Published 13 August 2026. How American states are regulating AI content provenance, and why it looks nothing like the EU's single statute.
While the European Union regulates AI through one omnibus law, the United States is doing it state by state. The result in 2026 is a patchwork: no federal AI transparency statute, but a fast growing set of state laws that mandate provenance marking, disclosure, and in some cases a free public detection tool. If you generate or publish AI content that reaches Americans, the relevant rules increasingly depend on which state your users are in. This guide walks the most important ones and draws out the common threads. It is background, not legal advice.
The headline law is California's AI Transparency Act, SB 942. After amendment by AB 853, its operative date is 2 August 2026, with additional obligations on large hosting platforms following on 1 January 2027. You can read the bill at California's legislative site.
SB 942 applies to covered providers: entities that build a generative AI system with more than one million monthly users that is publicly accessible in California. Covered providers must do several concrete things.
The latent disclosure is where California and C2PA meet. As amended, the law expects a C2PA compatible latent provenance mark carrying specific fields.
Read alongside our C2PA explainer, this is the same provenance metadata approach, now backed by a state mandate and a required detection tool. Note what it does not cover: SB 942's provenance duties target image, video, and audio, not plain text, which mirrors the technical reality that text and media carry provenance very differently.
Colorado took a different tack. The Colorado AI Act, SB 24-205, focuses on preventing algorithmic discrimination in high risk systems through a duty of reasonable care, plus a requirement that consumer facing AI disclose that a person is interacting with a machine. In 2026 the framework was reworked: SB 26-189, signed 14 May 2026, repealed and reenacted the Act, moving the core automated decision making duties to 1 January 2027. Colorado is less about watermarking media and more about fairness and up front chatbot disclosure, but it is part of the same transparency wave.
Utah's HB 276 on digital content provenance pushes past generic disclosure toward technical traceability. It requires companies that generate or host image, video, or audio content to preserve provenance metadata and to support takedown workflows for non consensual synthetic media. That combination, keep the provenance and enable removal of abusive deepfakes, signals where a lot of state law is heading: not just a label, but an auditable trail.
SB 942 does not stop at the companies that generate content. A second wave of obligations, beginning 1 January 2027, reaches large hosting platforms, the services where AI content is distributed. The direction is to make provenance and disclosure a property of the whole pipeline, not just the point of generation, so that a credential applied at creation is more likely to survive to the point a viewer actually encounters the content. For anyone planning ahead, that 2027 date matters as much as the 2026 one, because it changes what distribution partners will expect from the files you hand them.
The licensee provision is the quiet companion to this. Because a covered provider must contractually require its licensees to preserve disclosure capability, the duty propagates down the supply chain by contract. If you integrate a large model into your own product, expect that preservation requirement to arrive in your agreement, and design your handling so you do not strip the very marks you are now bound to keep.
If provenance marking is the headline, chatbot disclosure is the rule spreading fastest and hitting the most businesses. A growing set of states now require that a person interacting with an AI system be told so, clearly and up front, unless it is obvious from context. The rationale is the same transparency principle as the EU's direct interaction duty: people should not be tricked into thinking a machine is a human. In practice this is a low cost change, a short, visible notice on a chatbot or voice agent, but the laws are specific enough that a buried or ambiguous disclosure may not satisfy them. Several states extend the idea further for sensitive contexts, adding stricter rules where the person on the other end may be a minor.
Transparency law is not confined to synthetic media and chatbots. A parallel track targets AI in consequential decisions, especially employment. Several states now require notice, and sometimes explanation, when AI tools are used in hiring or other high stakes determinations, and Colorado's framework centers on preventing algorithmic discrimination in exactly these high risk uses. For a business, this means the compliance question is broader than watermarking: it is anywhere AI touches a decision or a communication that a person has a right to understand. Provenance is one piece of a wider transparency expectation.
Step back from the individual statutes and four themes recur across nearly every 2026 state law:
The direction of travel is unmistakable, even without a federal law: mark AI media, disclose AI interactions, and keep the provenance intact.
If you are a large generative AI provider, California's thresholds may already capture you, and the detection tool plus latent disclosure obligations are concrete engineering work. If you are a business that merely uses AI, the practical takeaways echo the EU picture: preserve the provenance marks your tools attach, disclose AI interactions and synthetic media where a reasonable person would expect to know, and do not rely on a third party detector as proof of anything, given the documented error rates. And if you operate across states, assume the strictest applicable rule rather than betting on the gaps between them.
Finally, the same honesty caveat applies as everywhere on this site. These laws create duties to mark and disclose. They do not create a magic universal detector, and they cannot change the fact that a keyed text watermark is unreadable without the provider's key. Compliance is about process and provenance, not about proving a negative with a score.
Because the map is a patchwork and still filling in, the smart posture is to prepare for the direction of travel rather than any single statute. That means three habits. Keep the provenance signals your tools attach, so you are ready for marking and preservation duties wherever they land. Build a simple, consistent disclosure practice for synthetic media and AI interactions, so you satisfy chatbot and deep fake rules without scrambling. And maintain a light audit trail of what was AI generated and what was disclosed, so you can show reasonable process if asked. Do those three things and you are broadly aligned with California, Colorado, Utah, and whatever the next state adds, without having to re engineer your process each time a bill passes.
Is there a federal US AI transparency law? As of 2026, no single federal statute mandates AI content disclosure the way the EU AI Act does. Regulation is happening at the state level, which is why the picture is a patchwork.
Does California SB 942 apply to my small business? Its provenance duties target covered providers, generative AI systems with more than a million monthly users. A small business using AI is more likely affected by chatbot disclosure rules and by the preservation duties that flow down through contracts from large providers.
What is the difference between manifest and latent disclosure? A manifest disclosure is a visible label a user can choose to add. A latent disclosure is a machine readable provenance mark embedded in the content, carrying details like the system name and a timestamp.
Do these laws require watermarking text? The provenance and detection duties focus on image, video, and audio. Text is treated differently, reflecting that a text watermark is keyed and not third party readable.
Related: EU AI Act Article 50 explained · C2PA content credentials · AI detector false positives