Back to Blog
Compliance GuidesMarch 29, 202614 min readReviewed by the PrivacyLawMap editorial teamLast reviewed June 9, 2026

AI and Data Privacy 2026: State Law Compliance Guide (CCPA ADMT, Profiling, AI Training)

Share:
Turn This Guide Into a Working Privacy SetupSponsored

Termly can generate and maintain your privacy policy, consent banner, and data-request workflow as requirements change.

Start Free with Termly

Quick answer

US state privacy laws do not regulate “AI” by name — they regulate profiling and automated decision-making. As of 2026, at least 15 comprehensive state laws give consumers profiling opt-out rights and require assessments before high-risk automated processing. Key obligations:

  • Let consumers opt out of profiling that produces legal or similarly significant effects (CA, CO, CT, TX, VA, OR and more).
  • Complete a data protection assessment before profiling, automated decisions, or sensitive-data AI processing.
  • Follow California’s CCPA ADMT rules: pre-use notices, access to the decision logic, and opt-out rights.
  • Document and limit AI training data, and honor deletion and access requests for personal data used to train models.

Why AI and Data Privacy Are Colliding in 2026

If your business uses artificial intelligence — whether for customer recommendations, fraud detection, hiring tools, chatbots, or marketing analytics — you are almost certainly subject to provisions in US state privacy laws that specifically regulate AI and automated decision-making. Start with the AI privacy compliance checker to identify ADMT, profiling, and assessment duties. As of March 2026, at least 15 state comprehensive privacy laws contain provisions addressing profiling, automated decisions, or both, and enforcement is accelerating.

This guide explains exactly how US state privacy laws apply to AI, what compliance obligations they create, and what practical steps you should take today to reduce your risk. Whether you build AI tools or simply use them, these rules affect you.

How State Privacy Laws Define AI-Related Processing

State privacy laws don’t typically use the term “AI” directly. Instead, they regulate specific activities that AI systems perform, using two key legal concepts:

Profiling

Most state privacy laws define profiling as any form of automated processing of personal data to evaluate, analyze, or predict aspects of a person’s behavior, preferences, economic situation, health, reliability, or location. This definition captures nearly every machine learning model that processes personal data — from recommendation engines to credit scoring algorithms.

States with explicit profiling provisions include California, Colorado, Connecticut, Delaware, Indiana, Iowa, Kentucky, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon, Rhode Island, Tennessee, Texas, Utah, and Virginia.

Automated Decision-Making

A narrower but more consequential concept, automated decision-making refers to decisions made by technology without meaningful human involvement that produce legal or similarly significant effects on a consumer. Examples include loan approvals, insurance pricing, employment screening, and housing decisions.

California’s CPRA regulations (currently being finalized by the CPPA) would create the most detailed automated decision-making rules in the country, including requirements for pre-use notices, access to the logic involved, and opt-out rights.

The Five Core AI Obligations Under State Privacy Laws

1. Data Protection Assessments for AI Processing

At least 15 state laws require businesses to conduct data protection assessments (also called privacy impact assessments) before engaging in processing that presents a heightened risk of harm. Profiling and automated decision-making are explicitly listed as triggers in most of these laws.

State DPA Required for Profiling? DPA Required for Automated Decisions? Notable Detail
CaliforniaYes (proposed)Yes (proposed)CPPA rulemaking includes detailed ADMT regulations
ColoradoYesYesMust weigh benefits against potential risks to consumers
ConnecticutYesYesPublic Act 26-64 adds surveillance-pricing disclosure duties effective October 1, 2026
MarylandYesYesMODPA enforcement began April 1, 2026; includes sensitive data focus
VirginiaYesYesMust make assessments available to AG upon request
TexasYesYesAG can request assessments; 18,000+ employee threshold
OregonYesYesCovers nonprofit organizations too
DelawareYesYesEffective January 1, 2025
MontanaYesYesLowest revenue threshold ($25K) in the country
MinnesotaYesYesEffective July 31, 2025; includes profiling in employment decisions

If you deploy any AI model that processes personal data, you very likely need a documented assessment before launch. Use our Privacy Law Calculator to determine which states’ laws apply to your business.

