Significant Decisions: The Case for Bargaining over Algorithmic Control
July 21, 2026
By Ellie Spangler
This publication is part of the 2026 Roosevelt Network Undergraduate Emerging Fellowship Journal.
Introduction
A warehouse worker receives an automated performance alert designating her pace of work as substandard. Her handheld scanner counts the seconds between each completed task, logged against a productivity requirement no one has explained to her, set by people she will never meet and published nowhere she can find. When enough seconds accumulate, the system generates a written warning automatically, and then another (Lecher 2019). Today, these systems of minuscule calculations increasingly add up to the operating conditions for American labor. The term “algorithmic management” initially described the software used by gig-work platforms for managerial functions including allocation of work, performance evaluation, and informational support (Lee et al. 2015). A decade later, algorithmic management is in use far beyond the platform context. Across warehouses, call centers, retail stores, and offices, automation shapes scheduling, performance evaluation, task assignment, and termination decisions (Jarrahi et al. 2021; Parent-Rocheleau and Parker 2022).
Article 11, recently added to the regulations implementing the California Consumer Privacy Act (CCPA), represents an attempt to extend existing consumer and privacy protections to automated decision-making contexts, including automated systems used for worker management. Compliance becomes mandatory in January 2027, giving unions a limited opportunity to reconsider what worker power looks like in a changed regulatory environment. The regulations speak to individual workers, giving them the right to know about the automated technologies that control their work and, under certain circumstances, the right to opt out of automated management. Once Article 11 takes full effect, unions should be prepared to treat expanded disclosure and opt-out as leverage for contract terms that employers are not currently required to offer, as well as a basis for legislative reforms that transform individual rights into collective data rights.
The algorithms driving workforce-wide transformation, particularly machine-learning systems, use advanced statistics to reproduce human processes of pattern recognition, redistributing when human decision-making occurs and often obscuring that decision-making process from those experiencing its effects. In the workplace, surveillance systems transform routine work activities into data streams: records of productivity, outputs, ratings, location, and communication (Kellogg, Valentine, and Christin 2020). Some machine-learning systems are trained—using this historical data—to identify combinations of attributes correlated with some set of specified outcomes. Once trained, the system can apply the resulting model to current employees, generating scores, recommendations, and predictions to automate a decision or structure a manager’s decision-making (Barocas and Selbst 2016). Crucially, the humans who shape automated decision-making tools (ADMTs) exercise their judgment upstream, through formative choices including which data the model is trained on and the outcomes it is built to optimize (Barocas and Selbst 2016; Seppälä and Małecka 2024).
Power, in this automated infrastructure, is embedded in system design and exercised through the persistence of encoded decision logic over time. Workers subject to algorithmic management can be measured against a system built from their own collective data and calibrated to reproduce the employer’s priorities (Barocas and Selbst 2016; Kellogg, Valentine, and Christin 2020). Workers retain little control over their data’s use and receive no compensation in return for the data they provide, other than the continued ability to perform data-generating work (Bernhardt, Kresge, and Suleiman 2022; Arrieta-Ibarra et al. 2018). Despite relying on the power of workers’ collective data, automated management leaves workers without access to information about how they are monitored or evaluated, foreclosing even the informational basis required for a collective response. The data workers produce collectively becomes the employer’s instrument of individualized control (Bernhardt, Kresge, and Suleiman 2022; Kellogg, Valentine, and Christin 2020).
Article 11 of the regulations implementing the CCPA requires employers to disclose information about how ADMTs operate—a significant legal foothold for workers. Unions hold the power to transform disclosures into enforcement mechanisms the CCPA cannot provide. Individually, each disclosure reveals some insight into how an ADMT evaluated one worker. CCPA’s partial disclosures, aggregated across a workforce, become evidence of how ADMTs govern, revealing the structural patterns behind individual cases. Ten thousand workers collectively requesting access to information about algorithmic evaluations can generate an informational basis for contract provisions that no individual employee can negotiate alone, narrowing the gap between consumer protection and enforceable labor rights. CCPA’s disclosures will only become organizing tools when aggregated and used to inform negotiation. Businesses must comply with the ADMT regulations by January 1, 2027, and unions must immediately begin this work. Those who wait will find CCPA’s formal regulation already in place, and the function they could have demanded increasingly foreclosed.
