CCPA risk assessments and AI training: the 2026 CPPA regulations
The CPPA's risk assessment, cybersecurity audit and automated decisionmaking regulations took effect January 1, 2026, with some deadlines phased in through 2028. A risk assessment may be needed for activities such as selling personal information or training automated decisionmaking technology, and de-identified scopes can reduce the burden. Counsel confirms what applies.
Do the 2026 CPPA regulations require a risk assessment before AI training?
They can, depending on what the business does with personal information. The California Privacy Protection Agency approved a package on risk assessments, cybersecurity audits and automated decisionmaking technology on September 22, 2025, effective January 1, 2026, with some compliance deadlines phased in from 2027 to 2028, according to the CPPA's regulations index. For a company licensing records, the practical question is whether the delivered data is personal information at all.
The agency's regulations list processing activities that present significant risk and call for a documented risk assessment. The activities most relevant here include selling or sharing personal information and certain uses of automated decisionmaking technology, including training it. Read the current regulation text for the exact triggers, definitions and dates, because details and deadlines were adjusted during rulemaking.
This is general information, not legal, tax or financial advice. Confirm with your own counsel before acting.
What a risk assessment is
A risk assessment is a documented analysis in which a business weighs the benefits of a processing activity against its risks to individuals, and decides whether and how to proceed. Think of it as a written record that the company asked the hard questions first: what is processed, why, who receives it, what harms could arise and what safeguards reduce them.
| Element | Typical content to expect | Who prepares it |
|---|---|---|
| Description of the activity | Purpose, categories of personal information, recipients | Privacy lead or counsel |
| Benefits and risks | Value to the business and potential harms to individuals | Privacy lead with business owner |
| Safeguards | Minimization, de-identification, contractual limits on the buyer | Counsel and security lead |
| Review and updates | Who signs off and when it is revisited | Company leadership |
Which of these the regulations require, and in what form, is set out in the text. The company's counsel owns that reading.
Why scope decisions reduce the burden
If a licensed scope contains no personal information of California residents, or contains only properly de-identified records, the triggers tied to selling or sharing personal information may not apply. That is why SourceX agrees de-identification and redaction rules with the company before any work begins, and why data is delivered only after an executed agreement and the company's authorization.
Do not read that as an exemption. A scope has to be de-identified in substance, and the legal test lives in the statute. The sale definition is covered in is licensing company records a sale under the CCPA. Employee records have their own coverage, explained in the employee data exemption guide.
How does the GDPR compare for companies with EU data?
Companies that hold personal data about people in the EU may face a different regime, which has its own data protection impact assessment concept. A company with EU data may therefore owe a separate analysis, and whether the GDPR reaches a US company at all is a question for counsel. Treat the two as parallel obligations, not substitutes, and ask counsel whether the company has EU data subjects at all. For the AI-regulation side, see whether the EU AI Act applies to a US company that licenses data.
Which records usually trigger the question?
Not every record set raises it. Sort the inventory before the legal discussion.
| Record set | Why it may raise the question | Common scoping response |
|---|---|---|
| CRM contacts and deal notes | Names and business contact details of California residents | De-identify, or exclude contact fields and keep outcomes |
| Support tickets and chat transcripts | Customer identifiers and free-text personal details | Redact identifiers before delivery |
| Call recordings and transcripts | Voices, statements and payment details | Transcribe, redact, or leave out of scope. See PCI DSS and call recordings |
| Finance and operations records | Mostly company data, limited personal fields | Usually lower concern, still reviewed |
| Engineering records | Developer names and email addresses in commits | Remove identifiers, keep structure |
An inventory that labels each set this way lets counsel spend time on the few sets that matter instead of the whole archive.
What the regulations do not change
The updated regulations sit on top of the existing rules, they do not replace them. The company must still keep its privacy promises, honor client confidentiality terms and respect recording consent laws. A risk assessment is documentation of a decision, not permission to proceed. If the analysis shows risks that safeguards cannot reduce, the right answer may be to exclude the record set. Nothing is binding until the company agrees price and terms and signs, so there is room to adjust scope as the review develops.
