Control
Automated decision tech without opt-out
Consumers must be able to opt out of automated decision technology making significant decisions about them.
Informational data, not legal advice. Summaries are TwinEthos's own words and rules have not been reviewed by a lawyer: check the official text before relying on any of it. A guard addresses an item; adding it is not a statement that your code meets any law.
Reach
enacted, not yet applying in California (US-CA); next date 2027-01-01.
The guard to add
Offer an ADMT opt-out (or a qualifying human appeal), store the consumer's choice, and check it before the model runs on any significant-decision path.
Two pieces: an opt-out endpoint linked from the pre-use notice (e.g. POST /privacy/admt-opt-out) that stores a per-consumer admt_opt_out preference, and a check at the top of the server-side decision function that reads that preference and routes opted-out consumers to a human decision-maker without calling the model. Where the business instead relies on a human appeal, the decision response carries an appeal route (POST /decisions/{id}/appeal) to a reviewer who can interpret the model output and overturn the decision. A UI-only toggle that the decision service never reads does not count.
Where it goes: 1 application source code, 2 data models, 9 AI output handling, 14 user-facing text.
What reviewers look for: the stored preference read (if consumer.admt_opt_out, preferences.get('admt_opt_out')) before chat.completions.create or predict on the decision path, an opted-out branch that never calls the model, the opt-out endpoint linked from the notice, or an appeal route whose reviewer has authority to change the outcome.
Example (FastAPI + OpenAI SDK), before:
def decide_tenancy(applicant):
resp = client.chat.completions.create(model=MODEL, messages=tenant_prompt(applicant))
return approve_or_deny(resp.choices[0].message.content)After:
def decide_tenancy(applicant):
if prefs.get(applicant.consumer_id, 'admt_opt_out'):
return route_to_human(applicant, reason='admt_opt_out') # model never runs
resp = client.chat.completions.create(model=MODEL, messages=tenant_prompt(applicant))
return approve_or_deny(resp.choices[0].message.content)
@app.post('/privacy/admt-opt-out')
def admt_opt_out(user=Depends(current_user)):
prefs.set(user.consumer_id, 'admt_opt_out', True)
return {'opted_out': True}Engineering guidance, not legal advice. Each provision below may add its own details (a cadence, a deadline, a required notice element): open it for those.
Upcoming dates
- : Consumers must be able to opt out of automated decision technology (California (US-CA); first application)
Every rule this guard addresses
Binding law — not yet in force or stayed (1)
- California (US-CA)
- Consumers must be able to opt out of automated decision technology 11 CCR 7010(c)-(d) · applies from 2027-01-01