Binding law — not yet in force or stayed
Consumers requesting access to ADMT must receive a plain-language explanation
A California business using automated decisionmaking technology (ADMT) for a significant decision must provide a requesting consumer information about that use. The response must explain the specific purpose, the relevant logic, the outcome and use of the output, and the consumer's other CCPA rights in plain language. Detect an ADMT significant-decision path with no consumer access request mechanism or explanation artifact.
Who it applies to
- Duty falls on: controller
- Systems covered: automated decision, consequential decision
- CCPA-covered businesses using ADMT for significant decisions about California consumers. The ADMT requirements apply from 2027-01-01.
- Whether it applies depends on facts outside the code; a person has to decide.
The guard to add
Store each ADMT decision's purpose, logic, output, and use at decision time, and return them in plain language from a consumer access-request path.
At decision time, write a decision-log row with the purpose, the key factors or reason codes, the model output, how the output was used, the human's role, and the model version. Provide an access-request path (privacy portal endpoint or DSAR export job) that verifies the requester and assembles a plain-language response from those rows using a template that explains the purpose, the logic, the outcome, and the person's other rights. Without decision-time records the access response cannot be reconstructed later, so the logging belongs in the decision service, not in the privacy team's tooling.
Where it goes: 2 data models, 9 AI output handling, 14 user-facing text.
What this provision adds:
- The access response explains in plain language the specific purpose, the relevant logic, the outcome and how the output was used, and the consumer's other CCPA rights.
Example (Python + scikit-learn), before:
score = model.predict_proba([features])[0][1]
applications.update(app_id, status='approved' if score >= 0.6 else 'denied')After:
score = model.predict_proba([features])[0][1]
status = 'approved' if score >= 0.6 else 'denied'
decision_log.insert({'consumer_id': cid, 'purpose': 'credit line eligibility',
'key_factors': reason_codes(features), 'model_output': score,
'how_used': 'scores of 0.6 or more approve; lower scores deny',
'human_role': 'underwriter reviews appeals', 'model_version': MODEL_VERSION})
applications.update(app_id, status=status)Control: Significant-decision ADMT without consumer access explanation. The same guard addresses 1 item with binding law in 1 jurisdiction. Engineering guidance, not legal advice.
Related incidents
No guardrail sits on this exact control; these incidents are cited by guardrails on related controls.
- UnitedHealth nH Predict claim-denial litigation (2023-11; alleged (not proven)). A class action filed in November 2023 alleges that UnitedHealth's nH Predict model had a 90% error rate, measured by denials reversed on appeal, while only about 0.2% of members appealed. UnitedHealth disputes the allegations; the litigation is ongoing. Source: STAT News · evidence grade: primary · cited by Explain adverse AI-assisted decisions and offer a way to contest them — everywhere
Rule id ccpa-admt.access-explanation · review status: primary source derived