{"id":7686,"date":"2025-09-11T05:59:00","date_gmt":"2025-09-11T10:59:00","guid":{"rendered":"https:\/\/trustarc.com\/?post_type=resource&#038;p=7686"},"modified":"2025-09-15T09:50:31","modified_gmt":"2025-09-15T14:50:31","slug":"california-ai-transparency-laws-sb942-ab2013","status":"publish","type":"resource","link":"https:\/\/trustarc.com\/resource\/california-ai-transparency-laws-sb942-ab2013\/","title":{"rendered":"California\u2019s AI Transparency Laws: How SB 942 and AB 2013 Will Reshape AI Data Practices"},"content":{"rendered":"\t\t<section id=\"block_b4289f7eecc4b4917ab4a4b0c92c39be\" class=\"resource-intro intro-simple\">\n\t\t\t<div class=\"container\">\n\t\t\t\t\t\t\t\t\t<strong class=\"sub-title block uppercase\">Article<\/strong>\n\t\t\t\t\t\t\t\t\t\t<h1>California\u2019s AI Transparency Laws: How SB 942 and AB 2013 Will Reshape AI Data Practices<\/h1>\n\t\t\t\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\n\n\t<section id=\"block_41bef1e608a50714c4ba8dc7304907d2\" class=\"columns-content\">\n\t\t<div class=\"container\">\n\t\t\t<div class=\"left\">\n\t\t\t\t\t\t\t<\/div>\n\t\t\t<div class=\"middle\">\n\t\t\t\t<div class=\"content\">\n\t\t\t\t\t<h2>Setting the stage for AI transparency<\/h2>\n<p>If 2023 and 2024 were the teaser trailers for U.S. AI regulation, 2025 is the blockbuster release. And California (never shy about a starring role in tech policy) has premiered two headline acts: the <a href=\"https:\/\/leginfo.legislature.ca.gov\/faces\/billStatusClient.xhtml?bill_id=202320240SB942\" target=\"_blank\" rel=\"noopener\">California AI Transparency Act (SB 942)<\/a> and <a href=\"https:\/\/leginfo.legislature.ca.gov\/faces\/billTextClient.xhtml?bill_id=202320240AB2013\" target=\"_blank\" rel=\"noopener\">Assembly Bill 2013 on Generative AI Training Data Transparency<\/a>.<\/p>\n<p>Both laws take effect January 1, 2026, and together they create a one-two punch of accountability. SB 942 focuses on outputs: how AI-generated content is labeled, detected, and disclosed. AB 2013 focuses on inputs: how the data used to train <a href=\"https:\/\/trustarc.com\/resource\/data-protection-responsible-generative-ai-use\/\" target=\"_blank\" rel=\"noopener\">generative AI systems<\/a> is documented and made public.<\/p>\n<p>For privacy and compliance professionals, these laws are more than legislative updates. They are operational mandates with real penalties for noncompliance. And they\u2019re arriving at a moment when public trust in AI is fragile, regulators are sharpening their teeth, and stakeholders are asking, \u201cHow do we <strong><em>prove<\/em><\/strong> our AI is playing fair?\u201d<\/p>\n<h2>Understanding California\u2019s AI Transparency Act (SB 942)<\/h2>\n<p>The California AI Transparency Act is a consumer protection law with a simple premise: if you make AI that generates or alters content, you must tell people clearly, consistently, and in a way that can\u2019t be easily stripped out.<\/p>\n<p>However, <strong>the law\u2019s scope is narrower than \u201call AI\u201d.<\/strong> It applies only to <em>covered providers<\/em> (developers of a GenAI system with over 1,000,000 monthly visitors or users that are publicly accessible within California). It does not apply to certain exclusively non-user-generated experiences, such as video games, television, streaming, movies, or interactive content that is not created or modified by users. These exemptions mean some large AI content producers are outside the Act\u2019s reach.<\/p>\n<h4>Core requirements include:<\/h4>\n<h5>AI detection tools, free to the public<\/h5>\n<p>Covered providers must offer a publicly accessible detection tool to identify whether their generative AI system created or altered an image, video, or audio file. The tool must work via a web interface and an API, support content uploads or URLs, and output <em>system provenance data<\/em> (such as the system version and creation date) without exposing <em>personal provenance data<\/em>. The detection tool must be free to use, though providers may impose reasonable limitations to address security or integrity risks to their GenAI system.<\/p>\n<h5>Manifest disclosures (visible labels)<\/h5>\n<p>Users must be able to add a visible label: \u201cmanifest disclosure,\u201d that identifies content as AI-generated. Labels must be clear, conspicuous, permanent (or nearly so), and appropriate for the medium.<\/p>\n<h5>Latent disclosures (embedded metadata)<\/h5>\n<p>All AI-generated content must include embedded information: provider name, GenAI system name and version, creation timestamp, and a unique identifier. This must be detectable by the provider\u2019s AI detection tool and aligned with industry standards.