California’s AI Disclosure Law Went Live August 2: What Small Marketing Agencies Must Change Now
Executive Summary
- The California AI Transparency Act became operative on August 2, 2026, after AB 853 moved the date back from January 1, 2026. As of publication no court has enjoined it, so treat it as enforceable.
- The law regulates generative AI providers with more than 1,000,000 monthly visitors or users, and its disclosure duties cover image, video, and audio content only. Text output is outside these provisions. It does not regulate your marketing agency directly, which is exactly why most agency owners have not read it.
- Three things reach you anyway: a manifest disclosure option your production standards and client contracts now have to address, hidden provenance data that your delivery workflow can silently destroy, and a 96 hour license revocation clause that applies to licensees who modify a covered system.
- The provision that already creates direct agency liability is federal, not Californian. FTC staff state plainly that advertising agencies and public relations firms can be liable under the Consumer Reviews and Testimonials Rule, 16 CFR Part 465, which has been in force since October 21, 2024.
- Washington is pushing in the opposite direction. Executive Order 14365 created a DOJ AI Litigation Task Force, the FTC set aside its Rytr order on December 22, 2025, and the FTC proposed a preemption oriented policy statement on July 1, 2026. None of that invalidates California law today. Plan for divergence, not for a single national rule.
In this article
- What actually became law on August 2, 2026
- Does the California AI Transparency Act apply to your agency?
- The three obligations now sitting on your AI vendors
- The 96 hour clause, and the separate problem of provenance stripping
- What changes on January 1, 2027 and January 1, 2028
- The federal government is pushing the other way
- What already creates direct agency liability today
- What to put in your MSAs and SOWs
- A 90 day plan for an agency with no compliance staff
- Mapping this to the NIST AI RMF and ISO/IEC 42001
1. What actually became law on August 2, 2026
On August 2, 2026, the California AI Transparency Act became operative and imposed provenance disclosure duties on large generative AI providers serving California users. The statute started life as SB 942, which set an operative date of January 1, 2026. In October 2025, AB 853 rewrote that date to read, in the plain words of the amended Section 22757.6, that the chapter shall become operative on August 2, 2026.
The California AI Transparency Act is a state law requiring generative AI providers with more than 1,000,000 monthly visitors or users to embed hidden provenance data in AI generated image, video, and audio content, to offer users an option to add a visible disclosure, and to publish a free public tool that detects whether such content came from their system. Violations carry a civil penalty of $5,000 per violation.
Three details matter more than the headline. First, the statute’s disclosure duties reach only image, video, and audio content, or any combination of those. Sections 22757.2 and 22757.3 use that phrase repeatedly. AI drafted body copy, subject lines, and ad headlines are not covered by these provenance provisions at all, which narrows the practical scope for a lot of agency work.
Second, AB 853 did not just move a date. It expanded the statute with new categories of regulated entity, each with its own later start. Third, the law is operative and, as of publication, has not been enjoined. The high profile California AI case, xAI v. Bonta, targets AB 2013, the training data transparency statute, and does not touch the AI Transparency Act.
For an agency owner, the practical question is usually not whether California will enforce this against you, because an agency that merely uses commercial AI tools is not a covered provider. The question is what your vendors are about to change underneath you, and what your clients are about to start asking you to certify.
2. Does the California AI Transparency Act apply to your agency?
Almost certainly not, because the statute regulates covered providers, and a covered provider is defined as a person that creates, codes, or otherwise produces a generative artificial intelligence system with over 1,000,000 monthly visitors or users that is publicly accessible within California. A 12 person creative shop in Sacramento that runs client work through commercial AI tools builds nothing, codes nothing, and serves nobody at that scale. It is a user of covered systems, not a covered provider.
There is a real exception. If your agency builds, fine tunes, white labels, distributes, or licenses its own generative AI system rather than simply using someone else’s, run the analysis instead of assuming the answer. The threshold still applies, so a proprietary tool used by a handful of clients is not covered. But an agency that has productized an AI offering in front of a large public audience should get that reviewed rather than filed under “we are just an agency.”
The distinction is worth stating clearly because published commentary blurs it, and agency owners have been told they face a new California disclosure mandate on their advertising. They do not. The AI Transparency Act imposes no disclosure duty on advertisers, on agencies, or on the content you deliver to a client.
