← All posts / Policy

California's AI Transparency Law Is Live — and Nearly Half of Major AI Companies Are Out of Compliance

The first independent audit of California's SB 942 AI Transparency Act found that only 7 of 13 major generative AI companies published legally required detection tools — and even compliant tools struggle to survive basic edits.

California's AI Transparency Law Is Live — and Nearly Half of Major AI Companies Are Out of Compliance

On August 2, 2026, California’s AI Transparency Act — SB 942, as amended by AB 853 — quietly became one of the first AI transparency laws in the world with real teeth. Any generative AI provider with more than 1 million monthly users must now mark its photo, audio, and video outputs with machine-readable metadata and publish a publicly available AI detector so anyone can check whether a piece of content came from that company’s technology. A parallel transparency regime took effect the same day in the European Union.

Two weeks later, we have the first independent scorecard — and it is not flattering. An investigation by the media outlet Indicator, conducted with the human-rights organization WITNESS and first reported widely by KQED on August 17, tested all 13 major companies covered by the law. Only seven had a working, publicly available detection tool. An eighth — AI music company Suno — shared its tool with KQED and said it had released it at the beginning of August in compliance with the law. The remaining five: nothing.

What the law actually requires

SB 942, originally passed in 2024 and amended by AB 853 in 2025, targets what legislators call “covered providers” — generative AI services with over 1 million monthly users. Its obligations are straightforward in outline:

  • Provenance metadata. AI-generated or AI-edited images, video, and audio must carry an invisible, machine-readable marker identifying the content’s synthetic origin.
  • A public detector. Each provider must offer a free tool that lets anyone — a journalist, a teacher, an election official, a teenager worried about a deepfake — upload a file and find out whether it was created or modified by that provider’s AI.
  • Enforcement. Violations carry civil penalties of $5,000 per violation per day, enforced by the California Attorney General. When KQED asked whether any fines had been issued yet, the AG’s office said it could not comment on potential or ongoing investigations.

Notably, the law covers images, video, and audio — not text. The EU’s parallel rules go further, requiring detection for AI-generated text as well, which is one reason Anthropic (whose models do not produce photorealistic images or video) recently committed to watermarking text across its new Claude models.

The compliance scorecard

The Indicator/WITNESS team — Alexios Mantzarlis, Bruna Santos, and Jacobo Castellanos — hunted for detector tools on company websites and followed up with each company to confirm. Their census covered Google, Meta, Microsoft, OpenAI, Adobe, xAI (Grok), Midjourney, Mistral, HeyGen, Synthesia, ElevenLabs, Suno, and TikTok. Together, these services draw roughly 10.6 billion monthly visits.

Compliant (7 + 1): Adobe, ElevenLabs, Google, Meta, TikTok, OpenAI, and Microsoft — with Microsoft receiving credit for an inspection tool buried inside Microsoft Designer, its graphic design product — plus Suno, which produced a tool after the initial report and told KQED it had launched in early August.

Non-compliant (5): HeyGen, Midjourney, Mistral, Synthesia, and xAI did not have tools available and did not respond to KQED’s requests for comment. Synthesia, a UK-based AI video platform, said it has embedded the required metadata but is “still seeking clarification on a few technical points,” arguing that as a business-to-business platform its risk profile differs from consumer apps. That argument may matter in Sacramento: the law’s “1 million users” threshold was written with consumer products in mind, and enterprise-only providers are already lobbying for a carve-out.

The detectors that exist aren’t good enough

Compliance, it turns out, is only the first problem. The Indicator/WITNESS team ran 243 tests across the seven available detectors using 85 files — original and edited outputs from each company’s own generator, files from rival AI tools, and non-synthetic files, some deliberately tampered with to carry forged AI credentials.

The results, in their words, “need work”:

  • Every detector could recognize its own unedited content. That is the minimum bar, and everyone cleared it.
  • Once files were edited — cropped, resized, re-encoded — performance collapsed. Only Google’s SynthID and OpenAI’s detector correctly identified their own output even after tampering attempts.
  • Only Adobe and Microsoft could reliably flag content generated by other companies’ tools (more than half the time), and the report notes this is unsurprising: the law does not require cross-provider detection, so a Midjourney image will sail through OpenAI’s checker looking “organic.”
  • Three tools impose aggressive rate limits. OpenAI’s verification tool blocked the researchers after as few as 7 tests in one session; Google and Meta capped usage at 10 to 15 checks per day — hobbling exactly the kind of systematic verification the law was meant to enable.

OpenAI, for its part, acknowledged the structural weakness: “Metadata is not foolproof. It can be stripped, lost through uploads and downloads, or broken by transformations like file format changes, resizing, or screenshots.”

Why this matters beyond California

Three dynamics make this story bigger than one state’s scorecard.

First, the enforcement question is now live. Nearly half of covered companies are openly non-compliant two weeks in, and the AG’s office is silent on enforcement. If California doesn’t act, SB 942 joins the long list of tech rules honored mainly in the breach — and the EU, whose transparency rules took effect the same day, is watching the same companies.

Second, the stage two mandate is coming. State Sen. Josh Becker told KQED that starting in January, large online platforms — social media companies and search engines — will be required to detect AI content themselves and let users inspect it. That shifts the burden downstream, and if the underlying detectors are unreliable and rate-limited, platforms will inherit an impossible task. Meta’s experience is a preview: its “AI info” labels have already been flagging Canva background-removal edits this summer, irritating marketers and illustrating how blunt the labels can be.

Third, detection is asymmetric warfare. Metadata survives only until the first screenshot. The report’s forged-credential tests show detectors can be fooled not just by stripping markers but by adding fake ones. As one of this year’s persistent research themes has shown, watermark-based transparency regimes face a basic fragility problem — which is why Anthropic’s move to bake watermarks into the token-generation process itself, rather than bolting them on afterward, is being watched closely as a possible sturdier model.

What to watch

  1. AG enforcement. The first $5,000-per-day fine against a Midjourney or xAI would transform compliance incentives overnight. Silence through September would send the opposite signal.
  2. The Suno pattern. A company releasing a tool only after a reporter calls is compliance by press inquiry. Expect more of this — and expect the AG to take a dim view of it if enforcement begins.
  3. Cross-detection standards. The law’s biggest structural gap is that detectors only need to recognize their own provider’s output. A C2PA-style shared provenance standard, or an amendment requiring interoperability, is the obvious fix — and the one the industry will resist hardest.
  4. January’s platform mandate. When social platforms must run detection at upload scale, the rate limits and accuracy problems documented this month stop being a researcher inconvenience and become an infrastructure failure.

For now, the honest summary of the world’s first AI transparency scorecard: the law works well enough to expose who is ignoring it, and the tools work well enough to show why ignoring them is still possible. That’s progress — of the most provisional kind.