California AI Transparency Act Operative: Midjourney Has No Watermark, Fines Start Today
Resumo
Califórnia começou a aplicar lei que exige de sistemas de IA com mais de 1 milhão de usuários a incorporação de dados de proveniência legíveis por máquina, ferramenta de detecção gratuita e rótulos visíveis; Midjourney não cumpre a lei e enfrenta multas de até $5 mil por violação por dia.

Every AI image, video, or audio system with more than one million monthly users in California is now legally required to embed machine-readable provenance data in its outputs, offer a free public detection tool, and let users add visible AI labels to generated content — or face civil penalties starting at $5,000 per violation per day. California's AI Transparency Act, Senate Bill 942 as amended by Assembly Bill 853, became operative today, August 2, 2026, making California the first US state to enforce a comprehensive AI content provenance mandate. Midjourney, one of the most widely used AI image generators in the country, ships no C2PA content credentials and no known pixel watermark as of today — a compliance posture that appears to put it squarely in scope of a law now being enforced by the California Attorney General and, for the first time in US AI regulation, city attorneys and county counsel with fee-shifting authority.
One complication: a pending urgency bill, SB 1000, passed the California Senate 33-1 in May and was ordered to Assembly third reading on July 2. As an urgency statute, it would take effect immediately upon Governor Newsom's signature. As of the last available legislative status, it had not been signed — but its provisions would remove the one-million-user threshold, delete the manifest-disclosure requirement, and revise the detection-tool rules. SB 1000's status should be verified before any compliance action is finalized.
What SB 942 Requires of Covered AI Providers
The law uses the term "covered provider" to describe any operator of a publicly accessible generative AI system that has more than one million monthly visitors or users in California per the California AI Transparency Act text. That threshold attaches to the specific system, not to the parent company's total user base. Exact definitions of how to count monthly users and what "publicly accessible in California" means are left to provider interpretation — the legislature named no technical standard and issued no AG enforcement advisory as of this writing.
Covered providers must satisfy three operative requirements beginning today.
The first is a free public detection tool, accessible without account creation, that allows any person to check whether a piece of image, video, or audio content was generated or substantially altered by that provider's AI system under BPC § 22757.2(a). The tool must support both file uploads and URL submissions, and must provide an API for programmatic access. Providers cannot collect or retain personal information from users who submit content for detection. OpenAI's openai.com/verify tool, launched in May 2026 alongside its C2PA and SynthID dual-layer rollout, satisfies this requirement for ChatGPT outputs — though it is limited to images generated by OpenAI's own systems and cannot verify images from other generators.
The second requirement is a manifest disclosure: under BPC § 22757.3(a), providers must give users the option to add a visible, human-readable "AI-generated" label to content they produce, in a format that is permanent or extraordinarily difficult to remove.
The third is a latent disclosure: under BPC § 22757.3(b), every AI-generated or substantially altered image, video, or audio output must carry embedded machine-readable provenance metadata, automatically and by default, identifying the provider name, the system name and version, and the creation timestamp. The statute instructs providers to use "widely accepted industry standards" — language that points to C2PA without naming it, consistent with the law's deliberate alignment with EU AI Act Article 50, which also references C2PA as the reference implementation for machine-readable provenance.
Text-only outputs are excluded from all three requirements.
Enforcement Architecture: Why City Attorneys Matter
The California Attorney General holds primary enforcement authority under SB 942 — consistent with California's aggressive AI enforcement posture, which AG Rob Bonta has described as building an "AI oversight, accountability and regulation program" amid federal regulatory inaction. What makes SB 942's structure distinctive within US AI regulation is the expansion of standing to city attorneys and county counsel, who may also bring civil actions under BPC § 22757.5. A fee-shifting provision requires a prevailing plaintiff to recover attorney costs — lowering the financial barrier for local prosecutors to pursue cases against well-resourced companies without budget for expensive AI enforcement campaigns.
The penalty structure is designed to accumulate quickly. Each deficiency counts as a violation, and each day of non-compliance is a discrete, separate violation per the Vorp Labs compliance checklist. A covered provider that fails to deploy a compliant detection tool for 30 days faces potential exposure of $150,000 from that single deficiency alone, before attorney's fees. Unlike California's CCPA enforcement regime, SB 942 includes no general notice-and-cure period. The 96-hour licensee revocation deadline is a substantive compliance requirement, not a cure window.
