California SB 942 vs EU Article 50: what applies to you
Two AI content transparency regimes, two different targets. A side-by-side read of who each one binds, what it demands, and how to satisfy both without running two pipelines.
Published 14 August 2026 · Authentrail
Two AI content transparency regimes now matter to anyone publishing at scale: Article 50 of the EU AI Act (Regulation (EU) 2024/1689) and California's SB 942, the AI Transparency Act. They are frequently discussed as if they were the same law in two jurisdictions. They are not. They bind different parties, demand different artefacts, and fail in different ways — and understanding which one lands on you determines whether you are building a signing pipeline or a vendor-management process.
The core difference: who is on the hook
This is the distinction everything else follows from.
SB 942 targets the tool. It places obligations on covered providers of generative AI systems — measured by user volume — requiring them to offer detection capability and to attach provenance disclosures to what their systems produce. The statute is aimed at the companies operating the generators, not at the marketing department using one.
Article 50 targets both the tool and the publisher. The EU AI Act splits duties between providers and deployers, and it gives deployers obligations of their own. A team that publishes AI-generated content it did not create still carries an Article 50 duty. That is why Article 50 is the one that reaches agencies, publishers, and in-house content teams directly.
If you publish rather than build, the practical summary is: Article 50 binds you directly; SB 942 shapes the market you buy from and drives what your clients and platforms will ask you to demonstrate.
What each one asks for
SB 942 — latent and manifest disclosures
California's framework distinguishes two kinds of disclosure. A latent disclosure is embedded in the content itself — metadata identifying the content as AI-generated, the system that produced it, and the time of production, conveyed in a way that is detectable by a decoding tool but not visible to a casual viewer. A manifest disclosure is the visible, user-facing kind: clear, conspicuous, and appropriate to the medium. Covered providers must offer latent disclosure and must make manifest disclosure available as a user option, alongside a free public detection tool that lets anyone check whether content came from that system.
Article 50 — marking, deepfake disclosure, and text
Article 50 requires that generative outputs be marked in a machine-readable format and detectable as artificially generated, that deepfakes be disclosed as artificially generated or manipulated, and that AI-generated text published to inform the public on matters of public interest be disclosed under Article 50(4) unless it has undergone human review with someone holding editorial responsibility. Chatbots and other systems interacting directly with people must disclose that they are AI.
The two regimes converge on the technical answer even where the legal structures differ. SB 942's latent disclosure and Article 50's machine-readable marking are both satisfied in practice by C2PA Content Credentials — a signed manifest embedded in the file using the IPTC digitalSourceType vocabulary, independently verifiable at verify.contentauthenticity.org. One correctly implemented signing pipeline addresses the embedded-metadata half of both. Our C2PA implementation guide covers the mechanics.
Territorial reach
Both regimes reach beyond their own borders, by different routes.
The AI Act follows the output: it applies where a system's output is used in the Union, regardless of where the publisher is established. A Dubai agency or a New York studio publishing AI-generated campaign material that reaches EU audiences falls inside Article 50, with no establishment test to opt out of.
SB 942 applies through California's standard hook: providers doing business in California and making systems publicly available to Californians. For a publisher, the relevant consequence is indirect but real — the generative tools you use will increasingly ship provenance by default because their own compliance requires it, and your obligation becomes not to destroy what arrives already attached.
Penalties
Article 50 breaches can draw administrative fines of up to €15 million or 3% of total worldwide annual turnover, whichever is higher, enforced by national market surveillance authorities. SB 942 operates on a per-violation civil penalty model with daily accrual, enforced through California's civil enforcement route. The structures are different enough that comparing headline numbers is not very informative; the operative difference is that the EU figure can attach to a publisher directly, while the California figure principally attaches to the system provider.
Timing
The AI Act entered into force in August 2024 and applies its obligations on a staggered schedule; the Article 50 transparency obligations became enforceable on 2 August 2026. That date has passed, which changes the character of the conversation internally — this is no longer a roadmap item to be scheduled against other priorities, and a library that is unmarked today is exposed today.
California's AI Transparency Act carries its own 2026 compliance date for covered providers. The practical effect for publishers arrives slightly ahead of the legal one: the generators you buy from begin shipping provenance by default in order to meet their own obligations, which means AI evidence starts arriving in your library whether or not you asked for it. Assets that used to be silently unattributable now announce themselves — and an asset that announces itself as AI-generated, published without marking, is a much easier thing for a complainant to point at.
The wider US patchwork
California is not alone, and treating it as the whole US picture is a mistake that ages badly. Utah has enacted digital content provenance requirements, and additional states have bills at various stages. Federal legislation has been proposed repeatedly and has not produced a binding general marking mandate.
For planning purposes, treating California SB 942 as the strictest current US baseline is the pragmatic call. It is the most demanding enacted state regime, and content that satisfies it is unlikely to fall short of a lighter state rule. What that does not do is remove the need to keep watching: the patchwork is still forming, and a per-state segmentation strategy is a maintenance burden that grows monotonically.
Where the UAE fits
Teams operating in the Gulf ask about this constantly, and the honest answer is that the legal position is different in kind. The UAE's PDPL contains no synthetic-media marking mandate. Provenance disclosure is recommended practice under the UAE AI Charter and related deepfake advisory guidance, not a statutory requirement.
The pressure there is procurement, not enforcement. GovTech and large enterprise tenders increasingly ask suppliers to demonstrate content provenance, and an unmarked library is a disqualifier in a bid long before it is a legal problem. That means UAE exposure should be reported as procurement readiness rather than compliance — a distinction worth keeping in your reporting, because conflating them produces false alarms that erode trust in the whole process.
One pipeline, three verdicts
The temptation when facing several regimes is to segment: mark EU-facing content, leave the rest. In practice this fails, because content libraries are reused across markets and the audience's jurisdiction governs rather than the publisher's. An asset made for a US campaign ends up on a global site three months later.
The maintainable approach is a single pipeline that marks everything to the strictest applicable standard, combined with per-region reporting so you can see the different verdicts an asset attracts:
- EU: AI evidence without machine-readable marking is a violation. Unknown origin requires attestation or marking — the deployer bears the burden of knowing what is synthetic.
- US: AI content without latent disclosure fails the California baseline. No AI evidence means state provenance laws are not triggered.
- UAE: Never a violation, but AI content without provenance is flagged as procurement risk.
The same scan produces all three. That is the design Authentrail uses — every asset is evaluated against EU, UAE, and US rules simultaneously, so a multinational team sees its full exposure in one pass rather than running three processes and reconciling them.
What to do this quarter
If you publish content and have not started: scan your library, find out how much of it carries AI evidence without marking, and remediate that bucket first — it is the one that is unambiguously a violation under both regimes today. Then decide a policy for unknown-origin assets, because that bucket will be larger than the first one and no amount of detection will resolve it for you.
Read the Article 50 guide for the obligation that most likely binds you directly, or run a scan on the homepage to see what your own files declare. Pricing is here.
This guide is general information about published regulatory requirements, not legal advice. Confirm your obligations with qualified counsel before relying on them.