Editor’s Note: Provenance metadata crossed a threshold Aug. 2: California’s AI Transparency Act became operative the same day most of the EU AI Act’s Article 50 duties began applying, an alignment AB 853 engineered. Generative AI providers with over 1 million monthly visitors or users now owe California a free detection tool, embedded latent disclosures and a visible labeling option for AI-generated image, video and audio. Penalties are $5,000 per violation, with each continuing day a separate violation.
For cybersecurity, data privacy, regulatory compliance and eDiscovery professionals, the deeper story is downstream. The platform-level ban on knowingly stripping provenance data does not arrive until Jan. 1, 2027, capture devices follow in 2028, and the provenance disclosures these laws require at creation can be lost in workflows that convert, re-encode and stamp files. Authentication questions will reach courtrooms ahead of any AI-specific evidence rules; the federal Advisory Committee deferred both of its AI proposals in May.
Watch the Jan. 1, 2027, platform duties, the first California or EU enforcement move, this fall’s federal evidence mini-conference, the Justice Department’s posture toward state AI laws, and pending SB 1000, which would recast the act. Provenance is now a compliance surface. Treat it like one.
Content Assessment: California's AI Transparency Act arrives alongside Europe's Article 50
Information - 93%
Insight - 92%
Relevance - 92%
Objectivity - 93%
Authority - 91%
92%
Excellent
A short percentage-based assessment of the qualitative benefit expressed as a percentage of positive reception of the recent article from ComplexDiscovery OÜ titled, "California's AI Transparency Act arrives alongside Europe's Article 50."
Industry News – Artificial Intelligence Beat
California’s AI Transparency Act arrives alongside Europe’s Article 50
ComplexDiscovery OÜ Staff
On Aug. 2, the invisible tag inside an AI-generated image stopped being a courtesy. California’s AI Transparency Act became operative the same day most of the European Union’s Article 50 transparency duties began applying, and disclosure of machine-made media is now a legal obligation under two major regulatory regimes rather than an industry nicety.
The convergence was deliberate. When Gov. Gavin Newsom signed AB 853 on Oct. 13, 2025, the amendment moved the California act’s operative date from Jan. 1, 2026, to Aug. 2, 2026, a shift that attorneys A.J. Bahou and Eric J. Stocking of Bradley Arant Boult Cummings wrote was designed to put California’s obligations on the same schedule as the EU AI Act’s transparency rules. Sacramento and Brussels are now aligned on the same principal date, and covered companies face overlapping disclosure duties in both jurisdictions.
The two regimes differ in scope, exceptions and transition provisions, but neither stops at its border in practice. The California thresholds capture the major national tools, and the EU rules reach providers placing systems on the European market wherever they are based. Providers are unlikely to maintain separate provenance implementations state by state, which may position California’s requirements as a practical baseline.
What California now requires
The California AI Transparency Act, enacted as SB 942 in September 2024 and amended by AB 853, applies to covered providers: companies that create, code or otherwise produce a generative AI system with over 1 million monthly visitors or users that is publicly accessible in California. Three duties attached Aug. 2.
First, covered providers must offer a free AI detection tool that lets users assess whether image, video or audio content was created or altered by the provider’s own system. The tool must output any system provenance data it finds, support URL submission and an application programming interface, and avoid retaining users’ personal information beyond narrow feedback functions.
Second, providers must embed a latent disclosure in AI-generated image, video and audio content: provenance information carried in the content itself or its metadata, not easily perceived by a person but detectable by the provider’s AI detection tool. The disclosure must convey, to the extent technically feasible and reasonable, the provider’s name, the system’s name and version, the creation or alteration time and date, and a unique identifier. It must also be permanent or extraordinarily difficult to remove, again to the extent technically feasible. Third, providers must offer users the option of a manifest disclosure, a visible label identifying content as AI-generated. The provider-level detection and disclosure duties do not cover text; they apply to image, video and audio content. The act also exempts products that provide exclusively non-user-generated video game, television, streaming, movie or interactive experiences.
