Menu
SaaS5 min read

California's ADMT Rules Start January 1, 2027: What AI-Powered B2B SaaS Must Ship

California's CCPA regulations on automated decisionmaking technology apply from January 1, 2027 to businesses using ADMT for significant decisions in employment, lending, housing, education, and healthcare. Your customers carry the obligations, but they will need your product to support notices, opt-outs, explanations, appeals, and risk assessments.

Umair Abbas

Umair Abbas

  • SaaS
  • AI
  • Privacy
  • CCPA
  • Compliance
California's ADMT Rules Start January 1, 2027: What AI-Powered B2B SaaS Must Ship — cover illustration
X LinkedIn

If your product uses AI or scoring to help customers decide who gets hired, approved for credit, offered housing, admitted, or given access to healthcare services, a California deadline is about twelve weeks away. The California Privacy Protection Agency's regulations on automated decisionmaking technology, known as ADMT, were approved in September 2025 and took effect January 1, 2026. Businesses that use ADMT to make significant decisions must comply with the ADMT requirements beginning January 1, 2027. Most B2B SaaS vendors are not the "business" making those decisions. Their customers are. That does not make this someone else's problem. Customers will need features to comply, and they will ask vendors for them in renewals and procurement.

What counts as ADMT and a significant decision

In plain terms, ADMT covers technology that processes personal information and uses computation to replace, or substantially replace, human decision-making. A significant decision is one that results in the provision or denial of financial or lending services, housing, education enrollment or opportunities, employment or independent contracting opportunities or compensation, or healthcare services. According to a summary by Thompson Coburn, targeted advertising alone is not a significant decision. That covers a lot of B2B software: applicant screening and ranking in HR tech, underwriting and fraud tools in fintech, tenant screening in proptech, admissions tools in edtech, and eligibility or triage tools in healthcare.

What businesses must do

Based on the final regulations and practitioner summaries, a business using ADMT for significant decisions needs to provide a pre-use notice explaining the purpose, the categories of data used, and consumers' rights; offer an opt-out unless an exception applies, with exceptions including one built around a qualified human appeal; respond to access requests with information about how the ADMT was used and the logic involved; and conduct a risk assessment before using ADMT for significant decisions. ADMT already in use before January 1, 2027 must be compliant by that date, and new ADMT must comply before first use. Separately, risk assessment summaries and attestations are due to the agency starting April 1, 2028.

Features your customers will ask for

Notice templates and placement. Configurable pre-use notices that appear where the decision begins, such as an application form, with customer-editable text and a record of which version each person saw. Opt-out and human review routing. A way to route a person's case to human decision-making when they opt out, with queues, assignments, and service levels. Explanations from logs. Per-decision records of the inputs used, the model or rules version, the output, and any human override, so customers can answer access requests without engineering tickets. Appeals. A workflow for a person to contest a decision and for a qualified reviewer, with authority to change the outcome, to resolve it. Risk assessment support. Documentation of your model's purpose, data, logic, known limitations, testing for bias, and safeguards, written so a customer's privacy team can drop it into their own assessment.

json
{
  "decision_id": "dec_7f3a",
  "tenant_id": "acme-hr",
  "decision_type": "employment.screening",
  "subject_ref": "cand_1192",
  "notice_version": "admt-notice-v3",
  "model_version": "screen-2026-09-30",
  "inputs_used": ["resume.skills", "assessment.score"],
  "output": { "recommendation": "advance", "score": 0.71 },
  "human_review": { "required": true, "reviewer": "usr_88", "final": "advance" },
  "opt_out": false,
  "created_at": "2026-10-08T09:30:00Z"
}

Design choices that reduce scope

Some products can stay further from the definition by design. If your AI ranks or summarizes, but a person reviews every case and makes the call, document that workflow and make it the default. Avoid features that auto-reject without review in significant-decision contexts unless your customer explicitly enables them and understands the consequences. These are product decisions with legal effects, so make them with counsel, not just in sprint planning.

Start with a gap assessment

List every place your product scores, ranks, filters, or recommends people in the five significant-decision areas. For each, note whether a human makes the final decision, what data is used, and whether you log enough to explain it. That list becomes your roadmap, and a version of it makes a strong answer to the questionnaires already arriving.

Update contracts and documentation

Expect customers to update data processing agreements to cover ADMT. Be ready to describe what your system does, what data it uses, how you test for unfair outcomes, how customers configure human review, and how long decision logs are retained. Keep that documentation versioned with your models so it stays accurate after each release. A clear, current model fact sheet saves weeks in procurement for every customer in a regulated area.

California is not the only jurisdiction

Other jurisdictions are writing rules for automated decisions too, and many customers operate nationally or internationally. Building logging, notice, review, and appeal capabilities once, configurable by customer and region, is cheaper than bolting on a new feature for each law. Treat California's January date as the first milestone of a broader capability, not a one-off compliance project.

Test for unfair outcomes before customers ask

Risk assessments ask businesses to weigh potential harms, including unlawful discrimination, and to describe safeguards. Customers will look to vendors for evidence. Run regular evaluations of your models on representative data, document what you measured and what you changed as a result, and make those summaries available under NDA. If you cannot yet test for a protected characteristic directly, explain the proxies and limits honestly. Clear, modest documentation is more credible than broad claims of fairness, and it gives a customer's privacy team material they can actually use.

Founder takeaway

January 1, 2027 is close. If your product touches hiring, lending, housing, education, or healthcare decisions, map where automation influences outcomes, ship per-decision logging, add configurable notices, opt-out routing, and appeal workflows, and package model documentation your customers can reuse. Compliance support is becoming a buying criterion, and early movers will win renewals on it.

Related Articles

More on This Topic

  • CRA Reporting Is Live: What SaaS Companies That Ship Apps, Agents, and SDKs Must Do — cover illustration

    SaaS

    CRA Reporting Is Live: What SaaS Companies That Ship Apps, Agents, and SDKs Must Do

    Since September 11, 2026, manufacturers of products with digital elements sold in the EU must report actively exploited vulnerabilities and severe incidents through ENISA's Single Reporting Platform within 24 hours. Pure SaaS is mostly out of scope, but the mobile apps, desktop agents, CLIs, and SDKs many SaaS companies ship are not.

    Read article
  • EU Data Act Switching Rules: SaaS Exit Readiness Before Switching Charges End in January 2027 — cover illustration

    SaaS

    EU Data Act Switching Rules: SaaS Exit Readiness Before Switching Charges End in January 2027

    From January 12, 2027, the EU Data Act bans switching charges, including data egress fees, for data processing services, and SaaS is in scope. A founder guide to the contract clauses, export tooling, and offboarding workflow your product needs now.

    Read article
  • Seat Pricing Is Dying: Usage and Outcome Pricing for AI SaaS — cover illustration

    SaaS

    Seat Pricing Is Dying: Usage and Outcome Pricing for AI SaaS

    AI consumption costs break classic seat packaging. Here is how founders design hybrid seat+usage and outcome pricing without inventing margin fairy tales.

    Read article

Ready to build something powerful?

Tell us what you are building. We will respond within 24 hours with a clear, honest assessment — no pressure, no sales pitch.

NDA protected · Reply within 24 hours · No commitment required