The idea of watermarking AI-generated content is older than the current generative AI boom. What is new is the combination of technical maturity, cross-industry alignment, and regulatory pressure that has emerged in the past twelve months. For the first time, the specifications, the tooling, and the political will are pointing in the same direction.
What the standards actually do
Modern provenance standards do two things. First, they embed a cryptographically signed manifest describing how a piece of content was created — the model, the prompt author, the edit history, the platform. Second, they specify perceptual watermarks that survive common transformations: cropping, recompression, screenshot capture, minor edits. Neither piece is perfect, but together they raise the cost of laundering AI-generated content past the level where casual bad actors can do it.
The specifications have converged more than public discourse suggests. C2PA is the dominant framework for manifest-based provenance, with support from the major AI labs, browsers, and camera manufacturers. Perceptual watermarking is more fragmented, but a small number of methods have become interoperable enough to matter.
What they do not do
No watermark is robust to a determined adversary. Anyone motivated to strip provenance metadata can, and anyone with basic image or audio processing tools can degrade perceptual watermarks. The point of the standards is not to prevent misuse; it is to create a positive signal that platforms and courts can act on when it is present. That is a lower bar, and it is achievable.
- Manifest-based provenance is nearly solved technically; adoption is the bottleneck.
- Perceptual watermarks survive normal use but not motivated attack.
- The value is in the presence of a positive signal, not the absence of a bypass.
“A watermark that survives casual sharing is enough. A watermark that survives a motivated adversary is impossible. Policy should be designed for the former.”
The adoption gap
The specifications work. The problem is that most content on the internet still passes through platforms and pipelines that strip provenance metadata by default. Social platforms strip EXIF and manifest data as an anti-abuse measure. Messaging apps recompress images. Screenshots break everything. Closing this gap requires platform commitments, not just standards.
Regulators are starting to notice. Recent draft rules in the EU and several US states require large platforms to preserve provenance metadata rather than strip it. Whether the requirements survive the legislative process is uncertain, but the direction of travel is clear.
What to do now
For AI product teams, the pragmatic move is to ship C2PA manifests on generated content and treat it as part of the product rather than an afterthought. For platforms, the move is to stop stripping manifests. For enterprises deploying generative AI internally, embedding provenance on outputs is inexpensive insurance against downstream disputes.
Key Topics
Extended Knowledge
- C2PA is the dominant manifest-based provenance framework.
- Perceptual watermarks are complementary to manifests, not a replacement.
- Platform preservation of provenance metadata is the largest adoption gap.
Frequently Asked
Determined adversaries can remove them. Casual users generally cannot, which is the useful threshold.
It is the closest thing to a consensus standard for manifest-based provenance.
In some jurisdictions, increasingly yes for specific applications. Broad mandatory watermarking is still a work in progress.