2. Consumer Opt-Out Rights for Profiling

Nearly every comprehensive state privacy law grants consumers the right to opt out of profiling that furthers decisions producing legal or similarly significant effects. Several states go further:

  • Colorado, Connecticut, and Virginia were the first to include explicit opt-out rights for profiling.
  • Maryland’s MODPA (enforcement active since April 1, 2026) requires opt-out for profiling used in decisions about “access to or the cost of financial lending services, housing, insurance, education enrollment, and criminal justice.”
  • California’s proposed ADMT regulations would require a pre-use notice before any significant automated decision and a separate opt-out mechanism.
  • Minnesota requires opt-out for profiling in employment, lending, insurance, and housing contexts.

If your AI system influences consumer-facing decisions, you must provide a working opt-out mechanism. See our Opt-Out Link Generator for implementation guidance.

3. Transparency and Notice Requirements

When you use AI to process personal data, state privacy laws require you to disclose this in your privacy policy. At minimum, you must describe:

  • The categories of personal data processed by your AI systems
  • The purposes of that processing (profiling, targeting, personalization, automated decisions)
  • Whether personal data is sold or shared with third parties for AI training
  • How consumers can exercise their opt-out rights

California’s proposed ADMT rules would add requirements to explain “the logic involved” in automated decisions and “the key parameters that are most influential in the decision.”

4. Sensitive Data and AI Training

If your AI models process or are trained on sensitive personal data (racial or ethnic origin, religious beliefs, health information, precise geolocation, biometric data, children’s data, sexual orientation), virtually every state law requires you to obtain affirmative consent before processing. This means:

  • You cannot use sensitive data to train AI models without explicit consumer opt-in
  • You cannot use AI to infer sensitive data categories without consent (some state AGs have signaled this interpretation)
  • Maryland’s MODPA and Minnesota’s law go further: they restrict even the collection of certain sensitive data beyond what is reasonably necessary

5. Data Minimization Limits on AI Training

Multiple state laws now include data minimization requirements — businesses must limit personal data collection and use to what is “reasonably necessary” for the disclosed purpose. For AI, this creates a direct constraint: you cannot collect more data than needed to operate your stated service just because it would improve your model.

The PlayOn Sports enforcement action ($1.1M fine, March 2026) illustrates this — using tracking technology to collect student data for targeted advertising exceeded what was “reasonably necessary” for the ticketing service. Companies training AI models on customer data should take note.

Emerging AI-Specific Legislation in 2026

While existing state privacy laws already regulate AI through profiling and automated decision-making provisions, several states are advancing AI-specific bills in 2026:

  • Washington HB 2225 — Passed the legislature in March 2026. Regulates AI companions, marking Washington as the second state to pass AI companion-specific legislation.
  • New York “One Fair Price Package” — Two bills would prohibit personalized algorithmic pricing based on consumer data and ban electronic shelf labels in large retailers. AG Letitia James is championing the legislation.
  • Connecticut SB 4 / Public Act 26-64 — adds surveillance-pricing disclosure and retail restrictions to the state’s existing privacy law, among other consumer-protection amendments.
  • Colorado SB 26-189 ADMT law — Signed May 14, 2026. Repeals and reenacts the 2024 AI provisions as an automated decision-making technology law for consequential decisions, with developer documentation, deployer notice, post-adverse-outcome explanation, correction, record-retention, and human-review duties starting January 1, 2027.
  • California ADMT rulemaking — The CPPA continues developing detailed automated decision-making technology regulations, expected to be the most comprehensive AI-privacy framework in the country.

These bills signal a clear trend: states are moving from regulating AI indirectly (through privacy law profiling provisions) to regulating it directly. Businesses should prepare for a patchwork of AI-specific requirements layered on top of existing privacy obligations.

