CA AI Transparency Act Takes Effect — Midjourney Lacks C2PA
- O que aconteceu
- California's AI Transparency Act (SB 942) became operative August 2, requiring AI-generated images, video, and audio to carry C2PA provenance metadata. Midjourney — a Content Authenticity Initiative member since 2023 — ships with no compliant watermark on Day 1, according to TechTimes, facing potential $5,000/day fines per violation.
- Porque é importante
- This is the first US state law with enforceable AI content provenance requirements. The August 2 date was deliberately synchronized with the EU AI Act's Article 50 enforcement, creating a transatlantic provenance standard. California's decentralized enforcement — AG plus city attorneys with fee-shifting — makes local prosecution viable.
- O que fazer
- If you deploy AI-generated content in California, verify your provider's C2PA compliance today. If you use Midjourney, your outputs carry no provenance signal — plan for environments where that matters. Watch for the first enforcement action; it will set precedent.
California's AI Transparency Act — Senate Bill 942 — is now enforceable. As of August 2, 2026, any generative AI system with more than one million monthly users in California must embed C2PA provenance metadata in every image, video, and audio output. Midjourney — a Content Authenticity Initiative member since 2023 — shipped with no compliant watermark and no public detection tool on Day 1, according to TechTimes analysis, making it the most prominent non-compliant tool under the new law.
SB 942 Is Now Enforceable
SB 942, signed into law in 2025, became operative August 2 with three enforceable requirements for covered generative AI providers, per the statute text(abre num novo separador):
- Free public detection tool — accessible without an account, supporting file uploads and URLs, with an API for programmatic access. Personal data cannot be collected from users submitting content for verification.
- Visible AI label option — users must be able to apply a permanent, human-readable "AI-generated" label to their outputs.
- Embedded provenance metadata — every AI-generated image, video, or audio output must carry machine-readable C2PA provenance data by default, identifying the provider name, system name and version, and creation timestamp.
Text-only outputs are excluded from all three requirements. Fines: $5,000 per violation, per day — and each deficiency counts as a separate violation.
Midjourney's Day 1 gap
Midjourney is the most significant non-compliant tool on the law's first day. Despite joining the Content Authenticity Initiative in 2023, the company has not shipped C2PA content credentials or a pixel-level watermark, per TechTimes analysis(abre num novo separador). With over 20 million registered users as of 2023, its California user base almost certainly exceeds the one-million-monthly threshold — though Midjourney does not publicly disclose state-level user counts.
The penalty math is aggressive. Each deficiency counts as a separate violation, and each day of non-compliance is a discrete violation. A provider that fails to deploy a detection tool for 30 days faces potential exposure of $150,000 from that single gap — before attorney's fees. Unlike California's CCPA enforcement regime, SB 942 includes no general notice-and-cure period.
Midjourney has not made a public statement about its SB 942 compliance plans or a C2PA implementation timeline. We rate Midjourney Conditional — still the strongest AI image generator for artistic quality, but its active non-compliance with SB 942 and the EU AI Act exposes commercial users to regulatory risk.
Enforcement architecture
The enforcement architecture is more decentralized than any prior US AI regulation:
- California Attorney General holds primary authority. AG Rob Bonta has described building an "AI oversight, accountability and regulation program" amid federal inaction.
- City attorneys and county counsel may bring civil actions under the law, with fee-shifting that requires prevailing plaintiffs to recover attorney costs — lowering barriers for local prosecutors.
- The 96-hour licensee revocation rule requires providers to revoke licenses within 96 hours if a third-party licensee modifies a system in a way that makes provenance compliance technically impossible. This targets the open-source ecosystem: providers cannot insulate themselves by licensing to downstream operators who strip the provenance requirements.
Synchronized with the EU
The August 2 date was chosen deliberately to align with the EU AI Act's Article 50 enforcement schedule, according to TechTimes. The European Commission published its official Day 1 statement(abre num novo separador) on August 2, confirming that transparency obligations — chatbot disclosure, synthetic content marking, and deepfake labeling — are now enforceable across all 27 EU member states, with fines up to €15 million or 3% of global annual turnover.
The convergence creates a transatlantic provenance standard: providers that build C2PA-plus-watermarking infrastructure for EU compliance simultaneously satisfy California's requirements. For regulators, it's a compounding deterrent — a provider that ignores both regimes faces exposure from both sides.
Why it matters
This is the first US state law with real teeth for AI content provenance. For two years, the AI policy conversation has been dominated by Washington — export bans, framework deadlines, congressional hearings. California just bypassed all of it and enacted a law that is enforceable today, with penalties that accumulate daily.
For the AI tool ecosystem, the operative question is no longer "will there be AI regulation?" It's "which tools are compliant, and which are Midjourney?"
The watermark gap
One structural limitation: C2PA metadata is stripped when images are uploaded to Instagram, reposted on X, or sent through WhatsApp. A May 2026 study by Presenc AI(abre num novo separador) found that while 75-85% of AI-generated images carry provenance signals at generation, only 30-50% still carry them when distributed online.
SB 942 addresses this with two mechanisms. The "to the extent technically feasible and reasonable" language gives providers interpretive flexibility. More significantly, the January 1, 2027 phase will require large online platforms — social media networks, search engines, and mass-messaging services with more than two million unique monthly users — to detect, preserve, and surface C2PA provenance data, and explicitly prohibit knowingly stripping it. That obligation begins in five months.
SB 1000 could change the rules immediately
A pending urgency bill, SB 1000, passed the California Senate 33-1 in May and is awaiting an Assembly floor vote, according to TechTimes. If signed by Governor Newsom, it would take effect immediately and make three material changes: remove the one-million-user coverage threshold (bringing all providers in scope regardless of user count), delete the manifest-disclosure requirement (the visible AI label option), and revise the detection-tool and latent-disclosure rules. Any compliance posture built on the current text should verify SB 1000's status before finalizing.
What changes for you
- If you deploy AI-generated images, video, or audio in California: Verify your provider's C2PA compliance status today. The detection infrastructure now exists — use it.
- If you're a Midjourney user: Your outputs carry no provenance signal. Missing credentials don't prove content isn't AI-generated, but they do mean it's not coming from a compliant provider. Plan for environments where provenance matters.
- If you're tracking AI regulation: California's AG-plus-city-attorney enforcement model, combined with the EU's parallel activation, creates the first real transatlantic enforcement architecture for AI. Watch for the first enforcement action — it will set precedent for every provider.
FAQ
Which AI companies must comply with SB 942?
Any provider with a generative AI system exceeding one million monthly California users. OpenAI, Google, Adobe, and Meta have deployed C2PA content credentials or SynthID watermarks. Midjourney has not.
Does a missing watermark mean content is not AI-generated?
No. Images from non-compliant generators like Midjourney or self-hosted open-weight models carry no provenance signal at all. Missing C2PA metadata proves only that the content was not generated by a compliant provider.
Ferramentas e modelos afetados
Nunca mais precisas de te pôr a par
O resumo semanal — apenas mudanças de veredicto e ações urgentes. Sem enchimento.