United States - California - AI Transparency Act (SB 942)

California SB 942 — California AI Transparency Act

United States

RAI-US-CA-CS9CAXX-2024
Effective: January 1, 2026
In Force(In Force)
ActTransparency and DisclosureEnforcement and Penalties
Export PDF

California Senate Bill 942 establishes comprehensive transparency requirements for generative AI systems with over one million monthly users. The law mandates that covered providers offer free AI detection tools, embed invisible provenance metadata in AI-generated content, provide visible disclosure options to users, and maintain strict data handling practices. Violations carry civil penalties of $5,000 per day.

Overview

California Senate Bill 942, the California AI Transparency Act, represents the most comprehensive state-level regulation of AI content transparency in the United States. Signed by Governor Gavin Newsom on September 19, 2024, and effective January 1, 2026, the law addresses growing concerns about AI-generated misinformation, deepfakes, and the difficulty of distinguishing synthetic content from authentic human-created media. SB 942 establishes a multi-layered framework requiring large generative AI providers to implement detection tools, embed provenance metadata in AI-generated content, and offer visible disclosure options to users. The legislation responds to the rapid deployment of powerful generative AI systems capable of producing increasingly realistic text, images, video, and audio content that can be used to deceive viewers, spread misinformation, impersonate individuals, or undermine trust in authentic media. By mandating both visible and invisible content labels alongside detection capabilities, California creates accountability mechanisms that allow individuals, platforms, journalists, and researchers to verify the synthetic nature of content. The law complements AB 2013, which focuses on training data transparency, together creating a comprehensive framework addressing both the input (training data) and output (generated content) sides of the generative AI pipeline.

Definitions

SB 942 establishes precise definitions that determine the law's scope and technical requirements. Covered provider means any person that creates, codes, or otherwise produces a generative artificial intelligence system that has over one million monthly visitors or users, establishing a significant size threshold that targets major AI platforms while exempting smaller developers. Generative artificial intelligence system means artificial intelligence, as defined in Section 11546.45.5 of the Government Code, that is capable of generating synthetic content, including text, images, video, and audio. Provenance data means data that is used to trace and verify the authenticity of content, track the origin of content, or track whether content has been modified, establishing the foundational concept for the law's disclosure requirements. System provenance data means provenance data about devices used to create content or services used to create or alter content that does not include personal provenance data, distinguishing technical metadata from personally identifiable information. Personal provenance data means provenance data that contains information that identifies, or could be used with other information to identify, a particular individual or a device associated with a particular individual, triggering enhanced privacy protections within the transparency framework. Manifest disclosure refers to visible, human-readable labels on AI-generated content that users can see and understand. Latent disclosure refers to embedded, machine-readable metadata that persists with content regardless of visible markings.

Governance and Institutional Framework

SB 942 establishes a decentralized enforcement model relying on existing government legal offices rather than creating new regulatory agencies. The California Attorney General serves as the primary enforcement authority with power to bring civil actions against violators and collect penalties for deposit into the state General Fund. City attorneys and county counsel share concurrent enforcement authority, enabling local prosecution of violations within their jurisdictions and creating multiple accountability pathways. This distributed enforcement model recognizes that generative AI transparency violations may manifest differently across communities and that local legal offices may be better positioned to identify and respond to harms affecting their residents. The law does not establish formal rulemaking authority, leaving technical implementation details to covered providers while requiring compliance with specific outcome-based requirements. No registration, certification, or approval process exists—providers must self-assess whether they meet the one million user threshold and implement required measures accordingly. The absence of a dedicated oversight agency means monitoring depends on complaint-driven enforcement, investigative journalism, academic research, and market surveillance by government attorneys.

