In effectSB 942 (2024); amended by AB 853 (2025)California

California AI Transparency Act for Healthcare

How California AI Transparency Act applies to healthcare organizations and the obligations to plan for.

Effective
August 2, 2026
Max penalty
$5K
Applies to
developer + platform + device manufacturer

Why this law matters for healthcare

Healthcare providers, payers, and health-tech vendors deploying AI for clinical decision support, diagnostics, prior authorization, or patient interaction.

For healthcare, the AI Transparency Act matters as a content-provenance regime rather than a clinical-AI rule: its covered-provider duties attach to whoever builds a public generative AI system exceeding 1,000,000 monthly California users, so they bite when a digital-health company is itself the AI developer or when an organization publishes AI-generated patient or marketing media — not when a hospital merely deploys a third-party clinical tool. Organizations operating in California should treat this law as part of the baseline regulatory obligations alongside any sector-specific federal rules.

Key obligations

Industry-specific compliance considerations

California regulates healthcare AI through three separate statutes with three different triggers, and only one of them is the AI Transparency Act: AB 3030 (2024, Ch. 848) covers generative AI used to write clinical patient communications, SB 1120 (2024, Ch. 879) covers AI used in payer utilization review, and SB 942 covers the provenance of AI-generated media. The California AI Transparency Act (SB 942, codified at Bus. & Prof. Code Chapter 25 and amended by AB 853) is a content-provenance and disclosure law, not a clinical-AI safety statute. It reaches healthcare not by regulating diagnosis or treatment decisions, but by governing AI-generated and AI-altered image, video, and audio content — and it places its core duties on the "covered provider" that builds the generative AI system, which most hospitals and health systems are not. The healthcare-relevant question is therefore narrower than it first appears: when does a healthcare organization become a covered provider, and what does the Act require of the AI-generated content it publishes?

Does the California AI Transparency Act apply to hospitals and healthcare providers?

Chapter 25 imposes its primary duties on a "covered provider" — defined as a person that creates, codes, or otherwise produces a generative AI system that has over 1,000,000 monthly visitors or users and is publicly accessible within California. A typical hospital, clinic, payer, or provider group that buys and deploys a third-party generative AI tool is a user of that system, not its covered provider, so the covered-provider obligations operative August 2, 2026 fall on the AI developer rather than the healthcare deployer.

The Act does reach healthcare organizations directly in three situations: (i) when a digital-health or health-AI company itself develops a publicly accessible generative AI system that exceeds the 1,000,000-monthly-user threshold in California — for example a consumer-facing symptom-checker or patient-engagement chatbot; (ii) when, under AB 853, an organization operates a large online platform or a generative-AI hosting platform that distributes covered content (operative January 1, 2027); and (iii) when a healthcare organization is a contractual licensee of a covered provider’s system and is required by contract to preserve the system’s disclosure capability.

Which California laws govern clinical and patient-facing healthcare AI instead of SB 942?

As of August 17, 2026, California reaches healthcare AI through three statutes with three different subject matters, and a compliance program that maps only the AI Transparency Act will miss two of them. AB 3030 (2024, Chapter 848, approved September 28, 2024) added Health and Safety Code Chapter 2.13, commencing with Section 1339.75, and governs generative AI used to produce written or verbal patient clinical information. SB 1120 (2024, Chapter 879, approved September 28, 2024) amended Health and Safety Code Section 1367.01 and Insurance Code Section 10123.135 and governs AI and algorithms used in payer utilization review. SB 942, as amended by AB 853, governs provenance and disclosure of AI-generated image, video, and audio content, with covered-provider duties operative August 2, 2026. Neither AB 3030 nor SB 1120 carries an urgency clause or a special operative date in its chaptered text, so both took effect January 1, 2025 under California’s default effective-date rule for statutes enacted in the 2024 regular session.

The distinction that matters operationally is which party each statute binds. AB 3030 binds the health facility, clinic, physician’s office, or group practice sending the communication: a generative-AI communication conveying patient clinical information must carry a disclaimer that it was generated by generative artificial intelligence, displayed prominently at the start of written communications, throughout continuous chat interactions, and verbally at the start and end of audio, together with clear instructions describing how the patient may contact a human health care provider or other appropriate person. That requirement does not apply at all where a communication generated by generative AI is read and reviewed by a human licensed or certified health care provider before it goes out, so the compliance path is a review workflow rather than a technology control. SB 1120 binds the health care service plan or disability insurer conducting the review and requires that a determination of medical necessity be made only by a licensed physician or licensed health care professional competent to evaluate the specific clinical issues, after reviewing the requesting provider’s recommendation and the patient’s clinical information — AI may inform that review but cannot make the determination. SB 942 binds neither of those parties: its duties fall on the covered provider that produced the generative AI system. A hospital deploying a purchased generative AI scribe can therefore owe AB 3030 disclaimer duties while owing no SB 942 covered-provider duties at all, and clinical algorithms functioning as medical devices remain subject to FDA software-as-a-medical-device oversight, which none of the three California statutes displaces.