State AI-Specific Laws Already in Force (Texas TRAIGA and Utah AI Act)

The profiling and ADMT provisions above all live inside comprehensive privacy laws. But two states have also enacted standalone AI statutes that are already enforceable — a distinction generic “AI and privacy” overviews routinely miss, because most consolidate everything under the 2027 California/Colorado ADMT timeline. If you operate in Texas or Utah, these create obligations now, not in 2027.

AI-specific law Status Effective date What it regulates Enforcement & penalties
Texas Responsible Artificial Intelligence Governance Act (TRAIGA, HB 149)In forceJanuary 1, 2026Prohibits AI systems intentionally built to incite self-harm or crime, to produce unlawful deepfake or child sexual abuse content, or to enable government “social scoring,” and restricts certain biometric-identification uses. Signed June 22, 2025.Texas Attorney General has exclusive enforcement (no private right of action); civil penalties run $10,000–$200,000 per violation and $2,000–$40,000 per day for continuing violations, with a cure period for curable violations.
Utah Artificial Intelligence Policy Act (SB 149, amended 2025)In forceMay 1, 2024 (2025 amendments effective May 7, 2025)Requires businesses to disclose generative-AI use in high-risk interactions — legal, financial, medical, or mental-health advice, or whenever a consumer asks — and makes clear that “an AI system did it” is not a defense to a Utah consumer-protection violation.Utah Division of Consumer Protection and Attorney General enforcement, with administrative and court-ordered penalties per violation. The statute now sunsets July 1, 2027.

Neither TRAIGA nor the Utah AI Act is a comprehensive privacy law, so they layer on top of the profiling-opt-out and assessment duties covered above rather than replacing them. A business running a customer-service chatbot in Utah or a behavior-targeting model in Texas can owe duties under a state privacy law and the state AI statute at the same time.

Primary sources retrieved June 9, 2026: Texas HB 149 enrolled bill text and legislative history (capitol.texas.gov/HB00149; January 1, 2026 effective date, exclusive AG enforcement, and the $10,000–$200,000 penalty range confirmed against Norton Rose Fulbright and Perkins Coie TRAIGA analyses), and the Utah Artificial Intelligence Policy Act (S.B. 149) with its 2025 amendments and July 1, 2027 sunset (le.utah.gov/SB0149).

Real-World Enforcement: AI Privacy Violations

Enforcement agencies are already using existing privacy laws to target AI-related practices. The table below maps recent state-privacy enforcement actions to the underlying automated-processing conduct, with statutory authority and primary-source links:

Company Amount Year Authority Automated-processing conduct
Disney$2.75M2026California AG (CCPA)Failure to honor opt-out across streaming platforms with algorithmic ad targeting (details)
PlayOn Sports$1.1M2026CPPA (CCPA)Tracking students via ticketing platform for targeted advertising without adequate opt-out (details)
Tractor Supply$1.35M2025CPPA (CCPA)Failure to honor universal opt-out signals interacting with algorithmic ad systems
Honda$632,5002025CPPA (CCPA)Asked for excessive personal information to verify opt-out and right-to-know requests, frustrating automated DSAR pipelines
Sephora$1.2M2022California AG (CCPA)Sold consumer data via behavioral-advertising integrations without honoring GPC and Do Not Sell signals (foundational opt-out enforcement)
Todd Snyder$345K2024California AG (CCPA)Online opt-out workflow blocked by automated form validation that rejected valid consumer requests

The pattern is clear: businesses that use automated systems to process personal data for advertising, profiling, or decision-making face heightened enforcement risk, especially when those systems touch children’s data or fail to honor opt-out requests. See our full enforcement penalties guide for more cases. Source: California Attorney General press releases at oag.ca.gov/news and CPPA enforcement announcements at cppa.ca.gov/about-us/newsroom/ (retrieved May 23, 2026).

