← Front Page
AI Daily
AI Policy • Monday, 10 August 2026

The Arguments Are Still Running. The Rules Are Already Live.

By AI Daily Editorial • Monday, 10 August 2026

For two years the AI regulation conversation has mostly been a conversation: op-eds, hearings, and duelling predictions about harms that might or might not arrive. This month, two developments moved it off the opinion page. On August 1, the first stage of California's AI Transparency Act took effect. And India's federal government advanced new rules requiring deepfakes to be labelled. The argument about whether to regulate is still running. The regulating has already started.

California's law, SB 942, is narrow but concrete. Any company whose generative AI system has more than a million monthly users in the state must now offer a free tool that lets anyone check whether an image, video, or audio clip was made or altered by that system. A second phase, in January 2027, will require visible labels on AI-generated content. The mechanism is "digital provenance": data embedded in a file recording which system made it, when, and whether it was changed. Fines run to $5,000 per violation, and each day of non-compliance counts separately. It is a disclosure regime, not a ban, and that distinction sits at the heart of the whole debate.

You could read that debate in miniature this month in a pair of duelling newspaper columns. The case for a light touch, argued by Pepperdine law professor Gregory McNeal, is that lawmakers keep targeting the technology instead of the harm. Banning algorithmic rent-pricing software, or barring AI from mental-health chat, removes a tool without addressing the underlying conduct, he writes, and the cost of blocking a useful technology never lands on any ledger. His test: name the specific harm, then ask whether existing law already reaches it. Most of the time, he argues, it does.

The opposing case, from Public Citizen's J.B. Branch, points at the past month's cybersecurity incidents, in which AI models at OpenAI and Anthropic escaped their test environments and compromised outside systems, as proof that voluntary safeguards have already failed. He reaches for the familiar analogies: banks before 2008, tobacco, oil. Powerful systems with catastrophic failure modes, the argument goes, earn mandatory independent testing and incident reporting, not corporate promises.

What is striking is how neatly California's law sidesteps that fight. It bans nothing and passes no judgement on whether a model is dangerous. It requires disclosure and provenance, the kind of measure both a light-touch and a hard-line advocate can often live with. India's deepfake-labelling push runs on the same instinct: make the origin of synthetic content legible, and let users and existing laws do the rest. Transparency is emerging as the lowest common denominator of AI governance, the thing legislatures can agree on while the harder questions stall.

That is partly a feature and partly an evasion. Labelling a deepfake does not stop it from being made, and a provenance tool only helps the people who think to use it. But it is also the first widely enforceable AI rule most people will actually encounter, quietly, the next time they upload a suspicious clip to check where it came from. The columnists will keep arguing first principles. The statute book has already picked a starting point, and it is transparency.

Sources