California AI Transparency Act Amendments
California SB 1000 — California AI Transparency Act (2026 Amendments)
United States
RAI-US-CA-SB10000-2026SB 1000
California AI Transparency Act Amendments is In Force in United States, according to leginfo.legislature.ca.gov. We have not yet been able to confirm the status.
ActTransparency and DisclosureAccountability and DocumentationEnforcement and PenaltiesCalifornia expands AI provenance disclosure, privacy safeguards, and enforcement.
Summary
SB 1000 amends California’s AI Transparency Act to expand provenance disclosure, require a free disclosure verification tool, and strengthen privacy and interoperability rules. It also adds targeted enforcement for false assistive-technology claims and preserves public civil enforcement.
Full article
Read full text ↗Overview
SB 1000 is a chaptered California statute that amends the California AI Transparency Act within the Business and Professions Code. It was approved by the Governor and filed with the Secretary of State on 2026-09-30 as Chapter 861, Statutes of 2026, and it took effect immediately as an urgency statute. The law is part of California’s broader effort to make AI-generated content more legible, verifiable, and resistant to misuse. Its central aim is to strengthen provenance disclosure for image, video, and audio content generated or altered by generative AI systems, while also addressing privacy, technical interoperability, and enforcement. The Legislature expressly found that consumers need reliable provenance information to combat misinformation, disinformation, fraud, extortion, and other malicious uses of generative AI. It also emphasized that provenance technology is still developing and that the law should remain adaptive and technologically agnostic.
The amendment significantly reshapes the existing framework. It removes the one-million monthly user threshold from the definition of covered provider, replaces the former AI detection tool with a disclosure verification tool, deletes the user-facing option to add a manifest disclosure, and requires the latent disclosure to indicate whether the GenAI system created or altered the content. It also introduces a temporary, narrower carve-out for GenAI systems designed to primarily function as assistive technology, while prohibiting false claims about that status. In enforcement terms, the statute preserves state-initiated civil actions and adds a separate temporary penalty provision for false assistive-technology representations. The result is a more expansive transparency regime with a stronger emphasis on machine-readable provenance, user privacy, and interoperability with standards-based systems.
Definitions
The statute revises key definitions in Section 22757.1 to support the new disclosure model. “Artificial intelligence” is defined as an engineered or machine-based system that varies in autonomy and can infer from input how to generate outputs affecting physical or virtual environments. “Generative artificial intelligence system” refers to AI that can generate derived synthetic content, including text, images, video, and audio, emulating the structure and characteristics of training data. The law also defines “covered provider” more broadly than before: it now means any person that creates, codes, or otherwise produces a GenAI system that is publicly accessible within California. The former user threshold is gone. Other defined terms include “assistive technology,” “capture device,” “large online platform,” “mass messaging platform,” “metadata,” “minor modification,” “personal information,” “provenance data,” and “system provenance data.”
Several definitions are especially important for compliance. “Minor modification” covers routine alterations such as brightness, contrast, color changes, sharpening, saturating, resizing, scaling, cropping, format conversion, and denoising or background-noise removal in audio. “Provenance data” must be in a format compliant with, or interoperable with, widely adopted specifications adopted by an established standards-setting body. “System provenance data” must not be reasonably capable of being associated with a particular user and must contain either device/system/service information used to generate the content or information related to content authenticity. These definitions reflect the statute’s intention to make provenance disclosure useful without exposing unnecessary personal information. They also create a standards-aware framework that depends on technical compatibility rather than any single mandated format.
Governance and Institutional Framework
Governance under SB 1000 remains centered on California’s public enforcement authorities, especially the Attorney General, city attorneys, and county counsels. The statute does not create a private right of action. Instead, civil penalties are recoverable in government-filed civil actions, and the Attorney General must establish a mechanism to receive reports from covered providers about third-party licensee noncompliance. This approach places implementation oversight in the hands of existing public enforcers rather than a new standalone AI regulator. The law also structures compliance through provider obligations, licensee duties, and platform-level technical access requirements, leaving the market to develop tooling that satisfies the state’s substantive transparency standards.
The law’s governance design is notable for its reliance on interoperability, third-party tools, and notice-based remediation. A provider may satisfy the disclosure verification tool requirement by directing users to a qualifying third-party tool, so long as the tool complies with the section, is compatible with latent disclosures, and is clearly accessible through the provider’s interface. The same collaborative governance logic appears in the standards language for provenance data, which must align with widely adopted specifications. This allows California’s framework to evolve alongside technical standards rather than freezing a single implementation. The result is a regulatory model that combines state enforcement, private technical implementation, and standards-based coordination, while retaining strong public control over penalties and reporting.
