California AB 2713

California AB 2713 — California AI Transparency Act: System Provenance Data

United States

RAI-US-CA-AB27130-2026

AB 2713

Awaiting Entry(Awaiting Entry)

California AB 2713 is Awaiting Entry in United States, according to leginfo.legislature.ca.gov. We have not yet been able to confirm the status.

ActTransparency and DisclosureAccountability and DocumentationGovernance and Oversight
Export PDF

California AB 2713 strengthens AI provenance transparency rules for large online platforms.

Summary

California AB 2713 amends the California AI Transparency Act to refine the obligations placed on large online platforms that host content associated with AI provenance information. It requires provenance detection, user-facing disclosure, and accessible inspection of standardized provenance data while limiting obligations for noncompliant formats and personal information.

Full article

Read full text ↗

Overview

California AB 2713 amends the California AI Transparency Act to refine the obligations placed on large online platforms that host content associated with AI provenance information. The statute is chaptered as Chapter 856, Statutes of 2026, and it becomes operative on 2027-01-01. Its core purpose is to improve user access to provenance signals tied to content that has been generated or substantially altered by generative AI systems, or captured by a capture device, while limiting compliance burdens where the relevant provenance data is not based on widely adopted specifications from an established standards-setting body. The law sits within the Business and Professions Code and updates Section 22757.3.1.

The amended framework requires a large online platform to detect provenance data when it is embedded in, attached to, or otherwise associated with distributed content; provide a user interface that reliably indicates whether system provenance data or a digital signature identifies the content as AI-generated, AI-altered, or captured; and allow users to inspect available system provenance data in an easily accessible manner. The platform may satisfy the inspection obligation by displaying the data directly, linking to another website or application, or allowing a download in a format that cannot easily be embedded into unrelated content. The statute also preserves an express boundary: it does not require a platform to maintain, display, or allow download of personal information, and it does not compel action regarding provenance data or digital signatures that are not compliant or interoperable with widely adopted specifications issued by an established standards-setting body.

Definitions

The statute itself uses several functional terms without creating a broad standalone glossary. A “large online platform” is the regulated entity, and its duties attach when content is distributed on that platform. The key technical concept is “system provenance data,” which refers to metadata or related signals that indicate the authenticity, origin, or modification history of content. The law also refers to “digital signature,” “provenance data,” “GenAI system,” and “capture device,” making clear that the inspection and disclosure requirements are tied to content created or substantially altered by generative AI systems, as well as content captured by devices that may embed provenance information. The phrase “widely adopted specifications issued by an established standards-setting body” is central because the new subsection expressly limits the platform’s obligations to provenance data and signatures that conform to or are interoperable with such specifications.

Two practical definitional boundaries matter for compliance. First, the statute distinguishes system provenance data from personal information: the obligations in subdivision (a) must not be construed to require a platform to maintain, display, or permit a user to download personal information. Second, the law focuses on technical feasibility and interoperability. A platform is not required to take action with respect to provenance data, system provenance data, or digital signatures that fail to comply with widely adopted specifications from an established standards-setting body. In effect, the statute encourages a standards-based ecosystem while avoiding a mandate to process proprietary or incompatible provenance formats. The result is a compliance regime that is narrower than a universal content-labeling law but more detailed than a generic transparency policy.

Governance and Institutional Framework

AB 2713 is structured as a direct statutory obligation enforced through California’s ordinary business and consumer protection legal architecture rather than through a specialized new AI regulator. The operative legal duty is placed on large online platforms in the Business and Professions Code. This means the law relies on existing state enforcement channels, including the Attorney General and other mechanisms available under California law, rather than creating a bespoke licensing or certification agency. The governance model is therefore decentralized: regulated platforms must build and maintain the technical and user-interface functionality, while the state’s role is to interpret, supervise, and enforce compliance as part of its broader consumer protection and unfair competition framework.

The statute’s institutional design also depends on standards-setting bodies outside the California government. By tying the obligation to “widely adopted specifications issued by an established standards-setting body,” the legislature effectively incorporates a standards-based governance layer into state law. That approach makes the law more interoperable with industry and international provenance efforts, but it also means that compliance may vary depending on whether content provenance formats have been adopted broadly enough to fall within the statutory boundary. The legislation thereby creates a hybrid model: California mandates disclosure and inspection for standardized provenance data, but it does not attempt to define all technical formats on its own. This reduces regulatory friction and may encourage platform collaboration with standards bodies, content authenticity initiatives, and third-party display tools.