<\/p>\n<h5>License enforcement<\/h5>\n<p>If a licensed third party disables disclosure capabilities, the provider must revoke their license within 96 hours. Licensees must cease using the system once a license is revoked.<\/p>\n<h5>Penalties<\/h5>\n<p>Civil penalties of $5,000 per violation, per day, plus possible injunctive relief, make this a law with real teeth.<\/p>\n<p>California\u2019s AI Transparency Act moves labeling and provenance from a \u201cnice to have\u201d to a \u201cnon-negotiable\u201d but only for covered providers and only for content within its defined scope. If your AI touches California consumers and isn\u2019t in an exempt category, transparency must be woven into your design and delivery pipelines.<\/p>\n<p style=\"text-align: center\"><strong>How mature is your AI risk management?<\/strong><\/p>\n<a href=\"https:\/\/trustarc.com\/ai-quiz\/\" target=\"_blank\" rel=\"noreferrer\" class=\"btn\"><span>Take the quiz<\/span><\/a><h2>Breaking down California AB 2013 Generative AI Training Data Transparency<\/h2>\n<p>If SB 942 answers \u201cHow do we show people what\u2019s AI-made?\u201d, AB 2013 asks <em>\u201cWhat\u2019s in the AI\u2019s brain?\u201d<\/em><\/p>\n<p>By January 1, 2026, any developer releasing a new or substantially modified GenAI system (or a significant update) in California <strong>must publish training data documentation on their website<\/strong>. This must include:<\/p>\n<ul>\n<li><strong>High-level dataset summaries:<\/strong> sources or owners, purpose alignment, volume (ranges allowed), and types of data points.<\/li>\n<li><strong>IP and privacy flags:<\/strong> whether datasets contain copyrighted, trademarked, or patented material; whether they include personal or aggregate consumer information under <a href=\"https:\/\/trustarc.com\/regulations\/ccpa-cpra\/\" target=\"_blank\" rel=\"noopener\">California Consumer Privacy Act (CCPA)<\/a> definitions.<\/li>\n<li><strong>Acquisition details:<\/strong> whether datasets were purchased or licensed.<\/li>\n<li><strong>Processing history:<\/strong> cleaning, modification, or enhancement steps, and their purpose.<\/li>\n<li><strong>Timeframes:<\/strong> when data was collected (and whether collection is ongoing), and when it was first used in training.<\/li>\n<li><strong>Synthetic data disclosure:<\/strong> if synthetic data generation was used, with an optional explanation of its functional purpose.<\/li>\n<\/ul>\n<p><strong>Exemptions<\/strong> exist for:<\/p>\n<ul>\n<li>Generative AI systems or services whose sole purpose is to ensure security and integrity.<\/li>\n<li>Systems used solely for the operation of aircraft in the national airspace.<\/li>\n<li>Systems developed for national security, military, or defense purposes that are made available exclusively to a federal entity.<\/li>\n<\/ul>\n<p>This is the first U.S. law to mandate public documentation of training data for commercial AI systems at this level of specificity. For compliance leaders, it means standing up <em>data lineage management<\/em> as a core governance function.<\/p>\n<p><strong>Unlock deeper compliance insights with a free trial of <a href=\"https:\/\/trustarc.com\/products\/privacy-data-governance\/nymity-research\/\" target=\"_blank\" rel=\"noopener\">Nymity Research<\/a>.<\/strong> Get instant access to jurisdiction-by-jurisdiction analysis, legislative tracking, and practical compliance guidance\u2014including ongoing updates to California\u2019s AI laws. <a href=\"https:\/\/trustarc.com\/free-trial\/nymity-research\/\" target=\"_blank\" rel=\"noopener\"><em>Start your free trial today.<\/em><\/a><\/p>\n<h2>Practical implications for privacy and compliance teams<\/h2>\n<p>Think of SB 942 and AB 2013 as California handing you a two-page \u201cAI transparency checklist,\u201d except it\u2019s written in legal code and costs $5,000\/day to ignore.<\/p>\n<p><strong>Operational changes<\/strong> you\u2019ll likely need:<\/p>\n<ul>\n<li>New governance workflows to track data sources, IP rights, and privacy risk from dataset ingestion through model deployment.<\/li>\n<li>Cross-functional playbooks between engineering, legal, privacy, and communications to handle disclosure labeling, detection tool updates, and public documentation.<\/li>\n<li>Vendor and partner audits to ensure licensees and third parties keep required disclosure features intact.<\/li>\n<\/ul>\n<p><strong>Risk factors and violation scenarios:<\/strong><\/p>\n<ul>\n<li><strong>Missing dataset documentation:<\/strong> A developer updates their GenAI model but fails to update the public training data summary as required under AB 2013. This could trigger enforcement if discovered during an investigation.