Article-by-article breakdown

California AI Transparency Act

California SB 942 — California AI Transparency Act

DefinitionsKey Definitions and Scope

Applies from: 2026-01-01

Applies to

  • Covered providers
  • Generative AI system developers

Plain English

This section establishes the foundational terms that define who and what the law applies to. A 'covered provider' is any entity that creates or produces a generative AI system used by over one million monthly visitors or users, setting a clear threshold for applicability to major platforms. This means smaller developers or systems with limited reach are generally exempt from these specific requirements.

The law defines a 'generative artificial intelligence system' as AI capable of creating synthetic content like text, images, video, or audio. Crucially, it distinguishes between 'manifest disclosure,' which refers to visible, human-readable labels on AI-generated content, and 'latent disclosure,' which means embedded, machine-readable metadata that persists with the content. Understanding these distinctions is vital for compliance, as the law mandates both types of transparency.

Key points

  • Applies only to generative AI systems with over 1 million monthly users.
  • Generative AI includes systems producing synthetic text, images, video, and audio.
  • Distinguishes between 'manifest' (visible) and 'latent' (embedded) disclosures.
  • 'Provenance data' is key for tracing content authenticity and modifications.

What you need to do

  1. 1.Regularly monitor your system's user base to determine if you meet the 'covered provider' threshold.
  2. 2.Ensure your internal teams understand the definitions of manifest and latent disclosures.
  3. 3.Categorize your AI outputs to align with the law's definitions of synthetic content.

Key Focus Area: AI Detection Tool ProvisionMandatory AI Detection Tools

Applies from: 2026-01-01

Applies to

  • Covered providers

Plain English

Covered providers are required to offer free, publicly accessible tools that can assess whether content was created or significantly altered by their specific generative AI systems. This provision aims to empower users, platforms, and researchers to verify the origin of synthetic content, helping to combat misinformation and deepfakes.

The detection tools must be capable of identifying content generated by the provider's *own* AI models, not just any AI-generated content. This places a direct responsibility on providers to develop or integrate robust detection capabilities specific to their technology. The goal is to provide a mechanism for external parties to confirm if a piece of media originated from a particular large generative AI system.

Key points

  • Providers must offer free, public tools to detect AI-generated content.
  • Tools must identify content created or altered by *their specific* generative AI systems.
  • Aims to enable verification of synthetic content origin.
  • Supports combating misinformation and deepfakes.

What you need to do

  1. 1.Develop or acquire technology to accurately detect content generated by your AI models.
  2. 2.Create a user-friendly, publicly accessible interface for this detection tool (e.g., a website or app).
  3. 3.Ensure the tool is free to use for all users.
  4. 4.Regularly update and improve the detection tool's accuracy.

Key Focus Area: Content Provenance MetadataInvisible Provenance Metadata (Latent Disclosures)

Applies from: 2026-01-01 (phased for image, video, and audio content per AB 853 amendments)

Applies to

  • Covered providers

Plain English

This provision mandates that all AI-generated content must embed invisible, machine-readable metadata, known as latent disclosures. This metadata must include essential information such as the provider's name, the generative AI system's name and version, a timestamp of creation, and a unique identifier for the content. The critical aspect here is that this metadata must be designed to persist even when the content is shared, modified, or undergoes common transformations like compression or format conversion.

The intent is to create a permanent digital fingerprint for AI-generated media, allowing its synthetic origin to be traced and verified regardless of how it is distributed or altered. This 'system provenance data' is distinct from 'personal provenance data,' which identifies individuals, and is subject to different privacy considerations.

Key points

  • All AI-generated content must embed invisible, machine-readable metadata.
  • Metadata must include provider name, system name/version, timestamp, and unique ID.
  • Metadata must persist through content sharing, modification, and common transformations.
  • This is 'system provenance data,' distinct from 'personal provenance data'.

What you need to do

  1. 1.Implement robust watermarking, steganography, or other embedding techniques for all AI-generated outputs.
  2. 2.Ensure the embedded metadata is resilient to common content manipulations (e.g., cropping, compression, screenshots).
  3. 3.Develop internal systems to generate and manage unique identifiers for each piece of AI-generated content.
  4. 4.Coordinate with legal and technical teams to ensure compliance with persistence requirements.

Cross-jurisdiction equivalents

EUEU AI Act, Article 52(3)The EU AI Act requires providers of generative AI to ensure AI-generated content is marked in a machine-readable format, though SB 942 is more prescriptive on the specific data points and persistence.

Key Focus Area: Visible Disclosure OptionsVisible AI Content Labels (Manifest Disclosures)

Applies from: 2026-01-01

Applies to

  • Covered providers

Plain English

In addition to invisible metadata, covered providers must offer users the option to include clear, conspicuous, and human-readable labels that identify content as AI-generated. These 'manifest disclosures' must be appropriate for the specific medium—whether it's text, images, video, or audio—and easily understandable to a reasonable person.

