Drooid Logo
Back to story perspectives

Full Breakdown

California Implements New AI Risk Assessment Regulations

10/21/2025, 1:05:42 PM

Overview of the New Regulations

California has finalized regulations under the California Consumer Privacy Act (CCPA) that mandate businesses to conduct risk assessments for any processing of personal information that poses a significant risk to consumer privacy. These regulations require businesses to submit detailed information about their risk assessments to the California Privacy Protection Agency (CPPA), including the number of assessments conducted and the time period covered. The first submissions for high-risk activities will be due by April 1, 2028, for the years 2026 and 2027.

Requirements for Risk Assessments

The regulations stipulate that risk assessments must be comprehensive, involving multiple departments within a company, including IT, security, and legal. Each assessment must document the purpose of data processing, categories of personal information involved, potential privacy risks, and the safeguards implemented to mitigate these risks. Businesses are encouraged to integrate these assessments into their existing data governance frameworks and may utilize third-party experts to assist in the process.

Who Must Conduct Risk Assessments?

Businesses that engage in activities such as selling personal information, using sensitive data, or deploying automated decision-making technologies (ADMTs) to make significant decisions about consumers are required to perform risk assessments. This broad definition may encompass a wide range of organizations, including advertising technology firms and data brokers. Assessments must be updated at least once every three years or sooner if there are material changes in processing activities.

Annual Reporting Obligations

In addition to conducting risk assessments, businesses must report their activities to the CPPA annually. Reports will include the business name, contact information, the number of assessments conducted, and an attestation of compliance. While the full text of each assessment is not required, the CPPA may request underlying reports within thirty days of a request.

Criticism and Opposition

Despite the intent to enhance consumer privacy, some critics argue that the regulations could impose significant burdens on businesses, particularly smaller firms that may lack the resources to comply with extensive reporting and assessment requirements. Concerns have also been raised about the potential for these regulations to stifle innovation in the rapidly evolving AI sector.

Verbatim Quotes

  • “These extensive requirements are designed to ensure a thorough evaluation of a project’s privacy impact.” — Ogletree Deakins Cybersecurity and Privacy Practice Group
  • “Conclusion For general counsel and privacy officers, the message is clear: more businesses will soon be required to conduct formal privacy risk assessments for high-risk data processing activities and to report on those activities annually to the Agency.” — Ogletree Deakins Cybersecurity and Privacy Practice Group

Conclusion

California's new regulations represent a significant shift towards proactive privacy management, requiring businesses to take accountability for their data processing activities. As these regulations take effect, companies must prepare for compliance to enhance data governance and consumer trust while navigating the complexities of AI and privacy law.