How do you prove that a video, image or audio clip was made by a machine and not a human? California now has a legal answer to that question. California’s AI Transparency Act, originally introduced as SB 942 and later amended by AB 853, establishes a structured framework that forces generative AI providers to label, watermark and offer detection tools for AI-generated content.
Governor Gavin Newsom signed SB 942 into law on 19 September 2024. A year later, on 13 October 2025, AB 853 expanded its scope and pushed the first enforcement date to 2 August 2026. The Act targets deepfakes, misinformation and undisclosed synthetic media by placing accountability directly on the companies that build and distribute generative AI systems.
This guide breaks down every official date, obligation, penalty and covered entity under California’s AI Transparency Act. Whether you build AI systems, host AI models, run a large online platform or manufacture capture devices, this blog covers what you need to know before the deadlines arrive.
California’s AI Transparency Act is a state law that requires large generative AI providers to disclose when content is machine-generated.
SB 942 was introduced during the 2023-2024 legislative session in response to growing concerns about AI-generated deepfakes. The bill targeted generative AI systems capable of producing realistic images, videos and audio that could mislead the public. Governor Newsom signed it on 19 September 2024, making California one of the first states to mandate transparency obligations specifically for generative AI outputs.
The original bill focused on providers with more than one million monthly users. It required them to offer free AI detection tools, embed provenance data into AI-generated media and give users the option to add visible labels to their outputs.
AB 853, signed on 13 October 2025, significantly broadened the scope of the original Act. It pushed the enforcement date from 1 January 2026 to 2 August 2026 to align with the EU AI Act‘s transparency enforcement timeline. AB 853 also expanded coverage to include three new categories of regulated entities: large online platforms, generative AI hosting platforms, and capture device manufacturers.
California is home to the world’s largest AI companies and has a long track record of leading on technology regulation. The state’s lawmakers acted after high-profile incidents involving AI-generated deepfakes in elections and public discourse. The Act reflects a broader regulatory philosophy: if you build the technology, you bear responsibility for its transparency.
The Act applies to four distinct categories of entities, each with its own set of obligations and enforcement timeline.
A covered provider is any person or entity that creates, codes or produces a generative AI system meeting two conditions. First, the system must have more than one million monthly visitors or users. Second, it must be publicly accessible within California’s geographic boundaries. This definition captures major AI platforms like OpenAI, Google, Meta, Anthropic and similar companies operating large-scale generative AI tools.
This category includes public-facing social media platforms, file-sharing services, mass-messaging platforms and standalone search engines. To qualify, a platform must have more than two million unique monthly users within the prior 12 months. These platforms are not required to build AI systems themselves but must detect and label AI-generated content distributed through their services.
These are websites or applications that make the source code or model weights of a generative AI system available for download to California residents. Open-source AI repositories and model-sharing platforms fall under this category. They must ensure that any system they distribute includes compliant disclosure mechanisms.
Businesses that manufacture devices with built-in cameras, microphones or voice recorders for sale in California are also covered. This includes smartphone manufacturers, camera companies and any hardware producer whose devices capture images, video or audio. Their obligation is to embed provenance data into content captured by their devices.
The Act follows a phased rollout, giving different categories of regulated entities staggered deadlines to achieve compliance.
Governor Newsom officially signed SB 942, establishing the California AI Transparency Act. The original operative date was set for 1 January 2026. This signing marked California as the first US state to impose comprehensive transparency requirements on generative AI providers.
AB 853 amended the original Act. It extended the operative date to 2 August 2026, expanded the scope to cover hosting platforms, large online platforms and device manufacturers, and introduced additional requirements for provenance data handling. The alignment with the EU AI Act’s enforcement date was a deliberate choice to create regulatory consistency for global AI companies.
This is the first major enforcement deadline. By this date, covered providers must have a free AI detection tool publicly available, offer manifest disclosure options to users and embed latent disclosures in all AI-generated image, video and audio content. Third-party licensing agreements must also include transparency obligations. Handling sensitive personal information within AI systems adds another layer of responsibility that providers cannot afford to overlook.
Generative AI hosting platforms must ensure that downloadable AI systems include manifest and latent disclosure capabilities. Large online platforms must begin detecting provenance data in distributed content, provide users with an interface to check whether content is AI-generated and enable direct inspection of content provenance data.
Device manufacturers must offer users the option to embed latent disclosures in captured content. These disclosures must identify the device manufacturer and include the time and date of content creation or alteration. Latent disclosures must be enabled by default on all qualifying devices sold in California.
The Act introduces three primary technical obligations for covered providers, each designed to create a layered system of content authentication.
