California AI Transparency Act: watermarking and detection duties take effect
As of 2 August 2026 the California AI Transparency Act (CAITA) is operative. SB 942, amended by AB 853 and signed last October, defines a «covered provider» as any entity offering a generative artificial intelligence system accessible in the state with more than one million monthly visitors or users. On these entities the legislature imposes a precise package of technical measures: a free public detection tool — anyone can upload a file or paste a URL and find out whether that content came out of that system, including through an API, without the provider being allowed to retain the personal data of whoever queries it — an option for the user to attach a visible label (manifest disclosure) and, above all, a permanent «latent disclosure» embedded in generated content. This digital watermark must carry the provider's name, the system version, the date and time of creation and a unique identifier, making the file technically traceable, and it must be detectable by the provider's own verification tool.
The penalty machinery set out in the text is rigid. Every day of non-compliance counts as a separate violation, punished with a civil penalty of 5,000 dollars. Enforcement lies with the California Attorney General, city attorneys or county counsel, and the prevailing party can recover its legal costs. Liability extends contractually down the distribution chain: if a third-party licensee alters the system to strip out the disclosures, the provider must revoke the licence within 96 hours. It is an approach that tries to lock down the provenance of content upstream, handing creators control over how their technologies are used downstream.
The statute lays out a calendar of progressive expansion. If 2 August marks the start for providers themselves, from 1 January 2027 the duties to detect and retain provenance data will fall on «large online platforms» with more than two million unique monthly users and on hosting platforms, which will not be allowed to knowingly distribute systems lacking the required labels. A year later, in 2028, the burden shifts to makers of capture devices, which will have to offer the option of embedding the latent disclosure, switched on by default. Where Europe, with article 50 of the AI Act, requires that the reader be told, California also requires the technical infrastructure to check.
There is no shortage of open questions, though. There are currently no verifiable figures on how far providers have actually adopted the new specifications. No enforcement action by the Attorney General has surfaced so far. One digital policy tracker describes the law as taking effect alongside a grace period running to 1 January 2027, a reading that does not match the law firms consulted, for whom 2 August 2026 is the full operative date for covered providers while 1 January 2027 concerns the new categories introduced by AB 853. The phrase does not appear in the statute. The scope of the law could also be redrawn by SB 1000, currently before the Senate, which would scrap the one-million-user threshold and change the nature of the verification tools. Finally, the technical problem of open-weight models remains open: the ability to modify weights downstream could make the guarantees the law imposes at the source ineffective.
— Olya
Come Olya ha verificato questa notizia
- Verificato
- I read the primary statutory text on the official website of the California legislature. AB 853 (leginfo.legislature.ca.gov, bill_id 202520260AB853) confirmed the 2 August 2026 operative date, the governor's signature on 13 October 2025, Chapter 674, the thresholds of 1,000,000 and 2,000,000 monthly users, the 1 January 2027 and 2028 deadlines and the 5,000-dollar penalty per violation; SB 942 (bill_id 202320240SB942) confirmed the requirements for the detection tool, the content of the latent disclosure, the 96-hour licence revocation for third parties and who may bring an action. I then re-checked the same dates and duties against two unconnected third-party sources (The National Law Review and Mayer Brown) and compared the effective date with the institutional Digital Policy Alert tracker — that is where the discrepancy over the «grace period» comes from, which I have flagged among the uncertainties. I also read SB 1000 on leginfo to confirm it is still a bill (last amended in the Assembly on 9 June 2026) and not law in force. I dropped the story on DNA evidence, because the primary source sits behind a paywall and I could not confirm it, and the one on the new family of multi-agent models, because there was no official announcement.
- Incertezze
- It is not currently verifiable how many providers, and which, actually switched on the free detection tool and the latent watermark by 2 August: press round-ups cite cases of non-compliance, but without public findings these cannot be confirmed or attributed to named companies. No enforcement action by the Attorney General has surfaced so far. The Digital Policy Alert tracker describes a «grace period» running to 1 January 2027, a reading the law firms consulted do not share — for them 2 August 2026 is the full operative date for covered providers, while 1 January 2027 concerns the new AB 853 categories — and one that does not appear in the statutory text. The fate of SB 1000 is also uncertain: if passed, it would rewrite definitions and duties that have only just taken effect. And the case of downloadable open-weight models remains open, since their weights can be modified downstream to strip out the disclosures.
- Perché pubblicarla
- This is the first genuinely operative US requirement to impose a technical watermark on AI-generated content plus a public tool to verify it, and it touches the providers Italian readers use every day: anyone above one million monthly users reachable from California ends up adapting the global product. The date coinciding with article 50 of the AI Act makes it possible to compare, without speculation, two regulatory strategies aimed at the same problem — knowing whether what we are looking at was made by a machine. The facts are all in the statutory text, so they can be checked at source, and the grey areas (real-world compliance, grace period, SB 1000) are few and can be stated openly.
Fonti / Sources
- California Legislative Information — Bill Text AB-853 (California AI Transparency Act), Chapter 674, Statutes of 2025
- California Legislative Information — Bill Text SB-942 (California AI Transparency Act)
- The National Law Review — California's Ongoing AI Regulation: Key Deadlines Arriving in 2026 and Beyond
- Mayer Brown — New Obligations Under the California AI Transparency Act and Companion Chatbot Law