California’s AI Transparency Act has become operative, requiring covered generative AI providers to offer detection tools and add provenance disclosures to AI-generated media. Lawmakers are already considering changes that would rewrite several of those requirements.

A covered provider is a person that creates, codes or otherwise produces a generative AI system with more than 1 million monthly visitors or users that is publicly accessible in California. The definition includes systems that generate text, but the duties apply to images, video, audio or combinations of those formats.

The chapter excludes products, services, websites and applications that provide exclusively non-user-generated video game, television, streaming, movie or interactive experiences.

AI detection and disclosure requirements

The required “AI detection tool” is narrower than a general detector. It must assess whether media was created or altered by the covered provider’s own system, accept a file or URL and support an application programming interface (API). It must report detected system provenance while withholding personal provenance data.

Providers must also offer an optional visible disclosure identifying media as AI-generated. A separate latent disclosure is compulsory for AI-generated media created by their systems. Where technically feasible and reasonable, it must identify the provider, system and version, creation or alteration time and date and a unique identifier. It must follow widely accepted industry standards and be “permanent or extraordinarily difficult to remove” where technically feasible.

Privacy and licensing requirements

When operating the detection tool, providers generally cannot collect or retain users’ personal information, keep submitted content longer than necessary or retain personal provenance data.

Licensing carries a separate contractual obligation: providers must require third-party licensees to maintain the system’s latent-disclosure capability. If a provider knows a licensee modified the system so it can no longer include the required disclosure, it must revoke the license within 96 hours of discovery.

The statute does not name the Coalition for Content Provenance and Authenticity (C2PA) standard. C2PA’s official explainer says provenance metadata can be removed. Its durable Content Credentials combine cryptographic hard bindings with soft bindings such as invisible watermarking or fingerprint lookup, which can enable a credential stored elsewhere to be rediscovered. C2PA makes provenance information tamper-evident but does not make embedded metadata unremovable.

Penalties and later requirements

A violator is liable for a $5,000 civil penalty per violation, enforceable through a civil action by the attorney general, a city attorney or county counsel. Each day a covered provider, large online platform or capture device manufacturer remains in violation counts as a separate violation once the relevant duties apply. Those public enforcers may also seek injunctive relief and reasonable attorney’s fees and costs when a third-party licensee continues using a system after revocation.

The act also contains later phases added by Assembly Bill 853, enacted in 2025. Large online platforms and generative AI hosting platforms face additional duties from Jan. 1, 2027, followed by requirements for capture device manufacturers covering specified devices from Jan. 1, 2028.

Pending rewrite under Senate Bill 1000

Senate Bill 1000, whose findings say “AI provenance technology is still developing,” would remove the provider threshold, replace the detection tool with a revised disclosure verification tool and eliminate the optional visible disclosure.

The urgency measure would also permit compliant third-party tools and shorten the deadline for terminating a noncompliant licensee’s authorization from 96 to 72 hours. As of Aug. 10, it was item 61 on the Assembly’s third-reading file and required a two-thirds vote. If enacted, it would take effect immediately.

Personalized Feed
Personalized Feed