Skip to main content

On-demand webinar coming soon...


On-demand webinar coming soon...

Blog

California AI Transparency Act: Requirements, Deadlines, and Compliance Steps

The Act introduces disclosure, provenance, and detection requirements for generative AI providers. 

Harry Chambers
Regulatory Content Strategist
July 30, 2026

Banner image for the California AI Transparency Act article showing the California State Capitol dome and U.S., California, and POW/MIA flags on the left, alongside a black panel with a mint-green abstract graphic on the right.

California’s AI Transparency Act, amended through Assembly Bill 853, becomes operative on August 2, 2026. It creates a framework for helping people identify content created or altered by generative artificial intelligence (GenAI) and inspect information about its origin.

The first phase applies to covered providers of publicly accessible GenAI systems. Requirements extend to large online platforms and GenAI hosting platforms from January 1, 2027, followed by certain capture device manufacturers from January 1, 2028.

The Act affects operations team differently:

  • for privacy teams, the Act raises questions about personal information, provenance data, and public-facing transparency
  • AI governance teams need to connect disclosure controls to the systems producing and distributing content
  • enterprise risk teams need to account for phased deadlines, third-party dependencies, and daily penalties for ongoing violations.

Key Takeaways

  • The California AI Transparency Act becomes operative on August 2, 2026, and applies to publicly accessible GenAI systems with more than one million monthly users or visitors.
  • Covered providers must offer AI-content detection and include manifest and latent disclosures in certain AI-generated image, video, and audio content.
  • Additional duties apply to large online platforms and GenAI hosting platforms from January 1, 2027, and to certain capture device manufacturers from January 1, 2028.
  • Readiness requires coordinated ownership across privacy, AI, product, engineering, legal, and enterprise risk functions.

 

What Changes Under the California AI Transparency Act

A "covered provider" is a person that creates, codes, or produces a generative AI system with more than one million monthly visitors or users that is publicly accessible within California.

Covered providers must offer a free AI detection tool that lets users assess whether image, video, audio, or combined media content was created or altered by the provider’s GenAI system. The tool must return any system provenance data found in the content without exposing personal provenance data.

The tool must accept uploads or URLs and support API access. For example, a publisher reviewing a video should be able to upload the file, submit a link, or check it through an integrated service. Covered providers must also include manifest and latent disclosures in covered AI-generated content.

Manifest disclosures visibly identify content as AI-generated in a clear, understandable, and durable format. A label displayed on an AI-generated video is one example.

Latent disclosures sit within the content or its metadata. They should include the provider’s name, the AI system name and version, the date and time of creation or alteration, and a unique identifier. The provider’s detection tool must remain able to identify them.

Licensing agreements must also require licensees to preserve these disclosures. Where a licensee fails to comply, the provider must revoke the license within 96 hours.

 

The Next Phases Extend Across the Content Ecosystem

From January 1, 2027, large online platforms must detect provenance data that follows widely adopted specifications from an established standards-setting body.

They must show users when system provenance data is available and provide information about the content’s authenticity, origin, or modification history. Access could take the form of an on-platform view, a downloadable file with attached provenance data, or a link to the information in another website or application.

Platforms must also avoid knowingly stripping compliant system provenance data or digital signatures where technically feasible.

The definition covers public-facing social media, file-sharing, mass messaging, and stand-alone search platforms with more than two million unique monthly users during the previous 12 months. Broadband internet access and telecommunications services fall outside the definition.

Also from January 1, 2027, a GenAI hosting platform must not knowingly make available a GenAI system that fails to place the required disclosures.

A third phase begins on January 1, 2028. Manufacturers of covered capture devices first produced for sale in California on or after that date must give users an option to include a latent disclosure in captured content. They must also embed latent disclosures by default, subject to technical feasibility and alignment with widely adopted specifications. 

These requirements cover devices that record photographs, audio, or video, including cameras, mobile phones with built-in cameras or microphones, and voice recorders.

 

What Privacy Teams Should Review

The Act distinguishes between system provenance data and personal provenance data.

