There is an entire category of law I had quietly filed under finished. Not beloved, not perfect — finished. Fought out decades ago, lost by the side that resisted it, and by now so ordinary that nobody notices it working. The panel on the back of the cereal box. The sticker on the window of a used car. The folded sheet in the box with your medication. A company that sells you a thing has to tell you some true facts about the thing. I could not have named a single case that settled it, and I never needed to, which is more or less what settled means.
So when California told AI developers to publish a summary of what their models had been trained on, I read it as paperwork. Dull, invoice-generating paperwork. And when I pictured the fight that would eventually come — because a fight always comes — I assumed it would arrive from Washington wearing a preemption argument: Congress occupies the field, states stand down, we have all seen this movie.
That is not the fight. One company went into federal court and made an argument both older and larger: that the First Amendment forbids the state from making it write the page at all.
I was wrong in a useful way, and the useful part has almost nothing to do with AI. It is about how much of what you assume is settled is simply unchallenged — and what happens the first time somebody with a trillion-dollar balance sheet decides to challenge it.
First, the part nobody disputes: what California actually asks for
The statute everyone is arguing about is short. The operative sentence lives in California Civil Code section 3111, and it says that on or before January 1, 2026, and before each time thereafter that a generative AI system is made publicly available to Californians, the developer "shall post on the developer's internet website documentation regarding the data used" to train it.
What the developer has to post is a high-level summary of the datasets, addressing twelve enumerated topics. The very first item on the list is "[t]he sources or owners of the datasets." Item five is the question everybody actually wants answered: whether the datasets include anything protected by copyright, trademark or patent, or whether they are entirely in the public domain. The statute exempts exactly three kinds of model — security and integrity tools, systems for operating aircraft in the national airspace, and models built for national security or defense purposes and released only to a federal entity.
The bill, carried by Assemblymember Irwin, was signed in September 2024 and chaptered as Chapter 817. The Transparency Coalition, which had pushed for it, called the signing a landmark victory for AI transparency. Unlike most tech statutes, there is no revenue threshold at all — it reaches any entity that designs, codes, produces or substantially modifies a generative system for public use in California, and it reaches backward to systems first released or updated on or after January 1, 2022.
Now here is the part that matters most, and that the coverage keeps skipping. As the AI-governance writer Peter Kahl puts it, AB 2013 asks for "a high-level summary of the datasets used to train those systems. Not the training data itself. Not the model weights. Not the source code, training recipes, exact dataset lists, URLs, hashes, or the corpus. A webpage."
A webpage. The state's framing is that this is no different in kind from requiring a nutrition label on a box of cereal.
And here is the evidence that it is survivable: before the ink was dry on the lawsuit, OpenAI and Anthropic both complied. Both filings explicitly reference the statute and are structured to touch each of the twelve required categories. And neither one identifies a single specific dataset, repository or named source — they rely on generalized categories like publicly available information, licensed third-party data, user-provided data subject to opt-out, human-generated data and synthetic data. Law-firm analysis of the first filings found they stayed at a high level throughout.
Hold onto that, because it cuts both ways. It is the best argument that the law is not burdensome. It is also the best argument that the law, as currently complied with, does not tell you very much.
The company that complied on December 30 and sued on December 29
The sequence is not in dispute; the docket lays it out. xAI filed its complaint in the Central District of California on December 29, 2025. The day after filing suit — and two days before the statute took effect — the company posted a limited disclosure, described in xAI's own words, quoted by the court, as a "high-level, limited disclosure that does not reveal its trade secrets."
Read that again, because it reframes the whole case. xAI is not refusing to post a page. It posted a page, and then went to court to establish that the state cannot make it post a fuller one. The judge put the standing question precisely: whether the company's "desire to go no further than what it has already disclosed" is conduct "arguably inflected with a constitutional interest" — and he found that it was, a threshold ruling about who gets to sue, not about the First Amendment.
