Outdated Drivers Are Slowing You Down
One free scan finds every outdated or missing driver and matches the right update for your exact hardware.Free scan · exact hardware matchWindows Errors? Fix Them Before They Spread
Repair common Windows errors and clear accumulated junk for a smoother, more stable PC - no reinstall needed.Free scan · no reinstalliTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more
Agentic AI does not get a governance exemption under DoD contracting rules or state privacy law. Neither CMMC nor the California and Colorado privacy frameworks exempts a system because it is autonomous, multi-step, or labeled an “agent.” Whether an obligation applies depends on the information the system touches, the contract or entity it operates under, the personal data it processes, and whether its output is used to make or materially influence a regulated decision. The agent label is not a trigger in either direction.
This article works through those scope tests for two regimes: Department of Defense contracts under CMMC, and state privacy law, using California and Colorado as current examples. Dates and rule status are current as of early October 2026.
Why the agent label doesn’t settle the question
An agent differs from a chatbot because it acts. It reads files, calls APIs, writes to ticketing systems, sends messages, and chooses between options. Each of those capabilities widens the set of systems and data it touches, which makes scope harder to pin down, not easier. Regulators ask the same questions they ask of any system: what information it holds, which system holds it, who is affected, and what decision it shapes.
Recommended Free Tools
Three tests do most of the work:
- Information test (CMMC): Does the system process, store, or transmit federal contract information (FCI) or controlled unclassified information (CUI)?
- Personal-information test (state privacy): Does it process personal information about people covered by a state statute?
- Decision test (automated decision-making rules): Is its output used to make, or to substantially facilitate or materially influence, a decision the statute treats as significant or consequential?
CMMC: the obligation follows contract information and the system that handles it
What the DFARS text ties to CMMC
DFARS Subpart 204.75 describes the Cybersecurity Maturity Model Certification (CMMC) as a framework for assessing a contractor’s information security protections, and applies it to unclassified contractor information systems. The subpart was revised November 10, 2025 (DFARS Subpart 204.75). Where a contract carries a CMMC requirement, the current contract clause text at DFARS 252.204-7000 and related CMMC provisions requires the contractor to maintain the specified CMMC level or higher for each contractor information system used to perform the contract that processes, stores, or transmits FCI or CUI. The same text directs that the correct CMMC level flow down to applicable subcontracts and other covered instruments.
The trigger is the information and the system. The contract does not need to mention AI for an AI-enabled system to fall within it.
How an agent gets pulled into scope
The following are applications of the scope test, not examples written into the clause. Each one can bring an agent deployment within a covered system:
Rank #2
- An agent hosted in a tenant that stores CUI, even if the agent only summarizes documents it reads.
- An agent given connectors to a file share, mailbox, ticketing system, or code repository that holds CUI. The connected systems become part of what has to be assessed.
- An agent that writes CUI into a log, memory store, or retrieval index. That store is now a place where CUI is stored.
- An agent operated by a vendor or subcontractor that receives CUI. The flowdown requirement then reaches that party.
Status is continuous, not a one-time sign-off
DFARS requires a contractor to hold current CMMC status and to affirm continuous compliance annually in the Supplier Performance Risk System (SPRS). The currency periods differ: the provision sets different intervals for conditional versus final status, for Level 1 versus Levels 2 and 3, and for affirmations. Treat the clause and your own status record as the controlling schedule, and do not assume a single recertification cycle. Adding an agent that touches CUI can change the system boundary, so confirm the status and affirmation still describe the system as it actually runs.
State privacy law: personal information and decisions, not AI labels
State privacy statutes apply to a business or controller based on jurisdiction, entity thresholds, and the personal information it processes. Automated decision-making technology (ADMT) rules form a narrower layer that attaches when a system is used for a specific category of decision. California and Colorado are the two examples covered here. Other states are not addressed.
Rank #3
California: rules in force, obligations staged
The California Privacy Protection Agency (CPPA) package covering CCPA updates, cybersecurity audits, risk assessments, and ADMT was approved by the Office of Administrative Law, filed September 22, 2025, and took effect January 1, 2026 (CPPA regulations page). The obligations do not all begin on that date. The CPPA’s September 23, 2025 announcement sets out the staged milestones (CPPA announcement, September 23, 2025):
| Obligation | Start or deadline, as stated by the CPPA |
|---|---|
| Risk-assessment compliance | Begins January 1, 2026. Covered businesses must submit an attestation and summary to the CPPA by April 1, 2028. |
| ADMT requirements for businesses using ADMT to make significant decisions | Begin January 1, 2027. |
| Cybersecurity audit certification, businesses with revenue over $100 million | Due April 1, 2028. |
| Cybersecurity audit certification, businesses with revenue between $50 million and $100 million | Due April 1, 2029. |
| Cybersecurity audit certification, businesses with revenue under $50 million | Due April 1, 2030. |
The CPPA’s announcement quotes Jennifer Urban, Chair of the California Privacy Protection Agency Board: “These rules ensure that Californians continue to have the strongest privacy protections in the country while being responsive to the realities of business implementation.” That is the agency’s own framing of its intent, not a statement of what each rule requires.