<\/li>\n<li><strong>Noncompliant metadata:<\/strong> A provider releases AI-generated marketing images without embedding the latent disclosures SB 942 requires. If these assets are publicly distributed, each piece of noncompliant content could count as a separate violation.<\/li>\n<li><strong>License enforcement gaps:<\/strong> A licensee removes mandatory disclosure features from a licensed GenAI system. If the provider does not revoke the license within 96 hours of discovery, both the provider and the licensee could be exposed to penalties.<\/li>\n<\/ul>\n<h4>Broader compliance considerations for multi-jurisdiction alignment:<\/h4>\n<p>While not a requirement of SB 942 or AB 2013, California\u2019s rules are among the most detailed in the U.S. Organizations operating across multiple regions should build processes that meet the most stringent overlapping requirements. This may include:<\/p>\n<ul>\n<li><strong>Mapping disclosure obligations<\/strong> in each jurisdiction where your AI operates (e.g., SB 942 in California, Colorado AI Act transparency rules, EU AI Act content labeling).<\/li>\n<li><strong>Designing universal disclosure templates<\/strong> that meet or exceed the strictest format, permanence, and metadata requirements you face globally.<\/li>\n<li><strong>Coordinating dataset documentation standards<\/strong> so that your AB 2013-compliant training data summaries also satisfy disclosure or risk assessment obligations under other AI or privacy laws.<\/li>\n<\/ul>\n<p>Meeting these standards can help differentiate your organization as a trusted AI provider, especially in markets where public skepticism of AI remains high. It also reduces operational friction when scaling AI deployments across states and countries.<\/p>\n<h2>Compliance roadmap for California\u2019s AI transparency laws<\/h2>\n<h4>Step 1: Conduct a gap analysis<\/h4>\n<p>Compare existing AI governance against both laws. Pay special attention to provenance tracking, dataset documentation, and labeling workflows.<\/p>\n<h4>Step 2: Build a living training data inventory<\/h4>\n<p>Document source, ownership, type, processing history, and legal status for every dataset. <a href=\"https:\/\/trustarc.com\/resource\/building-data-inventory-mapping-ropa\/\" target=\"_blank\" rel=\"noopener\">Update this inventory<\/a> with each model update or retraining.<\/p>\n<h4>Step 3: Implement disclosure templates<\/h4>\n<p>Develop standardized manifest and latent disclosures that meet SB 942\u2019s permanence and clarity requirements. Test for resilience against stripping or alteration.<\/p>\n<h4>Step 4: Update vendor contracts<\/h4>\n<p>Mandate disclosure compliance in all GenAI licensing agreements. Include revocation rights and enforcement timelines.<\/p>\n<h2>Suggested practices and tools for achieving AI transparency<\/h2>\n<p>From a privacy-by-design perspective, California\u2019s laws effectively require:<\/p>\n<ul>\n<li><strong>Integrated dataset documentation tools<\/strong> (e.g., metadata catalogs, lineage tracking platforms).<\/li>\n<li><strong>Content authenticity solutions<\/strong>: watermarking, C2PA-compliant metadata embedding, and detection APIs.<\/li>\n<li><strong>DPIA integration<\/strong>: add AI transparency checks to your data protection impact assessments and NIST AI Risk Management Framework processes.<\/li>\n<\/ul>\n<h3>Sector-specific watchpoints:<\/h3>\n<h4>Healthcare: HIPAA considerations when disclosing dataset characteristics<\/h4>\n<p>Under AB 2013, developers must disclose whether training datasets include personal information or aggregate consumer information as defined in the CCPA. For healthcare organizations subject to <a href=\"https:\/\/trustarc.com\/regulations\/hippa-privacy\/\" target=\"_blank\" rel=\"noopener\">HIPAA<\/a>, this requirement demands extra caution. If training data includes protected health information (PHI), even in de-identified or aggregated form, disclosure summaries must avoid re-identification risks and maintain HIPAA-compliant safeguards.<\/p>\n<p>Moreover, if synthetic data generation was used to augment sensitive datasets, AB 2013 allows developers to note its purpose, which could be leveraged to demonstrate HIPAA-aligned privacy preservation. The key challenge for <a href=\"https:\/\/trustarc.com\/resource\/state-of-privacy-management-in-healthcare\/\" target=\"_blank\" rel=\"noopener\">healthcare entities<\/a> will be balancing AB 2013\u2019s transparency mandates with HIPAA\u2019s strict confidentiality requirements and ensuring that no publicly posted dataset summaries inadvertently reveal sensitive medical details.