Practised by
2 links
Graph · Strategy
01 · In focus
The structured facts the source records about Content provenance and cryptographic authenticity infrastructure, the count of declared adjacencies in the corpus, and the federation map zoomed on this node and its neighbours.
strategy
↑2 declared connections
02 · Connections
Split by direction. Direct links are the ones Content provenance and cryptographic authenticity infrastructure’s source record names; inferred backlinks are records elsewhere in the corpus that point at this entity.
2 links
Other records that name this entity.
2 links
03 · Background
Body prose as it appears in movement-graph’s published markdown for this entity. Links to other corpus entities resolve to their graph page; links to deeper repo paths are kept as text so the page does not invent a route.
Movement organisations organise to build, standardise, and mandate the substrate that lets any downstream actor — a journalist, a court, a platform, a regulator, an end user — verify whether a piece of media was produced by an AI system, edited by one, or captured authentically. The vehicles are technical standards (C2PA Content Credentials manifests attached to images, video, and audio), hardware attestation (cameras that cryptographically sign captures at the sensor), open-source verification tools (WITNESS's ProofMode for civil-society video capture; browser plug-ins for C2PA reading), journalism-side newsroom workflows, and legal mandates that require covered generators to embed provenance signals into their outputs. The strategy's target output is not a rule about what AI can do — it is the infrastructure that makes every other rule about AI-generated content operationalisable.
An actor chooses this strategy because every other consumer- or governance-side response to synthetic media is blocked by the pre-question of whether the media in front of the decision-maker is authentic. Disclosure mandates, deepfake laws, court evidentiary rules, platform labelling policies, movement-run certifications — each requires an underlying answer to "is this AI, and if so which system produced it, and if not who captured it under what chain-of-custody" that is enforceable at technical scale. Provenance infrastructure — cryptographic manifests binding creator identity, capture device, edit history, and generative-model claims to the artefact itself — turns a policy proposition ("AI-generated political ads must be labelled") into an inspectable machine-readable fact. The strategy's adopters are the actors positioned to build the infrastructure (specialist civil-society tech teams), sit on the standards bodies (C2PA, ISO), advocate for statutory mandates (digital-rights coalitions), and train downstream users on verification (journalism collectives, human-rights investigators).
It trades off elegance for adversarial robustness. Watermarks in generated content are technically fragile — adversarial removal is a solved problem for images at consumer-friendly quality and an actively studied problem for LLM output — and the provenance-infrastructure strategy is running against an active counterfeiting layer that scales as generation does. Hardware attestation depends on manufacturer buy-in that concentrates trust in a small number of camera and sensor vendors whose commercial interests are only sometimes aligned with civil-society goals; C2PA's governance is Adobe- and industry-dominated in a shape the civil-society-in-standards-bodies counter-read directly names. And every provenance manifest is a potential surveillance surface — cryptographically-signed capture chains, extremely useful for a court and a court-adjacent adversary alike, put photojournalists, whistleblowers, and dissidents at risk from the same infrastructure that would authenticate their material to a broader audience. The strategy's most sophisticated adopters (WITNESS in particular) have surfaced this dual-use tension as the defining design constraint, and the strategy's adoption at consumer scale will succeed only insofar as the tension is resolved rather than deferred.
Distinct from consumer-facing AI use disclosure mandate. Disclosure mandate is the rule: the operator must announce that AI is present at the point of encounter. Provenance infrastructure is the substrate: the cryptographic machinery that makes the announcement machine-verifiable rather than a promise. Disclosure without provenance is enforceable only against operators willing to self-declare; provenance without disclosure is inspectable but not legally required. The two strategies are complementary layers of the same governance stack — the mandate says what must be disclosed, the provenance infrastructure is what makes the disclosure inspectable — and mature policy proposals (EU AI Act Article 50 machine-readable-format requirements; C2PA-aligned US NIST guidance) increasingly pair them. Organising typically bifurcates: policy-track advocates work the mandate, technical-track organisers work the substrate.
Distinct from civil-society participation inside AI technical-standards bodies. Standards-room participation is a tactic — sitting inside C2PA, ISO/IEC JTC 1/SC 42, IETF working groups on media formats to shape their drafts. Provenance-infrastructure organising is a strategic focus that uses standards-room participation as one of its instruments (alongside open-source deployment, mandate advocacy, and verification-tool training). The relationship is instrument-to-strategy: an organisation adopting the provenance strategy will typically deploy the standards-room tactic; an organisation deploying the standards-room tactic in a different substantive area (network protocols, telecoms) is running the tactic outside this strategy.
Distinct from movement-run consumer-facing AI certification. Movement-run certification is a positive trust mark applied to organisations — an audited claim about a producer or model. Provenance infrastructure is a negative-or-positive claim about artefacts — a cryptographically inspectable chain-of-custody statement about a specific image, video, or piece of text. The two strategies coexist without overlap: a movement certification of a generator can be checked against the C2PA manifests that generator's outputs carry, and a provenance-verification tool can carry a movement certification's mark in its user interface. But the audit surfaces are different, the adopters are different, and the failure modes are different (a bad certification captures the mark; a bad provenance infrastructure captures the substrate).
Feeds empirical audit and expose. Provenance-infrastructure adoption is itself an auditable dimension: audits of platforms on how they surface Content Credentials, of generators on whether their outputs carry the manifests they claim, of newsrooms on their verification-workflow adoption. Once the substrate exists, an audit organisation can benchmark actors' engagement with it — the Automating Society-style annual scan applied to provenance surfaces.
Adjacent to community-defined benchmarks and standards. Community benchmarks measure AI performance against a task; provenance infrastructure marks AI presence in an artefact. Both are movement-side attempts to make the AI-content landscape legible; both work at the technical-standards register; both share the failure mode that the industry-defined version outcompetes the community-defined version on adoption. The C2PA / Content Authenticity Initiative governance question — is provenance a movement infrastructure or an industry compliance surface — is the same shape as the benchmark-governance question and can be read as the same strategic contest under a different label.
The strongest competing posture against this strategy is industry-owned Content Authenticity Initiative capture — the C2PA / CAI governance is founded and dominated by Adobe, Microsoft, and major camera vendors; the resulting standard risks becoming a compliance vocabulary in which participation signals rights-consideration without imposing the substantive constraints civil society requires. The counter-move is not a rival standard (the network effects are prohibitive) but sustained civil-society presence inside the C2PA governance layer, an open-source verification stack that runs on the manifests without relying on the founders' infrastructure, and a policy-track push for mandates that specify machine-readable outcomes rather than delegating to whichever standard the industry hands the regulator. Without this bracket, the strategy risks the counter-narrative-framing failure mode transposed to the standards layer: the movement built the infrastructure vocabulary; the industry uses it to defang the mandate.
Source: entities/strategies/strat-content-provenance-and-cryptographic-authenticity.md — movement-graph pin 5edfc3b.