1 · Concept overview
Established Content authenticity infrastructure is the stack of technical and legal machinery meant to let a viewer answer one question about a piece of media: where did this come from? It has four technical layers and one legal one. Capture signing puts a cryptographic signature on a photograph or video at the moment a sensor records it. Content credentials — the C2PA standard’s manifests — carry a signed, tamper-evident record of what was done to the file afterwards. Invisible watermarking embeds a statistical signal in generated content so that its synthetic origin can be read back later. Post-hoc detection tries to classify media with no marks at all. Above all four sits disclosure law: statutes in China, the European Union and California that now require synthetic content to carry machine-readable marks.
Established Every layer has now been measured, and every layer failed at least one measurement that its proponents said mattered. The highest-assurance capture signature on the market was forged within a year of shipping. Pixel-level invisible watermarks are provably removable. Deepfake detectors lose roughly half their benchmark accuracy on real circulating fakes. The largest platform labelling programme catches, by the best available estimate, 35 to 45 percent of what it aims at. This brief is the record of those measurements, and of the narrower thing the infrastructure can still honestly deliver.
Frontier The synthesis question none of the neighbouring briefs owns is whether a partially broken authenticity stack is worth building anyway. Future Democracies records what deepfakes measurably did to the 2024 elections (little, at the persuasion layer); AI Governance treats provenance as a missing precondition for AI liability; Digital Citizenship owns the identity rails a provenance signature might one day bind to. This brief owns the pipe between capture and belief: what a signature, a manifest, a watermark and a label can each prove, to whom, and at what surviving rate after the internet has handled the file.
2 · Current scientific position
Established The standard exists, is versioned, and is governed by a vendor consortium. The Coalition for Content Provenance and Authenticity (C2PA) formed in February 2021 around Adobe, Microsoft, Intel, Arm, the BBC and Truepic, and published specification 1.0 in January 2022. The specification defines a manifest: a set of signed assertions (capture device, edits, AI generation) cryptographically bound to the asset’s hash (a hard binding), with provision for soft bindings — watermarks or perceptual fingerprints that let a stripped manifest be re-associated from a remote store. The 2.x series (the commission’s seed citation is version 2.2; the consortium published 2.4 in April 2026) tightened the validation model and added a formal Conformance Program with a unified trust list, launched June 2025; the interim trust list was frozen on 1 January 2026. Established As of mid-2026, by the public record, no software implementation had yet been certified under that Conformance Program — four years after specification 1.0, the trust layer the architecture depends on is still being assembled.
Established Capture signing shipped in roughly seventeen camera models plus one phone line. Leica’s M11-P (late 2023) was first, followed by two further Leica bodies, eleven Sony models including the first C2PA video camcorder (the PXW-Z300), and Canon’s EOS R1 and R5 Mark II by firmware in July 2025. Google’s Pixel 10 (August 2025) signs every capture by default with hardware-backed keys at C2PA Assurance Level 2, the highest defined. Nikon’s single implementation, on the Z6III, is suspended — the reason is in the attack record below. Fujifilm and Panasonic have announced commitments and shipped nothing; Samsung marks only AI-edited images, not captures. Sony’s implementation requires a paid licence, which says something about who the customer currently is: newsrooms and agencies, not the public.
Established On the generation side, credentials are attached at scale; on the distribution side, one platform reads them seriously. Adobe’s Firefly tools have written Content Credentials since 2021 workflows; OpenAI has attached C2PA metadata to generated images since 2024 and in May 2026 added conformance work, SynthID image watermarking and a public verification preview (vendor claims throughout this sentence). TikTok became the first video platform to read Content Credentials on 9 May 2024, auto-labelling inbound AI content and committing to attach credentials to downloads; by 10 July 2026 it reported more than 3 billion videos labelled (platform’s own figure). Frontier The independent estimate that matters more: reporting on the same programme put automated detection at roughly 18 percent of AI-generated content in early 2024 and 35 to 45 percent by late 2025 — meaning a majority of synthetic content on the most diligent platform still reaches users unlabelled unless the creator self-discloses. Established Meta’s parallel effort misfired in the other direction: its “Made with AI” label, launched May 2024 and driven by C2PA and IPTC metadata, tagged lightly retouched real photographs as AI, and by 1 July 2024 was renamed “AI info” after photographer protest — a false-positive failure, where TikTok’s is false-negative. Google is rolling C2PA and SynthID verification into Gemini, Search and Chrome through 2026; YouTube shows a “captured with a camera” label on qualifying video; the US Department of Defense integrated Content Credentials into its DVIDS distribution service in August 2024.