The complaint ran at the statute from three constitutional grounds at once — a Fifth Amendment takings claim, a Fourteenth Amendment vagueness claim, and the First Amendment compelled-speech claim. In its own filings xAI calls the statute an unconstitutional trade-secrets-destroying disclosure regime. That phrase is the plaintiff's characterization, not anybody's finding, and the distinction matters for everything that follows.
On March 4, 2026, Judge Jesus G. Bernal denied the injunction — and here is where I want to be careful, because this is the point at which the coverage tends to go wrong. The court did not uphold AB 2013. It denied a preliminary injunction, because xAI had not cleared the likelihood-of-success bar. The rest of the injunction test — irreparable harm, the balance of equities, the public interest — was never reached at all, because likelihood of success is "a threshold inquiry" and the court stopped there. Nobody has held AB 2013 constitutional. Nobody has held it unconstitutional either.
What actually sank xAI at this stage was not principle. It was pleading. The court's answer was that the company's case rested on generalized, abstract pleading: "Plaintiff's Complaint trades in frequent abstraction and hypotheticals, rather than pleading specifics about Plaintiff's practices." And the judge went out of his way to say the door is still open — it is "not lost on the Court the important role of datasets in AI training and development, and that, hypothetically, datasets and details about them could be trade secrets." The finding was that xAI "failed at this stage to sufficiently allege that trade secrets are implicated." At this stage. Not ever.
The specific gap is almost comic. Asked what was secret about its own data, the company never actually said: "Plaintiff has not alleged that it actually uses datasets that are unique, that it has meaningfully larger or smaller datasets than competitors, or that it cleans its datasets in unique ways." The vagueness claim went the same way — the court noted that xAI seems to "understand and use with ease" the word dataset throughout its own complaint, which makes it hard to argue the word is unconstitutionally vague.
Two more details worth filing away. The state's own lawyers gave xAI its ticket into court when they refused to disavow enforcement — the Attorney General's office said it could not comment on whether or when it would act, and that refusal made the injury concrete enough to litigate. And for anyone forecasting the fallout: xAI has been clear that this is "an as-applied, not facial, challenge to this statute," which narrows what a formal win would accomplish on paper, whatever it would accomplish in practice.
Twelve days after losing, xAI appealed. The case is now before the Ninth Circuit as No. 26-1591, the district case stayed and terminated on March 23, 2026. As of this writing, no decision has issued. One of the few places following the docket closely is a running tracker of the case; the IAPP's account frames the stakes about right, noting that the suit pits AI transparency against constitutional protections, with a great deal of litigation still ahead.
The sentence the whole appeal hangs on
Here is where things get interesting, and where the case stops being about AI.
The district judge did not reach for an AI precedent, because there isn't one. He reached for Pharmaceutical Research and Manufacturers of America v. Stolfi, a Ninth Circuit decision from August 26, 2025 about Oregon's prescription-drug-pricing disclosure law. Stolfi sorts compelled-disclosure laws into two buckets: reporting to the government, and what it calls "direct disclosure requirements" — laws that make one private entity communicate information directly to another. And it sets the default hard: a direct disclosure requirement is "generally viewed as a content-based 'compelled speech' requirement subject to strict scrutiny, unless the content of the direct disclosure requirement qualifies as 'commercial speech.'"
So the whole case now turns on one clause. In the judge's own words, AB 2013 is "entitled to strict scrutiny unless it qualifies as commercial speech" — and, notably, he said Stolfi "appears to obligate" that view while he remains skeptical of it. A judge applying a rule he does not think fits is not a stable foundation for anything.
He found the commercial-speech exception applied — but only likely. Because AB 2013 gives the public information needed to decide whether to use a model or rely on its outputs "relative to the other options on the market," the court held that the law "likely implicates commercial speech." The bridge that gets him there is a single phrase in Stolfi about informing parties to "actual or potential" commercial transactions — disclosures that do not themselves propose a transaction can still be commercial speech if they inform people about one. That sentence, written about drug prices, is currently holding up California's AI transparency law.
