Skip to content
← BlogCompliance6 min read

California's new AI content law kicks in August 2. Does it touch your outreach?

California's AI Transparency Act becomes operative August 2, 2026, requiring AI content detection and disclosure tools. Here's who it actually covers.

By David Lara, Founder

Founder-reviewed ·How we research and correct articles

California’s AI Transparency Act becomes operative on August 2, 2026 — a date the legislature picked on purpose to land the same week the EU AI Act’s own transparency obligations kick in. The law started life as SB 942, got substantially rewritten and delayed by AB 853, which Governor Newsom signed on October 13, 2025, and now arrives with a broader scope than the original version had. If you send any kind of AI-assisted marketing or outreach and California is in your audience, it’s worth ninety seconds to figure out whether this one is actually about you.

What the law actually requires

Starting August 2, 2026, a “covered provider” — defined as anyone who creates, codes, or otherwise produces a generative AI system with more than one million monthly visitors or users, publicly accessible in California — has to do three specific things: offer a free AI content detection tool that lets a user check whether an image, video, or audio file was created or altered by that system; give users the option to attach a visible “manifest” disclosure to AI-generated content; and embed a latent, machine-readable disclosure — provenance data baked into the file itself — in any AI-generated image, video, or audio output. Two later milestones extend the same logic further out: large online platforms and generative-AI hosting platforms get pulled in starting January 1, 2027, and capture-device manufacturers (cameras, phones) have to offer latent-disclosure options in new devices from January 1, 2028.

Who this actually covers

Read the threshold again: covered providers are generative AI systems with over a million monthly users. That’s a bar built for the handful of companies operating large public-facing image, video, and audio generation models — not for a business using an AI tool to draft outreach copy or an agency running client campaigns. If you’re not a platform other companies build on top of, this law’s August 2 obligations almost certainly aren’t landing on your desk directly.

Two caveats are worth knowing anyway, because they show where the law is headed rather than where it stops today:

The law is about image, video and audio — not text. A cold email drafted with AI assistance isn’t the kind of “AI-generated content” this statute regulates. If your outreach involves AI-generated video prospecting content or voice-cloned calling at real scale, though, you’re closer to the kind of output this law was written for, and the platforms you build that on may themselves become covered providers.

The January 2027 expansion reaches further than the platforms building the models. “Large online platforms” and “generative AI hosting platforms” is a broader category than “the company that trained the model,” and exactly how that phrase gets applied to marketing and outreach tooling is the kind of thing that gets clarified through the first few enforcement actions and guidance documents, not through the statute’s text alone.

It’s worth noting why the threshold sits where it does, too. AB 853’s expansion targeted platforms large enough to be the actual source of AI-generated deepfakes and synthetic media at scale — the million-monthly-user bar deliberately keeps the detection-tool and embedded-metadata obligations off a small business or agency that’s a customer of those platforms, not a builder of one. That’s a design choice, not an oversight, and it’s why this law reads very differently from a general cold-email or CAN-SPAM-adjacent rule that applies regardless of size.

The direction matters more than this specific deadline

Even where CAITA doesn’t reach you directly, it’s one more entry in a pattern that’s been building all year: regulators moving from “disclose that AI was involved” toward “prove, with embedded metadata, what was AI-generated and what wasn’t.” Chatbot disclosure rules are already binding in multiple jurisdictions, and transparency obligations under frameworks like the EU AI Act’s Article 50 are running on a similar timeline to CAITA’s own. None of that is scoped to email today. All of it points toward provenance and disclosure becoming a baseline expectation for any AI-assisted content, text included, sooner rather than later.

California CAITA (AB 853)EU AI Act, Article 50Chatbot disclosure laws
What triggers itGenerative AI content: image, video, audioAI-generated or manipulated content and AI system interactionsA person talking to an AI, not a human
What it requiresDetection tool + visible/latent disclosureLabeling of AI-generated content and disclosure of AI interactionClear notice that you're talking to an AI
Covers text-based cold email today
Operative dateAugust 2, 2026August 2, 2026 (GPAI/transparency)Already binding in several jurisdictions
Different mechanisms, same instinct: prove what's real and who's on the other end of it.

None of these three regimes reach a plain-text cold email today — that’s the reassuring headline. But three regulatory efforts, in three jurisdictions, converging on the same demand within one year tends to widen rather than stay put. The safe assumption isn’t “this doesn’t apply to me, so ignore it.” It’s “not yet — build toward it now instead of scrambling later.”

California AI Transparency Act — quick answers

Does this law apply to my cold-email tool or agency?

Almost certainly not directly. The August 2, 2026 obligations apply to "covered providers" — generative AI systems with more than one million monthly users in California. Most businesses using AI to draft outreach, and most agencies running campaigns for clients, are users of AI tools rather than covered providers of one.

What if I use AI to write my cold emails?

The law's disclosure and detection requirements cover AI-generated image, video, and audio content, not text. Using AI to draft email copy isn't the activity this statute regulates, though the broader transparency trend it's part of is moving toward text as well.

Is this the same as the EU AI Act?

No, they're separate laws, but their August 2, 2026 dates were deliberately aligned. California's law extended its own operative date specifically to land alongside the EU AI Act's transparency and GPAI enforcement milestone, so the two are worth tracking together even though they come from different jurisdictions with different scopes.

What should I actually do about it right now?

If you're not a covered provider, nothing is mandatory today. The useful move is building good habits ahead of the requirement: accurate sender identity, no impersonation in AI-assisted content, and authentication that proves who actually sent a message — all of which put you ahead of where this regulatory direction is heading, regardless of when or whether it becomes mandatory for your specific tooling.

Where Norbelys already sits on this

The through-line across every version of this regulation, from CAITA to the EU AI Act to the chatbot-disclosure laws already in force, is provenance: being able to prove who — or what — actually produced a piece of content and who sent it. That’s not a new requirement for Norbelys. Every message sent through the platform authenticates against your domain’s own DKIM and DMARC records, so recipients and their mail providers can already verify exactly who sent it — the same “prove what’s real” instinct this whole wave of AI legislation is built around, applied to the sending side instead of the content side. Combined with suppression-list enforcement and California’s existing outreach rules under the CCPA/CPRA, Norbelys is built for a compliance direction that isn’t slowing down. Check your domain’s authentication setup and see how far ahead of this trend your sending already is — or start fresh on a platform built for it from day one.