Established Watermarking has one deployment at genuine scale and one honest large-scale quality measurement. Google DeepMind’s SynthID-Text, published in Nature in October 2024 (Dathathri, See et al.), watermarks by tournament sampling — candidate tokens compete under keyed scoring functions, biasing generation toward a detectable statistical signature. The system ran live on nearly 20 million Gemini responses; the thumbs-up rate differed from unwatermarked output by 0.01 percentage points, and raters found no significant preference difference — watermarking text, at this operating point, costs approximately nothing in quality. Detection at a 1 percent false-positive rate strengthens with length and weakens sharply on short or low-entropy text, and the authors state plainly that paraphrasing weakens it and that decentralised open-weight models cannot be made to carry it. Google reported over 10 billion pieces of content watermarked across Gemini, Imagen, Lyria and Veo by May 2025, and opened a SynthID Detector portal (vendor figures; no independent audit of detector accuracy has been published).
Established The adversarial literature is unusually one-sided: every published attack class succeeds against at least one deployed defence. Zhao and colleagues (NeurIPS 2024) proved and demonstrated that pixel-level invisible image watermarks are removable by a regeneration attack — add noise, reconstruct with a diffusion model — and recommended the field retreat to semantic watermarks. Saberi and colleagues under Feizi (ICLR 2024) established a fundamental trade-off between evasion and spoofing error rates, removed low-perturbation watermarks by diffusion purification, removed robust ones by model substitution, and — the underrated result — spoofed watermarks onto real photographs with only black-box detector access, making authentic images test as AI-generated. Kassis and Hengartner’s UnMarker (IEEE S&P 2025) is a universal black-box attack that needs no detector feedback and no knowledge of the scheme; it drove the best semantic watermarks below 43 percent detection, and its authors conclude defensive watermarking “is not a viable defense against deepfakes.” Frontier No deployed scheme has yet published a robustness result that survives this attack literature; the open question is whether one can exist, and it is treated in the frontier section.
Established Passive detection collapsed when tested on real circulating fakes. Deepfake-Eval-2024 (Chandra et al., with Oren Etzioni) collected 45 hours of video, 56.5 hours of audio and 1,975 images from 88 websites in 52 languages — deepfakes that actually circulated in 2024 — and measured open-source state-of-the-art detectors losing 50 percent of AUC on video, 48 percent on audio and 45 percent on images relative to their academic benchmarks. Commercial and fine-tuned detectors did better but remained below human deepfake forensic analysts. The academic benchmark suite the field graded itself on was, in effect, measuring the wrong distribution.
Established Capture signing was then broken twice, at both ends of the market, within twelve months. In September 2025 a researcher publishing as Horshack built a NEF encoder that fed AI-generated images through the Nikon Z6III’s multiple-exposure path, producing camera-signed JPEGs of, among other things, an AI pug flying a jet; Nikon detected the flaw on 4 September 2025, announced on 24 September that it was revoking every certificate it had issued, and suspended the service — the first mass revocation event in the ecosystem’s history. In August 2026 David Buchanan demonstrated forged capture signatures on the Pixel 10 itself: a public one-click root exploit (CVE-2026-43499) on fully patched devices lets an attacker use the StrongBox secure element as a signing oracle without extracting any key, forging Assurance Level 2 provenance for an AI-generated image. Google closed the report as “Won’t fix (infeasible),” paid a 7,500 dollar bounty, and Buchanan’s conclusion — that the entire image pipeline would have to move inside the secure enclave, and even then a photograph of a screen defeats it — stands unrebutted.
Established An academic-government audit of the specification itself found the trust machinery optional in practice. An April 2026 study from UMBC’s Cyber Defense Lab with co-authors including Neal Krawetz and an NSA researcher (Golaszewski et al.) documented that validators are not required to check certificate revocation — the revoked Nikon certificate was still accepted by Adobe’s inspection tool six months after revocation; that timestamps are not cryptographically bound and can be replaced undetected; that different validators return different verdicts on the same file; that GPS assertions could be spoofed on a Pixel 10 Pro without detection; and that signed media become unverifiable when signing certificates expire — sometimes within months, against legal retention windows of 22 to 25 months for election and financial records. Conformance certification, the study noted, relies on self-reported compliance without source-code examination.
