AI Automation
Agency, San Francisco.
San Francisco is the global epicentre of AI development, with the highest density of AI-native businesses anywhere. California's CCPA/CPRA adds a strict state-level privacy layer on top of federal HIPAA and FINRA requirements — one of the most demanding compliance stacks in the US.
California's automated decision-making rules came into force on 1 January 2026, and they apply to ordinary business workflows, not just models.
The California Privacy Protection Agency's regulations covering automated decision-making technology took effect on 1 January 2026, with the obligations attaching to significant decisions phasing in through 2027. This is the substantive difference between building in California and building in most other states: there is an operative rule about automated decisions rather than a general privacy statute applied after the fact.
Two further statutes landed on the same date. AB 2013 requires documentation of the data used to train generative AI systems, and SB 53 imposes transparency and safety obligations on frontier models. Most of our clients are not training frontier models, but the training-data documentation requirement reaches anyone who fine-tunes or ships a generative system, and it is easier to satisfy by recording provenance during the build than to reconstruct afterwards.
All of this sits on top of CCPA and CPRA, which already give Californians deletion, access and opt-out rights that an automation has to be able to honour. A workflow that cannot locate and delete one person's data across every system it touches is not compliant, regardless of how well the model performs.
Who you answer to here
- California Privacy Protection Agency
- ADMT regulations in force since 1 January 2026
- California Attorney General
- CCPA and CPRA enforcement
- FINRA and SEC
- For the financial services and fintech cluster
Sources
- 01CCPA regulations, including automated decision-making technology, California Privacy Protection Agency
- 02California Consumer Privacy Act (CCPA), California Attorney General
Six industries.
One engineering team.
Healthcare
Clinical admin, patient flow, and compliance automation.
HIPAA Privacy and Security Rules, 21st Century Cures Act interoperability mandates, and ONC information-blocking rules govern all healthcare AI deployments.
- Appointment scheduling and patient reminders
- Clinical documentation and records processing
- Referral routing and prior authorisation
Fintech
KYC, AML, reconciliation, and regulatory reporting.
SEC Rule 17a-4, FINRA Rules 3110 and 3120, BSA/AML requirements, and SOX Section 302/404 for publicly listed companies govern all financial AI automation.
- KYC/AML onboarding and ongoing monitoring
- Transaction reconciliation and exception handling
- Regulatory reporting and audit trail generation
Legal
Document review, client intake, and billing automation.
ABA Model Rules 1.1 (competence) and 1.6 (confidentiality), FRCP e-discovery requirements, and state bar ethics opinions on AI use in legal practice.
- Contract review and clause extraction
- Client intake and matter management automation
- Billing, time capture, and accounts receivable
Manufacturing
Predictive maintenance, quality control, and supply chain.
OSHA 29 CFR regulations, FDA 21 CFR Part 11 for electronic records and signatures, ISO 9001, and EPA environmental reporting requirements.
- Predictive maintenance and asset health monitoring
- Quality control inspection and defect classification
- Supply chain and inventory optimisation
Education
Admissions, student support, and administrative automation.
FERPA (Family Educational Rights and Privacy Act), COPPA for under-13 users, Section 508 accessibility requirements, and applicable state education codes.
- Admissions processing and applicant scoring
- Student support routing and early intervention alerts
- Administrative reporting and compliance documentation
E-commerce
Inventory, pricing, fulfilment, and customer service automation.
CCPA/CPRA (California), FTC Act Section 5, PCI DSS for payment data, and COPPA for platforms with under-13 users.
- Inventory forecasting and replenishment automation
- Dynamic pricing and margin optimisation
- Customer service triage and returns processing
Brief, engineer, ship.
Brief
Tell us what you are trying to stop doing manually. One hour, no deck required.
Week 1Engineer
We map the process, confirm the compliance requirements, and build it to a fixed spec.
Weeks 2–8Ship
You go live with a compliant, auditable automation. We stay alongside for support and iteration.
Week 8+