The goal is to provide immediate, visible cues to consumers that the content they are engaging with is synthetic. This empowers users to make informed decisions about the authenticity and origin of information, complementing the machine-readable latent disclosures. Providers must design user interfaces that make these labeling options accessible and effective without being overly intrusive.

Key points

  • Users must have options to add clear, visible labels to AI-generated content.
  • Labels must be conspicuous, human-readable, and appropriate for the medium.
  • Aims to provide immediate cues to consumers about synthetic content.
  • Requires careful UI/UX design to ensure effectiveness without intrusiveness.

What you need to do

  1. 1.Design user interfaces that clearly present labeling options for AI-generated content.
  2. 2.Implement labeling mechanisms that are adaptable across different content types (text, image, video, audio).
  3. 3.Ensure labels are easily understandable and not easily overlooked by users.
  4. 4.Conduct user testing to confirm the clarity and conspicuousness of your manifest disclosures.

Cross-jurisdiction equivalents

EUEU AI Act, Article 52(3)The EU AI Act requires providers of generative AI to disclose that content is AI-generated, particularly for deepfakes, aligning with the spirit of visible labeling.

Key Focus Area: Privacy-Preserving DesignPrivacy Protections for Provenance Data

Applies from: 2026-01-01

Applies to

  • Covered providers

Plain English

This provision emphasizes the importance of privacy in the implementation of AI transparency measures. It mandates that detection tools must not retain personal information from users beyond what is strictly necessary for their operation. This ensures that while content origin is verifiable, user privacy is not compromised.

Furthermore, the law requires a clear distinction between 'system provenance data' (technical metadata about the AI system) and 'personal provenance data' (information that identifies an individual or their device). Any handling of personal provenance data would trigger enhanced privacy protections, likely aligning with existing California privacy laws like the CCPA and CPRA. This ensures that the pursuit of transparency does not inadvertently lead to new privacy risks for individuals.

Key points

  • Detection tools must not retain personal information beyond operational necessity.
  • Clear distinction required between 'system provenance data' and 'personal provenance data'.
  • Enhanced privacy protections apply to 'personal provenance data'.
  • Aims to prevent new privacy risks while enabling transparency.

What you need to do

  1. 1.Implement data minimization principles in the design and operation of detection tools.
  2. 2.Establish clear data classification policies for provenance data, distinguishing between system and personal information.
  3. 3.Ensure compliance with CCPA/CPRA for any personal data collected or processed.
  4. 4.Conduct privacy impact assessments for all data handling related to provenance and detection.

Cross-jurisdiction equivalents

US-CACCPA/CPRAThis provision directly intersects with California's existing comprehensive privacy laws, requiring adherence to their principles for any personal data involved in provenance.

Key Focus Area: Third-Party Licensing ControlsLicensee Disclosure Obligations

Applies from: 2026-01-01

Applies to

  • Covered providers
  • Licensees of generative AI technology

Plain English

This provision extends transparency obligations beyond the direct provider to entities that license generative AI technology. Covered providers must ensure that their licensing agreements with third parties contractually require these licensees to maintain the mandated disclosure capabilities—both manifest and latent. This means licensees cannot disable or remove the transparency features built into the AI system.

Furthermore, if a provider discovers that a licensee has modified the technology in a way that disables these disclosure capabilities, the provider is obligated to revoke the license within 96 hours. This creates a strong incentive for both providers to monitor their licensed technology and for licensees to comply with the transparency requirements, ensuring that the integrity of AI-generated content is maintained throughout its distribution chain.

Key points

  • Providers must contractually require licensees to maintain disclosure capabilities.
  • Licensees cannot disable manifest or latent disclosure features.
  • Providers must monitor for disclosure-disabling modifications by licensees.
  • License revocation is required within 96 hours if such modifications are discovered.

What you need to do

  1. 1.Review and update all licensing agreements for generative AI technology to include specific clauses on maintaining disclosure capabilities.
  2. 2.Implement monitoring systems to detect unauthorized modifications by licensees that disable disclosures.
  3. 3.Establish a rapid response protocol for license revocation within the 96-hour timeframe.
  4. 4.Educate licensees on their obligations under SB 942.

Key Focus Area: Permanence of Embedded DisclosuresRobustness of Latent Disclosures

Applies from: 2026-01-01

Applies to

  • Covered providers

Plain English

This provision specifically addresses the technical resilience of latent (invisible) disclosures. It mandates that these embedded metadata elements must be designed to be either permanent or extremely difficult to remove. This requirement is crucial because AI-generated content often undergoes various transformations as it is shared and distributed across different platforms and applications.

The disclosures must be able to survive common content manipulations such as compression, format conversion, cropping, and even screenshot capture. The intent is to prevent malicious actors from easily stripping away the provenance data, thereby ensuring that the synthetic nature of the content remains verifiable throughout its lifecycle. This places a significant technical challenge on providers to implement highly robust embedding techniques.

