Control
Synthetic content not machine-readable-marked
AI-generated or AI-altered audio, image, video, or text must carry machine-readable marking or provenance data identifying it as artificial.
Informational data, not legal advice. Summaries are TwinEthos's own words and rules have not been reviewed by a lawyer: check the official text before relying on any of it. A guard addresses an item; adding it is not a statement that your code meets any law.
Reach
Law in force in China (CN), European Union (EU), Connecticut (US-CT).
The guard to add
Mark every generated image, audio, video, or text output with machine-readable provenance, such as a signed C2PA manifest or watermark, before it is saved, served, or published.
In the generation service, a marking step sits between the generator call and every sink (image.save, s3.put_object, blob.upload, FileResponse, res.send, publish). Images, video, and audio get a signed C2PA manifest whose actions record digitalSourceType trainedAlgorithmicMedia, and where robustness matters an invisible watermark as well (imwatermark WatermarkEncoder, AudioSeal, SynthID) so the mark survives metadata stripping. Generated text carries provenance metadata in the API response or document, or a text watermark where the model provider offers one. Sinks accept only the marked artifact, and a test confirms the mark is present and detectable.
Where it goes: 9 AI output handling, 1 application source code, 12 repository artifacts.
What reviewers look for: c2pa signing (c2pa.Builder / builder.sign, c2patool, @contentauth/c2pa, c2pa-node) or a watermark encoder on every path from images.generate, audio.speech.create, or a diffusion pipeline to a save or serve call; a test that reads the mark back from a generated sample.
Example (diffusers + invisible-watermark + c2pa), before:
image = pipe(prompt).images[0] # StableDiffusionPipeline
image.save(out_path)After:
image = pipe(prompt).images[0]
content_id = uuid.uuid4()
bgr = cv2.cvtColor(np.array(image), cv2.COLOR_RGB2BGR)
enc = WatermarkEncoder()
enc.set_watermark('bytes', content_id.bytes[:4]) # 32-bit id, detectable later
cv2.imwrite(tmp_path, enc.encode(bgr, 'dwtDct'))
sign_c2pa(tmp_path, out_path, content_id=content_id) # our helper around c2pa.Builder.signEngineering guidance, not legal advice. Each provision below may add its own details (a cadence, a deadline, a required notice element): open it for those.
Upcoming dates
- : Large GenAI providers must embed tamper-resistant provenance data (Connecticut) (Connecticut (US-CT); first application)
- : Synthetic AI output must be machine-readably marked as artificial (European Union (EU); later phase)
Every rule this guard addresses
Binding law — in force (3)
- China (CN)
- Deep-synthesis services that may confuse the public must carry a conspicuous label (China) 互联网信息服务深度合成管理规定 第十七条 (Art. 17)
- Connecticut (US-CT)
- Large GenAI providers must embed tamper-resistant provenance data (Connecticut) Conn. PA 26-15 Sec. 15(b)
- European Union (EU)
Standard / soft law (1)
- Everywhere (*)
- GenAI systems should employ content-provenance methods and measure their effectiveness (NIST GenAI Profile) NIST AI 600-1 §2.8 (Information Integrity) + GV-4.3-001 / MS-1.1-001 / MS-2.7-005