ConstraintCognitive automation2025-09-22
California's privacy rules require a person with authority over whether a business starts high-risk data processing, including automated decisions, to review and approve its risk assessment
Product manageroccupation page →Event date / reported
2025-09-22
Evidence stage
ConstraintFailure, rollback, regulation or cost is suppressing adoption. Can lower an assessment or widen its uncertainty.
Tasks this bears on
Deciding what not to build
Saying no to a customer, an executive and an engineer in the same week, with a reason each of them can repeat.
Still human-led✓ Evidence-backed
Where this applies
California regulations binding businesses whose processing of personal information presents significant risk, including automated decision-making technology used for significant decisions. A business must conduct a risk assessment before initiating the processing and document whether it will initiate it; an individual who has the authority to participate in deciding whether the business will initiate the processing must review and approve the assessment; and the stated goal is restricting or prohibiting the processing when the risks to consumers outweigh the benefits. It binds businesses, not product managers by name, covers personal-data processing rather than every product decision, and first submissions to the regulator fall due later.
What this means
For products that make significant automated decisions about people, California now requires the decision whether to go ahead — and the reasons it could be stopped — to be written down and approved by a person who has the authority to say no.
What it does not yet show
It binds businesses in one state and covers personal-data processing; it does not show who in a company makes the call or how often processing is stopped.
What you can check
Open the CPPA's approved regulations text, § 7152(a)(9), and find "must review and approve the assessment".
Does it change the assessment?
No. The impact index is never moved by a single event. What this record did: the 1 linked task judgement above now rest on evidence instead of inference.
Source
California Privacy Protection Agency — Text of Regulations (CCPA Updates, Cyber, Risk, ADMT, and Insurance Regulations), Cal. Code Regs. tit. 11, §§ 7150–7157 (approved by the Office of Administrative Law September 22, 2025; effective January 1, 2026) · verified 2026-09-27 · Claude (VOLO agent) · interpreted 2026-09-27 · Claude (VOLO agent)
Primary source — published by the party that did this, or the authority of record. No co-signature needed.