AI disclosure · California · updated
California AB 853: platforms from 1 January 2027, capture devices from 2028
AB 853 (Chapter 674, Statutes of 2025) puts provenance duties on large online platforms. Their section, Business and Professions Code § 22757.3.1, ends: “This section shall become operative on January 1, 2027.” (Cal. Bus. & Prof. Code § 22757.3.1(c), applies from 1 January 2027). From that day a large online platform has to detect provenance data in what it distributes, show users what it says, and not knowingly strip it.
Large online platforms
““Large online platform” means a public-facing social media platform, file-sharing platform, mass messaging platform, or stand-alone search engine that distributes content to users who did not create or collaborate in creating the content that exceeded 2,000,000 unique monthly users during the preceding 12 months.”
“Detect whether any provenance data that is compliant with widely adopted specifications adopted by an established standards-setting body is embedded into or attached to content distributed on the large online platform.”
“A large online platform shall not, to the extent technically feasible, knowingly strip any system provenance data or digital signature that is compliant with widely adopted specifications adopted by an established standards-setting body from content uploaded or distributed on the large online platform.”
The platform also has to provide a user interface that discloses whether provenance data is available, the name of the GenAI system or capture device, and whether digital signatures are available, and let users inspect the system provenance data (§ 22757.3.1(a)(2)–(3)).
GenAI hosting platforms, from 1 January 2027
“A GenAI system hosting platform shall not knowingly make available a GenAI system that does not place disclosures pursuant to Section 22757.3.”
Capture devices, from 1 January 2028
“This section shall become operative on January 1, 2028.”
For devices first produced for sale in California on or after 1 January 2028, the manufacturer offers a latent disclosure with its name, the device's name and version, and the time and date, embedded by default (§ 22757.3.3(a)).
Penalties
“A violator of this chapter shall be liable for a civil penalty in the amount of five thousand dollars ($5,000) per violation to be collected in a civil action filed by the Attorney General, a city attorney, or a county counsel.”
“Each day that a covered provider, large online platform, or capture device manufacturer is in violation of this chapter shall be deemed a discrete violation.”
Check what survives your pipeline
$ npx --allow-git=root github:agentwares/agent-disclosure output https://cdn.your-site.example/uploads/image.jpgFetches the file once, as your platform serves it, and reports whether a C2PA manifest and its signature are still there: the provenance data § 22757.3.1(b) says not to strip.
A signed readiness report
The free checks print everything they find. The Article 50 readiness report ($49, one-time, no account) is the same checks for up to 10 URLs and 25 artefacts, dated and hash-signed, as PDF and JSON, to keep or hand over.
Keep a dated record of every check, and of every disclosure and marking you ship
okgate keeps every tool call your agents make in a hash-chained audit log with daily Merkle roots on a public page: 90 days on Pro ($99/month), 365 days with a compliance export on Team ($299/month).
A record of your disclosure and marking checks, kept the same way, is not built yet. I want that record