Urgent.News

What's breaking now, across thousands of outlets.

Finance & Markets

Probably Provenance? You Can’t Just Slap a Sticker on It

C2PA treats provenance like a sticker. This essay argues AI agents need locally held, tamper-evident logs that anyone can verify.

Probably Provenance? You Can’t Just Slap a Sticker on It

Provenance, or a verifiable record of an object's origin and history, is transitioning from a philosophical concept to practical infrastructure in our media landscape. The Content Credentials (C2PA) initiative, a collaboration of over 6,000 organizations, aims to create a signed record of a piece of content's origin and edit history.

C2PA presents content with a cryptographic chain of custody, a cryptographic hash of the asset embedded in the file's metadata. However, two structural choices in C2PA's design fall short for the challenges of the future. Firstly, the record is a "sticker" that can be detached from the file when it's re-encoded, cropped, or pushed through a platform's upload pipeline.

Secondly, trust is rooted in a central authority, a curated list of certificate authorities and time-stamping authorities. This centralized trust point is a single point of failure, as seen in the Certificate Transparency initiative. As autonomous systems become more prevalent, the need for provenance becomes even more critical.

Regulations like the EU AI Act require high-risk AI systems to automatically record events throughout their lifecycle. Building provenance the C2PA way, with a sticker attached to the artifact and trust in a central authority, inadvertently creates vulnerabilities that could undermine its purpose.

Written by urgent.news from HackerNoon's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Read the original at hackernoon.com →

More in Finance & Markets

More from Monday 3 August →