Sacramento moved its date to meet Brussels

On Sunday two separate AI transparency regimes became enforceable within hours of each other, on opposite sides of the Atlantic, and that was not a coincidence. AB 853, signed on 13 October 2025, amended California's AI Transparency Act and reset its start date. The statutory language is plain: this chapter shall become operative on August 2, 2026. The original SB 942, signed by Governor Newsom in September 2024, had been due to start on 1 January 2026. The legislature pushed it back seven months and landed it on the exact day the European Union had already fixed for its own transparency obligations.

The Californian duties attach to a covered provider, defined in the statute as a person that creates, codes, or otherwise produces a generative artificial intelligence system that has over 1,000,000 monthly visitors or users and is publicly accessible within the geographic boundaries of the state. That threshold captures every frontier laboratory and every image, audio and video generator operating at scale. Enforcement sits with the Attorney General, a city attorney, or a county counsel, and the penalty is 5,000 dollars per violation, with each day of continued violation deemed a discrete one.

AB 853 also added three categories that are not live yet, and the staggering is worth noting because it tells you where the law is heading. Large online platforms, defined by more than 2,000,000 unique monthly users, and generative AI system hosting platforms both start on 1 January 2027. Capture device manufacturers, meaning the people who build cameras, phones and voice recorders, start on 1 January 2028. Today only the model makers are on the hook.

One law asks for a mark, the other asks for a reader

Why it matters: Article 50(2) of the AI Act requires providers of systems generating synthetic audio, image, video or text to mark the output in a machine-readable format, and to make those solutions effective, interoperable, robust and reliable as far as this is technically feasible. It is a marking duty. It says what has to be put into the file. It does not say that anyone has to be given a way to read it back out.

SB 942 does say that. Alongside the embedded disclosure, a covered provider has to make available an AI detection tool at no cost to the user. The statute specifies that the tool must be publicly accessible, must let a person upload content or submit a URL, and must include an application programming interface that allows a user to invoke the tool without visiting the covered provider's internet website. That last clause is the one to read twice. It is not a web form. It is a mandated endpoint.

The practical difference: Brussels obliged the industry to write something into the file. Sacramento obliged the same companies to hand out the decoder, free, and to make it callable from a script. Two regimes aimed at the same problem, and only one of them produced a capability a buyer can actually use on a Monday morning.

Nothing in the Californian text limits who may use that tool by geography. The obligation is framed around where the system is accessible and how many users it has, not around where the person doing the checking sits. A procurement officer in Rotterdam or Manchester can call the same endpoint as one in San Jose. That is an unusual thing for a state statute to produce, and it arrived without any European legislature having asked for it.

The disclosure carries a version number, not a flag

The second asymmetry is in what the mark actually says. California's latent disclosure has to convey the name of the covered provider, the name and version of the generative system that made or altered the content, the time and date of that creation or alteration, and a unique identifier. The statute permits that payload to be carried directly or through a link to a permanent internet website. It is a record, not a warning label.

Yes, but: a machine-readable mark under Article 50(2) can satisfy the European requirement while telling you only that some model was involved. That is enough to discharge a labelling duty and close to useless when you are trying to reconstruct an incident. Knowing that a file came from a named system at a stated version, at a stated moment, is the difference between an audit trail and a shrug. If a supplier sends you a generated product image in March and you are arguing about it in November, the version string is the fact that settles which model was in service.

There is one more Californian clause with an operational edge. Where a third party licenses a covered system and modifies it so the required disclosures stop working, the provider has to revoke the licence within 96 hours of discovering it. That is a hard, short, countable deadline sitting inside a transparency statute, and it is the kind of term that tends to migrate into commercial contracts long before any regulator invokes it.

Two days out, the readers were in different states

OpenAI has been building toward this. On 19 May 2026 it joined the C2PA standards steering committee, embedded Google DeepMind's SynthID watermark in images from ChatGPT, the API and Codex, and released Verify, a public research preview that lets anyone upload an image and check it for either signal. On 31 July 2026, two days before the Californian date, it extended the work to audio and introduced API access for verification so that developers can put provenance checks inside their own workflows. The sequencing speaks for itself.

Google's position on its own pages reads differently. SynthID is deployed at enormous scale, covering output from Gemini, Imagen, Lyria and Veo, with more than 10 billion pieces of content marked. The SynthID Detector, though, is still presented by DeepMind as an early tester programme, with the company describing itself as collaborating with journalists and media professionals to test the portal, and offering a waitlist rather than an open door. A content detection API has been previewed to a set of named partners including Shutterstock, Snap and Canva.

The open question: whether a waitlisted portal for accredited professionals meets a statutory standard of publicly accessible, with an API a user can invoke, is not something a journal can settle, and no enforcement action has been announced. What can be said precisely is that the standard is now operative, the meter runs at 5,000 dollars a day per continuing violation, and two of the largest covered providers arrived at the same deadline with visibly different amounts of the machinery built.

Every checker only reads its own maker's ink

Here is the limit nobody advertises. These tools are provenance readers for the provider that built them. Google's detector is framed around identifying whether content was created or altered by Google AI. OpenAI's tool checks for the signals OpenAI embeds. There is no cross-vendor register, no shared lookup, and no obligation anywhere in either statute to build one. The law mandates readers in the plural and leaves the integration to you.

The bottom line: a European owner holding one questionable image now has a real capability that did not exist last week, and a real trap sitting next to it. The capability is that a specific claim can be tested for free against the company most likely to have produced the file. The trap is the negative result. Checking an image against every covered provider and getting no hit does not establish that a person made it. It establishes that no marking participant made it, which also describes every open-weights model run on a rented server, every tool that strips metadata on export, and every screenshot.

So the sane use is narrow and worth doing anyway. Test positively, when you have a reason to suspect a named source. Put the version string into the file note when a check comes back with one, because that is the piece that will still mean something a year from now. And stop treating an unmarked file as evidence of anything at all, because from today the absence of a mark is the least informative result the system can return.