What it does is change the material you receive from your tools, and change the contractual posture of the companies that sell those tools to you. That is a supply chain problem, and supply chain problems are the ones small agencies handle worst, because nobody owns them.
GOVERNANCE INSIGHT
Not being regulated is not the same as not being exposed
The agencies that get hurt by laws like this are rarely the ones the statute names. They are the ones sitting one link down the chain, signing client contracts that promise things the agency never verified, using tools whose behavior just changed. Your exposure runs through your contracts and your production workflow, not through the California Attorney General.
3. The three obligations now sitting on your AI vendors
Covered providers owe three distinct duties as of August 2, 2026, and each one changes something you touch. The obligations are a latent disclosure, a manifest disclosure option, and a free public detection tool. All three are written to cover image, video, or audio content, or any combination of those.
Latent disclosure
A latent disclosure is provenance data embedded invisibly in the content itself. Section 22757.3(b) requires a covered provider to include a latent disclosure in AI generated image, video, or audio content that conveys the name of the covered provider, the name and version number of the system that created or altered the content, the time and date of creation or alteration, and a unique identifier. The statute qualifies this with the phrase to the extent that it is technically feasible and reasonable, and requires the disclosure to be detectable by the provider’s own detection tool, consistent with widely accepted industry standards, and permanent or extraordinarily difficult to remove.
This is the duty that interacts with your production workflow, and it is invisible by design. When your team exports an image, transcodes a video, runs a file through a compression step, or pushes an asset into a platform that rewrites metadata on upload, embedded provenance data can be lost. Nobody on your team will see it happen. Section 4 explains what that does and does not mean legally, because the distinction matters.
Manifest disclosure
A manifest disclosure is the visible version, and Section 22757.3(a) requires providers to offer the user the option to include one in image, video, or audio content created or altered by the system. The disclosure must identify the content as AI generated, be clear, conspicuous, appropriate for the medium, and understandable to a reasonable person, and be permanent or extraordinarily difficult to remove to the extent technically feasible.
Note the word option. California did not mandate that AI content carry a visible label, and it imposes no duty on your agency to apply one. It mandated that the provider give the user a switch. In practice that means the choice now sits with whoever is at the keyboard in your studio, which in most agencies is a junior designer with no instruction either way. Nothing in the statute requires you to decide this per deliverable, but your production standards and client contracts should say who decides and what the default is. That is a governance gap you can close this week for reasons that are commercial rather than statutory.
Detection tool
Section 22757.2(a) requires each covered provider to make available a free AI detection tool that lets a user assess whether image, video, or audio content was created or altered by that provider’s system, supporting both file upload and URL submission as well as an API, while outputting system provenance data and withholding personal provenance data.
Understand the limits before you rely on it. These tools are provider specific: one tells you whether content came from that provider’s system, not whether content is AI generated in general, and only if the provenance data is still intact. If your pipeline stripped the metadata, the tool may return nothing useful, which is false reassurance rather than a clean bill of health.
The strategic consequence is still real. A client, a competitor, a journalist, or an opposing lawyer can now take a deliverable you produced and query the vendor’s tool. If your agency told a client the work was original human creative and the provenance data says otherwise, that is no longer an argument about credibility. It is a document.
4. The 96 hour clause, and the separate problem of provenance stripping
Section 22757.3(c) is narrower than most summaries suggest, and reading it precisely saves you from solving the wrong problem. It has three parts. A covered provider that licenses its system to a third party must require by contract that the licensee maintain the system’s capability to include a latent disclosure. If the covered provider knows that a licensee modified the licensed system such that it is no longer capable of including that disclosure, the provider must revoke the license within 96 hours of discovering the action. The licensee must then stop using the system.
Two conditions must be met before that clock starts: the licensee modified the licensed generative AI system itself, and the covered provider knows about it. This is a provision about tampering with the tool, not about what happens to a file after the tool has finished with it.
Whether your agency is a licensee under Section 22757.3(c) depends entirely on what you signed. A standard business subscription is not usually a license to modify the system. An enterprise agreement, a white label arrangement, a reseller deal, or an API integration where you build your own product surface on a foundation model is a different question, and the answer lives in your contract, not the statute.
