By Sagar Shankaran, Founder of CallSphere
The CPPA's ADMT, risk-assessment, and cybersecurity-audit regulations took effect January 1, 2026. Pre-use notices, opt-outs, and access rights now reach AI voice and chat agents that touch significant decisions.
Key takeaways
California finalised the ADMT regulations on 23 September 2025 and they took effect 1 January 2026. The risk-assessment clock is already running; the consumer-facing rights flip on 1 January 2027. AI voice and chat that touch a "significant decision" now sit inside the rule.
The California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA), is the foundation. The California Privacy Protection Agency (CPPA) finalised three packages on 23 September 2025: amended CCPA regulations, Automated Decisionmaking Technology (ADMT) rules, risk-assessment rules, and cybersecurity-audit rules. The Office of Administrative Law approved the package; effective date 1 January 2026. Risk-assessment compliance starts immediately for in-scope businesses; ADMT consumer-facing rights — pre-use notice, opt-out, access — go live 1 January 2027.
ADMT means "any technology that processes personal information and uses computation to replace human decision-making or substantially replace human decision-making." The trigger is a "significant decision" — financial or lending services, housing, education, employment, healthcare services. A pre-use notice must precede collection. The consumer can opt out of ADMT for the significant decision (with limited exceptions). The consumer can request access to information about the logic, training data categories, intended use, and how outputs were used. Cybersecurity audits become mandatory for businesses that meet the thresholds, with phased deadlines through 2030. Penalties remain $2,500 per violation, $7,500 per intentional violation or per violation involving a minor.
Hear it before you finish reading
Talk to a live CallSphere AI voice agent in your browser — 60 seconds, no signup.
A voice agent that decides who gets a same-day appointment, prioritises a lead for credit, screens a tenant, or routes a healthcare benefits eligibility check is making — or substantially replacing — a significant decision. From January 2027 the agent must surface a plain-language pre-use notice before processing, host a published opt-out workflow, accept access requests, and document an alternative non-ADMT process. From January 2026, a documented risk assessment must already exist for any qualifying processing. Sensitive personal information continues to trigger right-to-limit obligations. Honor Global Privacy Control signals as a valid opt-out request. Build a 45-day response window for verifiable consumer requests, extendable by 45 more.
CallSphere is HIPAA and SOC 2 aligned with 37 agents, 90+ tools, 115+ DB tables, 6 verticals, and 50+ businesses at 4.8/5. California-facing tenants get an ADMT pre-use notice generator that pulls from each workflow's logic graph; a one-click opt-out path inside the voice and chat agents; an access-request engine that returns logic, input categories, and output mapping in JSON or PDF; and a risk-assessment template aligned to the CPPA's 10 required elements. The audit log captures every inference and tool call to satisfy access-request reconstruction. GPC signals are honored at the website and IVR boundary. Cybersecurity-audit evidence — vulnerability management, access controls, incident response, vendor diligence — is exported on demand. Pricing $149 / $499 / $1,499; 14-day trial; 22% lifetime affiliate at /affiliate; see /pricing; contact /contact; company at /about.
flowchart LR
A[CA Caller] --> B[Voice Agent]
B --> C[Pre-Use Notice]
C --> D[Significant Decision?]
D --> E[Opt-Out Path]
D --> F[Alt Non-ADMT]
B --> G[Risk Assessment]
G --> H[CPPA Audit File]
Are healthcare AI agents always ADMT? If the agent decides who gets a healthcare service, yes. If it only schedules around clinician decisions, often no — but document the boundary.
Does HIPAA carve us out? HIPAA's pre-existing carve-outs for protected health information remain. Non-PHI processing is still in scope; many voice agents process both.
Still reading? Stop comparing — try CallSphere live.
CallSphere ships complete AI voice agents per industry — 14 tools for healthcare, 10 agents for real estate, 4 specialists for salons. See how it actually handles a call before you book a demo.
When do consumer-facing rights start? 1 January 2027 for ADMT rights. Risk assessments are due before processing in 2026.
What counts as opt-out compliance for voice? A clear voice prompt that routes to the alternative non-ADMT process plus a published web/IVR opt-out URL.
Can we charge to honor an access request? No, the first request per 12 months is free; subsequent requests can be charged a reasonable fee.
Written by
Sagar Shankaran· Founder, CallSphere
Sagar Shankaran is the founder of CallSphere, where he builds production AI voice and chat agents deployed across healthcare, hospitality, real estate, and home services. He writes about agentic AI, LLM engineering, and shipping voice agents that handle real calls in production.
See how AI voice agents work for your industry. Live demo available -- no signup required.
A founder's guide to the female voice generator landscape: AI female voices, Japanese voices, robot voices, and how CallSphere ships 57+ voices live.
MOS 4.3+ is the band where AI voice feels human. Drop below 3.6 and conversations break. Here is how to measure, improve, and alert on MOS in production AI voice using G.711, Opus, and the underlying packet loss / jitter / latency math.
The April 5 to May 5 2026 vertical voice AI cycle reset the buyer playbook for SMB and mid-market. Pricing patterns, integration depth, vendor selection, and the build-vs-buy line.
Xai grok voice mode usage limits official: grok 4's voice mode is a credible alternative to ChatGPT Advanced Voice and Gemini Live — here's the latency and feature comparison. Practical context for teams in California.
California MSPs and IT helpdesks: integrate CallSphere's 10-agent voice + chat AI into ConnectWise, Autotask, ServiceNow, or your PSA in 24-72 hours.
California property managers: a smooth integration of CallSphere's after-hours voice + chat escalation system with AppFolio, Buildium, Yardi, and your on-call lad...
© 2026 CallSphere LLC. All rights reserved.