Established Meanwhile the legal layer arrived, on three jurisdictions’ schedules. China’s Measures for Labeling of AI-Generated Synthetic Content took effect 1 September 2025: explicit labels on synthetic content, implicit metadata labels naming the provider and a content reference number, platform duties to verify labels and flag suspected synthetic content, app-store review duties, and a prohibition on maliciously deleting, altering or concealing labels or providing tools to do so. The EU AI Act’s Article 50 applied from 2 August 2026: providers of generative systems must ensure outputs are “marked in a machine-readable format and detectable as AI-generated,” deployers must disclose deepfakes, with an artistic-work carve-out, a 2 December 2026 grace date for systems already on the market, and a Code of Practice on transparency drafted through 2026 to define what counts as adequate marking. California’s SB 942, delayed and extended by AB 853, became operative the same day — 2 August 2026: latent disclosures embedded in AI output, a free public detection tool from every covered provider (those above one million monthly users), licence revocation within 96 hours if a licensee strips disclosure capability, 5,000 dollars per violation per day, then platform duties to surface provenance from 1 January 2027 and capture-device disclosure options from 1 January 2028. Frontier Three regimes now mandate, under penalty, a technical capability whose published attack record is uniformly successful; the position of this brief is that this is not a contradiction but a wager, and section 6 states how it resolves.
3 · Frontier questions
Frontier The live scientific question is whether any invisible watermark can survive an adaptive adversary at acceptable false-positive rates. The impossibility-flavoured results (Saberi et al.’s evasion–spoofing trade-off; Zhao et al.’s provable regeneration removal) apply cleanly to pixel-level schemes. Semantic watermarks — which alter image structure rather than pixel residue — were the proposed escape, and UnMarker then broke the deployed examples without even knowing which scheme it faced. What remains open is narrower than the public debate suggests: whether a semantic scheme with a secret key, a bounded perturbation budget and server-side detection can hold against attackers who lack large compute. Nobody has published a positive result at that operating point; nobody has proven it impossible either.
Frontier The second contested question is behavioural: whether labels change what people believe or share. The one platform-relevant experimental result reported in 2025, from the Dais at Toronto Metropolitan University, found small overlay labels of the kind every platform actually uses produced no statistically significant improvement in deepfake identification, no reduction in belief, and no reduction in sharing; the only intervention that worked was a full-screen interstitial the user must actively dismiss — which no major platform deploys, because it taxes engagement. Frontier This sits awkwardly beside the regulatory bet: Article 50’s deployer-disclosure duty assumes disclosure does epistemic work, and the best current evidence is that the formats platforms will tolerate do none.
Speculative The threshold question: at what coverage does absence of credentials become evidence? The long-run promise of provenance is a default flip — when enough legitimate capture is signed, unsigned media earns a discount. Nobody has estimated the coverage level at which that inference becomes rational rather than punitive toward the billions of devices that will never sign, and no measurement programme currently tracks what fraction of media reaching users carries intact credentials. It is the single most decision-relevant unmeasured number in the field.
Frontier The liar’s dividend is documented as behaviour; its electoral price is not yet measured. Chesney and Citron predicted in 2019 that awareness of deepfakes would let liars dismiss authentic evidence; the Brennan Center’s 2024 review collects real cases — a Spanish foreign minister calling genuine police-violence images fake, a Michigan mayor calling authenticated recordings “phony, engineered tapes,” an Indian politician attributing verified audio to AI — and cites forthcoming work by Schiff, Schiff and Bueno cataloguing the pattern. Whether such denials measurably rescue careers, and whether provenance infrastructure shrinks or (by teaching the public that fakery is everywhere) enlarges the dividend, are both open.
Frontier Identity binding is the quiet frontier. Device provenance says a camera signed this; the Creator Assertions work layered on C2PA lets a person attach a verified identity (Tim Bray’s 2025 field test attached his via OAuth to LinkedIn and a Clear identity check). Whether the infrastructure converges on device attestation (privacy-preserving, weakly meaningful) or identity attestation (strongly meaningful, surveillance-adjacent) is unresolved and is really a question about digital identity rails, not about media formats.
