Provenance and Disclosure
Purpose
Every AI-generated image needs a paper trail: who made it, what model, what prompt, what date, what permissions. C2PA Content Credentials, SynthID watermarks, and EXIF AI-disclosure tags are the 2026 standards. Without them, commercial use, journalism, regulated industries, and EU AI Act compliance all break. This reference defines the embedding, verification, and takedown-response protocol.
Scope Boundary
- IN scope: C2PA Content Credentials, SynthID, EXIF / XMP AI tags, watermark verification, takedown-request response, platform-specific disclosure norms.
- OUT of scope: image generation itself (
generate), prompt design (prompt/cinematic), upscaling (upscale), policy refusals (policy), copyright case-by-case legal review (delegate toclause).
Core Concepts
Why Provenance Matters in 2026
| Driver | Effect |
|---|---|
| EU AI Act Article 50 | Mandates AI-content disclosure for "deepfakes" and synthetic content; enforcement from 2026 |
| US state laws (CA, NY, TX) | Require AI-disclosure for political ads, deepfakes |
| Platform policy (Meta, X, TikTok, YouTube) | Most major platforms require AI-content labels |
| Journalism / news | AP, Reuters, NYT require provenance; reject undocumented synthetic |
| Stock-photo platforms | Adobe Stock, Getty enforce provenance; otherwise reject |
| Brand legal | Liability for misrepresentation if AI not disclosed |
| Court / evidence | C2PA-signed images survive evidentiary challenge |
A 2025 image with no provenance is a 2026 liability.
The Three Standards
| Standard | What it provides |
|---|---|
| C2PA Content Credentials | Cryptographically signed manifest with creation history |
| SynthID (Google) | Invisible pixel-level watermark, robust to crops / compression |
| EXIF / XMP AI tags | Metadata fields readable by editors / DAM systems |
These complement each other: C2PA for chain-of-custody, SynthID for tamper-evident watermarking, EXIF for legacy compatibility.
C2PA Content Credentials
The Coalition for Content Provenance and Authenticity (Adobe, Microsoft, BBC, NYT, etc.) ships an open standard (v2.0 in 2026):
| Manifest Field | Content |
|---|---|
claim_generator |
Tool that created the manifest (e.g., nano-banana-2) |
signature |
X.509 certificate chain |
actions |
Sequence of operations (created, edited, exported) |
assertions |
Specific facts (model name, prompt summary, training-data attestation) |
ingredients |
Source images / references used |
parent_relations |
If derived from prior C2PA-signed image |
Implementation:
# Python c2patool example
from c2pa import builder
builder.add_assertion("c2pa.actions", {
"actions": [{"action": "c2pa.created"}]
})
builder.add_assertion("c2pa.training_data", {
"training_data_used": "Imagen-4 base model, March 2026 checkpoint"
})
builder.sign(certificate, private_key, "output.jpg")Verification: open in Photoshop / Premiere / VLC 4+ — Content Credentials panel shows the manifest. Online: contentcredentials.org/verify.
SynthID
Google's invisible-watermark system (DeepMind 2023, expanded 2024-2026):
| Property | Detail |
|---|---|
| Visibility | Imperceptible to humans |
| Robustness | Survives compression (JPEG quality 60+), cropping (>50% retained), color shifts |
| Detection | Google's SynthID Detector or compatible third-party tools |
| Models supporting | Imagen, Nano Banana, Veo (video), Lyria (audio) |
| API | Embedded automatically in Google AI generations; cannot opt-out |
For Imagen / Nano Banana 2 outputs, SynthID is always on. Disclosure is mandatory; verification gives audiences a way to check.
EXIF / XMP AI Tags
Standard fields for AI-generated images (IPTC and Adobe XMP working groups, 2024+):
XMP-iptcExt:DigitalSourceType = "trainedAlgorithmicMedia"
XMP-iptcExt:DigitalSourceFileType = "image/jpeg"
XMP-photoshop:Credit = "AI generated by Nano Banana 2"
XMP-photoshop:Source = "gemini-3.1-flash-image@google"
EXIF:Software = "Gemini 3.1 Flash Image / 2026-08-19"
EXIF:UserComment = "Prompt summary: portrait, studio lit"Read by Photoshop, Lightroom, DAM systems (Adobe Bridge, Photo Mechanic), social-platform ingestors.
