Control
GenAI content without latent provenance disclosure
AI-generated image/video/audio must carry a latent, machine-readable disclosure with provenance data.
Informational data, not legal advice. Summaries are TwinEthos's own words and rules have not been reviewed by a lawyer: check the official text before relying on any of it. A guard addresses an item; adding it is not a statement that your code meets any law.
Reach
Law in force in California (US-CA); next date 2027-01-01.
The guard to add
Embed a signed C2PA manifest or equivalent latent disclosure in generated or captured media when it is created, and do not distribute systems or files that lack it.
Where media is created (the generation handler after images.generate or a diffusion pipeline, or the capture pipeline in device firmware or camera app), build a provenance manifest stating who and what produced it (provider or manufacturer, system or device name and version, timestamp, unique id) and sign and embed it (c2pa.Builder with builder.sign, c2patool, c2pa-node) before the file is saved, uploaded, or returned. Later re-encode steps preserve the manifest. Where the product distributes generative systems rather than media (a model or weights hosting platform), the publish or listing step checks that each system declares support for latent disclosure and blocks publication otherwise.
Where it goes: 9 AI output handling, 1 application source code, 12 repository artifacts, 14 user-facing text.
What reviewers look for: a C2PA signing call on every path from the generator to image.save, s3.put_object, FileResponse, or res.send; manifest fields naming the producer, version, timestamp, and id; for capture products, a provenance setting that is on by default; for hosting platforms, a disclosure check that runs before a listing becomes public or downloadable.
Example (c2pa-python), before:
image = pipe(prompt).images[0]
image.save(out_path)After:
image = pipe(prompt).images[0]
image.save(raw_path)
manifest = {
'claim_generator_info': [{'name': 'acme-image-service', 'version': '2.3.0'}],
'assertions': [
{'label': 'c2pa.actions', 'data': {'actions': [{'action': 'c2pa.created',
'digitalSourceType': 'http://cv.iptc.org/newscodes/digitalsourcetype/trainedAlgorithmicMedia',
'when': datetime.now(UTC).isoformat()}]}},
{'label': 'com.acme.provenance', 'data': {'system': 'acme-image', 'system_version': '2.3.0', 'content_id': str(uuid.uuid4())}}]}
builder = c2pa.Builder(manifest)
with open(raw_path, 'rb') as src, open(out_path, 'w+b') as dst:
builder.sign(signer, 'image/png', src, dst) # signer from our load_c2pa_signer()Engineering guidance, not legal advice. Each provision below may add its own details (a cadence, a deadline, a required notice element): open it for those.
Upcoming dates
- : GenAI hosting platforms must not distribute systems that omit disclosures (California) (California (US-CA); first application)
- : Capture device manufacturers must offer latent provenance disclosure (California) (California (US-CA); first application)
- : GenAI providers must embed latent provenance disclosure in synthetic media (California) (California (US-CA); later phase)
Every rule this guard addresses
Binding law — in force (1)
- California (US-CA)
- GenAI providers must embed latent provenance disclosure in synthetic media (California) Cal. Bus. & Prof. Code 22757.3(a)
Binding law — not yet in force or stayed (2)
- California (US-CA)
- Capture device manufacturers must offer latent provenance disclosure (California) Cal. Bus. & Prof. Code 22757.3.3(a) · applies from 2028-01-01
- GenAI hosting platforms must not distribute systems that omit disclosures (California) Cal. Bus. & Prof. Code 22757.3.2(a) · applies from 2027-01-01