Binding law — not yet in force or stayed
Capture device manufacturers must offer latent provenance disclosure (California)
Under California AB 853 (Bus & Prof Code 22757.3.3), a capture device manufacturer must, for any capture device first produced for sale in California on or after 2028-01-01: provide the user an option to include a latent disclosure in captured content conveying the manufacturer name, device name+version, and creation/alteration timestamp; and embed such latent disclosures by default (to the extent technically feasible and standards-compliant). Detect capture-device firmware/software with no latent-provenance option or default embedding.
Who it applies to
- Duty falls on: provider
- Systems covered: limited risk
- Manufacturers of capture devices (cameras, phones w/ cameras/mics, voice recorders) first produced for sale in California on/after 2028-01-01. Operative 2028-01-01; only to the extent technically feasible + standards-compliant.
The guard to add
Organizational artifact to keep (not verifiable from code); the guard is the record, its owner and its upkeep.
Embed a signed C2PA manifest or equivalent latent disclosure in generated or captured media when it is created, and do not distribute systems or files that lack it.
Where media is created (the generation handler after images.generate or a diffusion pipeline, or the capture pipeline in device firmware or camera app), build a provenance manifest stating who and what produced it (provider or manufacturer, system or device name and version, timestamp, unique id) and sign and embed it (c2pa.Builder with builder.sign, c2patool, c2pa-node) before the file is saved, uploaded, or returned. Later re-encode steps preserve the manifest. Where the product distributes generative systems rather than media (a model or weights hosting platform), the publish or listing step checks that each system declares support for latent disclosure and blocks publication otherwise.
Where it goes: 9 AI output handling, 1 application source code, 12 repository artifacts, 14 user-facing text.
What this provision adds:
- Give the user an option to include a latent disclosure in captured content conveying the manufacturer name, the device name and version, and the creation or alteration timestamp.
- Embed that latent disclosure by default, to the extent technically feasible and standards-compliant, for capture devices first produced for sale in California on or after 2028-01-01.
Example (c2pa-python), before:
image = pipe(prompt).images[0]
image.save(out_path)After:
image = pipe(prompt).images[0]
image.save(raw_path)
manifest = {
'claim_generator_info': [{'name': 'acme-image-service', 'version': '2.3.0'}],
'assertions': [
{'label': 'c2pa.actions', 'data': {'actions': [{'action': 'c2pa.created',
'digitalSourceType': 'http://cv.iptc.org/newscodes/digitalsourcetype/trainedAlgorithmicMedia',
'when': datetime.now(UTC).isoformat()}]}},
{'label': 'com.acme.provenance', 'data': {'system': 'acme-image', 'system_version': '2.3.0', 'content_id': str(uuid.uuid4())}}]}
builder = c2pa.Builder(manifest)
with open(raw_path, 'rb') as src, open(out_path, 'w+b') as dst:
builder.sign(signer, 'image/png', src, dst) # signer from our load_c2pa_signer()Control: GenAI content without latent provenance disclosure. The same guard addresses 3 items with binding law in 1 jurisdiction. Engineering guidance, not legal advice.
Rule id ca-ab853.capture-device-latent-disclosure · review status: primary source derived