<\/p>\n<h4>Finance: SEC and FINRA record retention rules for AI-generated disclosures<\/h4>\n<p>SB 942\u2019s manifest and latent disclosure requirements mean that any AI-generated financial communications, from investor presentations to client statements, must be labeled and embedded with provenance metadata. <strong>For financial institutions under SEC or FINRA oversight, this creates a dual compliance obligation:<\/strong> maintaining SB 942-compliant disclosures while ensuring that all labeled AI-generated materials are retained in accordance with recordkeeping rules.<\/p>\n<p>For example, <a href=\"https:\/\/www.finra.org\/rules-guidance\/rulebooks\/finra-rules\/2210\" target=\"_blank\" rel=\"noopener\">FINRA Rule 2210<\/a> and <a href=\"https:\/\/www.finra.org\/rules-guidance\/guidance\/interpretations-financial-operational-rules\/sea-rule-17a-4-and-related-interpretations\" target=\"_blank\" rel=\"noopener\">SEC Rule 17a-4<\/a> require preserving certain communications for specified periods. If AI tools are used to create client-facing reports or marketing materials, firms must not only apply SB 942\u2019s disclosure protocols but also store the original AI-labeled versions and their metadata in case of regulatory audits or disputes.<\/p>\n<h4>E-commerce: Brand protection when AI-generated marketing or product content is labeled<\/h4>\n<p>In the e-commerce sector, SB 942\u2019s visible and embedded labeling of AI-generated content has direct brand implications. Marketing images, product descriptions, and promotional videos created by generative AI must carry manifest disclosures that are clear, conspicuous, and appropriate for the medium. This means customers may see explicit indicators that a product image or ad was AI-generated\u2014a potential trust-building measure for some brands, but a reputational risk if not managed carefully.<\/p>\n<p>The latent metadata requirements also mean that, even if visible labels are cropped or removed in unauthorized use, the embedded provenance can still identify the source. E-commerce companies will need to integrate these labeling practices into their creative workflows and brand guidelines, ensuring the disclosures are consistent, aesthetically aligned, and do not detract from customer engagement.<\/p>\n<h2>How California\u2019s AI laws compare to other jurisdictions<\/h2>\n<p>California\u2019s approach is more prescriptive than most U.S. states and aligns closely with the <strong>EU AI Act<\/strong>, which also requires training data and output transparency for specific systems.<\/p>\n<p><strong>EU AI Act<\/strong>: <a href=\"https:\/\/trustarc.com\/regulations\/eu-ai-act\/\/\" target=\"_blank\" rel=\"noopener\">Applies tiered obligations<\/a> based on risk category, with explicit transparency requirements for high-risk and foundation models.<br \/>\nCanada\u2019s AIDA: Establishes requirements for \u201chigh-impact systems,\u201d including risk mitigation and recordkeeping, but provides less detail on training data disclosure formats.<\/p>\n<p><strong>Colorado<\/strong>: The <a href=\"https:\/\/trustarc.com\/resource\/colorado-ai-act-obligations\/\" target=\"_blank\" rel=\"noopener\">Colorado AI Act<\/a> imposes obligations for developers and deployers of \u201chigh-risk AI systems,\u201d including transparency measures, documented risk management programs, and consumer rights regarding AI-driven decisions.<\/p>\n<p><strong>Utah<\/strong>: The <a href=\"https:\/\/trustarc.com\/resource\/utah-ai-policy-act\/\" target=\"_blank\" rel=\"noopener\">Utah AI Policy Act<\/a> requires disclosure when AI is used in consumer interactions, including informing individuals when they engage with generative AI tools or chatbots.<\/p>\n<h2>Preparing for California AI Transparency Act (SB 942) and AB 2013 compliance: Why early action builds trust and reduces risk<\/h2>\n<p>Technical standards for provenance embedding, watermarking, and dataset documentation formats will continue to evolve\u2014driven by both industry bodies and potential federal AI legislation. Privacy leaders should watch for updates from the <a href=\"https:\/\/trustarc.com\/regulations\/nist-ai-rmf\/\" target=\"_blank\" rel=\"noopener\">NIST AI Risk Management Framework<\/a>, the <a href=\"https:\/\/c2pa.org\/\" target=\"_blank\" rel=\"noopener\">Coalition for Content Provenance and Authenticity (C2PA)<\/a>, and guidance from organizations like IAPP to ensure their programs stay current.<\/p>\n<p>By acting early, organizations can do more than just meet California\u2019s January 1, 2026 deadlines. They can shape industry norms, influence best practices, and position themselves as trusted leaders in the responsible use of AI.