California's New AI Disclosure Rules for AI-Generated Images, Video, and Audio Take Effect

·

The recent surge in the use of artificial intelligence (AI) to create synthetic media has prompted regulators at both federal and state levels to consider new approaches to enhance transparency and protect consumers. While efforts are underway at the federal level, California is taking a proactive stance by enacting comprehensive laws aimed at addressing the risks associated with AI-generated images, video, and audio.

The law targets transparency around AI-generated content, requiring providers of generative artificial intelligence (GenAI) systems to make visible and machine-readable disclosures as well as publicly accessible detection tools. Service providers offering users GenAI functionalities for creating or altering images, video, and audio should carefully assess the new compliance obligations and implementation timeline.

California’s initial wave of requirements became operative on August 2, marking a significant milestone in the state’s efforts to regulate AI-generated content. The law applies to GenAI services that have more than one million monthly visitors or users and are publicly accessible in California.

The act imposes rigorous disclosure and detection requirements on GenAI service providers operating in the state. Covered providers must implement both latent disclosures and a manifest disclosure option for AI-generated images, video, and audio, as well as make available a free public AI detection tool.

Latent Disclosure: Providers must embed a unique identifier that provides information about the name and version of the GenAI system used to create or alter content. This disclosure must be durable, consistent with widely accepted industry standards, and compatible with the service provider’s AI detection tool.

Manifest Disclosure Option: Covered providers must offer users the option to include a manifest disclosure in any image, video, or audio content created or altered by their GenAI system. The manifest disclosure must clearly identify the content as being AI-generated and be permanent or difficult to remove, if technically feasible.

AI Detection Tool: Providers must make available at no cost a publicly accessible tool that permits users to determine whether certain content was created or altered by its GenAI system. This tool must allow for content upload, URL submission, and application programming interface support, while ensuring the collection of user personal information is narrowly defined and not retained longer than necessary.

The law also requires providers to collect feedback from users to continually improve detection tools and their efficacy. Providers that license their GenAI systems to third parties must contractually require the licensee to maintain the system’s latent disclosure capability and revoke any noncompliant licenses within 96 hours of discovery.

California enacted CAITA in 2024, initially slated for January 1, 2026, but amended in 2025 to delay its operation until August 2, 2026. The law excludes products or services that are exclusively non-user-generated video game, television, streaming, movie, or interactive experiences.

The first set of CAITA requirements targets companies creating, coding, or producing GenAI systems with more than one million monthly users that are publicly accessible in California. By its own terms, the act does not apply to AI-generated textual content.

Additional requirements for GenAI system hosting platforms, large online platforms, and manufacturers of devices will be rolled out in 2027 and 2028. Noncompliance carries significant civil penalties, enforceable by state authorities, but there is no private right of action.

The law does not create a private right of action; instead, enforcement authority is vested in the attorney general and other state actors who may bring civil actions seeking penalties of $5,000 per violation against any covered provider. State authorities can also seek injunctive relief and recover attorney fees and costs.

CAITA represents a substantial shift in legal requirements for large-scale GenAI providers operating in California, mandating clear disclosures and robust provenance measures for AI-generated content. It sets a new bar for AI transparency compliance and will have significant operational, technical, and contractual impacts on affected businesses throughout the AI ecosystem.