Key Focus Areas
The statute’s main focus is provenance transparency for generative AI content. It requires a free disclosure verification tool that can assess whether image, video, or audio content, or any combination of those media types, was created or altered by the provider’s GenAI system, except for minor modifications. The tool must output detected system provenance data, accept uploaded files or URLs, and support access via application programming interface or similar technology without requiring the user to visit the provider’s website. It must also avoid disclosing personal information unless the affected user expressly consents after receiving clear notice about the permanence of embedded provenance data. These provisions show a strong policy preference for user-friendly verification coupled with privacy protection.
Another focus is the latent disclosure regime. Providers must embed a permanent or extraordinarily difficult-to-remove disclosure that conveys the provider’s name, the GenAI system name and version, the time and date of creation or alteration, a unique identifier, and whether the GenAI system created or altered the content. Beginning 2029-01-01, if the system is designed to primarily function as assistive technology, that status must also be disclosed in the latent disclosure. SB 1000 also narrows the media exemption to products, services, websites, or applications that provide exclusively non-user-generated videogames. In addition, the law addresses third-party licensing by requiring notice to licensees, time-bound remediation, and reporting to the Attorney General when a licensee modifies a system into noncompliance. The law therefore combines disclosure, privacy, platform interoperability, licensing controls, and enforcement in one package.
Implementation Framework
Implementation begins with the covered provider’s duty to provide a disclosure verification tool at no cost. The tool must be publicly accessible, but providers may impose reasonable access limits to prevent demonstrable risks to system security or integrity or to prevent malicious misuse. The user must be able to upload content or submit a URL, and the tool must support a way to invoke it without visiting the provider’s website. Providers must collect user feedback about the tool’s efficacy and incorporate relevant feedback into improvements. They may not collect, use, retain, sell, share, or otherwise make available personal information derived from tool users or processed content beyond what is strictly necessary to comply with the chapter, except for limited opt-in communication with users who ask to be contacted.
The latent disclosure requirements apply to image, video, or audio content, or combinations thereof, that are created or altered, except by minor modification, by the provider’s GenAI system, to the extent technically feasible. The disclosure must be permanent or extraordinarily difficult to remove or tamper with, compatible with the provider’s disclosure verification tool, and interoperable with widely recognized industry standards. If the covered provider licenses its GenAI system to a third party, it must notify the licensee of its obligations under the chapter. If the provider knows that an identifiable third-party licensee has modified the system so that it no longer complies, the provider must either terminate the authorization within 72 hours or notify the licensee within 72 hours of the noncompliance and reporting duties. The licensee then has 96 hours to remediate or stop using the system and report back. This sequence creates a structured remediation pathway rather than immediate automatic revocation.
Monitoring and Evaluation
Monitoring under SB 1000 is built into the tool itself and the reporting chain for licensed systems. Providers must collect user feedback on the disclosure verification tool and incorporate that feedback into efforts to improve efficacy. That requirement is unusual in that it explicitly ties ongoing performance improvement to end-user experience, suggesting that the legislature expects provenance tools to evolve over time. The law’s emphasis on interoperability and standards compliance also functions as an evaluation mechanism, because providers must ensure that disclosures work with established technical specifications and with their own verification tools. In practical terms, providers are encouraged to measure whether content can still be detected after ordinary transformations, while also minimizing unnecessary exposure of personal information.
For third-party licensees, the monitoring model is notice-driven rather than continuous surveillance. The statute expressly says a covered provider is not required to monitor, investigate, or otherwise inquire into a licensee’s use or modification of a licensed GenAI system. Instead, the provider’s duty arises when it knows of noncompliance. At that point, the statute requires a rapid remedial process and, if needed, reporting to the Attorney General. The Attorney General’s reporting mechanism is the principal public-facing monitoring channel for these licensee issues. This design is important because it limits the compliance burden on providers while still ensuring that noncompliant deployments are surfaced to enforcement authorities. It also shows that California is regulating provenance through auditability and response obligations rather than through constant supervisory review.
Penalties, Liability, and Appeals
SB 1000 preserves and refines civil enforcement. A violator of the chapter is liable for a civil penalty of $5,000 per violation, enforced through civil action by the Attorney General, a city attorney, or a county counsel. Each day of violation by a covered provider, large online platform, or capture device manufacturer counts as a discrete violation. A prevailing plaintiff is entitled to reasonable attorney’s costs and fees. The statute also specifies that a civil action brought before the effective date of the act adding the relevant subdivision cannot be maintained if the alleged conduct would not violate the chapter after the amendment takes effect. There is no separate administrative appeals process described in the text, and no private right of action is created.
The statute adds a special temporary penalty for false assistive-technology representations. A violator of subdivision (d) of Section 22757.3 is liable for $50,000 per violation in a civil action filed by public enforcement officials, and each day of violation is a discrete violation. This special provision remains in effect only until 2029-01-01, when it is repealed. That makes the assistive-technology safeguard both more serious and more time-limited than the general penalty rule. The structure suggests the legislature’s concern that a provider might exploit the temporary exemption for assistive technology by mislabeling a general-purpose GenAI system. Liability thus turns not only on technical noncompliance but also on deceptive characterization. The statute’s penalty scheme is calibrated to deter both ordinary disclosure failures and more serious misrepresentation.