Then there is the part I keep turning over. It was xAI, not California, that argued for the Zauderer standard — the most deferential test available, the one that asks only whether a disclosure is purely factual, uncontroversial and not unduly burdensome. The judge declined to use it, on the ground that the Supreme Court has rarely applied Zauderer outside misleading-advertisement cases. But he wrote, in passing, that he might well have found the law "purely factual, noncontroversial" under it. So xAI asked for a test the judge was inclined to think the statute passes, and got instead the intermediate Central Hudson test — under which it came closer to winning than anywhere else in the opinion.
And then, in the same paragraph, the sentence xAI will build its entire appeal on:
"Ultimately, Plaintiff has demonstrated a distinct possibility of prevailing on the merits under Central Hudson. But it had not demonstrated a likelihood of success on the merits."
A distinct possibility. That is a judge telling a losing party, on the record, that it is one better-pleaded complaint away from a different answer.
Now take xAI's side, because it is stronger than the headlines suggest
It would be easy to write this piece as "rich company invents a constitutional right to secrecy." I do not think that is honest, and I do not think it is what is happening.
Start with the concession the transparency side usually refuses to make. Kahl makes it anyway: "The strongest intuitive argument against AB 2013 is the trade secret argument. AI companies do have trade secrets. They have proprietary methods for collecting, filtering, cleaning, deduplicating, weighting, sequencing, and evaluating data. … Those methods can deserve legal protection. That point should be conceded clearly." He is right. The question was never whether xAI has secrets. It is whether the twelve categories reach them — and xAI, remarkably, declined to explain how.
Then there is the doctrine, which is genuinely unsettled. The intellectual architecture of xAI's argument was built in a 2023 essay on compelled editorial transparency, where the legal scholar Eric Goldman argues that transparency laws forcing internet services to disclose information about their editorial operations do not qualify for Zauderer's relaxed scrutiny and, given what he calls their "inevitably censorial consequences," should trigger strict scrutiny "just like outright speech restrictions do." He made the same case at greater length a year earlier, calling the practice mandatory editorial transparency and flagging the problem that a regulator checking whether your disclosure is accurate ends up supervising the thing being disclosed.
The best statement of the other side comes from Clay Calvert of the American Enterprise Institute, writing after the Ninth Circuit rejected California's commercial-speech framing in an earlier case: "Does applying a different level of scrutiny really matter in a case like this? Absolutely." He is right about that too. Almost every compelled-disclosure case is decided by the choice of test, not by the facts. And the foundation itself may be moving — Calvert notes that Justice Thomas recently wrote that the Court "should reconsider Zauderer" and the decisions applying it, on the ground that the test gives short shrift to First Amendment interests.
xAI also has precedent in its own circuit, won by another Musk company. In September 2024 the same court handed X Corp. a win in X Corp. v. Bonta, holding that California's content-moderation reporting provisions "likely compel non-commercial speech and are subject to strict scrutiny, under which they do not survive." Press-freedom groups read that ruling the same way: the Reporters Committee for Freedom of the Press noted the court's view that compelling speakers to disclose or alter their editorial standards "burdens fully protected expression," and that even "undeniably admirable goals" must yield when they collide with the Constitution.
Nor is the public simply on transparency's side. Polling from the Foundation for Individual Rights and Expression in January 2026 found that 92% of Americans think it is at least somewhat important for governments to protect free speech when regulating AI, and that 72% are concerned — 41% "very" or "extremely" concerned — that laws restricting AI-generated content could be used to suppress criticism of elected officials. Those are not unreasonable fears, and they do not evaporate because the plaintiff here is unsympathetic.
