California Privacy Protection Agency Releases New AI Regulations
The California Privacy Protection Agency has finalized new regulations under the California Consumer Privacy Act, significantly expanding requirements for businesses and employers handling consumer data and using automated decision-making technology (ADMT).
Effective Jan. 1, 2026, the regulations introduce new mandates around consent, transparency, and data governance. Employers and businesses using ADMT for “significant decisions” — including those related to employment — must provide advance notice, offer opt-out options, and allow individuals to appeal automated outcomes. The rules also establish mandatory risk assessments for high-risk data processing activities and annual cybersecurity audits for companies meeting specific size or data thresholds beginning in 2028. These audits must be conducted by independent professionals and retained for at least five years.
SHRM is closely monitoring the regulations’ implementation and the potential impact on employers that use AI tools for hiring and workforce management. The organization will continue to advocate for clear guidance, regulatory flexibility, and alignment with federal standards to ensure compliance while maintaining practical and effective workplace operations.