California AI Transparency Act: system provenance data.
What changed between versions
The detection requirement (subdivision (a)(1)) was broadened from requiring platforms to detect only provenance data 'compliant with widely adopted specifications adopted by an established standards-setting body' to detecting 'any provenance data' embedded into, attached to, or otherwise associated with content.
The inspection requirement (subdivision (a)(3)) was broadened from allowing inspection of 'all available system provenance data that is compliant with widely adopted specifications' to allowing inspection of 'any system provenance data embedded into, attached to, or otherwise associated with the content.'
The exemption provision (subdivision (d)) was refined to state that the section does not require action with respect to provenance data that is 'not compliant or interoperable' with widely adopted specifications, adding 'interoperable' as an additional qualifier alongside 'compliant.'
The user interface requirement (subdivision (a)(2)(A)) was changed from disclosing the availability of system provenance data that indicates content was generated by a GenAI system, to requiring the interface to reliably indicate whether any system provenance data or digital signature identifies the content as having been generated or substantially altered by a GenAI system or captured by a capture device.
A new subdivision (b) was added stating that the obligations shall not be construed to require a large online platform to maintain, display, or allow a user to download personal information. This creates a privacy carve-out from the provenance transparency requirements.
The prohibition on stripping provenance data (subdivision (c)) was broadened from prohibiting stripping of data 'compliant with widely adopted specifications' to prohibiting stripping of 'any system provenance data or digital signature' from content uploaded to, distributed on, or downloaded from the platform.