Why provenance stripping is a real risk anyway, and a different one
Here is the distinction that matters. When your automated pipeline destroys embedded provenance data as a side effect of resizing, transcoding, or exporting, you have almost certainly not violated Section 22757.3(c), because you did not modify the generative AI system. You modified a file it produced. California’s 96 hour revocation mechanism is not aimed at you.
That does not make it harmless. Losing provenance creates a different and more mundane set of exposures: breach of your AI vendor’s terms of service, breach of a client contract in which you promised provenance would be preserved, a platform policy problem once the January 1, 2027 obligations arrive, and an evidentiary hole if anyone later asks you to demonstrate how a deliverable was made. Those are contract, commercial, and proof problems rather than California statutory violations, and small agencies lose money on exactly that category.
The realistic failure mode is not deliberate stripping to hide something. It is an automated pipeline doing it silently while nobody notices for eleven months. If you have tooling between the model output and the client deliverable, someone should test whether provenance survives it. Not because California will fine you, but because you will eventually need to answer the question.
| Date | Who becomes covered | Threshold | Core duty |
|---|---|---|---|
| August 2, 2026 | Covered generative AI providers | Over 1,000,000 monthly visitors or users, publicly accessible in California | Latent disclosure, manifest disclosure option, free public detection tool, licensee contracting |
| January 1, 2027 | Large online platforms | Over 2,000,000 unique monthly users in the preceding 12 months | Detect and act on embedded provenance data in distributed content |
| January 1, 2027 | Generative AI hosting platforms | Any site or app offering model weights or source code for download | Do not knowingly make non compliant systems available |
| January 1, 2028 | Capture device manufacturers | Producers of cameras, phones with cameras or microphones, voice recorders | Provide disclosure capability in captured content by default |
5. What changes on January 1, 2027 and January 1, 2028
The January 1, 2027 wave is the one that will actually change how your work behaves in the wild, because it reaches the distribution platforms your campaigns run on. AB 853 defines a large online platform as a public facing social media platform, file sharing platform, mass messaging platform, or standalone search engine that distributes content created by someone other than the user, and that exceeded 2,000,000 unique monthly users during the preceding 12 months.
Many of the major platforms a media buyer works with will clear 2,000,000 unique monthly users, though the statute’s definitions and counting rules are specific and each platform’s status is its own question. From January 1, 2027, covered platforms have statutory obligations concerning latent disclosures in the content they distribute. How any individual platform implements that is not yet knowable, and this article will not guess. The practical instruction is to watch for implementation announcements from the platforms you actually buy on, because their product decisions will reach your campaigns long before a regulator does.
The same date brings in generative AI hosting platforms, defined as a website or application that makes available for download the source code or model weights of a generative AI system. If any part of your creative stack depends on self hosted open weight models, that supply route is now inside the statute’s perimeter.
January 1, 2028 adds capture device manufacturers, meaning producers of devices that record photographs, audio, or video. That is a longer horizon, but it points where this is going. California is building provenance in at the point of capture as well as the point of generation, which over time makes the absence of provenance data on a piece of content meaningful in itself.
6. The federal government is pushing the other way
While California tightened disclosure requirements, the federal government spent the last eight months actively working to constrain state AI laws, which means agencies should plan for divergence rather than for a single national standard. Three moves define the current posture.
First, on December 11, 2025, the President signed Executive Order 14365, published at 90 FR 58499. Section 3 directed the Attorney General to establish an AI Litigation Task Force within 30 days whose sole responsibility is to challenge state AI laws, including on grounds that they unconstitutionally regulate interstate commerce or are preempted by federal regulations.
That task force is not theoretical. On April 24, 2026, the Department of Justice intervened in xAI’s lawsuit against Colorado’s SB 24-205, arguing the Colorado AI Act violates the Equal Protection Clause, as Jenner and Block documented five days later. We covered the downstream employer consequences in our analysis of what actually applies to employers after Colorado’s law stalled.
Second, the FTC softened its early AI enforcement stance. On December 22, 2025, the Commission reopened and set aside its 2024 final consent order against Rytr, an AI writing service whose subscribers could generate reviews, on a 2 to 0 vote. The Commission found that the facts alleged failed to support a Section 5 violation and that the order unduly burdened innovation. Bureau of Consumer Protection Director Christopher Mufarrige said condemning a technology because it potentially could be used in a problematic manner is inconsistent with the law and ordered liberty. Venable’s advertising law team analyzed the reversal in January 2026.