Violations carry a civil penalty of $5,000 per violation, and each day a violation continues counts as a discrete violation. Enforcement belongs to the California attorney general, city attorneys and county counsel; the statute creates no private right of action. A provider that licenses its system to a third party must contractually require the licensee to maintain disclosure capability and must revoke the license within 96 hours of discovering the licensee has modified the system to eliminate it.
State Sen. Josh Becker, who authored SB 942, said the law requires large generative AI companies both to identify AI-generated content and to provide the public a way to check it. Assemblymember Buffy Wicks, who authored AB 853, said the amendments aim to give people the information to understand where a piece of content comes from and to tell authentic material from fabricated.
The stripping ban arrives in stages
The provision most relevant to provenance survival at platform scale is not the one that just took effect. AB 853 added a prohibition on stripping provenance: a large online platform shall not knowingly strip any system provenance data or digital signature that complies with widely adopted specifications from an established standards-setting body, to the extent technically feasible, from content uploaded or distributed on the platform. The definition is specific: public-facing social media, file-sharing, mass messaging or stand-alone search services that distribute content to users who did not create or collaborate in creating it, and that exceeded 2 million unique monthly users during the preceding 12 months.
That duty does not begin until Jan. 1, 2027. The same date brings affirmative obligations: platforms must detect standards-compliant provenance data in content, disclose its availability to users and let users inspect it. Generative AI hosting platforms face their own Jan. 1, 2027, rule barring them from knowingly making available systems that omit the required disclosures. Capture device manufacturers follow on Jan. 1, 2028, when cameras, phones and voice recorders first produced for sale in California must offer users the option to include latent disclosures in captured content and must embed those disclosures by default.
The staged structure means the Aug. 2 milestone is a starting gun, not a finish line. Provider duties are live now; the platform-level stripping prohibition, the piece that would penalize provenance removal at scale, sits five months out for the platforms it binds. And nothing in the enacted chapter prohibits distributing tools designed to remove provenance data. That ban appeared in AB 3211, a broader Wicks provenance bill that died in the Legislature in August 2024, and it did not return.
Brussels kept Article 50 while delaying the high-risk regime
Europe’s half of the convergence survived a season of regulatory retrenchment, and it is now settled law. The digital omnibus regulation, adopted July 8 and in force since July 27, pushed application of the AI Act’s high-risk regime to Dec. 2, 2027, for Annex III systems and to Aug. 2, 2028, for high-risk systems embedded in regulated products. Article 50’s transparency obligations stayed put. Jones Walker attorneys wrote in July that those duties remained on schedule for Aug. 2, with one narrow reprieve: systems already on the market before that date have until Dec. 2, 2026, to implement the technical marking requirement.
Article 50 obliges providers to ensure synthetic audio, image, video and text outputs are marked in machine-readable form and detectable as artificially generated, so far as technically feasible, and obliges deployers to disclose deepfakes. The marking duty carves out systems performing assistive functions for standard editing that do not substantially alter the deployer’s input, and the deepfake duty bends for authorized law enforcement uses and for evidently artistic, creative, satirical or fictional works, where a limited disclosure suffices. Note the difference in reach: the EU marking duty covers synthetic text, and California’s provider duties do not. Violations can expose companies to fines of up to 15 million euros or 3 percent of worldwide annual turnover, whichever is higher, with lower maximums for small and medium-sized enterprises. ComplexDiscovery covered the EU side of this timeline when the European Parliament moved to pause the high-risk rules; the California side completes the pairing.
Early deployment signals are mixed, and deployment is not the same thing as compliance. Tech Times reported Aug. 2 that OpenAI, Google, Adobe, Meta and Stability AI had shipped content credentials under the Coalition for Content Provenance and Authenticity (C2PA) standard or Google DeepMind’s SynthID watermarks, and that it could identify neither content credentials nor a pixel watermark in Midjourney’s output as the law took effect. Two provenance-service publications reported the same gap: C2PA Viewer wrote in February that Midjourney output carried no C2PA credentials, and Lumethic reported in July that it found neither a C2PA manifest nor a known invisible watermark as of version 8. Midjourney is a Content Authenticity Initiative member. None of these observations settles the legal question: a deployed marker does not by itself satisfy the act’s detection tool and disclosure requirements, and a reported absence does not establish a violation.