Disclosure Strings (Per Platform)
| Platform | Required disclosure |
|---|---|
| Meta (FB, IG) | "AI-generated" label; auto-detected from C2PA / metadata or self-declared |
| X / Twitter | "Made with AI" community note + manual label |
| YouTube | "Altered or synthetic content" toggle in upload |
| TikTok | "AI-generated" label; auto-applied to known providers |
| "AI-generated" disclosed in post | |
| Subreddit-specific; r/SDForums lenient, r/photography strict | |
| Adobe Stock | Reject without C2PA |
| Getty Images | Reject AI-generated entirely (as of 2024) |
| Shutterstock | Allow with disclosure |
| News outlets | Reject for editorial; allow for clearly-marked illustration |
| Government / regulated | Per-jurisdiction; assume strict |
When in doubt: disclose explicitly in caption + metadata.
Distribution Pipeline
Generate image
↓ embed C2PA + SynthID + EXIF
Sign with project certificate
↓
Optional: edit in Photoshop (preserves C2PA chain)
↓
Export final
↓ verify provenance preserved
Distribute with caption disclosure
↓
Maintain takedown-ready archiveEach step preserves provenance. Stripping metadata at export breaks the chain.
Takedown / Appeal Response
When a platform flags an AI image incorrectly or correctly:
| Scenario | Response |
|---|---|
| Correctly flagged AI, no disclosure attempted | Acknowledge, re-upload with disclosure |
| Correctly flagged AI, disclosure was made | Show C2PA manifest + EXIF metadata |
| Falsely flagged real photo as AI | Show original camera EXIF + RAW |
| User-submitted DMCA on synthetic likeness | Verify training-data attestations, respond per platform DMCA flow |
| Government takedown (regulatory) | Engage clause legal; provide C2PA chain |
Maintain a takedown response log: each event with date, platform, claim, evidence provided, outcome.
Likeness / Public Figure / Minor Cases
Provenance includes attestation of training-data and likeness rights:
| Case | Provenance need |
|---|---|
| Public figure likeness | Document permission OR clearly-labeled satire / commentary |
| Minor depicted | Document age / parental consent OR refuse |
| Trademark / brand depicted | Document fair-use rationale |
| Recognizable person (not public) | Photo release equivalent |
| Historical figure | Public domain often OK; clarify in caption |
Sketch's policy Recipe handles refusals; provenance documents what is permitted.
Long-Term Archive
Keep for 10+ years (or jurisdictional limits):
- Original generation API response (raw bytes).
- Prompt text + parameters.
- C2PA manifest.
- Final signed export.
- Distribution log (where used, when, captioned how).
- Takedown / appeal log.
Storage: S3 with object lock / GCS retention policy / cold archive.
Verification Tools
| Tool | Use |
|---|---|
| contentcredentials.org/verify | Web upload; shows C2PA |
| c2patool CLI | github.com/contentauth/c2patool — script verification |
| Photoshop Content Credentials panel | Designer-friendly |
| Truepic | Mobile capture-to-verify |
| Project Origin (BBC) | News-org C2PA verification |
| Google SynthID Detector | Detects Google AI watermarks |
| Anthropic / OpenAI provenance APIs | Per-vendor verification |
When NOT to Use Provenance Embedding
| Scenario | Reason |
|---|---|
| Internal mock-up / scratch art | No distribution; metadata adds noise |
| Personal hobby art shared informally | Self-declared in caption sufficient |
| Performance-critical thumbnail (<10 KB target) | C2PA adds 5-15 KB; may matter |
Default: embed by default. Skip only with documented reason.
Anti-Patterns
| Anti-pattern | Risk |
|---|---|
| Strip EXIF on export "for privacy" | Breaks provenance; can't prove origin |
| Use "Save for Web" without C2PA preservation | Loses manifest in optimization |
| No takedown-response log | Pattern not visible; same issue recurs |
| Generic "AI generated" without specifying model | Insufficient for some platforms |
| Public-figure depiction without rationale | Legal exposure |
| Trust unsigned images claiming provenance | Forgery risk |
| Skip SynthID detection on third-party uploads | Miss undisclosed AI |
| Disclose only in caption, not metadata | Caption can be stripped |
Workflow
- Choose provenance standards — C2PA (mandatory) + SynthID (auto for Google) + EXIF / XMP (mandatory).
