Skip to main content
Encypher Logo

Policy

AI provenance laws and policy briefs

A current register of rules that directly govern AI marking, content provenance, detection, and disclosure. Each entry separates the legal duty from the evidence C2PA can provide. General privacy, copyright, election, and consumer-protection laws are included only when they impose a content-authenticity duty.

Last reviewed August 3, 2026. This register is technical information, not legal advice.

Regulatory requirements

"Requires disclosure" and "requires provenance" are not the same rule. The cards below state the covered group, the duty, and the role of C2PA.

California

California AI Transparency Act

Operative

August 2, 2026

Who and what
Covered generative AI providers with more than 1,000,000 monthly visitors or users and public access in California. Later duties reach large online platforms, GenAI hosting platforms, and capture-device manufacturers.
Core duty
Provider-specific detection, optional manifest disclosure, embedded latent disclosure, and license controls for covered image, video, and audio. Platform duties begin January 1, 2027. Capture-device duties begin January 1, 2028.
C2PA relationship
C2PA can carry the signed system provenance record and support platform detection, display, and integrity checks. It does not replace durable latent marking, provider detection, user experience, privacy, or operating controls.
Read the California Act and C2PA guide

European Union

EU AI Act Article 50

Applicable

August 2, 2026

Who and what
Providers of certain AI systems that generate synthetic audio, image, video, or text, plus deployers subject to the separate disclosure duties in Article 50.
Core duty
Machine-readable marking for covered AI outputs, with separate visible-disclosure duties for specified deepfakes and certain public-interest text.
C2PA relationship
C2PA can provide an interoperable machine-readable provenance layer. A deployment still needs the correct scope, source type, robustness, disclosure, and operating controls.
Read the EU AI Act and C2PA guide

United States, federal

Federal AI provenance landscape

No general mandate

As of August 3, 2026

Who and what
No general federal law requires all AI-generated content to carry a C2PA credential or machine-readable AI mark.
Core duty
Sectoral law, consumer-protection law, election rules, impersonation rights, privacy law, contracts, and agency action may still govern a specific use.
C2PA relationship
C2PA can supply evidence of origin, disclosed AI use, supplied rights, actions, and integrity. It is evidence. It does not create a federal safe harbor.

Other US states

Synthetic-media and election disclosures

Varies by state

Check the current statute

Who and what
Many states regulate synthetic media in election, impersonation, intimate-image, or consumer settings. Definitions, media coverage, timing, exceptions, and enforcement differ.
Core duty
Some laws call for visible disclosure or removal procedures rather than embedded provenance. They should not be described as one uniform C2PA mandate.
C2PA relationship
A signed provenance record can support a disclosure or evidence program, but each statute needs its own legal and technical mapping.

Policy briefs

Coming soon

Briefs in preparation cover:

  • Provenance in procurement
  • State synthetic-media disclosure register
  • Content authenticity in elections

Get new policy briefs by email

One email per brief. Nothing else.