Timeline checkpoints for a company
| When | What to do |
|---|---|
| Before qualification | Confirm whether the company is a covered business and has California residents' data |
| During the data inventory | Mark record sets containing personal information, sensitive fields and call recordings |
| Before scope is final | Counsel decides whether a risk assessment is needed for any retained personal information |
| Before delivery | Confirm de-identification rules were applied and the agreement restricts re-identification |
| Annually | Review whether regulations, deadlines or processing activities have changed |
Call recordings need special care. See whether a recording notice covers AI training. Background on the category of material is in what AI training data is.
What a partner needs to know
Your role is unchanged: introduce, give basic fit information, and leave records alone. Candidates still need 50+ full-time employees at peak (contractors excluded), years of documented operations, rights to license and an authorized sponsor. When an owner asks about risk assessments, say these three things.
- The rules were updated in 2026, so the company should ask counsel about its own situation.
- Scope and de-identification decisions are made with the company before any work begins.
- Nothing is binding until the company agrees price and terms and signs.
Cybersecurity audits and automated decisionmaking
The same package covers cybersecurity audits and automated decisionmaking technology, so a company reading the regulations will meet those topics too. They are separate obligations from a risk assessment, with their own triggers and phased deadlines. A company that only licenses historical records may not be affected by every part, but its counsel should read the whole package rather than one section, and should note the 2027 to 2028 compliance dates listed by the agency.
Questions for counsel
- Is the company a covered business under the CCPA?
- Would any retained records be personal information of California residents?
- Which regulation triggers and deadlines apply, as the current text reads?
- Who will document any required assessment, and who signs off?
- Does the company also hold EU personal data?
Next step
If a company you know is ready to discuss licensing with counsel in the room, register as a partner and make the introduction, or run the company fit checker first. The how it works page lays out the stages. No reward is guaranteed; it is paid only after the buyer pays and SourceX receives its fee.
- Step 1Share your linkSend your personal link to a company you know.
- Step 2Company appliesThe company applies itself at /apply.
- Step 3Buyer selects and paysThe buyer selects and pays for the data and SourceX receives its fee.
- Step 4You get your rewardYour share of SourceX fees becomes payable.
Common questions
When do the CPPA risk assessment regulations take effect?
The CPPA lists the package on risk assessments, cybersecurity audits and automated decisionmaking technology as effective January 1, 2026, with some compliance deadlines phased in from 2027 to 2028. Dates can change and details are in the regulation text, so the company's counsel should confirm the schedule that applies.
Does licensing de-identified records trigger a risk assessment?
That depends on whether the delivered records are personal information and on the regulation's triggers. A properly de-identified scope may avoid triggers tied to selling or sharing personal information, but the legal test is in the statute and regulations. Counsel decides, and de-identification rules are agreed before any work begins.
Is a CCPA risk assessment the same as a GDPR DPIA?
They are related ideas but separate legal obligations with different triggers, content and regulators. A company with both California and EU personal data may need to consider each regime on its own terms. Counsel should map which obligations attach to which record sets.
Does the company have to file the assessment with the agency?
Do not assume either way. Reporting and submission requirements are set by the regulation text and may include phased deadlines. Ask counsel to read the current provisions. The partner's role is only to mention that the topic exists and refer the sponsor to the company's own advisers.
Does this apply to companies outside California?
Only if they are covered businesses handling California residents' personal information. A company without California operations or California residents' data may fall outside the CCPA, though other laws and its own contracts can apply. Counsel checks coverage record set by record set.
Related pages
- CCPA employee data exemption expired: what it means for licensing workplace records
- PCI DSS and call recordings: how to remove card data before licensing
- How SourceX US company data referrals work
- What is AI training data?
- Does the EU AI Act apply to a US company that licenses data?
- Is licensing company records a 'sale' under the CCPA?
Free resources
- Earnout scenario calculator — Probability-weighted earnout value and its present value.
- Profit margin calculator — Profit and margin across three scenarios.
- Client opportunity brief generator — An editable intro email, summary and checklist.
- All free tools · MCP resource center
By SourceX Partnerships Team · Published 2026-10-09 · Updated 2026-10-09
Know a US company with valuable proprietary data?
Become a referral partner from anywhere we support, get your link and introduce an owner or authorized decision-maker.
Refer a company →I own a business
Explore licensing your company's data to AI developers worldwide. Start a short assessment; no uploads needed.
Start an assessment