TwinEthosRequest access

Law

California AB 853

California Attorney General / city attorney / county counsel · California (US-CA) · 3 provisions encoded · verified against the official source as of 2026-08-31.

Informational data, not legal advice. Summaries are TwinEthos's own words and rules have not been reviewed by a lawyer: check the official text before relying on any of it. A guard addresses an item; adding it is not a statement that your code meets any law.

Official text: files.lbr.cloud.

Binding law — not yet in force or stayed

Capture device manufacturers must offer latent provenance disclosure (California)

Cal. Bus. & Prof. Code 22757.3.3(a) · official text · Enacted, not yet applying: applies from 1 Jan 2028 · California (US-CA)

Under California AB 853 (Bus & Prof Code 22757.3.3), a capture device manufacturer must, for any capture device first produced for sale in California on or after 2028-01-01: provide the user an option to include a latent disclosure in captured content conveying the manufacturer name, device name+version, and creation/alteration timestamp; and embed such latent disclosures by default (to the extent technically feasible and standards-compliant). Detect capture-device firmware/software with no latent-provenance option or default embedding.

Who it applies to

  • Duty falls on: provider
  • Systems covered: limited risk
  • Manufacturers of capture devices (cameras, phones w/ cameras/mics, voice recorders) first produced for sale in California on/after 2028-01-01. Operative 2028-01-01; only to the extent technically feasible + standards-compliant.

The guard to add

Organizational artifact to keep (not verifiable from code); the guard is the record, its owner and its upkeep.

Embed a signed C2PA manifest or equivalent latent disclosure in generated or captured media when it is created, and do not distribute systems or files that lack it.

Where media is created (the generation handler after images.generate or a diffusion pipeline, or the capture pipeline in device firmware or camera app), build a provenance manifest stating who and what produced it (provider or manufacturer, system or device name and version, timestamp, unique id) and sign and embed it (c2pa.Builder with builder.sign, c2patool, c2pa-node) before the file is saved, uploaded, or returned. Later re-encode steps preserve the manifest. Where the product distributes generative systems rather than media (a model or weights hosting platform), the publish or listing step checks that each system declares support for latent disclosure and blocks publication otherwise.

Where it goes: 9 AI output handling, 1 application source code, 12 repository artifacts, 14 user-facing text.

What this provision adds:

  • Give the user an option to include a latent disclosure in captured content conveying the manufacturer name, the device name and version, and the creation or alteration timestamp.
  • Embed that latent disclosure by default, to the extent technically feasible and standards-compliant, for capture devices first produced for sale in California on or after 2028-01-01.

Example (c2pa-python), before:

image = pipe(prompt).images[0]
image.save(out_path)

After:

image = pipe(prompt).images[0]
image.save(raw_path)
manifest = {
  'claim_generator_info': [{'name': 'acme-image-service', 'version': '2.3.0'}],
  'assertions': [
    {'label': 'c2pa.actions', 'data': {'actions': [{'action': 'c2pa.created',
      'digitalSourceType': 'http://cv.iptc.org/newscodes/digitalsourcetype/trainedAlgorithmicMedia',
      'when': datetime.now(UTC).isoformat()}]}},
    {'label': 'com.acme.provenance', 'data': {'system': 'acme-image', 'system_version': '2.3.0', 'content_id': str(uuid.uuid4())}}]}
builder = c2pa.Builder(manifest)
with open(raw_path, 'rb') as src, open(out_path, 'w+b') as dst:
    builder.sign(signer, 'image/png', src, dst)   # signer from our load_c2pa_signer()

Control: GenAI content without latent provenance disclosure. The same guard addresses 3 items with binding law in 1 jurisdiction. Engineering guidance, not legal advice.

Rule id ca-ab853.capture-device-latent-disclosure · review status: primary source derived

Binding law — not yet in force or stayed

GenAI hosting platforms must not distribute systems that omit disclosures (California)

Cal. Bus. & Prof. Code 22757.3.2(a) · official text · Enacted, not yet applying: applies from 1 Jan 2027 · California (US-CA)

Under California AB 853 (Bus & Prof Code 22757.3.2), a GenAI system hosting platform (a site/app that makes available for download the source code or model weights of a GenAI system) must not knowingly make available a GenAI system that fails to place the disclosures required by Section 22757.3. Since SB 1000 (in force 2026-09-30) that is the covered provider's latent disclosure in 22757.3(a); the manifest-disclosure option was repealed and the 1,000,000-user threshold on covered providers removed. Operative 2027-01-01. Detect a model-hosting/distribution path with no gate checking that hosted GenAI systems carry the latent-disclosure capability.

Who it applies to

  • Duty falls on: operator
  • GenAI hosting platforms (make GenAI source code or model weights available for download to CA residents). Operative 2027-01-01. The disclosure the hosted system must place is the latent disclosure in 22757.3(a) as amended by SB 1000; before 2029-01-01 the chapter does not apply to a GenAI system designed to primarily function as assistive technology (22757.5(b)).
  • Whether it applies depends on facts outside the code; a person has to decide.

