Compliance 9 min

California AI Transparency Act: Enterprise Compliance Guide

California's AI Transparency Act creates provenance duties for large public GenAI providers, but AB 853 changed the operative timeline. Enterprise buyers should know the amended dates before planning readiness work.

TL;DR

  • Map each AI workflow to an owner, applicable requirement, evidence source, and review cadence.
  • Keep inventory, policy, approvals, exceptions, and audit trails connected to actual AI usage.
  • Treat external frameworks as inputs to operating controls, not as substitutes for implementation.
  • Review stale evidence, expired exceptions, and control drift before an auditor or buyer asks.

Update: AB 853 Changed the Timeline

Last reviewed May 21, 2026. This article has been updated to reflect AB 853, which was approved and filed on October 13, 2025. SB 942 originally made the California AI Transparency Act operative on January 1, 2026, but AB 853 amended that timing. The chapter now becomes operative on August 2, 2026, with additional obligations for large online platforms and GenAI hosting platforms beginning January 1, 2027, and capture-device manufacturer obligations beginning January 1, 2028. The official AB 853 bill text is available from California Legislative Information.

This distinction matters. A company reading older SB 942 summaries may think covered providers were already late as of January 1, 2026. Under the amended text, readiness work should be planned against the August 2, 2026 operative date, while also tracking the later 2027 and 2028 duties for platform and device categories.

The New Standard for AI Transparency

California's SB 942 created the California AI Transparency Act in 2024. AB 853 then amended the statute in 2025, delayed the operative date, and added later duties for several platform and device categories. The law is narrower than many broad AI-policy summaries imply. The core covered-provider definition still focuses on a person or entity that creates, codes, or otherwise produces a generative AI system with more than 1,000,000 monthly visitors or users and that is publicly accessible in California.

That means most enterprises are not directly covered merely because employees use AI at work. The practical enterprise issue is procurement and workflow control: if a team relies on covered public GenAI tools to create customer-facing media, the company should know whether the tool supports disclosure mechanisms, whether exported files preserve provenance data, and whether downstream editing strips those signals. Treat the Act as a media-provenance and vendor review trigger, not as a blanket rule for every AI-written email, report, or support draft.

Mandatory Watermarking and Content Provenance

SB 942 focuses its detection-tool, manifest-disclosure, and latent-disclosure requirements on image, video, and audio content, including combinations of those media. Covered providers must make a no-cost AI detection tool available, offer users the option to include a clear manifest disclosure in generated or altered image, video, or audio content, and include latent provenance data in AI-generated image, video, or audio content when technically feasible and reasonable.

The Act does not impose the same watermarking requirement on blocks of generated text. It also does not name C2PA as the required standard; it requires latent disclosures to be consistent with widely accepted industry standards. Enterprise teams should still prefer tools and workflows that preserve content provenance, because media files often move through editing, DAM, CMS, and social-publishing systems that can strip metadata. A governed workflow can help preserve provider disclosures, document when provenance is lost, and route external media through review before publication.

The Imperative of Immutable Audit Trails

SB 942 does not create a general enterprise audit-trail mandate for every generative AI deployment. Section 22757.4 sets the civil penalty structure: covered providers that violate the chapter can face $5,000 per violation, enforced by the Attorney General, a city attorney, or county counsel. The Act also includes privacy limits for detection tools, including restrictions on retaining personal information, submitted content, and personal provenance data.

Audit trails remain important, but the reason should be stated accurately. For enterprise buyers and deployers, logs help answer practical governance questions: which tool produced the media, which workflow exported it, whether a manifest disclosure was requested, whether latent provenance survived editing, and who approved external use. Those logs support vendor management, incident response, and consumer-protection reviews, even when SB 942 itself places the core statutory duties on covered providers.

Use Review Gates Without Inventing Legal Duties

SB 942 does not distinguish low-impact and high-impact enterprise AI usage, and it does not use the phrase "meaningful human review." Those concepts appear in other AI governance discussions and in some automated-decision frameworks, but they should not be attributed to this Act.

