- SB 1000 took immediate effect September 30, 2026 and deleted the former one-million-user minimum in the covered-provider definition.
- Covered providers must offer a free, provider-specific disclosure verification tool and include a qualifying latent disclosure to the extent technically feasible.
- AB 2713 makes defined large online platforms expose and preserve qualifying provenance beginning January 1, 2027; the platform definition retains a separate two-million-user test.
- Checking a final export with its provider verifier and inspecting a distributed download are practical production checks, not blanket statutory duties for every creator.
California's AI video provenance rules changed on September 30, 2026. Governor Gavin Newsom signed SB 1000 and AB 2713 that day, and both amended the California AI Transparency Act. The immediate change reaches the companies that make publicly accessible generative AI systems. A separate set of duties for large distributing platforms becomes operative on January 1, 2027. For a video team, the useful question is whether provenance can be checked after a file leaves the generator and moves through editing, export, and distribution.
The governor's signing announcement identifies both bills. The analysis below follows the chaptered SB 1000 and AB 2713 texts, rather than an earlier version of either bill.
What changed in the California AI Transparency Act?
The California AI Transparency Act now has a broader provider definition, a more specific verification tool, and a revised latent disclosure rule. SB 1000 took effect immediately when chaptered on September 30. AB 2713 revises what large online platforms must detect, display, expose for inspection, and avoid stripping, but its platform section becomes operative January 1, 2027. The duties depend on the actor, the content, and the technical qualifications in the text.
That split matters. A generated clip can pass through several services before a viewer sees it. The California AI Transparency Act places duties on a covered provider at creation or alteration and on a qualifying large platform at distribution. It does not make every editor, advertiser, or person who posts a video a covered provider just because they touch the file. Role classification needs the statutory definitions and the real workflow.

The one million user figure that appeared in the older covered-provider definition is gone. A different two million unique monthly user test remains in the definition of a large online platform. Treating those as the same threshold would misidentify who owes which duty.
SB 1000 expands provider coverage without making every tool equivalent
Under amended Business and Professions Code §22757.1(e), a covered provider is a person that creates, codes, or otherwise produces a generative AI system publicly accessible within California. The former requirement that the system have more than one million monthly visitors or users was deleted. SB 1000's legislative digest says so directly, and the enacted definition contains no replacement provider audience-size floor.
The system definition includes AI that generates synthetic text, images, video, or audio. The specific disclosure and verification provisions discussed here address image, video, audio, and combinations. The bill also excludes products that provide exclusively non-user-generated video games. Before January 1, 2029, the California AI Transparency Act excludes a GenAI system designed primarily as assistive technology, while separately prohibiting a covered provider from falsely claiming that designation. These are narrower statutory boundaries than a blanket claim that every AI system must watermark every output.
Another change in the California AI Transparency Act is that SB 1000 deletes the former rule that providers offer users an option to include a manifest disclosure. A manifest disclosure is the visible or audible kind a person can readily notice. The revised provider requirement centers on a latent disclosure, which is meant to persist in or with the media. That does not erase separate visible-disclosure laws. California's SB 1050 synthetic performer advertising rule is a distinct requirement for certain ads starting January 1, 2027.
What must a provider's verification tool do?
California AI Transparency Act §22757.2 replaces the old term “AI detection tool” with “disclosure verification tool.” A covered provider must make one available at no cost. It must let a user assess whether image, video, or audio content was created or altered, except by a minor modification, by that provider's GenAI system. This is provider-specific verification. It is not a promise that the tool can identify any AI-made file from any model.
The tool must return detected system provenance data. It must accept an uploaded file or a URL, and support invocation away from the provider's website through technology that includes an API. Public access can have reasonable limits to address demonstrable security or misuse risks. A provider may point users to a compliant third-party tool if that tool is compatible with its latent disclosures and clearly accessible through the GenAI system's interface.