<\/p>\n<p>Opacity was a feature of AI in its early days. In California, it\u2019s now becoming a liability. By operationalizing transparency in both outputs (SB 942) and inputs (AB 2013), privacy and compliance leaders can:<\/p>\n<ul>\n<li>Minimize fines, legal risk, and reputational damage<\/li>\n<li>Build lasting trust with customers, partners, and regulators<\/li>\n<li>Future-proof their AI governance frameworks against a fast-moving regulatory landscape.<\/li>\n<\/ul>\n<p>Compliance will no longer be the finish line; it will be the entry ticket to market credibility. The organizations that lead now won\u2019t just meet California\u2019s bar; they\u2019ll set the benchmark for responsible AI worldwide. The question isn\u2019t whether you\u2019ll comply; it\u2019s whether you\u2019ll lead.<\/p>\n\t\t\t\t\t\t\t\t\t<div class=\"question-box-multiple\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<div class=\"question-box bg-dark\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<div class=\"icon\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t<img decoding=\"async\" src=\"https:\/\/trustarc.com\/wp-content\/uploads\/2024\/02\/icon_AI_Small.svg\" class=\"attachment-full size-full\" alt=\"\" \/>\t\t\t\t\t\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<h4>AI Governance, Streamlined and Simplified.<\/h4>\n\t\t\t\t\t\t\t\t\t\t\t\t\t<p>Identify applicable AI laws, automate risk scoring, and track compliance so you can prove responsible AI use without overloading your governance team.<\/p>\n<a href=\"https:\/\/trustarc.com\/solutions\/ai-risk\/\" target=\"_blank\" rel=\"noreferrer\" class=\"cta\">Streamline AI governance<\/a>\t\t\t\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<div class=\"question-box bg-dark\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<div class=\"icon\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t<img decoding=\"async\" src=\"https:\/\/trustarc.com\/wp-content\/uploads\/2024\/02\/icon_Insight_Small.svg\" class=\"attachment-full size-full\" alt=\"\" \/>\t\t\t\t\t\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<h4>Smarter Mapping. Stronger Risk Management.<\/h4>\n\t\t\t\t\t\t\t\t\t\t\t\t\t<p><span style=\"font-weight: 400\">Automate data flow mapping, risk analysis, and vendor assessments to reduce privacy risk and keep compliance on track in a fraction of the time.<\/span><span style=\"font-weight: 400\"><br \/>\n<\/span><\/p>\n<a href=\"https:\/\/trustarc.com\/products\/privacy-data-governance\/data-mapping-risk-manager\/\" target=\"_blank\" rel=\"noreferrer\" class=\"cta\">Map and manage with ease<\/a>\t\t\t\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t\t\t\t\t\t<h2>Frequently Asked Questions: California AI Transparency Act (SB 942) &amp; AB 2013 Generative AI Training Data Transparency<\/h2>\n<h3>1. What is the California AI Transparency Act (SB 942)?<\/h3>\n<p>The California AI Transparency Act (SB 942) is a state law that takes effect on January 1, 2026, and requires large generative AI providers to make their AI-generated content identifiable through both <strong>visible labels<\/strong> (manifest disclosures) and <strong>embedded metadata<\/strong> (latent disclosures). It also mandates that these providers <strong>offer a free, publicly accessible AI detection tool<\/strong> to identify content created or altered by their systems.<\/p>\n<h3>2. Who is considered a \u201ccovered provider\u201d under SB 942?<\/h3>\n<p>A \u201ccovered provider\u201d is defined in the bill as any entity that <strong>creates, codes, or otherwise produces<\/strong> a generative AI system with <strong>over 1 million monthly users in California<\/strong> and that is publicly accessible in the state.<\/p>\n<h3>3. Are there exemptions under SB 942?<\/h3>\n<p>Yes. SB 942 does <strong>not<\/strong> apply to products, services, websites, or applications that <strong>exclusively provide non-user-generated<\/strong> video games, television, streaming, movie, or interactive experiences.<\/p>\n<h3>4. What are \u201cmanifest\u201d and \u201clatent\u201d disclosures in SB 942?<\/h3>\n<ul>\n<li><strong>Manifest disclosures<\/strong> are visible labels applied to AI-generated content, such as \u201cThis image was generated by AI.\u201d They must be clear, conspicuous, permanent (or nearly so), and appropriate for the medium.<\/li>\n<li><strong>Latent disclosures<\/strong> are embedded metadata that include details such as the provider\u2019s name, the AI system name and version, the date\/time of creation, and a unique identifier. These must be detectable by the provider\u2019s AI detection tool and meet industry standards.