On August 2, 2026 the California AI Transparency Act became operative. This is an effective date, not a new enactment: the underlying statute is SB 942, signed in 2024 with an original operative date of January 1, 2026. AB 853, approved by the Governor and filed with the Secretary of State on October 13, 2025, moved that date to August 2, 2026 and added two later tranches of obligations, one for large online platforms from January 1, 2027 and one for capture device manufacturers from January 1, 2028. The alignment with August 2, 2026 is not a coincidence: it is the same day the EU AI Act’s transparency obligations became applicable.
The duties fall on a “covered provider,” defined as a person that creates, codes, or otherwise produces a generative AI system that has over 1,000,000 monthly visitors or users and is publicly accessible within California. A covered provider must make available a free, publicly accessible AI detection tool that lets a user check whether content was created or altered by the provider’s system and view available provenance data, without exposing personal information. It must embed a latent disclosure in AI-generated content, to the extent technically feasible and reasonable, conveying the provider’s name, the system name and version, the time and date of creation, and a unique identifier. And it must give users the option to include a manifest disclosure, a visible label that is clear, conspicuous, appropriate for the medium, and understandable to a reasonable person.
Enforcement is by civil penalty of 5,000 dollars per violation, with each day of a continuing violation counted separately, plus attorney’s fees for a prevailing plaintiff. That per-day structure is the part worth modeling: a single unlabeled output pipeline left running becomes a compounding exposure rather than a one-time fine.
For any company shipping a consumer-facing generative product at scale, the practical consequence is that provenance marking is now a shipped feature in two of the world’s largest markets at once, on the same date, under two different legal instruments. The California rule is narrower than the EU’s in scope but more specific in its plumbing: it names the metadata fields and requires a working public detector, which is a build item rather than a policy statement. Providers that treated content credentials as a roadmap item now need them in production, and the 1,000,000 monthly user threshold means the obligation arrives with growth rather than at launch.