Not sure where to start? Answer 3 questions and get a tailored compliance action plan.
What applies to me? →California AI Transparency Act (SB 942 as amended by AB 853)
Issued by
State of California
The California AI Transparency Act requires covered generative AI providers to make a free AI-detection tool available to users and to embed latent disclosures in AI-generated content. It applies to companies that develop or distribute covered generative AI systems to California consumers. Providers must also include license terms that allow revocation of access within 96 hours if a licensee removes or disables required disclosure capabilities.
Applies To
Overview
Operative as of 2 August 2026, the California AI Transparency Act establishes disclosure and provenance obligations for generative AI providers serving California users. The law requires covered providers to offer a no-cost detection tool that enables users and third parties to identify AI-generated content. Latent disclosures must be embedded in covered content so that the AI origin can be identified even after distribution. License agreements governing downstream use of covered AI systems must include enforceable terms requiring that disclosure functionality remain intact, with revocation triggered within 96 hours of a detected breach. The Act functions through a combination of civil enforcement and contractual compliance mechanisms, placing obligations on both the provider and, through pass-through license terms, on downstream licensees. Enterprises that deploy covered generative AI systems in California-facing products should treat this as an active compliance obligation requiring immediate operational review.
Key Requirements
- •Provide a free, publicly accessible AI-detection tool capable of identifying content generated by the covered system.
- •Embed latent disclosures in all covered AI-generated content to preserve provenance information after distribution.
- •Include contractual terms in all licenses for the covered AI system that prohibit removal or disabling of disclosure capabilities.
- •Revoke a licensee's access within 96 hours upon discovering that the licensee has stripped or circumvented required disclosure functionality.
- •Obligations apply to providers of covered generative AI systems as defined under SB 942 as amended by AB 853, operative from 2 August 2026.
What Your Organization Must Do
- →Audit all generative AI systems in your product stack to determine whether any meet the definition of a covered system under the Act.
- →Verify that each covered provider you procure from has deployed a compliant, no-cost detection tool accessible to your organization and end users.
- →Review and update vendor contracts to include the mandatory disclosure-preservation terms and to confirm the provider's 96-hour revocation obligation is enforceable.
- →Establish an internal monitoring process to detect if any downstream licensee or integration partner removes or disables AI disclosure functionality.
- →Document latent disclosure standards in your AI content governance policy and confirm those standards are applied at the point of content generation.
- →Assign a responsible team or officer to track provider compliance and to execute or escalate revocation procedures within the 96-hour window if a breach is identified.
Playbook Guidance
Step-by-step implementation guidance for compliance teams.
Frequently Asked Questions
- Which companies must comply with the California AI Transparency Act and does it apply to AI deployers or only developers?
- The Act covers providers that develop or distribute covered generative AI systems to California consumers, capturing both developers and deployers. Downstream licensees also face pass-through obligations through mandatory contract terms, so enterprises deploying third-party generative AI in California-facing products should treat themselves as directly affected.
- What is the compliance deadline for the California AI Transparency Act SB 942 as amended by AB 853?
- The Act becomes operative on 2 August 2026. Compliance programs, vendor contract updates, and detection tool deployments must all be in place before that date, so organizations should begin operational readiness reviews well in advance.
- What exactly does the free AI-detection tool requirement mean for covered providers under CA-AITA?
- Covered providers must offer a no-cost detection tool that allows users and third parties to identify AI-generated content produced by the covered system. The tool must be publicly accessible, meaning providers cannot restrict it to paying customers or enterprise subscribers.
- What is the 96-hour revocation rule under the California AI Transparency Act and who is responsible for enforcing it?
- If a licensee removes or disables required AI disclosure functionality, the covered provider must revoke that licensee's access within 96 hours of discovering the breach. The obligation sits with the provider, but enterprises should verify this term is enforceable in their vendor agreements.
- How do latent disclosure requirements under CA-AITA differ from visible watermarking or labeling obligations in other AI regulations?
- CA-AITA requires embedded provenance data that persists after distribution, not necessarily a visible label at the point of consumption. This technical requirement means disclosure must survive file transfers, editing, and republication, which is a distinct and more demanding standard than simple on-screen labeling.
- What contract changes must enterprises make to vendor agreements to comply with the California AI Transparency Act?
- All licenses covering a generative AI system subject to the Act must include enforceable terms prohibiting removal or disabling of disclosure capabilities. Compliance and legal teams should audit existing vendor contracts now and negotiate amendments that incorporate the mandatory disclosure-preservation language before the August 2026 operative date.
