California SB 1000: no user threshold, new verification tool

SB 1000 recasts the California AI Transparency Act: no user threshold, a disclosure verification tool, no manifest option. What Sume's docs list.

4 min readSume
All posts

SB 1000's digest says it would recast the California AI Transparency Act (CATA) to delete the user threshold from "covered provider," replace "AI detection tool" with "disclosure verification tool," and delete the requirement to offer users a manifest disclosure option. It also adds to the latent disclosure whether the GenAI system created or altered the content. It declares an urgency statute, to take effect immediately.

This reads the enrolled text (August 30, 2026) on the leginfo page and the Governor's September 30 release, read 2026-10-01. The enrolled text is the version I read; check leginfo for the final chaptered text. This is not legal advice and says nothing about whether Sume is a covered provider.

What changed in the text I read?

SB 1000 enrolled text changes, read 2026-10-01.
TopicBeforeIn SB 1000
Covered providerOver 1,000,000 monthly visitors or usersAny person producing a publicly accessible GenAI system in California; no threshold
Tool nameAI detection toolDisclosure verification tool
Manifest disclosureProvider offers the user an optionRequirement deleted
Latent disclosureProvider name, system, time, identifierAlso whether the GenAI system created or altered the content

What must the verification tool do?

Section 22757.2 lists criteria: it lets a user assess whether image, video or audio was created or altered (beyond minor modification) by the provider's system, outputs detected system provenance data, is publicly accessible, accepts an upload or URL, and supports an API so it can be invoked without visiting the provider's site. A provider may instead direct users to a compliant third-party tool.

What does Sume's documentation list?

Looking only at the pages cited here: GET /v1/catalog discovers capabilities, models, runtime readiness and pricing metadata. Image requests accept output_format of png, jpeg, webp or svg, and results return a media.sume.com URL. The metadata field is caller metadata stored on the job and not sent to the provider. None of these pages describes a provenance mark or a verification tool, and I am not claiming one exists.

For the earlier bill and what the docs say about marks, see latent vs manifest disclosure and whether Sume adds C2PA or a watermark.

What should a developer do now?

If you ship AI media to California users, ask counsel whether you are a covered provider under the new definition, and whether your own pipeline strips or alters any marks a model provider adds. Keep your own record of job ids and result URLs so you can answer questions about where a file came from.

Sources

Related posts

More in Developers

All Developers posts

Written by Sume