TwinEthosRequest access

Control

Synthetic content not machine-readable-marked

AI-generated or AI-altered audio, image, video, or text must carry machine-readable marking or provenance data identifying it as artificial.

Informational data, not legal advice. Summaries are TwinEthos's own words and rules have not been reviewed by a lawyer: check the official text before relying on any of it. A guard addresses an item; adding it is not a statement that your code meets any law.

Family: AI-generated content is not labeled, marked, or traceable as artificial · control id cond.synthetic-content-not-machine-marked

Reach

4items this one guard addresses
3jurisdictions where binding law on it is in force
0more where it is enacted, not yet applying
1standards and frameworks on the same control

Law in force in China (CN), European Union (EU), Connecticut (US-CT).

The guard to add

Mark every generated image, audio, video, or text output with machine-readable provenance, such as a signed C2PA manifest or watermark, before it is saved, served, or published.

In the generation service, a marking step sits between the generator call and every sink (image.save, s3.put_object, blob.upload, FileResponse, res.send, publish). Images, video, and audio get a signed C2PA manifest whose actions record digitalSourceType trainedAlgorithmicMedia, and where robustness matters an invisible watermark as well (imwatermark WatermarkEncoder, AudioSeal, SynthID) so the mark survives metadata stripping. Generated text carries provenance metadata in the API response or document, or a text watermark where the model provider offers one. Sinks accept only the marked artifact, and a test confirms the mark is present and detectable.

Where it goes: 9 AI output handling, 1 application source code, 12 repository artifacts.

What reviewers look for: c2pa signing (c2pa.Builder / builder.sign, c2patool, @contentauth/c2pa, c2pa-node) or a watermark encoder on every path from images.generate, audio.speech.create, or a diffusion pipeline to a save or serve call; a test that reads the mark back from a generated sample.

Example (diffusers + invisible-watermark + c2pa), before:

image = pipe(prompt).images[0]   # StableDiffusionPipeline
image.save(out_path)

After:

image = pipe(prompt).images[0]
content_id = uuid.uuid4()
bgr = cv2.cvtColor(np.array(image), cv2.COLOR_RGB2BGR)
enc = WatermarkEncoder()
enc.set_watermark('bytes', content_id.bytes[:4])   # 32-bit id, detectable later
cv2.imwrite(tmp_path, enc.encode(bgr, 'dwtDct'))
sign_c2pa(tmp_path, out_path, content_id=content_id)   # our helper around c2pa.Builder.sign

Engineering guidance, not legal advice. Each provision below may add its own details (a cadence, a deadline, a required notice element): open it for those.

Upcoming dates

Every rule this guard addresses

Binding law — in force (3)

Standard / soft law (1)