Two AI Disclosure Laws Took Effect August 2. Only One Is Likely About You.
California's AI Transparency Act and the EU AI Act's Article 50 both went live August 2. The thresholds matter, and most small businesses read the wrong one.
Two significant AI disclosure regimes became operative on the same day this month, and the coverage of both has been muddy enough that a lot of small business owners now believe they have obligations they do not have, while missing the one they might.
Here is the sorting.
California: probably not you, but you will feel it
The California AI Transparency Act became operative on August 2, following a delay and expansion enacted through AB 853. Morgan Lewis's summary of the operative rules lays out three core duties for covered providers: maintain a free public AI detection tool, offer users a way to attach a visible AI-generated label to content, and embed durable metadata identifying the system name, version, and creation date.
The threshold is the part to read closely. A covered provider is one offering a generative AI system with more than one million monthly visitors or users that is publicly accessible in California. Video games, television, and streaming entertainment are carved out.
If you run an accounting practice, a construction company, or a regional retailer, you are not a covered provider. You do not owe California a detection tool. What you should take from this law is the second-order effect: the tools you buy are now building provenance labeling into their products, and by January 1, 2027, large online platforms with more than two million unique monthly users must detect that provenance data, show it to users, and stop stripping it from uploads. Device manufacturers follow on January 1, 2028.
Translated: the marketing image you generate and post is increasingly going to arrive at its destination carrying a label that says how it was made. Not because you are regulated, but because the tool and the platform on either side of you are.
Enforcement here runs through the state attorney general, at $5,000 per violation with each day counted separately, and there is no private right of action. That last detail is worth noting, because it means the risk profile is regulatory rather than a plaintiff's bar problem.
The EU: this one can reach smaller operators
Article 50 of the EU AI Act also took effect August 2, and it is structured differently in a way that matters. California's operative duties fall on the companies building the systems. The EU's fall on providers and deployers, and a deployer can be an ordinary business using an ordinary tool.
Cooley's client alert breaks the obligations into four. Providers must disclose that a user is interacting with AI unless that is already obvious, and must embed machine-readable markings in synthetic audio, images, video, and text along with a way to detect them. Deployers must inform people when they are subject to emotion recognition or biometric categorization, and must disclose when published content on matters of public interest was artificially generated or manipulated, unless it went through substantive human editorial review.
Penalties reach 15 million euros or 3% of worldwide annual turnover, whichever is higher. Systems that already existed before the deadline have until December 2, 2026 to complete the marking and detection requirements.
Whether these obligations reach your specific business depends on scope questions that turn on where your users are and how your service is offered, and that is a determination to get from counsel rather than from a blog post, ours included. What we will say is that "we do not sell in Europe" is a conclusion people reach faster than the facts usually support, particularly for anyone running a website chatbot that anyone in the world can open.
The three questions worth answering this month
Where does AI touch something a customer sees? Most businesses cannot answer this, which is the actual problem. Website chat, marketing images, product descriptions, automated email replies, phone systems, review responses. Write the list. It is usually longer than the owner expects, and about a third of it was set up by someone who has since left.
Is your chatbot honest about being a chatbot? The EU rule turns on whether AI interaction is disclosed unless already obvious, and the same expectation is showing up in state law and in ordinary customer patience. A bot with a human first name, a stock headshot, and no label is the configuration to fix. Ours is a neon cowboy named Frank who says what he is in his first message, which costs us nothing and settles the question.
What does your vendor mark, and can anyone read it? Ask directly. Several major model providers began embedding provenance signals this month, and the detection tools that would let a third party verify them are, in most cases, not public yet. Knowing which of your tools mark output, and in what format, is a reasonable thing to have written down before a customer or regulator asks.
What we would not do
We would not buy a compliance product over this. Not yet. The vendors moving fastest right now are selling to the anxiety rather than to the requirement, and for a business well under these thresholds, the honest scope of work is a couple of hours of inventory and a short written policy, not a platform subscription.
We would also not treat this as the end of the arc. Two regimes landed on August 2, more state laws are phasing in through 2027 and 2028, and the direction is consistent across all of them: content will carry its origin, and businesses will be expected to say what they used. The organizations that will find this easy are the ones that started keeping track early, while the stakes were still low.
That is the whole advantage on offer here. Not compliance theater. Just knowing, before someone asks, what your business actually uses and what it tells people about it.
If you want a second read on which of these rules genuinely apply to your operation, that is a conversation we are glad to have.
Join the conversation
Straight talk welcome. Comments are moderated, no pitches, no spam.
Comments load once the Hyvor Talk Website ID is set in
article.html.