TL;DR: Sending personal data to an AI API counts as sharing under CPRA, triggering opt-out rights. The CPPA finalized automated decision-making regulations covering employment, credit, and other significant decisions. If you use AI tools with California resident data and exceed CCPA thresholds, you need vendor DPAs, opt-out mechanisms, ADMT notices, and training data disclosures.
Most small teams that use AI tools are sharing personal data with third parties, whether they think of it that way or not. Every call to an AI API that includes a user message, a customer record, or an employee file is a disclosure of personal information. If any of those individuals are California residents, CCPA and CPRA apply.
This guide covers what California's privacy law actually requires for AI tool use in 2026, focusing on the obligations most likely to affect organizations that use AI rather than build it.
CCPA and CPRA: the framework in brief
The California Consumer Privacy Act (CCPA) took effect in 2020 and gave California residents rights over their personal information: the right to know what data is collected, the right to delete it, and the right to opt out of its sale. The California Privacy Rights Act (CPRA) amended CCPA significantly, with its changes taking effect January 1, 2023. CPRA added the right to correct inaccurate data, expanded opt-out rights to cover "sharing" (not just selling), created the sensitive personal information category, and established the California Privacy Protection Agency (CPPA) as an independent enforcement authority alongside the Attorney General.
For 2026, the operative framework is CPRA-as-amended. When this guide says "CCPA," it means the current law including all CPRA amendments.
The thresholds for coverage: annual gross revenue over $25 million, buying/selling/sharing personal information of 100,000 or more California residents annually, or deriving 50% or more of revenue from selling personal information. Organizations below all three thresholds have no CCPA obligations, though they may still have obligations under other state laws.
How AI tools trigger CCPA obligations
The most common way organizations accidentally incur CCPA obligations through AI tool use is the "sharing" trigger.
Under CPRA, sharing personal information means disclosing it to a third party for cross-context behavioral advertising. But the disclosure obligation is broader: any time you send personal data to a third party, that is a disclosure that must be described in your privacy policy, and California residents are entitled to know about it.
When your customer service team runs a customer complaint through an AI summarization tool, that customer's personal information is disclosed to the AI vendor. When your HR team uses an AI screening tool to review job applications, applicant data goes to the AI vendor. When your sales team runs meeting recordings through an AI transcription service, customer names, companies, and conversation content move to a third-party system.
None of this is prohibited. But it requires:
- Disclosure in your privacy policy that you use AI tools and what categories of data they process
- A data processing agreement (DPA) or equivalent contractual protection with the AI vendor
- Verification that the AI vendor does not use your data to train its models (unless you have explicitly consented and disclosed this to users)
- An opt-out mechanism if the disclosure constitutes sharing for advertising purposes
The privacy-first AI APIs that don't train on your data guide covers which major AI vendors offer no-training defaults and what contract terms to look for.
Automated decision-making technology (ADMT) rules
The CPPA finalized its automated decision-making technology (ADMT) regulations, which represent the most significant new AI-specific obligations under California law.
ADMT is defined broadly: technology that processes personal information to make a decision, or to facilitate human decision-making, about a consumer. This covers scoring systems, ranking tools, filtering algorithms, and AI-assisted decision support tools.
The regulations create three rights for California residents:
Right to access. Consumers can request information about what ADMT was used to make decisions about them, what personal information was used, how the system works at a general level, and what the outcome was.
Right to opt out. Consumers can opt out of ADMT used for significant decisions affecting them. Significant decisions include: employment (hiring, promotion, termination, compensation, performance evaluation), education (admissions, financial aid, academic evaluation), housing, credit, health care, and insurance. If you use an AI tool to help rank job applicants, screen resumes, or score employee performance, those California residents have the right to opt out.
Right to human review. For ADMT used in significant decisions, consumers can request that a human review the decision. The business must have a process for this review and must respond to requests.
Businesses must also conduct a pre-deployment risk assessment before using ADMT for covered significant decisions. The assessment must document the purpose of the ADMT, the personal information used, the likely impact on consumers, and the safeguards in place.
For small teams, the most immediate ADMT obligation is usually the opt-out mechanism. If you use an AI hiring tool, your job application process needs to include notice that ADMT is used and a way for applicants to opt out or request human review.
Training data and CCPA obligations
Using California residents' personal information to train an AI model creates specific CCPA obligations.
