C2PA and SynthID: After the EU AI Act, Media Provenance Is an Engineering Task

AI-generated text, images, audio, and video are becoming harder to tell apart from human-made work. That has turned provenance from a research topic into a pipeline requirement, and the deadlines have started to bind.
The EU AI Act's transparency duties under Article 50 apply from 2 August 2026, with a grace period for marking running to 2 December 2026. India amended its IT Rules in February 2026 to cover synthetically generated information. Marking generated media is now something a team has to implement, not something a team discusses.
Three tools that answer different questions
The mistake most teams make is treating provenance, watermarking, and detection as interchangeable. They are not, and they fail in different ways.
Provenance, in the C2PA sense, is cryptographically signed metadata attached to or referenced by a file. It answers a specific question: who signed this, with what tool, and has it changed since. Its main weakness is that it is easy to strip. A screenshot, a re-encode, or a platform that drops metadata removes the manifest.
An invisible watermark is a signal embedded in the content itself, whether in pixels, audio samples, or token choices. It answers: was this produced by a system that applies this watermark. Its weakness is that heavy editing, rewriting, or adversarial attacks can weaken or remove the signal, and it is usually only detectable by the vendor's own detector.
A detection classifier is a model trained to guess whether content is synthetic. It answers: does this look AI-generated. It is probabilistic, it drifts as generators improve, and it produces false positives on real content.
The key distinction is that provenance and watermarks are applied at creation time by a cooperating party. Detection is applied afterwards to content from anyone, including adversaries, which makes it the weakest form of evidence, though the only option for content that was never marked.
Why detection alone is not enough
Detection is an arms race. Classifiers learn the artifacts of known generators, and new models plus simple post-processing change those artifacts. False positives hurt real people, because edited real photos, compressed video, and non-native writing get flagged. When that becomes a fairness problem, a genuine customer selfie is rejected.
And a clean score proves nothing. Content may come from a generator the model has never seen. The practical guidance is to treat detection as one risk signal, with human review for consequential decisions.
How C2PA actually works
The Coalition for Content Provenance and Authenticity publishes an open technical standard for recording the origin and edit history of digital content. Its steering committee includes Adobe, Google, Microsoft, Meta, OpenAI, Amazon, Sony, and the BBC, among others. The specification sits in its 2.x series and is revised regularly, so designs should check the current version rather than pin one release.
The core unit is the C2PA manifest, a cryptographically signed data structure describing an asset's provenance. A manifest store can hold several, one per step in the asset's life. Assertions are individual statements about the asset, with standard ones covering actions such as created or edited, including by an AI system, plus ingredients and thumbnails.
By mid-2026, OpenAI attaches C2PA manifests to every image produced by its image models, and Google attaches both C2PA manifests and SynthID watermarks to outputs from its image and video generation. Adobe's Firefly has done the same since 2024. Camera firmware from Canon, Sony, Nikon, and Leica now writes Content Credentials at capture, which means the same plumbing that lets a newsroom verify a photograph also lets a hiring manager verify a profile picture.

What SynthID does differently
Google DeepMind's SynthID is a family of watermarking technologies that adapts the signal to each content type rather than using one technique for everything. Images get a signal spread across the image so normal visual quality is preserved and some common transformations do not erase it. Video distributes watermark information through frames, helping a verifier examine a clip rather than one isolated area. Audio places the signal within the sound, inaudible but machine-detectable. Text has the model subtly shift token probabilities, with a verifier examining enough text for the expected statistical pattern.
Text watermarking is the most fragile case. A short answer may not contain enough evidence. Heavy paraphrasing, translation, or mixing output from several models can weaken the pattern. That is why a negative result should be reported as "no supported watermark detected," rather than "written by a human."
What this means for a team shipping generated media
Three practices follow from the tool differences.
Sign at creation and preserve the original. C2PA survives re-encoding sometimes, but metadata is often dropped downstream. The only reliable record of provenance is the file you kept.
Do not treat a missing watermark as proof of human authorship. A missing signal may mean the generator does not apply one, the editing removed it, or the detector was unavailable. Each of those is a different fact.
Separate the technical question from the truth question. C2PA cryptography helps reveal unauthorized changes, but it does not by itself certify that a product depiction is accurate or that every statement in a manifest is true. Provenance tells you where a file came from. It does not tell you whether the file is honest.
The market has responded to all this. AI watermarking and provenance spending was valued at roughly $480 million in 2025, with projections above 28 percent annual growth through 2034. That is enterprise spending, not consumer adoption, and it reflects a simple reality: as the cost of generating media falls, the value of proving where media came from rises. The teams that treat provenance as pipeline infrastructure rather than a laboratory curiosity will be the ones ready when the marking rules bind.
What a compliant pipeline looks like
Abstractions aside, a team that has to mark generated media now needs a specific sequence of steps, and each step maps to one of the tools above.
At creation, the pipeline signs the output. For images produced through a major API, this happens automatically: OpenAI attaches a C2PA manifest to every image, Google attaches both a manifest and a SynthID watermark, and Adobe does the same through Firefly. A team working through a minor provider may have to add the manifest itself.
Through editing, the pipeline preserves the chain. Each tool that touches the asset should append an assertion rather than replace the manifest, so the history survives. This is where most pipelines leak, because a tool that re-encodes the file may drop metadata it does not understand.
At distribution, the pipeline keeps the original. Platforms routinely strip metadata, recompress uploads, and generate previews. The signed file that leaves the production system is the only reliable record, and it should be retained independently of wherever the image gets posted.
At the human layer, the pipeline labels. A visible label is the simplest form of disclosure and the one regulators expect for certain uses. It is also the one most easily cropped away, which is why it sits alongside the machine-readable signals rather than replacing them.
The distinction regulators draw
Article 50 of the EU AI Act, and India's amended IT Rules, both draw a line that is easy to blur in an engineering discussion.
The obligation is about transparency, not accuracy. A marked image is certified as generated or edited by an identified process, and that is all the mark asserts. The distinction matters because it determines what a manifest is for. It records provenance, which is who made the file and how. It does not vouch for content, which is whether what the file depicts is real.
Getting that distinction wrong leads to a predictable failure. A team treats a valid Content Credential as evidence that an image is trustworthy, when the credential only confirms that the image came from the system it claims to come from. A manipulated photo with an intact manifest is still a manipulated photo, and a manifest does not detect the manipulation.
The takeaway for a working team
Three things follow, and they are all about discipline rather than technology.
Treat marking as part of the export step, not a later addition. Provenance is applied at creation, and retrofitting it is not possible for an asset already in circulation.
Keep the original, because the copy others see will usually be stripped. The manifest is only useful if a team can produce the file that carries it.
And separate the provenance question from the detection question in how the team talks about the output. Provenance tells you where a file came from. Detection tells you what a model guesses about content it has never seen, which is the weaker claim. Saying so plainly, internally and to clients, is what keeps a compliance program honest about what it can and cannot prove.
Related articles
Qwen-AgentWorld Puts Seven Environments Inside a Single Language World Model
Agent capability is increasingly limited by the environment around the model, not the model's raw reasoning score.
TwelveLabs Pegasus 1.6 Turns First-Person Video Into Robot Training Data
Understanding an action is only part of teaching it, and the CEO says as much.
The Enterprise Agent Plumbing Race: Ampersand and Restate Fund the Read-Write Layer
Neither company builds a model. Both build the plumbing that lets an agent actually do something inside a system a business already runs.
Reactor Raises $74M: Video World Models Need a Runtime of Their Own
A round of this size, backed by the company that also designs the GPUs, tells you where the money thinks the next bottleneck is.