← Blog

California SB 942 LLM Requirements: Duties, Scope, and the Text-Only Boundary

Parminder Singh
Parminder Singh··5 min read
Summarize with AI

California SB 942 defines generative AI broadly enough to include systems that generate text, images, video, and audio. Its operative detection and disclosure duties focus on image, video, and audio content. This guide separates covered-provider applicability from content-level duties, licensee rules, later AB 853 obligations, enforcement, and the narrow evidence role available at an enterprise HTTP AI request boundary.

Compliance & Regulationai-complianceai-governancecomplianceregulationllmpolicy-enforcement
California SB 942 LLM Requirements: Duties, Scope, and the Text-Only Boundary

California SB 942 uses a broad definition of generative AI and a narrower set of content duties. The definition includes systems capable of generating text, images, video, and audio. The detection and disclosure provisions then concentrate on image and video content, plus audio content. That difference decides how an LLM enters the analysis.

A compliance memo that labels every chatbot "covered" and stops there has skipped the operative language.

TL;DR

  • A covered provider creates, codes, or otherwise produces a GenAI system with over one million monthly users or visitors that is public in California.
  • The GenAI definition includes text, while detection and disclosure duties focus on image and video content, plus audio content.
  • Covered providers need a no-cost detection tool and a manifest option, along with latent disclosures and licensee controls.
  • AB 853 moved the chapter's operative date to August 2, 2026 and added later platform and device duties.

Applicability begins with the provider and system

The chaptered SB 942 text defines a covered provider as a person that creates, codes, or otherwise produces a generative AI system with over 1,000,000 monthly visitors or users and public accessibility within California. That definition points to the system producer. An enterprise employee calling a third-party model API ordinarily occupies a different role from the company that created the system.

Apply four facts in order: who created or coded the system, which system the count covers, how the monthly count is measured, and how California users can access it. Keep the supporting analytics snapshot and ownership diagram. A vendor contract can identify the parties, while product and traffic records establish how the system is actually offered.

The statute excludes products and services providing exclusively non-user-generated video game and television content, plus streaming, movie, or interactive experiences. Legal should document any reliance on that exclusion against the real product behavior.

The text-only and multimodal boundary

SB 942 defines a GenAI system as AI capable of generating derived synthetic content, including text and images, plus video and audio, that emulates the structure and characteristics of its training data. The operative mechanisms then name image and video content, as well as audio content, including combinations of those media.

That wording creates an important applicability fork for LLM products. A text-only system enters the defined category, while the content-level detection and disclosure requirements target the listed non-text media. A multimodal assistant that can return an image or narrated audio, plus generated video, needs those output paths assessed individually. Calling the whole product an "LLM" supplies too little information.

Our SB 942 risk-assessment workflow starts with a generation-path inventory for exactly this reason. Record model capabilities and product functions enabled, plus output media and version. One disabled image function on Tuesday can become an active covered path after a Friday release.

The detection tool has six operational duties

A covered provider must make an AI detection tool available at no cost. The tool must let a user assess whether covered image and video content or covered audio content came from or was altered by the provider's GenAI system and output detected system provenance data. It must avoid outputting detected personal provenance data.

The tool also needs public accessibility, subject to reasonable access limits addressing demonstrable security or integrity risks. Users must be able to upload content or supply a URL, and an API must support invocation without visiting the provider's website. The provider must collect feedback about efficacy and incorporate relevant feedback into improvement attempts.

Data handling around the tool carries its own duties. The provider faces restrictions on collecting or keeping personal information. Submitted content can remain only as long as necessary for the section, and detected personal provenance data cannot be retained. These belong in the detection-tool design review, separate from model inference logs.

Manifest and latent disclosures serve different jobs

For covered image and video content or covered audio content created or altered by the system, a manifest disclosure option is required from the provider. The visible disclosure identifies the content as AI generated and must be clear and conspicuous, medium-appropriate and understandable, and difficult to remove where technically feasible.

