What became operative on 2 August
California passed the AI Transparency Act as SB 942 in 2024, with a compliance date of 1 January 2026. That date moved. AB 853, signed on 13 October 2025, rewrote parts of the Act and pushed the operative date to 2 August 2026 — the same day the EU AI Act's transparency article took effect, an alignment several legal commentators read as deliberate. As of last week, the core duties are live.
There are three of them, and they apply to the company that builds the generative system:
| Duty | What it requires | Where users would notice |
|---|---|---|
| Latent disclosure | Embed provenance data that uniquely identifies the content, names the generative system and its version, and records the date the content was created or altered — where technically feasible. | Almost nowhere. It lives inside the file, for machines to read. |
| Manifest disclosure | Offer users the option to attach a clear, conspicuous label identifying the content as AI-generated. The label must be permanent or extraordinarily difficult to remove. | A toggle or export option in the app, and a visible marker on the output when it is switched on. |
| AI detection tool | Make available, at no cost, a publicly accessible tool that lets anyone check whether a piece of content came from that provider's system, and surfaces any provenance data found. | A public web page, usually separate from the product itself. |
Note the asymmetry between the first two. The hidden marker is mandatory and always on; the visible label is a user option the provider has to offer. So the law's default outcome is not a watermark on every AI picture — it is a silent trail in the metadata plus a public tool that can read it.
Who is actually covered
The Act binds a "covered provider": a person that creates, codes or otherwise produces a generative AI system with over 1,000,000 monthly visitors or users that is publicly accessible within California. Two things follow that matter for our category.
First, the threshold attaches to the generative system, not to a corporate parent's total audience. Second, most companion apps do not build their own image or voice models — they call someone else's. In that arrangement the model provider is the one holding the labelling obligation, and the app is a customer of a system that either carries provenance data or does not. The practical question for an app operator is therefore less "am I a covered provider" and more "does my image vendor stamp its output, and does my pipeline preserve that data when it resizes, re-encodes or screenshots the result".
Neither the statute nor the current commentary names specific apps as covered or not, and we are not going to guess at monthly-user figures we cannot verify.
Text is exempt — and that is the biggest difference from the EU rule
The disclosure duties are written for "image, video, or audio content, or content that is any combination thereof". A system that only produces text is outside them, however large it is. For a chat-first companion app, that means the conversation itself is untouched by this law; the generated selfie, the voice message and the animated clip are not.
That is a real divergence from Europe. As we covered when the EU AI Act's Article 50 became applicable, the EU marking duty reaches generated text as well, and it adds a separate obligation to tell users they are talking to an AI at all. California's Act does neither.
| California AI Transparency Act | EU AI Act, Article 50 | |
|---|---|---|
| Live since | 2 August 2026 | 2 August 2026 (marking grace period to 2 December 2026 for systems already on the market) |
| Content in scope | Image, video, audio | Text, image, audio, video |
| "You're talking to an AI" duty | No | Yes, for systems that interact directly with people |
| Public detection tool | Required | Not required |
| Size threshold | Over 1,000,000 monthly users | None — applies regardless of size |
| Penalty ceiling | $5,000 per violation, per day | €15 million or 3% of worldwide annual turnover |
And neither should be confused with the safety and age rules that get discussed in the same breath. California's SB 243, operative since 1 January 2026, is the companion-chatbot law: AI disclosure in conversation, break reminders for known minors, self-harm protocols, and damages of $1,000 per violation that a harmed user can pursue personally. The Transparency Act is about where a file came from. Complying with one says nothing about the other.
What this looks like from inside a character app
Nothing about the chat experience is required to change. What may change, quietly:
- Metadata on generated images. Download an AI selfie and inspect the file: content credentials or an equivalent signed manifest naming the generating system, its version and a timestamp. The specifications usually cited here are C2PA content credentials for the signed metadata and imperceptible watermarking for the pixel-level layer, since metadata alone does not survive a screenshot.
- A labelling option at export. Some apps will surface a "mark as AI-generated" switch on share or download. Under the Act that option has to exist for covered providers; whether it defaults on is up to them.
- A detection page you will probably never visit. Useful in one specific situation: someone has sent you an image and claims it is real. That is what the free tool is for.
- Voice, not just pictures. Audio is explicitly in scope. Companion apps with voice calls or generated voice notes fall under the same duty as image generators, which is easy to overlook.
What the Act does not do is restrict what can be generated. It is a provenance rule, not a content rule — no bearing on filters, adult content or age gates.
The dates still ahead
Two later phases are already written into the law. From 1 January 2027, "large online platforms" — public-facing social media, file-sharing, mass-messaging or stand-alone search services that distribute content their users did not create, and that exceeded 2,000,000 unique monthly users over the preceding 12 months — must detect provenance data that complies with widely adopted standards, tell users when it is present, let them inspect it, and refrain from knowingly stripping it out. That is the phase that determines whether any of this survives contact with the internet, because provenance data that gets scrubbed on upload is provenance data nobody can check.
From 1 January 2028, makers of capture devices — cameras, phones — must offer latent disclosures on captured content and enable them by default where technically feasible, which builds the other half of the picture: a marker that says "a lens recorded this", not just "a model generated this".
What we're checking in reviews
We do not certify legal compliance and we are not lawyers. What we can record is observable behaviour, which is how our review methodology treats anything a vendor could otherwise just assert. From this month, for every app we look at that generates images or voice, we note whether a downloaded file carries any provenance metadata at all, whether the app offers a visible AI label on export, and whether the metadata survives the app's own sharing flow rather than being stripped on the way out.
Those are narrow, checkable facts. They also happen to be the ones most likely to differ between two apps that look identical in a store listing — the same problem we ran into with app-store age ratings, where the badge told you far less than the behaviour did.
Related on CompanionRank
The EU's AI Disclosure Rules Now Apply to Companion Apps In-Chat Image Generation: What It Adds Privacy & Age Verification, Explained How We ReviewFrequently asked questions
What is the California AI Transparency Act?
It is the law created by SB 942 in 2024 and amended by AB 853, which was signed on 13 October 2025. It requires large providers of generative AI to embed hidden provenance data in the image, video and audio content their systems produce, to offer users an option for a visible label, and to publish a free AI detection tool. Its main obligations became operative on 2 August 2026.
Which companion apps are covered by the Act?
The obligations fall on a covered provider, defined as a person that creates, codes or otherwise produces a generative AI system with over 1,000,000 monthly visitors or users that is publicly accessible within California. A character app that generates images or voice at that scale is in scope. A small studio below the threshold is not, and an app that only generates text is outside the labelling duties regardless of size.
Does the Act apply to AI-generated text in chat?
No. The disclosure duties are written for image, video or audio content, or any combination of those. Text-only output is not covered. This is the single biggest practical difference from the EU AI Act, whose Article 50 marking duty does extend to generated text.
What are the penalties, and can users sue?
The civil penalty is $5,000 per violation, with each day of violation counted as a discrete violation. Enforcement sits with the Attorney General, a city attorney or a county counsel. There is no private right of action, which is the opposite of California's SB 243 companion chatbot law, where a harmed user can sue directly.
What changes in 2027 and 2028?
From 1 January 2027, large online platforms — public-facing social media, file-sharing, mass messaging or stand-alone search services that distribute other people's content and exceeded 2,000,000 unique monthly users over the preceding 12 months — must detect compliant provenance data, show it to users, let users inspect it, and must not knowingly strip it. From 1 January 2028, makers of capture devices such as cameras and phones must offer latent disclosures and enable them by default where technically feasible.