Key Focus Areas

  • AI Detection Tool Provision: Covered providers must offer free, publicly accessible tools that assess whether content was created or altered by their specific generative AI systems, enabling verification of synthetic content origin.
  • Content Provenance Metadata: All AI-generated content must embed invisible metadata including provider name, system name/version, timestamp, and unique identifier that persists through content sharing and modification.
  • Visible Disclosure Options: Users must have options to include clear, conspicuous labels identifying content as AI-generated in formats appropriate to each medium (text, image, video, audio).
  • Privacy-Preserving Design: Detection tools cannot retain personal information from users beyond what is necessary for operation, and system provenance data must be distinguished from personal provenance data.
  • Third-Party Licensing Controls: Licensees receiving generative AI technology must contractually maintain disclosure capabilities, with license revocation required within 96 hours if disclosures are disabled.
  • Permanence of Embedded Disclosures: Latent disclosures must be designed to be permanent or extremely difficult to remove, ensuring metadata persists through content distribution and manipulation.
  • API Access for Detection: Detection tools must provide API access enabling programmatic verification beyond website interfaces, supporting platform-level and automated detection workflows.
  • User Feedback Integration: Providers must collect user feedback on detection tool accuracy and use it to improve detection capabilities over time.
  • Cross-Medium Adaptability: Disclosure requirements apply across all generative content types—text, images, video, and audio—with format-appropriate labeling for each medium.
  • Misinformation Countermeasures: The comprehensive transparency framework aims to combat deepfakes, synthetic media manipulation, and AI-generated misinformation by enabling content verification.

Implementation Framework

SB 942 takes effect January 1, 2026, providing covered providers approximately 15 months from signing to implement required capabilities. Implementation requires a multi-track approach addressing detection tools, manifest disclosures, latent disclosures, and third-party licensing controls. For detection tools, providers must develop or deploy systems capable of identifying content generated by their specific AI models, create public-facing web interfaces for content verification, build APIs for programmatic access, implement feedback collection mechanisms, and establish data handling practices that minimize retention of personal information and user content. The technical challenge of detection varies by content type—text detection remains particularly difficult due to the stylistic variability of language models, while image, video, and audio detection can leverage watermarking, steganographic embedding, and spectral analysis techniques. For manifest disclosures, providers must design user interfaces offering clear opt-in labeling options that work across different content types and distribution contexts. Labels must be 'clear, conspicuous, appropriate for the medium, and understandable to a reasonable person,' requiring human factors analysis to ensure effectiveness without being intrusive. For latent disclosures, providers must implement robust metadata embedding that survives common content transformations including compression, format conversion, cropping, and screenshot capture. For licensing, providers must update agreements with third-party licensees, establish monitoring for disclosure-disabling modifications, and create rapid (96-hour) license revocation procedures. The law does not prescribe specific technical implementations, allowing providers flexibility while requiring outcome-based compliance.

Monitoring and Evaluation

SB 942 does not establish formal monitoring, reporting, or evaluation mechanisms beyond enforcement proceedings. Compliance assessment will occur primarily through enforcement actions initiated by the Attorney General, city attorneys, or county counsel in response to complaints, investigations, or public reporting. Third-party monitoring is expected from several sources: academic researchers studying AI detection effectiveness may systematically test provider tools and publish findings; investigative journalists covering AI misinformation may probe disclosure compliance; civil society organizations advocating for AI transparency may conduct audits and public assessments; and technology platforms receiving AI-generated content may evaluate incoming content against declared provenance data. Market mechanisms may also drive monitoring, as competitors and content authenticity services compare detection tool performance across providers. The law's requirement for user feedback collection on detection tools creates internal data that providers should use for continuous improvement, though this data is not reported to regulators. The effectiveness of latent disclosures in surviving content manipulation will likely be tested by researchers and bad actors alike, providing de facto evaluation of technical robustness. Platform policies requiring AI content disclosure will create practical testing grounds for whether SB 942 disclosures function as intended in content distribution contexts.

Penalties, Liability, and Appeals

SB 942 establishes specific civil penalties and enforcement mechanisms with clear liability standards. Violations carry penalties of $5,000 per violation, collectible through civil actions. Critically, each day of violation constitutes a separate offense, meaning ongoing non-compliance can accumulate substantial penalties—a provider out of compliance for one year could face penalties of $1.825 million or more per violation type. Enforcement actions may be brought by the California Attorney General, city attorneys, or county counsel, with any civil penalties collected deposited into the state General Fund. The distributed enforcement authority increases the likelihood of action against violators, as multiple legal offices may independently pursue cases. Prevailing government plaintiffs are entitled to recover reasonable attorney's fees and costs, removing financial barriers to enforcement. For third-party licensee violations—specifically, modifications that disable disclosure capabilities—the law enables injunctive relief actions to halt unauthorized conduct, providing equitable remedies beyond monetary penalties. The law does not establish a private right of action, meaning individual consumers or affected parties cannot directly sue for violations; enforcement depends on government attorneys taking action. Appeals from enforcement actions follow standard California civil procedure, with defendants able to challenge penalty determinations in Superior Court and pursue appellate review. The significant daily penalty structure creates strong financial incentives for compliance, particularly for large providers where extended non-compliance could generate multi-million dollar liability.