Speculative Whether provenance can carry legal weight is untested in any high court. AI Governance notes that the liability route to governing AI requires causation traceable from harm back to a model — provenance infrastructure that, that brief says flatly, does not exist. If C2PA-grade provenance ever anchors a chain of custody in litigation, the UMBC findings on unbound timestamps and expiring certificates become the cross-examination script.
4 · Technological bottlenecks
Established The first bottleneck is that the internet deletes the evidence by default. Tim Bray’s September 2025 field investigation put it directly: nearly every online photo is delivered via social media or professional publishing software, and in both cases metadata is routinely stripped — historically as a privacy measure, now as an authenticity-destroying one. CDN and image-optimisation pipelines recompress and discard; screenshots launder perfectly. A handful of infrastructure providers (Cloudflare, Fastly, Cloudinary) support preservation; preservation is nowhere the default. Soft bindings — watermark- or fingerprint-keyed lookup of manifests from a remote repository, the “durable credentials” design — are the standard’s answer, and they inherit every robustness problem of the watermark layer.
Established The second is that capture attestation bottoms out in hardware nobody will warranty against attack. The Pixel 10 result is the clean statement: the signing key lived in certified secure hardware and was never extracted — the attacker simply borrowed the signer. Google’s “won’t fix” is economically rational; defending against root-plus-fault-injection on a consumer phone is not a product requirement anyone pays for. And beneath all of it sits the analog hole: a good screen photographed by an honest camera yields an honestly signed image of a lie. No cryptographic design closes that.
Established The third is trust-list governance moving slower than deployment. A conformance programme opened June 2025; an interim trust list was frozen January 2026; zero software implementations were certified by mid-2026; certification relies on vendor self-report. The Nikon revocation showed the revocation machinery exists; the UMBC audit showed validators ignore it. A public-key infrastructure in which revocation checking is optional is, for forensic purposes, decorative.
Established The fourth is that open-weight generation cannot be conscripted. The Nature paper’s authors concede it: watermarking is enforced at the sampler, and whoever runs the sampler chooses. Every open-weight image and language model is a non-watermarking generator available to anyone, which bounds forever the fraction of synthetic content that arrives marked. Disclosure mandates bind the compliant; the threat model is the non-compliant.
Frontier The fifth is demand. Sony charges for its authenticity licence; newsrooms and the US military buy; no consumer market has materialised, and platforms bear labelling costs against engagement revenue. California’s statute manufactures demand by fiat — the free-detection-tool and platform-display duties are, economically, a forced market — and whether mandated demand produces working infrastructure rather than compliance theatre is precisely what the next two years will show.
Established The sixth is archival time. Signing certificates expire in months to a few years; election and financial records must remain verifiable for 22 to 25 months and courts for decades. Without standardised re-timestamping or archival countersigning, today’s verified capture is next year’s unverifiable blob — the Arizona Secretary of State pilot images documented by the UMBC team validated in January 2025 and failed a year later.
5 · Research dependencies
What this field waits on is mostly other people’s results.
Frontier A watermark with a published, adversarially audited robustness bound. Not robustness against a fixed attack suite — against the UnMarker class of scheme-agnostic attacks, at stated false-positive rates. This is a cryptography-adjacent open problem; until it exists, every soft binding and every detection mandate rests on sand.
Frontier Trusted-execution security that survives physical access, priced for consumer devices. Capture attestation inherits the state of the TEE field wholesale. The relevant results will come from the hardware-security community, not the media-provenance one, and the current answer — fault injection defeats fielded secure elements, vendors decline to defend — is a dependency, not a footnote.
Established A measurement instrument for coverage. Deepfake-Eval-2024 did for detection what nobody has done for provenance: measured the real distribution. The equivalent study — what fraction of media reaching users on the top distribution paths carries intact, valid credentials — requires only crawling and validation tooling, and does not exist.
Frontier Behavioural science of disclosure at platform scale. The Dais result (small labels do nothing) needs replication, and the effective format (blocking interstitials) needs a measured engagement cost, because regulation is currently mandating the format that does not work while platforms refuse the one that does.
Established Archival cryptography practice. Long-lived verification needs the timestamping and re-signing discipline the document-archival world has run for decades (qualified timestamps, countersignature chains) imported into media provenance — an engineering-standards dependency on existing art, not new science.
