California AI Transparency Act: SB 942 Does Not Regulate You. It Changes Your AI Images Anyway.

California's AI Transparency Act became operative on 2 August 2026, the same day as EU AI Act Article 50. It does not regulate brands, but it changes what your AI images carry.

California AI Transparency Act: SB 942 Does Not Regulate You. It Changes Your AI Images Anyway.
California's California AI Transparency Act (SB 942) directly regulates large generative AI developers rather than individual creators, but it forces technical watermarks and metadata into AI-generated images anyway.
This article is general information about advertising and content disclosure rules. It is not legal advice. Obligations differ by jurisdiction, depend on your specific circumstances, and change. Check your own position with a qualified adviser before acting on anything here.

On 2 August 2026, two things happened on the same day, on opposite sides of the Atlantic.

In Brussels, Article 50 of the EU AI Act began to apply, bringing transparency obligations for AI-generated images and video. In Sacramento, the California AI Transparency Act became operative, having been pushed back from January by a later amendment.

Most coverage has treated the Californian law as a smaller, local version of the European one. It is not. It runs in an entirely different direction, and for anyone selling online it is arguably the more consequential of the two, even though it places no obligation on you at all.

That last point is where nearly every summary goes wrong, so it is worth being precise about it.

From r/AI_UGC_Marketing:
"The FTC has required clear disclosures and banned fake testimonials for decades (heavily updated back in 2009). It has always been illegal and unethical to fake a review, human or AI. The real crux of the matter is that human influencers and TikTokers simply choose to ignore the law. Even with the new AI disclosure laws coming out of states like New York that go into effect on June 6th, creators and everyone on this forum are just going to completely ignore it too. AI didn't create this crisis. The laws have always been there, people just don't care."

He is right about the history, right about enforcement, and wrong about this particular law, in a way that explains why it matters.

On the history he is correct. Disclosure obligations are old, the FTC has policed endorsements for decades, and none of this began with generative AI. He is also right that compliance with disclosure rules has been patchy, because every regime he is describing works the same way: it tells a person to declare something, and then depends on that person choosing to declare it. Non-compliance is always available. Usually it is free.

The New York date is 9 June rather than 6 June, which is a small thing except that it illustrates how loosely these rules are being reported, including by people who follow them closely.

But California's law is not that kind of law, and this is the whole point of it. It does not ask advertisers to declare anything. It obliges the companies that make the generation tools to stamp their output at the moment of creation. Nobody has to care, agree, or comply for that to happen to your files.

You cannot ignore an obligation that was never placed on you and is being carried out by somebody else. That is precisely why, of the two laws that landed on 2 August, this is the one more likely to change what happens to your marketing content.

Who SB 942 Actually Binds

The law applies to a "covered provider", defined as a business that creates or produces a generative AI system with more than one million monthly visitors or users that is publicly accessible in California.

That is OpenAI. That is Midjourney. That is Adobe Firefly, Runway, and the handful of others operating at that scale.

It is not you. A Shopify store generating product imagery in one of those tools is a user of a covered provider's system, not a covered provider. You have no filing to make, no tool to build, no compliance programme to run.

If you have read a blog post telling you that SB 942 means your brand must now label its AI images in California, that post is wrong. The obligation sits one layer up the stack, with the companies making the models.

So why does it matter to you? Because of what it obliges those companies to do to your files.

The Obligation That Reaches Your Images

From 2 August, covered providers must do four things. Three are housekeeping. The fourth changes the economics of AI imagery.

A free detection tool. Each covered provider must offer a publicly available tool that lets anyone check whether a given piece of content came from that provider's system.

An optional visible label. Providers must give users the option to attach a manifest disclosure, a visible marker, to generated content. Optional for the user, mandatory for the provider to offer.

A contractual chain. Licensees must be required, by contract, to preserve the disclosure capability rather than strip it out.

A latent disclosure, applied by default. This is the one that matters. Every image, video and audio file the system produces must carry embedded, machine-readable provenance data, where technically feasible.

The latent disclosure is not a watermark you can crop out. It is metadata written into the file at the point of creation, and it records the provider's name, the name and version of the system that made or altered the content, a timestamp, and a unique identifier tying the file back to the system that generated it.

