On September 2, I published a piece that spent several hundred words being irritated at a number.
The number was 1,000,000 — the monthly-user floor in California's AI Transparency Act, below which a generative-AI company owed the state no provenance duties at all. I called it the clause that exempted exactly the content most likely to fool you, because the tools making convincing fakes are rarely the ones with a million people logging in every month.
Near the end of that piece I wrote a sentence I would now like back. Senate Bill 1000, I noted in passing, would delete the user threshold from the covered-provider definition and rename the detection tool a disclosure verification tool. Then the piece moved on to its ending. The whole story was sitting in that one clause, and it went unread.
So: a correction, and then an argument. On September 30, 2026, Governor Newsom signed the bill that deletes my number, and the sentence doing the deleting does two other things in the same breath. One is that rename, which reads like housekeeping and isn't. The other removes the only part of this law an ordinary person could ever have seen with their own eyes.
What one sentence in the official digest actually does
First, the status, because this piece had a clock on it. Governor Newsom signed SB 1000 on September 30, 2026, the last day he had to sign or veto what was still on his desk. It got there having passed without a single no vote in either house on the final rounds — 72-0 on the Assembly floor on August 25, 2026, then 39-0 on Senate concurrence two days later — and was presented to the Governor at 3 p.m. on September 2, 2026. (Had he done nothing, it would have become law anyway: under the state constitution, a bill passed before September 1 and handed over afterward that is not returned on or before September 30 of that year becomes a statute.) It carries an urgency clause, so it took effect the moment he signed it rather than on January 1, 2027.
Now the sentence. The Legislative Counsel's Digest — the neutral summary printed at the top of every California bill — packs three verbs into a single clause: SB 1000 would "delete the user threshold from the definition of 'covered provider,' replace the term 'AI detection tool' with 'disclosure verification tool,' delete the above-described requirement of a covered provider to offer the user the option to include a manifest disclosure in content."
Delete, replace, delete. Take them in order.
One: the threshold. Before SB 1000, Business and Professions Code section 22757.1 defined a covered provider as someone producing a generative AI system that "has over 1,000,000 monthly visitors or users and is publicly accessible within the geographic boundaries of the state." SB 1000's version: a person who produces a generative AI system "that is publicly accessible within the geographic boundaries of the state." Not lowered, not indexed, not tiered. Gone. Compliance lawyers at Morgan Lewis read it the same way — the act would reach any GenAI system that is publicly accessible in the state. This is the change everyone wrote about, and it is genuinely large.
Two: the rename. The law before SB 1000 required a covered provider to make available an AI detection tool at no cost to the user. SB 1000 makes that a "disclosure verification tool." The Assembly Privacy and Consumer Protection Committee's analysis records it in one line: "Recasts 'AI detection tool' as 'disclosure verification tool.'"
Three: the visible label. This is the one worth stopping on. Before SB 1000, section 22757.3 required a covered provider to offer the user the option to include a manifest disclosure (manifest being the statute's word for a mark on the face of the image, the kind a person can perceive). SB 1000 deletes that subdivision. What remains is the latent disclosure: provenance data written into the file for software to read. The same analysis states it flatly — the bill "Deletes the requirement that a covered provider offer a user the option to include a manifest disclosure in GenAI content." In short: it keeps the label you cannot see and drops the one you can.
Here is where things get interesting.
The rename is not the scandal I wanted it to be
My first instinct was that California had quietly downgraded a detection mandate into a receipt check. I went looking for the narrowing and could not find it.
Read both versions of what the tool must do. The text before SB 1000: the tool "allows a user to assess whether image, video, or audio content, or content that is any combination thereof, was created or altered by the covered provider's GenAI system." SB 1000's text: the identical sentence, with "except by minor modification" inserted. In both versions the tool answers only for the covered provider's own system. Neither ever asked anyone to tell you whether a machine made a picture. Each asked a company whether its machine made it.
