California's AI Transparency Act is in force, but a lot of quick summaries still flatten it into something simpler than it is.
That is a problem because the law matters, and it arrives in stages.
If a company walks away with "California now requires AI labels," it will miss the more useful question: which entities have duties now, which entities pick them up later, and what technical or workflow evidence should already exist before anyone starts asking more exacting compliance questions.
That is the frame worth using now.
The Statute Is Live, But Not All At Once
The original California AI Transparency Act came from SB 942. AB 853 amended it before the law took effect and expanded the structure.
The result is not one date with one compliance moment.
The staged dates matter:
- covered-provider duties and the chapter's general enforcement provisions became operative on August 2, 2026;
- large-online-platform and GenAI-hosting-platform duties become operative on January 1, 2027; and
- capture-device-manufacturer duties become operative on January 1, 2028, for covered devices first produced for sale in California on or after that date.
Some companies are already inside the law. Others should be using the current window to prepare instead of treating the statute as a future issue.
Who Is Covered Right Now
The present-tense obligations fall first on a covered provider.
California defines that term to reach a person that creates, codes, or otherwise produces a generative AI system with more than 1,000,000 monthly visitors or users that is publicly accessible in California.
That threshold matters because it narrows the immediate field. Not every company using generative AI is covered today. Not every enterprise deploying internal tools is covered today either.
But for the companies that do clear that threshold, this is not mainly a statement of transparency values. It is a set of tooling and content-handling duties.
The chapter also excludes products, services, internet websites, and applications that provide exclusively non-user-generated video game, television, streaming, movie, or interactive experiences. That carveout matters when companies try to analogize every media product into the statute.
What Covered Providers Have To Do
The first major duty is an AI detection tool.
The law requires a covered provider to make available, at no cost, an AI detection tool that allows users to assess whether image, video, audio, or combined content was created or altered by that provider's GenAI system. The tool must output any system provenance data detected in the content, must not output detected personal provenance data, must accept an upload or URL, and must support an API. It must be publicly accessible, although reasonable access limits are permitted to address demonstrable risks to the system's security or integrity. Covered providers must also collect efficacy feedback and comply with restrictions on collecting or retaining user information, submitted content, and personal provenance data.
That is already a substantial operational requirement. This is not just a disclosure sentence in a terms-of-use page.
The second major duty is disclosure.
Covered providers must offer users the option to include a manifest disclosure in image, video, audio, or combined content created or altered by their GenAI systems. That disclosure must identify the content as AI-generated, be clear and conspicuous, and be permanent or extraordinarily difficult to remove to the extent technically feasible. Providers must also include a latent disclosure in AI-generated covered media created by their systems. To the extent technically feasible and reasonable, that disclosure must convey the provider name, system name and version, creation or alteration date and time, and a unique identifier, either directly or through a permanent website link. It must also be detectable by the provider's detection tool, consistent with widely accepted industry standards, and permanent or extraordinarily difficult to remove to the extent technically feasible.
The law also pushes into licensing relationships. If a covered provider licenses its system to a third party, the provider must require by contract that the licensee preserve the system's latent-disclosure capability. If the provider knows the licensee modified the system so that capability no longer exists, the provider must revoke the license within 96 hours. A licensee must stop using the system after a revocation under that provision.
That piece is easy to miss, but it matters. California is not only regulating outputs. It is also reaching contractual controls and downstream system integrity.
What AB 853 Changed
AB 853 made this a broader statute than the original SB 942 version many people still have in mind.
Beginning January 1, 2027, qualifying large online platforms must detect standards-compliant provenance data, disclose its availability and specified authenticity information through a user interface, permit users to inspect available system provenance data, and, to the extent technically feasible, refrain from knowingly stripping compliant system provenance data or digital signatures. On the same date, GenAI hosting platforms may not knowingly make available systems that fail to place the disclosures required by Section 22757.3. Beginning January 1, 2028, capture-device manufacturers must offer and enable by default specified latent disclosures for covered devices first produced for sale in California on or after that date, subject to technical-feasibility and standards-compliance conditions.
Companies should stop relying on any summary that still says the whole law simply took effect on January 1, 2026. That is outdated. Companies that are not yet directly covered by the August 2026 provider duties may still be moving into the law's later phases. If they wait until late 2026 or late 2027 to think seriously about provenance, labeling, or product controls, they are likely already behind.
The Real Compliance Work Is Technical And Procedural
The practical challenge here is not writing one good disclosure sentence.
It is proving that the right information survives the actual distribution path.
Companies should be asking questions like these now:
- Which systems generate image, video, or audio outputs that may fall inside the statute?
- What provenance or metadata is currently attached to those outputs?
- Does that data survive export, reposting, resizing, transcoding, or partner distribution?
- Can the company actually detect its own output reliably through a free user-facing tool?
- If the system is licensed out, where is the contractual requirement preserving latent disclosure capability?
- What happens when a downstream user strips, breaks, or disables provenance markers?
Those are engineering, product, legal, and vendor-management questions at the same time.
That is also why this law matters. It forces a more operational version of AI transparency than a lot of commentary admits.
What Records Companies Should Keep
The statute does not prescribe a general recordkeeping program. As a compliance and defensibility measure, however, a company that may be covered now or later should document its scope analysis and implementation work.
At a minimum, that record should include:
- system inventory for covered media-generation tools;
- monthly-visitor-or-user basis for any threshold analysis;
- detection-tool design and testing records;
- provenance and disclosure specifications;
- documentation showing whether manifest and latent disclosures are technically feasible in each workflow;
- API availability and user-access controls for the detection tool;
- contract terms for licensed systems;
- incident or exception handling when provenance is stripped, broken, or unavailable; and
- decision logs for scope calls, especially where the company concluded a system or workflow was outside the statute.
That kind of documentation matters because California's law is enforceable through civil actions, even though the statute does not itself create a general recordkeeping section.
The Penalty Structure Should Get Attention
The statute authorizes a civil penalty of $5,000 per violation, enforceable by the Attorney General, a city attorney, or a county counsel. Each day of noncompliance is a discrete violation for a covered provider, large online platform, or capture-device manufacturer. The statute separately provides an injunctive remedy and fees and costs for a third-party licensee's failure to cease using a revoked system.
That does not automatically mean immediate aggressive enforcement. It does mean the law should not be treated as symbolic.
The per-day structure is exactly the kind of thing that makes delayed operational fixes more expensive later.
What Companies Should Do Now
The short version is simple.
If you are clearly a covered provider, this should already be implementation and validation work.
If you are more likely to be affected by the January 2027 or January 2028 phases, use the current window to map systems, test provenance behavior, and clean up any workflow that assumes transparency can be bolted on at the last minute.
The best immediate steps are:
- Identify which products and workflows generate image, video, or audio content that may be covered.
- Confirm whether any system crosses the current monthly-user threshold.
- Test whether provenance data survives the real channels where content is shared.
- Review whether a free user-facing detection tool and API are actually ready.
- Check license agreements and downstream controls for any third-party distribution of the system.
- Build a written record of scope, exceptions, testing, and fixes.
Bottom Line
As of August 2, 2026, the covered-provider provisions are operative and should be treated as current compliance requirements.
The deeper point is that this statute is not mainly about slogans like "AI-generated content should be labeled." It is about whether a company can produce working detection tools, persistent provenance, durable disclosures, and defensible records across real content workflows.
That is where the compliance work actually is.

Leave a Reply