Control
GenAI provider offers no provenance verification tool, or one that exposes personal information
Anyone holding media can check, at no cost and by upload, URL or API, whether a provider's GenAI system created or altered it and see the system provenance data, without the check exposing personal information found in the content or taken from the person checking.
Informational data, not legal advice. Summaries are TwinEthos's own words and rules have not been reviewed by a lawyer: check the official text before relying on any of it. A guard addresses an item; adding it is not a statement that your code meets any law.
Reach
Law in force in California (US-CA).
The guard to add
Ship a free public endpoint and API that reads your latent provenance from uploaded or linked media and returns only system provenance data.
Add a verification route (for example POST /v1/provenance/verify) and publish it as an API: accept a file upload or a URL, read the embedded C2PA manifest or watermark with the library the generation path signs with (c2pa.Reader, c2pa-node, c2patool, the watermark decoder), and answer whether your GenAI system created or altered the content from the claim generator, actions and signature. Build the response from an allowlist of system provenance fields; drop identity assertions (cawg.identity), author or creator fields, and EXIF owner and location unless a stored consent record of the person they concern covers them. Process the upload in memory or a temporary file and delete it; require no sign-in or personal data, and use rate limits or abuse checks instead. Link the tool from the generation interface; a compatible third-party verifier linked there is an alternative.
Where it goes: 1 application source code, 6 API calls and integrations, 9 AI output handling, 14 user-facing text.
What reviewers look for: a public route and API spec entry that reads provenance from an upload or a URL; an allowlist of system provenance fields between the parsed manifest and the response, with personal fields only behind a consent check; no auth dependency or login decorator on the route; no persistent write of the submitted file; a link to the tool, or to a third-party verifier, in the generation interface.
Example (FastAPI + c2pa-python), before:
@app.post('/v1/images')
def generate(req: Prompt):
png = sign_with_c2pa(render(req.prompt))
return Response(png, media_type='image/png')
# no way to check a file against our disclosuresAfter:
SYSTEM_FIELDS = ('claim_generator', 'claim_generator_info', 'signature_info', 'validation_status')
@app.post('/v1/provenance/verify') # public, free, documented in openapi.json
async def verify(file: UploadFile | None = None, url: str | None = None):
data = await file.read() if file else fetch_media(url) # in memory; nothing stored
try:
store = json.loads(c2pa.Reader(sniff_mime(data), io.BytesIO(data)).json())
except Exception:
return {'ours': False, 'provenance': None}
active = store['manifests'][store['active_manifest']]
actions = [a for a in active.get('assertions', []) if a['label'].startswith('c2pa.actions')]
return {'ours': is_our_generator(active), # created or altered by our system
'provenance': {**{k: active.get(k) for k in SYSTEM_FIELDS}, 'actions': actions}}
# identity, author and EXIF assertions are never echoed unless consented_fields(active) lists themEngineering guidance, not legal advice. Each provision below may add its own details (a cadence, a deadline, a required notice element): open it for those.
Upcoming dates
- : GenAI providers must offer a free disclosure verification tool that withholds personal information (California) (California (US-CA); later phase)
Every rule this guard addresses
Binding law — in force (1)
- California (US-CA)
- GenAI providers must offer a free disclosure verification tool that withholds personal information (California) Cal. Bus. & Prof. Code 22757.2(a)