Rank #4
What counts as ADMT: check the approved text
The November 22, 2024 proposed text defined ADMT as technology that processes personal information and uses computation to execute a decision, replace human decisionmaking, or substantially facilitate human decisionmaking. It expressly included software derived from AI (CPPA proposed text, November 22, 2024). Under that wording, an agent that substantially facilitates a human decision could fall within the concept even if a person makes the final call. A human reviewer therefore should not be assumed to remove obligations. Whether a reviewer’s role changes the result depends on the approved text and its exceptions. The proposed text is useful for understanding the regulator’s direction, but it is not the controlling definition. Confirm the wording in the approved regulations at the CPPA regulations page above before you state a definition, exception, or threshold.
Quick wins for a faster PC:
Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →Repair Windows errors before they cause bigger problemsFix Now →Colorado: a changed statute, with draft rules still in progress
Colorado’s Attorney General reports that SB 26-189, signed in May 2026, repealed and reenacted the prior ADMT provisions with new requirements for ADMT used in consequential decisions. Developers whose ADMT materially influences consequential decisions have obligations, and so do deployers. Consumers gain rights to request and correct inaccurate personal data that ADMT uses (Colorado Attorney General, ADMT and chatbot safety rulemaking). Keep the enacted statute and the draft rules separate:
Best Value
- Enacted law: SB 26-189 was signed in May 2026. The updated ADMT provisions take effect January 1, 2027.
- Draft rules, not final: The Attorney General released interim draft ADMT and chatbot rules on October 6, 2026. Formal comments are accepted through October 26, 2026.
Colorado Privacy Act: profiling rights with a narrow reach
Separately from the ADMT provisions, the Colorado Privacy Act gives consumers rights concerning sale, targeted advertising, and certain kinds of profiling, according to the Attorney General’s Colorado Privacy Act page (Colorado Privacy Act). Whether it reaches a particular agent depends on the entity, the processing context, and the data involved. Do not assume it covers employment data or every AI use.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Comparing the two regimes
| Question | CMMC and DoD contracts | State privacy and ADMT rules |
|---|---|---|
| What decides applicability? | A contractor system used to perform the contract that processes, stores, or transmits FCI or CUI, at the level the contract requires. | A covered entity, personal information about covered individuals, and in ADMT cases a significant or consequential decision use. |
| What is protected? | Federal contract information and CUI in covered systems. | Personal data of consumers and the people affected by covered decisions. |
| What evidence do you keep? | Current CMMC status, the SPRS affirmation, and subcontract flowdowns. | Risk assessments, cybersecurity audits, and consumer-rights processes, where the applicable statute requires them. |
| What sets the clock? | The contract clause and the status and affirmation intervals. | Effective dates, staged deadlines, and rulemaking that can change the text. |
| Where does this article reach? | Federal DoD contracting. | California and Colorado only. |
A scope checklist for an agentic deployment
The steps below are a working synthesis of the scope tests in the cited texts. The statutes and clauses do not prescribe these exact steps.
Quick Recap
- Map the information. Does the agent, or any tool it connects to, access, store, process, or transmit FCI or CUI in a contractor system used on a DoD contract? Record the contract’s required CMMC level and the system boundary the agent sits within.
- Map the personal data. Which personal information does the system process, about whom (consumers, employees, applicants, or others), for what purpose, and in which states?
- Map the decision. Is the output used to make, or to materially influence or substantially facilitate, a consequential or significant decision? The test is about how the output is used, not how the system is built.
- Document the human role. Record what the agent does on its own and what a reviewer actually checks. Test that role against the applicable final text and its exceptions.
- Trace vendors and flowdowns. Identify every vendor or subcontractor that operates the system or receives the data. Review contracts, flowdowns, access permissions, logging, incident handling, retention, and change control.
- Date each obligation. Separate what is in effect now from what is prospective or still in rulemaking, and re-check California’s staged dates and Colorado’s draft-rule status before each release.
Reading the answers
- If FCI or CUI reaches the agent on a contractor system used for a DoD contract: CMMC scope applies to that system at the level the contract requires. Confirm current status before the agent goes live.
- If the agent processes personal information of California residents and substantially facilitates significant decisions: plan for the ADMT requirements that begin January 1, 2027, once you have confirmed the approved text.
- If the agent is used for Colorado consequential decisions: plan for the updated provisions effective January 1, 2027, and track the draft rules through their comment period.
- If none of these tests is met: the deployment is not cleared. The question moves to the general privacy statutes of each state where you do business, which this article does not cover.
Limits of this analysis
- This is not legal advice. CMMC applicability turns on the solicitation or contract, the information type, the system boundary, and the required level.
- Privacy applicability turns on jurisdiction, the entity, the people affected, the data, and the processing or decision use.
- Coverage here is limited to federal DoD provisions and the official California and Colorado materials cited above. It does not establish every state statute, threshold, exemption, or effective date. A nationwide compliance plan requires a separate state-by-state review of primary sources.
“
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.
The Tool Desk
Outbyte Driver Updater FREEFix the driver behind crashes, sound loss and screen glitchesFind Drivers →Outbyte PC Repair FREEClear out junk files and repair common Windows errorsFree Scan →