Key Focus Areas

The statute focuses on transparency, authenticity, and content traceability. Its main policy goal is to ensure that users can understand whether online content has been generated or substantially altered by AI and, if so, obtain accessible provenance information that helps them assess origin, modification history, and authenticity. The law’s UI requirement is significant because it obligates platforms not only to preserve provenance signals but also to surface them in a way that is “clearly and conspicuously” available to users. That makes provenance disclosure a consumer-facing compliance function rather than a back-end archival duty.

A second focus area is content integrity across the lifecycle of online distribution. The prohibition on knowingly stripping provenance data or digital signatures, to the extent technically feasible, addresses the risk that labels or authenticity signals will be removed when content is uploaded, redistributed, or downloaded. This reflects a lifecycle approach to AI transparency: provenance should persist as content moves across the platform ecosystem. A third focus area is legal and technical scope control. The statute expressly avoids imposing obligations related to personal information and excludes noncompliant or noninteroperable provenance formats. That limits exposure to privacy concerns and places the law within the practical boundaries of available standards. The result is a narrow but meaningful regime aimed at making AI-generated and AI-modified content more intelligible to users without imposing open-ended data retention duties.

Implementation Framework

Implementation begins with content ingestion and provenance detection. A large online platform must detect whether provenance data is embedded into, attached to, or otherwise associated with content distributed on the platform. If provenance is present, the platform must provide a user interface that reliably indicates whether the provenance data or digital signature identifies the content as generated or substantially altered by a GenAI system, or captured by a capture device. The interface must also reveal enough information to identify the content’s authenticity, origin, or history of modification, including whether provenance data exists, the name of the GenAI system or capture device if applicable, and whether digital signatures are present. These functions likely require platform engineering changes at the upload, storage, rendering, and download layers.

The inspection requirement may be satisfied in three ways: direct display through the platform UI; a link to a website or application that displays the provenance data, including a third-party service; or a downloadable copy of the provenance data, subject to federal copyright law and in a format that cannot easily be embedded into unrelated content. The law also includes a feasibility qualifier for stripping provenance: the platform must not knowingly strip system provenance data or digital signatures “to the extent technically feasible.” This language matters because it allows platforms to calibrate implementation against technical constraints, but it does not create a blanket exception. Internal compliance programs should therefore map provenance ingestion, display, and preservation workflows, and also document how the platform handles formats outside the statutory interoperability threshold.

Monitoring and Evaluation

Monitoring under AB 2713 is built around operational performance and user-access reliability. Because the law requires a user interface that “reliably indicates” provenance status, platforms should evaluate whether the interface consistently displays provenance information for content where it exists and whether that information remains accurate after reuploads, transformations, or downloads. The statute does not create a dedicated reporting regime or a formal state audit process, but it implicitly expects ongoing internal monitoring of provenance detection, interface accuracy, and stripping-prevention controls. In practice, this means compliance teams will need evidence that provenance data is detected, surfaced, and preserved as intended across product updates and platform integrations.

Evaluation should also address edge cases. The statute expressly excludes personal information from the display and download obligation, so systems need review procedures that ensure provenance displays do not expose unrelated private data. Likewise, compliance teams should track whether provenance formats are compliant with “widely adopted specifications issued by an established standards-setting body,” because the statute does not require action for noncompliant or noninteroperable formats. That creates a need for periodic technical assessment of standards adoption and compatibility. While the law does not prescribe a specific metrics framework, effective oversight would likely include logs of provenance detection rates, false negatives, user-interface uptime, download availability, and incidents involving attempted stripping of provenance data or digital signatures.

Penalties, Liability, and Appeals

AB 2713 does not create a bespoke penalty schedule, criminal offense, or private right of action. Instead, enforcement is expected to occur through California’s ordinary statutory and administrative mechanisms applicable to Business and Professions Code violations. That means liability exposure will depend on how the amended section is enforced under the broader state legal framework, including potential actions by state officials. Because the statute is framed as a compliance obligation imposed on large online platforms, failure to detect provenance data, provide the required interface, allow inspection, or avoid knowingly stripping provenance may create regulatory and litigation risk even though the section itself does not enumerate fine amounts.

