Field note · AI & Technology

The AI Watermark You'll Never See

California's AI Transparency Act went live Aug 2, 2026. The invisible AI marker is mandatory today; the visible label, and platform checks, aren't.

AP
Anuraag Paul
Co-Founder & Chief Sustainability Officer, Newtral
Published
August 7, 2026
Last reviewed
August 7, 2026
Read time
6 min · 1,031 words
Current

California's AI Transparency Act became operative on August 2, 2026, and most coverage frames it the way its short title suggests: a watermarking law for AI content, finally live. That's incomplete in a way that matters for anyone whose job is to know what changed.

The statute, read section by section, requires less than "AI content must now be labeled." Covered providers must mark their output invisibly - that part is mandatory. They must offer to mark it visibly - that part is optional, at the user's discretion. The detection tool the law requires each provider to build only reads that provider's own marks. Nothing operative yet obliges anyone else - the platforms where AI content circulates, or the devices that capture real photos and video - to check for a mark, preserve one, or supply one of their own. Those duties exist in the statute. They start in 2027 and 2028.

01

What became operative on August 2, 2026

The California AI Transparency Act - Senate Bill 942 (2024), delayed and expanded by Assembly Bill 853 (2025) - is codified at Business and Professions Code §22757 et seq.. Its default operative date, set by §22757.6, is August 2, 2026, pushed back from the original January 1, 2026 by AB 853.

The obligation that took effect on that date applies to a "covered provider": anyone who creates a generative AI system with more than one million monthly visitors or users accessible within California (§22757.1). Two duties attach to that provider as of August 2: build a free AI detection tool (§22757.2), and mark AI-generated image, video, and audio content in specific ways (§22757.3).

02

Mandatory and invisible, optional and visible

Section 22757.3 splits marking into two kinds, and the split runs the opposite direction from what "AI transparency" suggests. The visible label - content marked so a person looking at it would recognize it as AI-generated - is something a covered provider "shall offer the user the option to include." It does not have to be there. The invisible layer - a latent disclosure carrying the provider's name, the system's name and version, a timestamp, and a unique identifier - a provider "shall include": the statute does not condition that duty on anyone's choice, only on technical feasibility of the specific content it carries.

This is not a loophole; it is what the statute says, in as many words. But it means the obligation that's actually live today guarantees a hidden marker, not a human-visible one - and coverage that treats "AI content must now be labeled" as the headline result is describing the part of the statute that remains discretionary.

03

A detection tool that only detects itself

The detection tool requirement compounds this. Section 22757.2 requires a covered provider's tool to assess whether content "was created or altered by the covered provider's GenAI system" - its own system, not anyone else's. Section 22757.3 repeats the same scoping: the latent disclosure must be "detectable by the covered provider's AI detection tool." Nothing operative today requires a universal or cross-provider verification capability. If a person encounters AI-generated content of uncertain origin, the tool that can check for a mark is whichever provider's tool matches the system that made it - assuming they can identify which provider that might be in the first place.

04

The two dates that actually close the gap

The statute does contain provisions built to close that gap. They are just not live yet. Section 22757.3.1 requires "large online platforms" - social media, file-sharing, and search services with more than two million monthly users that distribute content their users didn't create - to detect standards-compliant provenance data, surface its availability to users, and refrain from stripping it "to the extent technically feasible." Section 22757.3.2 bars a GenAI hosting platform from knowingly distributing a system that skips the marks Section 22757.3 requires. Both become operative January 1, 2027 - seventeen months after the date most coverage is treating as the law's arrival. Section 22757.3.3, requiring capture-device manufacturers to embed authenticity markers in real photos and video by default, doesn't arrive until January 1, 2028.

That reading - that the statute currently guarantees a mark but not a means of checking it outside its own source - isn't something the Act says about itself; it follows from placing the operative-today sections next to the 2027 and 2028 ones and asking what capability exists on which date. Until those later dates, the architecture that would let an ordinary person, a platform, or a downstream business actually find, trust, or preserve a provenance mark generated somewhere else in the ecosystem simply isn't required to exist.

05

What a well-run AI operation does with eighteen months

For an organization that builds or licenses a generative AI system crossing California's one-million-user threshold, the compliance task due now is concrete: a working detection tool, and mandatory latent marking on generated media, engineered to survive re-encoding and platform transit "to the extent technically feasible" - a phrase with no enforcement action or judicial ruling yet on record to define its practical limits.

For an organization on the other side of this relationship - one that hosts, distributes, or consumes AI-generated content at scale - the honest reading of August 2, 2026 is that it changed less than it looks like. Content leaving covered providers' systems now carries a hidden marker more often than it did a week ago. Nothing yet obliges the platform in between, or the device on the other end, to do anything with it. An organization that needs to verify AI content's origin today - for moderation, for fraud prevention, for basic due diligence - cannot lean on this law to do that work until 2027 at the earliest, and not until 2028 for the capture-device side of the same problem. Building that capability sooner isn't a compliance obligation yet. For the next year and a half, it's a competitive one.


Source note: This article is based on the current text of the California AI Transparency Act, Business and Professions Code §22757 et seq. (as amended by AB 853, Stats. 2025, Ch. 674), read directly from the California Legislative Information website.

Noa · ESG compliance

Map your disclosures against AI & Technology.

Noa reads your disclosures, traces every number to its source, and flags what's missing.

Book a demo
AP
About the author
Anuraag Paul
Co-Founder & Chief Sustainability Officer, Newtral
View LinkedIn profile →