Content provenance & transparency

The 2026 dates, and a checker.

A plain, dated map of the content-provenance and AI-transparency rules landing across jurisdictions, and a free tool to check whether a file carries a content credential. This is orientation, not advice: whether any rule applies to you depends on what you do and where.

Legal-status caveat. The EU Digital Omnibus amendments were adopted by Parliament (16 Jun 2026) and Council (29 Jun 2026). Confirm Official Journal publication and entry into force before relying on any amended date. Article 50 at 2 August 2026 was not delayed by the Omnibus. We refresh this table monthly.

What lands, and when

DateEventWho it applies to
1 Sep 2025in forceChina AI-content labellingProviders of AI-generated content services in China.
22 Jan 2026in forceKorea AI Basic ActIn-scope AI providers in Korea (fines graced to ~Jan 2027).
2 Aug 2026bindsEU AI Act Art 50: provider marking dutyProviders of generative AI systems must mark synthetic output in a machine-readable way. For systems already on the market before this date, the marking grace runs to 2 Dec 2026 (below).
2 Aug 2026bindsEU AI Act Art 50: deployer disclosure dutyDeployers must disclose AI interaction and label deepfakes / AI-generated or manipulated content. Narrower than, and separate from, the provider marking duty.
2 Aug 2026bindsCalifornia SB 942 / AB 853Covered providers only. See the statutory threshold below. Not every AI product is covered.
1 Sep 2026upcomingTexas AG complaint portal opensComplaint-driven enforcement under TRAIGA (in force since 1 Jan 2026).
2 Dec 2026deadlineEU AI Act Art 50(2): provider marking grace expiresProviders of systems already on the market before 2 Aug 2026 lose the machine-readable-marking grace period.
1 Jan 2027upcomingColorado AI Act (SB 24-205) + Chatbot Safety ActIn-scope developers and deployers of high-risk AI systems in Colorado; California platform duties also begin.

California SB 942: the covered-provider threshold

SB 942 does not apply to every AI product. It reaches a covered provider, a person that creates, codes, or otherwise produces a generative AI system with more than 1,000,000 monthly visitors or users that is publicly accessible within California. Below that threshold, or where the system is not publicly accessible, its provenance-disclosure duties are not triggered. Whether you cross the threshold is a question for your own advisers.

Check a file for a content credential

A quick, in-browser read of whether a file carries a C2PA content credential, whether it still matches the file, and whether it declares AI/generative involvement. Nothing is uploaded; the check runs entirely on your device.

Loading the checker…

Monitoring is coming

Scheduled provenance monitoring and marking-drift alerts, with signed scan records. Register interest for the beta ahead of the 2 December 2026 marking window.

Prefer email? Write to contact@cuecrux.com.

Informational, not legal advice. A content credential establishes provenance, not truth or legal compliance; whether any obligation applies to you depends on your own circumstances. Verify each date against the primary sources linked above; this page is reviewed monthly.