Skip to main content
Encypher Logo

California AI Transparency Act

California AI provenance duties are now operative

SB 942, as amended by AB 853, sets disclosure and detection duties for large generative AI providers. C2PA can supply the signed provenance record, but compliance also needs durable marking, detection, user experience, privacy, and operating controls.

Aug 2, 2026

Covered-provider duties became operative

>1M

Monthly visitors or users in the covered-provider definition

$5,000

Civil penalty per violation under the Act

Relationship map

How C2PA supports the California Act

The statute creates legal duties. C2PA supplies a machine-readable evidence layer inside the broader compliance program.

California AI Transparency Act and C2PA relationship map showing provider duties, a C2PA provenance layer, and the additional controls required for compliance
A C2PA manifest can record the tool, AI use, actions, time, ingredients, identifiers, and content hash. The law still requires controls outside that credential.

Timeline

Three operative dates

  1. Aug 2, 2026

    Covered-provider duties are operative

    Free provider detection, optional manifest disclosure, embedded latent disclosure, and related license controls apply under the Act.

  2. Jan 1, 2027

    Platform and hosting duties begin

    Large online platforms must detect, disclose, expose, and preserve qualifying provenance data. GenAI hosting platforms face a disclosure gate.

  3. Jan 1, 2028

    Capture-device duties begin

    Covered newly produced capture devices must offer, and default to, latent capture disclosures to the extent the statute specifies.

Scope

Who the Act reaches

The statute assigns different duties to four groups. The thresholds and operative dates are part of the rule, not footnotes.

Covered providers

A person that creates, codes, or otherwise produces a generative AI system with more than 1,000,000 monthly visitors or users and that is publicly accessible in California. The current media duties focus on image, video, audio, and combinations of them.

Large online platforms

Public-facing social, file-sharing, mass-messaging, and stand-alone search services that distribute content to people who did not create it and exceeded 2,000,000 unique monthly users in the prior 12 months, subject to statutory exclusions. Duties begin January 1, 2027.

GenAI hosting platforms

Beginning January 1, 2027, a hosting platform may not knowingly make available a GenAI system that does not place the disclosures required by section 22757.3.

Capture-device manufacturers

For covered devices first produced for sale in California on or after January 1, 2028, the manufacturer must offer and enable latent capture disclosures as the statute directs, to the extent technically feasible and standards-compliant.

Current duties

What covered providers must do now

Offer a free AI detection tool

The public tool must let a user assess whether covered media was created or altered by that provider's GenAI system and report detected system provenance data. Provider-specific detection is a separate control from general C2PA verification.

Offer a manifest disclosure option

Users must be offered an option to include a manifest disclosure in covered media. This is the natural point for a structured C2PA claim that identifies AI generation and carries provenance fields.

Embed a latent disclosure

AI-generated covered media must carry a latent disclosure detectable by the provider's tool and permanent or extraordinarily difficult to remove, within the statute's technical-feasibility terms. Ordinary embedded C2PA metadata can be stripped by some transformations, so a manifest alone should not be treated as the whole latent-marking control.

Police licensed systems

The provider must contractually require relevant licensees to preserve the required capability, revoke a license within the statutory period after discovering a disabling modification, and enforce the Act's stop-use consequence.

C2PA mapping

What C2PA covers, and what it does not

Requirement
C2PA contribution
Remaining control
Provenance record
Signed claim, actions, ingredients, AI source type, time, signer, and content binding.
Choose and populate the fields the product and law require.
File integrity
Cryptographic verification shows whether the signed asset or claim changed.
Define recovery and disclosure behavior when the credential is absent or damaged.
Detection and display
Open readers can find and render an intact C2PA manifest.
Operate the provider-specific detector and required user interfaces.
Durable latent marking
C2PA can carry and identify provenance data, including references to other signals.
Use a marking layer that meets the Act's durability and detectability tests.
Compliance program
Produces inspectable evidence for testing, audits, and incident review.
Add privacy, retention, security, feedback, licensing, and governance controls.

2027 platform duties

Platforms must detect, show, expose, and preserve provenance

Detect provenance data that complies with widely adopted specifications from an established standards-setting body.

Show users when system provenance data reliably indicates GenAI generation, substantial alteration, or capture by a device.

Provide a way to inspect the provenance directly, download the content with its attached data, or follow a link to the record.

Do not knowingly strip qualifying system provenance data or digital signatures when preservation is technically feasible.

C2PA fits this architecture because it is an open specification from the Coalition for Content Provenance and Authenticity and supports interoperable discovery, validation, and display. The statute does not create a C2PA safe harbor and does not name a single approved standard.

Implementation

A practical readiness sequence

  1. 1

    Classify each product against the statute's defined roles, user thresholds, media scope, exclusions, and operative dates.

  2. 2

    Map every required disclosure field and detection outcome to a testable product requirement.

  3. 3

    Sign supported outputs with a C2PA claim and the correct AI digital source type. Keep the credential verifiable outside your own service.

  4. 4

    Pair the manifest with a latent marking method that meets the provider's durability and detectability obligations.

  5. 5

    Build public detection, provenance display, download or link, privacy, feedback, and incident-recovery paths.

  6. 6

    Test common edits, metadata stripping, social-platform processing, format conversion, false results, and missing credentials. Keep the evidence for counsel and audit review.

Sources

Primary references

Statutory references: California Business and Professions Code sections 22757.1 through 22757.6. This summary reflects the enacted text available on August 3, 2026.

FAQ

California Act questions

When did the California AI Transparency Act take effect?

The Act became operative on August 2, 2026. Duties added by AB 853 for large online platforms and generative AI hosting platforms become operative on January 1, 2027. Duties for covered capture devices begin on January 1, 2028.

Who is a covered provider under the California Act?

A covered provider is a person that creates, codes, or otherwise produces a generative AI system with more than 1,000,000 monthly visitors or users that is publicly accessible within California. Other definitions and exclusions in the statute still matter to a specific product.

Does the California AI Transparency Act require C2PA?

No. The statute does not name C2PA. Its platform provisions refer to system provenance data that follows widely adopted specifications from an established standards-setting body. C2PA is an open provenance standard that can support those duties, but each implementation must still satisfy the statute's technical and operational requirements.

Does a C2PA manifest satisfy every requirement in the Act?

No. A C2PA manifest can carry a signed provenance record, AI-generation information, ingredients, actions, timestamps, and an integrity binding. The Act also requires provider detection tools, latent disclosures that meet durability criteria, user interfaces, privacy safeguards, license controls, and later platform and device duties. Those controls sit around the C2PA evidence layer.

Does the current Act cover AI-generated text?

The covered-provider content duties in sections 22757.2 and 22757.3 are framed around image, video, audio, and combinations of those media. Teams handling text should assess other California, federal, sectoral, contractual, and foreign requirements separately.

Add inspectable provenance to your AI output workflow

Use C2PA to sign the record. Test the surrounding disclosure, detection, durability, and operating controls against the California Act with counsel.

Try verification

See also: the separate guide to the EU AI Act and content provenance.