System provenance data describes the device, system, service, or authenticity of content without being reasonably associated with a person. Personal provenance data includes personal information or unique device, system, or service details reasonably associated with a user.

Detection tools and provenance records need to keep those categories separate. A tool verifying that an image came from a specific GenAI system should return the required system details without exposing information about the person who created or uploaded it.

The review should cover data collection, retention, access controls, public explanations, and the treatment of provenance information across product workflows.

Public statements also need to match product behavior. A notice saying users may inspect provenance data falls short when the interface buries the information or the metadata disappears after export. 

 

Preparing AI Governance Programs

The Act makes content provenance part of the AI lifecycle. Start with an inventory of systems that create, alter, host, license, or distribute covered content. Record which systems cross the user threshold, which outputs require disclosures, and which downstream platforms or licensees rely on those disclosures remaining intact.

Testing should follow the content journey. A latent disclosure may survive the initial export yet disappear after compression, editing, reposting, or conversion to another file format. Those failure points need documented owners and remediation paths.

The same applies to technical feasibility decisions. Where an obligation depends on what is technically feasible, document the assessment, supporting evidence, approver, and review date.

Licensing adds a third-party control. The process should cover contract terms, monitoring, escalation, and license revocation within the 96-hour window. 

For a broader view of emerging requirements, explore OneTrust coverage of California automated decision-making technology, the Colorado AI Act, and other U.S. AI regulatory frameworks.  

 

Considerations for Enterprise Risk Programs

The Act creates exposure across several deadlines, business models, and technology relationships.

Readiness planning should separate the August 2026 duties for covered providers from the 2027 platform and hosting obligations and the 2028 device requirements.

The Attorney General, city attorneys, and county counsels may seek civil penalties of $5,000 per violation. Each day of noncompliance counts as a separate violation.

A defensible record should include the system inventory, disclosure test results, provenance specifications, licensee controls, escalation logs, and technical feasibility assessments.

That evidence also supports clearer reporting. Instead of stating that the business is "on track," risk leaders get a view of which controls are complete, where testing failed, and which dependencies still sit with vendors or product teams.

 

Build a Defensible Compliance Process

Organizations should begin by determining whether any GenAI system meets the definition of a covered provider. They should then map the content types produced by those systems and assess whether current detection tools, manifest labels, and latent disclosures satisfy the Act’s requirements.

Teams should test whether provenance information persists across common content journeys and confirm that detection tools return system provenance data without exposing personal provenance data.

Organizations that license GenAI systems should review contractual terms and establish a process for responding to licensee noncompliance within 96 hours.

Large online platforms, hosting platforms, and capture device manufacturers should also start planning for the requirements taking effect in 2027 and 2028. Those future phases require technical design, standards alignment, and cross-company coordination that warrant preparation well before their operative dates.

 

Continue Your AI Readiness

Explore OneTrust DataGuidance for ongoing analysis of California’s AI requirements and other U.S. regulatory developments.

Learn how OneTrust AI Governance helps organizations maintain AI inventories, assess use cases, assign ownership, document controls, and support regulatory readiness across the AI lifecycle.

See how OneTrust Privacy Automation supports privacy governance, records of processing, data oversight, and documentation where AI systems process personal information.

 
Key Questions About the California AI Transparency Act

 

The Act becomes operative on August 2, 2026. Requirements for large online platforms and GenAI hosting platforms begin on January 1, 2027. Requirements for certain capture device manufacturers begin on January 1, 2028.

A covered provider is a person that creates, codes, or produces a generative AI system with more than one million monthly visitors or users that is publicly accessible within California.

Covered providers must include manifest and latent disclosures in covered AI-generated image, video, and audio content. Manifest disclosures visibly identify content as AI-generated. Latent disclosures provide system-level provenance information within the content or its metadata.

System provenance data describes the device, system, service, or authenticity of content without being reasonably linked to a user. Personal provenance data includes personal information or device, system, or service information reasonably associated with a user.

Violations carry a civil penalty of $5,000 per violation. Each day of noncompliance is treated as a separate violation.