Provenance Dies at the First Screenshot
California’s AI Transparency Act goes live tomorrow. The law everyone expected Washington to kill verifies where content is born and goes blind exactly where it travels.
For most of the past year, the confident read on California’s AI Transparency Act was that it would never actually take effect. It would be preempted by a federal framework, enjoined in federal court, or quietly overtaken by the larger fight in Washington over whether states get to regulate AI at all. It was a reasonable read. It was also the reason a lot of organizations did the rational thing and waited.
The waiting room turned out to be empty. On August 2, the law becomes operative anyway.
What arrives tomorrow is worth understanding precisely, because the interesting part is not the headline requirement. It is the seam between what the statute can verify and what it cannot, and who is left holding the decision on the wrong side of that seam.
What the law actually does
SB 942 was signed by Governor Gavin Newsom on September 19, 2024. It was then amended by AB 853, signed October 13, 2025, which moved the operative date from January 1, 2026 to August 2, 2026, an alignment the drafters chose to track the European Union’s AI Act transparency timeline.
The law reaches what it calls a covered provider: a person or company that makes a generative AI system with more than one million monthly users or visitors, publicly accessible within California. That threshold is deliberate. It is aimed at the large, well-resourced model makers, not the corner startup.
As of August 2, a covered provider must do the following. First, make available a free, publicly accessible tool that lets a user check whether a given piece of image, audio, or video content was created or altered by that provider’s system. Second, give users the option to include a visible disclosure, what the statute calls a manifest disclosure, on content the system generates. Third, embed a latent disclosure, a hidden, machine-readable provenance signal, in that generated image, audio, and video, so the detection tool has something to read. Those transparency obligations also flow down to third-party licensees of the system.
Enforcement has teeth. The statute sets a civil penalty of five thousand dollars per violation, and provides that each day of noncompliance “shall be deemed a discrete violation,” so exposure compounds daily. The action is brought by the Attorney General, a city attorney, or a county counsel, and a prevailing plaintiff recovers reasonable attorney’s fees and costs. Injunctive relief is written in for the case of a third-party licensee that strips the required disclosures.
A second phase follows on January 1, 2027, when AB 853 extends obligations to generative AI hosting platforms and to large online platforms. Requirements for the manufacturers of devices that capture images, audio, and video follow separately, on January 1, 2028.
On its own terms, this is a coherent, well-constructed regime. The critique that follows is not that it was done carelessly. It is that its architecture verifies one thing and is being received as if it verified another.
The rescue that never came
Begin with the organizations that waited, because the reason they waited is itself the first governance lesson.
The bet was that Washington would take this decision off the table before the compliance date landed. On the surface, the bet had support. In December 2025 the White House issued an executive order directed at state AI regulation, calling for a national framework and instructing the Justice Department to establish a task force to challenge state AI laws in court. Before that, a provision in the federal budget reconciliation package would have barred state enforcement of AI regulation for ten years.
Now trace what each of those actually produced. The proposed moratorium did not survive: the Senate voted ninety-nine to one to strip it out. The executive order, whatever its intent, cannot by itself displace a state statute, because preemption in our system runs through an act of Congress, not through an order from the President, a limit that outside counsel across the field flagged immediately. And the Justice Department’s litigation task force, as of the most recent public reporting, had not filed its first complaint. Three separate federal levers, and none of them moved California’s date.
This is the pattern I return to again and again, because organizations keep making the same move. “We are waiting for the regulation to settle” is treated as a neutral, prudent holding position. It is neither neutral nor prudent. It is a decision to let a deadline you did not set decide your posture for you. The firms that deferred compliance were not being cautious. They were quietly outsourcing a governance decision to a federal rescue that was never actually on the calendar. The absence of a settled federal rule did the deciding, and the cost of that decision arrives tomorrow, on schedule, for anyone who mistook waiting for safety.
That is the wrong default in its plainest form. Something gets decided by no one, through inaction, and the bill lands on the people who assumed inaction was free.
The part the statute cannot reach
Now the harder half, and the reason this is not, in the end, a story about a detection tool.
The mechanism California chose is provenance. The provider marks its own output, and the tool reads that mark. This matters, because it means SB 942 is not asking anyone to perform the trick that failed so publicly this year, the general-purpose “is this AI” detector that flags the U.S. Constitution and pre-ChatGPT student essays as machine-written. The law is narrower and more honest than that. It asks a provider to check for the signal it planted in its own content. Where the content is still intact, this works, and it is a genuine improvement over guessing.
But provenance is a chain, and a chain is only as strong as its weakest handoff. The visible label is optional and removable by the user. The hidden mark degrades or disappears the moment content is screenshotted, re-encoded, cropped, compressed by a platform, or run through a second tool that does not preserve it. This is not a defect someone failed to catch. It is the nature of provenance data: it is durable at the source and fragile in transit.