In practice this means the C2PA specification, the content provenance standard the major model providers have converged on. The statute does not name it. It asks for methods consistent with widely accepted industry standards, which currently means C2PA and Google's SynthID for its own outputs.

Non-compliance for a provider runs at $5,000 per day per violation, with each day treated as a separate violation. That is enough to make the providers take it seriously, which is the entire point.

What This Means in Plain Terms

Before 2 August, an AI-generated product image was, for practical purposes, anonymous. You generated it, downloaded it, uploaded it to your product page or ad account, and nothing about the file announced where it came from. Detection relied on people spotting six-fingered hands.

After 2 August, images produced by the largest tools arrive carrying a record of their own creation. Provider, model, version, timestamp, identifier.

The word people reach for is watermark, and that is misleading. A watermark is something a viewer sees. This is closer to a birth certificate travelling with the file: invisible in normal use, and readable by anything that knows to look.

Two honest caveats, because the internet is currently full of overstatement in both directions.

Provenance metadata can be stripped. C2PA data is an attachment to the file, and re-encoding, screenshotting or running an image through a tool that discards metadata will remove it. Anyone telling you AI images are now permanently and unavoidably traceable is overselling the technology.

Coverage is not universal. The law reaches systems above a million monthly users that are accessible in California. Smaller and self-hosted models sit outside it, and enforcement of an obligation to embed data "where technically feasible" has not yet been tested.

So the accurate statement is narrower than the headlines, and still significant: AI imagery from the mainstream tools now defaults to being identifiable, and staying anonymous has become an active step rather than the natural state of things.

The Squeeze: Provenance Meets Platform Detection

On its own, provenance metadata would be a technical curiosity. What makes it consequential is that something is now reading it.

The advertising platforms have spent 2026 building AI labelling into their ad systems, and they are not relying solely on advertisers to declare what they used. TikTok uses C2PA Content Credentials to detect synthetic media automatically, including where the uploader has not disclosed it. Meta applies an "AI info" label both when its own generative tools were used and when its detection identifies third-party generative tools in the creative.

Put the two halves together.

California obliges the model providers to stamp their output. The platforms read the stamps. An advertiser who assumed the question of whether an image was AI-generated would remain a private matter is relying on an assumption that expired this summer.

This is the part almost no coverage joins up, because the California story is filed under regulation and the platform story is filed under advertising operations. They are the same story. One built the signal, the other built the reader.

What It Does to the Cost Case for AI Imagery

The argument for generated imagery has always been production cost. A studio shoot with a photographer, a model, a location and a day of retouching against a prompt and thirty seconds. That gap is real and it is not going away.

What has changed is that the comparison is no longer production cost against production cost, because one side of it now carries obligations and consequences the other does not.

An AI image may need labelling under the EU AI Act if it reaches European consumers. It may need disclosure under state advertising law. It arrives at the platform carrying provenance data that can trigger an automatic label. And it lands in front of an audience that has an opinion about that label.

The consumer data on this is not ambiguous. Research from Klaviyo and Datalily found that only 7% of consumers say visible AI-generated marketing content makes them trust a brand more, while 31% say it makes them trust the brand less. Separately, 78% say they would rather see ads made by people, even if AI could produce better ones.

A four-to-one trust penalty is not a rounding error on a conversion rate. And the labels are increasingly not yours to withhold.

Meanwhile a photograph taken by an actual customer carries no provenance obligation, triggers no platform label, and needs no disclosure, because there is nothing to disclose. It is a photograph of a real thing, taken by a real person.

Where Customer Content Sits in This

Everything above describes a rising cost attached to synthetic imagery. The natural question is what the alternative supply looks like, and for most brands the honest answer is that they already have one and have never organised it.

This is where 82DASH fits. It is a customer content library: a way to collect photos, videos, feedback and reviews directly from the people who have already bought the product, with rights cleared at the moment of submission.

The mechanism is deliberately unglamorous. A customer scans a QR code or taps an NFC tag, on a receipt, on packaging, at a till or in a follow-up message. They submit a photo or a short video. A reward lands on their phone in an Apple Wallet or Google Wallet pass within seconds. The rights agreement is captured at the point of submission, which is what makes the content usable in a paid advertisement rather than only on your own channels.

Three properties of that content matter specifically in a disclosure regime.