That 96-hour rule is the statute's most operationally demanding provision. If a covered provider discovers that a third-party licensee has modified a licensed AI system in a way that makes compliance with the disclosure requirements technically impossible, the provider must revoke that license within 96 hours under BPC § 22757.3(c)(2). The licensee must then immediately cease using the system. This provision is directed at the open-source model ecosystem: it prevents providers from insulating themselves from non-compliance by licensing their technology to downstream operators who strip the provenance requirements. Covered providers will need audit rights in their license agreements and technical monitoring capabilities to detect downstream stripping — or they face enforcement exposure for their licensees' failures.
Midjourney: Compliant Member, Non-Compliant Tool
The most prominent compliance gap as SB 942 enters enforcement is Midjourney. The company has been a member of the Content Authenticity Initiative — the industry body that developed and promotes the C2PA standard — since 2023, according to Lumethic's July 2026 analysis. It has not shipped an implementation.
As of July 2026, images generated through Midjourney's Discord interface or web platform carry no C2PA content credentials and no documented imperceptible watermark, per C2PA Viewer's tracking of AI generator support. An aibuzz.blog watermarking gap analysis published June 2026 attributed Midjourney's posture to its business model: a consumer subscription service built around Discord, where feature development has historically taken priority over provenance infrastructure. Midjourney has not made a public statement about its SB 942 compliance plans or a C2PA implementation timeline.
Whether Midjourney's user base exceeds the one-million-monthly-user threshold in California is not publicly disclosed. Given that the company claimed more than 20 million registered users in 2023, the probability of clearing that bar seems high. If it does, it is currently operating without the free detection tool, the latent provenance data, or the user-facing disclosure mechanism the law requires — making it the highest-profile provider exposed to enforcement action on the law's first day.
The Watermark That Doesn't Survive Instagram
The primary technical implementation for SB 942's latent disclosure requirement is C2PA — the Coalition for Content Provenance and Authenticity standard, co-developed by Adobe, Arm, BBC, Intel, Microsoft, and Truepic, and now embedded in more than 6,000 member organizations' products. A C2PA content credential is a cryptographically signed manifest embedded in a file's metadata, recording which AI system generated the content, when, and with what tools.
The documented limitation is structural: C2PA metadata is stripped when a file is screenshotted, re-uploaded to Instagram, reposted on X (formerly Twitter), or passed through WhatsApp, as detailed in prior TechTimes coverage of the EU disclosure mandate. The manifest that proves the image is AI-generated survives creation, survives download — and then disappears when the image enters the social web. A Presenc AI watermarking adoption study published in May 2026 found that while roughly 75-85 percent of AI-generated images from major platforms carry some provenance signal at the point of generation, only 30-50 percent of those images still carry provenance when distributed online.
SB 942 addresses this with two mechanisms. The "to the extent technically feasible and reasonable" language gives providers interpretive flexibility on the latent disclosure requirement. More significantly, the law's 2027 phase adds an obligation for large online platforms — social media networks, search engines, and mass-messaging services with more than two million unique monthly users — to detect compliant provenance data, surface it to users, and explicitly prohibit knowingly stripping it, per BPC § 22757.3.1. That provision does not take effect until January 1, 2027, leaving today's enforcement covering only the provider side of the equation. Instagram, X, and WhatsApp are not yet required under California law to preserve what they currently strip.
The technical picture is more nuanced than a simple failure, however. The C2PA 2.1 specification, released in 2024, added formal watermarking support, enabling what the standard calls "durable credentials" — a layered approach that combines hard binding (cryptographic hash), soft binding (pixel-level watermark embedded in the image itself), and cloud-based manifest storage accessible even when both embedded layers are removed. A provider that implements the full durable approach — C2PA metadata plus a pixel watermark like Google's SynthID, backed by server-side hash logging — can recover provenance data even after the metadata has been stripped by a social platform. The operative enforcement question for SB 942 is not whether this architecture exists, but whether the statute's "technically feasible and reasonable" standard requires it. The California AG has not published guidance on this question.
