US AI regulation and synthetic media labelling

California's AI Transparency Act Bets That Watermark Mandates Beat Downstream Deepfake Liability

CAITA's Aug. 2 disclosure rules for major AI providers are a workable model, but daily fines and metadata that erodes in transit reveal the compliance gap.

California's AI Disclosure Mandate, By the Numbers People of Internet Research · US 1M+ monthly User threshold for coverage Providers with over one million mo… $5,000 Penalty per violation, per day Each day of continued non-complian… Jan 1, 2027 Platform provenance duties begin Large online platforms must start … Jan 1, 2028 Device-level disclosure begins Capture device manufacturers must … peopleofinternet.com
California's AI Disclosure Mandate, By… People of Internet Research · US 1M+ monthly User threshold for coverage $5,000 Penalty per violation, per d… Jan 1, 2027 Platform provenance dutie… Jan 1, 2028 Device-level disclosure begins peopleofinternet.com

Key Takeaways

A Statute Built on a Fair Premise

The strongest case for California's AI Transparency Act (CAITA) is straightforward: synthetic image, video, and audio content is now cheap to produce and hard to distinguish from the real thing, and existing law gives ordinary people almost no tools to tell the difference. A voter watching a synthetic video of a candidate, a job applicant vetting a company's marketing, or a parent evaluating a viral clip has no reliable way to check provenance. Provenance metadata that survives from creation to consumption is a genuinely useful piece of infrastructure, and requiring the companies best positioned to build it — the model providers themselves — to do so is a defensible allocation of the burden. That is the premise Sacramento acted on, and as of August 2, 2026, it is binding law.

CAITA, enacted as SB 942 in 2024 and substantially delayed and amended by AB 853 (approved October 13, 2025), requires "covered providers" — generative AI systems with more than one million monthly visitors or users accessible in California — to do three things (SB 942 statute text; AB 853 statute text). First, embed latent, machine-readable metadata in AI-generated media identifying the system and version used and the date of creation or alteration. Second, offer users an optional visible "manifest" disclosure — a watermark or label — that is permanent or extraordinarily difficult to strip out. Third, publish a free, publicly accessible detection tool that lets anyone check whether a given file carries that provenance data. Civil penalties run $5,000 per violation, with each day of continued non-compliance treated as a separate violation, enforced by the state attorney general, city attorneys, or county counsel — the statute creates no private right of action (Morgan Lewis analysis).

The Design Choices Are Better Than the Alternative

Compared to the deepfake-criminalization statutes several states passed in the early 2020s, CAITA is a meaningful improvement, and it's worth saying so plainly. The Electronic Frontier Foundation's long-standing objection to laws like Texas's political-deepfakes statute is that criminalizing content based on an "intent to deceive" standard hands prosecutors discretion to go after satire, dramatization, and ordinary editing — a Houston mayor cited that state's law when calling for a political opponent to be investigated (EFF, "Not a Hoax"). CAITA sidesteps that problem almost entirely: it regulates disclosure infrastructure at the provider level, not speech content, and it imposes no criminal liability on individual speakers who create or share synthetic media. A satirist who uses a CAITA-compliant tool commits no violation; the obligation sits on OpenAI, Google, Adobe, and similar platforms to make the tool label its output, not on the person using it. That is a real First Amendment improvement over content-based deepfake statutes, and regulators elsewhere should study it.

Where the Statute's Own Design Undercuts It

The trouble is that provenance metadata is fragile in exactly the ways the law doesn't account for. As one early compliance review of the August 2 rollout put it, "the latent disclosure that survives collection may not survive processing" — routine steps like format conversion, re-compression, screenshotting, or social-platform re-encoding strip embedded metadata as a side effect, not by design (EDRM analysis). A provider can embed a fully compliant watermark at the point of generation and have it vanish three re-uploads later through no fault of the original system. CAITA's phased structure acknowledges this only partially: large online platforms don't have to detect and surface provenance data until January 1, 2027, and capture-device manufacturers (cameras, phones) aren't required to offer latent disclosure by default until January 1, 2028. That two-and-a-half-year gap between provider obligations and platform/device obligations means the detection tool CAITA mandates today will, for now, mostly confirm that metadata is missing — not because a covered provider failed to embed it, but because nothing downstream was built to preserve it yet.

The daily-accrual penalty structure compounds that risk asymmetrically. A genuine compliance gap in a widely-forked or self-hosted open model, or a metadata pipeline that silently breaks after a routine update, can generate a $5,000-per-day exposure before anyone notices — a bill that reaches $500,000 in 100 days regardless of whether the provider acted in bad faith. Sacramento was also deliberate about calibrating scope: the one-million-user threshold excludes startups and research labs, and a since-introduced bill, SB 1000, would strip that threshold and apply CAITA to all generative AI products regardless of size — a move that would sweep in exactly the smaller developers the current design was built to spare, without the compliance infrastructure the large players have.

The Fix Is Sequencing, Not Retreat

None of this argues for abandoning provenance disclosure as a policy tool — it argues for sequencing enforcement to match technical reality. California should treat the current phase-in as a genuine grace period: penalize willful non-disclosure now, but hold daily fines for metadata-survival failures until the 2027–2028 platform and device obligations actually give the ecosystem a chance to preserve what providers embed. The EU's parallel Article 50 transparency obligations under the AI Act, which took effect on a deliberately matched timeline, face the identical fragility problem and would benefit from the same restraint. A disclosure regime that only works end-to-end once every layer of the pipeline complies shouldn't impose end-to-end penalties before every layer is required to.

Sources & Citations

  1. SB 942, California AI Transparency Act (statute text)
  2. AB 853, California AI Transparency Act amendment (statute text)
  3. Morgan Lewis: New California AI Disclosure Rules Become Operative
  4. EDRM: California's AI Transparency Act Arrives Alongside Europe's Article 50
  5. EFF: Not a Hoax — The Very Real Threat of Political 'Deepfakes' Laws