The transparency obligations under Article 50 of the EU AI Act took effect on 2 August, which means providers of generative systems must now mark synthetic outputs in a machine-readable format and make them detectable as machine-made. The code of practice setting out how to satisfy that requirement was still being finalised in June, weeks before the deadline it governs, and anything already on the market has until 2 December. Brussels has mandated an outcome and left the specification to catch up, which is not unusual and is not the interesting part.
Sitting on GitHub in the meantime is a small command-line utility that strips Google’s SynthID watermark, C2PA Content Credentials, and the EXIF and IPTC metadata underneath both, from an image, in a single command. It is free, it is not hidden, and most of the commentary I have read treats its existence as an indictment of the regulation. That reading is wrong, and expensively so, because it assumes the mark was ever going to do the job marketing hired it for.
Focus On: Marketers Are Buying the Wrong Kind of Trust
The provenance debate has organised itself almost entirely around durability: can the mark survive a re-encode, or an adversary who wants it gone? On that narrow question the answer is rather better than the pessimists allow. A paper published this year tested six removal attacks across four technique families and confirmed that they defeat the watermark detectors while preserving the picture, though they also leave residue of their own; forensic classifiers trained on the removal artefacts rather than on the watermark signal caught the doctored images at better than 98 per cent accuracy under a strict one per cent false-positive budget. Removal, on that evidence, substitutes one detectable signature for another.
So let us grant the technology everything, and assume a mark that cannot be lifted, present on every asset in every channel. It would still answer a forensic question — was this made by a machine — and the damage marketing is currently sustaining is not forensic.
Consider what happened when eight thousand consumers across eight markets were asked in December what visible AI-generated marketing does to their trust in a brand. Seven per cent said it increased it; thirty-one per cent said it decreased it. Whether the content was verified, signed, authentic, or manipulated never entered the judgement, because the label did the damage on its own. Nor is under-disclosure an escape route, since ninety-one per cent of that same sample expect brands to disclose AI use and 52 per cent say they would stop buying after an experience they judged inauthentic. Canva’s 2026 survey puts 87 per cent of consumers on the view that authentic advertising still requires a human involved, with 78 per cent preferring human-made work even where the machine would do it better. Against all of which, 77 per cent of senior marketing decision-makers plan to increase spend on AI-generated creator content this year.
That gap is the story, and it is a relational problem being answered with a forensic instrument. No improvement in the instrument closes it.
The label states a fact and withholds the reason
Read the disclosure figures a second time, though, and a more useful explanation presents itself. “Made with AI” is a confession. It reports that a machine was involved and says nothing about which part of the work it touched, or to whose benefit, and a confession offered without a reason invites the audience to supply the worst one available. We have been measuring the reaction to a bare fact and concluding that customers dislike the technology.
The question customers are actually answering is one of congruence: whether the way a brand used a machine fits what they believed they were buying from it. A retailer that renders a garment on a body shaped like mine has used AI in a way I can follow and would probably prefer to the alternative. A bank running synthetic transaction patterns to catch fraud on my account before I notice it has done something I would pay for. Neither disclosure costs anything, because in both cases the machine did work the customer wanted done and could not do themselves. The condolence email drafted by a model costs a great deal, and it costs it whether or not anyone labels it, because the thing being purchased in that exchange was attention, and the machine was used to avoid spending it.
Transparency is therefore necessary and insufficient in roughly equal measure. Article 50 will make you declare the fact of machine involvement; nothing in the regulation, and nothing in C2PA, obliges you to declare the reason, and the reason is the entire trust variable. Brands that own their use of AI — that say plainly what the machine did and what it did not, and why the split falls where it does — have a fair chance of coming out of the disclosure ahead of where they went in. Brands treating the label as a legal minimum will find it read as an admission, which is precisely what a bare legal minimum looks like from the outside.
Human ingenuity still needs to be visible in the work, though not for the sentimental reasons usually offered. Visible craft is evidence that the effort was allocated deliberately rather than by default, and allocation is what customers are assessing when they call something inauthentic. Aim is the whole of it: where you point the machine, and whether you can say so in a sentence.