Personal information has its own controls. The tool generally must not output personal information found in the content. The statute allows an exception if the person concerned gives express, clear consent after a specified warning that exported provenance becomes part of a file's permanent digital footprint. It also restricts collection, use, retention, and sharing of personal information from the user or processed content beyond what is strictly necessary, with a narrow opt-in contact exception. These details matter when a team tests a real customer clip rather than a synthetic sample.
For an exported video, a useful check is to run the provider's verification tool on the actual final file and keep the result with the production record. That is an optional workflow recommendation here, not a statutory duty imposed on every creator. Testing an intermediate render alone may miss what happened during the final encoding and upload.
What does the latent disclosure have to contain?
Under §22757.3(a), a covered provider must include a latent disclosure in qualifying generated or altered image, video, or audio content to the extent technically feasible. The content may carry the information directly or link to a permanent website. The required items are the provider's name, the GenAI system's name and version, the creation or alteration time and date, a unique identifier, and whether the system created or altered the content. From January 1, 2029, the disclosure must also state whether the system is designed primarily as assistive technology.
The disclosure must be permanent or extraordinarily difficult to remove or tamper with, compatible with the provider's verification tool, and compliant or interoperable with widely recognized industry standards. “Technically feasible” is part of the enacted obligation. It should not be rewritten as an unconditional guarantee that every downstream transformation preserves the data.
The California AI Transparency Act's “minor modification” definition includes brightness, contrast, or color changes; sharpening; saturation; resizing; scaling; cropping; file-format conversion; and audio denoising or background-noise removal. The provider's verification and latent-disclosure obligations exclude content changed only by such a minor modification. Whether a particular production step is only a minor modification depends on what the step actually does. Generating a new shot or substantially altering a voice is a different question from a straightforward resize.

The disclosure is evidence about a particular system's contribution. It is not a universal truth label. A valid provenance record may say which model altered a piece of content; it cannot, by itself, prove that every visual claim made in the video is accurate.
AB 2713 makes the distribution handoff visible
The California AI Transparency Act uses a separate definition for large online platforms. A large online platform is a public-facing social media, file-sharing, mass-messaging, or standalone search platform that distributes content to people who did not create or collaborate on it and exceeded two million unique monthly users during the preceding 12 months. Broadband internet access and telecommunications services are excluded. A private production workspace is not automatically a large online platform merely because it stores videos.
Beginning January 1, 2027, AB 2713's revised §22757.3.1 requires a qualifying large platform to detect whether provenance data is embedded, attached, or otherwise associated with distributed content. Its user interface must reliably indicate whether available system provenance data or a digital signature identifies the content as generated or substantially altered by GenAI, or captured by a device. It must make enough information conspicuous to identify authenticity, origin, or modification history, including whether provenance exists, the relevant system or device name if applicable, and whether digital signatures exist.
The platform must let a user inspect available system provenance data in an easily accessible way. It may display the data directly, link to a website or app that displays it, or allow a controlled download of provenance data. The law does not require the platform to maintain, display, or allow download of personal information. It also says the platform need not act on provenance or signatures outside compliance or interoperability with widely adopted specifications from an established standards body.
To the extent technically feasible, the platform must not knowingly strip system provenance data or a digital signature from content uploaded, distributed, or downloaded there. The word “knowingly” and the technical-feasibility qualification both matter. The provision is not a guarantee that every recoded preview, crop, or repost will retain all provenance. It does make preservation at the platform boundary a concrete issue for testing and policy.

This is the practical gap the two bills put into focus. Generation is only the first step. A video can be trimmed, recompressed, subtitled, uploaded, and downloaded before anyone inspects it. The chaptered text does not prescribe one test plan for all those transitions; a team can still measure where its own files lose a verifiable signal.
What should a video team check before release?
Start by naming the systems that created or altered the file, and note which one supplied any latent disclosure. Check whether the provider has a verification tool for its own output. Then run that tool against the final export, save the result, and repeat the check on a platform download where the distribution channel allows it. Record the filename and version so a passing result cannot be mistaken for a different cut.
