SACRAMENTO, 22 AUG 2026 — California's AI Transparency Act became operative on 2 August 2026. Generative AI providers with more than one million monthly users must now publish a free, publicly accessible tool that identifies content their own systems created or altered.
They must also embed a latent disclosure carrying provenance information into generated image, audio and video, and offer users the option of a visible manifest label. The Attorney General, city attorneys and county counsels may bring civil enforcement actions.
The three obligations
A manifest disclosure is the visible one: clear, conspicuous, suited to the medium, understandable to a reasonable person, and permanent or extraordinarily difficult to remove where technically feasible. Providers must offer it as an option to the user.
A latent disclosure is the invisible one, carrying provenance either directly or through a link to a permanent website, again subject to technical feasibility and reasonableness.
The detection tool is the novel part of the law, and the one with the most interesting weaknesses.
Requiring a vendor to detect its own output is genuinely novel
Labelling rules are now common. The EU AI Act requires machine-readable marking of synthetic content, Korea requires notification and labelling for Korean users, and several US states have their own variants. All of those put the burden on the generator to mark what it makes.
SB 942 goes a step further by requiring the provider to operate a service that tells anyone, free of charge, whether a given file came from its models. That is not marking; it is verification on demand, offered to the public rather than to a regulator.
The design has an obvious appeal. A label can be stripped, but a detector that works on the underlying artefact is harder to defeat. Putting the tool in public hands also means that an editor checking a submission, a bank vetting a document, or a court has no need for a relationship with the vendor.
It also creates a liability the industry has spent years avoiding. A public tool that returns an answer is a tool that can be wrong in public, and both error directions are costly.
The false-positive problem is the reason this has not been done before
Detection of AI-generated content is an unsolved problem, and its failure modes are dangerously asymmetric.
A false negative is embarrassing. A false positive is an accusation. A detector that wrongly flags a student's essay, a journalist's photograph, or an insurance claim as machine-generated does real harm to a specific person. The history of AI text detectors in schools is a long demonstration of exactly that.
The statute narrows the problem sensibly by scoping the tool to the provider's own systems rather than to AI content generally. Detecting whether an image came from your own model, where you control the generation pipeline and can embed signals at source, is a far more tractable problem than detecting whether an image came from any model.
That scoping is what makes the requirement plausible. It also means the tool answers a narrower question than most users will assume, a gap in understanding that is sure to cause trouble.
Technically feasible is doing a lot of load-bearing work
Both disclosure obligations are qualified by technical feasibility, and one is further qualified by reasonableness. These escape clauses will determine what the law actually requires in practice.
Provenance metadata survives some transformations and not others. Re-encoding, screenshotting, cropping and platform re-compression destroy most embedded signals, and a screenshot of a generated image is a new file with no history. Any provider can argue that durable latent disclosure is not technically feasible against a determined stripper, and they will be substantially right.
The honest description of what this achieves is therefore narrower than the ambition. It raises the cost of casual misrepresentation and creates a checkable trail for content that has not been deliberately laundered. It does nothing against someone who screenshots the output, and the statute's own drafters clearly knew that, which is why the qualifiers are there.
Why a Californian threshold sets a global product decision
The million-user threshold means this reaches the largest providers, and the largest providers do not build a Californian variant.
For a company operating a single global service, the cheapest response to a jurisdiction-specific transparency rule is almost always to implement it everywhere. Differentiating the product by region costs engineering time and expands the testing matrix, all while inviting the expensive mistake of shipping the wrong build to the wrong market.
So, just as GDPR consent interfaces arrived in markets with no equivalent law, users in Jakarta, Manila and Singapore are likely to receive Californian transparency features without any regional regulator having acted. This is how a state statute becomes a global default.
The corollary for regional regulators is that they inherit an implementation they did not specify. If a detection tool is available in this region because California required it, its accuracy, its scope and its continued existence are governed by Californian enforcement rather than by anything a regional authority can influence.
What remains unconfirmed
No enforcement action has been reported and the operative date is three weeks old. Which providers are treating themselves as covered is not established, nor is how the million monthly user threshold is measured or over what period.
Penalty amounts are not described in the material reviewed. It is not established what accuracy standard applies to the detection tool, whether providers must disclose its error rates, what follows from an incorrect result, or how a court will read the technical feasibility qualifier. Whether the tools now in operation cover text as well as image, audio and video is not stated.
What to watch for
The first thing to watch is what the tools actually report. A detector that returns a confidence score with a documented error rate is a usable instrument; one that returns a bare yes or no is an assertion, and the difference will matter the first time somebody is accused on the strength of it.
The second signal is whether any provider openly claims infeasibility. A large operator stating on the record that durable latent disclosure cannot be achieved against a determined stripper would test the statute's qualifier immediately, and in public.
Finally, it will be telling whether these features appear outside the United States. If they do, the global-default mechanism is confirmed; if providers geofence them to California, it means differentiation was cheaper than expected, which would be the more surprising outcome.