Adapting Privacy Rights Processes for Emerging AI Regulations
-
August 18, 2026
-
As artificial intelligence (“AI”) regulations evolve across jurisdictions, organizations face growing pressure to reevaluate their individual privacy rights governance and response processes. The California Consumer Privacy Act (“CCPA”), General Data Privacy Regulation (“GDPR”) and other privacy laws all address consumer privacy rights with the right to opt out, the right to access and the right to erasure. Similar rights are required under existing and emerging AI regulations, including the newly enacted CCPA Article 11 regulations1 regarding automated decisionmaking2 technology (“ADMT”), the Colorado Automated Decision-Making Technology Act (“ADMTA”)3 and the EU Artificial Intelligence Act (“EU AI Act”).4
This article examines these emerging regulations and offers a practical roadmap for organizations to enhance existing privacy rights response processes to address the evolving AI regulatory landscape.
CCPA Article 11: Automated Decisionmaking Technology
The new CCPA requirements surrounding cybersecurity audits, risk assessments and ADMT apply to organizations using ADMT for “significant” decisions, defined as “a decision that results in the provision or denial of financial or lending services, housing, education enrollment or opportunities, employment or independent contracting opportunities or compensation, or healthcare services.” Under CCPA Article 11, organizations are required to implement pre-use notices,5 right to opt-out measures6 and access request measures7 by January 1, 2027.
The Colorado ADMTA Law (based on Senate Bill 26-189)
Similar to California’s ADMT regulations, the Colorado ADMTA8 emphasizes transparency, data accuracy and meaningful human involvement by requiring correction mechanisms and human review when automated systems materially influence significant decisions. Pursuant to section 6‑1‑1705 of the ADMTA9, organizations will be required to provide the following:
- Right to correction: If a consumer experiences an adverse outcome from a consequential decision materially influenced by covered ADMT, they may request correction of factually incorrect or materially inaccurate personal data used in that decision.
- Instructions: Organizations deploying ADMT must provide clear instructions for accessing personal data and requesting corrections, consistent with Colorado privacy law requirements.
- Human review and reconsideration: Organizations deploying ADMT must offer the consumer an opportunity for meaningful human review and reconsideration of the consequential decision to the extent commercially reasonable.
EU AI Act
The EU AI Act does not include specific provisions that grant a direct “opt‑out” or “erasure” right under its own text; these rights continue to reside under the EU’s GDPR10. The EU AI Act focuses on transparency obligations. Specifically, Article 50 requires providers and deployers, in certain scenarios, to inform users when they are interacting with AI systems. So, while the EU AI Act itself does not introduce new opt‑out or erasure requirements, it integrates closely with GDPR’s existing rights and emphasizes enhanced transparency and human review.
Enhancing Privacy Rights Response Processes
Organizations do not need to build entirely new operational frameworks to comply with emerging AI rights requirements. Rather, many of the rights introduced under CCPA Article 11, the Colorado ADMTA regulations and related AI regulations can be incorporated into existing privacy rights response programs. By leveraging established data subject rights processes, including intake portals, governance structures, audit trails and automated workflows, organizations can create scalable and defensible mechanisms for managing AI-related requests. Organization should employ the following approaches.
Expand Rights Intake Mechanisms.
Organizations should review and update existing privacy rights portals, web forms and request intake channels to accommodate AI-specific rights requests. Similar to traditional privacy rights forms, AI rights intake should dynamically guide individuals based on their jurisdiction and request type, including:
- Requests to opt out of the use of ADMT for significant decisions.
- Requests for information regarding the use of AI or ADMT in a decision-making process.
- Requests to correct data used in an AI-enabled consequential decision.
- Requests for human review or reconsideration of an automated decision.
Using a unified intake process helps ensure that organizations collect only the information necessary to validate and process the request while maintaining a consistent user experience.
Enhance Workflows and Response Procedures.
Existing privacy rights workflows should be expanded to incorporate AI-specific review and fulfillment activities. This includes identifying when a request involves an AI system, determining whether the AI system was used in a significant or consequential decision and routing the request to appropriate stakeholders such as privacy, legal, compliance, human resources, risk or model governance teams. Organizations should develop standardized response templates that explain:
- Whether ADMT or AI was used.
- The purpose of the AI system.
- The role of personal data in the decision-making process.
- The extent of human involvement.
- Available appeal, review, correction or opt-out options.
- Any applicable legal exceptions.
Standardized workflows and communications improve consistency and reduce response times.
Automate Fulfillment Through System Integration.
Many organizations already automate aspects of privacy rights fulfillment through integrations with customer, employee and enterprise systems. These same capabilities can be extended to AI rights requests. Organizations should consider integrating their privacy rights platforms with:
- AI governance and model inventory solutions.
- Human resources and recruiting platforms.
- Customer decisioning systems.
- Data catalogs and data governance repositories.
- Case management and workflow tools.
Automated integrations can help identify whether a consumer or employee was subject to an AI-enabled decision, retrieve relevant decision records, support correction requests and document human review activities. Automation enables organizations to scale as AI-related request volumes increase.
Establish AI Rights Governance and Metrics.
As with privacy rights programs, AI rights compliance should be supported by clear operational governance. Organizations should maintain inventories of AI systems that may be subject to regulatory requirements, document associated workflows and ownership and establish escalation procedures for complex requests.
In addition, organizations should consider developing dashboards and reporting capabilities that track variables including AI-related request volumes by type, processing timelines, opt-out rates, human review outcomes, correction requests and regulatory response metrics. These metrics provide visibility into compliance performance and will help organizations demonstrate accountability to regulators and stakeholders.
How FTI Consulting Can Help
Organizations must prepare for the CPPA’s new regulatory requirements, including Article 9 Cybersecurity Audits, Article 10 Risk Assessments, and Article 11 ADMT compliance obligations. A trusted partner can help you learn more about how these requirements may affect your organization and assist with readiness, assessment and implementation efforts.
Footnotes:
1: California Consumer Privacy Act (“CCPA”) Regulations, Article 11, Automated Decisionmaking Technology, Cal. Code Regs. tit. 11, §§ 7200, 7220-7022 (2026)
2: “Decisionmaking” is spelled as one unhyphenated word in the original legislation
3: Colorado Automated Decision-Making Technology Act (ADMTA), Colo. Rev. Stat. §§ 6-1-1701 to -1709 (2026)
4: “High Level Summart of the AI Act,” EU Artificial Intelligence Act (February 27, 2024)
5: Cal. Code Regs. tit. 11, § 7220 (2026)
6: Cal Code Regs. tit. 11, § 7221 (2025)
7: Cal Code Regs. tit. 11, § 7222 (2026)
8: Colorado Automated Decision-Making Technology Act (ADMTA), Colo. Rev. Stat. §§ 6-1-1701 to -1709 (2026)
9: Colo. Rev. Stat. § 6-1-705 (2026)
10: Regulation (EU) 2016/179, 2016 O.J. (L 119) 1
Related Insights
Related Information
Published
August 18, 2026
Key Contacts
Senior Managing Director
Senior Managing Director
Senior Managing Director
Managing Director
Managing Director