Relationship to Other Instruments
SB 1000 amends existing sections of the California AI Transparency Act rather than replacing the entire framework. It revises Sections 22757.1 through 22757.5 and adds Section 22757.4.1, while leaving the chapter’s overall structure intact. The law’s own legislative findings emphasize compatibility with established standards and technological neutrality, which means it is designed to sit alongside industry provenance mechanisms rather than displace them. Its definition of provenance data expressly incorporates compliance or interoperability with widely adopted specifications adopted by an established standards-setting body, signaling an intent to align legal duties with emerging technical ecosystems.
The statute also interacts with other California AI and consumer-protection measures by narrowing the scope of one exemption and expanding enforceable transparency obligations. It specifically excludes products, services, websites, or applications that provide exclusively non-user-generated videogames, but not broader entertainment categories. Its provisions on assistive technology are temporary and tied to a 2029 repeal date for the special penalty section. The broader statutory design suggests that SB 1000 is a sequel to the original transparency regime, tightening obligations while preserving the earlier chapter’s policy purpose. Because the law is chaptered and in force, compliance should be analyzed as part of the current California AI Transparency Act, not as a standalone proposed amendment.
National/Federal Alignment
California’s approach under SB 1000 aligns with federal concerns about AI transparency, consumer deception, and content authenticity, but it remains a state-specific disclosure regime rooted in California business regulation. The statute expressly references misinformation, public health, election integrity, fraud, and extortion as reasons for immediate effectiveness. In that sense, it complements federal priorities around deceptive synthetic media and online trust, while moving faster and more concretely than any general federal AI transparency mandate identified here. The law also incorporates privacy protections by limiting personal information handling in the disclosure verification tool, which is consistent with broader U.S. privacy and cybersecurity policy trends even though no federal counterpart is established by this statute.
The law also contains an express federal alignment point in its definitions: “Large online platform” excludes broadband internet access service and telecommunications service as defined under federal law. That cross-reference helps avoid overlap with federal communications categories and narrows the statute’s downstream reach. More broadly, the statute’s standards-based language and technical-feasibility qualifiers suggest an effort to harmonize with federal and industry interoperability norms rather than to create isolated state-only technical rules. At the same time, because the measure is a California statute, it does not establish federal preemption or national applicability. It instead adds a state enforcement layer that companies operating nationally must accommodate if they make GenAI systems publicly accessible in California.
Implementation Timeline
| Milestone | Date | Notes |
|---|---|---|
| Governor approval and filing with Secretary of State | 2026-09-30 | Chapter 861, Statutes of 2026; urgency statute effective immediately. |
| Act effective date | 2026-09-30 | Status is In Force. |
| Assistive-technology exemption applies | 2026-09-30 | Chapter does not apply before 2029-01-01 to GenAI systems designed to primarily function as assistive technology. |
| Assistive-technology status disclosure begins | 2029-01-01 | Latent disclosure must state whether the system is designed to primarily function as assistive technology. |
| Special false-assistive-technology penalty repealed | 2029-01-01 | Section 22757.4.1 sunsets and is repealed. |
Compliance Checklist
| Check | Required Action |
|---|---|
| Covered provider status | Confirm whether the GenAI system is publicly accessible in California; the user-threshold test no longer applies. |
| Disclosure verification tool | Provide a no-cost tool that can assess whether image, video, or audio content was created or altered by the system, excluding minor modifications. |
| Privacy controls | Prevent the tool from disclosing personal information unless express consent is obtained after required notice. |
| Access and interoperability | Allow content upload, URL submission, and API or equivalent invocation without requiring website-only access. |
| Latent disclosure | Embed permanent or hard-to-remove provenance data including provider name, system name/version, date/time, unique identifier, and whether the system created or altered the content. |
| Standards alignment | Ensure provenance data is compliant with or interoperable with widely recognized industry standards. |
| Licensee controls | Notify licensees of chapter obligations and follow 72-hour/96-hour remediation and reporting steps for known noncompliance. |
| Assistive technology claims | Do not falsely represent a system as primarily assistive technology; the enhanced penalty applies to false claims. |
| Enforcement readiness | Prepare for civil actions by the Attorney General, city attorneys, or county counsels and daily violation counting. |
Sources and References
| Source | Type |
|---|---|
| Senate Bill No. 1000, Chapter 861, Statutes of 2026 — California Legislative Information | official |
| Governor of California — signing announcement, 30 September 2026 | official |
More AI regulation in United States
© Regulations.AI — created on 9 Oct 2026 using Gemini 3.6 Flash