- Lead. California’s AI Transparency Act — SB 942 as amended by AB 853 — became operative on 2 August 2026, creating the United States’ first enforceable watermarking and detection-tool mandate for generative AI providers that serve more than one million California users per month.
- Fact. Covered providers must embed machine-readable C2PA provenance data in all AI-generated or substantially altered images, video, and audio, and must also offer a free public tool — with a third-party API — for detecting whether content was produced by their system. Penalties stand at $5,000 per violation per day.
- Stake. Because any platform with more than one million monthly California visitors falls under the law regardless of where it is headquartered, the rule is functionally national in scope and forces every major AI company — OpenAI, Google, Anthropic, Meta, and others — to implement compliant infrastructure or face cumulative fines that could reach $150,000 within a single month from a single non-compliant feature.
California’s AI Transparency Act took effect on 2 August 2026, making the state the first US jurisdiction to impose a legally enforceable requirement on generative AI companies to watermark their synthetic media and provide consumers with the tools to verify what they are seeing. The law — originally Senate Bill 942, later amended by Assembly Bill 853 — applies to any entity that offers a publicly accessible generative AI system with more than one million monthly users in California, a threshold low enough to capture virtually every major AI platform operating in the United States.
The legislation was first signed in 2024 with an original effective date of January 1, 2026. The legislature pushed that to August 2 through AB 853, citing the need to align California’s watermarking requirements with the EU AI Act’s Article 50 provenance timeline and to give covered providers time to build compliant infrastructure.
Three Technical Obligations Now Enforceable
Covered providers face three distinct compliance requirements. First, they must embed latent disclosures — machine-readable provenance metadata including the provider name, system name and version, a creation timestamp, and a unique content identifier — in any synthetic or substantially altered image, video, or audio. The embedding must follow C2PA (Coalition for Content Provenance and Authenticity) standards and be “permanent or extraordinarily difficult to remove”; the same framework now required under the EU AI Act.
Second, providers must operate a free, publicly accessible detection tool capable of determining whether a given piece of content was generated by their system, available through both a web interface and a third-party API. Critically, the detection tool cannot retain user submissions or collect personal data beyond what is needed to return a result. Third, providers must enable users to add visible “AI-generated” labels to content, formatted for each medium type.
The obligations cover images, video, and audio. They do not extend to text — an exclusion that reflects the current limits of reliable text watermarking technology and is expected to be revisited in future legislative sessions.
Liability Structure Creates Compounding Exposure
The penalty structure is designed to accumulate quickly. Each day of non-compliance counts as a separate violation at $5,000, meaning a provider that fails for 30 days to maintain a compliant detection tool faces $150,000 in potential exposure from that single deficiency alone. Enforcement authority lies with the California Attorney General as well as city and county attorneys, and prevailing plaintiffs can recover attorneys’ fees in addition to per-violation fines.
Providers that distribute their systems to third-party licensees must contractually require those licensees to maintain watermarking capabilities, and have a 96-hour window to revoke access if they discover a licensee has stripped provenance data from the pipeline.
The operative date coincides with the start of enforcement by the European Commission’s AI Office against general-purpose AI model providers under the EU AI Act’s GPAI rules, which also kicked in on 2 August. For the major AI companies, both sides of the Atlantic are now simultaneously watching for compliance — a dual regulatory pressure that was a theoretical scenario as recently as six months ago.