
California Finalizes Groundbreaking Regulations on AI, Risk Assessments, and Cybersecurity, Part II: What Businesses Need to Know
In July 2025, the California Privacy Protection Agency (CPPA) Board unanimously approved new regulations pursuant to the California Consumer Privacy Act (CCPA) that specifically address the use of automated decisionmaking technologies (ADMTs), requirements for completing risk assessments, and, for businesses processing large amounts of California resident data or engaging in the large-scale sale or sharing of data, mandatory annual cybersecurity audits. While these regulations have been in the drafting process since 2023, they reflect an ongoing trend in California and across the country in favor of heightened, proactive accountability mandates.