The Terms and Conditions of Automated Management
The opacity of workplace ADMTs is reinforced by a legal landscape designed for an industrial economy of discrete transactions, identifiable decision-makers, and individual harms, with little architecture to capture collective and cumulative informational harms (Cohen 2019). In the digital labor-platform sector, employers deploying ADMTs have often positioned themselves as platform intermediaries (Dubal 2022) and classified workers as independent contractors when automated decisions govern the workplace. These workers lose access to the collective bargaining protections of the National Labor Relations Act (NLRA) and many core employment law protections (HRW 2025). For those who remain employees under law, the NLRA does not clearly identify algorithmic management as a mandatory subject of bargaining, meaning workers with union representation do not hold a guaranteed right to bargain over automated systems (Mignucci 2025).
Beyond collective bargaining, only fragments of legal protection can be assembled from frameworks built for other purposes and applied to algorithmic management by approximation. ADMTs are technically subject to both the Uniform Guidelines on Employee Selection Procedures, which regulates tests and selection tools used in hiring decisions, and Title VII’s disparate impact doctrine, which requires employer justification of employment practices that disadvantage protected groups. Both require proof of a harm to take effect—proof often shielded by trade secret and intellectual property law in the algorithmic management context. A discriminatory pattern in an ADMT’s outputs runs through layers of inaccessible proprietary design choices, rendering legal remedies dependent on evidence the legal system makes hardly accessible. Some privacy laws apply to the handling of personal data regardless of how a worker is classified. Designed for one-time transactions a consumer can exit, these legal frameworks are mismatched with automated management’s continuous and cumulative effects on working conditions, which shape a dependent and ongoing relationship between employer and employee where a worker cannot exit without loss of income. But, for workers excluded from employment protections, the legal claim over the collection and processing of their data provides another avenue of accountability.
Early state and local laws attempting to address automated management do not fare better at filling legal gaps. Illinois’s Artificial Intelligence Video Interview Act requires employers to notify candidates and obtain consent before using AI to analyze video interviews, among other obligations (820 ILCS 42/5), but applies at a single point in the hiring process and has no bearing on the continuous automated management of employees. New York City’s Local Law 144 requires bias audits of automated employment decision tools and public disclosure of results, but allows employers to determine for themselves whether their systems qualify as regulated tools, making noncompliance difficult to identify (Wright et al. 2024). In both cases, employers might formally comply with regulation while experiencing no functional constraints on their use of automation. A pattern of disclosure obligations, employer self-assessment, and coverage limited to decision events recurs across early attempts to regulate automated management. Regulations built for consumers and applied to workers consistently produce procedural oversight without substantive constraints.
On September 22, 2025, California’s Office of Administrative Law updated and approved the California Privacy Protection Agency’s (CPPA) ADMT regulations under the CCPA, marking the first time California established legal obligations governing employers’ use of automated decision-making. These regulations serve as the culmination of a five-year effort, delayed well beyond its original deadline, marked by persistent lobbying pressure from technology and business groups (CPPA 2025; Andrews 2025). The regulation’s design reflects extensive stakeholder influence over its scope, exemptions, and enforcement mechanisms. The regulations apply to any CCPA-covered business operating in California that meets size thresholds, regardless of whether the individual subject to automated decision-making is classified as a consumer, contractor, applicant, or employee (Cal. Code Regs. tit. 11, §7001 et seq.).
The regulation’s coverage is narrowed through a two-part, compounding definition. The category of regulated technologies is limited to those which “process personal information and use computation to replace human decision-making or substantially replace human decision-making” (§7001[e]). A technology “substantially replaces” human decision-making when a business uses its output to make a decision without qualifying “human involvement.”1 Applicability is further narrowed to “significant decisions” which, in the employment context, include hiring, work allocation and compensation,2 promotion, demotion, suspension, and termination (§ 7001[ddd][4][A]–[D]). Covered employers must provide pre-use notice before collecting workers’ personal information, risk assessments of ADMTs, opt-out rights for workers in some circumstances, and access to information about decisions after they are made (§§7150–7157; §§7220–7222). While these protections may sound substantive on paper, they dissolve on contact with the workplace.
Form Without Function: A Policy Analysis of the CCPA
California’s ADMT regulations offer workers three protections against automated management: the right to know how ADMTs make decisions, the power to contest those decisions, and protection from encoded discrimination. At every stage, CCPA places regulatory authority in the hands of the party being regulated, supplying no external verification or consequences for harms imposed on workers. Before CCPA applies at all, employers hold the pen. They can assert sufficient human involvement in their systems, classify their technology as excluded from regulatory obligations, or claim their automated management is too diffuse to produce a “significant decision.” No authority can verify these claims. Workers the regulation reaches have access to the framework’s single claim to oversight, which is a risk assessment that the deploying employer produces and is not obligated to communicate. The regulation delivers four formal rights, each one designed for a consumer who can afford to walk away.