6 · Required experiments
Frontier One result outranks everything else in this section, and it needs no new apparatus. China’s labelling measures (in force 1 September 2025), EU AI Act Article 50 (2 August 2026) and California SB 942 (2 August 2026) constitute a three-jurisdiction natural experiment on the same hypothesis: that legal compulsion can push machine-readable marking through an ecosystem that strips it by default. The decisive test is already running: three mandatory-marking regimes came into force within twelve months of each other, and by the end of 2027 platform transparency reports will show whether the labelled share of AI-generated media rises decisively above the 35 to 45 percent baseline or stays flat while stripping and open-weight generation absorb the mandate. A clear rise would overturn this brief’s central scepticism; a flat line would confirm that the binding constraint was never legal but physical — the stripping pipelines and the uncooperative generators no statute reaches.
Frontier Second: adversarial certification. The conformance programme currently certifies on vendor self-report. The experiment is cheap and defined: fund an independent red team against every capture implementation seeking Assurance Level 2, publish results as a condition of listing. Nikon’s multi-exposure exploit and Buchanan’s signing oracle were both produced by individuals without institutional budgets; a certification regime that outsources its security audit to hobbyists after launch is running the experiment anyway, in the least controlled way possible.
Frontier Third: the label-format trial nobody will run voluntarily. A platform-scale randomised comparison of overlay labels against blocking interstitials, measuring belief, sharing and the engagement cost. The Dais study supplies the hypothesis and the effect direction; only a platform (or a regulator compelling one) can supply the sample. Article 50’s Code of Practice process is the obvious venue and has so far specified formats without requiring outcome evidence.
Established Fourth: the coverage census. Crawl the top distribution surfaces monthly; validate every manifest encountered; publish the survival rate of credentials by platform and transformation. This is the missing denominator for every claim in the field, requires no new science, and no one has funded it.
Frontier Fifth: an independent audit of the deployed watermark detectors. SynthID’s detection operating curve on adversarially handled content — after paraphrase, after regeneration, after UnMarker — has no published third-party measurement, and California’s mandated free detection tools create, for the first time, a legal surface an auditor can test against at scale.
7 · Engineering requirements
Frontier An authenticity stack that survives its own threat model is a systems-engineering programme, and its components are specifiable today. Capture: the imaging pipeline — sensor readout, ISP, encoding, signing — inside attested execution, because Buchanan’s analysis shows signing alone, outside the pipeline, authenticates only the last step. No shipping phone does this; it implies silicon-level co-design between sensor vendors and TEE designers, and its bill-of-materials cost is unmeasured because nobody has built one.
Established Distribution: preservation as a default, not a feature. The engineering here is mundane — CDNs and social pipelines must recompress without discarding manifests, or re-sign transformations as the standard permits. A short list of infrastructure providers already supports it; the work is making preservation the cheap path, which is a defaults-and-procurement problem, not a research one. California’s January 2027 platform duties are the first legal forcing function aimed exactly here.
Frontier Recovery: soft-binding lookup at internet scale. Durable credentials require a global manifest repository keyed by watermark or fingerprint, answering billions of queries with adversarial inputs — an infrastructure with the availability profile of DNS and the abuse profile of a certificate authority. It exists today only as vendor pilots.
Established Key lifecycle: fleet-scale PKI with mandatory revocation. The Nikon event is the sizing exercise: one compromised model line forced revocation of every certificate the vendor had issued. Engineering requirements follow directly — per-device (not per-model) keys, revocation checking that validators cannot skip, archival countersigning so expiry does not orphan the historical record, and privacy-preserving revocation transport, which the specification currently handles badly by the UMBC audit’s account.
Established Validation: one verdict per file. Divergent validator verdicts on identical inputs are fatal to public trust and are an engineering defect with a known cure — a conformance test corpus and mandated behaviour, the pattern TLS libraries and web browsers converged on a decade ago.
8 · Adjacent technologies
Established The neighbouring briefs divide this territory cleanly, and this one deliberately does not re-till their ground. Future Democracies owns the electoral measurement: its record of the 2024 cycle — a few dozen viral AI-disinformation cases across the UK, EU and France, exposure concentrated among the already-aligned, no evidence of decisive effect — is the base rate against which authenticity infrastructure’s urgency must be argued, and this brief imports rather than re-derives it. AI Governance owns the statute book and the liability argument; where it says the liability route needs provenance that does not exist, this brief is the engineering annex explaining exactly what does not exist and why. Digital Citizenship owns identity rails, which become load-bearing here the moment provenance binds to persons instead of devices. Civic Technology owns the participation platforms whose evidentiary hygiene would be a downstream consumer.