Do not over read one order into a general policy. The same FTC release states that the Commission will continue to hold accountable actors that use AI to violate the law or deceive consumers about the capabilities of their generative AI. The fair reading is that the Commission has grown skeptical of liability resting only on a tool’s potential for misuse. It has not stepped back from AI deception enforcement, and an agency that fabricates an endorsement is squarely in the second category.
Third, Section 7 of EO 14365 directed the FTC to issue a policy statement explaining when state laws that require alterations to the truthful outputs of AI models are preempted by the FTC Act. The Commission delivered a proposed statement on July 1, 2026, with comments closing July 31, 2026, on a 2 to 0 vote.
Read that proposed statement carefully before assuming it rescues you from California. Start with what it is: a proposed policy statement expressing the Commission’s view. It is not a rule, not a court decision, and it does not by itself preempt any state statute. The preemption theory it advances targets state laws that coerce companies into distorting model outputs, and the example the Commission names is Colorado’s Artificial Intelligence Act, which the proposed statement describes as impliedly preempted to the extent it conflicts with a federal regulatory scheme.
A provenance labeling law is a materially different animal from an output steering law. California’s Act does not require anyone to alter the substance of what a model produces. It requires metadata about origin. Nothing in the proposed statement suggests the AI Transparency Act is preempted, and betting your compliance posture on that outcome would be a bad trade.
7. What already creates direct agency liability today
The rule that creates real, direct, present tense liability for a marketing agency is federal and has been in force since October 21, 2024: the FTC’s Trade Regulation Rule on the Use of Consumer Reviews and Testimonials, codified at 16 CFR Part 465. Unlike California’s transparency statute, this one names you.
FTC staff answer the question directly in the agency’s own published guidance. Asked whether advertising agencies, public relations firms, review brokers, or reputation management companies can be liable under the rule, the staff answer is one word: yes. They go on to explain that such firms could be liable under Section 465.2(a) if they write, create, or sell a fake or false consumer review, consumer testimonial, or celebrity testimonial.
The AI connection is in the text of the rule itself. Section 465.2(a) makes it an unfair or deceptive act for a business to write, create, or sell a review or testimonial that materially misrepresents any of three things: that the reviewer or testimonialist exists, that they used or had experience with the product, service, or business, or the nature of that experience.
All three prongs matter, and agencies tend to fixate on the first. A synthetic persona presented as a customer fails the existence prong. But an AI polished quote attributed to a real client who never used the specific product fails the second prong, and an AI embellished testimonial that overstates what a genuine customer actually experienced fails the third. Using AI is not itself the violation. Materially misrepresenting the person, their use, or their experience is. That is squarely inside the rule, and no state law is needed to get there.
The exposure is quantified but conditional. Under 16 CFR 1.98, the maximum civil penalty under Sections 5(l), 5(m)(1)(A), and 5(m)(1)(B) of the FTC Act is $53,088, set by the adjustment published at 90 FR 5581 on January 17, 2025. Three qualifications belong with that number. It is a ceiling adjusted annually for inflation, so confirm the current figure before quoting it in a contract or client memo. Penalties are imposed by a court, not assessed by the agency. And the rule authorizes them for knowing violations, which means a documented good faith process is worth something. There is no private right of action, so the risk is regulatory rather than a plaintiff’s bar problem.
| Question | California AI Transparency Act | FTC Consumer Reviews Rule, 16 CFR Part 465 |
|---|---|---|
| In force since | August 2, 2026 | October 21, 2024 |
| Names agencies as liable | No. Regulates covered providers | Yes. FTC staff guidance says agencies and PR firms can be liable |
| Penalty | $5,000 per violation, each day a discrete violation, plus costs and fees to a prevailing plaintiff | Court imposed, up to the inflation adjusted statutory maximum of $53,088, for knowing violations |
| Who enforces | Attorney General, city attorney, or county counsel | Federal Trade Commission |
| Private right of action | No | No |
| Your practical exposure | Indirect, through vendor contracts and client warranties | Direct, as the entity that created the content |
Getting your AI governance in order
Dynamic Comply helps small and medium sized businesses build a real AI governance foundation using the NIST AI RMF and ISO/IEC 42001.