Relationship to Other Instruments

SB 942 operates within California's expanding AI regulatory framework and connects to multiple existing legal frameworks. California AB 2013 creates a complementary framework—while SB 942 addresses output transparency through content provenance and detection, AB 2013 addresses input transparency through training data disclosure. Together they establish comprehensive generative AI transparency covering both sides of the AI development and deployment pipeline. California AB 2839 addresses election-related AI content specifically, prohibiting certain deceptive AI-generated election content and creating additional disclosure requirements for political advertising using AI. SB 942's content provenance framework supports AB 2839 compliance by enabling verification of synthetic political content. The California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA) intersect with SB 942 where provenance data handling involves personal information, creating overlapping compliance obligations. The European Union AI Act includes transparency requirements for AI-generated content, particularly for systems that generate synthetic audio, images, video, or text, creating parallel compliance obligations for providers serving both California and EU markets.

International Alignment

SB 942 aligns California with emerging international standards for AI content transparency while establishing requirements that exceed most existing frameworks. The European Union AI Act requires transparency measures for AI systems that generate synthetic audio, images, video, or text, including labeling obligations for deepfakes and AI-generated content designed to inform or deceive. SB 942's requirements are generally more specific and technically prescriptive, particularly regarding detection tool capabilities and latent disclosure persistence. China's regulations on deep synthesis (deepfake) technology require labeling of synthetically generated content and prohibit certain deceptive uses, showing parallel regulatory evolution though with different enforcement mechanisms and political contexts. The United Kingdom's emerging AI regulatory framework, based on existing sector regulators applying core principles, does not currently include SB 942-equivalent content provenance mandates, though the Online Safety Act addresses some synthetic content harms. SB 942's extraterritorial reach—applying to any provider with one million users who serves California residents—may influence global AI development practices as major providers implement California-compliant systems worldwide rather than maintaining separate regional versions. The law's focus on detection tool provision represents a unique contribution to international AI governance, as most frameworks emphasize disclosure without mandating verification capabilities. California's position as a technology hub and major market gives SB 942 potential to influence both federal U.S. legislation and international AI governance frameworks.

Implementation Timeline

DateMilestone
February 2024SB 942 introduced in California Senate by Senator Josh Becker
May 2024Bill passes Senate with amendments addressing scope and technical requirements
August 2024Bill passes California Assembly
September 19, 2024Governor Gavin Newsom signs SB 942 into law
2025AB 853 passes, modifying SB 942 to establish phased content provenance framework
January 1, 2026Law takes effect; covered providers must comply with all requirements
2026 (phased)Content provenance requirements phase in for image, video, and audio content per AB 853 amendments
OngoingProviders must maintain detection tools, update provenance systems, and respond to enforcement actions

Compliance Checklist

RequirementDetails
Determine Covered Provider StatusAssess whether your generative AI system has over 1 million monthly visitors or users; if so, all requirements apply
Develop AI Detection ToolBuild or deploy tool capable of assessing whether content was created/altered by your generative AI system
Make Detection Tool Publicly AccessibleProvide free web interface accepting content uploads and URL inputs for detection
Implement API AccessCreate API enabling programmatic detection for non-website usage scenarios
Output Provenance DataEnsure detection tool outputs system provenance data when AI-generated content is identified
Collect User FeedbackImplement mechanism to gather user feedback on detection accuracy for continuous improvement
Implement Manifest DisclosuresOffer users options to include visible labels identifying AI-generated content, clear and conspicuous for each medium
Implement Latent DisclosuresEmbed invisible metadata in all AI-generated content: provider name, system name/version, timestamp, unique ID
Ensure Disclosure PermanenceDesign latent disclosures to be permanent or extremely difficult to remove through content transformation
Update Licensing AgreementsRequire third-party licensees to maintain disclosure capabilities contractually
Establish Revocation ProceduresCreate process to revoke licenses within 96 hours if disclosure-disabling modifications discovered
Implement Privacy ProtectionsEnsure detection tools do not retain personal information or content beyond operational necessity

Sources and References

SourceType
SB 942 Bill Text - California LegislaturePrimary Source
SB 942 Bill History - California LegislaturePrimary Source
SB 942 Bill Analysis - California LegislatureLegislative Analysis
Governor Newsom Signing AnnouncementPrimary Source
California Attorney General's OfficeGovernment Agency
AB 2839 (Election Deepfakes) - California LegislatureRelated Legislation
Plain English

California's new AI Transparency Act, Senate Bill 942, mandates clear disclosure requirements for generative artificial intelligence content from large providers. This law applies to any company whose generative AI system, capable of creating synthetic text, images, video, or audio, reaches over one million monthly users.