The latent disclosure applies to AI-generated covered media. Where technically feasible and reasonable, it conveys the covered provider and system name and version, plus creation or alteration time and a unique identifier, directly or through a permanent website link. It must be detectable by the provider's tool and consistent with widely accepted industry standards. It must also be difficult to remove where technically feasible.

Keep these tests separate in the SB 942 compliance checklist. A visible badge proves the manifest path. A file inspected through the provider's detection API proves a different mechanism.

Licensing creates duties for both sides

When a covered provider licenses its GenAI system to a third party, the contract must require the licensee to maintain the latent-disclosure capability. If the provider knows the licensee modified the system so that capability disappeared, the provider must revoke the license within 96 hours of discovering the action. The licensee must cease using the system after revocation.

This is where role labels become operational. The provider needs a license inventory and a capability-test schedule, along with a dated discovery record and a revocation path. The licensee needs change control around any component that can alter the output pipeline. Our SB 942 incident-reporting guide covers the 96-hour clock and the three records that make it provable.

I would reject a contract clause as the sole control. A promise to preserve provenance needs a recurring sample that shows the licensed deployment still produces it.

AB 853 changes the dates and adds new actors

The chaptered AB 853 text moved the chapter's operative date to August 2, 2026. It also added duties with later dates. Large online platforms have provenance-detection and user-interface obligations, plus inspection and anti-stripping obligations beginning January 1, 2027. GenAI hosting platforms face a related rule beginning on that date. Capture-device manufacturer duties begin January 1, 2028 for covered devices first produced for sale in California on or after that date.

Those actors have separate definitions and thresholds. A large online platform, for example, uses a threshold above 2,000,000 unique monthly users during the preceding 12 months. Avoid importing that threshold into the covered-provider test, which retains the over-1,000,000 monthly visitor or user language.

Civil enforcement also deserves precision. AB 853 states a $5,000 civil penalty per violation, with each day a covered provider or large online platform, or a capture-device manufacturer, remains in violation treated as a discrete violation.

DeepInspect

DeepInspect provides an independent policy decision at the HTTP AI request boundary. For LLM and multimodal calls deliberately routed through it, DeepInspect evaluates the application-supplied identity and role against organizational policy for content classification and model authorization before the request reaches the endpoint.

Each decision produces a signed, tamper-evident record outside the calling application's write path. That evidence shows which authenticated actor and model route were involved, under which policy and when. The SB 942 content mechanisms remain separate generation-layer controls, which keeps the compliance claim inside the boundary the architecture can support.

Book a technical deep dive at deepinspect.ai.

Frequently asked questions

Does SB 942 apply to every large language model?

The statute's GenAI definition includes systems that generate text, but covered-provider status also requires the creator or producer role and the user or visitor threshold. It further requires public accessibility in California. The operative detection and disclosure mechanisms focus on image and video content, plus audio content. Assess a text-only system and a multimodal system against those elements rather than using the LLM label as the conclusion.

Is an enterprise customer a covered provider?

Ordinary use of a third-party API points to a customer or deployer role. Creating, coding, or otherwise producing the GenAI system can produce a different result, especially where an enterprise develops or materially changes its own system. A licensee also carries the specific duty to cease use after revocation and must preserve latent-disclosure capability through the contract. Legal should classify the role against the actual build and licensing facts.

What changes for a multimodal assistant?

Inventory each enabled output path. Generated images and audio, plus generated video, bring the content mechanisms into focus: detection-tool coverage and a manifest option, plus latent disclosure. Preserve a sample for each medium and model version. Test downstream export paths because editing and transcoding components can affect provenance after generation.

Where does DeepInspect fit against the LLM requirements?

DeepInspect covers HTTP traffic deliberately routed between authenticated users or agents and LLM endpoints. It can evaluate application-supplied identity and model authorization, plus content policy, before forwarding and can record the decision. It cannot create latent disclosures, render a manifest label, operate the provider's public detection tool, or preserve provenance through an unrelated downstream editor. Those duties stay with the generation and distribution systems.