Skip to main content

California Gazette

California AI Transparency Act Takes Effect, Making the State First to Require Provenance Disclosures in AI-Generated Content

California AI Transparency Act Takes Effect, Making the State First to Require Provenance Disclosures in AI-Generated Content
Photo Credit: Unsplash.com

The California AI Transparency Act became operative on August 2, 2026, making California the first state in the nation to enforce a comprehensive framework requiring generative AI providers to embed provenance data in synthetic images, video, and audio, offer free public detection tools, and give users the ability to identify content that was created or altered by artificial intelligence. The law, authored by Bay Area lawmakers Senator Josh Becker (D-Menlo Park), Assemblymember Buffy Wicks (D-Oakland), and Assemblymember Rick Chavez Zbur (D-Los Angeles), arrives during a 2026 election cycle in which deepfakes, manipulated audio, and synthetic video have become active threats to voter confidence and public trust.

Key Takeaways

  • The California AI Transparency Act (CAITA), established by SB 942 in 2024 and amended by AB 853 in 2025, requires covered providers of generative AI systems with more than one million monthly users to embed machine-readable provenance disclosures in AI-generated images, video, and audio, offer free public AI detection tools, and give users the option to include visible manifest disclosures on content they create.
  • Noncompliance carries civil penalties of $5,000 per violation, with each day of noncompliance treated as a separate violation, enforceable by the California Attorney General, city attorneys, or county counsel.
  • The operative date was deliberately aligned with the European Union’s AI Act enforcement timeline; the European Code of Practice on Transparency of AI-Generated Content took effect on the same date, with its rules aligned to CAITA’s provisions.
  • Additional requirements for large online platforms and GenAI hosting platforms take effect January 1, 2027, followed by obligations for capture device manufacturers — including phones and cameras — beginning January 1, 2028.
  • The law relies on the C2PA (Coalition for Content Provenance and Authenticity) standard, an industry framework backed by companies including Adobe and Microsoft that uses cryptographically signed “Content Credentials” to track a file’s creation history.
  • The California legislature is simultaneously advancing SB 1000, an urgency bill that passed the Assembly on August 27, 2026, and could revise several of CAITA’s core requirements, including potentially removing the one-million-user threshold.

Three Technical Obligations Define the First Phase

CAITA’s first phase, now in effect, applies to “covered providers” — defined as persons or entities that create, code, or otherwise produce a generative AI system with more than one million monthly visitors or users that is publicly accessible within California. The threshold captures the major generative AI platforms operating in the state while exempting smaller developers and research tools that have not reached commercial scale.

Covered providers must now meet three distinct technical obligations simultaneously. The first requires every covered provider to offer a free, publicly accessible AI detection tool — both a URL-based interface and an API — that allows anyone to check whether a specific piece of content originated from that provider’s system. The tool must be available at no cost to the user, a provision designed to ensure that the ability to verify content provenance is not gated behind a subscription or institutional license.

The second obligation requires covered providers to offer users the option to include a visible “manifest disclosure” on AI-generated content. This is the human-readable layer — a label, icon, or notice that signals to a viewer that the content was created or altered using generative AI. The disclosure is opt-in for the user creating the content, meaning the provider must build the functionality and make it available, but the user decides whether to display it.

The third obligation is the technical core of the law. Covered providers must embed a “latent disclosure” — a hidden, machine-readable provenance watermark — in every AI-generated image, video, or audio file produced by their system. Unlike the visible manifest disclosure, the latent disclosure is not optional. It operates beneath the surface of the content itself, carrying metadata about how the file was created, which system produced it, and when. The technical standard underpinning this requirement is the C2PA framework, an industry specification developed by a coalition that includes Adobe and Microsoft, which uses cryptographically signed “Content Credentials” to create a tamper-evident record of a file’s origin and editing history.

The Law Arrives During a Contested Election Cycle

CAITA’s operative date is not incidental to the political calendar. The 2026 midterm election cycle has already produced documented instances of AI-generated content being used to impersonate candidates, fabricate endorsements, and create synthetic audio of public officials making statements they never made. Senator Becker’s office has cited estimates that AI-powered scams cost Americans more than $1 billion per year, and the growing sophistication of generative AI tools has made it increasingly difficult for voters, journalists, and election administrators to distinguish authentic media from fabricated content using visual inspection alone.

The provenance framework CAITA establishes does not solve that problem entirely — and the law’s authors have been clear about its limitations. Provenance data records how a piece of content was created and modified, but it does not judge whether the content is truthful. A real photograph can still appear beside a false caption. Authentic footage can be edited to remove important context. Screenshots and compressed copies shared through messaging services may lose the embedded provenance data entirely. The C2PA standard itself notes that a file without Content Credentials should not automatically be treated as untrustworthy, and that a valid credential does not certify the accuracy of the message. What the law provides is an additional verification layer — a tool that, when present, allows a viewer to inspect the origin of a piece of content before deciding whether to trust it.

Senator Becker described the law’s effects in measured terms, noting that most people will not see dramatic changes overnight but that the information behind digital content will begin shifting in ways designed to protect consumers. That framing — transparency as infrastructure, not as an immediate fix — reflects the law’s phased architecture, which rolls out progressively more demanding requirements over three years.