What SB 1000 Could Change — Immediately
A pending urgency bill introduces meaningful legal uncertainty into what would otherwise be a straightforward operative-date story.
SB 1000, authored by Senator Josh Becker — the same legislator who wrote SB 942 — passed the California Senate 33-1 in May 2026 and was ordered to Assembly third reading on July 2, 2026, per LegiScan's bill status tracker. As an urgency statute, it takes effect immediately upon the Governor's signature, without waiting for a January 1 operative date.
The bill's June 9, 2026 version would make three material changes to SB 942: it would remove the one-million-user coverage threshold; it would delete the manifest-disclosure duty (the requirement to let users add visible AI labels); and it would revise the detection-tool, privacy, latent-disclosure, and licensing rules, as documented by Vorp Labs' legislative alert. Any company that relied on the one-million-user threshold to determine it is not covered would need to reassess immediately if SB 1000 passes. Any compliance program built around the manifest-disclosure requirement would need to be restructured.
As of July 11, 2026, the most recent date on which Vorp Labs' compliance checklist was confirmed against the statute, SB 1000 had not been signed. Its current legislative status should be verified through the California Legislative Information portal before any compliance decisions are finalized.
The Synchronized Transatlantic Standard
Today's date was not chosen by accident. AB 853, signed by Governor Newsom on October 13, 2025 as Chapter 674 of the Statutes of 2025, pushed the SB 942 operative date from January 1, 2026 to August 2, 2026 specifically to align with the EU AI Act's Article 50 enforcement schedule. August 2 is the date on which Article 50 of the EU AI Act took full enforcement effect for AI-generated content across all 27 EU member states — simultaneously imposing a virtually identical content provenance mandate on the same set of global AI providers.
The convergence creates what amounts to a transatlantic watermarking standard: providers that build C2PA plus imperceptible-watermarking infrastructure for EU compliance simultaneously satisfy California's latent disclosure requirement, and vice versa. For global AI companies, the dual enforcement creates one compliance infrastructure problem rather than two parallel ones. For regulators, it creates a compounding deterrent: a provider that ignores both the EU's Article 50 (which can reach €15 million, approximately $17.3 million, or 3 percent of global annual turnover, whichever is higher, per William Fry's analysis) and California's $5,000-per-day structure faces exposure from both directions simultaneously.
The EU's enforcement architecture differs meaningfully from California's. Article 50 violations in the EU are investigated by national market surveillance authorities across 27 member states, with the European AI Office holding supervisory authority over general-purpose AI model providers. California's structure — AG plus city attorneys with fee-shifting — is more decentralized and, arguably, more accessible to smaller local enforcement offices with specific community concerns about AI deepfakes.
Three More Phases Still to Come
Today's enforcement covers covered generative AI providers. SB 942 as amended by AB 853 schedules two additional implementation phases that will significantly expand the law's reach.
Beginning January 1, 2027, large online platforms — social media networks, general-purpose search engines, and mass-messaging platforms with more than two million unique monthly users — must detect C2PA-compatible provenance data in content distributed on their services, surface that provenance to users, and prohibit knowingly stripping compliant provenance signals from content they distribute per BPC § 22757.3.1. This phase is the structural fix for the Instagram/X/WhatsApp stripping problem: it will impose legal liability on platforms that strip rather than simply leaving the problem to providers to work around. Hosting platforms — services that make generative AI system source code or model weights available to developers — must also, beginning January 1, 2027, refuse to host systems that do not embed the required disclosures.
Beginning January 1, 2028, manufacturers of capture devices — cameras, mobile phones with cameras or microphones, and voice recorders — first produced for sale in California on or after that date must offer a user-accessible option to embed latent provenance disclosures carrying the manufacturer name, device name and version, and creation timestamp per BPC § 22757.3.3. This provision extends SB 942's provenance architecture to authentic human-captured content, not just AI-generated synthetic media — Sony, Nikon, Canon, and Samsung all already ship C2PA signing capability in 2026 camera models, suggesting the device-manufacturer phase will find substantial prior compliance infrastructure already in place.