Which healthcare AI use cases fall under SB 942's covered-provider duties?

Because the Act regulates AI-generated and AI-altered image, video, and audio content, the healthcare use cases most likely to trigger covered-provider analysis are content-producing and patient-facing rather than clinical: large consumer health chatbots and symptom checkers offered to the public, AI image or video generation used in patient-education libraries and health-marketing campaigns, AI-generated or AI-altered media in telehealth and wellness apps, and synthetic-voice patient-communication tools. The threshold question for each is whether the healthcare entity itself produced the underlying generative AI system and meets the 1,000,000-monthly-California-user bar.

Clinical decision support, diagnostic algorithms, prior-authorization triage, and other consequential medical-decision AI sit outside SB 942’s subject matter — those systems are addressed by FDA software-as-a-medical-device oversight, HIPAA, and state consequential-decision regimes such as the Colorado AI Act, not by the AI Transparency Act’s content-provenance rules. Treating SB 942 as a clinical-AI law is a common and material misread.

What are the covered-provider obligations and operative dates for healthcare AI content?

Beginning August 2, 2026 (Section 22757.6), a covered provider must maintain a free, publicly available AI detection tool that lets a user assess whether content was created or altered by the provider’s system; offer users a manifest (visible) disclosure option for AI-generated or AI-altered image, video, or audio content; apply latent (embedded) provenance disclosures to covered content where technically feasible and reasonable; and require its licensees by contract to maintain the system’s disclosure capability. A healthcare entity that qualifies as a covered provider must build these surfaces into any qualifying patient-facing generative product.

AB 853 adds later phase-in duties that can reach healthcare distribution and hardware: large online platforms and generative-AI hosting platforms become subject to detection, disclosure, and anti-stripping duties on January 1, 2027, and capture-device manufacturers must support latent disclosures for devices first produced for sale in California on or after January 1, 2028. Health systems running large patient portals or media platforms, and medical-device makers shipping cameras or recorders, should map these dates even where the August 2, 2026 covered-provider duties do not apply to them.

How does SB 942 interact with HIPAA, FDA, and clinical-AI rules?

SB 942 is additive to, and does not displace, the existing healthcare regulatory stack. HIPAA continues to govern protected health information independently — including AI vendors handling PHI as business associates — and FDA software-as-a-medical-device requirements continue to govern clinical algorithms. The AI Transparency Act’s concern is provenance and disclosure of AI-generated media, so a healthcare organization can simultaneously owe HIPAA, FDA, and SB 942 obligations on different aspects of the same deployment.

Where AI is used for consequential medical decisions affecting California consumers, organizations should also watch consequential-decision frameworks rather than relying on SB 942 to cover that risk. The Act’s penalties are content-disclosure penalties, so a compliance program should not assume that satisfying SB 942 addresses clinical-safety, fairness, or privacy obligations.

For the PHI and ePHI workflow analysis, use the HIPAA compliance for AI in healthcare guide alongside this California content-provenance page.

How should healthcare compliance programs operationalize SB 942 today?

A workable healthcare checklist starts by inventorying public-facing generative AI products the organization itself builds, and determining for each whether it crosses the 1,000,000-monthly-California-user covered-provider threshold; that determination, and its rationale, should be documented so it is defensible if challenged. For products that do qualify, scope the detection tool, manifest-disclosure option, and latent-provenance implementation against the August 2, 2026 date. For third-party generative tools the organization merely deploys, review vendor contracts to confirm the vendor carries the covered-provider duties and that the organization does not strip provenance data from AI-generated patient content.

Compliance programs typically pair these Act-specific controls with NIST AI RMF Map and Govern functions and ISO/IEC 42001 Annex A controls for AI system documentation and transparency, since the primary SB 942 control vector is provenance and disclosure evidence rather than substantive model performance. Enforcement is by civil action: a violator is liable for a civil penalty of $5,000 per violation, with each day of violation deemed a discrete violation, collected by the California Attorney General, a city attorney, or a county counsel.

Recommended next steps

  1. Inventory AI systems used in healthcare workflows that may fall within California AI Transparency Act's scope.
  2. Map each system against the obligations above and identify the responsible role (developer vs deployer).
  3. Adopt a structured framework — see NIST AI RMF and ISO/IEC 42001 — to demonstrate due care and produce audit-ready evidence.
  4. Document obligations satisfied and gaps in a single register, refreshed at the cadence required by the law (typically annual).
Related

We may receive referral commissions from recommended compliance tools. Recommendations are based on product fit and not on commission size. Links marked “partner link” include a tracked redirect.