AI Transparency Is Here: What California’s SB 942 & EU Article 50 Mean for Marketers
Last week two AI transparency laws came into effect that Is going to change how marketers and businesses continue to use AI content.
California’s AI Transparency Act (SB 942) and the EU AI Act’s Article 50 transparency rules went live on the same day – Aug 2nd 2026. At a high level, both say the same thing in different words — if AI touched it, the content has to say so, and that mark has to survive distribution.
Actually, both the laws becoming operative wasn’t a coincidence. California’s legislature moved the operative date from January 1 to August 2, 2026, bringing it into alignment with the EU AI Act’s Article 50 timetable. Together, these represent two of the most significant AI-transparency regimes now coming into force in major Western markets, and they’re going to change how marketing teams brief, produce, and publish content.
However, the regulations came with a plethora of open questions for marketers and technologists alike.
- What is AI-generated content under this laws?
- Who’s actually on the hook?
- And for how much
- Are we operationally and technologically ready for this?
- What about false positives?
- Next martech opportunity?
- Provenance integrity for vendor selection
- AI SDR and Voice Assitants
- Disclose practices for campaigns
What is AI-generated content under this laws?
Under SB 942, it’s synthetic content – text, images, video, or audio that’s created or substantially altered by a generative AI system.
The law requires two kinds of disclosure:
Latent disclosure: hidden, machine-readable metadata embedded in the file (think C2PA-style provenance data) that a detection tool can read
Manifest disclosure: a visible, user-facing disclosure identifying content as AI-generated.
But this is an important distinction: covered providers must offer users the option to include this type of disclosure. The California law does not simply require every end user or marketer to visibly label everything AI touched.
Under the EU’s Article 50, the scope is broader. It covers four distinct situations: AI systems that interact directly with people (chatbots, voice assistants), AI-generated or manipulated content, emotion recognition and biometric categorization tools, and deepfakes or AI-written text on matters of public interest published without human editorial review.
Now the question that I am still asking myself as a marketer – what is meant by “substantially altered”.
It is a subjective term – what is substantial to me might not be substantial to you or vice versa. Similarly what is considered “AI-generated/manipulated” content? If a designer cleans out the background of a stock photo using a AI and then creates a completely new design manually or a writer uses AI to just tighten a manually-written composition does it all fall under AI-generated/manipulated?
Who’s actually on the hook?
SB 942 only applies to “Covered Providers” – companies that create, code, or produce a generative AI system with more than one million monthly visitors or users, publicly accessible in California. This is a developer-level obligation. It targets the companies building the AI tools (OpenAI, Midjourney, Adobe, etc.), not the businesses using them. If you’re a marketer using ChatGPT or Midjourney, you’re not directly regulated but your vendor is, and their compliance gaps become your risk.
The regulation also states that a covered provider must make an AI detection tool available at no cost, publicly accessible, capable of assessing image/video/audio content, and capable of accepting uploads or URLs; it must also support an API.
The EU AI Act on the other side draws a wider net.
It distinguishes providers (who build and place a system on the market) from deployers (who use it under their own authority) and both carry obligations. If your agency or brand is deploying AI systems that interact with EU users (a chatbot on your site, an AI voice assistant, emotion-detection in ad testing), you may have direct deployer duties, not just a downstream dependency on your vendor.
And for how much?
SB 942 penalties run at $5,000 per violation, per day, and this is the detail most people miss – enforcement isn’t limited to the California Attorney General. City attorneys and county counsel can bring civil actions too.
Thankfully, there’s no private right of action, so competitors or consumers can’t sue directly, but the number of government actors who can is much wider than people assume.
The EU side could have far more devastating impact: fines up to €15 million or 3% of worldwide annual turnover, whichever is higher. And Article 50 applies extraterritorially – a UK or US company serving EU users is in scope regardless of where it’s headquartered.
Some more questions that are going on in my head:
Are we operationally and technologically ready for this?
Having provenance information or an AI watermark on an asset at the point of creation is one thing. Being able to retain or verify that information through a complex publishing workflow is another.
We create an asset using an AI tool. It then passes through multiple rounds of edits and resizes, through DAMs and CDNs, and finally into the CMS.
Are all of these systems equipped to retain the relevant provenance information?
And perhaps even more importantly: can we tell when that information has been stripped, modified or lost?
What about false positives?
A fully human-created photo or video could be incorrectly associated with AI because of faulty detection, metadata confusion or other technical issues. Conversely, the absence of provenance metadata doesn’t necessarily prove that content was not generated or manipulated by AI.
That’s not just a brand safety problem. Depending on how these regimes evolve and how organisations represent their content provenance, it could become a compliance and reputational problem too.
Is this the next Martech opportunity?
Every popular CMS, DAM and CDN in our stack was built primarily for storage, transformation and delivery — not for end-to-end content provenance.
That gap won’t close itself.
Someone needs to build the tooling.
I wouldn’t be surprised if, in the next 12–18 months, we see a new martech or content-governance category whose entire job is tracking whether provenance information survives the publishing path and generating the audit trail legal and compliance teams will eventually ask for.
Marketing teams may increasingly adopt these capabilities simply because the alternative is another layer of boring, manual compliance work trying to keep themselves safe.
Vendor due diligence is quietly becoming a compliance function
Provenance integrity is likely to become a meaningful vendor-selection criterion as these requirements mature.
Which AI tools in your stack actually embed machine-readable provenance information?
Which systems preserve it?
Which ones strip it out?
Which ones can tell you what happened to it along the way?
Several major generative platforms and publishing workflows still have different levels of provenance support and interoperability. That’s increasingly becoming a real vendor-selection question, not a nice-to-have.
What happens to all the AI SDRs and voice assistants?
We have all seen significant growth and adoption of these tools in recent times.
Under Article 50, providers of AI systems intended to interact directly with people generally need to design those systems so people are informed that they are interacting with AI, unless that is already obvious from the circumstances and context.
That brings marketing chatbots, AI SDRs and voice assistants on EU-facing properties into the conversation.
The exact obligation will depend on who is the provider, who is the deployer, and how the system is presented. But the days of treating disclosure as an afterthought are probably over.
Disclosure practices for campaigns also need a second look.
If you’re running AI-generated images, video, voiceovers or synthetic avatars in ads, social content or influencer-style content, you need to understand both the underlying platform’s compliance posture and your own obligations under the markets in which the content is being used.
And this is bigger than one law or one compliance exercise.
California already has multiple AI-related laws on the books with different operative dates and requirements, while additional obligations under the EU AI Act continue to phase in through 2027 and 2028.
This isn’t a one-time compliance exercise.
It’s becoming a new, ongoing category of marketing risk, vendor governance and process.
Content provenance is moving from a “nice ethical practice” to something that is increasingly regulated in specific contexts and markets.
And marketing teams that treat AI content disclosure purely as a creative or brand-voice decision may be missing the bigger picture.
It’s now also a legal, operational and technology decision.
To me, all of this is not just about compliance. It’s kind of a pattern that I am seeing.
We adopted the technology faster than we built the operational muscle — the inventory, the vendor clauses, the workflows, the controls and the audit trails to govern it responsibly.
The law is just forcing that conversation earlier than we’d probably have had it on our own.










Leave a Reply