TwinEthosRequest access

Control

GenAI content without latent provenance disclosure

AI-generated image/video/audio must carry a latent, machine-readable disclosure with provenance data.

Informational data, not legal advice. Summaries are TwinEthos's own words and rules have not been reviewed by a lawyer: check the official text before relying on any of it. A guard addresses an item; adding it is not a statement that your code meets any law.

Family: AI-generated content is not labeled, marked, or traceable as artificial · control id cond.genai-content-no-latent-provenance-disclosure

Reach

3items this one guard addresses
1jurisdictions where binding law on it is in force
0more where it is enacted, not yet applying
0standards and frameworks on the same control

Law in force in California (US-CA); next date 2027-01-01.

The guard to add

Embed a signed C2PA manifest or equivalent latent disclosure in generated or captured media when it is created, and do not distribute systems or files that lack it.

Where media is created (the generation handler after images.generate or a diffusion pipeline, or the capture pipeline in device firmware or camera app), build a provenance manifest stating who and what produced it (provider or manufacturer, system or device name and version, timestamp, unique id) and sign and embed it (c2pa.Builder with builder.sign, c2patool, c2pa-node) before the file is saved, uploaded, or returned. Later re-encode steps preserve the manifest. Where the product distributes generative systems rather than media (a model or weights hosting platform), the publish or listing step checks that each system declares support for latent disclosure and blocks publication otherwise.

Where it goes: 9 AI output handling, 1 application source code, 12 repository artifacts, 14 user-facing text.

What reviewers look for: a C2PA signing call on every path from the generator to image.save, s3.put_object, FileResponse, or res.send; manifest fields naming the producer, version, timestamp, and id; for capture products, a provenance setting that is on by default; for hosting platforms, a disclosure check that runs before a listing becomes public or downloadable.

Example (c2pa-python), before:

image = pipe(prompt).images[0]
image.save(out_path)

After:

image = pipe(prompt).images[0]
image.save(raw_path)
manifest = {
  'claim_generator_info': [{'name': 'acme-image-service', 'version': '2.3.0'}],
  'assertions': [
    {'label': 'c2pa.actions', 'data': {'actions': [{'action': 'c2pa.created',
      'digitalSourceType': 'http://cv.iptc.org/newscodes/digitalsourcetype/trainedAlgorithmicMedia',
      'when': datetime.now(UTC).isoformat()}]}},
    {'label': 'com.acme.provenance', 'data': {'system': 'acme-image', 'system_version': '2.3.0', 'content_id': str(uuid.uuid4())}}]}
builder = c2pa.Builder(manifest)
with open(raw_path, 'rb') as src, open(out_path, 'w+b') as dst:
    builder.sign(signer, 'image/png', src, dst)   # signer from our load_c2pa_signer()

Engineering guidance, not legal advice. Each provision below may add its own details (a cadence, a deadline, a required notice element): open it for those.

Every rule this guard addresses

Binding law — in force (1)

Binding law — not yet in force or stayed (2)