Where the metadata dies
For cybersecurity, information governance and eDiscovery professionals, the operative question is not whether provenance metadata exists but whether it survives. C2PA’s Content Credentials, the framework at the center of these deployment moves, binds cryptographically signed manifests to a file. Neither statute mandates C2PA by name: California’s provider rules point to widely accepted industry standards, Article 50 anticipates relevant technical standards, and Content Credentials is a prominent implementation in practice. The design is tamper-evident rather than tamper-proof: an alteration that no tool records can invalidate the binding between an asset and its manifest, while a C2PA-aware application can preserve the provenance chain by adding a new signed manifest that records the edit. Tools without C2PA support may strip the credential, separate it from the file or simply fail to update it. The standard’s answer to lost metadata is durable credentials, soft bindings such as invisible watermarks or fingerprints that can help rediscover a credential after the metadata itself is gone.
Brandon Epstein, a technical forensics specialist at Magnet Forensics, wrote in an April analysis published by the forensics vendor that the provenance chain can break the moment a file passes through an application that lacks C2PA support, including messaging apps and social platforms that re-encode uploads or strip metadata. Epstein said the absence of credentials proves nothing on its own, because adoption remains limited, and advised examiners to weigh content credentials as one input among several rather than as a verdict.
That fragility runs straight through the discovery workflow. A native image collected from a custodian device may carry its latent disclosure intact through preservation and hashing, then lose it in processing, where conversion to review formats, re-encoding and endorsement stamping alter the file and can orphan or invalidate the manifest. The latent disclosure that survives collection may not survive processing, and a production set can arrive in court stripped of the very provenance disclosures two statutes now require at creation.
The governance work starts upstream of any lawsuit. Organizations already generate synthetic media at volume through marketing, communications and training functions, and every covered tool in that stack is now required to include disclosures in its output. Information governance teams should inventory which systems embed content credentials, decide where visible manifest labels belong, and confirm that retention and digital asset management systems preserve provenance fields rather than shedding them at ingestion. A provenance disclosure is a record about a record, and it belongs on the retention schedule.
The practical adjustments are within reach. Teams handling image, video and audio evidence should collect and preserve natives, validate any content credentials at intake and log the validation results, document every conversion applied in processing, ask processing vendors what happens to C2PA manifests at ingestion and conversion, and negotiate ESI protocol language that treats provenance fields as metadata to be preserved and produced. Requesting parties should ask for natives of synthetic media and for processing documentation. And counsel on either side can now run disputed exhibits through the detection tools the California act mandates, remembering their limit: each tool assesses only whether content came from that provider’s own system.
The authentication fight arrives before the rules do
The federal evidence framework is not racing to keep up; it is deliberately holding still. At its May 7 meeting, the Advisory Committee on Evidence Rules deferred action on proposed Rule 707, which would apply expert-reliability standards to AI-generated evidence offered without a testifying expert, and on a draft Rule 901(c) burden-shifting framework for deepfake challenges, opting to convene a mini-conference with technologists and litigators this fall. A Federal Judicial Center survey informing the deepfake deliberations found that just 15 of 931 responding judges had encountered a deepfake challenge to audiovisual evidence.
The result is a gap litigators will live in for years: provenance obligations are now statutory in California and the European Union, while courts continue to authenticate synthetic media under the existing framework of Rules 901 and 902. Where it survives and validates, provenance metadata can anchor an authentication showing under Rule 901. It does not, standing alone, make an exhibit self-authenticating, establish a chain of custody or prove that what the content depicts actually occurred; the C2PA coalition itself cautions that provenance alone cannot establish whether content is true. But its absence, where processing destroyed a disclosure that existed at creation, will invite explanation.
