Cal. Civ. Code § 1798.140(ah), (ad): "sharing" and "sale"
Personal information entering AI tools as a sale, sharing, or disclosure
The law defines sale and sharing broadly: any transfer of personal information to another business for monetary or other valuable consideration, or for cross-context behavioral advertising. Disclosures to properly contracted service providers are carved out; disclosures to everyone else are not.
A prompt containing a customer's name, account details, or health information sent to an external AI tool is a disclosure of personal information, full stop. If the tool's terms let the provider use that data to improve its models, the transfer looks like a sale or sharing the business never disclosed and offered no opt-out for. LayerX found in 2025 that 71% of GenAI connections happen through personal, non-corporate accounts, where no negotiated terms protect the data at all.
Cal. Civ. Code § 1798.140(ag); CCPA Regs §§ 7050-7051
Service provider vs third party: the contract and the training clause
An AI vendor is a service provider only under a written contract that limits processing to specified business purposes and bars it from selling, sharing, or using the data outside the contract. The regulations are explicit that a provider using personal information to train its own models beyond the customer's purposes is not acting as a service provider.
This is the clause that decides whether your AI stack is compliant. An enterprise AI agreement with a no-training commitment can keep the vendor a service provider; a consumer-tier chatbot with default data retention cannot, which makes every employee prompt to it a disclosure to a third party. Gartner found in 2026 that 88% of employees with enterprise AI access also use personal AI tools, meaning even organizations that bought compliant AI still leak through non-compliant channels.
CCPA Regulations, ADMT rules (approved Sept. 2025)
Automated decision-making technology: notice, opt-out, and access
The CPPA's ADMT regulations, adopted July 24, 2025 and approved by the Office of Administrative Law on September 22, 2025, require businesses using ADMT for significant decisions (employment, lending, housing, education, health care access and similar) to provide pre-use notice, honor opt-out rights in most cases, and explain outcomes on request. Businesses must comply with the ADMT requirements by January 1, 2027.
If AI materially shapes decisions about hiring, compensation, lending, or access to services, California residents must be told beforehand and can generally opt out. Informal AI use inside those workflows, a recruiter screening resumes through a chatbot, breaks the notice obligation before it is even written, because the business does not know the ADMT exists. The compliance clock to January 1, 2027 starts with an honest inventory of where AI already touches significant decisions.
CCPA Regulations, risk assessments (Art. 10, §§ 7150 et seq.)
Risk assessments for high-risk processing, including AI and ADMT
Businesses must conduct and document risk assessments before processing that presents significant risk to privacy, including using ADMT for significant decisions, processing sensitive personal information, and using personal information to train ADMT or facial recognition. The requirements took effect January 1, 2026, with the first submissions to the CPPA due by April 1, 2028.
An assessment must weigh what personal information flows into AI, for what purpose, and with what safeguards. It cannot be done credibly while the organization is blind to actual usage, and IBM found in 2025 that 63% of organizations have no AI governance policy and only 17% have technical controls that redact or block sensitive data at the point of entry. Documented point-of-entry controls are exactly the kind of safeguard the assessment format asks you to show.
Former § 1798.145(m)-(n) exemptions, expired Jan. 1, 2023
Employee and B2B data fully covered
The temporary exemptions for employee, job-applicant, and business-contact data expired on January 1, 2023. California workers now hold the full set of rights: notice, access, deletion, correction, and limits on sensitive personal information.
HR is one of the heaviest informal AI use cases: drafting reviews, summarizing complaints, comparing candidates. Every one of those prompts can carry employee personal information that the employee can now demand access to or deletion of. A business cannot delete personal information it pushed into an external AI tool with no deletion mechanism, so the only reliable position is keeping identifiers out of prompts in the first place.