That does not make review gates unnecessary. If AI-generated media, chatbot scripts, financial explanations, legal-adjacent drafts, hiring content, healthcare content, or safety-related communications will reach consumers, a human review workflow is still good governance. Using role-based access control and routing logic, a company can require approval before external publication, record who approved the content, and document whether the relevant provider disclosure was preserved. The review gate is a risk-control best practice here, not a specific SB 942 command.

Managing Data Inputs and RAG Compliance

The Act does not directly regulate enterprise Retrieval-Augmented Generation (RAG) inputs or require companies to disclose every document source behind a customer-facing AI bot. RAG quality, source freshness, permission boundaries, and customer-data isolation are still critical, but they are governed by broader privacy, security, consumer-protection, contractual, and sector-specific obligations rather than SB 942's media-provenance rules.

A practical control program should still connect these concerns. Keep an inventory of external-facing AI systems, identify which ones generate or alter image, video, or audio content, track the providers and model routes involved, and separate that media-provenance evidence from RAG source-management evidence. This avoids overstating one statute while still giving security, legal, and product teams the facts they need.

The Road to Compliance

Plan readiness around the amended dates, not the original SB 942 date. Covered providers should prepare detection-tool and disclosure programs before August 2, 2026. Large online platforms and GenAI hosting platforms should separately map the duties that begin January 1, 2027. Capture-device manufacturers should track the obligations that apply beginning January 1, 2028 for covered devices first produced for sale in California on or after that date.

Enterprise buyers should focus on a narrower readiness plan: identify covered GenAI providers in the stack, ask vendors how their manifest and latent disclosures work, test whether editing and publishing workflows preserve provenance, and define review rules for external image, video, and audio content. A centralized AI control layer can help, but the goal should be precise: preserve provenance where it exists, prevent employees from bypassing approved media workflows, keep evidence of publication decisions, and avoid conflating this law with unrelated high-risk decision or RAG-source obligations. Accurate scoping makes the compliance program stronger and easier to defend.

Free Resource

The 1-Page AI Safety Sheet

Print this, pin it next to every screen. 10 rules your team should follow every time they use AI at work.

You get

A printable 1-page PDF with 10 clear do's and don'ts for AI use.

Operational Checklist

  • Assign a requirement owner for each framework, law, customer obligation, or internal policy in scope.
  • Assign an evidence owner for inventory, approvals, exceptions, testing, audit logs, and review notes.
  • Assign a review-cadence owner for stale controls, overdue evidence, and expired exceptions.
  • Assign a legal escalation owner for high-risk use cases, unclear roles, and external commitments.

Metrics to Track

  • Audit evidence completeness
  • Retention exception count
  • Policy violation recurrence rate
  • Review cycle SLA adherence

Free Assessment

How Exposed Is Your Company?

Most companies already have employees using AI. The question is whether that's happening safely. Take 2 minutes to find out.

You get

A short report showing where your biggest AI risks are right now.

Knowledge Hub

Article FAQs

It can apply outside California if the company is a covered provider: it creates, codes, or produces a GenAI system with more than 1,000,000 monthly visitors or users and that is publicly accessible in California. A company is not directly covered merely because employees use an AI tool at work.
SB 942's detection-tool, manifest-disclosure, and latent-disclosure provisions focus on image, video, and audio content, including combinations of those media. The Act does not create the same watermarking requirement for generated text.
Most internal usage is affected indirectly through vendor selection and publication workflows. Enterprises should know which covered providers they use, whether AI-generated media exports carry provenance data, and whether internal editing or publishing steps remove disclosures.
No. SB 942 is a transparency and provenance law for covered GenAI providers. Human review may still be required or prudent under other laws, contracts, sector rules, or internal risk policies, but it should not be described as an SB 942 requirement.
That was the original SB 942 timing. AB 853, approved and filed on October 13, 2025, delayed operation of the chapter to August 2, 2026 and added later phased obligations for large online platforms, GenAI hosting platforms, and capture-device manufacturers.

SAFE AI FOR COMPANIES

Deploy AI for companies with centralized policy, safety, and cost controls.

Sign Up