Key points

  • Latent disclosures must be permanent or extremely difficult to remove.
  • Disclosures must survive common content transformations (e.g., compression, cropping).
  • Aims to prevent malicious removal of provenance data.
  • Requires robust technical implementation for metadata embedding.

What you need to do

  1. 1.Invest in advanced watermarking or steganographic technologies that are resilient to various content manipulations.
  2. 2.Rigorously test the persistence of embedded metadata across different platforms, file formats, and editing scenarios.
  3. 3.Continuously research and update embedding techniques to counter evolving methods of metadata removal.
  4. 4.Collaborate with industry experts to develop best practices for robust latent disclosures.

Key Focus Area: API Access for DetectionProgrammatic Access for Detection Tools

Applies from: 2026-01-01

Applies to

  • Covered providers

Plain English

To facilitate broader and more efficient verification of AI-generated content, SB 942 requires that the mandated detection tools provide API (Application Programming Interface) access. This means that in addition to a public-facing website or application, the detection capabilities must be programmatically accessible.

API access enables other platforms, researchers, journalists, and automated systems to integrate the detection functionality directly into their own workflows. This supports large-scale content verification, automated monitoring, and the development of third-party tools that can leverage the provider's detection capabilities. It moves beyond manual, one-off checks to enable systemic detection across the digital ecosystem.

Key points

  • Detection tools must offer API access for programmatic verification.
  • Enables integration into other platforms and automated systems.
  • Supports large-scale content verification and third-party tool development.
  • Goes beyond simple web interfaces for detection.

What you need to do

  1. 1.Develop and maintain a robust, well-documented API for your AI detection tool.
  2. 2.Ensure the API is scalable and can handle a high volume of requests.
  3. 3.Provide clear guidelines and support for developers wishing to integrate with your API.
  4. 4.Consider rate limits and authentication mechanisms for API usage.

Key Focus Area: User Feedback IntegrationContinuous Improvement via User Feedback

Applies from: 2026-01-01

Applies to

  • Covered providers

Plain English

This provision mandates that covered providers must implement mechanisms to collect user feedback on the accuracy and performance of their AI detection tools. Furthermore, providers are required to actively use this feedback to continuously improve their detection capabilities over time.

This requirement acknowledges that AI detection technology is constantly evolving and that real-world usage can reveal limitations or areas for enhancement. By integrating user feedback into the development cycle, the law aims to foster a dynamic and responsive approach to AI transparency, ensuring that detection tools remain effective and reliable as generative AI systems become more sophisticated.

Key points

  • Providers must collect user feedback on detection tool accuracy.
  • Feedback must be used for continuous improvement of detection capabilities.
  • Aims to ensure detection tools remain effective and reliable.
  • Fosters a dynamic and responsive approach to AI transparency.

What you need to do

  1. 1.Implement user feedback channels within your detection tool (e.g., surveys, reporting features).
  2. 2.Establish internal processes for analyzing user feedback and identifying areas for improvement.
  3. 3.Allocate resources for ongoing research and development to enhance detection accuracy.
  4. 4.Communicate updates and improvements to users based on their feedback.

Penalties, Liability, and AppealsEnforcement and Penalties for Non-Compliance

Applies from: 2026-01-01

Applies to

  • Covered providers
  • Licensees of generative AI technology

Plain English

SB 942 establishes significant civil penalties for violations, designed to create strong financial incentives for compliance. Each violation carries a penalty of $5,000, and critically, 'each day of violation constitutes a separate offense.' This means that ongoing non-compliance can quickly accumulate substantial fines, potentially reaching millions of dollars for extended periods of non-adherence.

Enforcement authority is distributed among the California Attorney General, city attorneys, and county counsel, allowing for multiple pathways for legal action. Prevailing government plaintiffs are also entitled to recover reasonable attorney's fees and costs. While there is no private right of action for individuals, the law does allow for injunctive relief actions against third-party licensees who disable disclosure capabilities, providing equitable remedies beyond monetary penalties. Appeals follow standard California civil procedure.

Key points

  • Civil penalty of $5,000 per violation.
  • Each day of violation constitutes a separate offense, leading to potentially high cumulative fines.
  • Enforced by California Attorney General, city attorneys, and county counsel.
  • Prevailing government plaintiffs can recover attorney's fees and costs.
  • No private right of action for individuals.
  • Injunctive relief available for licensee violations.

What you need to do

  1. 1.Recognize the high financial risk associated with non-compliance due to daily penalties.
  2. 2.Establish robust internal compliance programs and regular audits.
  3. 3.Be prepared for potential investigations or enforcement actions from multiple government entities.
  4. 4.Ensure legal counsel is aware of the enforcement mechanisms and potential liabilities.

Cross-jurisdiction equivalents

EUEU AI Act, Article 99The EU AI Act also includes significant fines for non-compliance (up to €35 million or 7% of global annual turnover), demonstrating a global trend towards substantial penalties for AI regulation violations.

Need help applying this to your case?

The wizard takes 60 seconds and tells you which articles you actually need to worry about based on your jurisdictions, use case, and data.

Start the wizard →