Binding law — not yet in force or stayed
Embed tamper-resistant provenance data in AI-generated images, video and audio (Washington HB 1170)
From 2027-02-01, a covered provider (a person or entity that creates, codes or otherwise produces a generative AI system with over 1,000,000 monthly users that is publicly accessible in Washington to consumers for personal use) must, to the extent commercially and technically reasonable, include provenance data in video, image or audio content its system creates or materially alters, so a user can assess whether the system created or materially altered it, and make the data difficult to remove or tamper with; a commonly supported standard such as the C2PA specification is compliant (Laws 2026, ch. 167, Secs. 1-2). Detect media-generation code that writes or serves output with no C2PA manifest or watermark.
Trust and provenance not reviewed by a lawyer · audit-grade · source verified 4 Oct 2026 · release 2026.10.05
- Lane
- Binding law — not yet in force or stayed Enacted, not yet applying: applies from 1 Feb 2027
- Official source
- Laws 2026, ch. 167 (E2SHB 1170), Sec. 2(1) · captured 4 Oct 2026 · anchor hash (SHA-256)
95469aeb5707…· 11 more anchors in the data release - Verification
- Quoted text found word for word in the captured official document (4 Oct 2026). Source last verified 4 Oct 2026: checked against the captured official document.
- Data release
- Data release 2026.10.05, data as of 4 Oct 2026, schema 0.3.10.
- Legal review
- Not reviewed by a lawyer. TwinEthos derived this rule from the official text it cites: treat it as research to check against that text; it is not legal advice. No TwinEthos rule has been legally reviewed yet. Open questions for counsel on this rule: 1.
- Audit standard
- Audit-grade: meets all 10 checks of the TwinEthos audit standard that apply to it. The audit standard is TwinEthos's own quality bar for provenance, dates, applicability, detectors, fixtures, remediation and licences; it is not a legal review.
- Detectors
1 detector (code pattern), experimental: written from the rule's text and not yet measured for precision on real code, so treat a hit as a lead to verify.
Known limits:
- Provider-side marking stripped by a later re-encode (cv2.imwrite, Pillow save)
- Provenance added by a separate media service
- Only covered providers (over 1,000,000 monthly users, publicly accessible to Washington consumers) are in scope; provenance added by the model vendor counts only if it survives later re-encoding.
Who it applies to
- Duty falls on: provider
- Covered providers: generative AI systems (generating images, audio or video) with over 1,000,000 monthly users, publicly accessible in Washington to consumers for personal use. Applies from 2027-02-01, to the extent commercially and technically reasonable. Excludes governments, business-to-business distribution, exclusively video-game or interactive products, and upscaling, noise-reduction or compression systems. How monthly users are counted, and whether an application built on another company's model is itself a covered provider, need human determination.
- Not covered:
- State, local and tribal governments are not covered providers (Sec. 1(2))
- Business-to-business uses, sales, licensing or distribution of generative AI systems (Sec. 3(2))
- Products, services, websites or applications that provide exclusively video game or interactive experiences (Sec. 5(1))
- Systems used solely for upscaling, noise reduction or compression (Sec. 5(2))
- Minor modifications (brightness, contrast or color, sharpening, saturating, filters, resizing, scaling, cropping, format conversion, resampling, denoising, removing background noise in audio) do not 'materially alter' content (Sec. 2(4))
- No duty to put information about an identified or reasonably identifiable individual into the provenance data (Sec. 2(3)), or to disclose trade secrets or confidential design information (Sec. 3(1))
- Whether it applies depends on facts outside the code; a person has to decide.
The guard to add
Mark every generated image, audio, video, or text output with machine-readable provenance, such as a signed C2PA manifest or watermark, before it is saved, served, or published.
In the generation service, a marking step sits between the generator call and every sink (image.save, s3.put_object, blob.upload, FileResponse, res.send, publish). Images, video, and audio get a signed C2PA manifest whose actions record digitalSourceType trainedAlgorithmicMedia, and where robustness matters an invisible watermark as well (imwatermark WatermarkEncoder, AudioSeal, SynthID) so the mark survives metadata stripping. Generated text carries provenance metadata in the API response or document, or a text watermark where the model provider offers one. Sinks accept only the marked artifact, and a test confirms the mark is present and detectable.
Where it goes: 9 AI output handling, 1 application source code, 12 repository artifacts.
What this provision adds:
- The provenance data must let a user assess whether the provider's system created or materially altered the content, and be difficult to remove or tamper with; the C2PA specification is expressly compliant.
Example (diffusers + invisible-watermark + c2pa), before:
image = pipe(prompt).images[0] # StableDiffusionPipeline
image.save(out_path)After:
image = pipe(prompt).images[0]
content_id = uuid.uuid4()
bgr = cv2.cvtColor(np.array(image), cv2.COLOR_RGB2BGR)
enc = WatermarkEncoder()
enc.set_watermark('bytes', content_id.bytes[:4]) # 32-bit id, detectable later
cv2.imwrite(tmp_path, enc.encode(bgr, 'dwtDct'))
sign_c2pa(tmp_path, out_path, content_id=content_id) # our helper around c2pa.Builder.signControl: Synthetic content not machine-readable-marked. The same guard addresses 8 items with binding law in 6 jurisdictions. Engineering guidance, not legal advice.
Standards that recommend the same control
- Businesses providing AI should develop and, as needed, implement technology to identify AI-generated content, such as watermarks (Japan, soft law) (Japan AI appropriateness guideline (AI Promotion Act Art. 13) · 人工知能関連技術の研究開発及び活用の適正性確保に関する指針 2(3) 十分な安全性の確保 (safety, including technology to identify AI-generated content))
- GenAI systems should employ content-provenance methods and measure their effectiveness (NIST GenAI Profile) (NIST GenAI Profile (AI 600-1) · NIST AI 600-1, Sec. 2 risk list (Information Integrity))
Rule id wa-hb1170.genai-media-provenance-data · review status: primary source derived