A Third of Industry Fails to Show Up for AI Transparency
On August 1, California’s Artificial Intelligence Transparency Act (CAITA) became operational, making it the first U.S. law to require generative AI providers to embed provenance data in their output and publish free public detection tools. The European Union’s parallel requirements under its AI Act Code of Practice kicked in the same day. Senator Josh Becker, who authored the California legislation, called it “the beginning of a quiet revolution” for the internet. Quiet is right. Most people won’t notice anything. Whether the companies required to build the infrastructure noticed is a different question.
What CAITA Requires
CAITA applies to any generative AI provider with more than 1 million monthly users that’s publicly accessible in California. It covers images, video, and audio, while text is explicitly excluded. Covered providers must do three things:
- Embed latent disclosures (metadata identifying the content, the GenAI system name and version, and creation date)
- Offer users a manifest disclosure option (a visible, permanent AI-generated label)
- Make available a free, publicly accessible AI detection tool that accepts uploads and URLs, supports API access, collects user feedback, and doesn’t retain personal data
Noncompliance runs $5,000 per violation per day, enforced by the Attorney General with no private right of action. The law phases in over two years. January 1, 2027 brings requirements for large online platforms to detect and display provenance data, while January 1, 2028 pulls in capture device manufacturers. But the first deadline has already passed, and the early returns aren’t inspiring confidence.
The Compliance Census
Indicator and WITNESS (a media outlet and a human rights organization focused on video) ran the first real compliance census, evaluating 13 companies that clear CAITA’s 1 million user threshold representing roughly 10.6 billion monthly visits. Their findings, covered by KQED on August 17, paint a picture of an industry that knew this was coming and showed up half-dressed.
| Company | Status | Notes |
|---|---|---|
| Adobe | Has tool | Dedicated public detector |
| ElevenLabs | Has tool | Includes confidence percentages |
| Has tool | Integrated into Gemini interface | |
| Meta | Has tool | Described as “research demo” |
| OpenAI | Has tool | Aggressive rate limiting |
| TikTok | Has tool | Global preview stage |
| Microsoft | Partial | Points to C2PA inspection tool |
| Suno | Has tool | Shared after original report |
| HeyGen | Missing | No response, no comment |
| Midjourney | Missing | No response, no comment |
| Mistral | Missing | No response, no comment |
| Synthesia | Partial | Metadata embedded, tool “pending” |
| xAI | Missing | No response, no comment |
Synthesia, a UK-based AI video platform, told both outlets it has embedded the required metadata but is “still seeking clarification on a few technical points.” Their head of corporate affairs, Alexandru Voica, argued that transparency rules should track a tool’s reach and risk profile, given that Synthesia is a B2B product. Which is an odd line in the sand, since a corporate training video or synthetic spokesperson reaches human eyes the same way any other video clip does.
How Well the Tools Work
Having a tool is the floor, not the ceiling. The Indicator/WITNESS team ran 243 tests across 85 files, and the results should make anyone relying on these tools for verification nervous.
Most detectors correctly identified their own unedited output, but OpenAI couldn’t even manage that. Its tool refused a Sora-generated MP4 and failed to identify a ChatGPT-generated MP3 that didn’t carry content credentials in the first place. When files were edited (cropped, screenshotted, re-encoded, sent through WhatsApp, re-recorded on an iPhone), only Google and OpenAI’s detectors survived all tampering attempts, which is surprising given OpenAI’s failure on clean files.
The credential spoofing test reveals a deeper vulnerability. The Indicator team copied a genuine OpenAI content credential from a ChatGPT-generated image and pasted it into a real photograph of an orchid. Adobe’s detector declared the orchid was created with ChatGPT, albeit with a warning about unrecorded changes. In other words, anyone can attach an AI credential to a real photo, then point to the “AI-generated” label to discredit authentic images. This means a tool can both create fake images and disparage the real ones.
Interoperability Gap
Every detector only recognizes its own company’s output, so a piece of media generated by Midjourney won’t trigger OpenAI’s detector. A Synthesia video won’t show up in Google’s tool. Someone trying to determine whether a given image was AI-generated would need to run it through a dozen separate detectors, assuming all of them existed (they don’t). The law doesn’t require cross-provider detection, and companies have a legitimate liability concern about vouching for signals they can’t verify directly. But the practical effect is that C2PA content credentials, the supposed industry-wide standard for provenance, aren’t truly interoperable where it matters: at the detection layer.

On top of that, several tools fail CAITA’s specific feature requirements. Three impose rate limits (OpenAI blocks users after as few as 7 tests in a session; Google and Meta cap at 10 to 15 per day). Most don’t accept URLs, which CAITA presents as an alternative to upload, and downloading a file can strip metadata, so that limitation isn’t trivial. Only TikTok, and Google in part, collect feedback on tool efficacy, which the law requires.
What Happens Next
David Evan Harris, who helped draft CAITA and participated in the EU code of practice expert working groups, told Indicator that “of the big companies, only a few have gone out of their way to comply in a robust manner, while others have half-baked, unreliable tools that could be challenged legally if not improved.” That’s a polite way of saying what the data confirms.
Pending legislation could reshape the regulatory environment. California SB 1000, also introduced by Becker, would eliminate the 1 million user threshold entirely, scrap the manifest disclosure option, reduce the licensee revocation window from 96 to 72 hours, and replace the AI detection tool obligation with a stricter disclosure verification tool requirement. California AB 2713 would rework the provisions for large online platforms. Both could pass before the next compliance deadlines.
Anthropic, which doesn’t generate photorealistic images or video, announced it will watermark all text output from future Claude models using SynthID, Google DeepMind’s watermarking technique. That satisfies the EU’s text detection requirements (which CAITA doesn’t cover) and has generated predictable uproar on LinkedIn. The watermark is invisible to readers and doesn’t affect output quality.
Eighty-two signatories have committed to the EU Code of Practice, with all EU-market providers required to make content detectable by December 2. California’s January 2027 deadline for large platforms will add another compliance layer. For now, the tools exist on paper more than in practice, the detection landscape is fragmented, and roughly a third of the covered industry hasn’t shown up at all, and several of those that did only made partial attempts at compliance. Two weeks in, the quiet revolution sounds a lot like silence.