The regulations’ “human involvement standard” narrows its scope and serves as an initial point where employers self-assess their regulatory obligations. CCPA must clearly define a distinction between human and automated decision-making for regulatory purposes, but in practice this distinction is unclear. ADMTs are dependent on human decisions about data gathering and labeling, decisions which encode human values into the system (Seppälä and Małecka 2024; Barocas and Selbst 2016). CCPA assesses the presence of a human reviewer at the decision output stage, leaving upstream decisions encoded in a system’s design and training data outside its regulatory scope (§7001[e][1][A]–[C]). The text implicitly acknowledges that human judgment is more unevenly distributed than the human involvement threshold can encompass. Article 11 requires pre-use notice describing the “human’s role in the decision-making process” even when an ADMT does not satisfy the definition of “human involvement” (CPPA 2025, §7220[c][5][B]). A system which functionally delivers automated results, presenting a human reviewer with a pre-generated range of choices, may also fall outside the definition of ADMT, because the “human involvement” standard evaluates the existence of a formal reviewer instead of the functional capacity to intervene. The unstable boundary between human and machine involvement is not easily identified from outside an organization, so an employer’s self-classification of formal “human involvement” in automated decisions partially determines the CCPA’s regulatory authority. Workers cannot challenge an employer’s assertion of human involvement, and the regulations provide no accompanying verification procedure to identify misclassification (§ 7001[e][1]).
A second route out of regulatory coverage allows employers to argue that whatever their system does, it belongs to a category CCPA does not regulate. Excluded technologies, including calculators, databases, and spreadsheets, are named, but left undefined in the regulatory text. An employer using a compensation algorithm based on productivity data may escape ADMT classification if they characterize the system as a rules-based calculation implemented through a calculator or a spreadsheet. The regulations do not provide a mechanism requiring an employer to justify their system’s classification, and misclassification produces no additional assessment or regulatory consequence. As the Local Law 144 audit documented in an analogous context, employer self-classification with no external check produces a rational incentive to underclassify. The exclusion list’s one limiting condition, “provided that they do not replace human decision-making,” points back to the employer’s ability to meet CCPA’s unverifiable, self-assessed human involvement standard. The regulated party may decide if their system qualifies as an ADMT and what level of human involvement is sufficient in whichever configuration minimizes their regulatory obligation.
The regulations’ “significant decision” definition creates yet another route out of regulatory coverage by assuming ADMTs culminate in specific employment events (§7001[ddd]). In a recent OECD survey, 90 percent of American managers surveyed reported using algorithmic tools for monitoring, evaluation, or instruction (Milanez, Lemmens, and Ruggiu 2025). Many of these tools operate continuously, producing no single output that constitutes a significant decision. Under continuous automated management, a worker cannot point to a moment an ADMT began to shape opportunities, establish when harm occurred, identify outputs that triggered harm, or mount a challenge to a specific decision because no specific decision was ever made. Systems whose effects are distributed across time without producing a single decision event are left unregulated. Limiting oversight to specific “significant decisions” is a misrepresentation of how algorithmic management operates. Only output is regulated, while the choices about ongoing data extraction and use that produce it are obscured by CCPA’s legal architecture. Where no clean decision moment exists, CCPA has no clear point of attachment.
Risk assessment delivers a worker’s first operational protection in automated management scenarios the regulations’ definitions do not already exclude. A business deploying an ADMT conducts, documents, and approves CCPA’s risk assessment process in its entirety, without independent review (§ 7152[a]). Assessments are only required “once every three years” or within 45 days of any “material change” in data processing (§7155[a]2]–[3]), a schedule that can only provide snapshots of continuously operating systems. The regulations’ stated goal for risk assessment, “restricting or prohibiting the processing of personal information if the risks to privacy of the consumer outweigh the benefits” (7154[a]), implies a threshold after which ADMT deployment must be constrained. The regulatory text imposes none. Businesses may proceed with their use of ADMTs, and CCPA specifies no consequences regardless of how the assessment concludes. The risk assessment process requires no input from workers subject to automated decision-making (§ 7151[b]), although employees who operate an ADMT must be consulted (§7151[a]). An assessment conducted without input from the workers with the most direct knowledge of daily work under automated management is unlikely to surface harms that independent oversight would identify. After assessment is complete, CCPA does not require its submission of the risk assessment report unless it is specifically requested (§ 7157[e]).3 No record of how businesses assess risks and benefits is created. No mechanism checks compliance. A procedure conducted and shelved by the regulated party provides oversight in name only.
