-out workflows? Vendors who cannot answer these questions are a liability.

Third, update your privacy notices. If you are using ADMT in covered contexts, your privacy notice needs to say so before you use the tool, not after someone complains.

Fourth, document everything. Regulators look for good-faith effort. A business with a written inventory, vendor correspondence, and an in-progress assessment is in a materially better position than one with nothing on paper.

This is also a vendor selection issue going forward. If you are evaluating new HR or property management software, ADMT explainability and compliance support should be on your scorecard.

What we'd actually do

  • Run a one-hour software audit this week. Pull your full stack of HR, screening, and evaluation tools and flag every one that generates a score or ranking about a person. That list is your ADMT inventory and your starting point for every other step.
  • Send a written inquiry to each flagged vendor. Ask specifically: does your system qualify as ADMT under California regulations, what documentation do you provide for risk assessments, and how do you support opt-out requests? Their response tells you whether they are a compliance partner or a liability.
  • Draft a plain-language notice for any covered context. Before your next hire or tenant screening cycle, make sure applicants know automated tools are being used. This is the lowest-effort, highest-protection step you can take right now.

If you want to work through your AI governance stack with people who do this with SMBs every day, the AI For Business community at Skool is where we work through exactly these kinds of builds and compliance questions.

FAQ

Does California's ADMT rule apply to my small business if I just use an ATS?

If your applicant tracking system ranks, scores, or filters candidates and your business meets CCPA thresholds (generally over $25 million in annual revenue, or handling data on 100,000-plus consumers), you are likely covered. Even below those thresholds, the notice and opt-out requirements may apply depending on how the tool is used and how many people it affects.

What is a risk assessment under California's ADMT rules and how hard is it to complete?

A risk assessment documents what the system does, what data it uses, where it could produce discriminatory outcomes, and what safeguards are in place. For a straightforward tool with good vendor documentation, a first assessment might take a few days of focused work. For complex or opaque systems, it can take significantly longer, especially if your vendor cannot explain the model.

If we use a third-party vendor for tenant screening, are we still responsible for ADMT compliance?

Yes. Under California's framework, the business deploying the tool bears the compliance obligation, not the software vendor. You need to ensure your vendor can support your obligations, including providing explainability documentation and opt-out mechanisms. Review your vendor contracts and get their compliance commitments in writing.

JOIN THE COMMUNITY

Want this running in your business?

The Skool community is where we show the full builds, share the templates, and help you implement. Three tiers, from team training to fractional AI expert.

  • Weekly Q&A with Alex and Cameron
  • Templates and frameworks you can steal
  • Real builds, running in real businesses
Join skool.com/aiforbusiness