As of August 2, 2026, California’s AI Transparency Act is operative. For large public generative AI providers, the law turns provenance from a nice-to-have into a product and compliance responsibility.
The practical point is easy to miss: this is not a blanket rule that every piece of AI content must show a visible watermark. The law creates a more specific system around detection tools, machine-readable provenance, user-facing disclosure options, and accountability when models are licensed to others.
Who is in scope now?
The immediate requirements apply to a “covered provider”: an entity that produces a publicly accessible generative AI system with more than one million monthly visitors or users in California. The statute covers systems that generate synthetic content, including text, images, video, and audio, but the core operational duties currently focus on image, video, and audio provenance.
What covered providers need to provide
- A free AI detection tool. Users must be able to assess whether image, video, or audio was created or altered by the provider’s GenAI system. The tool must return detected system provenance data, support uploads or URLs, and expose an API. It cannot disclose personal provenance data.
- A visible disclosure option. Users must be offered an option to include a clear, conspicuous disclosure that identifies qualifying media as AI-generated. The disclosure must be permanent or extraordinarily difficult to remove where technically feasible.
- Latent provenance disclosure. For AI-generated image, video, and audio, providers must include machine-readable disclosure data where technically feasible and reasonable. That data can include the provider name, system and version, creation or alteration time, and a unique identifier.
- Licensed-model controls. Providers licensing a GenAI system must contractually preserve its disclosure capability. If a licensee disables that capability, the provider must revoke the license within 96 hours of discovering it.
Why this changes the product roadmap
Most teams have treated content provenance as a policy page, an optional metadata field, or a vendor feature to evaluate later. California makes it an end-to-end product question: Can the generation system attach provenance? Can a user inspect it? Can a detection endpoint read it? Does the provenance survive the product and partner path?
That means the work crosses model engineering, product design, trust and safety, privacy, developer relations, and partner contracts. A label added at export is not enough if the underlying system cannot support detection and durable provenance.
The next dates matter too
The law’s platform duties are phased. Starting January 1, 2027, qualifying large online platforms must detect standards-compliant provenance data attached to distributed content, show users when reliable system provenance is available, make that data inspectable, and avoid knowingly stripping it where technically feasible. GenAI system hosting platforms also face a January 1, 2027 restriction on knowingly making available systems that do not place the required disclosures.
In other words, the first phase asks generation providers to make provenance available. The next phase asks distribution and hosting layers to preserve and surface it. That is a content supply chain, not a watermark checkbox.
A practical 30-day response
- Map every image, video, and audio generation path, including APIs, partner products, and licensed models.
- Identify what provenance data is generated, where it is stored, and whether it survives export and distribution.
- Test a user-facing detection flow with uploads, URLs, privacy controls, and API access.
- Review licensing terms for model modification, disclosure preservation, revocation triggers, and notification paths.
- Separate current obligations from the January 1, 2027 platform obligations so the roadmap does not collapse them into one vague “watermarking” project.
This is not legal advice, and technical feasibility matters in the statute. But the strategic lesson is clear: when content can be generated, authenticity information has to travel with it. Teams that build that capability into the workflow now will be better positioned for the next distribution-layer deadline.
For the canonical requirements, read the current California code text and the AB 853 amendments.