California AI Transparency Act (SB 942): What's Required
California's AI Transparency Act (SB 942) became operative August 2, 2026. Here's who counts as a covered provider, what to disclose, and the penalties.
Generate a website terms of use in 60 seconds
Describe what you need in plain English. A panel of AI agents (Researcher, Drafter, Critic, Validator, Adversary) writes a review-ready draft you can edit, sign, and send.
California's AI Transparency Act (SB 942) became operative on August 2, 2026. Large generative-AI providers — those with more than 1 million monthly California users — must now offer a free public AI-detection tool and support both visible and invisible disclosure of AI-generated content, backed by $5,000-per-day penalties for gaps.
Key takeaways
- SB 942 (Cal. Bus. & Prof. Code § 22757 et seq.) is now in force as of August 2, 2026, after AB 853 pushed its original January 1, 2026 start date.
- It applies to "covered providers" of generative AI systems with over 1,000,000 monthly California users — not to smaller tools or to businesses that merely use someone else's AI.
- Three obligations are live today: a free public detection tool, an optional visible ("manifest") disclosure, and a default invisible ("latent") machine-readable disclosure embedded in AI-generated images, video, and audio.
- A second wave hits January 1, 2027: "large online platforms" (2,000,000+ unique monthly users) must detect and surface provenance data in their interface under AB 853.
- Violations cost $5,000 per day per violation, plus the prevailing plaintiff's attorney's fees — exposure that compounds fast if a gap goes unnoticed.
What does the California AI Transparency Act actually require?
SB 942 targets one narrow problem: making it possible to tell whether content was made by a person or a machine. It does this through three linked obligations that apply the moment a company crosses covered-provider status.
First, a covered provider must make a free, publicly accessible AI-detection tool available — something anyone, not just the provider's own users, can use to check whether a piece of content came from that provider's system. Second, the system must let users add a manifest disclosure — a visible, clear label identifying AI-generated image, video, or audio content — as an available option. Third, and this is the part most engineering teams underestimate, the system must embed a latent disclosure by default: a hidden, machine-readable provenance marker baked into the content itself, not something a user has to opt into.
None of this requires disclosing what the AI was trained on or how it works. It requires disclosing that AI touched the content at all, and building tooling that lets someone verify that claim independently of the provider's own word.
Who counts as a "covered provider" under SB 942?
The law's scope hinges entirely on one number: 1,000,000 monthly visitors or users in California over the preceding 12 months, for a generative AI system that's publicly accessible. Cross it, and the three obligations above apply. Stay under it, and SB 942 doesn't reach you directly — though that's a narrower shield than it sounds, since the threshold is evaluated per system and can be crossed by a single viral month.
| Scenario | Covered by SB 942? | What to do |
|---|---|---|
| A GenAI image/video tool with 1M+ CA monthly users | Yes — covered provider | Deploy the free detection tool and both disclosure types now |
| A small AI writing assistant with 50,000 CA users | Not currently covered | Monitor growth; document your disclosure approach anyway |
| A business embedding a third party's GenAI API in its product | Depends on who built the system | Confirm contractually which party is the "covered provider" for SB 942 purposes |
| A social media platform with 2M+ unique monthly users distributing others' AI content | Not covered by SB 942 directly, but covered as a "large online platform" under AB 853 from Jan 1, 2027 | Start building provenance-detection into your content pipeline before the 2027 deadline |
| A B2B SaaS tool with no publicly accessible GenAI output | Not covered | No action needed under SB 942 |
The distinction between "building the AI system" and "using someone else's AI system" matters here in the same way it does under the EU AI Act's provider/deployer split — the entity that created or substantially modified the generative AI system is the one on the hook, not every business that touches its output downstream.
What happens on January 1, 2027 under AB 853?
AB 853, the same bill that pushed SB 942's start date to August 2026, adds a second, later-arriving obligation aimed at distribution rather than generation. Starting January 1, 2027, a "large online platform" — a public-facing social media platform, file-sharing platform, mass-messaging platform, or stand-alone search engine with more than 2,000,000 unique monthly users, excluding plain broadband or telecom services — must detect whether the content it distributes carries provenance data, and disclose that status through its own user interface.
In plain terms: the generator discloses at the source (SB 942, live now), and starting in 2027 the distributor has to surface that disclosure to its own users too (AB 853). A platform that hosts AI-generated content someone else made doesn't get to treat provenance as someone else's problem once this date arrives.
What are the penalties for non-compliance?
SB 942 sets a civil penalty of $5,000 per violation, with each day a covered provider remains non-compliant counted as a separate, discrete violation. A prevailing plaintiff is also entitled to recover reasonable attorney's fees and costs. That structure rewards fast fixes and punishes drift — a detection tool that's broken or missing for even a few weeks adds up quickly once you count each day separately.
How should this change your AI platform terms of use?
