Since 2 August 2026, the big generative AI tools have been under a legal duty to write provenance data into the images they produce. California’s AI Transparency Act became operative that day, and the statutory text is short about it: “This chapter shall become operative on August 2, 2026.”

You are not the party being regulated. The duty sits on the companies that build the generators, not on the sellers who use them. But the second order effect lands squarely on your listing gallery, and it is the reason this matters more than another compliance headline. The working assumption behind a lot of AI product photography has been that nobody can tell. As of this month, for content coming out of any generator large enough to be covered, that assumption is no longer safe. The file itself now carries a record of what made it.

What actually became operative

The law applies to a “covered provider”, defined in statute as “a person that creates, codes, or otherwise produces a generative artificial intelligence system that has over 1,000,000 monthly visitors or users and is publicly accessible within the geographic boundaries of the state.” That threshold catches the mainstream image tools. It does not catch a seller, an agency, or a brand that merely uses one.

Covered providers now owe three things.

  • A free AI detection tool. Providers must make available, at no cost, a publicly accessible tool that lets a user check whether a given piece of content was created or altered by that provider’s system, and that outputs any system provenance data it detects.
  • An optional manifest disclosure. Providers must offer users the option of a visible disclosure in the content. It is user elected, not automatic, so a visible “made with AI” mark is a choice rather than a default.
  • A mandatory latent disclosure. This is the one that changes the ground under you. Providers must embed a latent disclosure in AI-generated image, video and audio content conveying the name of the provider, the name and version number of the system, the time and date of creation or alteration, and a unique identifier, either directly or through a link to a permanent internet website.

The latent disclosure is invisible to the eye. That is the point. It travels inside the file rather than on top of the picture, which means a clean-looking render with no watermark in the corner can still announce its own origin to anything that reads it.

The scope is narrower than the headlines suggest in one useful way: the chapter covers “image, video, or audio content, or content that is a combination thereof”. Standalone text is outside it. Your bullet points and your A plus copy are not touched by this law.

If the image can no longer be anonymous, the listing has to win on everything else. Helium 10 covers the parts of a listing you fully control, keyword research, indexing and ranking, in one place. Code ECOMMGM10.

Try Helium 10

Affiliate link. E-CommSphere may earn a commission at no extra cost to you.

The penalty explains why the tools will comply

The enforcement design is what makes this real rather than aspirational. Under section 22757.4, “a covered provider that violates this chapter shall be liable for a civil penalty in the amount of five thousand dollars ($5,000) per violation to be collected in a civil action filed by the Attorney General, a city attorney, or a county counsel.” The next sentence is the sharp one: “Each day that a covered provider is in violation of this chapter shall be deemed a discrete violation.”

Five thousand dollars is trivial for a large AI company. Five thousand dollars a day, accruing per violation, with a prevailing plaintiff entitled to reasonable attorney’s costs and fees, is not. That is why the sensible planning assumption is that the major generators embed provenance and keep embedding it. And because these are global products, a California-shaped change tends to ship to everyone rather than to Californian users alone.

What this does and does not change for a seller

To be direct about it, because this is where most coverage goes wrong: the law creates no new obligation for you. There is no seller registration, no new field to fill, no disclosure you personally owe under this statute. If you generate a product lifestyle image today, the tool handles the disclosure and you are not the party at risk of the penalty.

What changes is the evidentiary picture, in three ways.

Detectability stopped being a gamble. A free, provider-run detection tool is now a required feature. A competitor, a marketplace, a journalist or a customer with a grievance can put your hero image into it and get an answer. The check no longer depends on someone’s eye for six-fingered hands.

The provenance record is specific, not generic. A latent disclosure carrying provider name, system name and version, and a creation timestamp is not a vague “this looks synthetic” signal. It is a dated record of which tool made the asset and when.

Your own archive is now readable too. The obligation attaches to content created or altered from the operative date forward. Assets generated before 2 August are not retrofitted. That means your gallery is likely a mix, which matters if you ever need to answer a question about a specific image rather than about your practice in general.

Auditing a catalogue is a data job before it is a design job. Helium 10 lets you pull your live listings and their images into one view so you can work through a gallery review ASIN by ASIN instead of tab by tab. Code ECOMMGM10.

Try Helium 10

Affiliate link. E-CommSphere may earn a commission at no extra cost to you.

Amazon’s own rule is a separate track

Amazon has its own requirement for AI-generated people, and it is worth being precise about the difference, because the two are easy to blur into a single scare story.

Amazon asks sellers to add the keyword contains-synthetic-performer to the dc:subject field of an image’s XMP metadata, set with an IPTC-compatible metadata editor before upload. It covers product images, lifestyle images, product videos and A plus Content that show photorealistic AI-generated people, across Amazon’s worldwide stores. The exemptions are as important as the rule: content showing only real people, even where AI tools were used to alter them, characters from films, television, video games or similar expressive works, content with no people in it, and non-photorealistic people.

Two things about that policy have not changed. Amazon has published no enforcement date, and there is no evidence of listings being suppressed over it. What has changed is the surrounding environment: an Amazon-side disclosure you set by hand now sits alongside a provider-side disclosure that arrives automatically. A gap between the two is a gap someone can measure.

The 2027 clause, and the limit of it

There is a second wave, and it is being misread. From 1 January 2027, a “large online platform” must not, to the extent technically feasible, knowingly strip system provenance data or a compliant digital signature from content uploaded or distributed on it, and must provide a user interface disclosing the availability of that data and letting a user inspect it.

Whether that reaches a marketplace listing page depends on the statutory definition, which is narrow. A large online platform is “a public-facing social media platform, file-sharing platform, mass messaging platform, or stand-alone search engine that distributes content to users who did not create or collaborate in creating the content that exceeded 2,000,000 unique monthly users during the preceding 12 months.” The only carve-outs written into the definition are broadband internet access services and telecommunications services.

Read plainly, that list is social media, file sharing, mass messaging and search. A product detail page is none of those four things on the face of the definition. So the honest position is this: the 2027 provenance-preservation duty is not plainly a duty on Amazon’s listing pages, and anyone telling you Amazon must stop stripping metadata from your photos in 2027 is asserting something the definition does not clearly say. It does land on the social surfaces where your creative also lives, which is a different and more likely route for an AI-generated ad asset to be flagged.

A third wave follows on 1 January 2028, when manufacturers of capture devices such as cameras and recorders selling in California must let users include these disclosures in captured content by default. That closes the loop from the other end: authentic camera files start carrying their own provenance, which makes the absence of it on a “photograph” informative in itself.

The practical read

Nothing here obliges you to stop using AI imagery, and nothing here fines you for having used it. The change is quieter and more durable than a ban. The cost of finding out has collapsed, the answer is now specific and dated, and it is delivered by a tool the generator is legally required to hand out for free.

Operators who treated “undetectable” as part of the value of AI product photography have lost that part. What remains is the part that was always defensible: the image is accurate about the product, the people in it are disclosed where Amazon’s policy asks for it, and nothing in the gallery makes a claim the product cannot keep. That standard survives detection.

Sources

Leave a Reply

Your email address will not be published. Required fields are marked *