<\/li>\n<\/ul>\n<h3>5. What is AB 2013: Generative AI Training Data Transparency?<\/h3>\n<p>AB 2013 is a California law effective January 1, 2026, that requires developers of generative AI systems to <strong>publish detailed documentation<\/strong> about the datasets used to train their systems. This includes information such as dataset sources, types of data points, intellectual property status, licensing details, data processing history, and whether synthetic data was used.<\/p>\n<h3>6. Who must comply with AB 2013?<\/h3>\n<p>Any developer releasing a <strong>new or substantially modified<\/strong> generative AI system in California (including significant updates to existing systems) must comply with AB 2013\u2019s public documentation requirements.<\/p>\n<h3>7. What are the exemptions under AB 2013?<\/h3>\n<p>AB 2013 does not require documentation for:<\/p>\n<ul>\n<li>Generative AI systems whose sole purpose is to ensure security and integrity.<\/li>\n<li>Systems used solely for the operation of aircraft in the national airspace.<\/li>\n<li>Systems developed for national security, military, or defense purposes <strong>that are made available exclusively to a federal entity.<\/strong><\/li>\n<\/ul>\n<h3>8. What specific information must be disclosed under AB 2013?<\/h3>\n<p>The law requires documentation that includes:<\/p>\n<ul>\n<li>Dataset sources or owners.<\/li>\n<li>How datasets align with the system\u2019s intended purpose.<\/li>\n<li>Data point types and estimated volumes.<\/li>\n<li>Intellectual property and privacy status (e.g., copyrighted, personal data).<\/li>\n<li>Whether datasets were purchased, licensed, or in the public domain.<\/li>\n<li>Processing or cleaning steps taken.<\/li>\n<li>Data collection timeframes and first-use dates.<\/li>\n<li>Whether synthetic data generation was used, with an optional explanation of why.<\/li>\n<\/ul>\n<h3>9. What are the penalties for violating SB 942 or AB 2013?<\/h3>\n<ul>\n<li><strong>SB 942:<\/strong> Civil penalties of $5,000 per violation, per day, plus possible injunctive relief and legal costs. Each day a violation continues counts as a separate offense.<\/li>\n<li><strong>AB 2013:<\/strong> The bill itself does not specify a monetary penalty in the retrieved text. However, it grants enforcement authority to the California Attorney General, meaning noncompliance could still result in enforcement actions, including investigations and other remedies allowed under California law.<\/li>\n<\/ul>\n<h3>10. How can privacy professionals prepare for compliance?<\/h3>\n<ul>\n<li>For<strong> SB 942:<\/strong> Develop <strong>workflows for labeling AI-generated content<\/strong> with both visible and embedded disclosures, ensure metadata persistence, and deploy a compliant detection tool.<\/li>\n<li>For<strong> AB 2013:<\/strong> Maintain a <strong>living inventory<\/strong> of training datasets with full source, licensing, processing, and IP details, and ensure this can be published in the required public format before release.<\/li>\n<li>In both cases: Integrate these obligations into <strong>vendor contracts, data governance frameworks,<\/strong> and <strong>multi-jurisdiction compliance plans.<\/strong><\/li>\n<\/ul>\n\t\t\t\t<\/div>\n\t\t\t<\/div>\n\t\t\t<div class=\"right sm\">\n\t\t\t\t<div class=\"share-it\">\n\t\t\t\t\t<strong class=\"title block uppercase\">Follow us<\/strong>\n\t\t\t\t\t<div class=\"soc-list\">\n\t\t\t\t\t\t<a href=\"https:\/\/www.linkedin.com\/company\/trustarc\/\" target=\"_blank\"><img decoding=\"async\" src=\"https:\/\/trustarc.com\/wp-content\/themes\/trustarc\/assets\/dist\/images\/li-dark.svg\" alt=\"\" \/><\/a>\n\t\t\t\t\t\t<a href=\"\nhttps:\/\/twitter.com\/TrustArc\" target=\"_blank\"><img decoding=\"async\" src=\"https:\/\/trustarc.com\/wp-content\/themes\/trustarc\/assets\/dist\/images\/tw-dark.svg\" alt=\"\" \/><\/a>\n\t\t\t\t\t\t<a href=\"javascript:;\" id=\"copy-url\"><img decoding=\"async\" src=\"https:\/\/trustarc.com\/wp-content\/themes\/trustarc\/assets\/dist\/images\/link-dark.svg\" alt=\"\" \/><\/a>\n\t\t\t\t\t\t<span class=\"copied\" style=\"display:none;\">Link Copied!