If a delivery channel shows a provenance label, check what a viewer can actually inspect. A label that only appears in an upload dashboard does not answer what the audience sees. If a platform download drops an associated signature, capture the file and the step where it happened before drawing conclusions about the actor or the legal duty. Technical feasibility and standards compatibility are factual limits in these provisions, not details to skip.
The same workflow has a privacy side. Avoid putting a person's identity or private production metadata into provenance merely because a format can carry it. SB 1000's verification-tool and AB 2713's platform provisions both address personal information. Ask the responsible team to review a real export with the privacy and legal owners before standardizing a field set.
ngram lets teams plan a script and storyboard before rendering and export a finished video. For any video creation workflow, the final exported file is the useful checkpoint: verify the delivered file, then check what the publishing platform shows viewers.
If your AI video generator workflow involves generated footage or voice, our earlier AI video disclosure overview explains other disclosure regimes. For a separate look at verification technology, see the synthetic video detector analysis. Those pieces provide background; neither substitutes for the chaptered California text.
Enforcement and the limits of this analysis
The California AI Transparency Act, as amended by SB 1000, sets a general civil penalty of $5,000 per violation under §22757.4, with each day of violation by a covered provider, large online platform, or capture-device manufacturer treated as a discrete violation. That general section expressly excludes false claims that a system is primarily assistive technology. A separate temporary §22757.4.1 sets $50,000 per violation for that false-representation provision and expires January 1, 2029. These amounts are statutory penalty provisions, not an estimate of what any particular case will cost.
Provider licensing adds another conditional chain. A provider must notify a third-party licensee of its obligations when licensing the system. If the provider knows an identifiable licensee modified the licensed system into noncompliance, it has 72 hours to terminate authorization or notify the licensee. A notified licensee has 96 hours to fix the system or stop using or making it available and report back; a missing or adverse report then goes to the Attorney General. The same section says providers are not required to monitor or investigate licensee behavior to discover such modifications.
This is a reading of the chaptered statutes as of October 6, 2026, not legal advice. The application of a provision depends on the system, the parties' roles, the content, the export path, and later interpretation. The parts a creator can act on now are narrower and more concrete: preserve the exact final file, check it with the relevant provider's verifier, and inspect what the receiving platform shows.
Frequently asked questions
When did SB 1000 take effect?
SB 1000 was approved and chaptered September 30, 2026. Section 8 makes it an urgency statute with immediate effect. AB 2713 was also chaptered that day, but its revised large-platform section becomes operative January 1, 2027.
Does the California AI Transparency Act still require one million users for provider coverage?
No. SB 1000 removed the former more-than-one-million monthly visitor or user condition from the covered-provider definition. The law has a separate more-than-two-million unique monthly user test for the defined large online platforms.
Is a provider's verification tool a universal deepfake detector?
No. Section 22757.2 asks whether content was created or altered by that covered provider's GenAI system, with an exception for minor modification. A negative result from one provider's tool cannot establish that every other model had no role.
Does every AI-generated video need a visible label under SB 1000?
SB 1000 removed the prior option-to-include manifest-disclosure rule and revised the provider's latent-disclosure requirement. Separate laws may require visible notices in particular contexts. California's SB 1050, for example, addresses certain advertisements with prominent synthetic performers.
Do platforms have to preserve every metadata field?
AB 2713 addresses qualifying system provenance data and digital signatures, with standards, personal-information, knowing-stripping, and technical-feasibility qualifications. It does not say that every arbitrary metadata field must remain in every transformed copy.
Can a team test provenance after exporting video?
Yes. Under the California AI Transparency Act, the provider's tool must accept uploaded content or a URL, subject to the statute's permitted access limits. Checking the final export and a downloaded platform copy is a practical way to locate a break in the handoff. It is a recommended production check, not a general duty the statute places on every creator.
You just read it. Now watch it.
ngram turns this post into a short explainer video: scenes, voiceover, and motion graphics included.