If your organization trains or fine-tunes AI models using data that includes California resident personal information, that use must be disclosed in your privacy policy. California residents have the right to request deletion of their personal information, and under most circumstances you must honor those requests even if the data has been used for training. Technically, deleting training data and retraining a model is often impractical, and the law allows for some exceptions around technical feasibility, but the obligation to respond to deletion requests remains.
More commonly, small teams are not training their own models. But they may unknowingly allow AI vendors to use their data for training by accepting default terms. Most major AI API providers (Anthropic, OpenAI Enterprise, Azure OpenAI, Google Vertex AI) do not train on customer data by default, but consumer-tier products often do. If your team uses a consumer AI tool and sends California resident data through it, check the terms carefully.
If an AI vendor is using your submitted data to train its models, that should be disclosed to your California users. If it involves sensitive personal information, explicit consent may be required.
Sensitive personal information and AI tools
CPRA's sensitive personal information (SPI) category creates heightened obligations for specific data types, and many AI tools routinely process SPI.
SPI includes: government ID numbers, financial account credentials, precise geolocation, racial or ethnic origin, religious or philosophical beliefs, union membership, personal communications (email and text content not directed to the business), health condition and diagnosis, sex life or sexual orientation, and biometric data used for identification.
Common AI tool use cases that touch SPI:
- Meeting transcription tools may capture health conversations, personal communications, or financial details discussed in calls
- HR AI tools may process biometric data if they include facial recognition or voice identification
- Customer service AI may handle financial account information or health data
- AI writing assistants given access to email may process personal communications
California residents have the right to direct businesses to limit the use and disclosure of their SPI to what is necessary to provide requested services. If your site collects SPI, you need a visible link titled "Limit the Use of My Sensitive Personal Information" that allows residents to exercise this right.
For AI tools that process SPI, document what SPI categories flow into each tool, confirm the vendor has appropriate contractual restrictions on SPI use, and include SPI categories in your privacy policy's data inventory.
Practical compliance checklist for small teams
This checklist covers the AI-specific CCPA obligations most likely to apply to organizations using, rather than building, AI tools.
Threshold check
- Determine whether your organization meets CCPA thresholds (revenue, volume of California residents, revenue from data sales)
- If below all thresholds, document this determination annually
Privacy policy
- List all AI tools used and what categories of personal information they receive
- Disclose if any AI vendor uses submitted data for model training
- Include the "Limit the Use of My Sensitive Personal Information" link if any AI tool processes SPI
- Add an opt-out mechanism for ADMT used in significant decisions (employment, credit, housing, health care)
Vendor contracts
- Obtain a data processing agreement or service provider agreement with each AI vendor
- Confirm the AI vendor will not use your data to train models (or document your disclosure if they do)
- Verify the AI vendor honors consumer deletion requests that you pass through
ADMT compliance
- Identify any AI tools used to make or facilitate significant decisions (hiring, performance, credit)
- Add ADMT notice to workflows where these tools are used (job applications, credit applications)
- Create a process for responding to opt-out and human review requests
- Complete a pre-deployment risk assessment for any new ADMT used for significant decisions
Data inventory
- Document what SPI categories flow into each AI tool
- Verify each tool's data retention and deletion practices
The AI vendor evaluation checklist covers the due diligence questions to ask before selecting an AI tool, including CCPA-relevant questions about training data use and data residency.
Enforcement in 2026
The CPPA handles rulemaking and can initiate investigations and enforcement. The California Attorney General retains concurrent enforcement authority. There is no private right of action for most CCPA violations, but there is a limited private right of action for data breaches involving personal information that is not encrypted or redacted.
The CPPA has been actively investigating companies across sectors and has issued enforcement notices for violations of consumer rights obligations, privacy notice requirements, and opt-out mechanisms. Fines are $2,500 per unintentional violation and $7,500 per intentional violation, with each affected consumer potentially counting as a separate violation.
For practical guidance on privacy-first AI tool selection, the AI data privacy for small teams guide covers how to build a privacy-respecting AI stack. For a vendor-by-vendor comparison of how major AI providers handle data under GDPR and CCPA, see Anthropic vs OpenAI GDPR compliance.
Related Reading
- Privacy-first AI APIs: which don't train on your data (GDPR and CCPA, 2026)
- AI data privacy for small teams: GDPR and CCPA
- Anthropic vs OpenAI GDPR compliance 2026
- AI meeting transcription: data leak and compliance risks
- GDPR AI fines 2026: enforcement cases and what small teams must know
- GDPR-compliant AI assistants comparison 2026
- AI vendor evaluation checklist