So what is the reframe? It is the distinction the district court drew, and I think it holds. X Corp. involved a law requiring companies to state their opinions on contested categories — hate speech, misinformation, extremism — which is a script the government wrote for a speaker's mouth. AB 2013, by contrast, asks only for a "disclosure of facts" that does not proceed according to a script in conflict with the speaker's mission. On the censorship theory the court was blunt: "nothing in the language of the statute" suggests California is trying to shape model outputs rather than let consumers judge model quality, and "[n]o part of the statute indicates any plan to regulate or censor models based on the datasets."
There is one more thing I cannot make myself ignore. Three months after the district court ruled, the same corporate family filed a registration statement with the SEC — because SpaceX absorbed xAI in an all-stock deal announced in February 2026 valuing the combined company at $1.25 trillion. By July the plaintiff had a new name: it rebranded to SpaceXAI after an IPO that raised $75 billion, and those filings disclosed capital expenditures on AI of $12.7 billion in 2025 — more than three times what it spent on its space and connectivity segments. To be fair: securities disclosure is a different body of law with a different rationale, and going public is a choice. But it is hard to watch a company itemize its AI spending for investors while arguing that naming its data sources for customers is speech the state may not compel.
Brussels asked for more, and got no lawsuit at all
Here is the comparison that keeps this from being a purely American story, and it runs the opposite way to what you might expect.
Article 53(1)(d) of the EU AI Act requires every provider of a general-purpose AI model to "draw up and make publicly available a sufficiently detailed summary about the content used for training of the general-purpose AI model, according to a template provided by the AI Office." The same article carries its own answer to the trade-secret objection, written into the text: the obligation applies "[w]ithout prejudice to the need to observe and protect intellectual property rights and confidential business information or trade secrets."
The body that runs this is the European AI Office, which published the template on July 24, 2025. The template describes itself as a common minimal baseline for what has to be public.
Now compare the architecture of the two answers, because this is the whole point. California passed a statute and let the First Amendment question be litigated afterward. Brussels wrote the trade-secret answer into the recital: the summary should be "generally comprehensive in its scope instead of technically detailed" precisely in order to protect trade secrets while letting copyright holders enforce their rights. The Commission's explanatory notice calls the process behind the template a careful balancing exercise against the EU Charter of Fundamental Rights — determining which details to require was, in its words, done "to ensure that relevant information on the training data is provided … while confidential commercially sensitive information about the data sources and the precise manner in which providers curate the data and train their models is preserved." That is a paper trail. California never produced one.
And the punchline: Europe asks for something California never dared ask for. Under the template, providers must specify whether training data includes web-scraped content, including the top 10% of domain names they crawled (or the top 5%, or 1,000 domains, for smaller companies). The notice says the domain list too was balanced against trade secrecy — the aim being "meaningful information about the most relevant top domain names scraped, while striking a balance with the trade secrets."
The duty has been law since August 2, 2025; enforcement powers switched on in August 2026, and models already on the EU market before August 2025 have until August 2, 2027. What changed last August, as one analysis puts it, was not the duty but the means to enforce it — from that day the AI Office can demand documents, order corrections and impose fines. The penalty for getting the European summary wrong runs to up to 3% of worldwide turnover or €15 million, whichever is higher. Confirmed fines so far: zero. And when Brussels blinked on the rest of the AI Act in 2026 — the Digital Omnibus pushed high-risk deadlines out to 2027 and 2028 — it made no change at all to the GPAI transparency timeline. Of everything on the table, that is the piece Europe declined to trade away.
So how has xAI responded to a broader disclosure mandate, backed by turnover-based fines? Not with a lawsuit. The researcher Kieran Maynard put eleven summaries from seven providers side by side and found a clean split: Google, Meta, Microsoft and OpenAI filed on the actual template, while Anthropic, Mistral and xAI have not — they disclose training content the old way, as "a paragraph of prose in a model card."
To be fair to xAI, and this caveat is load-bearing: its older models are still inside the grace window, so prose in a model card is not a breach of anything. Its formal template filing is not yet due. What is true, and what I think matters, is that the company has never argued in any European forum that this obligation violates anyone's rights. It answered Brussels with a paragraph and answered Sacramento with a constitutional challenge.
