California provenance rules land in three phases
SB 942 as amended by AB 853 switches on across 2026, 2027 and 2028. Three dates, three different kinds of company, and one chain of custody.
Half the coverage calls it SB 942. The other half calls it AB 853. They are the same regime: SB 942 created the California AI Transparency Act, and AB 853 amended it — moving the provider-side start date to 2 August 2026 and adding two further tiers of duty behind it. Searching for one name and not the other is how people end up with two thirds of the picture.
Read as a whole, it is not three separate rules. It is one idea implemented in three phases, and the phases only make sense in relation to each other.
The three phases
| Effective | Binds | Core duty |
|---|---|---|
| 2 Aug 2026 | Covered generative AI providers, above one million monthly users | Latent disclosures embedded in generated content, plus a publicly accessible detection tool offered at no cost |
| 1 Jan 2027 | Large online platforms | Detect provenance data on distributed content, surface it to users, let users inspect it, and refrain from stripping it |
| 1 Jan 2028 | Capture-device manufacturers | Offer latent disclosure in captured content, embedded by default |
A separate 1 January 2027 duty also lands on generative-AI hosting platforms — the sites and applications that make model weights or source code available for download. That one is a distribution-side gate rather than a content-side one, and it catches a different set of companies than the platform tier does.
Two threshold notes, because they get conflated. The provider tier attaches above one million monthly users. The large-online-platform tier uses a higher bar and a different definition entirely, covering public-facing social, file-sharing, mass-messaging and stand-alone search services that distribute content their users did not create — the numbers and definitions are broken out in AB 853's platform duties land in January 2027.
Notice what is absent from all three rows: individual creators, agencies, studios and in-house teams. No phase of this regime places a direct duty on the person making or publishing the content. That is genuinely unusual among the 2026 transparency rules and it is the first thing to establish before writing an internal policy.
The single idea underneath
Phase one creates the mark. Phase two preserves and displays it. Phase three extends marking to material that was never generated at all.
That third phase is the one people struggle to place, and it is the one that makes the other two mean something. Without camera-side marking, an absent signal is ambiguous: a file with no provenance data could be an ordinary recording from an ordinary camera, or it could be generated content whose marking was stripped somewhere between export and upload. The two cases are indistinguishable, which caps how much weight anyone can put on the absence of a mark.
Extend marking to capture devices and the ambiguity narrows. "No provenance data at all" stops being the default state of honest footage and starts being a fact about a file that someone can ask about. That is a slow-moving change with a 2028 date on it and a long device-replacement cycle behind it, but the architecture is the point: the statute is building a chain of custody from lens to feed, not three unrelated disclosure mandates.
Whether the chain survives contact with reality is a separate matter, and the honest answer is that it depends entirely on the middle of the pipeline — which is where anyone reading this actually operates.
What each phase gives a producer
Even without a direct duty, all three phases change what is available to you.
From phase one: verification you can actually run. The provider tier's second obligation is the interesting one for a working producer. Covered providers must offer a publicly accessible detection tool, free, that surfaces provenance data for content. The intended users include journalists and platforms. They also include you, checking your own exports. Until now, "does my finished file actually carry credentials" has been a question most people answered by trusting their editor's claim rather than by testing the file. That changes the audit from aspirational to routine — auditing your exports with detection tools is the workflow version.
From phase two: a duty not to strip. Platform re-encoding on ingest has been the single most reliable way for embedded metadata to disappear between a finished export and a published post. A statutory duty on covered platforms to refrain from stripping provenance data and digital signatures is a real engineering change at the ingest layer, even though the visible surface change is a small indicator on a post. For producers who have invested in a signed pipeline, this is the phase where that investment stops evaporating at upload.
From phase three: an eventual baseline. Longer-term, and mostly relevant if you shoot as well as generate.
The duty that is yours anyway
None of this is addressed to you. Two things still land on your side of the fence.
Your pipeline must not destroy what upstream tools embed. A content credential manifest is a hard binding to a file. Re-encode it, convert the format, screenshot it, or run it through a non-aware editing step and the manifest is invalidated or gone. Durable approaches layer an invisible watermark that lives in the pixels and a perceptual fingerprint alongside the manifest, precisely so something survives recompression — and heavy crop or deliberate removal still defeats the stack. The practical instruction is unchanged: make every step in the chain provenance-aware, or re-sign at export. Sign, strip, survive walks the failure points, and rebuilding your export step is the fix list.
Your contracts increasingly ask for it. Client agreements are starting to specify that deliverables carry provenance data and that the production chain preserves it. That is a contractual duty you take on voluntarily, enforceable long before any regulator is involved, and it is the mechanism most likely to make this regime bite for a small studio.
A note on where this sits relative to Europe: California's first phase and the EU's Article 50 both became operative on 2 August 2026, and they do different jobs. Article 50 tells you what to attach and who attaches it. California builds infrastructure for verifying what is attached. Two transparency laws, one start date covers the overlap for anyone selling into both markets, and the EU marking obligation has a runway that California's does not — the limits of that runway are in the AI Act marking grace period.
A diary, not a compliance programme
Given that no phase binds a producer directly, the sensible response is calendar hygiene rather than a policy document.
- Now. Establish what your current exports contain. Run a finished file through a provider's detection tool rather than trusting the export dialog.
- Before January 2027. Re-test the path that matters most — export, upload, download the published version, check what survived. The platform duty is meant to improve that result; you want a before-and-after.
- Through 2027. If you sign deliverables for clients, add the provenance check to your delivery QA rather than treating it as an occasional audit.
- 2028 and after. Relevant mainly if you shoot original footage. Worth knowing the direction rather than planning against it.
The thing to avoid is the opposite failure — building a compliance function for duties that were never yours. Three phases, three kinds of company, and none of them is you. What is yours is the middle of the chain, and that has been true since before any of these dates existed.
FAQ
Is it SB 942 or AB 853?
Both. SB 942 is the California AI Transparency Act; AB 853 is the amendment that moved the provider start date to 2 August 2026 and added the platform and capture-device phases. Cite the Act, and check the amended text.
Do these rules apply to me as an individual creator?
Not directly. Every phase attaches to a company type — large generative AI providers, large online platforms, generative-AI hosting platforms, and capture-device manufacturers. Your exposure comes through client contracts and through whether your pipeline preserves what upstream tools embed.
Does this apply outside California?
The statute is Californian, but the companies it binds operate globally and do not generally build separate pipelines per state. In practice the effects show up wherever those providers and platforms serve users.
Will provenance data actually survive to the viewer?
Not reliably today. Manifests break on re-encode, and platforms have historically re-encoded on ingest. The 1 January 2027 duty not to strip is aimed squarely at that, which is why it is the phase most worth watching if you care about the chain holding end to end.