There is also no express appeals procedure in the operative language. Any challenge to enforcement, interpretation, or applicability would therefore likely proceed under generally available administrative, judicial, or constitutional channels rather than through a specialized review process in the statute. The law’s technical-feasibility language may be important in any dispute over whether a platform knowingly stripped provenance data or was required to take action with respect to noncompliant formats. Similarly, the exclusion for personal information may be relevant if a platform argues that particular provenance payloads could not be displayed without exposing private data. In short, the statute creates a compliance duty with ordinary state-law consequences, but it does not itself specify a separate sanctions architecture.

Relationship to Other Instruments

AB 2713 amends an existing framework rather than creating a standalone AI regime. It specifically revises Section 22757.3.1 of the Business and Professions Code, which already addressed AI detection tools and large online platform duties relating to system provenance data. The amendment narrows and clarifies those duties by stating that the law does not require platforms to act on provenance data or digital signatures that are not compliant or interoperable with widely adopted specifications issued by an established standards-setting body. As a result, the statute is best understood as a refinement of California’s earlier AI transparency architecture rather than a replacement for it.

The statute also fits within a broader state policy environment that includes separate California measures addressing AI transparency, AI-generated content, and platform accountability. It stands alongside other transparency-oriented rules because it is focused on disclosure and inspection rather than model registration or generalized AI licensing. At the same time, the explicit reference to standards-setting bodies ties the measure to technical provenance ecosystems used across the digital content supply chain. That makes the law relevant to platform engineers, content authenticity providers, and developers of provenance metadata specifications, even though the legal obligation is imposed only on large online platforms. The result is an interoperability-centered amendment that reinforces California’s transparency regime while leaving room for standards evolution.

National/Federal Alignment

As a California statute, AB 2713 operates within the state’s police powers and does not itself establish federal requirements. Its standards-based approach aligns conceptually with broader federal interest in content provenance, AI safety, and digital authenticity, but it is not a federal rule and does not depend on a federal agency promulgation to become operative. The law’s focus on provenance data, digital signatures, and user-facing disclosure is compatible with efforts in the broader U.S. ecosystem to improve authenticity signals for synthetic media and altered content. The statute’s respect for technical feasibility and standards interoperability also reduces the risk of collision with emerging federal technical specifications.

At the same time, AB 2713 differs from federal regulation by imposing a state-specific transparency obligation on large online platforms. It does not preempt the federal field, and it does not create a general national standard for provenance or content labeling. Instead, it adds a California-specific compliance layer that platforms must incorporate alongside any federal copyright, privacy, or platform governance rules. Because the law expressly preserves federal copyright constraints when allowing downloads of provenance data, and because it avoids requiring the handling of personal information, it is designed to coexist with federal legal regimes rather than displace them. For multi-jurisdictional platforms, the practical result is a California-specific operational requirement that should be harmonized with national product architecture.

Implementation Timeline

MilestoneDateNotes
Governor approval and filing2026-09-30Approved by the Governor and filed with the Secretary of State; chaptered as Chapter 856, Statutes of 2026.
Chaptered statute enacted2026-09-30AB 2713 becomes a chaptered Act amending Business and Professions Code Section 22757.3.1.
General operative date2027-01-01The amended large online platform provisions become operative on this date.
In-force date2027-01-01Under the stated constitutional rule and the operative clause, the law is effective on this date.

Compliance Checklist

CheckRequired Action
Provenance detectionDetect whether provenance data is embedded into, attached to, or otherwise associated with distributed content.
User interface disclosureProvide a clear UI indicator of whether content is AI-generated, substantially altered, or captured by a device.
Mandatory data fieldsDisplay whether provenance data exists, the GenAI system or capture device name if applicable, and whether digital signatures are present.
Inspection accessAllow users to inspect available system provenance data through direct display, link-out, or downloadable format.
Personal information safeguardEnsure provenance features do not require maintaining, displaying, or downloading personal information.
Noncompliant formatsNo action is required for provenance data or signatures that are not compliant or interoperable with widely adopted specifications.
Anti-stripping controlsDo not knowingly strip provenance data or digital signatures to the extent technically feasible.

Sources and References

SourceType
Assembly Bill No. 2713, Chapter 856, Statutes of 2026 — California Legislative Informationofficial
Governor of California — signing announcement, 30 September 2026official

© Regulations.AI — created on 9 Oct 2026 using Gemini 3.6 Flash