Three regimes, one asset
If the reason cannot be regulated into existence, you might at least expect the fact of disclosure to be simple. It is not.
The infrastructure itself is genuine, and it matured considerably this year. C2PA 2.4 is the live specification, the Content Authenticity Initiative counts more than six thousand member organisations, and 2026 was the year the Conformance Programme and official Trust List replaced the interim arrangement frozen on 1 January. OpenAI’s May update supports C2PA and SynthID together with a public verification preview, which is the one real interoperability win of the year; Canon shipped credentialed workflows for newsroom bodies in the same month, and Pixel 10 now signs at the point of capture.
Then it meets the world. Brussels requires machine-readable marking and leaves the form to codes of practice, while China’s Measures, in force since September 2025, specify visible text labels at a minimum of five per cent of image height, audio cues at 120 to 160 words per minute, embedded producer identifiers, and obligations running the full length of the supply chain — providers, platforms, app stores, and users alike. The Chinese trigger is content that may cause confusion or misunderstanding; the European trigger requires the content to falsely appear authentic. The same asset is therefore labelled in Shanghai and unlabelled in Stockholm, lawfully in both.
The platforms add a third layer that agrees with neither. Google Ads exempts AI-generated text entirely while TikTok covers any realistic AI modification regardless of subject, and Meta and TikTok run automated detection where Google and YouTube lean on self-report. De jure your creative is compliant, and de facto it depends which four platforms it ran on. The credentials often do not survive the journey in any case, since TikTok and YouTube do not preserve C2PA and metadata routinely dies on upload or recompression. The Content Authenticity Initiative says so itself, and says it plainly: a missing credential is not evidence that anything is fake. A verification system whose negative result means nothing is a system with one working half.
The cryptography was always the easy part. What took until this year to arrive was the Trust List, the institutional question of whose signature counts for anything, and Machiavelli’s argument in the Discourses was that institutions outlast their founders precisely because the founding is the easier half. Provenance has only just finished its founding, which makes treating it as settled infrastructure a category error the vendors are perfectly aware of.
What provenance is actually for
In The Agentic CMO I put Provenance first among five disciplines for handling data ethically, and I had training data in mind: where the corpus came from, whether the consent was real. The word has since taken a second job, and marketing has mis-assigned it. Provenance is being budgeted as a brand asset. It is a security asset.
The numbers sit unambiguously on the security side of the ledger. Deepfake fraud cost more than $1.5bn globally in the first nine months of 2025, 57 per cent of it investment fraud built on synthetic video of executives endorsing products they have never seen. Average organisational loss runs around $450,000, rising to $603,000 in financial services, while Arup lost roughly $25m to a single deepfaked video call. Low frequency, high severity: the risk profile that justifies infrastructure spend on its own terms, with no appeal to brand preference required.
What follows is a reclassification rather than a purchase. Sign and register the executive video library and the earnings communications, because when an impersonation surfaces you will need to prove a negative inside a news cycle and the credential is the only thing that does it at that speed. Move the customer-facing label out of legal and give it to whoever owns the creative, on the grounds that it is a creative decision with a measurable cost attached. And commission the jurisdictional audit while the December deadline is still four months away rather than four weeks.
I argued in Switched Off that access to a frontier model is a licence exercised at the discretion of the jurisdiction that issued it. Content provenance is the same lesson arriving from the opposite direction, since the rules under which your creative is lawful are written in four capitals and enforced by four platforms, none of which consulted the others.
My prediction is narrower than the industry’s. Watermarking will work, in the sense of being present, standardised, and mostly accurate by 2028, and it will not return a single point of consumer trust, because it was never built to carry an explanation. The brands that retain trust will do it by making the allocation of effort legible, saying what the machine did and why that was the right call, and they will spend the provenance budget catching the people pretending to be them. Decide this year which of those two lines your money sits on, because December will decide it for you otherwise.
Follow me
That’s all for this week. To keep up with the latest in generative AI and its relevance to your digital transformation programs, follow me on LinkedIn or subscribe to this newsletter.
Disclaimer: The views and opinions expressed in Chronicles of Change and on my social media accounts are my own and do not necessarily reflect the official policy or position of S&P Global.
