US State AI & Privacy Laws

CCPA / CPRA

California Consumer Privacy Act of 2018, as amended by the California Privacy Rights Act of 2020

California's privacy law, the strictest in the US, now reaches AI directly: prompts containing personal information count as disclosures, AI vendors can lose service-provider status, and the CPPA's ADMT regulations phase in through January 1, 2027.

California, United StatesIn force; CPRA amendments effective January 1, 2023; ADMT, risk assessment, and cybersecurity audit regulations approved September 2025, phasing in through 2027 and beyondVerified 2026-08-31

What it means for AI and data privacy

The CCPA, as amended by the CPRA, is the broadest US state privacy law, and it treats data flowing into AI tools the same way it treats any other disclosure of personal information: sending a customer's or employee's data to an external AI service is a disclosure, and depending on the vendor's terms it can be a sale or sharing that triggers opt-out rights. An AI vendor is only a service provider if its contract restricts use of the data; a vendor that trains its models on customer data steps outside that role and becomes a third party, with all the notice and opt-out consequences that follow. Since January 1, 2023 the law fully covers employee and job-applicant data, so HR records pasted into a chatbot are in scope. The CPPA's regulations on automated decision-making technology (ADMT), risk assessments, and cybersecurity audits were approved in September 2025 and took effect January 1, 2026, with ADMT compliance required by January 1, 2027 and first risk-assessment submissions due by April 1, 2028. For most organizations the immediate exposure is not a sanctioned AI project but unsanctioned use: personal information leaving in employee prompts to tools the business never vetted, contracted with, or disclosed.

Who it applies to

  • For-profit businesses doing business in California above the thresholds: over $25M annual revenue, or personal information of 100,000+ consumers or households, or 50%+ of revenue from selling or sharing personal information
  • Employers in scope for California employees, contractors, and job applicants, whose data has been fully covered since January 1, 2023
  • Businesses using ADMT to make significant decisions about consumers, which must meet the CPPA's ADMT requirements by January 1, 2027
  • AI vendors processing personal information for California businesses, whose contracts determine service-provider versus third-party status
  • Out-of-state and Canadian companies serving California residents at scale

Enforcement and penalties

The CPPA and the California Attorney General can seek administrative fines or civil penalties of $2,500 per violation, rising to $7,500 for intentional violations or violations involving minors' data, with each affected consumer potentially a separate violation; the CPRA removed the old 30-day cure right. The private right of action is limited to data breaches caused by failure to maintain reasonable security, with statutory damages of $100 to $750 per consumer per incident. Enforcement is active: the agency and AG have pursued sale/sharing violations, deficient vendor contracts, and dark patterns, and IBM's 2025 breach research found shadow AI involvement added an average of $670K to breach costs, on top of any penalties.

Key provisions for AI and data privacy

Cal. Civ. Code § 1798.140(ah), (ad): "sharing" and "sale"

Personal information entering AI tools as a sale, sharing, or disclosure

The law defines sale and sharing broadly: any transfer of personal information to another business for monetary or other valuable consideration, or for cross-context behavioral advertising. Disclosures to properly contracted service providers are carved out; disclosures to everyone else are not.

A prompt containing a customer's name, account details, or health information sent to an external AI tool is a disclosure of personal information, full stop. If the tool's terms let the provider use that data to improve its models, the transfer looks like a sale or sharing the business never disclosed and offered no opt-out for. LayerX found in 2025 that 71% of GenAI connections happen through personal, non-corporate accounts, where no negotiated terms protect the data at all.

Cal. Civ. Code § 1798.140(ag); CCPA Regs §§ 7050-7051

Service provider vs third party: the contract and the training clause

An AI vendor is a service provider only under a written contract that limits processing to specified business purposes and bars it from selling, sharing, or using the data outside the contract. The regulations are explicit that a provider using personal information to train its own models beyond the customer's purposes is not acting as a service provider.

This is the clause that decides whether your AI stack is compliant. An enterprise AI agreement with a no-training commitment can keep the vendor a service provider; a consumer-tier chatbot with default data retention cannot, which makes every employee prompt to it a disclosure to a third party. Gartner found in 2026 that 88% of employees with enterprise AI access also use personal AI tools, meaning even organizations that bought compliant AI still leak through non-compliant channels.

CCPA Regulations, ADMT rules (approved Sept. 2025)

Automated decision-making technology: notice, opt-out, and access

The CPPA's ADMT regulations, adopted July 24, 2025 and approved by the Office of Administrative Law on September 22, 2025, require businesses using ADMT for significant decisions (employment, lending, housing, education, health care access and similar) to provide pre-use notice, honor opt-out rights in most cases, and explain outcomes on request. Businesses must comply with the ADMT requirements by January 1, 2027.

If AI materially shapes decisions about hiring, compensation, lending, or access to services, California residents must be told beforehand and can generally opt out. Informal AI use inside those workflows, a recruiter screening resumes through a chatbot, breaks the notice obligation before it is even written, because the business does not know the ADMT exists. The compliance clock to January 1, 2027 starts with an honest inventory of where AI already touches significant decisions.

CCPA Regulations, risk assessments (Art. 10, §§ 7150 et seq.)

Risk assessments for high-risk processing, including AI and ADMT

Businesses must conduct and document risk assessments before processing that presents significant risk to privacy, including using ADMT for significant decisions, processing sensitive personal information, and using personal information to train ADMT or facial recognition. The requirements took effect January 1, 2026, with the first submissions to the CPPA due by April 1, 2028.

