Preliminary Comment on CPPA Opt-Out Preference Signals
Box Commons · 30 N Gould St Ste N, Sheridan WY 82801
- AB 566's opt-out signal requirements for AI systems create a verification gap — how does a consumer know their opt-out was honored?
- Independent third-party credentialing provides a scalable compliance pathway that serves both consumer protection and business certainty.
- The CPPA should recognize credentialing as a mechanism that bridges consumer privacy expectations with developer compliance obligations.
+ Jump to Section
I. The Scale Problem: From Millions to Billions of Signals
AB 566 represents a landmark in consumer privacy protection. By requiring all web browsers operating in California to offer built-in opt-out preference signal settings, the law will dramatically increase the volume of Global Privacy Control signals flowing through the digital ecosystem. After January 1, 2027, signals will flow from the general population of California internet users — not just privacy-conscious consumers who install browser extensions.
This shift in scale transforms opt-out signal processing from a niche compliance function into a core operational requirement. Increasingly, the systems receiving and processing these signals will be AI-driven systems: recommendation engines, advertising technology platforms, data broker aggregation tools, and automated data processing pipelines.
The question the Agency should consider is not merely whether businesses honor opt-out signals, but whether the AI systems handling those signals can be verified as doing so correctly, consistently, and without circumvention.
II. The Verification Gap
Consumer Reports' 2020 study of California data broker opt-out compliance found that 62% of the time, participants either could not determine whether their request was successful or were unable to submit a request at all. Participants encountered demands for government-issued identification, selfies, and Social Security numbers simply to exercise their right to opt out.
These findings predate the widespread deployment of AI-driven systems in consumer data processing. As AI systems increasingly mediate the relationship between consumer opt-out signals and business data practices, the verification gap will widen unless the Agency establishes clear expectations for how AI systems demonstrate compliance.
III. The Intersection of OOPS and Automated Decision-Making Technology
The Agency's finalized ADMT regulations require businesses using ADMT for significant decisions to conduct risk assessments, provide pre-use notice, and offer consumers opt-out rights. However, the current framework creates a regulatory gap at the intersection of OOPS and ADMT: when an AI system that is itself classified as ADMT receives an opt-out preference signal, what standard governs its processing of that signal?
The ADMT regulations address the AI system's decision-making outputs; the OOPS framework addresses the consumer's signal inputs. Neither framework currently addresses the fidelity of the AI system's signal processing — the critical link between the consumer's expressed preference and the system's behavioral response.
IV. Recommendations
1. Establish verifiable compliance standards for AI systems that receive and process opt-out preference signals, distinct from existing general business compliance requirements.
2. Recognize independent third-party credentialing as a compliance mechanism that bridges consumer privacy expectations with developer obligations.
3. Address the intersection of OOPS and ADMT regulations to ensure consistent treatment of AI systems that both make automated decisions and process opt-out signals.
Contact:
Brice Love, Acting Executive Director
Box Commons
[email protected]
Content Integrity Notice: This comment was authored by the Box Commons Policy Working Group. Generative AI was used for research synthesis and drafting support. All policy positions, recommendations, and normative claims were formulated and reviewed by human authors.
Related Filings
Comment on FTC Negative Option Rule ANPRM
Raises an issue no prior FTC commenter has addressed: AI agents that autonomously discover, evaluate, subscribe to, and pay for goods and services, breaking ROSCA's foundational assumption of a human consumer. Proposes a safe harbor framework for AI-readable disclosures.
Colorado AGComment on Colorado ADMT Proposed Rules: Training Data Certification
Recommends that Colorado's ADMT proposed rules recognize independent data certification as a mechanism for developers to satisfy training data documentation obligations, with a rebuttable presumption that certified datasets meet disclosure requirements. Backed by a live 22-station broadcast radio certification pipeline.