AI ADMT Consumer Opt-Out Rights: 2026 vs 2027

The biggest near-term AI-privacy shift is California’s ADMT framework, which finalizes consumer opt-out and pre-use notice rules for automated decision-making technology. The CPPA Board approved the regulations on July 24, 2025; the Office of Administrative Law (OAL) approved them on September 23, 2025 (Cal. Code Regs., tit. 11, div. 6, ch. 1 — cppa.ca.gov/regulations, retrieved May 23, 2026). Critical effective dates:

  • January 1, 2027 — Consumer right to opt out of significant-decision ADMT, pre-use notice requirement, and access right to the “logic involved” in automated decisions take effect for new ADMT deployments.
  • April 1, 2028 — First cybersecurity-audit certification deadline for businesses with $100M+ revenue (see our CCPA cybersecurity audit guide).
  • January 1, 2027Colorado SB 26-189 ADMT duties take effect for covered automated decision-making technology used in consequential decisions; developers must provide technical documentation, deployers must provide notices and post-adverse-outcome explanations, and consumers can request correction plus meaningful human review (retrieved June 6, 2026).
  • October 1, 2026 — Connecticut SB 4 / Public Act 26-64 surveillance-pricing disclosure duties take effect (Connecticut General Assembly, cga.ct.gov, retrieved May 23, 2026).
  • July 1, 2026 — Connecticut SB 1295 LLM-training-data disclosure requirement takes effect under the CTDPA.

The takeaway: any business deploying significant ADMT for California or Colorado consumers should treat 2026 as the documentation-and-notice year, with California ADMT rights and Colorado SB 26-189 covered-ADMT duties both kicking in January 1, 2027.

Compliance Checklist: AI and State Privacy Laws

Use this practical checklist to assess your AI-related privacy compliance:

  1. Inventory your AI systems — Identify every tool, model, or automated process that uses personal data. Include third-party AI services (chatbots, recommendation engines, analytics platforms).
  2. Map data flows — For each AI system, document what personal data goes in, what decisions or outputs come out, and which third parties receive data.
  3. Determine applicable state laws — Use the Privacy Law Calculator to identify which state laws apply to your business. Check whether profiling and automated decision-making provisions are triggered.
  4. Conduct data protection assessments — For any AI system that performs profiling or makes decisions with legal or significant effects, complete a privacy impact assessment documenting risks, benefits, and safeguards.
  5. Implement opt-out mechanisms — Provide consumers with a clear, functional way to opt out of profiling and automated decision-making. Ensure it works across all platforms and devices (learn from Disney’s $2.75M mistake).
  6. Update your privacy policy — Disclose your use of AI/automated processing, the types of decisions made, the data involved, and consumer rights. Use our Privacy Policy Generator for state-compliant language.
  7. Get consent for sensitive data — If your AI processes sensitive personal data, obtain affirmative opt-in consent before processing.
  8. Apply data minimization — Limit AI training data to what is reasonably necessary for the disclosed purpose. Do not repurpose data collected for one service to train models for another without notice and consent.
  9. Honor DSAR deadlines — Consumers have the right to know what data your AI processes about them. Ensure you can respond to data subject access requests within state-mandated timeframes.
  10. Monitor the regulatory landscape — AI regulation is evolving rapidly. Subscribe to updates and revisit your compliance posture quarterly.

Frequently Asked Questions

Do state privacy laws apply to AI tools we use but didn’t build?

Yes. If you deploy a third-party AI tool that processes your customers’ personal data, you are the “controller” under state privacy law and bear responsibility for compliance. You must ensure your vendor agreements include adequate data protection terms and that the tool respects opt-out signals. See our data processing agreements guide.

Is using AI for internal analytics covered by these laws?

Generally, internal analytics that do not produce decisions with legal or similarly significant effects on consumers are lower risk. However, if your analytics involve profiling (analyzing personal data to evaluate or predict behavior), data protection assessment requirements may still apply in states like Colorado, Connecticut, and Maryland.

How does Colorado SB 26-189 interact with state privacy laws?