An assessment must weigh what personal information flows into AI, for what purpose, and with what safeguards. It cannot be done credibly while the organization is blind to actual usage, and IBM found in 2025 that 63% of organizations have no AI governance policy and only 17% have technical controls that redact or block sensitive data at the point of entry. Documented point-of-entry controls are exactly the kind of safeguard the assessment format asks you to show.

Former § 1798.145(m)-(n) exemptions, expired Jan. 1, 2023

Employee and B2B data fully covered

The temporary exemptions for employee, job-applicant, and business-contact data expired on January 1, 2023. California workers now hold the full set of rights: notice, access, deletion, correction, and limits on sensitive personal information.

HR is one of the heaviest informal AI use cases: drafting reviews, summarizing complaints, comparing candidates. Every one of those prompts can carry employee personal information that the employee can now demand access to or deletion of. A business cannot delete personal information it pushed into an external AI tool with no deletion mechanism, so the only reliable position is keeping identifiers out of prompts in the first place.

Practical compliance steps

  1. 1Map where personal information can enter AI tools: sanctioned products, embedded AI features, and employee browser usage the business has never vetted
  2. 2Reclassify every AI vendor as service provider or third party based on its actual contract terms, and demand written no-training commitments where they are missing
  3. 3Update privacy notices to cover AI-related disclosures, and honor opt-outs of sale and sharing where AI transfers do not qualify for the service-provider carve-out
  4. 4Inventory ADMT used in significant decisions and build the pre-use notices, opt-outs, and access responses required by January 1, 2027
  5. 5Conduct and document risk assessments for AI processing of personal information, ready for CPPA submission by April 1, 2028
  6. 6Deploy a point-of-entry control that redacts personal information from prompts before it reaches external AI tools, covering employee and applicant data as well as customer data
  7. 7Train employees that HR and customer records are fully in scope, and monitor for shadow AI usage rather than assuming policy is followed

How Sanitized AI maps to this

Sale and sharing (§ 1798.140)

Personal information is redacted from prompts before submission, so what reaches external AI tools no longer identifies a consumer, cutting off the unintended disclosures that create sale and sharing exposure.

Service-provider discipline (§§ 7050-7051)

Administrators see which AI tools employees actually use, so the business can spot data flowing to vendors with no service-provider contract and steer usage toward the tools it has papered properly.

Risk assessments (Art. 10)

Interception dashboards show which categories of personal and sensitive information were caught in prompts and how often, giving risk assessments documented evidence of both the risk and the safeguard.

Employee data rights

Redaction of names, identifiers, and contact details in prompts keeps HR and applicant records out of tools that offer no deletion path, preserving the business's ability to honor access and deletion requests.

Frequently asked questions

Is pasting customer data into ChatGPT a CCPA violation?

It can be. Sending personal information to an external AI tool is a disclosure under the CCPA. If the tool is not under a service-provider contract with the business (a personal or free-tier account never is), the transfer can amount to an undisclosed sale or sharing, and it undermines the business's ability to honor access and deletion requests for that data. The violation risk sits with the business, not the employee.

Does using an AI vendor count as selling or sharing personal information?

Not if the vendor is a proper service provider: a written contract limiting processing to your business purposes, with no use of the data for its own model training. If the vendor can use the data beyond your purposes, California's regulator treats it as a third party, and transfers to it need to be disclosed with opt-out rights. The contract terms, not the marketing, decide.

What are the CPPA's ADMT regulations and when do they apply?

They are rules under the CCPA governing automated decision-making technology used for significant decisions about consumers, adopted by the CPPA board on July 24, 2025 and approved that September. The regulations took effect January 1, 2026, and businesses using ADMT for significant decisions must comply with the notice, opt-out, and access requirements by January 1, 2027. Related risk-assessment rules apply now, with first submissions to the CPPA due by April 1, 2028.

Does the CCPA apply to employee data in AI tools?

Yes. The employee and applicant exemptions expired January 1, 2023, so California workers have full CCPA rights over their personal information. Performance reviews, complaints, salaries, and resumes pasted into external AI tools are disclosures of covered data, and the employer remains responsible for honoring access and deletion requests it may no longer be able to fulfill.

What are the penalties for CCPA violations involving AI?

Administrative fines or civil penalties of $2,500 per violation, or $7,500 for intentional violations or those involving minors' personal information, enforced by the CPPA and the California Attorney General, with each affected consumer potentially counted separately. Consumers can sue directly only over data breaches tied to unreasonable security, at $100 to $750 per consumer per incident. There is no longer a guaranteed cure period.

Do employees using personal AI accounts create CCPA risk for the company?

Yes, and it is the dominant pattern. LayerX measured in 2025 that 71% of GenAI connections use personal, non-corporate accounts, and Gartner found in 2026 that 88% of employees with enterprise AI access also use personal AI tools. Data disclosed through those accounts sits outside every contract the business signed, which is precisely what turns a routine prompt into an unauthorized disclosure.

Primary sources

This guide summarizes the cited primary sources as of the verification date. It is general information, not legal advice.

The gap in every framework is the prompt box.

Sanitized AI catches sensitive data in prompts before it leaves and shows administrators which AI tools employees actually use.

Get a demo

Related standards