TwinEthos homeAPI access

Control

Machine-readable marking or deepfake disclosure on AI output removed or disabled

Code that handles AI-generated or AI-manipulated content keeps the machine-readable marks the generating system applied (C2PA manifests, provenance metadata, invisible watermarks) and any deepfake disclosure attached to it, and does not switch off the provider's marking.

Informational data, not legal advice. Summaries and rules have not been reviewed by a lawyer: always verify official law text for decisions. A suggested guard is intended to address each rule; adding it is not a statement of compliance to that law.

Family: AI-generated content is not labeled, marked, or traceable as artificial · control id cond.ai-output-marking-removed-or-obstructed

Reach

1items this one guard addresses
1jurisdictions where binding law on it is in force
0more where it is enacted, not yet applying
0standards and frameworks on the same control

Law in force in GR.

Trust and provenance

How far the rules this guard addresses have been checked. Each rule links to its provision, with its citation, official text and its own panel.

This control
Audit-grade: meets all 3 checks of the TwinEthos audit standard that apply to it.
Lanes
Binding law — in force 1
Verification
Sources last verified 3 Oct 2026; each provision states how.
Data release
Data release 2026.10.03.4, data as of 3 Oct 2026, schema 0.3.9.
Legal review
None of the 1 rule has been reviewed by a lawyer; no TwinEthos rule has been legally reviewed yet. Treat each as research to check against the official text; it is not legal advice. Open questions for counsel on them: 1.
Audit standard
1 of 1 rule audit-grade. The audit standard is TwinEthos's own quality bar for provenance, dates, applicability, detectors, fixtures, remediation and licences; it is not a legal review.
Detectors
3 detectors, all experimental: written from the rule's text and not yet measured for precision on real code, so treat a hit as a lead to verify. Each provision lists its detectors' known limits.

The guard to add

Keep the marks: process AI output so its C2PA manifest, provenance metadata and watermark survive, never switch off the generator's marking, and never strip an 'AI-generated' disclosure.

In every path that takes AI-generated media from the generator (images.generate, a diffusers pipeline, Imagen, a TTS or voice-clone call) to storage or publication, remove the calls that drop marks: ffmpeg -map_metadata -1, ImageMagick -strip, exiftool -all=, piexif.remove(, strip_metadata=True, remove_watermark( or remove_c2pa(. Where metadata must be reduced for privacy, remove only the named private fields and keep or re-sign the C2PA manifest (c2pa.Builder / c2patool) after editing. Leave the provider's marking on: no add_watermarker=False or pipe.watermark = None in diffusers, no add_watermark=False for Imagen. Edit and export code carries the deepfake or 'AI-generated' disclosure through; nothing removes or hides it. A test reads the mark back (c2pa.Reader, the watermark decoder) from a processed sample.

Where it goes: 9 AI output handling, 1 application source code, 12 repository artifacts.

What reviewers look for: in a module that generates or receives AI media, no metadata or watermark removal call (-map_metadata -1, -strip, exiftool -all=, piexif.remove(, strip_metadata, remove_/strip_ c2pa, watermark or provenance) and no disabled marking (add_watermarker=False, add_watermark=False, enable_watermark=False, pipe.watermark = None); privacy scrubbing names only private fields; a test that decodes the mark after processing.

Example (diffusers + ffmpeg post-processing), before:

pipe = StableDiffusionXLPipeline.from_pretrained(MODEL_ID, add_watermarker=False)
image = pipe(prompt).images[0]
image.save(tmp_path)
subprocess.run(['ffmpeg', '-i', tmp_path, '-map_metadata', '-1', out_path])

After:

pipe = StableDiffusionXLPipeline.from_pretrained(MODEL_ID)  # keeps the invisible watermarker
image = pipe(prompt).images[0]
image.save(tmp_path)
sign_c2pa(tmp_path, out_path, digital_source_type='trainedAlgorithmicMedia')  # our helper around c2pa.Builder.sign
assert read_c2pa(out_path)  # round-trip check: the mark survives

Engineering guidance, not legal advice. Each provision below may add its own details (a cadence, a deadline, a required notice element): open it for those.

Every rule this guard addresses

Binding law — in force (1)

Informational data, not legal advice. Summaries are TwinEthos's own words and rules have not been reviewed by a lawyer: check the official text before relying on any of it. A guard addresses an item; adding it is not a statement that your code meets any law.