Back to Home

Midjourney Has No AI Watermark as California Fines Begin

August 2, 2026, was the day California stopped asking nicely. The state's AI Transparency Act, Senate Bill 942 as amended by Assembly Bill 853, became fully operative, making California the first US state to enforce a comprehensive AI content provenance mandate. Any AI image, video, or audio system with more than one million monthly users in California must now embed machine-readable provenance data in its outputs, offer a free public detection tool, and let users add visible AI labels to generated content. Non-compliance starts at $5,000 per violation per day, and every day of non-compliance counts as a fresh violation.

And the most recognizable name standing on the wrong side of the compliance line? Midjourney. The company that turned Discord prompts into a cultural phenomenon has been a member of the Content Authenticity Initiative, the industry body behind the C2PA standard, since 2023. It has shipped exactly none of it: no C2PA content credentials, no documented pixel watermark, no public detection tool.

The Three Requirements That Just Went Live. SB 942 splits its obligations into three concrete duties. A "covered provider" is any operator of a publicly accessible generative AI system with more than one million monthly visitors or users in California, a threshold that applies per system rather than per company. The three requirements are:

  • A free public detection tool, usable without an account, that lets anyone check whether an image, video, or audio file came from that provider's AI system, supporting both file uploads and URLs, with an API for programmatic access.
  • A manifest disclosure option: users must be able to attach a visible, hard-to-remove "AI-generated" label to content they create.
  • Latent disclosure: every output must automatically embed machine-readable provenance metadata identifying the provider, system name and version, and creation timestamp, using "widely accepted industry standards", language widely read as pointing to C2PA.

Text-only outputs are exempt from all three. OpenAI's openai.com/verify tool, launched in May 2026 alongside its C2PA and SynthID dual-layer rollout, is the reference example of a compliant detection tool, even though it only verifies images from OpenAI's own systems.

The Scorecard: Midjourney vs the Compliant Crowd

Compare Midjourney's posture with the providers that showed up prepared. The field is not subtle about who did the homework.

ProviderC2PA credentialsPixel watermarkPublic detection tool
OpenAIYes (May 2026)SynthIDopenai.com/verify
GoogleYesSynthIDYes
AdobeYes (Firefly)YesYes
MetaYesPartialYes
MidjourneyNoneNone documentedNone

OpenAI, Google, Adobe, Meta, ElevenLabs, and Stability AI have all deployed C2PA content credentials, SynthID watermarks, or both. Midjourney, despite its CAI membership, is the highest-profile provider exposed to enforcement action on day one, with an estimated user base of over 20 million registered users that almost certainly clears the California threshold.

The Enforcement Architecture Nobody Is Laughing At

The penalties are not just big; they are built to compound. Each deficiency counts as a separate violation, so a provider that fails to deploy a compliant detection tool for 30 days faces $150,000 in exposure from that single gap before attorney's fees. There is no general notice-and-cure period. What makes SB 942 structurally unusual is that enforcement standing extends beyond the Attorney General to city attorneys and county counsel, with a fee-shifting provision that lets prevailing plaintiffs recover legal costs. Local prosecutors now have both the authority and the financial incentive to pursue well-resourced companies.

There is also a 96-hour license revocation rule aimed squarely at the open-source ecosystem: if a covered provider discovers a third-party licensee has modified a licensed AI system in a way that makes compliance technically impossible, the provider must revoke that license within 96 hours. Providers now need audit rights and technical monitoring in their license agreements, or they inherit their licensees' non-compliance.

The Catch: Watermarks Die on Instagram

Here is where the comparative review gets interesting, because compliance and detectability are not the same thing. C2PA metadata is stripped when an image is screenshotted, uploaded to Instagram, reposted on X, or passed through WhatsApp. A May 2026 study found that while 75-85 percent of AI-generated images from major platforms carry provenance at the point of generation, only 30-50 percent still carry it when distributed online.

The law knows this. Starting January 1, 2027, large online platforms with more than two million monthly users must detect compliant provenance data, surface it to users, and explicitly prohibit stripping it. Until then, enforcement covers only the provider side, and Instagram, X, and WhatsApp face no obligation to preserve what they currently destroy. The C2PA 2.1 specification's "durable credentials" approach, which layers cryptographic metadata, pixel-level watermarking, and server-side hash storage, can survive stripping, but whether California's "technically feasible and reasonable" standard requires that full stack remains unanswered.

The Verdict. Round one goes to the compliant crowd. OpenAI, Google, and Adobe built the infrastructure, and the synchronized date was deliberate: August 2 also marks full enforcement of the EU AI Act's Article 50 across all 27 member states, creating a transatlantic watermarking standard with EU penalties reaching up to roughly $17.3 million or 3 percent of global turnover. A provider that ignores both faces exposure from two directions at once.

Midjourney is the outlier in that picture, but the story is not a simple win for regulation. A pending urgency bill, SB 1000, passed the California Senate 33-1 in May and could rewrite parts of the law if signed, potentially removing the one-million-user threshold and deleting the manifest disclosure duty. And for users, one uncomfortable fact remains: an image with no watermark proves only that it did not come from a compliant provider, not that it was made by a human. In 2026, absence of evidence is not evidence of authenticity.

Comments

No comments yet. Be the first to share your thoughts!