California SB 1000: no user threshold, new verification tool
SB 1000 recasts the California AI Transparency Act: no user threshold, a disclosure verification tool, no manifest option. What Sume's docs list.

SB 1000's digest says it would recast the California AI Transparency Act (CATA) to delete the user threshold from "covered provider," replace "AI detection tool" with "disclosure verification tool," and delete the requirement to offer users a manifest disclosure option. It also adds to the latent disclosure whether the GenAI system created or altered the content. It declares an urgency statute, to take effect immediately.
This reads the enrolled text (August 30, 2026) on the leginfo page and the Governor's September 30 release, read 2026-10-01. The enrolled text is the version I read; check leginfo for the final chaptered text. This is not legal advice and says nothing about whether Sume is a covered provider.
What changed in the text I read?
| Topic | Before | In SB 1000 |
|---|---|---|
| Covered provider | Over 1,000,000 monthly visitors or users | Any person producing a publicly accessible GenAI system in California; no threshold |
| Tool name | AI detection tool | Disclosure verification tool |
| Manifest disclosure | Provider offers the user an option | Requirement deleted |
| Latent disclosure | Provider name, system, time, identifier | Also whether the GenAI system created or altered the content |
What must the verification tool do?
Section 22757.2 lists criteria: it lets a user assess whether image, video or audio was created or altered (beyond minor modification) by the provider's system, outputs detected system provenance data, is publicly accessible, accepts an upload or URL, and supports an API so it can be invoked without visiting the provider's site. A provider may instead direct users to a compliant third-party tool.
What does Sume's documentation list?
Looking only at the pages cited here: GET /v1/catalog discovers capabilities, models, runtime readiness and pricing metadata. Image requests accept output_format of png, jpeg, webp or svg, and results return a media.sume.com URL. The metadata field is caller metadata stored on the job and not sent to the provider. None of these pages describes a provenance mark or a verification tool, and I am not claiming one exists.
For the earlier bill and what the docs say about marks, see latent vs manifest disclosure and whether Sume adds C2PA or a watermark.
What should a developer do now?
If you ship AI media to California users, ask counsel whether you are a covered provider under the new definition, and whether your own pipeline strips or alters any marks a model provider adds. Keep your own record of job ids and result URLs so you can answer questions about where a file came from.
Sources
Related posts
More in Developers
- Green screen removal by API: chromakey in a video filter graph
Sume's video filter allowlists chromakey and colorkey, but an MP4 holds no alpha, so a key must be composited inside the graph. Not AI background removal.
- Claude API compaction block: keep Sume job ids past the summary
The compact-2026-09-04 beta swaps old messages for a signed compaction block. Keep Sume job ids and keys outside it; re-read with jobs_status.
- Claude mcp_tool_listing pin: what a Sume tool list depends on
A pinned mcp_tool_listing holds the Sume tool list fetched for one session scope. Sume's list depends on mcp:read vs mcp:write and never pushes list changes.
- Claude Code MCP 403 insufficient_scope: re-auth Sume with Write
Claude Code 2.1.274 names the missing permission on a 403 insufficient_scope. For Sume, a read-only grant lacks mcp:write: re-authenticate and turn Write on.
Written by Sume