If your product is near or above the 1,000,000-user threshold, your AI platform terms of use should say, plainly:
- That a free AI-detection tool exists and where to find it
- What manifest disclosure options users have when generating image, video, or audio content
- That latent/machine-readable disclosure is embedded by default and cannot be turned off
- Who is responsible for disclosure when your AI output is embedded in, or redistributed through, a partner's platform — this is the same allocation question the EU AI Act's Article 25 provider/deployer split forces on AI supply chains, just under California's own statute
Even below the threshold, stating your disclosure practices in plain language is a low-cost way to be ready if a growth spike pushes you over it — better to have already answered the question than to scramble once the counter crosses seven figures.
Common mistakes to avoid
- Assuming "we're too small" is a permanent shield. The 1,000,000-user threshold is measured on a trailing 12-month basis. A product that goes viral can cross it mid-year without anyone updating the terms of use to match.
- Treating manifest disclosure as sufficient on its own. SB 942 requires the latent, machine-readable disclosure to be embedded by default — an optional visible label alone doesn't satisfy the statute.
- Confusing SB 942 with the EU AI Act's Article 50. Both require disclosing AI-generated content, but they're separate statutes with separate thresholds, mechanisms, and enforcement bodies. Compliance with one doesn't automatically satisfy the other — see how Article 50's disclosure duty differs in scope.
- Ignoring the January 1, 2027 platform-side obligation because "we don't generate the content." If you distribute AI content at scale as a large online platform under AB 853, the detection-and-disclosure duty reaches you too, on a different clock than SB 942's.
- Leaving disclosure obligations out of vendor and partner agreements. If a partner embeds your GenAI output in their product, your terms of service and any partner agreement should state who owns SB 942 compliance for that combined output.
Sources
- California Business and Professions Code § 22757 et seq. (California AI Transparency Act, SB 942), California Legislative Information: https://leginfo.legislature.ca.gov/faces/billNavClient.xhtml?bill_id=202320240SB942
- AB 853 (2025) — amendments extending SB 942's operative date and adding large-online-platform obligations, California Legislative Information: https://leginfo.legislature.ca.gov/faces/billTextClient.xhtml?bill_id=202520260AB853
- California Enacts AI Transparency Law Requiring Disclosures for AI Content, Jones Day: https://www.jonesday.com/en/insights/2024/10/california-enacts-ai-transparency-law-requiring-disclosures-for-ai-content
- California Amends Artificial Intelligence Transparency Act and Passes AI Defenses Act, Hintze Law: https://hintzelaw.com/blog/2025/10/19/california-amends-artificial-intelligence-transparency-act-and-passes-ai-defenses-act
- California AI Transparency Act Amendments Signed Into Law, Troutman Privacy + Cyber + AI: https://www.troutmanprivacy.com/2025/10/california-ai-transparency-act-amendments-signed-into-law/
This article is general information, not legal advice. Laws vary by jurisdiction. Pactlio generates professional drafts for review — have a licensed attorney review anything important.
Frequently Asked Questions
What is the California AI Transparency Act (SB 942)?▾
SB 942, codified at California Business and Professions Code § 22757 et seq., requires large generative-AI providers to offer a free public AI-content detection tool and to make AI-generated content disclosable through visible and machine-readable markers. It became operative August 2, 2026.
Who counts as a 'covered provider' under SB 942?▾
A covered provider is anyone that creates, codes, or substantially modifies a generative AI system that is publicly accessible to Californians and that had more than 1,000,000 monthly visitors or users during the preceding 12 months. Smaller AI tools fall outside SB 942's direct scope.
When did SB 942 take effect?▾
SB 942 was enacted in 2024 with an original January 1, 2026 operative date. AB 853, signed October 13, 2025, pushed that date to August 2, 2026 to align its timeline with the EU AI Act. The three core disclosure duties are now in force.
What are the three disclosure requirements under SB 942?▾
Covered providers must: (1) offer a free, publicly accessible AI-detection tool that lets anyone check whether content was AI-generated; (2) provide users an option to add a manifest (visible) disclosure to AI-generated image, video, or audio content; and (3) embed a latent, machine-readable disclosure by default in that content.
What changes for large online platforms starting January 1, 2027?▾
Under AB 853, 'large online platforms' — public social media, file-sharing, mass-messaging, or search platforms with over 2,000,000 unique monthly users — must detect whether distributed content carries provenance data and disclose that status through their user interface, effective January 1, 2027.
What are the penalties for violating SB 942?▾
Violations carry a civil penalty of $5,000 per violation, and each day a covered provider remains out of compliance counts as a separate violation. A prevailing plaintiff can also recover reasonable attorney's fees and costs, so exposure compounds quickly for an uncorrected gap.
Does SB 942 apply to my small AI-powered product or app?▾
Only if you cross the 1,000,000-monthly-user threshold in California. Most early-stage AI products don't. But it's worth stating your provenance-disclosure practices in your AI platform terms of use now, since the threshold can be crossed unexpectedly after a growth spike.
How should I update my AI platform terms of use for SB 942?▾
If you're near or above the user threshold, your terms of use should name the detection tool you provide, explain how manifest and latent disclosures work in your product, and state who is responsible for disclosure when your AI output is embedded in a partner's platform.