California's AI Transparency Act became operative on August 2, 2026, and most coverage of it is aimed at the wrong audience. It applies to generative AI providers with more than a million monthly users, not to businesses that use AI tools. It also does not cover text at all. Here is what it actually requires, what changes in 2027, and the one part that genuinely reaches ordinary businesses.
California's AI Transparency Act became operative on August 2, 2026, and a lot of the commentary around it is aimed at an audience the law does not touch. If you run a business that uses AI tools to make images, video or copy, the short version is that this law is not about you. It is worth ten minutes anyway, because the part that will eventually affect you arrives in 2027 and is worth planning for now.
We build software and websites. We are not lawyers and this is not legal advice. Everything below cites the statute or a published legal analysis so you can take it to counsel if you need to.
What the law is
The California AI Transparency Act is SB 942, as amended by AB 853, signed October 2025. Its aim is provenance: making it possible to tell whether a piece of media was produced by a generative AI system, and by which one.
AB 853 pushed the operative date from January 1, 2026 to August 2, 2026, explicitly to line up with the EU AI Act. That alignment is deliberate and it matters: the major AI companies are now building to a roughly common transparency standard on both sides of the Atlantic rather than a patchwork.
Who is actually covered
The Act binds “covered providers”: entities that create, code or otherwise produce a generative AI system with more than one million monthly visitors or users that is publicly accessible within California.
That is a short list. OpenAI, Google, Anthropic, Meta, Midjourney and a handful of others. If you are reading this to work out your own compliance obligations, you almost certainly do not have any. The duties attach to the people who build the AI systems, not to the businesses that use them.
Covered providers owe four things: a free and public AI detection tool, the option for users to include a manifest disclosure in generated content, latent disclosures embedded in that content, and contractual obligations passed down to licensees so the provenance data is not simply stripped out downstream.
The scope limit nobody mentions
Here is the detail that gets lost in most summaries. The obligations cover image, video and audio content. They do not cover text.
This confuses people because the definition of a covered provider references text creation. But the disclosure and detection duties themselves reach visual and audio output. An AI-written blog post, product description or email sits outside this Act entirely.
That matters if you have been told your AI-assisted content now needs a California disclosure. It does not, at least not because of this law. Text provenance is moving separately, driven by the EU AI Act transparency commitments and by the model providers themselves. We covered how that works in the piece on Claude's text watermarking, which is the mechanism to understand if written content is your concern.
The phases that follow
The Act rolls out in stages, and the later ones are where an ordinary business starts to feel it.
- August 2, 2026: covered providers. In effect now.
- January 1, 2027: large online platforms and generative AI hosting platforms. Platforms must detect provenance data, surface authenticity information to users, and allow inspection of that data.
- January 1, 2028: capture device manufacturers, meaning cameras and phones sold in California.
The 2027 phase is the one worth marking. Once platforms are surfacing authenticity information, AI-generated images and video you publish may be visibly labelled by the platform whether or not you choose to label them. You do not get an obligation. You get an outcome you do not control.
Enforcement
Enforcement sits with the California Attorney General, a city attorney or a county counsel, with a civil penalty of $5,000 per violation plus attorneys' fees and costs. There is no private right of action here, which is a meaningful difference from the CIPA website-tracking suits currently hitting California businesses. That distinction is worth understanding, and we wrote about it in the piece on CIPA and SB 690.
What to actually do
Assuming you are not a covered provider, four practical things.
- Stop worrying about a compliance obligation you do not have. If a vendor is selling you AI Transparency Act compliance services and you are not a covered provider, ask them to point at the section that binds you.
- Assume AI images and video you publish will carry provenance data. The tools embed it now. From 2027 platforms start reading it. Publish on the assumption it is visible rather than hoping it is not.
- Decide your own disclosure posture deliberately. Not because California requires it, but because being labelled by a platform is worse than having said so yourself. This is the same reasoning as the watermark question.
- Keep AI out of anything that needs to be verifiably real. Case study photos, client work, before-and-after images, testimonials. The provenance infrastructure being built here exists specifically to make that kind of thing detectable, and the reputational cost of being caught is far higher than any regulatory one.
Our own position on this is unchanged: AI is a drafting and production tool, and anything presented as evidence of real work has to be real. That is the standard behind our blog-writing service, where every post is grounded in a client's actual numbers and published under a named author.
Frequently asked questions
Does California's AI Transparency Act apply to my business?
Almost certainly not. It applies to covered providers, meaning entities that create, code or produce a generative AI system with more than one million monthly visitors or users that is publicly accessible in California. That is a short list of large AI companies. Businesses that merely use AI tools to produce content are not covered providers and carry no obligation under the Act.
Does the AI Transparency Act cover AI-generated text?
No. The obligations apply to image, video and audio content only. This surprises people because the definition of a covered provider references text creation, but the disclosure and detection duties themselves reach visual and audio output. AI-written blog posts and marketing copy are outside the Act entirely.
What changes on January 1, 2027?
The Act phases in. Covered providers came under it on August 2, 2026. Large online platforms and generative AI hosting platforms take on duties from January 1, 2027, including detecting provenance data and surfacing authenticity information to users. Capture device manufacturers follow on January 1, 2028.
Do I need to label AI content my business publishes?
Not under this law. It places no labelling duty on ordinary businesses. What is changing is that the tools you use are embedding provenance data themselves, and platforms will begin surfacing it from 2027, so AI-generated images and video you publish may end up visibly marked regardless of what you do. Plan for the disclosure rather than assuming it stays invisible.