Every covered provider must build and publicly offer a free detection tool. This tool must allow any person to submit image, video or audio content and receive an assessment of whether it was created or altered by that provider’s generative AI system.
The tool must also output any system provenance data detected in the content. This is not optional. It must be available at no cost and accessible to the general public.
Covered providers must give users the option to include a visible, permanent label on AI-generated content. The label must clearly identify the content as AI-generated. It must be conspicuous, appropriate for the medium and understandable to a reasonable person. For images, this means a visible watermark.
For video, an overlay. For audio, a spoken tag or accompanying text. The goal is to ensure that anyone viewing the content can immediately recognise its synthetic origin.
Beyond visible labels, covered providers must embed a hidden, machine-readable provenance watermark in all AI-generated image, video and audio content. This latent disclosure must be permanent or extraordinarily difficult to remove. It must follow widely accepted industry standards, which in practice means the C2PA (Coalition for Content Provenance and Authenticity) specification.
The latent disclosure must convey information about the content’s origin, either directly or through a link to a permanent website.
California’s AI Transparency Act does not stop at the provider level. It extends accountability to every entity in the distribution chain.
When a covered provider licenses its generative AI system to a third party, the transparency obligations must travel with the licence. The licensee must include the same manifest and latent disclosures in content generated through the licensed system. This requirement prevents companies from avoiding compliance simply by licensing technology to another entity.
Every organisation using user consent mechanisms alongside AI tools must ensure those tools carry proper disclosure.
If a covered provider discovers that a third-party licensee is stripping watermarks or failing to include the required disclosures, the provider must revoke the licence within 96 hours. That is just four days. Failure to revoke within this window exposes the provider itself to civil penalties. This provision creates a strong incentive for providers to actively monitor how their technology is being used downstream.
Providers should review and update all third-party licensing agreements before 2 August 2026. Contracts must explicitly include CAITA’s transparency obligations, define revocation procedures and outline monitoring responsibilities. Vague or outdated licence terms will not be sufficient once enforcement begins.
The Act carries real financial consequences for non-compliance, and enforcement authority is distributed across multiple levels of government.
For a company operating a large-scale AI platform, even a brief period of non-compliance could result in significant cumulative fines. A 30-day gap, for example, could mean $150,000 in penalties for a single violation category.
Enforcement is handled through civil actions filed by the California Attorney General, a city attorney or a county counsel. This distributed enforcement model means that compliance is not dependent on a single federal agency taking action. Local prosecutors across California can independently pursue violations, increasing the likelihood of enforcement.
The Act does not create a private right of action. Individual consumers cannot sue providers directly under CAITA. However, enforcement by public officials can still be triggered by consumer complaints, whistleblower reports or investigative findings. Companies familiar with the Key Updates in CCPA will recognise a similar enforcement model in how state authorities handle violations.
The Act repeatedly references widely accepted industry standards for latent disclosures. In practice, this points directly to one framework.
The Coalition for Content Provenance and Authenticity (C2PA) is a non-profit project that develops open technical specifications for establishing content provenance. It allows provenance data to be bound to media files and tracks any changes made to that media, including alterations by generative AI systems. Major technology companies including Adobe, Microsoft, Google and Intel are founding members.
C2PA’s specification satisfies the Act’s requirement for latent disclosures that are permanent or extraordinarily difficult to remove. The standard embeds cryptographically signed metadata directly into media files. This metadata records the origin of the content, any edits or transformations applied and the identity of the system that generated it. Because the data is cryptographically bound, tampering with or removing it without detection is extremely difficult.
Covered providers that adopt C2PA will be well positioned to meet CAITA’s latent disclosure requirements. Those that use proprietary or non-standard watermarking methods risk having their approach challenged during enforcement proceedings. The Act’s language strongly favours established, interoperable standards, making C2PA the safest technical path to compliance. Choosing the right tools matters, and evaluating best consent management platforms alongside provenance tools can streamline overall compliance workflows.
This Act does not exist in isolation. It is part of a growing patchwork of AI regulations at state, national and international levels.
The decision to push the enforcement date to 2 August 2026 was explicitly tied to the EU AI Act’s transparency provisions. Both frameworks require AI-generated content to be clearly labelled, though the EU Act applies more broadly across all AI system categories. Companies operating in both jurisdictions will find significant overlap in their compliance obligations. Understanding the relationship between GDPR vs CCPA is equally critical for organisations managing cross-border compliance.
CAITA is one of several AI-focused laws California has enacted. SB 53, for instance, addresses frontier AI model safety and reporting. Together, these laws position California as the most active US state in regulating artificial intelligence. Businesses operating AI systems in California must now track multiple overlapping compliance requirements.
