Back to Blog

California's AI Transparency Act Has an Open Source Problem — and the EU Has Already Solved It

AIPolicy

California’s AI Transparency Act (SB 942) goes live August 2, 2026 — and most of the tech industry is largely fine with that. Require AI detection tools. Label AI-generated content. Embed metadata in image and video outputs. These are reasonable transparency asks. But a proposed amendment tucked into SB 1000 contains a provision that GitHub, Hugging Face, Mozilla, and Black Forest Labs are calling a quiet threat to the open source software supply chain.

What the Law Actually Requires

SB 942 targets “covered providers” — AI systems with over one million monthly California users. The law’s three core obligations: offer a free AI detection tool for image, video, and audio content; apply visible labels (watermarks, overlays) to AI-generated media; and embed latent metadata in all AI-generated outputs. Notably, text-only outputs are exempt.

That’s the baseline law, and it’s defensible. The transparency goal is legitimate. The problem is in the amendment.

The Provision That Breaks Open Source

SB 1000 proposes to extend SB 942 and introduces a new enforcement mechanism: if downstream users of your AI system fail to meet certain compliance requirements, the developer must revoke their license to use the code.

The problem is structural. Open source licenses — MIT, Apache 2.0, GPL — are designed to be perpetual and irrevocable. That’s not an oversight. It’s the architectural principle that allows developers to reliably build on, fork, and ship software without legal landmines. The moment you introduce revocability into that contract, the trust model collapses. And trust is what makes collaborative software development work at scale.

This matters beyond just a legal technicality. California is home to a significant share of open source AI tooling — models, weights, inference frameworks. Introducing conditional licensing into that ecosystem creates uncertainty that ripples through every team downstream.

What the EU Got Right

This is where the comparison to Europe becomes instructive. The EU AI Act includes Article 50, which establishes transparency obligations for AI-generated content — directly parallel to what SB 942 is trying to accomplish. The EU also published a Code of Practice on marking and labeling AI-generated content to help providers implement those obligations.

Critically, the EU Code of Practice explicitly recognizes the distinct nature of the open source ecosystem. Rather than requiring license revocation, it treats notifying downstream users of best practices through documentation as sufficient compliance. The transparency objective is preserved. The legal architecture of open collaboration is not disturbed.

California is trying to solve a problem the EU already thought through — and landed somewhere more technically sound.

What the Coalition Is Actually Asking For

The coalition letter is narrow and specific. Fix the license revocation provision. Align the enforcement mechanism with the EU framework. Leave the rest of SB 942’s transparency requirements intact. As the letter notes, developers who modify and deploy AI systems are already directly covered by the existing law — adding a downstream revocation requirement doesn’t strengthen enforcement, it just creates incompatibility with how software is licensed.

This isn’t an argument against AI transparency regulation. It’s an argument for regulation that accounts for how the ecosystem it’s regulating actually works. California has been active on AI policy this cycle — AB 1043’s age verification requirements being another example of sweeping obligations with downstream software implications — and getting the open source compatibility question right here matters for the credibility of what comes next.

August 2, 2026 is weeks away. If the amendment isn’t fixed before enforcement begins, open source developers face a choice between compliance and the licensing principles their tools are built on.

Further Reading

AI Disclosure

This document is drafted by an AI skill and is provided for informational and governance support purposes only. It does not constitute legal advice or a formal compliance determination. Do not publish or rely on this notice as a substitute for review by qualified legal counsel or a licensed compliance professional with jurisdiction-specific expertise.