Watch two dates and three developing issues from here. On Jan. 1, 2027, California’s platform duties and stripping prohibition activate. On Jan. 1, 2028, provenance moves into capture hardware.
The issues will move on their own schedules. The first enforcement action, by a California public enforcer or the first EU fine under Article 50, will show whether these statutes have teeth. In Washington, the Justice Department moved in April to intervene in xAI’s suit against Colorado’s algorithmic discrimination law; the department’s AI litigation task force was created under a December executive order directing challenges to state AI laws, and whether California’s transparency regime draws a similar challenge is an open question. In Sacramento, SB 1000, ordered to third reading in the Assembly in July, would recast the act again: it would delete the covered provider user threshold, drop the manifest disclosure option and take effect immediately as an urgency statute if enacted.
When a latent disclosure that existed at creation is missing from the exhibit on the screen, which side of your next authenticity dispute will that absence favor?

News sources
- Bill Text, AB 853, California AI Transparency Act (California Legislature via LegiScan)
- California Business and Professions Code, Division 8, Chapter 25 (Justia)
- New California AI Disclosure Rules Become Operative (Morgan Lewis)
- Key Deadlines Under the California AI Transparency Act (National Law Review, Bradley Arant Boult Cummings)
- Yes, August 2 Still Matters: The EU Approved a High-Risk AI Delay, but Most Transparency Obligations Remain (Jones Walker)
- EU AI Act Omnibus Agreement: Postponed High-Risk Deadlines and Other Key Changes (Gibson Dunn)
- Article 50, EU Artificial Intelligence Act (AI Act Explorer)
- Regulation (EU) 2026/1744, Digital Omnibus on AI (EUR-Lex)
- Governor Newsom Signs Bills to Crack Down on Sexually Explicit Deepfakes, Require AI Watermarking (Office of Gov. Gavin Newsom)
- California AI Transparency Act Operative: Midjourney Has No Watermark, Fines Start Today (Tech Times)
- C2PA and Media Authentication: What You Need to Know (Magnet Forensics)
- Which AI Image Generators Support C2PA? (C2PA Viewer)
- Which AI Image Generators Mark Their Output, and How (Lumethic)
- Report of the Advisory Committee on Evidence Rules, May 2026 (U.S. Courts)
- Federal Judges Set Bar for Deepfake Evidence Challenges (Esquire Deposition Solutions)
- Justice Department Intervenes in xAI Lawsuit Challenging Colorado’s Algorithmic Discrimination Law (U.S. Department of Justice)
- SB 1000: California AI Transparency Act, Bill Status (Digital Democracy, CalMatters)
- C2PA Specification 2.4 Explainer (Coalition for Content Provenance and Authenticity)
- Parliament Hits Pause on High-Risk AI Rules and Bans Nudifier Apps (ComplexDiscovery)
Assisted by GAI and LLM Technologies
Additional reading
- Federal magistrate judge treats LinkedIn’s Relativity aiR workflow as TAR
- One benchmark, three directions: 2026 legal rates rise, flatten and fall at once
- Confidence cools, commitment holds: full results from the 1H 2026 eDiscovery Business Confidence Survey
- Complete look: ComplexDiscovery OÜ’s 2025 to 2030 eDiscovery market size mashup
- The workstream of eDiscovery: Considering processes and tasks
- Andrew Haslam’s eDisclosure Systems Buyers Guide at 14: What the 1H 2026 update reveals
- A Complete Analysis of the Winter 2026 eDiscovery Pricing Survey
- The M&A Risk of Confusing Market Velocity with Marketing Capability
Source: ComplexDiscovery OÜ

ComplexDiscovery’s mission is to enable clarity for complex decisions by providing independent, data‑driven reporting, research, and commentary that make digital risk, legal technology, and regulatory change more understandable for practitioners, policymakers, and business leaders.



























