AI Images Need a Chain of Custody, Not Just a Disclosure Label

Illustrated infographic summarizing: AI Images Need a Chain of Custody, Not Just a Disclosure Label

By Greg Nowak. Updated 19 September 2026.

A disclosure such as “AI-generated” helps a reader understand how an image was made. It does not tell your business which file was approved, what happened during production, or whether the evidence attached to the original survived publication.

That requires a chain of custody. In this context, the term does not mean a heavyweight forensic process. It means maintaining a testable connection between the source you approved, the derivatives your team created and the file a customer, partner or journalist can actually download.

A label and a Content Credential do different jobs

A visible label communicates a decision to people. A C2PA Content Credential carries signed, machine-readable information about an asset’s provenance. It may describe its origin, the tool involved, recorded actions and its relationship to earlier files.

Neither proves that an image is truthful, legally owned or being used in the correct context. A valid signature shows that the signed claims and their binding to the asset validate. Whether the signer is trusted is a separate question, determined by the verifier and its configured trust lists.

Watermarks add another layer. OpenAI, for example, says supported images from its tools can contain both C2PA metadata and a SynthID watermark. The watermark may survive some transformations that remove metadata, but it carries less context. No signal should be treated as a universal AI detector.

Define the custody record before choosing tools

Begin with the questions the business may eventually need to answer: Who supplied the image? Which version was approved? Where was it edited? Which public renditions exist? What did verification find at each checkpoint? A useful record can live in a digital asset manager, CMS or project system if it has stable identifiers and clear ownership.

Checkpoint Test Evidence to retain Owner
Intake Inspect the untouched source Original file, source, asset ID and verification result Commissioning team
Creative export Check every approved export preset Parent asset, output file and export settings Designer or agency
Handoff Confirm files match the delivery register Sender, recipient, version and timestamp Project lead
CMS processing Inspect the stored master and generated sizes CMS ID, rendition names and results Content team
CDN delivery Download each representative public format Public URL, response format and result Web operations
Withdrawal Locate every active placement Pages, campaigns and replacement status Content owner
A workable chain reaches the delivered file. Stopping at the creative export or CMS upload leaves the most important transformations untested.

Test the route, not just the original

The common mistake is to validate a pristine source and assume the result applies downstream. Real publishing routes resize, crop, recompress and convert files. A CMS may make several thumbnails; a CDN may negotiate AVIF or WebP; a social publishing tool may create another copy. Treat every operation that changes the file as a checkpoint.

  1. Preserve an unchanged source and give it a stable internal identifier.
  2. Run a representative asset through each real editing and publishing route.
  3. Download the output from its public URL instead of inspecting only the CMS media library.
  4. Repeat the test for every format or preset that materially changes the file.

For a technical spot check, the official C2PA command-line tool can produce a concise validation report:

c2patool approved-source.jpg --info
c2patool downloaded-public-file.jpg --info

Use the same tool version and trust configuration when comparing environments. Keep the reports with the asset record; do not reduce them to a screenshot or an unexplained pass/fail field.

Record what the verifier actually found

“Verified” is too vague for an operational status. Your workflow should distinguish among at least these outcomes:

  • a manifest is present and validates;
  • a manifest validates, but the signer is not trusted under the selected trust policy;
  • a manifest is present but validation reports a problem;
  • no supported credential or watermark signal was detected.

The final state means “unknown”, not “human-made”. Metadata may be stripped during editing, conversion or sharing, while watermarks can be degraded. Coverage also varies by product, model, file type and export route. Conversely, detecting a provenance signal does not confirm the image’s accuracy, ownership or editorial suitability.

Make agency handoffs part of the system

Provenance frequently breaks between organisations rather than inside a single application. A brand, creative agency and web supplier can each follow their own process correctly while losing the relationship between the approved source and the published rendition.

A practical delivery register should name the controlled source, approved derivatives, expected credentials, verification result and permitted next transformations. The creative asset ID should map to the CMS entry and public placements. This makes later correction or withdrawal much faster, even when the credential itself has not survived.

Where supported, cloud or external manifest storage can improve resilience. Adobe’s Photoshop guidance, for example, distinguishes between attaching credentials to a file and publishing them to its Content Credentials cloud. That option should still be tested through your own workflow; it is not a reason to skip delivery checks.

Decide what happens when evidence disappears

A failed check needs an agreed response. For a routine marketing image, the team might retain the controlled original, document the failed transformation and publish a visibly labelled derivative. For a sensitive campaign, regulated communication or disputed image, the right response may be to change the export path, create a properly signed rendition or pause publication for review.

Start with 10–20 representative assets rather than the entire library. Include the main generation tools, agencies, export presets, CMS routes and delivery formats. That exercise normally reveals where evidence is lost and whether the remedy belongs in creative practice, supplier requirements or web infrastructure.

Turn the audit into a repeatable control

Once the weak points are known, verification can become part of release checks and supplier acceptance. Automation can flag missing manifests, validation problems or unexpected file changes, while a person handles ambiguous and higher-risk cases. The objective is not to make sweeping claims about authenticity. It is to preserve evidence and make uncertainty visible.

If your image workflow crosses several tools, suppliers or publishing systems, Greg can map the route, test representative files and turn the findings into controls your team can actually operate. Get in touch to discuss a focused provenance audit.

Related on GrN.dk

Need help with this kind of work?

Discuss your image provenance workflow Get in touch with Greg.

Sources

Latest articles

When an OpenAI request stalls, customers need an accurate status. Set sensible retry limits, preserve submissions, and make unresolved work visible.

I learned server operations by breaking my own servers. I want someone who stands next to me while I do it, then does it themselves the week after.

I am good at building and bad at calling. Here is who I want next to me, what is easiest to sell, and how we split it.

An AI assistant can prepare a refund, but a person should approve the exact payment and amount. Here is how to make that approval hold up through execution and retries.

AI can pull together onboarding tasks before a new hire’s first day. See how the manager approves specific access and how outstanding tasks are followed through.

An internal AI assistant can cite an obsolete handbook with confidence. Here is how to manage document ownership, updates, deletions, access and answer review.

Cloudflare Free provides useful website protection, but its rate limiting and bot controls have limits. Here is how to assess them for a WordPress site.

An AI assistant can answer questions and guide customers to a booking. Here are practical boundaries for prices, delivery times, personal data, and contact with a staff member.

Google and Bing now offer first-party AI search visibility reports. Here’s how to build a useful baseline without inventing a misleading GEO score.

AI crawlers can copy a familiar name. Here’s how to verify signed agents at the edge while keeping legitimate automated traffic moving.