<\/span>\n\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t\t\t\t\t<div class=\"key-topics\">\n\t\t\t\t\t\t<strong class=\"title block uppercase\">Key Topics<\/strong>\n\t\t\t\t\t\t<ul>\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<li><a href=\"https:\/\/trustarc.com\/topic-resource\/ai-privacy\/\" class=\"badge\">AI Privacy<\/a><\/li>\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<li><a href=\"https:\/\/trustarc.com\/topic-resource\/us-consumer-privacy-laws\/\" class=\"badge\">US Consumer Privacy Laws<\/a><\/li>\n\t\t\t\t\t\t\t\t\t\t\t\t\t<\/ul>\n\t\t\t\t\t<\/div>\n\t\t\t\t\t\t\t\t<div class=\"cta-area\">\n\t\t\t\t\t<p>Get the latest resources sent to your inbox<\/p>\n\t\t\t\t\t<a href=\"\/subscription-center\/\" class=\"cta\">Subscribe<\/a>\n\t\t\t\t<\/div>\n\t\t\t<\/div>\n\t\t<\/div>\n\t<\/section>\n\t\n\n\t\t<section id=\"block_284a58e5ec9a333c155a05455dfbb500\" class=\"resource-section\">\n\t\t\t<div class=\"container\">\n\t\t\t<div class=\"resource-head\">\n\t\t\t\t\t\t\t<h2>Related resources<\/h2>\n\t\t\t\t<a href=\"\/resources\/\" target=\"_blank\" rel=\"noreferrer\" class=\"cta block\">View all resources<\/a>\t\t<\/div>\n\t\t\t\t\t\t<ul class=\"resource-lists \">\n\t\t\t\t\t\t\t<li>\n\t\t\t\t\t<a href=\"https:\/\/trustarc.com\/resource\/managing-ai-dsrs\/\" class=\"resource-single\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t<div class=\"img-holder\">\n\t\t\t\t\t\t\t\t<img loading=\"lazy\" decoding=\"async\" width=\"380\" height=\"120\" src=\"https:\/\/trustarc.com\/wp-content\/uploads\/2024\/02\/res-feat-city-purple-380x120.png\" class=\"attachment-380x120 size-380x120 wp-post-image\" alt=\"\" \/>\t\t\t\t\t\t\t<\/div>\n\t\t\t\t\t\t\t\t\t\t\t\t<div class=\"text-holder\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<span class=\"resource-label uppercase\">Articles<\/span>\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<h4>DSRs Meet AI: How to Handle Requests About Model Inputs, Outputs, and Training Data<\/h4>\n\t\t\t\t\t\t<\/div>\n\t\t\t\t\t<\/a>\n\t\t\t\t<\/li>\n\t\t\t\t\t\t\t\t<li>\n\t\t\t\t\t<a href=\"https:\/\/trustarc.com\/resource\/trustarc-product-demo-video\/\" class=\"resource-single has-icon Webinars\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t<div class=\"img-holder\">\n\t\t\t\t\t\t\t\t<img loading=\"lazy\" decoding=\"async\" width=\"380\" height=\"120\" src=\"https:\/\/trustarc.com\/wp-content\/uploads\/2024\/02\/res-feat-rect-blue-380x120.png\" class=\"attachment-380x120 size-380x120 wp-post-image\" alt=\"\" \/>\t\t\t\t\t\t\t<\/div>\n\t\t\t\t\t\t\t\t\t\t\t\t<div class=\"text-holder\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<span class=\"resource-label uppercase\">Webinars and Videos<\/span>\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<h4>TrustArc Product Demo Video<\/h4>\n\t\t\t\t\t\t<\/div>\n\t\t\t\t\t<\/a>\n\t\t\t\t<\/li>\n\t\t\t\t\t\t\t\t<li>\n\t\t\t\t\t<a href=\"https:\/\/trustarc.com\/resource\/privacy-roi-checklist\/\" class=\"resource-single\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t<div class=\"img-holder\">\n\t\t\t\t\t\t\t\t<img loading=\"lazy\" decoding=\"async\" width=\"380\" height=\"120\" src=\"https:\/\/trustarc.com\/wp-content\/uploads\/2024\/02\/res-feat-woven-pink-380x120.png\" class=\"attachment-380x120 size-380x120 wp-post-image\" alt=\"\" \/>\t\t\t\t\t\t\t<\/div>\n\t\t\t\t\t\t\t\t\t\t\t\t<div class=\"text-holder\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<span class=\"resource-label uppercase\">Infographics<\/span>\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<h4>Privacy ROI Checklist: Your Guide to the 7 Essentials of Modern Privacy<\/h4>\n\t\t\t\t\t\t<\/div>\n\t\t\t\t\t<\/a>\n\t\t\t\t<\/li>\n\t\t\t\t\t\t<\/ul>\n\t\t\t\t\t<\/div>\t\t<\/section>\n\t\t","protected":false},"excerpt":{"rendered":"<p>Learn how California\u2019s SB 942 &#038; AB 2013 set new AI transparency rules\u2014label outputs, disclose training data, and stay ahead of compliance risk.<\/p>\n","protected":false},"featured_media":1260,"template":"","topic-resource":[60,114],"type-resource":[6],"class_list":["post-7686","resource","type-resource","status-publish","has-post-thumbnail","hentry","topic-resource-ai-privacy","topic-resource-us-consumer-privacy-laws","type-resource-articles"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO Premium plugin v27.4 (Yoast SEO v27.4) - https:\/\/yoast.com\/product\/yoast-seo-premium-wordpress\/ -->\n<title>California SB 942 &amp; AB 2013: AI transparency compliance guide | TrustArc<\/title>\n<meta name=\"description\" content=\"Learn how California\u2019s SB 942 &amp; AB 2013 set new AI transparency rules\u2014label outputs, disclose training data, and stay ahead of compliance risk.