Phased Implementation Extends Through 2028

The August 2, 2026, operative date covers only the first of three implementation phases. AB 853, the 2025 amendment authored by Assemblymember Wicks, expanded the original SB 942 framework to include three additional categories of regulated entities, each with its own timeline.

Beginning January 1, 2027, large online platforms — defined as public-facing social media sites, file-sharing services, mass-messaging platforms, or standalone search engines with more than two million unique monthly California users in the prior 12 months — must detect compatible provenance data embedded in content they distribute, disclose that provenance data to users, allow users to inspect available provenance information, and refrain from knowingly stripping compliant provenance data or digital signatures from uploaded or distributed content. GenAI hosting platforms — websites or applications that make available the source code or model weights of a generative AI system to California residents — face a parallel requirement: they may not knowingly distribute a GenAI system that does not include the required disclosures.

The third phase, effective January 1, 2028, reaches the hardware layer. Manufacturers of devices with built-in cameras, microphones, or voice recorders that are produced for sale in California must provide latent-disclosure options and embed provenance data by default at the moment of capture. By 2028, phones and cameras sold in California will be required to store provenance information as soon as an image is taken or audio is recorded — a requirement that extends the transparency framework from the point of AI generation back to the point of original content creation.

California and the EU Aligned Their Enforcement Timelines

The August 2 operative date was not the original plan. SB 942, signed by Governor Newsom in September 2024, initially set a January 1, 2026, effective date. AB 853, signed in October 2025, pushed the date forward by seven months, citing the need to align California’s requirements with the European Union’s AI Act enforcement timeline and to give covered providers adequate time to build compliant detection infrastructure. The European Code of Practice on Transparency of AI-Generated Content took effect on the same date, with its marking and detection rules aligned to CAITA’s provisions.

The transatlantic coordination was intentional. The chairs of the European working group that developed the EU’s transparency code publicly acknowledged the alignment, stating that both jurisdictions had looked forward to implementing parallel content transparency frameworks simultaneously. For generative AI providers operating in both markets — which includes virtually every major platform — the synchronized enforcement dates mean that a single compliance architecture can serve both regulatory regimes, reducing the friction of building separate systems for different jurisdictions.

California’s role as a regulatory first mover in AI transparency also carries implications for other states considering similar legislation. Washington, New York, and several additional states have introduced AI transparency proposals in 2026, many of which reference CAITA’s structure. The C2PA standard that CAITA relies on is an open specification, meaning other jurisdictions can adopt the same technical framework without building proprietary alternatives, potentially creating a de facto national provenance infrastructure driven by California’s market weight.

SB 1000 Could Reshape the Law Before Its Second Phase Arrives

Even as CAITA’s first phase takes effect, the California legislature is advancing SB 1000, an urgency bill that would revise several of the law’s core requirements. As of August 27, 2026, SB 1000 passed the Assembly with 39 votes in favor and none opposed, and has been ordered to engrossing and enrolling — a late-stage legislative step indicating the bill is moving toward the Governor’s desk.

If signed into law, SB 1000 would make several substantive changes to CAITA’s framework. The bill would remove the one-million-user threshold entirely, potentially extending the law’s obligations to smaller generative AI providers. It would also delete the manifest disclosure requirement and revise the rules governing detection tools and latent disclosures. The scope and final language of the revisions remain subject to the legislative process, but the bill’s rapid progress — urgency bills move on accelerated timelines — suggests that the version of CAITA now in effect could look meaningfully different by the time its second phase arrives in January 2027.

For covered providers already in compliance with the August 2 requirements, the pending legislation creates a monitoring obligation. Compliance teams that built systems around the current one-million-user threshold, the manifest disclosure option, and the existing detection-tool specifications may need to adjust those systems if SB 1000 changes the underlying requirements. The uncertainty is a feature of California’s iterative approach to AI regulation — the state has enacted 18 AI-related bills since 2024, layering new obligations on top of existing frameworks as the technology and its risks evolve.

FAQs

What does the California AI Transparency Act require?

The law requires covered generative AI providers with more than one million monthly users to embed hidden machine-readable provenance data in AI-generated images, video, and audio, offer a free public AI detection tool, and give users the option to include a visible disclosure on AI-generated content. Civil penalties of $5,000 per violation apply, with each day of noncompliance treated as a separate offense.

Which companies are affected?

The first phase applies to any person or entity that operates a publicly accessible generative AI system with more than one million monthly visitors or users in California. Beginning January 1, 2027, large online platforms with more than two million monthly users and GenAI hosting platforms face additional requirements. Device manufacturers with cameras or microphones face obligations starting January 1, 2028.

Does the law apply only to AI-generated deepfakes?

The law applies to all AI-generated or AI-altered image, video, and audio content produced by covered systems, not only to content that qualifies as a deepfake. Provenance disclosures are required regardless of whether the content is intended to deceive. A separate California law, AB 2655, specifically addresses politically deceptive deepfakes during election periods.

Can provenance data be removed or lost?

Provenance data can be lost when content is screenshotted, compressed through messaging services, or shared without the original file. The C2PA standard notes that a file without Content Credentials should not automatically be treated as untrustworthy. Beginning January 1, 2027, large online platforms will be prohibited from knowingly stripping compliant provenance data from content they distribute.

California Gazette

Capturing the Golden State's essence, one story at a time.