8. What to put in your MSAs and SOWs
Your contract language is the single highest leverage change available to a small agency, because it is the only place where AI risk gets allocated between you and your client before anything goes wrong. Most agency master service agreements written before 2024 say nothing about AI at all, which leaves you holding warranties drafted for a production process you no longer run.
Start by reviewing the warranty you already gave. Using generative tools does not by itself destroy originality, because a deliverable can still reflect genuine human authorship through selection, arrangement, editing, and transformation. The risk is narrower than that. If your MSA promises that deliverables are created exclusively by agency personnel, or makes broad guarantees about originality, ownership, or non infringement that you cannot substantiate given how the work is actually produced, that language needs to change. Replace it with a disclosed use provision that states the agency uses generative AI tools in production, identifies the categories of use, and warrants what you can genuinely stand behind.
Add a provenance clause. State whether deliverables will carry embedded provenance data, whether manifest disclosures will be applied, and who decides. Make the default explicit so the decision is not made silently by whoever exported the file.
Handle client removal requests carefully, and do not treat a written instruction as a permission slip. If a client asks you to remove or suppress provenance information, get the request in writing, then assess whether complying would conflict with applicable law, your AI vendor’s terms of service, platform rules, or a disclosure commitment you have already made elsewhere. A client cannot authorize you out of obligations you owe to someone else. Your contract should say that plainly, and should give you the right to decline.
Add a testimonial and endorsement representation. Given that FTC staff say agencies can be liable under 16 CFR Part 465, you want a clean allocation: the client represents that any person depicted in a testimonial is a real customer with the stated experience, and the agency represents that it will not create a review or testimonial from a person who does not exist. That single pair of sentences maps directly onto Section 465.2(a).
Finally, add a downstream terms clause. You are bound by the terms of service of every AI vendor in your stack, and those terms now carry California driven obligations. Your MSA should make clear that agency deliverables are subject to applicable vendor terms and that the client cannot direct the agency to breach them.
9. A 90 day plan for an agency with no compliance staff
A 12 to 40 person agency can reach a defensible position in 90 days without hiring anyone, because the work is inventory, decision, and documentation rather than legal analysis. Here is the sequence I would run.
Days 1 to 30: find out what is actually true
Build an AI tool register. List every generative tool in use, who uses it, which client work it touches, what plan or contract governs it, and whether that contract is a subscription or a license that permits modification. Expect to find tools nobody told you about, because in an agency the creative team adopts faster than the owner approves.
Then run one provenance test. Push AI generated image or video output through your normal export and delivery pipeline exactly as a client deliverable would travel, and check the result against that vendor’s public detection tool. Two caveats keep this honest: detection is provider specific, so you learn about one system, and this is not a compliance determination, since your agency is probably not subject to the statute anyway. What you get is an operational fact you do not currently have. That still makes it the most useful thing in this article.
Days 31 to 60: make the decisions somebody has to make
Write a one page AI use policy. It needs four decisions, not forty pages: which tools are approved, what client data may never be entered into them, whether manifest disclosure is on or off by default and who can override it, and the rule that no testimonial or review may depict a person who does not exist. Have every member of the production team read and acknowledge it.
Update your contract templates using the clauses in section 8. Do it once, in the template, rather than negotiating it deal by deal.
Days 61 to 90: make it survive contact with reality
Add an AI disclosure line to your project intake form so the decision is captured per engagement rather than per person. Create a simple deliverable log recording, for each campaign, which tools were used and whether provenance was preserved. Set a calendar reminder for October 2026 to review the January 1, 2027 platform obligations before they land.
Ninety days of this produces a tool register, a production test result, a signed policy, an intake record, and a deliverable log. Together those are credible evidence of reasonable governance for a client procurement team, an insurer, a platform, or a regulator, though what any particular one asks for will depend on the circumstances. That is the entire point. Small agencies rarely lose these fights on the merits. They lose because they cannot show what they did.
10. Mapping this to the NIST AI RMF and ISO/IEC 42001
Everything in the 90 day plan maps onto two established frameworks, which matters because it lets a small agency answer enterprise client questionnaires with a recognized vocabulary rather than an improvised one. The NIST AI Risk Management Framework organizes work into govern, map, measure, and manage functions, and ISO/IEC 42001 defines a certifiable AI management system.