As of mid-2026, no comprehensive federal AI transparency law exists in the United States. California’s approach may serve as a template for future federal legislation, similar to how the CCPA influenced federal privacy discussions. Companies that achieve compliance with CAITA will likely be well prepared for any federal requirements that emerge.
Compliance requires engineering work, legal updates and operational changes. Here is a practical checklist for each covered category.
Platforms must invest in provenance detection infrastructure. This includes tools to scan uploaded content for C2PA metadata, user interfaces that display AI-generated content labels and systems that preserve provenance data throughout the content distribution pipeline. Product and engineering teams should start scoping this work now.
Manufacturers must integrate latent disclosure capabilities into device firmware. This requires coordination between hardware, software and product teams. Devices must embed provenance data by default, meaning the feature cannot be buried in settings menus. It must be active out of the box.
California’s AI Transparency Act marks a major shift towards responsible AI by making transparency a legal requirement, not an option. Organisations that prepare early with clear content labelling, provenance tracking and AI governance practices will reduce compliance risks, strengthen user trust and stay ahead as AI regulations continue to evolve worldwide.
Regulatory requirements for AI and data transparency are expanding fast. Seers helps businesses stay ahead of compliance deadlines with automated tools for consent, privacy and data governance. Whether you are preparing for California's AI Transparency Act or managing global regulatory obligations, Seers gives you the control you need.
START FREE TODAYCalifornia’s AI Transparency Act is a state law established by SB 942 and amended by AB 853. It requires large generative AI providers to label AI-generated content with visible and machine-readable disclosures. The Act also mandates free AI detection tools for public use. Its primary goal is to combat deepfakes and undisclosed synthetic media by holding AI providers accountable for content transparency.
The Act follows a phased enforcement schedule. Covered providers must comply by 2 August 2026. Generative AI hosting platforms and large online platforms face a 1 January 2027 deadline. Capture device manufacturers have until 1 January 2028. AB 853 pushed the original 1 January 2026 date to align with the EU AI Act’s transparency enforcement timeline.
A covered provider is any person or entity that creates, codes or produces a generative AI system with more than one million monthly visitors or users. The system must be publicly accessible within California’s geographic boundaries. This definition captures major AI companies operating large-scale consumer-facing generative AI platforms.
A manifest disclosure is a visible label on AI-generated content, such as a watermark on an image or an overlay on a video. A latent disclosure is a hidden, machine-readable provenance watermark embedded directly into the media file. Both serve the same purpose of identifying AI-generated content, but they operate at different layers, one for human viewers and one for automated detection systems.
Non-compliance carries a civil penalty of $5,000 per violation. Each day of ongoing non-compliance is treated as a separate violation, which means penalties can accumulate quickly. Enforcement actions are filed by the California Attorney General, city attorneys or county counsel. Violators are also responsible for attorneys’ fees and court costs.
California’s AI Transparency Act specifically targets AI-generated image, video and audio content. Text-only outputs are not covered by the disclosure and detection tool requirements. However, providers should monitor ongoing legislative developments, as future amendments could expand coverage to include AI-generated text.
When a covered provider discovers that a third-party licensee is failing to include required disclosures or stripping watermarks, the provider must revoke the licence within 96 hours. Failure to act within this window exposes the provider to the same $5,000 per day penalty. This rule ensures that providers actively monitor downstream use of their technology.
C2PA, the Coalition for Content Provenance and Authenticity, provides the technical standard that satisfies the Act’s latent disclosure requirements. It embeds cryptographically signed metadata into media files, recording the content’s origin and any modifications. The Act references widely accepted industry standards, and C2PA is the leading specification in this space.
The Act’s covered provider obligations apply only to generative AI systems with more than one million monthly users that are publicly accessible in California. Smaller providers that fall below this threshold are not currently subject to the core disclosure and detection tool requirements. However, they may still be affected if they license technology from a covered provider.
California frequently sets regulatory precedents that other states follow. The CCPA influenced numerous state-level privacy laws, and the same pattern is likely with AI transparency. Several states are already considering similar legislation. Companies that comply with CAITA will be well positioned to meet requirements in other jurisdictions as they emerge.
Rimsha ZafarRimsha is a Senior Content Writer at Seers AI with over 5 years of experience in advanced technologies and AI-driven tools. Her expertise as a research analyst shapes clear, thoughtful insights into responsible data use, trust, and future-facing technologies.
Take our Free Cookie Audit and find out
Join 50,000+ websites using Seers.Ai to turn compliance into trust, insights, & measurable business growth.