The California AI transparency law, known as SB 942, comes into force today, 2 August 2026. Providers of generative AI with more than one million monthly users in California must now embed an invisible, hard-to-remove provenance marker in every image, video and audio file they produce, and offer the public a free tool to check whether content was generated by their system. Violations are penalised at $5,000 per day per offence.
There are few dates on which a rule genuinely changes what you see on the internet. Today is one of them, even if you don't live in California. Here's what the law provides, why it reaches far beyond US borders, and what it doesn't solve.
What the law requires
The text targets what it calls covered providers: companies operating a publicly accessible generative AI system with more than one million monthly visitors or users in California. In other words, the big names in the industry. Three obligations apply.
A mandatory invisible marker. This is the core of the mechanism. Every image, video or audio file generated or substantially modified must contain a machine-readable provenance trace. This trace must indicate the provider's name, the name and version of the system used, the timestamp of creation, and a unique identifier linking the content to the system that produced it. The law requires this marker to be permanent or extraordinarily difficult to remove, wording that rules out simple metadata that a crop can strip away.
A public, free detection tool. Each covered provider must make available to everyone a way to check whether a given piece of content comes from its system. Not a paid service reserved for professionals: a tool accessible to anyone.
An optional visible label. Providers must offer users the option of adding a visible notice indicating that the content was AI-generated. The user chooses whether to apply it, but the feature must exist.
The marking requirement applies to images, video and audio, but not to generated text. This is a deliberate choice by the legislature, reflecting a hierarchy of risk: a fake face or voice deceives far more effectively than a paragraph. It also means that an article written entirely by AI will carry no mandatory marker, while a simple illustration will. An asymmetry that raises questions, but is explained by the technical difficulty of watermarking text without distorting it.
Why it concerns you even in France
Three reasons make this law relevant well beyond California.
The technical standard is global. The law refers to widely accepted industry standards, which in practice means the C2PA specification, backed by a coalition including Adobe, Microsoft, the BBC and others. The same standard underpins the marking requirements set out in the European AI regulation. In other words, this isn't a Californian standard, it's the international standard finding its first binding application.
Companies won't run two versions. A provider that must watermark its outputs for California isn't going to maintain a separate pipeline for the rest of the world. Compliance therefore spreads mechanically to all users, wherever they are. It's the same mechanism that spread the practices of European data regulation worldwide.
The timeline is deliberately aligned with Europe. The effective date was pushed back from 1 January to 2 August 2026 precisely to coincide with European deadlines. That's not a coincidence, it's coordination.
What it doesn't solve
Let's stay clear-eyed about the limits, because they are real.
First, the law only covers large providers. An open model downloaded and run on a personal machine falls outside its scope. Yet as we've seen with open-weight models, these are precisely the ones no one can constrain once released. Someone wanting to produce a fake for malicious purposes will use an uncovered model, not a consumer service.
Second, a marker indicates what is AI-generated, but its absence proves nothing. Content without a marker may be authentic, or come from an uncovered system, or have been transformed enough to lose its trace. We gain a positive verification capability, not a guarantee of authenticity.
Finally, technical robustness remains a challenge. A marker must survive compression, cropping, a screenshot. The best implementations often manage this, but not always.
Why it's still progress
Despite these limits, this law changes something important: it shifts the burden of proof. Until now, faced with a dubious image, you had to demonstrate it was fake, an almost impossible exercise for an individual. From now on, for anything coming out of the major platforms, it becomes possible to positively verify the origin of content, for free.
It's a concrete counterweight to the concerns we described in our article on deepfakes, at a time when models like FLUX 3 or Seedance produce audio-visual content that is hard to distinguish from reality.
The question that remains open is one of usage. A free verification tool only helps if people use it, and experience suggests most share before they check. The law builds the infrastructure of trust. It cannot build the reflex.