The California AI Transparency Act Is Now in Force: What Your Business Actually Needs to Do
The California AI Transparency Act became operative on August 2, 2026. Penalties run to $5,000 per violation, and each day of noncompliance counts as a separate violation.
Those numbers have generated a lot of alarming headlines. So let us be direct about something first.
If you run a small or mid-sized business in California, this law probably does not bind you directly. It still reaches you through your contracts and your software vendors. Knowing which applies to you decides whether you need a compliance program or just a contract review.
Here is the honest picture.

What the Act Requires
The Act, originally Senate Bill 942 and later amended by Assembly Bill 853, targets synthetic media. Lawmakers wanted consumers to know when they are looking at or listening to something a machine generated.
Covered providers carry three obligations.
Latent provenance disclosures
Covered systems must embed tamper-resistant metadata into AI-generated image, video, and audio content. That machine-readable data identifies four things: the provider, the system and version, the time of creation, and a unique identifier.
In practice, this means the C2PA standard, since the statute asks for methods consistent with widely accepted industry standards.
Manifest disclosures
Providers must also give users the option to include a visible or audible label marking content as AI-generated. Those labels need to be clear and conspicuous.
A free detection tool
Finally, covered providers must offer a publicly accessible tool, at no cost, letting anyone upload content and check whether that provider’s system created it.
Notice that all three obligations sit with the provider rather than the user. That distinction is the whole ballgame for most businesses.
Who Counts as a Covered Provider
A covered provider creates or produces a generative AI system with more than one million monthly visitors or users, publicly accessible in California.
Why most businesses are not covered
Consider a Los Angeles apparel company generating product images with a commercial AI tool. That company is a user of someone else’s system, not a covered provider.
Similarly, an agency producing video ads with licensed software is a licensee rather than a provider. Neither has a detection tool to build or a compliance program to run under this chapter.
The threshold is genuinely high. Systems with over a million monthly users are platforms, not internal business tools.
Where the line gets blurry
That said, some businesses do cross into provider territory without intending to.
You may qualify if you host and modify an open-weight model on your own infrastructure, offer it publicly, and reach consumer scale. The same goes for white-labeled products, where you package an underlying model and sell access under your own brand.
No registration or certification process exists. Providers self-assess against the threshold and implement accordingly. So the burden of classifying correctly sits with you.
Exemptions
The statute also carves out certain providers. Those whose products exclusively offer non-user-generated video games, television, streaming, movies, or interactive experiences fall outside it.
The $5,000 Penalty Structure
Enforcement comes through civil actions brought by the Attorney General, a city attorney, or county counsel.
Each violation carries a $5,000 penalty. Critically, the statute deems each day of noncompliance a discrete violation, so exposure accumulates rather than capping out.
What that math looks like
A covered provider operating thirty days without a compliant detection tool faces exposure starting around $150,000. Extend that to a year and the figure climbs past $1.8 million for a single violation type.
Prevailing plaintiffs can also recover reasonable attorney fees and costs, plus injunctive relief.
Keeping it in proportion
These penalties apply to covered providers. Because the threshold requires over a million monthly users, the companies genuinely exposed are substantial platforms rather than typical small businesses.
So if a vendor or consultant is quoting $5,000 per day at you while selling a compliance package, ask them first whether your company is actually a covered provider. Often the answer is no.
The Provision That Does Reach You
Here is the part most coverage skips, and it matters far more to agencies and small businesses than the headline penalty.
The Act imposes duties on third-party licensees, meaning companies that license a covered provider’s system.
The 96-hour revocation rule
Say a covered provider learns that a licensee has removed or disabled the latent disclosure capability. The provider must then revoke that licensee’s access within 96 hours.
Once revoked, the licensee must stop using the system immediately.
Think about what that means operationally. An agency running scripts that strip metadata from deliverables risks losing access to the tools its production pipeline depends on, with very little notice.
Enforcement against licensees
Additionally, enforcement reaches licensees directly. The Attorney General and city or county attorneys can sue licensees who keep using a system after revocation, seeking injunctive relief plus fees and costs.
So the risk for a small agency is not usually a $5,000 daily penalty. It is losing your tooling and facing an injunction, which can be worse for a business that depends on those workflows.
Contractual exposure
Beyond the statute, enterprise clients are rewriting vendor agreements. Large buyers increasingly demand representations that any AI tools used by contractors comply with applicable California law.
Sign a contract promising compliance without vetting your software stack, and you have assumed direct contractual liability regardless of whether the statute reaches you.
AB 2013: The Training Data Rule
SB 942 does not operate alone. Assembly Bill 2013 addresses a different question entirely.
AB 2013 requires developers of generative AI systems made publicly available to Californians to post documentation about their training data.
That summary must cover several points. Sources or owners of the datasets. Types of data included. Whether the data contains personal information or copyrighted works. Collection dates, and whether any cleaning or filtering happened.
Who this applies to
Again, the obligation falls on developers rather than users. If your business trains or substantially modifies a model and makes it publicly available, review this carefully.
If you license someone else’s model, your concern is whether that vendor complies, which is a diligence and contract question rather than a filing obligation.
Why it still matters commercially
Enterprise procurement teams now ask about training data provenance. A vendor who cannot answer creates risk for your deals even when neither of you has a statutory duty.
What Arrives in January 2027
AB 853 did more than delay the operative date. It added new categories of obligation that phase in later.
Large online platforms and generative AI hosting platforms take on duties beginning January 1, 2027. Capture device manufacturers follow on a later schedule.
Does your business host user-generated content or distribute AI models? Then that January date deserves a calendar entry now. Definitions and thresholds here are technical, so classify well before the deadline.
A Practical Compliance Checklist
Four steps, scaled to what your business actually does.
Classify yourself first. Are you an end user, a licensee, a developer, or a covered provider? Everything else depends on that answer, and most businesses land in the first two categories.
Audit your AI tools and workflows. Inventory every AI application you use or resell. Then check whether any production process strips metadata from files, because that is the behavior most likely to create real exposure.
Review your contracts in both directions. Confirm your vendors represent compliance with California requirements. Meanwhile, examine what you have promised clients about AI use and disclosure, and make sure you can actually deliver it.
Write an internal AI policy. Define approved tools, prohibit unvetted platforms, and set rules for preserving provenance metadata. A written policy also helps when a client asks how you handle this.
How Carbon Law Group Helps
Most businesses contacting us about this law do not need a compliance program. They need a clear answer about whether the statute applies to them, and a contract review to make sure they have not promised something they cannot verify.
Pankaj Raval and our team advise Los Angeles businesses on AI classification under SB 942 and AB 2013, vendor and client contract terms allocating compliance risk, internal AI governance policies, and responses when a client or regulator raises a question.
Our value-based pricing matters here. Working out whether a new statute applies to you should take one conversation, not a retainer.
Get the Classification Right First
The California AI Transparency Act is real law with real penalties. It is also narrower than the coverage suggests, and the businesses most at risk are not the ones receiving the most marketing about it.
If you build or host models publicly, get classified properly and build the required capabilities. If you license tools from someone else, preserve the metadata and read your contracts carefully.
Either way, start with the classification question rather than a compliance purchase. Contact Carbon Law Group at carbonlg.com and we will tell you which category you are in before you spend money on the wrong problem.
Take the next step book your consultation today, and safeguard your brand’s future.
Connect with us: Carbon Law Group
Visit our Website: carbonlg.com
[Pankaj on LinkedIn]
[Sahil on LinkedIn]