The first worker-facing right the regulations extend is the pre-use notice, preliminary information about how workers’ personal data will be used before automated management begins (§7220[b][2]). In the workplace, pre-use notice most likely occurs during onboarding, a moment when workers are least positioned to evaluate or reject the terms of their employment. Under the regulations, a single consolidated notice may cover all future applications of an ADMT, regardless of how its design or purpose changes (§7220[e]). The information a worker encounters in pre-use notice is limited by exemptions for information revealing trade secret protections or security monitoring. Under these exemptions, employers can fulfill their legal obligations by disclosing categories of data inputs without explaining how their ADMT uses data (§7220[d][1], §7220[d][2]), §7220[c][5][A]). The extent to which employees are informed depends on how an employer determines whether exemptions apply. The regulations do not require external verification of employers’ application of exemptions, and employees have no opportunity to dispute absent information. Information that is disclosed is not required to remain accessible to employees throughout their employment. Employers may satisfy the notice requirement by linking more specific information to a separate webpage (§7220[c][5]), but this information can legally disappear before it is ever consulted again. An employee may move through an entire employment relationship having only technically received notice of an ADMT at onboarding. Pre-use notice, as CCPA constructs it, produces a record of formal consent, but withholds the information true consent depends upon.
The regulations’ access right offers a second encounter with the information pre-use notice withholds. After a significant decision occurs, workers may access the personal information used and a plain-language explanation of how the output was reached (§7222[a], [b][2]–[3]). As with pre-use notice, the employer determines the explanation’s contents. Trade secret protections allow employers to withhold information about system logic (§7222[c][1]), preventing employees from accessing the information about upstream design required to establish discriminatory patterns or understand how a specific decision was produced. The access right only applies to discrete decision events, so employees subject to continuous automated management cannot access information about how outputs accumulate into the conditions for a significant decision. Where an employer uses an ADMT to make decisions pertaining to a specific worker more than four times within a 12-month period,4 they may replace the explanation of a worker’s specific decision event with a statistical summary of how the system treated similar workers on average (§7222[j]). This regulatory choice responds to the workers most heavily impacted by automated evaluation with the least individualized disclosure. A worker whose decision outcomes deviate significantly from the system’s average parameters is provided no basis for establishing whether the system treated them differently from similarly situated workers. The access right carries no right to reevaluation or correction. Limited knowledge of how a decision was reached, in the absence of any mechanism to challenge it, does not return power to the worker.
The worker’s sole means of restricting the use of automated management is through the regulations’ opt-out right, which provides the ability to insist a significant employment decision be made by a person. For many of the most consequential employment decisions, the opt-out right does not apply. Hiring, compensation, and work allocation decisions are exempted from opt-out when an ADMT is used “solely” for these objectives, “works for the business’s purpose,” and “does not unlawfully discriminate” (§7221[b][2]–[3]). Any employer using an ADMT for these functions is eligible to claim the exemption as long as the system generates no output that, on its surface, disadvantages workers based on protected characteristics. The employer determines if their ADMT unlawfully discriminates, a claim that cannot be independently verified or contested by employees. Even where the opt-out right is nominally preserved, the regulations do not specify whether alternatives to ADMT use must be comparable, and where an exemption applies, no alternative need be described (§7220[c][5][C]). To prove an ADMT produced discriminatory outcomes, an employee needs access to its training data, parameters, and output history, information either protected as a trade secret or simply outside what CCPA requires employers to disclose to workers. While CCPA retains the form of legal protection, it removes access to all informational preconditions for mounting an antidiscrimination claim.
Where the opt-out right remains intact, the regulations permit employers to substitute it for an appeal process (§7221[b][1]), trading a right that limits exposure to automated management for one that responds to its consequences at the worker’s moment of maximum informational disadvantage. When a worker files an appeal, they are unable to access information that shaped the decision, like training data or parameters. Harms related to system design are outside the appeal process’s purview and the reviewer is under no obligation to search for them. The regulations leave the review process in the hands of a reviewer employed within the same organizational hierarchy that deployed the ADMT. Once the appeal is processed, the regulations require a response within 45 to 90 days (§7221[b]), but it does not specify how the outcome should be communicated or whether any automated decision must be overturned. Without mandatory reporting of appeal outcomes, no aggregate record can determine if the process functions as a meaningful constraint on automated management. Opt-out rights and appeal processes each address distinct phases of automated management and mitigate a particular type of risk (Barocas and Selbst 2016). When the appeals process replaces opt-out, workers bear the burden of correcting ADMT harms, while employers continue using the same ADMTs unchallenged.
