Skip to content

Content Provenance & AI Disclosure — C2PA, SynthID, and the Law

Content Provenance & AI Disclosure

TL;DR: “Is this AI, and do I have to say so?” splits into three different layers that get conflated constantly. (1) Technical provenance — how a file carries its origin: C2PA / Content Credentials (signed metadata, rich but easily stripped) vs SynthID (an invisible watermark baked into the pixels, robust but says only “from a Google-family model”). (2) Platform labels — what TikTok / Meta / YouTube show users; where platforms have said so on the record, labeling AI content does not reduce your reach (getting caught unlabeled does). (3) Disclosure law — what governments require: the EU AI Act Article 50 (applies 2 Aug 2026), FTC Act §5 (Operation AI Comply, 2024), NY’s synthetic-performer law (9 Jun 2026), California’s AI Transparency Act (2 Aug 2026). A file can carry C2PA metadata, a SynthID watermark, a platform label, and a legal disclosure duty — all four are different things. The operating rule: disclose realistic AI content conspicuously, keep claims substantiated, and don’t lean on platform labels to satisfy a legal duty.

Three layers — don’t conflate them

The single most common mistake in this area is treating C2PA, SynthID, an “AI” badge, and a legal disclosure requirement as one thing. They are four independent mechanisms:

What it isWho runs itBinding?
C2PA / Content CredentialsSigned metadata manifest attached to the fileIndustry standard bodyNo (voluntary tech)
SynthIDInvisible watermark inside the pixels/audio/textGoogle DeepMindNo (voluntary tech)
Platform labelsAn “AI” badge shown to viewersEach platformNo (private policy)
Disclosure lawA duty to tell peopleGovernments (EU/US/states)Yes — enforceable

Layer 1 — Technical provenance (how the file carries its origin)

C2PA / Content Credentials

The Coalition for Content Provenance and Authenticity standard: a cryptographically signed “manifest” recording a file’s origin and edit history — popularly the “nutrition label” for digital content, shown to users as the Content Credentials (“CR”) badge. Steering members include Adobe, BBC, Google, Intel, Microsoft, OpenAI, Sony, Truepic. (OpenAI joined the steering committee in May 2024 — some write-ups resurface this as if it’s new; it isn’t.) It’s written automatically by Adobe Firefly/Creative Cloud, Microsoft, and OpenAI’s DALL·E/Sora outputs.

The load-bearing limitation: it’s metadata, and metadata is fragile. Screenshots, re-uploads, recompression, or a platform that doesn’t preserve it strip it entirely. As of 2026, LinkedIn and TikTok preserve Content Credentials; Instagram and X strip them. So a missing credential proves nothing — absence is not evidence the content is human-made.

SynthID (Google DeepMind)

An invisible watermark embedded in the content itself — pixels, audio samples, or text-token patterns — covering image, audio, video, and text. It is auto-applied by Google’s generative models (Gemini image / Nano Banana / Nano Banana Pro, Imagen, Veo, Lyria). The SynthID Detector verifies it, but as of mid-2026 it’s waitlist / limited access (rolled out to journalists first), not an open consumer tool.

C2PA vs SynthID — the distinction that matters

  • SynthID is in the pixels — it survives crop, filter, compression, and screenshots that destroy C2PA metadata. But it carries only “this came from a Google-family model,” not a full history, and says nothing about non-Google AI or human content.
  • C2PA carries the rich, signed story (origin + every edit) — but it’s fragile and vanishes on a screenshot.
  • They are complementary, not interchangeable. One is robust-but-shallow; the other is rich-but-brittle.

For a business: Provenance tech is a signal, not proof. Assume any AI image you make in Google or Adobe tools already carries a provenance signal you can’t fully strip — and never treat “no credential” as “not AI.”

Layer 2 — Platform AI-labeling policies (2026)

PlatformMechanismAffects reach?
TikTokAuto-labels via C2PA (since May 2024, first major platform); creators must disclose realistic AI mediaNo — TikTok: the AI setting “won’t affect the distribution of your video as long as it doesn’t violate our Community Guidelines”
YouTubeAltered or synthetic content” disclosure for realistic content (not for animation or AI used only as a production aid)No — YouTube: disclosing “won’t limit a video’s audience or impact its eligibility to earn money”
Meta (IG/FB)AI info” label; reads C2PA + invisible markers; self-taggingPresented as informational; Meta has not put a no-reach-penalty promise in writing the way TikTok/YouTube have — don’t assume one
LinkedInShows the CR badge when a file carries C2PA; preserves credentialsNo stated reach effect
XMade with AI,” largely voluntary self-disclosure; strips incoming C2PANo stated demotion; weak enforcement

For a business: On every platform that has stated it on the record (TikTok, YouTube), labeling does not cost you reach — getting caught unlabeled does. Label proactively; it’s free insurance. But labels are inconsistent across platforms (IG/X strip credentials), so they are not a reliable system you can lean on for legal compliance.

