AutoSSL periodically checks eligible certificates and attempts renewal before expiration. Current cPanel documentation states that AutoSSL attempts to renew Let's Encrypt-issued certificates when they are within 29 days of expiration.
Renewal still requires successful domain-control validation. If DNS was changed, a hostname was removed, or validation is blocked, renewal can fail even though the existing certificate is still active.
Use SSL/TLS Status to watch expiration dates and AutoSSL results. Resolve renewal errors before the current certificate expires rather than waiting for the browser warning to appear.