Frontier Two further adjacencies matter more than they first appear. Future Legal Systems, because evidence law is where provenance either acquires teeth or is revealed as ornament — the moment a court weighs a signed capture against an unsigned one, the discount rate for unsigned reality gets set by precedent. And Reputation Economies, because a world of cheap synthesis prices trust into identities and track records rather than artifacts; if the artifact layer stays broken, reputation is the substitute good, and its briefs’ machinery — attestation, staking, revocation — is this field’s under different names.
Speculative The deep adjacency is with collective epistemics generally — Collective Intelligence treats how groups aggregate belief; authenticity infrastructure is an input-sanitation layer for that aggregation, and its failure mode (everything doubtable, the liar’s dividend compounding) is a collective-intelligence failure before it is a media-technology one.
9 · Institutional requirements
Established The de facto governing institution is a vendor consortium performing functions usually reserved for states: standards authorship, certification, and the trust list — effectively a passport office for cameras. C2PA writes the specification, runs the Conformance Program, and curates whose signing certificates validators should trust. The accountability gap is structural: the members with the largest deployed surface (Adobe, Google, Microsoft, OpenAI, TikTok’s parent) are simultaneously the regulated parties under Article 50 and SB 942, the certifiers of their own tooling, and the platforms that decide whether credentials survive upload. The UMBC audit’s finding that conformance rests on self-report without source examination is what that structure predicts.
Established Three governments have now built three different institutional answers. China internalised the whole stack into state administration: named provider codes in mandatory implicit labels, platform verification duties, app-store gatekeeping, and a legal prohibition on label tampering — provenance as a licensing regime. The EU delegated the technical definition to a Code of Practice process (drafting through 2026) that will decide, in effect, whether “machine-readable” means C2PA, watermarking, either, or both — a standards decision worth billions being made in a consultation format. California legislated the market structure directly: detection tools as a statutory product, platform display duties, capture-device duties, per-day penalties, no private right of action.
Frontier The institutional bet nobody has placed: an independent measurement organ. Every number in this brief about coverage and detection comes from a vendor, a platform, or a one-off academic benchmark. The field lacks its equivalent of crash testing — a standing body that buys the cameras, runs the attacks, crawls the platforms and publishes survival rates. The transparency-report obligations arriving in 2026–27 create the raw data; no institution is yet chartered to audit it. Established Newsroom institutions remain the proving ground: the BBC and CBC/Radio-Canada have run credential pilots, and the US military’s DVIDS adoption in August 2024 is the largest institutional deployment on record — organisations whose media face motivated doubt adopted first, which is the demand signal in its clearest form.
10 · Ethical & societal considerations
Established Provenance and privacy pull against each other in the artifact itself. Bray’s Leica test file carried the camera’s serial number in its manifest — forensic gold and, for a photographer documenting atrocity under a hostile government, a signed confession of presence. The specification supports redaction of assertions, but redaction discards exactly the binding that gives the credential its evidentiary force. Every design choice on the identity axis re-runs this trade: device-anonymous credentials prove little; identity-bound credentials prove much and surveil accordingly.
Frontier The distributional harm is the provenance privilege. If courts, platforms and editors come to discount unsigned media, the discount lands on whoever holds old hardware: the bystander’s phone video of police conduct, the citizen journalist in a jurisdiction where signed capture is a luxury good. Seventeen camera models and one flagship phone sign today; several billion devices never will. An authenticity default calibrated to the equipped would convert an evidence technology into a credibility tax on the unequipped — and no deployed policy framework yet states how unsigned truth keeps standing.
Frontier The liar’s dividend is an ethics problem wearing a technical costume. Documented denials of authentic evidence — the “phony, engineered tapes” pattern the Brennan Center collects — exploit public education about deepfakes; infrastructure that teaches people synthetic media is everywhere may enlarge the very dividend it means to shrink. The Brennan Center’s proposed counters are notably non-technical: norms against false authenticity claims, media protocols, public understanding of the dividend itself.