Colorado SB 26-189 adds covered-ADMT requirements on top of the Colorado Privacy Act starting January 1, 2027. Developers must provide technical documentation for covered ADMT, deployers must provide point-of-interaction notices and post-adverse-outcome explanations, and consumers can request correction of inaccurate personal data plus meaningful human review after adverse consequential decisions. This creates a dual compliance obligation for businesses operating in Colorado: CPA profiling opt-out and data protection assessment duties still apply, while SB 26-189 adds ADMT-specific notice, documentation, record-retention, and review duties.

Can I use customer data to train AI models?

It depends on what you disclosed in your privacy policy and the nature of the data. Under data minimization principles, you can only use personal data for purposes compatible with what you disclosed at collection. Using customer data to train models for a different purpose likely requires additional notice and may require consent. Sensitive data categories always require explicit consent.

What happens if my AI makes a wrong decision about a consumer?

Several state laws grant consumers rights to access, correct, and appeal automated decisions. If your AI denies a service, changes pricing, or otherwise produces a significant adverse outcome, the affected consumer may have the right to understand why, correct inaccurate data, and request human review. California’s ADMT regulations (OAL-approved September 23, 2025; consumer opt-out effective January 1, 2027) make these rights particularly robust.

What is ADMT (automated decision-making technology) under California law?

Under the CPPA’s 2025-approved ADMT regulations, ADMT means any technology that processes personal information and uses computation to replace or substantially replace human decision-making for a “significant decision” about a consumer — including decisions about employment, financial or lending services, housing, education enrollment, healthcare services, insurance, criminal justice, or essential goods and services. Starting January 1, 2027, businesses must provide a pre-use notice, an opt-out mechanism, and access to the logic involved when they use ADMT for these significant decisions.

Which states require AI privacy impact assessments in 2026?

At least 19 states require a data protection assessment (DPA) before profiling or automated decision-making that creates a heightened risk of harm: California (under ADMT rules), Colorado, Connecticut, Delaware, Indiana, Iowa, Kentucky, Maryland (MODPA, enforcement active April 1, 2026), Minnesota (effective July 31, 2025), Montana, Nebraska, New Hampshire, New Jersey, Oregon, Rhode Island, Tennessee, Texas, Utah, and Virginia. Colorado, Connecticut, Maryland, Texas, Oregon, and Virginia all explicitly require DPAs when AI is used for consequential decisions; Colorado SB 26-189 separately adds covered-ADMT documentation, notice, record-retention, and human-review duties starting January 1, 2027.

Which states have AI-specific laws in effect right now?

As of June 2026, two states have standalone AI statutes that are already enforceable. Texas — the Responsible Artificial Intelligence Governance Act (TRAIGA), effective January 1, 2026, enforced by the Texas Attorney General with civil penalties up to $200,000 per violation. Utah — the Artificial Intelligence Policy Act, in effect since May 1, 2024 and amended in 2025, which requires generative-AI disclosure in high-risk legal, financial, and medical interactions and sunsets July 1, 2027. Everywhere else, AI conduct is regulated indirectly today through the profiling-opt-out and data-protection-assessment provisions in 19+ comprehensive state privacy laws, with California ADMT consumer rights and Colorado SB 26-189 ADMT duties both beginning January 1, 2027.

For a complete analysis of which state laws apply to your business and what they require, start with the Privacy Law Calculator and review your obligations with the state comparison tool. For the AI-specific layer — NIST AI RMF, ISO/IEC 42001, and the Colorado and Texas AI statutes that sit on top of these privacy duties — see the US state AI regulation reference.

Published: March 29, 2026. Last verified: June 9, 2026. Texas TRAIGA (HB 149, effective January 1, 2026) and the Utah Artificial Intelligence Policy Act (S.B. 149, effective May 1, 2024, amended 2025, sunset July 1, 2027) verified against the Texas Legislature and Utah Legislature bill pages (date_retrieved: 2026-06-09); Colorado SB 26-189 and California ADMT effective dates verified June 6, 2026 against the Colorado General Assembly and CPPA rulemaking pages.

Put This Guide Into PracticeSponsored

Termly can turn the requirements above into a maintained privacy policy, consent banner, and data-request workflow.

Start Free with Termly