
Key takeaways
- The California AI Transparency Act (SB 942) became operative on 2 August 2026, not 1 January 2026. AB 853 moved the date.
- It binds providers of generative AI systems with more than one million monthly users that are publicly accessible in California.
- Three duties apply: a free detection tool, a durable latent disclosure carried inside every output, and a manifest disclosure the user can choose to apply.
- SB 1000 is on the Governor’s desk and would delete the million-user threshold, taking effect the moment it is signed. The deadline is 30 September 2026.
- Penalties run at 5,000 dollars per violation per day, and the only thing that answers an enforcement letter is a record.
What the California AI Transparency Act actually requires
SB 942 added sections 22757.1 to 22757.4 to the California Business and Professions Code. It does not regulate what a model may generate. It regulates whether anyone downstream can tell that a machine generated it, and it puts that burden on the provider rather than on the platform, the publisher or the reader. Three obligations sit at the centre. A free detection tool. A covered provider must publish a tool, at no cost, that lets anyone check whether a given piece of content came out of that provider’s system. Under section 22757.2 the tool has to accept content by upload, accept a URL, and expose an application programming interface, so that it can be used by a person inspecting one image and by a platform checking a stream of them. It must also collect and retain as little personal data as possible, which matters because a detection endpoint is otherwise an attractive place to accumulate exactly the material a provider should not be holding. A latent disclosure in every output. Section 22757.3 requires a disclosure embedded in the content itself or in its metadata, durable enough to survive ordinary handling, identifying the provider, the name and version number of the system, the time and date of creation, and a unique identifier. The statute calls this latent because it is present without being visible. It must remain readable by the provider’s own detection tool, which closes the obvious loophole of shipping a marker nothing can verify. A manifest disclosure on request. The provider must give users the option to add a visible label to AI-generated content, and that label has to be permanent or extraordinarily difficult to remove. Note the asymmetry: the latent disclosure is mandatory and automatic, the manifest disclosure is mandatory to offer and optional to use. One further duty is easy to miss and expensive to breach. If a provider licenses its system to a third party and then learns that the licensee has stripped out the latent disclosure, the provider has 96 hours to revoke the licence, and the licensee must stop using the system. That is a contractual obligation, a monitoring obligation and a clock, all in one sentence.
Who counts as a covered provider
A covered provider under section 22757.1(d) is an entity that creates, codes or otherwise produces a generative AI system with more than 1,000,000 monthly visitors or users, that is publicly accessible in California. Two things follow. The threshold counts users of the system, not customers of the company, so a free consumer tool attached to a small business can cross it while an expensive enterprise deployment never does. And “publicly accessible in California” is not the same as incorporated, headquartered or hosted there. The Act carves out systems whose output is exclusively non-user-generated video game, television, streaming, film or interactive entertainment content. A studio rendering its own assets is outside. A studio handing the same model to its audience is not.
The date moved, and two waves are still ahead
AB 853, signed on 13 October 2025, rewrote the timetable. The operative date for covered providers shifted from 1 January 2026 to 2 August 2026, a date chosen to line up with the EU AI Act rather than with California’s own calendar. Any compliance memo written before October 2025, and there are several still ranking on this query, states a deadline that no longer exists. AB 853 also added two later waves that most coverage treats as a footnote. From 1 January 2027, large online platforms that distribute content must detect whether provenance data is present, expose that availability in their interface, and let users inspect the provenance data in an accessible way. From the same date, a covered provider may not distribute a generative AI system that lacks the required disclosures, which converts a duty about output into a duty about product release. From 1 January 2028, manufacturers of capture devices, meaning cameras, phones and recorders, must offer users the option of a latent disclosure identifying the device, and must embed that disclosure by default. Read together, the three dates describe a chain of custody: the generator marks, the device marks, and the distributor must not break either mark. California is not legislating labels. It is legislating a provenance pipeline, one link per year. The wider state picture, including the ADMT rules and the employment provisions, sits in our guide to California AI laws.
SB 1000 would delete the million-user threshold
The most consequential fact about this statute today is not in the statute. Two bills amending it are sitting with the Governor. SB 1000 (Becker) was enrolled on 30 August 2026 and presented to the Governor at 3 p.m. on 2 September 2026. It amends sections 22757.1 through 22757.5 and adds section 22757.4.1, and it is an urgency statute, which means it takes effect immediately on signature rather than on the following 1 January. Four changes matter:
- The 1,000,000 monthly user threshold is removed. Coverage would extend to generative AI providers of any size that are publicly accessible in California.