Established Disclosure law has already met expression law and blinked. Article 50 carves out evidently artistic, satirical and fictional work, requiring only disclosure that does not hamper enjoyment — an honest acknowledgment that a blanket marking duty would burden legitimate expression, and a loophole exactly as large as the phrase “evidently artistic” is vague. Speculative The long ethical exposure is compelled attribution drift: infrastructure built to mark machines could be repurposed to mark people — mandatory identity binding for political speech is technically adjacent to everything described here, and only institutional restraint separates them.
11 · Civilizational implications
Frontier What is actually being renegotiated is the evidentiary status of recorded media, a settlement younger than it looks. Photography’s authority as evidence was constructed — by courts, newspapers and archives over decades — not conferred by optics. Cheap synthesis dissolves that settlement, and authenticity infrastructure is the first systematic attempt to rebuild it on cryptographic rather than institutional trust. The measured record so far says the cryptography inherits the institutions’ problems: keys are governed by committees, validators disagree, certificates expire, and the strongest attack — photographing a screen — is older than the transistor.
Speculative Two stable end-states are visible from here. In one, signed capture becomes ambient the way TLS did — a padlock nobody thinks about, coverage high enough that absence is informative, with the liar’s dividend held down by a functioning default. In the other, verification privatises: authenticated media becomes a subscription good inside closed loops — agencies, courts, militaries, premium platforms — while the open web runs on vibes and reputation, and the epistemic commons stratifies by ability to pay for proof. The TLS path took twenty years and browser-vendor coercion; the coercion analogue here (platform display duties, procurement mandates) has only just begun.
Frontier The stakes are mostly not electoral. The measured 2024 record in Future Democracies suggests mass persuasion was never the binding threat; the civilizational exposure is retail — fraud, fabricated evidence in ordinary litigation, synthetic intimate imagery, insurance and identity fraud — where a working chain of custody changes individual outcomes daily, and where its absence is already priced in as background loss. Infrastructure justified by democracy-scale rhetoric will succeed or fail on claims-adjuster-scale economics.
12 · Timelines
These horizons track the coverage question — whether marking and preservation become the default path for media reaching users — not the arms race, which has no terminal state.
- 10 yr: Frontier The three-regime natural experiment reports out. Platform transparency data either shows labelled share climbing well past the 35–45 percent baseline — vindicating mandates — or plateauing, relocating the whole effort into closed professional loops. Capture signing standard on flagship phones and professional bodies; at least one further mass certificate-revocation event on current PKI practice; no watermark with a surviving adversarial robustness bound unless the open semantic-scheme question resolves positively.
- 25 yr: Speculative Evidence law settles the discount rate for unsigned media in at least the major jurisdictions, which does more to drive adoption than any statute aimed at platforms. Preservation-by-default reaches the major distribution pipelines, because the January 2027 California platform duties and the EU Code of Practice converge on it. The provenance privilege becomes a named equity problem with case law.
- 50 yr: Speculative Either the TLS outcome — ambient, boring, assumed — or the field is remembered the way content-rating metadata systems are: a standards artifact that lost to platform economics. Which branch obtains depends on the coverage flip and on nothing else in this brief.
- 100 / 250+ yr: Handwave Claims that provenance infrastructure permanently restores — or that synthesis permanently destroys — a shared evidentiary commons are asserted in both directions with no mechanism behind either; recorded media’s authority was renegotiated once within living institutional memory and will be renegotiated again on timescales this long.
13 · Technology tree & dependencies
- Depends on Little on this map blocks the technical layer — cameras, manifests and watermarks are shipped engineering. What this topic genuinely waits on is institutional: the disclosure-mandate architecture assessed in AI Governance defines the demand side and the penalty structure, and the identity rails assessed in Digital Citizenship gate any move from device provenance to person provenance — the step that would make credentials evidentially strong and civically dangerous at the same time.
- Requires (not on this map) A watermarking scheme with a published robustness bound against scheme-agnostic removal attacks of the UnMarker class, since every durable-credential and detection mandate rests on it; commodity phones whose entire imaging pipeline runs in attested secure hardware, since signing outside the pipeline authenticates only the final step; manifest preservation as the default behaviour of CDNs and platform upload paths, since stripping currently deletes the evidence before anyone can read it; a conformance regime backed by independent adversarial security audit rather than vendor self-report, since both fielded capture breaks were found by outsiders after launch; an archival countersigning practice so signed media outlive their certificates, since legal retention windows already exceed certificate lifetimes; and a paying customer for verified capture beyond newsrooms and militaries, since infrastructure with no buyer becomes compliance theatre.
