CCPA AI Incident Reporting: California Breach Notice for LLM Events
California breach reporting for an AI incident follows the state data-breach statute and the CCPA private-action provision. The trigger depends on the personal information involved, acquisition or disclosure, encryption status, ownership, and security practices. CPPA automated-decisionmaking rules create a separate compliance track. This guide turns an LLM event into a notice decision, evidence package, and scoped response.

A support agent pastes a customer record into an unapproved LLM on Monday morning. By lunch, the browser tab is closed and the incident channel contains one cropped screenshot. California's notice analysis still needs the affected resident and the statutory personal-information category. It also needs the recipient and the acquisition facts. Record the date of discovery separately.
I would treat that missing request record as an incident-response defect in its own right. The legal clock keeps moving while five teams reconstruct one HTTPS call.
TL;DR
- California's breach-notice statute governs resident notice for covered personal information, including a 30-calendar-day deadline subject to statutory delay grounds.
- A single breach requiring notice to more than 500 California residents also requires an electronic sample notice to the Attorney General.
- The CCPA creates a narrower private action for specified data exposed through a failure to maintain reasonable security.
- CPPA ADMT notices, opt-outs, access rights, and appeals concern significant decisions. They create a separate track from breach notification.
- An AI gateway can preserve routed request evidence. It cannot decide legal notice or investigate and contain systems outside the HTTP model path.
California breach notice starts with ownership and data category
The current California breach-notice statute applies to a person or business conducting business in California that owns or licenses computerized data containing personal information. Notice goes to a California resident when covered unencrypted personal information was, or is reasonably believed to have been, acquired by an unauthorized person. Encrypted information also enters the test when the relevant key or security credential was acquired and could render the information readable or usable.
A business maintaining data for somebody else has a different first duty. Subdivision (b) requires it to notify the owner or licensee immediately following discovery when covered personal information was, or is reasonably believed to have been, acquired by an unauthorized person.
The first triage page should therefore name the data owner and system custodian. It should identify California residents and statutory data elements. It should also record the encryption state and credential exposure. Evidence of acquisition belongs on the same page. Calling the event an "AI breach" settles none of those fields.
The resident notice has a deadline and a prescribed shape
The breach-notice statute requires disclosure within 30 calendar days of discovery or notification of the breach. The statute permits delay for legitimate law-enforcement needs or to determine scope. A delay is also permitted to restore the reasonable integrity of the data system. Record the event that started the period and the basis for every delay.
The notice uses plain language and the title "Notice of Data Breach." Its required headings include "What Happened?", "What Information Was Involved?", "What We Are Doing", "What You Can Do", and "For More Information." Those labels look simple on paper. Filling them for prompt traffic requires a chronology tied to the actual requests.
The California Attorney General's reporting page adds the regulator-facing step. A person or business issuing notice to more than 500 California residents from one breach must electronically submit a single sample copy to the Attorney General, excluding personally identifiable information. The threshold concerns residents receiving notice, rather than the number of prompts.
CCPA private exposure is narrower than the notice statute
The CCPA private-action text addresses unauthorized access and exfiltration, theft, or disclosure of specified nonencrypted and nonredacted personal information, plus an email address combined with credentials that permit account access. The event must result from a business's violation of its duty to maintain reasonable security procedures and practices appropriate to the information.
That cause of action is narrower than every incident involving personal information. Its text limits the private action to the breach described in the provision itself. It provides statutory damages of $100 to $750 per consumer per incident or actual damages, whichever is greater, with statutory adjustment language now attached to the amounts.
For an LLM event, counsel needs two related files. The breach-notice file establishes the trigger and recipients. The CCPA private-action file evaluates the specified data, unauthorized event, security duty, and causation. Combining them into one yes-or-no checkbox hides the different tests.
ADMT decision rules run on a separate track
The CPPA's approved regulations govern automated decisionmaking technology used for significant decisions. They require pre-use notice and opt-out or qualifying appeal handling. They also require access information in defined circumstances. Their focus is how a business uses personal information to make decisions about lending, housing, education, employment, independent contracting, compensation, or healthcare.