The guard to add

Embed a signed C2PA manifest or equivalent latent disclosure in generated or captured media when it is created, and do not distribute systems or files that lack it.

Where media is created (the generation handler after images.generate or a diffusion pipeline, or the capture pipeline in device firmware or camera app), build a provenance manifest stating who and what produced it (provider or manufacturer, system or device name and version, timestamp, unique id) and sign and embed it (c2pa.Builder with builder.sign, c2patool, c2pa-node) before the file is saved, uploaded, or returned. Later re-encode steps preserve the manifest. Where the product distributes generative systems rather than media (a model or weights hosting platform), the publish or listing step checks that each system declares support for latent disclosure and blocks publication otherwise.

Where it goes: 9 AI output handling, 1 application source code, 12 repository artifacts, 14 user-facing text.

What this provision adds:

  • Gate making GenAI source code or model weights available for download on whether the system places the latent disclosure required by Section 22757.3(a); do not knowingly list one that fails to.

Example (c2pa-python), before:

image = pipe(prompt).images[0]
image.save(out_path)

After:

image = pipe(prompt).images[0]
image.save(raw_path)
manifest = {
  'claim_generator_info': [{'name': 'acme-image-service', 'version': '2.3.0'}],
  'assertions': [
    {'label': 'c2pa.actions', 'data': {'actions': [{'action': 'c2pa.created',
      'digitalSourceType': 'http://cv.iptc.org/newscodes/digitalsourcetype/trainedAlgorithmicMedia',
      'when': datetime.now(UTC).isoformat()}]}},
    {'label': 'com.acme.provenance', 'data': {'system': 'acme-image', 'system_version': '2.3.0', 'content_id': str(uuid.uuid4())}}]}
builder = c2pa.Builder(manifest)
with open(raw_path, 'rb') as src, open(out_path, 'w+b') as dst:
    builder.sign(signer, 'image/png', src, dst)   # signer from our load_c2pa_signer()

Control: GenAI content without latent provenance disclosure. The same guard addresses 3 items with binding law in 1 jurisdiction. Engineering guidance, not legal advice.

Rule id ca-ab853.genai-hosting-platform-gate · review status: primary source derived

Binding law — not yet in force or stayed

Large online platforms must detect and display content provenance (California)

Cal. Bus. & Prof. Code 22757.3.1(a) · official text · Enacted, not yet applying: applies from 1 Jan 2027 · California (US-CA)

Under California AB 853 (Bus & Prof Code 22757.3.1), a large online platform (public-facing social media, file-sharing, mass-messaging, or stand-alone search with >2,000,000 unique monthly users) must: detect standards-compliant provenance data embedded in distributed content; provide a user interface disclosing whether content was GenAI-generated/substantially-altered or captured by a capture device (incl. the system/device name and whether digital signatures exist); let users inspect the provenance data; and must not knowingly strip compliant provenance data or digital signatures. Operative 2027-01-01. Detect a large-platform content-distribution path with no provenance-detection or disclosure UI, or one that strips provenance.

Who it applies to

  • Duty falls on: operator
  • Systems covered: limited risk
  • Large online platforms (>2M unique monthly users; public social media / file-sharing / mass-messaging / stand-alone search) distributing content in California. Operative 2027-01-01. Excludes broadband ISPs and telecom services.

The guard to add

Read embedded C2PA provenance on upload, preserve it through media processing, and show users a Content Credentials indicator with a way to inspect the data.

In the upload or ingest handler, read embedded provenance (c2pa.Reader, c2pa-node, @contentauth/c2pa-web, or a c2patool report) and store the result with the media record: whether credentials are present, the generating system or capture device, and signature validity. Transcoding and thumbnail steps do not strip metadata (no -strip, exiftool -all=, -map_metadata -1, piexif.remove); the signed original is kept so its manifest stays inspectable. The post or media render component shows a badge stating whether provenance is available and what it says, with an inspect panel or link to the full provenance data.

Where it goes: 9 AI output handling, 1 application source code, 14 user-facing text.

What this provision adds:

  • The interface discloses whether content was GenAI-generated or substantially altered, or captured by a capture device, including the system or device name and whether digital signatures exist.

Example (FastAPI + c2pa-python), before:

@app.post('/upload')
async def upload(file: UploadFile):
    data = await file.read()
    s3.put_object(Bucket=PUBLIC_BUCKET, Key=file.filename, Body=data)

After:

@app.post('/upload')
async def upload(file: UploadFile):
    data = await file.read()
    try:
        reader = c2pa.Reader(file.content_type, io.BytesIO(data))
        provenance = json.loads(reader.json())
    except Exception:   # no manifest or unreadable
        provenance = None
    key = f'media/{uuid.uuid4()}'
    s3.put_object(Bucket=PUBLIC_BUCKET, Key=key, Body=data)   # original bytes, manifest intact
    db.media.insert(key=key, provenance=provenance, has_credentials=provenance is not None)

Control: Large online platform doesn't detect/display content provenance. The same guard addresses 1 item with binding law in 1 jurisdiction. Engineering guidance, not legal advice.

Rule id ca-ab853.platform-provenance-detection-and-display · review status: primary source derived