Your tool register is the map function, and it is also the asset inventory that ISO/IEC 42001 expects at the front of any management system. Your one page AI use policy sits in govern. The provenance test and the deliverable log are measure. The contract clauses and the intake form are manage, because they are the controls that change behavior rather than merely describing it.
The reason to bother with the framework language is commercial rather than regulatory. Neither framework is required by California’s Act or the FTC rule, and certification is not necessary for any of this to be useful. But enterprise clients increasingly send AI questionnaires to their agencies, and a shop that answers with named framework functions and a documented policy wins against a shop that answers with reassurance. We saw the same dynamic in software procurement, covered in our analysis of EU AI Act transparency duties for small SaaS companies, where August 2, 2026 was also the operative date. For how state AI statutes are converging on audit and documentation duties, see our explainer on Illinois SB 315 and the first state AI audit law.
One closing note on scale. The Duke and Deloitte CMO Survey published in March 2026 found that marketing AI usage has more than doubled in two years, with generative AI growing faster still, and that generative engine optimization is already in use at 4 in 10 companies. Adoption is not the differentiator anymore. Documentation is.
Talk to Ross about your AI governance needs
Every business has different AI governance requirements. Let us talk about yours.
Frequently Asked Questions
Does the California AI Transparency Act apply to my marketing agency?
Usually not. The law regulates covered providers, defined as those producing a generative AI system with over 1,000,000 monthly visitors or users that is publicly accessible in California, and its disclosure duties reach only image, video, and audio content. An agency that uses commercial AI tools is not a covered provider and owes no disclosure duty under the statute. Reassess if your agency builds, fine tunes, white labels, or licenses its own generative AI system at that scale.
When did the California AI Transparency Act take effect?
It became operative on August 2, 2026. The original statute, SB 942, set an operative date of January 1, 2026, but AB 853 amended Section 22757.6 in October 2025 to move that date to August 2, 2026. AB 853 also added later phases beginning January 1, 2027 and January 1, 2028.
What are the penalties under the California AI Transparency Act?
The statute sets a civil penalty of $5,000 per violation, and each day of a continuing violation counts as a discrete violation. Enforcement rests with the California Attorney General, a city attorney, or a county counsel. There is no private right of action, so private plaintiffs cannot sue under the statute directly.
Can an advertising agency be fined for AI generated fake reviews?
Yes. FTC staff guidance on the Consumer Reviews and Testimonials Rule states directly that advertising agencies, public relations firms, review brokers, and reputation management companies can be liable. Section 465.2(a) reaches material misrepresentations that the reviewer exists, that they used the product or service, or about their actual experience. Courts may impose civil penalties for knowing violations up to the inflation adjusted maximum, $53,088 under 16 CFR 1.98.
Will federal preemption cancel California’s AI disclosure law?
There is no basis to assume it will. Executive Order 14365, signed December 11, 2025, created a DOJ AI Litigation Task Force, and the FTC proposed a policy statement on July 1, 2026 addressing state laws that require altering the truthful outputs of AI models. A proposed policy statement is not a rule or a court ruling and does not itself preempt any state law. It names Colorado’s AI Act as its example, not California’s provenance labeling regime. As of August 2026 the California AI Transparency Act is operative and has not been enjoined.
What should a small agency do first?
Build a register of every generative AI tool in use and then run one provenance test by pushing AI generated image or video output through your normal delivery pipeline and checking it against that vendor’s free detection tool. Detection is provider specific, so the test tells you about one system, but it reveals in an afternoon whether your workflow preserves embedded disclosures. Policy, contract language, and logging follow from what you learn.
About the author
Ross J. is the founder of Dynamic Comply, an AI governance, compliance, and cybersecurity consulting firm based in Leesburg, Virginia. He brings more than 15 years of federal cybersecurity experience across the Department of State, the Department of Defense, and the Department of Homeland Security, and holds the CGRC certification along with credentials as a GSDC AI Compliance Lead Implementer and Auditor and Certified Ethical Hacker.
Related articles
This article is provided for general informational purposes and reflects the state of the law as of August 2026. It is not legal advice. Regulations in this area are changing quickly. Confirm current requirements and consult qualified counsel before making decisions for your organization.