Effective soonSB 942 (2024); amended by AB 853 (2025)California

California AI Transparency Act for Healthcare

How California AI Transparency Act applies to healthcare organizations and the obligations to plan for.

Effective
August 2, 2026
Max penalty
$5K
Applies to
developer + platform + device manufacturer

Why this law matters for healthcare

Healthcare providers, payers, and health-tech vendors deploying AI for clinical decision support, diagnostics, prior authorization, or patient interaction.

For healthcare, the AI Transparency Act matters as a content-provenance regime rather than a clinical-AI rule: its covered-provider duties attach to whoever builds a public generative AI system exceeding 1,000,000 monthly California users, so they bite when a digital-health company is itself the AI developer or when an organization publishes AI-generated patient or marketing media — not when a hospital merely deploys a third-party clinical tool. Organizations operating in California should treat this law as part of the baseline regulatory obligations alongside any sector-specific federal rules.

Key obligations

Industry-specific compliance considerations

The California AI Transparency Act (SB 942, codified at Bus. & Prof. Code Chapter 25 and amended by AB 853) is a content-provenance and disclosure law, not a clinical-AI safety statute. It reaches healthcare not by regulating diagnosis or treatment decisions, but by governing AI-generated and AI-altered image, video, and audio content — and it places its core duties on the "covered provider" that builds the generative AI system, which most hospitals and health systems are not. The healthcare-relevant question is therefore narrower than it first appears: when does a healthcare organization become a covered provider, and what does the Act require of the AI-generated content it publishes?

Does the California AI Transparency Act apply to hospitals and healthcare providers?

Chapter 25 imposes its primary duties on a "covered provider" — defined as a person that creates, codes, or otherwise produces a generative AI system that has over 1,000,000 monthly visitors or users and is publicly accessible within California. A typical hospital, clinic, payer, or provider group that buys and deploys a third-party generative AI tool is a user of that system, not its covered provider, so the covered-provider obligations operative August 2, 2026 fall on the AI developer rather than the healthcare deployer.

The Act does reach healthcare organizations directly in three situations: (i) when a digital-health or health-AI company itself develops a publicly accessible generative AI system that exceeds the 1,000,000-monthly-user threshold in California — for example a consumer-facing symptom-checker or patient-engagement chatbot; (ii) when, under AB 853, an organization operates a large online platform or a generative-AI hosting platform that distributes covered content (operative January 1, 2027); and (iii) when a healthcare organization is a contractual licensee of a covered provider’s system and is required by contract to preserve the system’s disclosure capability.

Which healthcare AI use cases fall under SB 942's covered-provider duties?

Because the Act regulates AI-generated and AI-altered image, video, and audio content, the healthcare use cases most likely to trigger covered-provider analysis are content-producing and patient-facing rather than clinical: large consumer health chatbots and symptom checkers offered to the public, AI image or video generation used in patient-education libraries and health-marketing campaigns, AI-generated or AI-altered media in telehealth and wellness apps, and synthetic-voice patient-communication tools. The threshold question for each is whether the healthcare entity itself produced the underlying generative AI system and meets the 1,000,000-monthly-California-user bar.

Clinical decision support, diagnostic algorithms, prior-authorization triage, and other consequential medical-decision AI sit outside SB 942’s subject matter — those systems are addressed by FDA software-as-a-medical-device oversight, HIPAA, and state consequential-decision regimes such as the Colorado AI Act, not by the AI Transparency Act’s content-provenance rules. Treating SB 942 as a clinical-AI law is a common and material misread.

What are the covered-provider obligations and operative dates for healthcare AI content?

Beginning August 2, 2026 (Section 22757.6), a covered provider must maintain a free, publicly available AI detection tool that lets a user assess whether content was created or altered by the provider’s system; offer users a manifest (visible) disclosure option for AI-generated or AI-altered image, video, or audio content; apply latent (embedded) provenance disclosures to covered content where technically feasible and reasonable; and require its licensees by contract to maintain the system’s disclosure capability. A healthcare entity that qualifies as a covered provider must build these surfaces into any qualifying patient-facing generative product.

AB 853 adds later phase-in duties that can reach healthcare distribution and hardware: large online platforms and generative-AI hosting platforms become subject to detection, disclosure, and anti-stripping duties on January 1, 2027, and capture-device manufacturers must support latent disclosures for devices first produced for sale in California on or after January 1, 2028. Health systems running large patient portals or media platforms, and medical-device makers shipping cameras or recorders, should map these dates even where the August 2, 2026 covered-provider duties do not apply to them.

How does SB 942 interact with HIPAA, FDA, and clinical-AI rules?

SB 942 is additive to, and does not displace, the existing healthcare regulatory stack. HIPAA continues to govern protected health information independently — including AI vendors handling PHI as business associates — and FDA software-as-a-medical-device requirements continue to govern clinical algorithms. The AI Transparency Act’s concern is provenance and disclosure of AI-generated media, so a healthcare organization can simultaneously owe HIPAA, FDA, and SB 942 obligations on different aspects of the same deployment.

Where AI is used for consequential medical decisions affecting California consumers, organizations should also watch consequential-decision frameworks rather than relying on SB 942 to cover that risk. The Act’s penalties are content-disclosure penalties, so a compliance program should not assume that satisfying SB 942 addresses clinical-safety, fairness, or privacy obligations.

For the PHI and ePHI workflow analysis, use the HIPAA compliance for AI in healthcare guide alongside this California content-provenance page.

How should healthcare compliance programs operationalize SB 942 today?

A workable healthcare checklist starts by inventorying public-facing generative AI products the organization itself builds, and determining for each whether it crosses the 1,000,000-monthly-California-user covered-provider threshold; that determination, and its rationale, should be documented so it is defensible if challenged. For products that do qualify, scope the detection tool, manifest-disclosure option, and latent-provenance implementation against the August 2, 2026 date. For third-party generative tools the organization merely deploys, review vendor contracts to confirm the vendor carries the covered-provider duties and that the organization does not strip provenance data from AI-generated patient content.

Compliance programs typically pair these Act-specific controls with NIST AI RMF Map and Govern functions and ISO/IEC 42001 Annex A controls for AI system documentation and transparency, since the primary SB 942 control vector is provenance and disclosure evidence rather than substantive model performance. Enforcement is by civil action: a violator is liable for a civil penalty of $5,000 per violation, with each day of violation deemed a discrete violation, collected by the California Attorney General, a city attorney, or a county counsel.

Recommended next steps

  1. Inventory AI systems used in healthcare workflows that may fall within California AI Transparency Act's scope.
  2. Map each system against the obligations above and identify the responsible role (developer vs deployer).
  3. Adopt a structured framework — see NIST AI RMF and ISO/IEC 42001 — to demonstrate due care and produce audit-ready evidence.
  4. Document obligations satisfied and gaps in a single register, refreshed at the cadence required by the law (typically annual).
Related

We may receive referral commissions from recommended compliance tools. Recommendations are based on product fit and not on commission size. Links marked “partner link” include a tracked redirect.