California's broader AI regulatory ecosystem provides additional context. AB 2013, the Generative AI Training Data Transparency Act, requires generative AI developers to publish summaries of training datasets and has been in effect since January 1, 2026. SB 53, the Transparency in Frontier AI Act — California's first law directly targeting frontier AI model developers — also took effect January 1, 2026, requiring developers of the largest models to publish safety frameworks, report critical safety incidents, and maintain whistleblower protections, with penalties up to $1 million per violation. xAI, Elon Musk's AI company, has challenged the constitutionality of AB 2013 in federal court; a California federal court denied its motion for a preliminary injunction on March 5, 2026, and the case continues in the Ninth Circuit.
What This Means for AI Users Today
For people who use AI tools to generate images, video, or audio, the most immediate practical change is that content generated by compliant covered providers now carries embedded provenance signals. If you generate an image through ChatGPT or Google's AI products, that image carries both a C2PA cryptographic manifest and a SynthID pixel watermark. Anyone with access to openai.com/verify or Google's C2PA and SynthID detection interface can determine whether the image came from those providers' tools, regardless of whether you chose to disclose it.
What those signals do not tell is who specifically ran the prompt. Neither C2PA nor SynthID embeds individual account or identity information in the outputs — the attribution is at the platform level, not the user level. An image confirmed as AI-generated is not evidence of who generated it.
For people who work in environments where undisclosed AI-generated content creates professional or legal risk — newsrooms, academic institutions, legal proceedings, government procurement — the operative date means that the detection infrastructure now exists, and its use is becoming standard. Whether the absence of a provenance signal proves an image is not AI-generated is a different question: images from non-compliant generators like Midjourney, or from self-hosted open-weight models, carry no signal at all. Missing credentials prove only that the content was not generated by a compliant provider, not that it was not AI-generated.
Frequently Asked Questions
Which AI companies must comply with California's AI Transparency Act today?
Any company that operates a publicly accessible generative AI system with more than one million monthly visitors or users in California. That threshold applies per system, not per company. OpenAI, Google, Adobe, Meta, ElevenLabs, and Stability AI have all deployed C2PA content credentials, SynthID watermarks, or both. Midjourney, despite being a Content Authenticity Initiative member since 2023, has not deployed either as of today. The law does not exclude open-source developers, nonprofits, or free products — if the system meets the threshold, it is covered.
Does compliance with the watermarking law mean the watermark actually reaches viewers?
Not reliably under today's enforcement scope. C2PA metadata — the machine-readable provenance signal the law requires — is stripped when images are uploaded to Instagram, reposted on X, or sent through WhatsApp. A provider can be fully compliant at the point of generation and have its required metadata systematically destroyed before the image reaches most viewers. The January 1, 2027 phase of the law will require large platforms to detect, preserve, and surface provenance data rather than strip it — but that obligation does not begin today. The C2PA 2.1 specification's "durable credentials" architecture (combining cryptographic metadata, pixel-level watermarking, and server-side hash storage) can partially recover provenance after stripping, but whether SB 942's "technically feasible and reasonable" language requires that full layered approach remains an open question the California AG has not yet addressed.
What is the penalty for violating SB 942, and who can enforce it?
Civil penalties of $5,000 per violation, with each day of non-compliance treated as a separate violation. A provider that fails to offer a compliant detection tool for 30 consecutive days faces potential exposure of $150,000 from that deficiency alone, before attorney's fees. The California Attorney General, any city attorney, and any county counsel can bring enforcement actions, and prevailing plaintiffs recover their attorney's costs. There is no general notice-and-cure period. The AG has not published SB 942-specific enforcement guidance as of today.
Could SB 942's requirements change before they're fully tested in enforcement?
Yes. A pending urgency bill, SB 1000, passed the California Senate 33-1 in May 2026 and was awaiting an Assembly floor vote as of July 2, 2026. If signed by Governor Newsom, it would take effect immediately and would remove the one-million-user coverage threshold, delete the manifest-disclosure requirement, and revise the detection-tool and latent-disclosure rules. Any compliance planning built on the current text of SB 942 should verify SB 1000's current status through the California Legislative Information portal before finalizing its approach.
ⓒ 2026 TECHTIMES.com All rights reserved. Do not reproduce without permission.