So the thing being deleted is not a duty. It is a false advertisement. The statute called it a detection tool; it was never a detector. The author's own explanation, printed inside that same committee analysis, is close to an admission: since 2024, Senator Josh Becker wrote, provenance technology has developed such that "the leading technologies for embedding provenance are not accurately described by the law." His office frames it as an interoperability-and-implementation update.
That is defensible, and I would rather have an honest name than a flattering one. But count the cost. For two years the conversation about this law has run on the phrase "free AI detection tool" — the Governor's own September 16, 2026 release on a different AI bill still describes them as AI-detection tools. If the word goes and the duty stays, the duty was always smaller than the word. We are being told, three words at a time, what we bought.
The deletion of the visible label has a real argument behind it too. Becker's statement says the original act "did not address the risk that visible labels create a binary signal implying that unlabeled content is authentic and labeled content is suspect - regardless of whether either inference is warranted." That is a genuine problem: a badge on the fakes teaches you to trust everything without one, and the fakes that matter will never carry it. TechNet, taking a "support if amended" position, praised the bill for "prioritizing latent disclosures over unfeasible manifest labeling requirements."
And a counterweight, because leaving it out would be dishonest: the visible label does not disappear from California's regime, it changes address. Last year's AB 853 added section 22757.3.1, requiring large online platforms to surface provenance in a user interface and forbidding them, to the extent technically feasible, from knowingly stripping it — a duty that lands on the platforms instead, on January 1, 2027. The same day he signed SB 1000, Newsom also signed AB 2713, which rewrites that section without moving its date: platforms will have to look for provenance data "otherwise associated with" content, not only data embedded into or attached to it. Generators embed, platforms display. Coherent — with a gap you can drive through. Between September 30, 2026, when SB 1000 took effect, and January 1, 2027, generators no longer have to offer a visible mark and platforms do not yet have to render one. The California Initiative for Technology & Democracy, which supported the bill if amended, objected to this deletion specifically: manifest disclosures, it wrote, "remain the most accessible way a consumer can quickly discern the origins of digital content."
And the committee's own summary tells you how much now rests on plumbing: the state's approach is to "label all GenAI content 'fake,' label a significant portion of real content 'real,' and prominently display these labels online." Step three is somebody else's job, starting January 1, 2027.
Beijing answered the same question a year earlier, and answered it twice
Why Beijing, of all places? Because it answered this exact question first — and because the comparison is easy to tell badly, it deserves care.
China's Measures for Labeling of AI-Generated Synthetic Content took effect on September 1, 2025 (the date in Article 14 of the Cyberspace Administration of China's published text, eleven months before California's act became operative at all) and were issued jointly by four agencies: the CAC, the Ministry of Industry and Information Technology, the Ministry of Public Security, and the National Radio and Television Administration, alongside a mandatory technical standard.
The design choice is the interesting part. China did not pick one label. It legislated two and gave them different jobs. In the English translation, an explicit label is "added to generated synthetic content or interactive scenario interfaces, which appear in forms such as text, sound, or images, and can be clearly perceived by users." An implicit label is "added to generated synthetic content file data by employing technical measures, which are not easily perceived or known of by users." One a person can see and one only a machine can read — the two categories California has now collapsed into one.
Their scopes are not identical, and this is where sloppy summaries go wrong. Explicit labels are required in the confusion-risk scenarios the deep synthesis rules already covered. The embedded one reaches further: as Bird & Bird explains, implicit labels apply to all AI-generated synthetic content irrespective of whether it may cause public confusion or misunderstanding — what Linklaters' practitioners call a fundamental mandatory obligation. Visible label for what could fool you; embedded label for everything.
What is not in the Measures anywhere is a number. The duties attach to the service, not to its size — to internet information service providers and content distribution services that produce AI-generated content, full stop. California arrived, on September 30, 2026, at a threshold-free rule Beijing wrote in from the start. The Measures also forbid anyone at all from stripping the mark: Article 10 says the labels "must not be maliciously deleted, altered, fabricated, or concealed by any organization or individual." Not a platform duty. Not a provider duty. Any person.