Starting January 1, 2026, these covered providers must meet several key obligations. They need to offer free, publicly accessible tools that can detect if content was generated or altered by their specific AI systems. Crucially, all AI-generated content must embed invisible metadata, known as "latent disclosures," detailing the provider, system version, timestamp, and a unique identifier. This metadata must be designed to be permanent and difficult to remove. Additionally, users must be given clear options to add visible labels, or "manifest disclosures," identifying content as AI-generated, in a way that suits the medium. Providers must also ensure their detection tools protect user privacy, not retaining personal information beyond what's necessary, and if they license their AI, they must ensure licensees maintain these disclosure capabilities, with a 96-hour window to revoke licenses if disclosures are disabled.

Enforcement falls to the California Attorney General, alongside city and county attorneys. Violations carry a steep civil penalty of $5,000 per day, per violation, meaning non-compliance can quickly lead to multi-million dollar fines. A key practical point is that the law doesn't provide specific technical instructions or a dedicated oversight agency. Instead, providers must self-assess their compliance and figure out the technical implementation themselves, relying on outcome-based requirements. This lack of prescriptive guidance, combined with the severe daily penalties, means companies face a significant challenge in ensuring they meet the spirit and letter of the law without clear regulatory hand-holding.

Plain-English rewrite by Regulations.ai — not legal advice. Verify against the official text.

Read this article-by-article

Plain-English breakdown of 10 key articles, with cross-jurisdiction equivalents where applicable.

Open breakdown →

What you must do — compliance checklist

0 / 10 marked complete

Plain-English obligations under United States - California - AI Transparency Act (SB 942). Not legal advice — verify against the official text before relying on it.

  1. #1CriticalBefore 2026-01-01

    Applies to: Any person producing a generative AI system.

    Covered provider means any person that creates, codes, or otherwise produces a generative artificial intelligence system that has over one million monthly visitors or users
  2. #2CriticalJan 1, 2026

    Applies to: Providers of generative AI systems with over one million monthly users.

    Covered providers must offer free, publicly accessible tools that assess whether content was created or altered by their specific generative AI systems
  3. #3CriticalJan 1, 2026

    Applies to: Providers of generative AI systems with over one million monthly users.

    Detection tools must provide API access enabling programmatic verification beyond website interfaces
  4. #4CriticalJan 1, 2026

    Applies to: Providers of generative AI systems with over one million monthly users.

    All AI-generated content must embed invisible metadata including provider name, system name/version, timestamp, and unique identifier
  5. #5CriticalJan 1, 2026

    Applies to: Providers of generative AI systems with over one million monthly users.

    Latent disclosures must be designed to be permanent or extremely difficult to remove, ensuring metadata persists through content distribution and manipulation.
  6. #6CriticalJan 1, 2026

    Applies to: Providers of generative AI systems with over one million monthly users.

    Users must have options to include clear, conspicuous labels identifying content as AI-generated in formats appropriate to each medium
  7. #7CriticalJan 1, 2026

    Applies to: Providers of generative AI systems with over one million monthly users.

    Licensees receiving generative AI technology must contractually maintain disclosure capabilities
  8. #8CriticalJan 1, 2026

    Applies to: Providers of generative AI systems with over one million monthly users.

    license revocation required within 96 hours if disclosures are disabled.
  9. #9CriticalJan 1, 2026

    Applies to: Providers of generative AI systems with over one million monthly users.

    Detection tools cannot retain personal information from users beyond what is necessary for operation
  10. #10ImportantJan 1, 2026

    Applies to: Providers of generative AI systems with over one million monthly users.

    Providers must collect user feedback on detection tool accuracy and use it to improve detection capabilities over time.

© Regulations.AI — created on 13-Jun-2026