California’s new AI transparency rules took effect August 2, requiring major generative artificial intelligence companies to give the public tools for identifying images, video, and audio created or altered by their systems.
The California AI Transparency Act applies to companies whose generative AI systems receive more than 1 million monthly visitors or users and are publicly available in the state. Covered providers must offer a free tool that allows someone to upload digital media or submit an online link to determine whether the company’s system produced or changed the content.
Detection tools must also display available information about the AI system connected to the file. Companies cannot use the process to collect personal information from the person submitting the material or reveal data that identifies an individual user.
California lawmakers first established the framework through SB 942 in 2024. AB 853, signed by Gov. Gavin Newsom in October 2025, delayed the first requirements until August 2, 2026, while adding future obligations for online platforms, AI model hosting services and manufacturers of cameras, phones and other recording devices.
Large AI providers must now give users the option to add a visible notice to media created or altered by their systems. The disclosure must identify the material as AI-generated, be understandable to an ordinary viewer, and remain difficult to remove when current technology allows.
Providers must also place information within the digital file itself. The law calls this a latent disclosure, which may identify the company, the AI system and version, the time and date the media was created or changed and a unique identifier connected to the content.
Such information is part of a broader system known as content provenance. Provenance creates a record of where a digital file originated and what changes were made to it, much like a history attached to the image, recording or video.
The record does not establish that the content is true or false. California is instead requiring covered companies to preserve information that may help users determine whether media came from a generative AI system and whether later alterations were recorded.
That distinction is central to the law. The state is not banning synthetic media or requiring platforms to remove content merely because it lacks a disclosure. The rules focus on traceability by giving users access to information about how certain digital material was produced.
Privacy protections limit what companies may retain through their detection tools. Providers generally cannot keep submitted media longer than needed to analyze it, store personal information about the person using the tool or preserve personal provenance data found within a file.
A company may retain contact information when a person voluntarily provides feedback and agrees to be contacted. The information may be used only to evaluate and improve the detection tool.
Public authorities are responsible for enforcing the requirements. California’s attorney general, city attorneys and county counsel may bring civil actions seeking penalties of $5,000 for each violation, with every day of continued noncompliance treated as a separate violation.
The enforcement structure differs from a private consumer lawsuit seeking financial compensation. Individuals may use the disclosure and detection systems, but the statute assigns penalty actions to designated state and local government lawyers.
Newsom acknowledged concerns about the law’s reach when he signed AB 853. His signing message stated that provenance tools could help people understand the origin of digital content while also raising technical and privacy questions that lawmakers might need to address.
Technology industry representatives raised similar concerns during legislative hearings. They argued that content authentication standards were still developing and warned that embedded records could expose device information, timestamps, locations, or other sensitive details.
The final law addresses some of those concerns by limiting several duties to what is technically feasible. Certain requirements also depend on standards that have been widely adopted by recognized technical organizations, rather than a system created solely by the state.
Responsibility will expand beyond AI developers on January 1, 2027. Large social media services, search engines, file-sharing platforms and mass messaging services will be required to detect qualifying provenance information and tell users when it is available.
Covered platforms must also provide a way to inspect the data and identify the relevant AI system or recording device when that information is present. They may not knowingly remove supported provenance records or digital signatures when the technology allows them to be preserved.
AI model hosting services will face related restrictions beginning on the same date. Websites and applications that allow users to download generative AI source code or model weights may not knowingly distribute systems that fail to include the disclosures required by the act.
Manufacturers will enter the framework on January 1, 2028. Cameras, mobile phones, voice recorders and similar devices first produced for sale in California must offer embedded provenance features when supported by widely adopted standards and technically feasible.
Those features may identify the manufacturer, device name and version, and the date and time the content was recorded or altered. The law also directs manufacturers to enable qualifying provenance functions by default.
The requirements for large generative AI providers are now operative. Rules governing major online platforms and AI hosting services begin January 1, 2027, followed by the capture device provisions on January 1, 2028.