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/trustarc.com\/resource\/california-ai-transparency-laws-sb942-ab2013\/\" \/>\n<meta name=\"twitter:label1\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data1\" content=\"1 minute\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/trustarc.com\\\/resource\\\/california-ai-transparency-laws-sb942-ab2013\\\/\",\"url\":\"https:\\\/\\\/trustarc.com\\\/resource\\\/california-ai-transparency-laws-sb942-ab2013\\\/\",\"name\":\"California SB 942 & AB 2013: AI transparency compliance guide | TrustArc\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/trustarc.com\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/trustarc.com\\\/resource\\\/california-ai-transparency-laws-sb942-ab2013\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/trustarc.com\\\/resource\\\/california-ai-transparency-laws-sb942-ab2013\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/trustarc.com\\\/wp-content\\\/uploads\\\/2024\\\/01\\\/res-feat-woven-blue-test.png\",\"datePublished\":\"2025-09-11T10:59:00+00:00\",\"dateModified\":\"2025-09-15T14:50:31+00:00\",\"description\":\"Learn how California\u2019s SB 942 & AB 2013 set new AI transparency rules\u2014label outputs, disclose training data, and stay ahead of compliance risk.\",\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/trustarc.com\\\/resource\\\/california-ai-transparency-laws-sb942-ab2013\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/trustarc.com\\\/resource\\\/california-ai-transparency-laws-sb942-ab2013\\\/#primaryimage\",\"url\":\"https:\\\/\\\/trustarc.com\\\/wp-content\\\/uploads\\\/2024\\\/01\\\/res-feat-woven-blue-test.png\",\"contentUrl\":\"https:\\\/\\\/trustarc.com\\\/wp-content\\\/uploads\\\/2024\\\/01\\\/res-feat-woven-blue-test.png\",\"width\":610,\"height\":152},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/trustarc.com\\\/#website\",\"url\":\"https:\\\/\\\/trustarc.com\\\/\",\"name\":\"TrustArc\",\"description\":\"\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/trustarc.com\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"}]}<\/script>\n<!-- \/ Yoast SEO Premium plugin. -->","yoast_head_json":{"title":"California SB 942 & AB 2013: AI transparency compliance guide | TrustArc","description":"Learn how California\u2019s SB 942 & AB 2013 set new AI transparency rules\u2014label outputs, disclose training data, and stay ahead of compliance risk.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/trustarc.com\/resource\/california-ai-transparency-laws-sb942-ab2013\/","twitter_misc":{"Est. reading time":"1 minute"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/trustarc.com\/resource\/california-ai-transparency-laws-sb942-ab2013\/","url":"https:\/\/trustarc.com\/resource\/california-ai-transparency-laws-sb942-ab2013\/","name":"California SB 942 & AB 2013: AI transparency compliance guide | TrustArc","isPartOf":{"@id":"https:\/\/trustarc.com\/#website"},"primaryImageOfPage":{"@id":"https:\/\/trustarc.com\/resource\/california-ai-transparency-laws-sb942-ab2013\/#primaryimage"},"image":{"@id":"https:\/\/trustarc.com\/resource\/california-ai-transparency-laws-sb942-ab2013\/#primaryimage"},"thumbnailUrl":"https:\/\/trustarc.com\/wp-content\/uploads\/2024\/01\/res-feat-woven-blue-test.png","datePublished":"2025-09-11T10:59:00+00:00","dateModified":"2025-09-15T14:50:31+00:00","description":"Learn how California\u2019s SB 942 & AB 2013 set new AI transparency rules\u2014label outputs, disclose training data, and stay ahead of compliance risk.","inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/trustarc.com\/resource\/california-ai-transparency-laws-sb942-ab2013\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/trustarc.com\/resource\/california-ai-transparency-laws-sb942-ab2013\/#primaryimage","url":"https:\/\/trustarc.com\/wp-content\/uploads\/2024\/01\/res-feat-woven-blue-test.png","contentUrl":"https:\/\/trustarc.com\/wp-content\/uploads\/2024\/01\/res-feat-woven-blue-test.png","width":610,"height":152},{"@type":"WebSite","@id":"https:\/\/trustarc.com\/#website","url":"https:\/\/trustarc.com\/","name":"TrustArc","description":"","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/trustarc.com\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"}]}},"_links":{"self":[{"href":"https:\/\/trustarc.com\/wp-json\/wp\/v2\/resource\/7686","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/trustarc.com\/wp-json\/wp\/v2\/resource"}],"about":[{"href":"https:\/\/trustarc.com\/wp-json\/wp\/v2\/types\/resource"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/trustarc.com\/wp-json\/wp\/v2\/media\/1260"}],"wp:attachment":[{"href":"https:\/\/trustarc.com\/wp-json\/wp\/v2\/media?parent=7686"}],"wp:term":[{"taxonomy":"topic-resource","embeddable":true,"href":"https:\/\/trustarc.com\/wp-json\/wp\/v2\/topic-resource?post=7686"},{"taxonomy":"type-resource","embeddable":true,"href":"https:\/\/trustarc.com\/wp-json\/wp\/v2\/type-resource?post=7686"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}