Skip to main content
TrustEdge AI

Sacramento, CA

AI governance in Sacramento

Where the rules are written, and applied

Sacramento is unusual: it is both where California’s AI rules are made and a metro full of organisations that have to comply with them. State agencies, health plans, and their contractors are adopting AI while the statutes governing it are still arriving.

We work on-site in Sacramento. TrustEdge has no Sacramento office — our engineers and assessors travel to you, and AI Academy and agent engagements are delivered nationally.

The pressure

What Sacramento organisations are actually dealing with

Public-sector and health-plan buyers need to show their work — what the system decides, who reviews it, what happens when it is wrong. Contractors to the state inherit those obligations through their agreements, often before they have a governance programme to point at.

Sectors we serve here

  • Government and public agencies
  • Healthcare and health plans
  • Legal

Regulatory context

The California rules that reach Sacramento buyers

California has more AI law in force than any other state. The rule most likely to reach you is not the frontier-AI headline act — it is an employment regulation that has bound every employer with five or more employees since October 1, 2025.

SB 1120 — AI cannot make the final medical-necessity call

The Physicians Make Decisions Act has applied since January 1, 2025. A health plan or insurer using AI in utilization review, utilization management, or prior authorization may not let the tool make the final determination of medical necessity. That determination must be made by a licensed physician or other competent health care professional reviewing the individual clinical circumstances. Enforced by the Department of Managed Health Care and the Insurance Commissioner, with administrative penalties for willful violations. For payers, this is the most concrete AI constraint in California health care.

CPPA ADMT regulations — significant decisions, from January 1, 2027

The CCPA regulations on automated decisionmaking technology, risk assessments, and cybersecurity audits were approved by the Office of Administrative Law on September 22, 2025 and took effect January 1, 2026. ADMT means technology that processes personal information and uses computation to replace or substantially replace human decisionmaking. The obligations attach to "significant decisions": financial or lending services, housing, education enrollment or opportunities, employment or independent contracting opportunities or compensation, and health care services. Behavioral advertising appeared in earlier drafts and is not in the final rule. Businesses using ADMT for a significant decision must give pre-use notice, offer an opt-out, and provide access to an explanation, with compliance required from January 1, 2027. Human reviewers must be able to understand and evaluate the ADMT output and to alter the final decision.

CPPA risk assessments — this clock is already running

Risk assessments are the CPPA obligation that is live today, not in 2027. Processing initiated on or after January 1, 2026 that involves selling or sharing personal information, processing sensitive personal information, using ADMT for a significant decision, training ADMT with personal information, or using automated processing to infer personal attributes requires a documented risk assessment. Processing that predates 2026 must be assessed and documented by December 31, 2027. The first documentation submission to the CPPA is due April 1, 2028. Cybersecurity audit certifications are staggered by revenue: April 1, 2028 above $100M, April 1, 2029 for $50M–$100M, April 1, 2030 below $50M.

All California AI provisions, in full →

Reviewed against primary sources as of August 2, 2026.

How we help

What we do in Sacramento

Talk to us about AI governance in Sacramento

No pitch, no pressure. We will tell you what is actually in scope and what an assessor will accept.