- Set up project certificate — for C2PA signing (per-org or per-project).
- Configure generation pipeline — embed C2PA at first export.
- Document model + prompt in C2PA assertions and EXIF UserComment.
- Preserve manifest through edits — Photoshop / Premiere honor C2PA chain.
- Verify final export — open in c2patool / contentcredentials.org.
- Apply platform disclosure per distribution channel.
- Build long-term archive — original + manifest + distribution log.
- Document takedown-response template for likely scenarios.
- Quarterly audit — re-verify a sample; check certificate validity.
Output Template
provenance_setup:
standards:
c2pa:
enabled: yes
certificate_id: org-aether-2026
certificate_expires: 2027_01_01
synthid:
enabled: auto_via_google
verifier: google_synthid_detector
exif_xmp:
enabled: yes
digital_source_type: trainedAlgorithmicMedia
software: "Gemini 3.1 Flash Image"
generation_chain:
model: gemini-3.1-flash-image
model_version: 2026-08-19
prompt_summary_in_xmp: yes
full_prompt_in_archive: yes
edit_chain:
photoshop_preserves_c2pa: yes
final_export_preserves_manifest: yes
distribution:
platforms:
- meta: c2pa_auto_label_yes
- x: manual_disclosure_required
- youtube: synthetic_content_toggle
- linkedin: caption_disclosure
- adobe_stock: c2pa_required
- getty: REJECTED_does_not_accept_ai
archive:
storage: s3_with_object_lock
retention_years: 10
contents: [api_response, prompt, manifest, signed_export, distribution_log]
takedown_response:
template: documented
log_location: archive/takedown_log.csv
audit_cadence: quarterlyAnti-Patterns
- Generation without C2PA — provenance broken at the source.
- Stripping EXIF at export "to save space" — destroys evidence chain.
- Generic "AI generated" disclosure without model name — insufficient for platforms with strict policies.
- Public-figure / minor depiction without rights documentation.
- Long-term archive missing — cannot defend in regulatory inquiry.
- Trust unsigned third-party images claiming provenance — forgery risk.
- Skip SynthID detection when ingesting external content.
- Caption-only disclosure (no metadata) — caption can be edited away.
- Re-encoding through tools that don't preserve C2PA (older ImageMagick, naive ffmpeg).
- Shipping certificate that's expired — manifests verify as untrusted.
- Per-asset certificates instead of org-level — hard to manage.
- No takedown-response log — same incident recurs.
- Metadata fields with conflicting / inconsistent claims — flags forgery suspicion.
- Treating C2PA as enough on its own — pair with SynthID + EXIF for resilience.
Deliverable Contract
A provenance setup is complete when:
- C2PA + SynthID (where applicable) + EXIF / XMP enabled.
- Project certificate active and not near expiry.
- Generation pipeline embeds manifest at first export.
- Edit chain preserves manifest through Photoshop / etc.
- Final export verified at contentcredentials.org.
- Platform disclosure per distribution channel.
- Long-term archive populated with all artifacts.
- Takedown-response template documented.
- Quarterly audit scheduled.
References
- C2PA specification — c2pa.org/specifications.
- Content Authenticity Initiative — contentauthenticity.org.
- contentcredentials.org/verify — public verification UI.
- Google SynthID — deepmind.google/technologies/synthid.
- Adobe Content Credentials — helpx.adobe.com/firefly/using/content-credentials.
- Project Origin (BBC) — projectorigin.org.
- IPTC Photo Metadata Standard 2024.
- EU AI Act Regulation (EU) 2024/1689 — Articles 50-52 on synthetic content disclosure.
- US AI EO 14110 (2023) and follow-on state laws.
- Truepic — truepic.com (mobile capture-to-verify).
- Reuters / AP / NYT AI-image policies (2024-2026 public statements).
- Adobe Stock / Getty / Shutterstock AI policies.
- DeepMind, SynthID: Identifying AI-generated content (2023 paper).
- W3C XMP Specification.