A Delayed Law Finally Takes Effect
California's AI Transparency Act, Senate Bill 942 and widely known by its acronym CAITA, became operative on August 2, 2026, making it the first mandatory watermarking and provenance-disclosure law for AI-generated content in the United States. The law was signed years earlier with a January 1, 2026 start date, but a follow-up bill, AB 853, passed in 2025, pushed that date back to August 2, 2026 to give providers more time to build the detection infrastructure the law requires.
CAITA binds any generative-AI provider with more than one million monthly users or visitors who are publicly accessible in California, a threshold that in practice reaches far past California's own market. OpenAI, Google, Meta, Microsoft and Adobe all clear it without difficulty, and so does effectively any consumer AI product built for a global audience, because a product used by millions worldwide rarely stays under one million users in the single largest US state.
Three Duties, One of Them Invisible
The statute imposes three separate obligations. A covered provider must offer, at no cost, a public AI-detection tool that accepts an uploaded file, a URL or an API call and returns whether the content was AI-generated; the tool may collect no personal information beyond voluntary, opt-in feedback. It must also offer users an optional visible disclosure mark that clearly and conspicuously identifies content as AI-generated and is permanent, or extraordinarily difficult to remove, wherever that is technically feasible.
The third duty is mandatory rather than optional, and it is the one users never see. Covered AI-generated images, video and audio must carry latent, machine-readable metadata naming the generating system, its version and the date the content was created or altered, embedded in a form durable enough to survive normal handling and consistent with widely accepted industry standards. Video games, television, streaming and movies are explicitly excluded from CAITA's scope, and a law-firm analysis of the statute notes that purely textual AI output falls outside it as well.
A Small Number That Compounds Fast
CAITA carries no private right of action. Only the California attorney general and other state actors can bring a case, and the penalty for a proven violation is $5,000, with each day a provider remains out of compliance counted as a separate violation. A gap that persists for a month against a single requirement is not a single $5,000 exposure; it is roughly thirty of them, stacking for as long as the gap stays open.
That structure rewards providers who fix a compliance gap fast and punishes the ones who do not notice it. It also sits at the opposite end of the enforcement spectrum from the European Union's AI Act, whose own transparency regime carries fines of up to EUR 15 million or 3 percent of worldwide annual turnover, whichever is higher. California metes out a slow drip; Brussels holds a much bigger stick. Ignoring either one is expensive, just on a different clock.
The Same Date, Two Independent Rulebooks
CAITA's August 2, 2026 start date lands on the same day the European Union's AI Act brings its own transparency regime into force. Article 50 of the AI Act requires providers of AI systems, including general-purpose systems, that generate synthetic audio, image, video or text to ensure the output is marked in a machine-readable format and is detectable as AI-generated, and those obligations also became applicable on August 2, 2026. The two dates matching is coincidence, not coordination; California's legislature and the European Parliament wrote these rules on separate timelines without reference to each other.
The technical specifications do not match just because the calendar does. CAITA tells a provider exactly what its latent metadata must contain: the generating system's name, its version and a creation or alteration date, embedded durably. Article 50 requires a machine-readable, detectable mark without naming those same fields in the statute itself, and the European Commission's Code of Practice leans toward a C2PA-style provenance approach for the technical form. A single embedding scheme built to clear one bar is not automatically built to clear the other, and nothing in either law promises that it will.
What an Owner Should Actually Check
The useful question is not whether CAITA exists; it is whether the provenance metadata your product already embeds satisfies it. Pull a sample of your own AI-generated output and confirm the latent metadata names the generating system and version and carries a creation date in a form that survives an ordinary export, a recompression or a platform re-upload. Then run that same sample through your own public detection tool and confirm it correctly flags it, because a detection tool that cannot recognize its own provider's output is itself a violation waiting to be found.
Then run the same check against the EU side rather than assuming the first check covers it. Confirm the mark is machine-readable and detectable under Article 50's own terms, and note that the AI Omnibus agreement reached in May 2026 gives generative systems already on the market before August 2, 2026 until December 2, 2026 to meet that regime's machine-readable marking duty specifically. That gap in the calendar is a window to test the overlap properly, not a reason to assume there is none.
Read next: August 2 Is When the EU AI Fines Become Real | Your Moderation Policy Can Stay in Your Building