It has no provenance problem. A customer photograph is a photograph. No embedded generation metadata, nothing for a platform detector to flag, no label attached at delivery.

Its rights position is documented rather than assumed. The difference between content submitted directly to you under an agreement and content found on social media is the difference between a file you can put behind ad spend and one you are hoping nobody objects to. This is the distinction between CGC, customer-generated content, submitted directly and rights-cleared, and UGC, publicly posted and rights-uncertain. Our glossary sets out the terms; the practical consequence is that only one of the two is safe to scale.

It is more persuasive to begin with. Salsify reports 74% higher conversion on product pages carrying customer imagery, and Bazaarvoice puts the uplift above 160% when shoppers actively interact with customer photos.

There is a broader principle underneath this, which is that the money currently going to commissioned creative could go to the people who already bought the product. Pay your customers, not creators. A brand paying a creator is paying someone with no relationship to the product to describe it convincingly. The customers who chose it, paid for it and use it will supply a photograph for the price of a small reward, and their version is more believable precisely because nobody paid them to hold an opinion.

Worth being plain about one thing: this is not an argument that AI has no place in your workflow. Cleaning up a real photograph, correcting colour, removing a distracting background object, generating a seasonal variation from a genuine base image, all of that is retouching with better tools and none of it is the problem. The exposure sits with imagery that invents a person or a scene that never existed, because that is what the disclosure regimes are built to catch.

If you want to see how the collection flow works end to end, the how it works page walks through it, and the Trust Center covers the rights and data handling side for anyone who needs to satisfy a legal review.

Install 82DASH on the Shopify App Store

What to Actually Do This Quarter

Not a compliance programme. You are not the regulated party. This is housekeeping.

Find out what is in your library. Most brands cannot currently answer the question "which of our current creative is AI-generated?" with confidence. Somebody generated something in a rush in March and it is still running. Audit it now, while the volume is small.

Check your provenance data before you assume it is gone. If you use AI imagery, run a file through the provider's detection tool and see what comes back. You may find your creative is more legible than you expected.

Stop stripping metadata by accident. Some brands are about to remove provenance data unintentionally through routine image pipelines and re-encoding. That is not a compliance breach for you, but it does mean your own records of what you made and how will not survive, which matters if a platform or a regulator ever asks.

Separate the two piles. Real photographs in one, generated imagery in the other, labelled internally. Every disclosure question for the next two years starts with knowing which is which, and no brand has ever regretted having that list.

Build the customer supply before Q4, not during it. Content collection has a lead time. Requests go out, submissions come back over days and weeks, and a library assembled in November is a library assembled at the worst possible moment.


Isabelle Simon, Communications Lead, 82DASH

Frequently Asked Questions

Does the California AI Transparency Act apply to my online store?
Almost certainly not directly. It binds "covered providers", meaning businesses operating generative AI systems with over one million monthly users that are publicly accessible in California. A brand using those tools is a user, not a provider, and carries no obligation under this statute. Other rules may still apply to your advertising, including the EU AI Act if you reach European consumers, and state advertising law in the US.

What is a latent disclosure, and can I remove it?
It is machine-readable provenance data embedded in the file at creation, recording the provider, the system name and version, a timestamp and a unique identifier. It is technically removable: re-encoding or stripping metadata will discard it. There is no obligation on you to preserve it, though removing it deliberately to conceal how content was made is likely to look worse than the original use.

Will my ads get labelled automatically because of this law?
Possibly, but through the platforms rather than the statute. Meta and TikTok both run automated detection that reads content provenance signals, so provenance data embedded under California's rules can feed a platform's labelling decision. The law and the label are separate systems that happen to interlock.

Do customer photos need any AI disclosure?
No. A photograph taken by a customer of a real product is not AI-generated content and falls outside these regimes entirely. The obligations attach to synthetic or substantially AI-altered imagery. This is a structural difference rather than a loophole: there is nothing to disclose because nothing was generated.

Is it still worth using AI for product imagery at all?
For modifying real photographs, generally yes. Background cleanup, colour correction and scene variation built on a genuine base image remain cheap and effective, and none of it invents a person or an event. The calculation has changed for fully generated imagery, particularly anything depicting a person, where labelling obligations, platform detection and a measurable consumer trust penalty now sit on the other side of the ledger.

Further Reading