The regulations shift every point of accountability for ADMT harms from the institution deploying it to the worker affected by it. The CCPA’s underlying consumer protection framework was designed for consumers who have the choice to withhold consent and not transact. Workers cannot. Even if an employee challenges an automated performance review, they still need their job. The rights CCPA affords to workers are sized for one person and imposed on systems that govern thousands. Insufficient pre-use notices, appeals without independence requirements, and aggregate summaries of input variables cannot limit automated systems operating at workforce scale. CCPA does not even offer this much to workers whose employers claim nominal human involvement, underclassify their systems, or use systems that never culminate in a “significant decision.” In cases when these regulations are applicable, they provide legal protection in form without its function. The average worker subject to automated decision-making in California has only the partial right to be informed, the partial right to appeal, and no meaningful capacity to exercise either right.
Bargaining for the Algorithm: Imagining Collective Solutions
Disclosure without collective action leaves power in the hands of employers. For workers who currently have little legal claim over the use of ADMTs, CCPA’s disclosures provide a legal foothold. Using the information provided by the CCPA, unions must use collective pressure at each gap in existing legal coverage. CCPA’s partial disclosures, processed collectively across thousands of workers, can become leverage at the bargaining table and evidence for the legislature. Beyond both, the effort to reclaim workers’ collective data remains.
The resolution of ADMT’s status as a subject of bargaining under the NLRA will shape the practical reach of any future union strategy in response to automated management. Fibreboard Paper Products Corp. v. NLRB, 379 U.S. 203 (1964), offers a starting point for determining when bargaining over algorithmic management might be legally compelled. In the case, the Court held that contracting out work performed by members of an existing bargaining unit was a mandatory subject of bargaining under the NLRA, even though the decision did not fundamentally restructure the business. In First National Maintenance Corp. v. NLRB, 452 U.S. 666 (1981), the Court established a balancing test for employment decisions beyond replacing one set of workers with another. According to this test, bargaining is only legally compelled when the benefits to the collective bargaining process outweigh the burden on the employer’s conduct of business.
Employers will likely invoke this balancing test, and the principle behind it, that certain business decisions belong exclusively to management, to oppose negotiations over ADMT deployment in the workplace. However, the Court left automation explicitly unresolved in First National Maintenance opinion, noting that decisions like automation would be “considered on their particular facts.” Unions are well positioned to argue that bargaining over the ADMTs that set working conditions is essential to meaningful collective negotiation, and that the benefits of advance bargaining outweigh the operational burdens imposed on employers. A union that may bargain over shift start times but not the algorithm that establishes a worker’s schedule or assesses their performance has a right to bargain that stops short of any structural intervention on workers’ behalf. No Supreme Court or NLRB precedent categorically resolves whether ADMT deployment as a whole is a mandatory subject, and the record of ADMT use that unions are able to build with the additional disclosures provided by the CCPA will provide an evidentiary foundation for eventual legal challenge.
Private-sector legislation must also account for NLRA preemption. Under Lodge 76, International Ass’n of Machinists & Aerospace Workers v. Wisconsin Employment Relations Commission, 427 U.S. 132, 140–48 (1976), states generally may not regulate conduct that Congress intended to leave to the economic choices of labor and management. States ordinarily may, however, enact minimum labor standards, rules that bind union and nonunion employers alike, like a minimum wage or a notice period, regardless of bargaining status. California’s No Robo Bosses Act (S.B. 947, 2026), now pending in the Assembly after clearing the state Senate, would bar employers from relying solely on an automated system to discipline, terminate, or deactivate a worker and require human review before either decision takes effect. The bill is sponsored by the California Federation of Labor Unions, AFL-CIO (Cal. Fed. of Labor Unions, AFL-CIO 2026), and other unions should support its passage as an attempt to achieve one of the most significant pending California proposals directed specifically at automated discipline, termination, and deactivation and applying to all private-sector employers.
For public employees, unions have a clear legislative target to expressly clarify and expand bargaining rights over the adoption, material modification, workplace use, and employment effects of covered ADMTs. The NLRA excludes state and local government employers from its coverage, so unions representing this workforce can press California to amend the Meyers-Milias-Brown Act (Cal. Gov. Code §§ 3504–3505), the Educational Employment Relations Act (Cal. Gov. Code § 3543.2), the Ralph C. Dills Act (Cal. Gov. Code § 3516), and the Higher Education Employer-Employee Relations Act (Cal. Gov. Code § 3562(e), (g), (q)–(r)) to add ADMT deployment as a mandatory subject of bargaining. These four statutes are applicable to state employees, K–12 and community college employees, city and county employees, and the University of California and California State University systems. These amendments could expand rights for a substantial portion of California’s public workers without waiting for federal reform.