- The manifest disclosure requirement is dropped, while the latent disclosure is kept and tightened: it must state whether the content was created or altered by AI, not merely that AI touched it.
- The AI detection tool becomes a disclosure verification tool, a renaming that shifts the test from “did our model make this” to “is a valid disclosure present”.
- Assistive-technology systems get a deferral, with civil penalties for falsely claiming that status.
AB 2713 was presented to the Governor on 8 September 2026 and amends section 22757.3.1. It narrows the platform duty to provenance data that meets widely adopted specifications issued by an established standards-setting body, and it prohibits a large online platform from knowingly stripping compliant provenance data or digital signatures from content it distributes. That is the clause that turns an abstract duty into an engineering requirement, because it points at a named standard rather than at a policy aspiration. The Governor has until 30 September 2026 to act on the remaining bills of the 2026 session. Neither bill is speculative drafting; both have cleared both houses. A provider that has just finished scoping its obligations against the million-user threshold should assume that number may not survive the month, and should scope the control rather than the exemption. The broader 2026 picture is covered in our AI laws guide.
What a covered provider must be able to produce
Every ranking analysis of this statute explains what it says. Almost none says what you hand over when the Attorney General writes. Disclosure law is proved by artefacts, not by intentions, and the artefacts here are specific. Detection tool evidence. Uptime and availability records for the public endpoint, the accuracy methodology and its results, the data-retention configuration showing what the tool keeps and for how long, and the API documentation as published. If the tool was unavailable for a period, the record of that period is part of the file. A latent disclosure specification. A written description of what is embedded, in which formats, using which encoding, and a version log tying each specification revision to the model versions that produced content under it. Without the version log, a piece of content surfacing two years from now cannot be matched to the rules that governed it. Per-asset provenance. The manifest attached to generated content carrying the provider identity, system name, version, creation timestamp and unique identifier that section 22757.3 demands. This is the record that a complaint is checked against. The licence file. The contractual clause requiring licensees to preserve latent disclosures, the monitoring method that would detect a breach, and, if a breach ever occurred, a timestamped log proving revocation inside the 96-hour window. A clause without a monitoring method is not a control, and an enforcement action will treat it as one. Change and complaint records. Model version history mapped to disclosure behaviour, plus the intake, investigation and resolution trail for reports of unmarked content. This is the same shape of file a European market surveillance authority asks for, which is the practical argument for building it once. Our guides to AI system documentation and to auditability set out how the record set is structured so that it answers more than one regulator.
One implementation, two regimes: SB 942 and EU AI Act Article 50
A provider serving both markets should not build California marking and European marking as separate projects, because the technical artefact is the same and only the paperwork differs. Article 50(2) of the EU AI Act requires providers of systems generating synthetic audio, image, video or text to mark outputs in a machine-readable format detectable as artificially generated or manipulated, using solutions that are effective, interoperable, robust and reliable as far as technically feasible. Article 50 was not touched by the deferrals in Regulation (EU) 2026/1744, the Digital Omnibus on AI, which entered into force on 27 July 2026 and pushed Annex III high-risk duties to 2 December 2027 and Annex I duties to 2 August 2028. The Article 50 transparency date held at 2 August 2026, and the transition for systems already on the market closes on 2 December 2026. Our Article 50 guide covers that regime in detail. So the two regimes turned on within days of each other, and both are now live. The convergence point is the standard. C2PA Content Credentials, whose technical specification reached version 2.2 in May 2025, has been fast-tracked as ISO/DIS 22144, Authenticity of information: Content Credentials, and JPEG Trust adopted C2PA version 1 as ISO/IEC 21617-1:2025. AB 2713’s reference to widely adopted specifications issued by an established standards-setting body points directly at this family. A provider that implements C2PA manifests, signs them, and keeps the signing infrastructure auditable satisfies the technical core of both regimes with one build. One caution belongs in any honest treatment of this. NIST AI 100-4, the synthetic-content report from the US AI Safety Institute, reviews the two provenance techniques the statute relies on, digital watermarking and metadata recording, and concludes that all of them have limitations and are vulnerable to tampering, with text the weakest case. California requires durability that the state of the art does not fully deliver. The compliant answer is not to claim otherwise, but to document the technique chosen, its known failure modes, and the monitoring that detects stripped or degraded marks. Singapore’s IMDA framework reaches the same conclusion from the other direction, treating content provenance as one governance dimension among nine rather than as a solved technical problem.