- Enables Evidence-grade media for courts, elections administration, insurance and journalism; the causation-tracing substrate that the liability route to AI governance explicitly lacks; platform labelling that could honestly claim coverage; and, if the default ever flips, an epistemic environment where unsigned extraordinary claims carry a rational discount.
- Adjacent Future Democracies for the measured electoral base rate; Civic Technology for the participation platforms downstream; Future Legal Systems for the evidence-law settlement; Reputation Economies for the substitute trust technology if the artifact layer stays broken.
14 · Common misconceptions & speculative claims
Handwave “A valid C2PA signature proves the image is real.” The claim circulates in vendor marketing and casual journalism, and it is the central category error of the field. Established A valid signature proves that a key on a trust list signed these bytes and that they have not changed since — nothing more. Nikon’s camera signed an AI pug flying a jet; the Pixel 10 signed Buchanan’s AI frog at the highest assurance level defined; and a photographed screen defeats every scheme forever. Provenance is a chain of custody. Chains of custody are valuable, and they begin at whatever the first custodian chose to put in the evidence bag.
Handwave “Watermarking will let us identify AI content.” As a universal claim this fails three independent ways. Established Adversarially: regeneration attacks provably remove pixel-level watermarks, UnMarker removes semantic ones without knowing the scheme, and spoofing attacks stamp real photos as synthetic — the false-accusation direction, which disclosure law has barely noticed. Structurally: open-weight models generate unmarked content by construction, bounding coverage below any threshold a mandate names. Statistically: SynthID-Text’s own authors publish that short and low-entropy text is weakly detectable. What survives is the modest true version: watermarking cheaply marks the output of cooperative, centralised generators, which is a real and non-trivial fraction of the problem.
Handwave “AI detection tools can tell.” Commercial detectors are sold on academic benchmark numbers. Established On deepfakes that actually circulated in 2024, open-source state-of-the-art lost 45–50 percent of AUC across modalities, and commercial tools, while better, stayed below human forensic analysts — who do not scale. Any institution buying detection as a solved capability is buying the benchmark, not the distribution.
Speculative “Metadata stripping makes the whole enterprise pointless.” The strong dismissal overshoots. Frontier Stripping is real and default — that is the measured present — but the infrastructure’s serious uses were never the open web: newsroom ingest, court chains of custody, platform-side reading at upload (TikTok reads credentials before its pipeline strips them for republication), and soft-binding recovery all operate inside loops where stripping is controllable. The honest statement is narrower than either camp’s: credentials currently work where a single institution controls the pipe, and nowhere else.
Handwave “Labels inoculate the public.” Frontier The only platform-relevant experiment reported finds the small overlay labels regulators are effectively mandating produce no measurable change in identification, belief or sharing; the format that works — a blocking interstitial — is the one no platform will ship. Disclosure policy is currently specifying the treatment that failed the trial.
Speculative “The 2024 elections proved the threat was hype, so the infrastructure is unnecessary.” Half right, wrong conclusion. Frontier The persuasion-at-scale threat underperformed its billing — Future Democracies documents the null. But the infrastructure’s load-bearing cases are retail (fraud, fabricated evidence, intimate-imagery abuse) and defensive (the liar’s dividend, where documented real-world denials of authentic recordings already exploit the doubt). An authenticity layer is less an anti-persuasion weapon than an anti-repudiation one.
Speculative “Provenance ends anonymous speech.” Established Identity binding is optional in the standard, redaction of assertions is supported, and device-level credentials need not name a person. The tension is real but lives one layer up, in whether platforms and courts come to demand identity-bound credentials — an institutional choice this brief flags as the field’s most consequential unforced error in waiting, not a property of the format.
Speculative “China solved it by mandate.” The measures are the world’s most comprehensive on paper — explicit and implicit labels, platform verification, a tamper ban. Frontier No coverage measurement has been published from inside the regime, the tamper prohibition cannot bind actors outside the jurisdiction, and the same stripping physics applies to Chinese pipelines as to everyone else’s. Mandates change who is liable, not what survives recompression; the labelled-share data the regime could publish, and has not, would settle what compulsion actually bought.