And before anyone calls Europe's version a triumph: by Maynard's reading it yields "no token counts, dataset names, or proportions." The template asks whether a source was used, never how much. The identical industry objection was fought in Brussels first — the tech sector's trade body argued that trade secrets must be "safeguarded at all costs," and the answer it got was that the AI Office must weigh trade secrecy against potentially overriding public interests rather than protect it absolutely. Europe's own transparency advocates think that balance landed in the wrong place: the result may fall short of delivering its full potential, one of them wrote, because opting for general descriptions "opens the door to corporate boilerplate and essentially meaningless responses." When three researchers built a quality-assessment framework for these summaries, an exhaustive search turned up only five published as of January 12, 2026.
Two continents, two failure modes. America is having a constitutional fight about whether the page can be required. Europe required the page, and is now finding out how little a required page has to say.
Now imagine the page ten years out
Let me get speculative, because the next decade of this is more interesting than the litigation.
Just imagine the branch where disclosure survives and then evolves. The page stops being prose and becomes structured data — versioned, timestamped, diffable. Your own assistant reads it before you do: you ask it to draft something sensitive, and it quietly declines to route the job to a model whose summary went from "licensed corpora" to "licensed corpora and publicly available web content" in a revision nobody announced. Procurement officers stop reading marketing decks and start reading changelogs. Insurers price model risk off the ingredient list. A small industry grows up around noticing what changed between version 4 and version 5 — not because anyone made it noble, but because the page became machine-readable and therefore checkable.
Just imagine the other branch. A broad First Amendment ruling lands, factual disclosure about a product becomes presumptively protected speech for anyone with a lawyer, and the page dissolves into the only thing left standing: the company's own claim about itself. You will still be told what a model was trained on. You will simply have no way to check, and no state that can make anyone tell you.
And just imagine the reach, because this is the part I think people underestimate. The rule that decided this case came out of a drug-pricing statute, and nothing in its two categories is specific to AI — it is written about compelled disclosure as such. Which is why a broad ruling would not stop at models. Business groups have been fighting this fight for years: the U.S. Chamber of Commerce urged the Ninth Circuit to hold that Oregon's drug-pricing law impermissibly compels speech, and lost. The through-line is that the same office has been on the other side of it since 2024: Rob Bonta's office led a multistate brief defending Oregon's drug-pricing transparency law, arguing such laws serve important state interests.
None of that is a prediction that the settled category collapses. It is a prediction that "settled" was always a description of who had not yet tried.
What the people who have read the briefs are saying
This is not a left-right fight, which is one of the more interesting things about it.
Defending the law: on July 22, 2026, LASST and a coalition of 28 civil-society organizations filed a Ninth Circuit amicus brief calling AB 2013 an ingredient label for AI products, stressing that what it does not require is that companies hand over datasets, disclose code or reveal proprietary algorithms — and noting that xAI is the only major AI company challenging it. The sharpest brief against xAI came from a place you might not expect: the Knight First Amendment Institute, a free-speech institution, which filed the same day arguing that transparency laws facilitating the free flow of accurate information about commercial products "should be subject to a relaxed standard of review." Two days later a competition-policy brief from the Open Markets Institute made the antitrust version: a handful of companies are becoming the gatekeepers of the AI era while insisting the public should know as little as possible, and transparency "is a prerequisite for accountability, competition, and democratic oversight."
Against the mandate, from the free-market side: the R Street Institute argues that state AI mandates are spreading faster than they are working, its Exhibit A being California's own governor asking the legislature to fix one of its AI laws before it took effect in 2026, warning of "unintended consequences."
On what is genuinely at stake, the most careful framing I found comes from Bahrad A. Sokhansanj and Mackenzie Arnold, writing in Lawfare, who reduce it to two open questions: will courts keep treating factual disclosure requirements for businesses as commercial speech, and will they confine Zauderer to cases about preventing marketplace deception? Those answers, they note, "could matter beyond AB 2013."
