September 22, 2026
California and Colorado start regulating automated decisions in January 2027
In January 2027, measures passed in California and Colorado take effect, mandating transparency and recourse from companies making automated decisions about people in employment, education, housing, lending, insurance, and healthcare. This post discusses the commitments and carve-outs for companies that need to comply and steps to become compliant.
What the laws require
California's CCPA (Articles 10 and 11) and Colorado's ADMT Act (SB 26-189) take effect January 1, 2027. Both regulate how a company reaches the outcome of a decision about a person. "Decision" here means a "significant" (California) or "consequential" (Colorado) decision: hiring, pay, promotion, termination, and their equivalents in housing, lending, insurance, education, and healthcare. If the outcome of one of those decisions was reached with automation, the person it affects is entitled to: (1) notice of automated decision making, (2) an explanation of how the automated decision was made, and (3) recourse: either an option to opt out or a human appeals process. While similar, these measures differ in implementation. California is request-driven, letting the person request an explanation, review, or opt-out, while Colorado proactively demands an explanation within 30 days for adverse outcomes (denial, termination, or materially worse terms) and does not provide the option to opt out. California applies to companies over a revenue, user, or business threshold and mandates a risk assessment, documentation of the automated process and its risks to privacy, to be filed with the state. Colorado applies to any company making decisions about its residents and requires a three-year data retention period.
When an outcome counts as automated
How do California and Colorado decide whether an outcome was affected by automation? Both laws treat a decision as a sequence of steps: smaller decisions that lead to the outcome. Each step is decided either by a person exercising judgement or by an automated decision-making technology (ADMT): any technology, AI or not, that processes a person's personal information and produces a score, ranking, classification, or prediction that decides or shapes the outcome. California determines if a decision's outcome was automated based on the amount of human involvement. Specifically, it asks if a "qualified human", who (1) knows how to interpret the ADMT results, (2) reviews the results, and (3) has the authority to overturn the result, stood between the ADMT's output and the outcome. If the ADMT "substantially replaced" human decision making, the outcome is automated. Colorado treats any outcome made with an ADMT as automated, regardless of human involvement.
Consider a job application with a thousand applicants and five roles to fill. A common process might include an automated resume screener, an automated video interview, two rounds of human interviews, and a final selection committee. Each step eliminates applicants, so the process is a funnel, and each applicant exits at a different step.
Hover a step to see its numbers and how each state reads it.
Under Colorado law, all thousand applicants are affected by ADMT and the 995 who were rejected are entitled to an explanation and, on request, a human review. Under California, what matters is that the last step in the applicant's journey is a qualified human. Applicants who were eliminated by the resume screener or video interview were affected by ADMT and deserve an explanation and possible recourse. Even if the tools produced scores rather than decisions, the absence of a qualified human makes the outcome automated. Applicants eliminated in the interviews or by the committee, by qualified humans, did not receive an automated decision, and no explanation is owed. Because the process contains automated steps, California still requires a risk assessment, even where the final decision is human.
If people affected by an ADMT are entitled to an explanation, does that mean I am obligated to respond to all applicants? Under Colorado, yes. The law defines an adverse outcome as one that denies, restricts, or reduces a person's selection for an opportunity and requires an explanation even if the result is not communicated to the affected person. In our example, the 995 applicants who were not hired received adverse outcomes, and Colorado's 30-day response window started when the applicant stopped being considered, not if or when a rejection was sent. Under California, no. The explanation is requested by the person, so an applicant who never asks for one is not owed anything beyond the notice of ADMT. However, that notice must include information on how to request an explanation or appeal, and an applicant who asks is entitled to their result. Practically, in both states, leaving the 995 applicants in a "pending" state does not avoid the decision; the decision was made when the software or team stopped considering the applicant.
Who these laws apply to
If you make decisions named in the significant or consequential categories about people in California or Colorado and meet any company threshold, these laws apply to you. California only mandates compliance from for-profit companies that meet any one of: (1) $25M or more in annual revenue (inflation adjusted), (2) personal information of 100,000 or more California residents, or (3) more than half of revenue from selling or sharing personal information. California also drops the recourse requirements for hiring, admissions, allocation of work, and compensation, where the tool is used to assess a person's ability to perform and can show it works for that purpose without discriminating on a protected characteristic. Colorado applies to any company doing business in the state and has no decision-specific exemptions, but the Attorney General can set the bar for recourse. Both states also defer to HIPAA, FERPA, GLBA, and state insurance law for decisions those regimes already govern. The exemption follows the decision, not the company, so employment or pay decisions would still be regulated.
Penalties
If you do nothing, penalties are enforced by the state. California's Privacy Protection Agency and Attorney General can fine $2,663 per violation and $7,988 per intentional violation (inflation adjusted), with each affected person counting separately. Colorado's Attorney General can fine up to $20,000 per violation under the Consumer Protection Act but, through 2029, must first offer a 60-day cure period unless the violation is intentional or repeated.
Your vendor's tool is your obligation
Most of these decisions are made with a vendor's tool, so isn't this the vendor's problem? No. Both laws assign the obligations to your company; vendors are only required to supply data and documentation. Neither state requires vendors to give notice, explanations, hear appeals, or file risk assessments on your behalf. If this applies to your company, you have a little over three months to get ready. List every tool your team uses that scores, ranks, or filters people. Azul connects to applications where hiring, employment, and contracting decisions are made and takes care of notices, explanations, recourse, and risk assessments. If you need help understanding how these regulations map onto your business, .