Which produces the seam. The law is verifiable exactly where content originates and blind exactly where content actually travels. And travel is the whole point. The AI output that will cause a problem is almost never the pristine copy still sitting inside the system that generated it, with its watermark intact and its detection tool one click away. It is the version several forwards downstream, screenshotted into a group chat, re-uploaded, restyled, stripped of every signal that made it checkable. By the time a piece of synthetic content is doing damage, it has usually shed exactly the provenance the statute relies on.
So the regime can confirm origin and little else. It authenticates the honest case, the content nobody was going to be fooled by, and goes quiet on the dishonest case, the content specifically laundered to remove its marks. That is not an argument against the law. It is a caution against reading it as more than it is: a receipt at the point of creation, not a verdict in the wild.
Origin is not truth
Here is where it lands, and it is a distinction worth holding onto well past this one statute.
SB 942 assigns a clear, enforceable duty. Mark your output. Offer the tool. Five thousand dollars a day if you do not. That is a real obligation, correctly placed on the party that can actually meet it, the provider.
What the law does not assign is the harder decision, the one that surfaces the moment a piece of content arrives with its provenance already stripped and the detection tool returns nothing. Is it authentic. Do you act on it. Who is accountable if you treat a real thing as fake, or a fake thing as real. The statute verifies where a piece of content came from. It does not tell you whether to believe it. Those are different questions, and the space between them, between origin and truth, is precisely where accountability still has no owner. Nothing operative tomorrow closes that gap, and it would be a mistake to let a compliance checkbox convince anyone that it did.
This is the quiet risk in every well-built transparency regime. It produces an artifact, a label, a watermark, a tool, and the artifact starts to stand in for the judgment. The presence of a detection tool feels like the question has been answered. It has not. It has been answered for the easy half of the content and left open for the half that matters, and the organization that forgets which half it is looking at will trust a stripped image because no watermark fired or distrust a real one for the same reason.
The default California just set is real, and it is worth having. Provenance at the point of creation is better than no provenance at all, and a legally mandated one is better than a voluntary one that competitors can skip. Take the win for what it is. Then be clear-eyed about what it is not. It is a record of where something was born. It is not a ruling on whether to believe it. That ruling is still a human judgment, made downstream, in the wild, where the watermark has already washed off, and it belongs to someone with a name.
You own the decision.
Sources and verification
Every load-bearing figure in this piece was checked against the primary statute before publication.
Primary law
• California AI Transparency Act, SB 942 (Becker, 2024). Full bill text: https://leginfo.legislature.ca.gov/faces/billNavClient.xhtml?bill_id=202320240SB942. Codified at California Business and Professions Code, Chapter 25, commencing at Section 22757.
– Covered provider, “over 1,000,000 monthly visitors or users and is publicly accessible within the geographic boundaries of the state”: Section 22757.1.
– AI detection tool, optional manifest disclosure, and embedded latent disclosure (which carries “the name of the covered provider” and is “detectable by the covered provider’s AI detection tool”): Sections 22757.2 and 22757.3.
– Civil penalty of “five thousand dollars ($5,000) per violation,” and “each day that a covered provider is in violation of this chapter shall be deemed a discrete violation,” enforced by the Attorney General, a city attorney, or a county counsel: Section 22757.4.
• AB 853 (2025), which amended SB 942 and set the operative date of August 2, 2026, phasing in further obligations for hosting platforms and large online platforms from January 1, 2027, and for capture-device manufacturers from January 1, 2028: https://leginfo.legislature.ca.gov/faces/billNavClient.xhtml?bill_id=202520260AB853.
Federal context
• Executive Order 14365, “Ensuring a National Policy Framework for Artificial Intelligence” (December 11, 2025), and the Department of Justice AI Litigation Task Force it directed. Analysis: White & Case, https://www.whitecase.com/insight-alert/state-ai-laws-under-federal-scrutiny-key-takeaways-executive-order-establishing; Ropes & Gray, https://www.ropesgray.com/en/insights/alerts/2026/03/examining-the-landscape-and-limitations-of-the-federal-push-to-override-state-ai-regulation.
• The proposed ten-year moratorium on state AI enforcement was removed from the federal budget reconciliation package by a Senate vote of 99 to 1.
Note on the detection mechanism. SB 942 requires provenance-based detection of a covered provider’s own output, read through the latent disclosure the provider embeds. It is not a general-purpose “is this AI” classifier. The observation that provenance signals degrade when content is screenshotted, re-encoded, cropped, or passed through a tool that does not preserve them is analysis from first principles, not a claim drawn from the statute.
Verified against the enrolled bill text (SB 942, Chapter 291, approved September 19, 2024) on August 1, 2026.



