What August 2 Means for Trust & Authenticity Online
The Coalition for Content Provenance and Authenticity (C2PA)'s Content Credentials can influence how new AI disclosure rules operate in the EU and California.
On August 2, two of the most consequential provenance rules in the world will become operative on the same day –– both meant to offer some way of trusting what we see online at a moment when synthetic media has blurred the line between what is genuine and what is AI generated or edited.
In the European Union, Article 50 of the AI Act enters into force, requiring disclosure of AI interactions and labeling of synthetic content. In California, its AI Transparency Act (SB 942, as amended by AB 853) will require large generative AI providers to offer free detection tools and make provenance information available for AI-generated content.
Other jurisdictions, from China to South Korea and India, have also already put –– or are in the process of putting –– content transparency requirements into law. What makes August 2 different is that two of the jurisdictions whose tech rules tend to set the global pace are now bringing theirs into force at the same time. That alone raises the stakes for the standards that regulators are increasingly pointing to as the practical mechanism for compliance, chief among them the Coalition for Content Provenance and Authenticity (C2PA) and its Content Credentials.
Authenticity Standards Are Filling the Regulatory Gap
Regulation and standards can reinforce each other positively. When a law requires "detection tools" or "provenance data" without specifying exactly what those look like, companies will turn to existing technical standards to fill the gap. In the case of detection tools that are overwhelmingly unreliable and insufficient in real-world settings, sociotechnical evaluation standards such as the TRIED Benchmark can reinforce and complement regulation.
For provenance, the C2PA's Content Credentials, tamper-evident metadata that travels with an image, video, or audio file to record when, where, and how it was created or modified, is already functioning as a de facto point of reference for both the EU Code of Practice on AI generated content and California's AI Transparency Act. That gives the C2PA outsized influence over how millions of people will experience these new transparency rules in practice.
The C2PA has already shown that standards development does not have to happen in a vacuum. Content Credentials development has taken human rights and privacy risks seriously from the start: Guiding Principles established early on; an ongoing, multi-year harm assessment; a standing Threats and Harms Task Force that WITNESS co-chairs and continuous development of technical mitigations for the risks that the group has identified. That represents a level of scrutiny many technical standards bodies never attempt. We have written about what it takes to embed human rights into a standard like this one in our own report.
Governance Innovation Before Harm or Regulation Forces It
As the C2PA becomes a standard that is increasingly emerging as a practical compliance mechanism, it has an opportunity to go further: broader participatory processes, redress mechanisms and safe harbor conditions tied to accountability, all building on the harm assessment work already underway. Acting now matters because harm from misuse reaches beyond the individuals and communities directly affected. Harm erodes trust, both in the standard itself and in its promise to help reclaim the trust the internet urgently needs, among the regulators, users and companies deciding whether to rely on it.
This is the spirit in which we published our report, C2PA Content Credentials and the Surveillance Risk. It translates a broader adversarial scenario analysis, mapping how Content Credentials metadata could be exploited by everyone from state actors to certificate issuers, into accessible case studies for a policy and civil society audience. It shows how the same metadata designed to prove authenticity can also expose who created a piece of content, from where and using what device, and it identifies where governance choices can close those gaps.
Real credibility here comes from participation and multi-stakeholder input from beyond the companies that fund and build the standard, and not from technical fixes alone. Without that, the C2PA risks being read as a compliance tool built and maintained by a handful of large technology companies, rather than a shared public standard.
Where the Laws Fall Short, and Why the C2PA's Governance Work Must Continue
Neither the EU nor California framework resolves the tension between requiring disclosure of who made a piece of content and protecting the people that disclosure could expose. The EU's Code of Practice on AI-generated content sets out marking and detection rules for providers and labeling rules for deployers, but leaves the underlying privacy design choices largely to the technical standards it references, and to existing privacy law that was not written with the specific risks that provenance recording creates in mind. California's law places real enforcement power behind provenance disclosure, but says little about who controls that data once it is generated or who is protected from being identified through it. Without deliberate governance choices about consent, retention and access, these transparency mandates could just as easily become surveillance infrastructure as authenticity infrastructure.
The C2PA is emerging as the most mature and widely implemented provenance mechanism available, which means how it is governed increasingly matters for public policy. Part of the answer lies in a balance between what the C2PA ecosystem can achieve on its own and what regulation will eventually require. The C2PA operates globally and can be part of the solution to addressing harm and misuse even in jurisdictions where regulation is weak, absent or even adverse, something no single national law can achieve on its own. Regulation, in turn, can anchor safe harbor protections to accountability and public interest, giving standards bodies a reason to keep improving rather than settling once minimum compliance is met.
As co-chairs of the C2PA's Threats and Harms Task Force, WITNESS will keep pushing that harm assessment work forward and looking for governance innovations from inside the ecosystem. We call on regulators drafting implementing guidance, and on the actors participating in the C2PA’s ecosystem to treat August 2 as the point where the harder governance work actually begins.
Read the full report: C2PA Content Credentials and the Surveillance Risk: Adversarial Scenarios and Governance Gaps in the Content Provenance Ecosystem.
Support the Internet Exchange
If you find our emails useful, consider becoming a paid subscriber! You'll get access to our members-only Signal community where we share ideas, discuss upcoming topics, and exchange links. Paid subscribers can also leave comments on posts and enjoy a warm, fuzzy feeling.
Not ready for a long-term commitment? You can always leave us a tip.