Does it work? Partially, on the available evidence — which is the regulator's own. On the rules' first anniversary, Beijing's municipal cyberspace regulator said 68 major technology companies in the city had adopted both visible and embedded labels and had largely enabled them to be recognized across platforms. "Largely," in one city, self-reported. Chinese state media separately reported authorities removing millions of items in a single campaign — again the regulator's numbers, not an audit. On day one, Western coverage described platforms scrambling to comply as WeChat, Douyin, Weibo and RedNote pushed out features.
And the wrinkle I refuse to leave out, because it mirrors California's deleted option exactly: Article 9 lets a user ask for content without the visible label, once the service agreement has made the user's own labeling duty explicit, with logs kept at least six months. What happens next is the difference — the embedded mark stays, responsibility transfers to a named account holder, and the log survives. California's answer to the same pressure was to delete the offer and put nothing in its place until the platforms catch up.
I am not holding up China's information regime as a model. A labeling rule inside a censorship apparatus is doing more than one job. But on the narrow engineering question — should the mark a human can see and the mark a machine can read be one duty or two? — they answered a year earlier, and they answered two.
The label nobody sees, in 2029
Just imagine it is 2029 and the design has done what designs do — become invisible.
Every image, video and audio file from every generator publicly reachable in California carries a machine-readable claim. There is no floor anymore, so the fourteen-person shop running a face-swap app owes what the frontier lab owes. Nothing you look at has a visible mark on it. The signal lives entirely in the plumbing: embedded at generation, read by the platform, rendered as a small badge you learn to stop noticing, the way you stopped noticing the padlock in your browser bar.
Then picture the first ordinary failure. Your cousin sends you a clip in a messaging app. Is a messaging app outside this chapter? Not automatically — and it is an easy thing to get wrong. The definition of a large online platform expressly includes a mass messaging platform, meaning one "that allows users to distribute content to more than 100 users simultaneously," and SB 1000 carries that definition forward unchanged. Clear the same 2,000,000-unique-monthly-user bar the social networks clear and a direct-message service is inside the chapter, not outside it.
The duty just does not attach to the message. It attaches to the platform, and only to what the platform can read: the section, as AB 2713 rewrote it, tells it to detect provenance data "embedded into, attached to, or otherwise associated with content distributed on the large online platform," and inside an end-to-end-encrypted thread there is nothing there to detect. And look where that section's feasibility escape clause sits — "to the extent technically feasible" qualifies the platform's promise not to strip provenance, not its duty to display it. So nothing renders. Not because messaging is exempt, but because the mark and the platform never meet.
You go looking for the verification tool — and discover there is no the. There is one per company, each answering the only question it is required to answer: was this mine? Twenty compliant tools, twenty honest answers, none of them the question you asked.
What worries me more is a definition. SB 1000 defines "minor modification" as a list: a change to brightness, contrast or color; sharpening; saturating; file resizing; scaling; cropping; file format conversions; denoising audio. Look at that list with an engineer's eye. It is, very nearly, a list of the operations that destroy file metadata as a side effect. The statute is drawing a legal line around transformations too trivial to trigger a new disclosure — a sensible instinct — in almost exactly the vocabulary of the pipeline steps that quietly discard the disclosure you already have. (No one did that on purpose.) It is what happens when law and infrastructure use the same words for different things.
One more: SB 1000 exempts systems designed primarily to function as assistive technology until January 1, 2029, and makes it a $50,000-per-violation offense to falsely claim that shelter. The legislature priced the lie ten times higher than the underlying violation, which tells you what it expects people to try.
What the people who read these bills are saying
No one registered opposition to SB 1000 at its June 16, 2026 hearing. The analysis says it twice — "The bill has no opposition" in the summary, and on the last page, under the heading Opposition, the words "None on file." Read that as a snapshot of one day rather than a verdict on the bill's life. But the arguments around it span the spectrum.
Supporting it, the Center for AI and Digital Policy called it an appropriate expansion and read the rename as "shifting the obligation from passive detection to active and embedded disclosure." Transparency Coalition.ai, also in support, tracked it all session.
