CCPA risk assessments and AI training: the 2026 CPPA regulations

The CPPA's risk assessment, cybersecurity audit and automated decisionmaking regulations took effect January 1, 2026, with some deadlines phased in through 2028. A risk assessment may be needed for activities such as selling personal information or training automated decisionmaking technology, and de-identified scopes can reduce the burden. Counsel confirms what applies.

Do the 2026 CPPA regulations require a risk assessment before AI training?

They can, depending on what the business does with personal information. The California Privacy Protection Agency approved a package on risk assessments, cybersecurity audits and automated decisionmaking technology on September 22, 2025, effective January 1, 2026, with some compliance deadlines phased in from 2027 to 2028, according to the CPPA's regulations index. For a company licensing records, the practical question is whether the delivered data is personal information at all.

The agency's regulations list processing activities that present significant risk and call for a documented risk assessment. The activities most relevant here include selling or sharing personal information and certain uses of automated decisionmaking technology, including training it. Read the current regulation text for the exact triggers, definitions and dates, because details and deadlines were adjusted during rulemaking.

This is general information, not legal, tax or financial advice. Confirm with your own counsel before acting.

What a risk assessment is

A risk assessment is a documented analysis in which a business weighs the benefits of a processing activity against its risks to individuals, and decides whether and how to proceed. Think of it as a written record that the company asked the hard questions first: what is processed, why, who receives it, what harms could arise and what safeguards reduce them.

ElementTypical content to expectWho prepares it
Description of the activityPurpose, categories of personal information, recipientsPrivacy lead or counsel
Benefits and risksValue to the business and potential harms to individualsPrivacy lead with business owner
SafeguardsMinimization, de-identification, contractual limits on the buyerCounsel and security lead
Review and updatesWho signs off and when it is revisitedCompany leadership

Which of these the regulations require, and in what form, is set out in the text. The company's counsel owns that reading.

Why scope decisions reduce the burden

If a licensed scope contains no personal information of California residents, or contains only properly de-identified records, the triggers tied to selling or sharing personal information may not apply. That is why SourceX agrees de-identification and redaction rules with the company before any work begins, and why data is delivered only after an executed agreement and the company's authorization.

Do not read that as an exemption. A scope has to be de-identified in substance, and the legal test lives in the statute. The sale definition is covered in is licensing company records a sale under the CCPA. Employee records have their own coverage, explained in the employee data exemption guide.

How does the GDPR compare for companies with EU data?

Companies that hold personal data about people in the EU may face a different regime, which has its own data protection impact assessment concept. A company with EU data may therefore owe a separate analysis, and whether the GDPR reaches a US company at all is a question for counsel. Treat the two as parallel obligations, not substitutes, and ask counsel whether the company has EU data subjects at all. For the AI-regulation side, see whether the EU AI Act applies to a US company that licenses data.

Which records usually trigger the question?

Not every record set raises it. Sort the inventory before the legal discussion.

Record setWhy it may raise the questionCommon scoping response
CRM contacts and deal notesNames and business contact details of California residentsDe-identify, or exclude contact fields and keep outcomes
Support tickets and chat transcriptsCustomer identifiers and free-text personal detailsRedact identifiers before delivery
Call recordings and transcriptsVoices, statements and payment detailsTranscribe, redact, or leave out of scope. See PCI DSS and call recordings
Finance and operations recordsMostly company data, limited personal fieldsUsually lower concern, still reviewed
Engineering recordsDeveloper names and email addresses in commitsRemove identifiers, keep structure

An inventory that labels each set this way lets counsel spend time on the few sets that matter instead of the whole archive.

What the regulations do not change

The updated regulations sit on top of the existing rules, they do not replace them. The company must still keep its privacy promises, honor client confidentiality terms and respect recording consent laws. A risk assessment is documentation of a decision, not permission to proceed. If the analysis shows risks that safeguards cannot reduce, the right answer may be to exclude the record set. Nothing is binding until the company agrees price and terms and signs, so there is room to adjust scope as the review develops.