CCPA can reach further than any single bargaining unit if its disclosure provisions are converted from individual rights into collective infrastructure. Unions can begin expanding collective worker power by advocating for reforms to Article 11 to require mandatory registration of every automated management tool an employer deploys in an accessible public database. This registration program should require disclosure of an ADMT’s purpose, the categories of personal information it processes, and the decision categories it informs. The documented weakness of New York City’s Local Law 144 (NYC Admin. Code §§ 20-870–20-875), where the New York State Comptroller identified the inability to identify noncompliant employers as a fundamental enforcement obstacle, strengthens the case for mandatory registration (Office of the New York State Comptroller 2025). Registration solves that problem directly, making disclosure the default. The registry that results is also a record on which future legal challenges to automated management can be built. However, a registration system will only document tools CCPA recognizes as ADMT, and CCPA’s “significant decision” framework currently fails to capture continuously operating ADMTs. Unions should advocate for an amendment clarifying that ADMT is used to make a significant decision when its output is retained, incorporated into a worker profile, or subsequently relied upon as a material input in a covered decision.
Legislative reforms will be slow moving, but collective bargaining agreements give unions an immediate means of limiting automated management, available under existing California and federal labor law right now.5 Unions can negotiate contract provisions that go substantially beyond what CCPA requires, starting with joint ADMT review committees, modeled in part on the optional labor-management safety and health committee structure recognized in California’s Injury and Illness Prevention Program regulation (Cal. Code Regs. tit. 8, §3203(c)). These standing labor-management bodies should feature defined composition and meeting frequency, access rights to specified categories of employer documentation, and a right to independent investigation. At minimum, the agreement should require the employer to disclose what a system is and how it was built including its purpose, the categories of personal information it processes, its decision parameters, and vendor documentation where the system is third-party. It should also require the employer to disclose what the system does once deployed: aggregate output data on a quarterly basis, disaggregated by decision type and, where legally permissible, by the demographic characteristics of affected workers; the full risk assessment conducted under CPPA before deployment of any new system or material modification of an existing one (Cal. Code Regs. tit. 11, §§ 7150–7157); and the appeal outcome data CPPA currently does not require to be reported at all (Cal. Code Regs. tit. 11, § 7221(b)(1)), disaggregated by decision type and protected class. Each of these categories describes data workers generate simply by doing their jobs, material ADMTs run on.
Unions should use Article 11 notices and access responses to identify covered systems and then invoke bargaining and information-request rights to seek the employer’s underlying risk assessments and related documentation. They should also pursue algorithmic impact clauses modeled partly on California’s pay-data reporting framework (Cal. Gov. Code §12999). The proposed clause would require the employer to perform a disparity analysis of ADMT outputs broken down by protected class, but limited to significant decision categories prior to system deployment. Unions across sectors have negotiated consultation and codetermination rights over new technology dating back decades, evidence that employers will agree to pre-deployment consultation and ongoing monitoring rights once unions have the leverage to demand them (Kresge 2020; Khan and Bernhardt 2025). Past and existing agreements are imperfect and leave significant gaps, but they demonstrate the feasibility of prospective ADMT governance as a subject of collective bargaining (Kresge 2020).
The proposals above function within CCPA’s framework to generate information unions can use to inform future actions at scale, but the framework itself reaches only as far as the deploying employer. Future regulations must move upstream, broadening disclosures to include information about a model’s goals, the choice of training data, and the factors controlling its results. However, disclosure can only describe data extraction. When an ADMT is built from data generated by workers performing their jobs, the system consumes a product of their labor. Any serious regulatory response to ADMTs would recognize this data extraction as a form of value transfer, one that necessitates worker consent and an equivalent return. If ADMTs achieve mandatory subject status, unions must consider how that bargaining power should extend to the data the systems generate, not just their outputs. A union should be able to bargain over whether worker data can be sold to a data broker, fed into a wage-suppression algorithm, or used to build the next generation of ADMTs. Privacy law treats this as a matter of individual consent, and labor law cannot currently accommodate the claim. Both fail to treat data as a collectively bargained asset, something a union negotiates control over and is paid for, the way it would negotiate over any other thing of value the employer extracts from a worker’s labor. Establishing this form of worker protections will only be won at the bargaining table or in the streets.
Conclusion
The CCPA’s ADMT regulations took effect January 1, 2026, but businesses already using automated decision-making systems are not required to comply until January 1, 2027. Once compliance becomes mandatory, employers will draft their pre-use notices and structure their risk assessments around the regulation as written. The regulations’ compliance architecture and its flaws will be institutionalized before most affected workers even know the regulation exists.