A model can violate an ADMT right without causing a security breach. A breach can involve an LLM summarizer that makes no significant decision. One event may implicate both tracks, but each requires its own issue list and evidence.
This distinction matters during incident command. The breach lead should avoid waiting for an ADMT classification before preserving evidence and evaluating the California notice statute. The privacy lead should still check whether the exposed transaction formed part of a significant decision, because the consumer may also exercise access rights. Opt-out and appeal rights may apply as well. Our California AI law overview separates these deployer duties from developer-facing laws.
Request evidence makes the notice decision faster
Preserve the originating identity and the prompt and response identifiers. Record content classifications and the model destination. Preserve the policy version and decision outcome, along with timestamps. Add the application transaction and provider ticket. Record the retention setting and downstream copy locations. Add every containment action. A model-provider dashboard showing token volume gives useful context and leaves the statutory data categories unresolved.
A stable correlation key should connect the request record to endpoint and IAM evidence. It should also connect application and provider evidence. The AI incident response plan covers command structure. The AI audit log schema names the fields that support reconstruction without relying on a screenshot pasted into Slack.
Run one practical test before an incident. Choose a production model route and seed a synthetic customer record. Then ask the response team to populate the California notice headings. The blank boxes reveal which evidence owners and retention paths need work.
Ownership and HTTP boundary
Security operations owns detection and containment. It also owns technical investigation. Privacy and legal own the statutory interpretation and affected-resident analysis. They also own the notice decision and wording. Application and data owners establish custody and purpose. The model provider supplies its access and retention facts. It also supplies deletion facts. Executive incident command approves the response path.
DeepInspect's useful boundary is narrower. It can evaluate and record deliberately routed HTTP traffic between authenticated users or agents and LLM endpoints. Local browser history and endpoint compromise require evidence from other systems. The same applies to stolen credentials and provider-side intrusion. Database access and traffic that bypasses the proxy also require other evidence. Harm analysis and California residency remain organizational decisions. Statutory data classification and notice delivery do as well.
The CCPA AI audit-evidence guide covers routine records. Incident reporting takes those records and builds one defensible chronology around one event.
DeepInspect
DeepInspect can preserve decision evidence for HTTP traffic deliberately routed between authenticated users or agents and LLM endpoints. It evaluates application-supplied identity and role against organizational policy before forwarding a request. The evaluation also covers content classification and destination. Model authorization is checked as well, then DeepInspect records the outcome outside the calling application's write path.
That record supports the chronology and recipient work behind a California notice decision. It also supports the data-category work. Endpoint forensics and provider investigation sit outside the proxy boundary. The same applies to residency analysis and legal conclusions. Containment outside the model route and delivery of notices also sit outside the proxy boundary.
Book a technical deep dive at deepinspect.ai.
Frequently asked questions
- Does every unauthorized LLM prompt require California resident notice?
The statutory notice test turns on covered personal information and California residency. It also turns on ownership or maintenance and unauthorized acquisition or reasonable belief of acquisition. The encryption conditions in the statute complete the test. An employee's use of an unapproved model deserves investigation, but the tool label alone does not decide notice. Document the facts and the legal conclusion, including a closure below threshold.
- When does the 30-calendar-day period begin?
The current statute ties the period to discovery or notification of the data breach. Capture the event and timestamp that established discovery. Record the source and decision owner as well. A later internal severity label should remain a separate chronology entry. Any delay for law enforcement or scope determination should cite the applicable statutory basis and supporting facts. The same requirement applies to a delay for restoration.
- Does an ADMT violation count as a reportable breach?
ADMT rights and breach notice address different events. A missing pre-use notice or mishandled opt-out concerns automated decision processing. California's breach-notice provision concerns unauthorized acquisition of covered personal information under its statutory conditions. The same system may create both issues, so the incident file should test each track rather than treating either one as a substitute for the other.