The stakes are concrete enough. A broad First Amendment ruling here could have wide-ranging implications for transparency provisions in laws like California's SB 53, Illinois' SB 315 and New York's RAISE Act. LASST's senior counsel Ben Rashkovich calls transparency "the floor for AI governance, not the ceiling" — and, to his credit, puts xAI's odds of winning at "probably pretty low." The framing that stuck with me is his: relatively low probability, tremendous consequences.
And the background condition nobody is really arguing about. Stanford's researchers measured it, and found transparency in AI is on the decline: on a 100-point scale, companies scored roughly 40 on average, down from 58 the year before, with training data named as one of four topics on which the entire industry is systemically opaque. The Foundation Model Transparency Index behind that number assessed 13 companies against 100 indicators in December 2025. And the company that sued scored fourteen out of a hundred — among the lowest in the index's history.
So what does this mean for you?
You are not a party to this case and you will never file a brief in it. You are, however, going to rely on these systems for things that matter. Here is what I would actually do.
Go read the disclosure page for whatever model you use, and notice what is missing. The pages exist; that was the whole point of January 1. But the first round of filings named no specific datasets at all. Knowing that the answer is "publicly available information" is different from knowing nothing, and it is a long way from knowing something.
Learn the difference between "denied an injunction" and "upheld the law." They are not the same thing, headlines blur them constantly, and the distinction will matter again on every AI case you read this year. The order is public and the docket is free to read.
When a company says a disclosure would destroy its trade secrets, ask which one. That is not a rhetorical jab — it is literally the question that decided this case. A company that cannot say what is secret about its data is telling you something.
Watch the standard of review, not the verdict. If the Ninth Circuit decides factual disclosure by a business is not commercial speech, the headline will be about AI and the consequence will not be.
If you are in the EU, check whether your provider filed on the template or wrote a paragraph. Both are currently lawful. They are not remotely the same act, and the difference tells you how a company behaves when nobody is suing it.
Do not let "they all do it" become "so none of it matters." OpenAI and Anthropic posted thin pages. xAI posted a thin page and sued. Thin compliance and a constitutional challenge to the concept of compliance are different problems, and only one of them gets fixed by amending a statute.
The lesson, as I see it
I opened by admitting I had filed this whole category of law under finished, and I want to close by saying what I actually learned from being wrong.
It is not that the First Amendment is being abused. That is too easy, and the argument xAI is making has real intellectual pedigree — serious scholars built it, serious judges are skeptical of the alternative, and a district judge who ruled against the company still wrote that it has a distinct possibility of prevailing. You do not get to wave that away because you dislike the plaintiff.
What I learned is that a disclosure regime is only as durable as the reasoning underneath it. California wrote a good statute and left the constitutional question for later. Europe wrote a broader obligation, built the trade-secret balance into the text, documented the balancing exercise against a charter of rights, and attached real fines — and has been sued by nobody, while getting summaries so thin that researchers can barely assess them. One system is fighting about whether the page can exist. The other has the page and is discovering it can be filled with almost nothing.
My vote? Build both halves. A disclosure obligation needs a record showing exactly what interest it serves and exactly what it declined to demand — the work Brussels did and Sacramento skipped — and it needs enough specificity that the finished page tells a reader something they could not have guessed. Neither half survives alone. A page nobody can be made to write is worthless; so is a page that says "publicly available information" and stops.
And the next time you catch yourself assuming a rule is settled, check whether anyone has recently had a trillion dollars' worth of reason to test it. That is not cynicism. It is just the schedule on which settled things come unsettled.
The HAIA Foundation spends its time on exactly this: the moment a boring obligation turns out to be load-bearing, and the argument that arrives to remove it. If you would rather find out before the ruling than after, that all lands here.