The proposals outlined here work within existing legal architecture because workers cannot wait for that architecture to be rebuilt, but disclosure-based frameworks like CCPA are completely inadequate to the task of regulating algorithmic management. Legal disclosure merely provides more information about ADMT’s existence; it does not grant any authority to regulate it. Only mandatory-subject status under the NLRA and California’s public-sector labor laws, collective bargaining agreements that surpass CCPA requirements, and legislative changes that transform CCPA’s individual disclosure rights into collective infrastructure can build workers’ power.
In pursuing collective power, workers fundamentally require control over the asset automated management runs on. The data ADMTs use is often produced by workers, collectively, in the course of doing their jobs, a fact current law treats as incidental. Mandatory-subject status creates an avenue through which unions might fight more expansively for data ownership as a subject of bargaining. But at present, unions are the institution positioned to aggregate disclosures into evidence, negotiate joint review committees into contracts, and press registration and amendment into law. Those who wait will find the regulations’ compliance architecture already built around them, and the question of who owns worker data will remain answered, by default, in the employer’s favor.
Footnotes
- Retaining human decision-making power requires a reviewer to “know how to interpret and use the technology’s output to make the decision”; “review and analyze the output of the technology, and any other information that is relevant to make or change the decision”; and “have the authority to make or change the decision based on their analysis…” (CPPA 2025, §7001[e][1][A]–[C]). ↩︎
- Compensation includes “salary, hourly or per-assignment compensation, incentive compensation such as a bonus, or another benefit (‘allocation/assignment of work and compensation’)” (§7001[ddd][4][B]). ↩︎
- An annual submission of summary information including number of assessments, data categories, and executive attestation is required, but the full risk assessment report is only submitted upon Agency request (§7157[a]–[b], [e]). ↩︎
- A continuous monitoring system, by definition, generates outputs far more frequently than four times per year. ↩︎
- The NLRA requires employers to bargain in good faith over wages, hours, and other terms and conditions of employment (29 U.S.C. §158(d)), and the NLRB has held that workplace surveillance technology implicating working conditions triggers a duty to bargain (NLRB, Endurance Environmental Solutions, LLC, 373 NLRB No. 141 (2024)). ↩︎
References
Andrews, Caitlin. 2025. “CPPA Board Finalizes Long-Awaited ADMT, Risk Assessment Rules.” IAPP, July 25. https://iapp.org/news/a/cppa-board-finalizes-long-awaited-admt-risk-assessment-rules.
Arrieta-Ibarra, Imanol, Leonard Goff, Diego Jiménez-Hernández, Jaron Lanier, and E. Glen Weyl. 2018. “Should We Treat Data as Labor? Moving Beyond ‘Free.’” AEA Papers and Proceedings 108: 38–42. https://doi.org/10.1257/pandp.20181003.
Barocas, Solon, and Andrew D. Selbst. 2016. “Big Data’s Disparate Impact.” California Law Review 104: 671–732. http://dx.doi.org/10.2139/ssrn.2477899.
Bernhardt, Annette, Lisa Kresge, and Reem Suleiman. 2022. Data and Algorithms at Work: The Case for Worker Technology Rights. Berkeley: UC Berkeley Labor Center. https://laborcenter.berkeley.edu/data-algorithms-at-work.
California Privacy Protection Agency (CPPA). 2025. “CCPA Updates, Cybersecurity Audits, Risk Assessments, Automated Decisionmaking Technology (ADMT), and Insurance Regulations.” https://cppa.ca.gov/regulations/ccpa_updates.html.
Cohen, Julie E. 2019. Between Truth and Power: The Legal Constructions of Informational Capitalism. New York: Oxford University Press. https://doi.org/10.1093/oso/9780190246693.001.0001.
Dubal, Veena B. 2022. “Economic Security & the Regulation of Gig Work in California: From AB5 to Proposition 22.” European Labour Law Journal 13 (1): 51-65. https://doi.org/10.1177/20319525211063111.
Human Rights Watch (HRW). 2025. The Gig Trap: Algorithmic, Wage and Labor Exploitation in Platform Work in the US. New York: HRW. https://hrw.org/report/2025/05/12/the-gig-trap/algorithmic-wage-and-labor-exploitation-in-platform-work-in-the-us.
Jarrahi, Mohammad Hossein, Gemma Newlands, Min Kyung Lee, Christine T. Wolf, Eliscia Kinder, and Will Sutherland. 2021. “Algorithmic Management in a Work Context.” Big Data & Society 8 (2). https://doi.org/10.1177/20539517211020332.