From the free-market side, R Street and the American Consumer Institute put California's AI Transparency Act amendments on a March 2026 list of the worst state AI policies in the country, arguing the law and its amendments "foment confusion and ambiguity rather than promoting certainty and transparency." Their sharpest point is one I had missed and cannot unsee: only providers above a million "users" had to comply, yet the law never defined the word the threshold turned on. SB 1000's answer is not to define the word. It is to delete it.
From the civil-liberties side, the Foundation for Individual Rights and Expression puts the constitutional objection directly: companies may watermark voluntarily, but the First Amendment restricts the government from compelling companies to do so. Take that seriously and California's caution stops looking like cowardice and starts looking like lawyering — a compelled visible mark on expressive work is far harder to defend in court than a compelled metadata field.
From the builders, a coalition including GitHub, Hugging Face, Mozilla and Black Forest Labs wrote to Becker that the act's license-revocation mechanism breaks open source, because those licenses are designed to be perpetual and irrevocable. SB 1000 partly answers them: a provider learning of a non-compliant licensee may now notify instead of terminate, on a clock shortened from 96 hours to 72. The Software Freedom Conservancy disputed the coalition's reading of free software licensing entirely while still calling the law's aim good policy (the best kind of disagreement).
And from the researchers, the reason none of this is settled: one widely cited paper proposes a family of regeneration attacks that strip invisible image watermarks, for a defined class of schemes under stated conditions — not proof that all marks are worthless, but not nothing. A position paper argues current implementations risk serving as "symbolic compliance rather than delivering effective oversight" when no standards hold them together. Interoperability, the least glamorous word in this bill, is what everything else rests on.
What does this mean for you?
Stop waiting for the badge. SB 1000 is law, so the generator-side visible label is gone and the platform-side one does not arrive until January 1, 2027. And it arrives platform by platform rather than everywhere at once: a direct-message service big enough to count is covered, one under the 2,000,000-unique-monthly-user bar is not, and inside an encrypted thread there may be nothing for even a covered platform to read. Treat a missing mark as information about the plumbing, not the content.
Learn the one question the tool answers. A disclosure verification tool tells you whether that company's system made or altered the file. If you do not know which company to ask, it cannot help you. Ask anyway when you have a guess; it is free, and it must accept a file or a URL.
Keep originals. When provenance might matter later, send photos as files rather than through the compress-and-resize path. Resizing, scaling, cropping and format conversion are this bill's named "minor modifications" — and the everyday operations most likely to discard the very data the law is trying to preserve.
Recalibrate who counts as covered. Now that this is law, "too small to be regulated" is no longer a category in California. That cuts both ways: it captures the tiny nudification app, and it captures the two-person studio with no compliance budget. Both are now the same word in the statute.
Judge the law by the interface, not the press release. The test in 2027 is not whether provenance data exists. It is whether a platform shows you something, in a place you will look, in words you will understand.
The lesson, as I see it
I came to this bill expecting to catch a legislature quietly weakening a law while taking credit for strengthening it. What I found was stranger: a legislature deleting the number I complained about, correcting a name that had been overselling the product for two years, and removing the one feature ordinary people could actually see — all in one sentence, with no registered opposition, on a bill nobody outside the compliance bar has read.
The threshold deletion is a real win and I will say so plainly. The rename is honest. The third deletion is a bet: that machines reading marks at scale will protect you better than a badge you could have seen with your own eyes, provided the platforms hold up their end from January 1, 2027.
My vote? Take the win, keep the receipt. A law finally willing to describe itself accurately beats one with a flattering name, and I would rather argue with a statute that tells the truth about what it does. But write the date down. If January 2027 arrives and the badges are not there, what we will have built is a transparency regime in which the only parties who can see the transparency are the ones we were trying to keep honest.
The HAIA Foundation reads the statutes so the press release does not get the last word — because the gap between what a law is called and what it does is where autonomy quietly goes missing. If that is the kind of reading you want in your inbox, subscribe and stay skeptical with us.





