Update: AB 853 Changed the Timeline
Last reviewed May 21, 2026. This article has been updated to reflect AB 853, which was approved and filed on October 13, 2025. SB 942 originally made the California AI Transparency Act operative on January 1, 2026, but AB 853 amended that timing. The chapter now becomes operative on August 2, 2026, with additional obligations for large online platforms and GenAI hosting platforms beginning January 1, 2027, and capture-device manufacturer obligations beginning January 1, 2028. The official AB 853 bill text is available from California Legislative Information.
This distinction matters. A company reading older SB 942 summaries may think covered providers were already late as of January 1, 2026. Under the amended text, readiness work should be planned against the August 2, 2026 operative date, while also tracking the later 2027 and 2028 duties for platform and device categories.
The New Standard for AI Transparency
California's SB 942 created the California AI Transparency Act in 2024. AB 853 then amended the statute in 2025, delayed the operative date, and added later duties for several platform and device categories. The law is narrower than many broad AI-policy summaries imply. The core covered-provider definition still focuses on a person or entity that creates, codes, or otherwise produces a generative AI system with more than 1,000,000 monthly visitors or users and that is publicly accessible in California.
That means most enterprises are not directly covered merely because employees use AI at work. The practical enterprise issue is procurement and workflow control: if a team relies on covered public GenAI tools to create customer-facing media, the company should know whether the tool supports disclosure mechanisms, whether exported files preserve provenance data, and whether downstream editing strips those signals. Treat the Act as a media-provenance and vendor review trigger, not as a blanket rule for every AI-written email, report, or support draft.
Mandatory Watermarking and Content Provenance
SB 942 focuses its detection-tool, manifest-disclosure, and latent-disclosure requirements on image, video, and audio content, including combinations of those media. Covered providers must make a no-cost AI detection tool available, offer users the option to include a clear manifest disclosure in generated or altered image, video, or audio content, and include latent provenance data in AI-generated image, video, or audio content when technically feasible and reasonable.
The Act does not impose the same watermarking requirement on blocks of generated text. It also does not name C2PA as the required standard; it requires latent disclosures to be consistent with widely accepted industry standards. Enterprise teams should still prefer tools and workflows that preserve content provenance, because media files often move through editing, DAM, CMS, and social-publishing systems that can strip metadata. A governed workflow can help preserve provider disclosures, document when provenance is lost, and route external media through review before publication.
The Imperative of Immutable Audit Trails
SB 942 does not create a general enterprise audit-trail mandate for every generative AI deployment. Section 22757.4 sets the civil penalty structure: covered providers that violate the chapter can face $5,000 per violation, enforced by the Attorney General, a city attorney, or county counsel. The Act also includes privacy limits for detection tools, including restrictions on retaining personal information, submitted content, and personal provenance data.
Audit trails remain important, but the reason should be stated accurately. For enterprise buyers and deployers, logs help answer practical governance questions: which tool produced the media, which workflow exported it, whether a manifest disclosure was requested, whether latent provenance survived editing, and who approved external use. Those logs support vendor management, incident response, and consumer-protection reviews, even when SB 942 itself places the core statutory duties on covered providers.
Use Review Gates Without Inventing Legal Duties
SB 942 does not distinguish low-impact and high-impact enterprise AI usage, and it does not use the phrase "meaningful human review." Those concepts appear in other AI governance discussions and in some automated-decision frameworks, but they should not be attributed to this Act.
That does not make review gates unnecessary. If AI-generated media, chatbot scripts, financial explanations, legal-adjacent drafts, hiring content, healthcare content, or safety-related communications will reach consumers, a human review workflow is still good governance. Using role-based access control and routing logic, a company can require approval before external publication, record who approved the content, and document whether the relevant provider disclosure was preserved. The review gate is a risk-control best practice here, not a specific SB 942 command.
Managing Data Inputs and RAG Compliance
The Act does not directly regulate enterprise Retrieval-Augmented Generation (RAG) inputs or require companies to disclose every document source behind a customer-facing AI bot. RAG quality, source freshness, permission boundaries, and customer-data isolation are still critical, but they are governed by broader privacy, security, consumer-protection, contractual, and sector-specific obligations rather than SB 942's media-provenance rules.
A practical control program should still connect these concerns. Keep an inventory of external-facing AI systems, identify which ones generate or alter image, video, or audio content, track the providers and model routes involved, and separate that media-provenance evidence from RAG source-management evidence. This avoids overstating one statute while still giving security, legal, and product teams the facts they need.
The Road to Compliance
Plan readiness around the amended dates, not the original SB 942 date. Covered providers should prepare detection-tool and disclosure programs before August 2, 2026. Large online platforms and GenAI hosting platforms should separately map the duties that begin January 1, 2027. Capture-device manufacturers should track the obligations that apply beginning January 1, 2028 for covered devices first produced for sale in California on or after that date.
Enterprise buyers should focus on a narrower readiness plan: identify covered GenAI providers in the stack, ask vendors how their manifest and latent disclosures work, test whether editing and publishing workflows preserve provenance, and define review rules for external image, video, and audio content. A centralized AI control layer can help, but the goal should be precise: preserve provenance where it exists, prevent employees from bypassing approved media workflows, keep evidence of publication decisions, and avoid conflating this law with unrelated high-risk decision or RAG-source obligations. Accurate scoping makes the compliance program stronger and easier to defend.
.png)