Kellogg, Katherine C., Melissa A. Valentine, and Angèle Christin. 2020. “Algorithms at Work: The New Contested Terrain of Control.” Academy of Management Annals 14 (1): 366–410. https://doi.org/10.5465/annals.2018.0174.
Khan, Mishal, and Annette Bernhardt. 2025. The Current Landscape of Tech and Work Policy in the U.S.: A Guide to Key Laws, Bills, and Concepts. Berkeley: UC Berkeley Labor Center. https://laborcenter.berkeley.edu/tech-and-work-policy-guide.
Kresge, Lisa. 2020. Union Collective Bargaining Agreement Strategies in Response to Technology. Berkeley: UC Berkeley Labor Center. https://laborcenter.berkeley.edu/union-collective-bargaining-agreement-strategies-in-response-to-technology.
Lee, Min Kyung, Daniel Kusbit, Evan Metsky, and Laura Dabbish. 2015. “Working with Machines: The Impact of Algorithmic and Data-Driven Management on Human Workers.” In Proceedings of the 33rd Annual ACM Conference on Human Factors in Computing Systems, 1603–12. New York: ACM. https://doi.org/10.1145/2702123.2702548.
Parent-Rocheleau, Xavier, and Sharon K. Parker. 2022. “Algorithms as Work Designers: How Algorithmic Management Influences the Design of Jobs.” Human Resource Management Review 32, no. 3: 100838. https://doi.org/10.1016/j.hrmr.2021.100838.
Lecher, Colin. 2019. “How Amazon Automatically Tracks and Fires Warehouse Workers for ‘Productivity,’” The Verge, April 25, https://theverge.com/2019/4/25/18516004/amazon-warehouse-fulfillment-centers-productivity-firing-terminations.
Mignucci, Melanie. 2025. “Extraordinary Times, Extraordinary Measures: Protecting the Right to Organize in the Age of Algorithmic Management.” Columbia Journal of Law and Social Problems 58 (3). https://jlsp.law.columbia.edu/files/2025/05/Mignucci.pdf.
Milanez, Anna, Anneleen Lemmens, and Chiara Ruggiu. 2025. “Algorithmic Management in the Workplace: New Evidence from an OECD Employer Survey.” OECD Artificial Intelligence Papers, No. 31. Paris: OECD Publishing. https://doi.org/10.1787/287c13c4-en.
Office of the New York State Comptroller. 2025. Enforcement of Local Law 144 — Automated Employment Decision Tools. Division of State Government Accountability. https://osc.ny.gov/state-agencies/audits/2025/12/02/enforcement-local-law-144-automated-employment-decision-tools.
Seppälä, Päivi, and Magdalena Małecka. 2024. “AI and Discriminative Decisions in Recruitment: Challenging the Core Assumptions.” Big Data & Society 11 (1): 1–12. https://doi.org/10.1177/20539517241235872.
US Bureau of Labor Statistics (BLS). 2026. “Union Members Summary 2025.” US Department of Labor. https://bls.gov/news.release/union2.nr0.htm.
Wright, Lucas, Roxana Mika Muenster, Briana Vecchione, Tianyao Qu, Pika (Senhuang) Cai, Alan Smith, Jacob Metcalf, et al. 2024. “Null Compliance: NYC Local Law 144 and the Challenges of Algorithm Accountability.” In Proceedings of the 2024 ACM Conference on Fairness, Accountability, and Transparency, 1701–13. New York: ACM. https://doi.org/10.1145/3630106.3658998.
Acknowledgments
Many thanks to the Roosevelt Network team for their investment in my ideas and growth as a writer, especially Eric Paul, Lina Hunt, Katie Kirchner, Robert-Thomas Jones, Alex Trefftz, and Elijah Wilson. I wish to express my appreciation for each of the Roosevelt fellows I have engaged with over three years, many of them dear friends. Each fellow inspires me with their grit, curiosity, and willingness to carry a policy conversation for hours, always leaving me with new ideas to explore and extending my endless reading list. This work would not have been possible without the conversations and support from my mentors Clarence Okoh and Marika Pfefferkorn and my many friends and colleagues who provided feedback including Shivam Saran, Patrick Oakford, Inica Kotasthane, Macy Stacher, Barrett Valentine, Teresa Foley Gannon, and Molly Nelson.
AUTHOR

Ellie Spangler graduated in May of 2026 from Macalester College, where she studied political science, economics, and statistics. She has participated in three of the Roosevelt Network’s undergraduate fellowships, where she’s explored her interest in automation’s impacts on the workforce and its intersection with regulatory systems.