Timeline checkpoints for a company

WhenWhat to do
Before qualificationConfirm whether the company is a covered business and has California residents' data
During the data inventoryMark record sets containing personal information, sensitive fields and call recordings
Before scope is finalCounsel decides whether a risk assessment is needed for any retained personal information
Before deliveryConfirm de-identification rules were applied and the agreement restricts re-identification
AnnuallyReview whether regulations, deadlines or processing activities have changed

Call recordings need special care. See whether a recording notice covers AI training. Background on the category of material is in what AI training data is.

What a partner needs to know

Your role is unchanged: introduce, give basic fit information, and leave records alone. Candidates still need 50+ full-time employees at peak (contractors excluded), years of documented operations, rights to license and an authorized sponsor. When an owner asks about risk assessments, say these three things.

  1. The rules were updated in 2026, so the company should ask counsel about its own situation.
  2. Scope and de-identification decisions are made with the company before any work begins.
  3. Nothing is binding until the company agrees price and terms and signs.

Cybersecurity audits and automated decisionmaking

The same package covers cybersecurity audits and automated decisionmaking technology, so a company reading the regulations will meet those topics too. They are separate obligations from a risk assessment, with their own triggers and phased deadlines. A company that only licenses historical records may not be affected by every part, but its counsel should read the whole package rather than one section, and should note the 2027 to 2028 compliance dates listed by the agency.

Questions for counsel

  • Is the company a covered business under the CCPA?
  • Would any retained records be personal information of California residents?
  • Which regulation triggers and deadlines apply, as the current text reads?
  • Who will document any required assessment, and who signs off?
  • Does the company also hold EU personal data?

Next step

If a company you know is ready to discuss licensing with counsel in the room, register as a partner and make the introduction, or run the company fit checker first. The how it works page lays out the stages. No reward is guaranteed; it is paid only after the buyer pays and SourceX receives its fee.

  1. Step 1Share your linkSend your personal link to a company you know.
  2. Step 2Company appliesThe company applies itself at /apply.
  3. Step 3Buyer selects and paysThe buyer selects and pays for the data and SourceX receives its fee.
  4. Step 4You get your rewardYour share of SourceX fees becomes payable.

Common questions

When do the CPPA risk assessment regulations take effect?

The CPPA lists the package on risk assessments, cybersecurity audits and automated decisionmaking technology as effective January 1, 2026, with some compliance deadlines phased in from 2027 to 2028. Dates can change and details are in the regulation text, so the company's counsel should confirm the schedule that applies.

Does licensing de-identified records trigger a risk assessment?

That depends on whether the delivered records are personal information and on the regulation's triggers. A properly de-identified scope may avoid triggers tied to selling or sharing personal information, but the legal test is in the statute and regulations. Counsel decides, and de-identification rules are agreed before any work begins.

Is a CCPA risk assessment the same as a GDPR DPIA?

They are related ideas but separate legal obligations with different triggers, content and regulators. A company with both California and EU personal data may need to consider each regime on its own terms. Counsel should map which obligations attach to which record sets.

Does the company have to file the assessment with the agency?

Do not assume either way. Reporting and submission requirements are set by the regulation text and may include phased deadlines. Ask counsel to read the current provisions. The partner's role is only to mention that the topic exists and refer the sponsor to the company's own advisers.

Does this apply to companies outside California?

Only if they are covered businesses handling California residents' personal information. A company without California operations or California residents' data may fall outside the CCPA, though other laws and its own contracts can apply. Counsel checks coverage record set by record set.

Free resources

By SourceX Partnerships Team · Published 2026-10-09 · Updated 2026-10-09

Know a US company with valuable proprietary data?

Become a referral partner from anywhere we support, get your link and introduce an owner or authorized decision-maker.

Refer a company →

I own a business

Explore licensing your company's data to AI developers worldwide. Start a short assessment; no uploads needed.

Start an assessment