Penalties, enforcement and who can actually sue
The civil penalty is 5,000 dollars per violation, and each day of non-compliance counts as a separate violation. There is no cap in the statute, so the arithmetic on a systemic failure is unbounded rather than nominal. Enforcement sits with the California Attorney General, a city attorney or a county counsel. They may seek the penalty and injunctive relief, and a prevailing plaintiff recovers reasonable attorney’s fees and costs. There is no private right of action. That is a meaningful difference from the CCPA regulations, which do carry a limited private claim for certain data breaches, and it shapes the risk profile: the realistic exposure here is a public enforcement action following a complaint or a press story, not a class action. It also means the trigger is often a journalist or a researcher running your own detection tool against content in the wild and publishing the result.
FAQ
When did the California AI Transparency Act take effect? 2 August 2026. SB 942 was signed on 19 September 2024 with an original operative date of 1 January 2026, but AB 853, signed on 13 October 2025, moved it to 2 August 2026 to align with the EU AI Act. Later obligations follow on 1 January 2027 for large online platforms and for the distribution of non-compliant systems, and on 1 January 2028 for capture-device manufacturers. Any guidance citing 1 January 2026 predates the amendment. Does SB 942 apply if we have fewer than a million users? Today, no. The covered-provider definition requires more than 1,000,000 monthly visitors or users and public accessibility in California. That may not hold for long. SB 1000, presented to the Governor on 2 September 2026, removes the threshold entirely and is an urgency statute, so it would apply immediately on signature. The Governor’s deadline for 2026 session bills is 30 September 2026. Scope your controls to the obligation rather than to the exemption. What is the difference between a latent disclosure and a manifest disclosure? A latent disclosure is embedded in the content or its metadata and is not visible to a reader. It carries the provider, the system name and version, the creation timestamp and a unique identifier, and it must be readable by the provider’s own detection tool. A manifest disclosure is the visible label a user can choose to apply, and it has to be permanent or very difficult to remove. The latent one is automatic and mandatory; the manifest one is mandatory to offer and optional to use. Does complying with EU AI Act Article 50 make us compliant with SB 942? Not automatically, but the technical work overlaps almost entirely. Article 50(2) requires machine-readable marking of synthetic output; SB 942 requires a latent disclosure with named fields plus a public detection tool that Article 50 does not demand. Build the marking against C2PA Content Credentials and ISO/DIS 22144, then add the California-specific fields and the detection endpoint. The gap is the tool and the record set, not the watermark. What happens if a licensee turns off our latent disclosure? The clock starts when you discover it. The provider must revoke the licence within 96 hours, and the licensee must cease using the system. In practice this means three things have to exist before the event: a contract clause that makes preservation a condition of the licence, a monitoring method capable of detecting removal, and a logging arrangement that can later prove when you found out and when you acted. Vendor terms alone will not carry this, which is why it belongs in vendor due diligence. Which California AI bills were signed in September 2026? SB 813 and AB 1405 on 9 September, establishing a process for regulating independent AI verification organisations and creating an AI auditor registry. AB 2246, AB 1709, AB 1856, SB 1119 and SB 867 on 10 September, covering child safety, addictive design and companion chatbots, including a temporary ban on companion chatbots in toys. SB 1050 on 16 September, requiring disclosure when a synthetic performer appears in an advertisement. An executive order on independent oversight followed on 18 September.
Conclusion
The marking obligation in California is settled. Its scope is not, and it may change before the end of this month. That combination argues for a particular sequence: implement the latent disclosure against a published standard, stand up the detection endpoint, and build the record set that proves both, before spending time on the threshold analysis that SB 1000 may make irrelevant. A provider that treats this as a labelling task will rebuild it when the scope moves. A provider that treats it as a provenance and evidence capability will absorb SB 1000, AB 2713 and Article 50 as configuration. That is the difference our AI compliance approach is built around: the control is the record, and the record is what survives a change in the law.