Layer 3 — Disclosure law (what you’re actually required to do)

EU AI Act — Article 50 (the big 2026 item)

Regulation (EU) 2024/1689, Article 50, transparency obligations — applies 2 August 2026:

  • Providers (50(2)): must mark generative-AI outputs as artificially generated in a machine-readable format (“effective, interoperable, robust… as far as technically feasible”). Exceptions for assistive/non-substantial editing.
  • Deployers (50(4)): must disclose deepfakes (AI-generated/manipulated image/audio/video) and AI-generated text published to inform the public on matters of public interest. Exceptions for artistic/satirical works and human-reviewed editorial content.
  • Who it binds: both. The marking duty is the model provider’s; the disclosure duty is whoever deploys/publishes — so a marketer publishing a generated deepfake is a deployer with a 50(4) duty.
  • A voluntary Code of Practice on transparency of AI-generated content (published June 2026) aids compliance but doesn’t replace the duty.
  • Caveat (do not state as settled): law firms report an “AI Omnibus” grace period to 2 December 2026 for the 50(2) marking duty on systems already on market — this is not on the official EC page as of writing; verify against the final adopted text. The 2 August 2026 applicability date is primary-confirmed.

US — FTC

  • Undisclosed AI imagery, or undisclosed material AI manipulation in an endorsement, can be deceptive under FTC Act §5 (claims must be truthful and substantiated; material connections disclosed).
  • AI deception is an active priority via Operation AI Comply (launched September 2024 — a sweep, not a standing “AI unit”).
  • The Endorsement Guides (16 CFR Part 255) were last revised in 2023 (not 2026) and already cover virtual influencers / AI avatars.
  • Penalties don’t auto-attach. A first §5 deception finding carries no civil penalty; penalties bite when conduct violates an existing order or a specific rule — e.g. the 2024 Fake Reviews Rule (16 CFR Part 465), max $53,088/violation (2025 amount).

State laws (US)

  • New York — Synthetic Performer Disclosure Law: effective 9 June 2026 (first in nation). Conspicuous disclosure required when an ad contains a “synthetic performer” (an AI-created human-seeming asset), where the advertiser has actual knowledge. $1,000 first / $5,000 subsequent; applies to ads reaching NY consumers.
  • California — AI Transparency Act (SB 942, amended by AB 853): operative 2 August 2026 (aligned to the EU date). Covered GenAI providers must offer a free public AI-detection tool, optional visible disclosure, and latent disclosure that is “permanent or extraordinarily difficult to remove” (i.e. C2PA/SynthID-style embedding, not strippable tags). AB 853 extends duties to large platforms and capture-device makers.

For a business: Disclosure is law now, not etiquette, and it’s converging on 2 August 2026 (EU + California), with NY live from 9 June 2026. If your content reaches the EU, NY, or California, undisclosed realistic synthetic media is legal exposure — not just a trust risk.

What to actually do

  1. Disclose realistic AI content conspicuously — it doesn’t cost reach where platforms have said so, and it’s the cheapest path to legal safety.
  2. Keep product claims substantiated — the FTC’s real high-risk area is deceptive claims, not the existence of AI in the workflow.
  3. Don’t rely on platform labels for compliance — they’re inconsistent (IG/X strip credentials) and they’re not your legal disclosure.
  4. Treat provenance as a signal, not proof — assume your Google/Adobe outputs carry SynthID/C2PA you can’t fully strip; never read “no credential” as “human-made.”
  5. Watch the dates — EU Art. 50 and California (2 Aug 2026), NY (9 Jun 2026). Re-verify; this area moves monthly.

Key Takeaways

  • Four separate mechanisms, constantly conflated: C2PA (metadata, fragile) · SynthID (watermark, robust) · platform labels · disclosure law. A file can have all four.
  • C2PA vs SynthID: signed-but-strippable history vs in-pixel-but-shallow watermark — complementary, not interchangeable. Absence of either proves nothing.
  • Labeling AI content doesn’t reduce reach where TikTok/YouTube have stated it — getting caught unlabeled does.
  • Disclosure is enforceable law, converging on 2 Aug 2026 (EU AI Act Art. 50 + California); NY’s synthetic-performer law is live 9 Jun 2026.
  • FTC reality (often misstated): §5 deception + Operation AI Comply (2024); Endorsement Guides last revised 2023; penalties attach to order/rule violations, not automatically.

Sources

Do-not-cite (errors/conflations): “OpenAI joined C2PA in 2026” (it was May 2024); “OpenAI + Google embedded SynthID into ChatGPT/DALL·E in 2026” (unconfirmed; OpenAI uses C2PA, not SynthID); C2PA “6,000+ members” / TikTok “1.3B videos labeled” (vendor figures, illustrative only); the EU “AI Omnibus” 2 Dec 2026 grace period (law-firm reporting, not yet primary); “Meta labels don’t affect reach” (Meta hasn’t said so on the record); “SynthID Detector is publicly available” (waitlist as of mid-2026); and the cardinal error — treating C2PA, SynthID, platform labels, and legal disclosure as the same thing.