What C2PA actually means for a production

At some point in the next year, someone in a legal or compliance role is going to ask a production a question it cannot currently answer: where did this image come from?

Not in a philosophical sense. In an evidentiary one. Which model produced it, what it was trained on, what rights attach to the output, and whether any of that can be demonstrated rather than asserted.

Most productions using generative tools today would fail that question. Not because anyone did anything wrong, but because nobody kept a record, and by the time the question arrives the record cannot be reconstructed.

What C2PA is

C2PA — Content Credentials — is an open standard for attaching tamper-evident provenance metadata to a piece of media. It records what was used to make an asset and what happened to it afterwards, cryptographically signed so that alteration is detectable.

It is not DRM. It does not stop anyone doing anything. It is a record, and the value of a record is that it exists when someone asks.

Why this became urgent

Three things converged.

  1. Broadcasters and platforms started asking. Disclosure requirements for synthetic media are arriving in commissioning paperwork, and the direction of travel is one way.

  2. Regulation started arriving. Provenance and disclosure obligations feature in AI legislation across several jurisdictions, including in draft form here in South Africa.

  3. Insurers and E&O started noticing. This is the one that will move the industry fastest. When errors and omissions cover starts asking about generative content, productions will comply within a quarter.

What it means in practice

The important thing about provenance is that it cannot be added later. A credential attached in post is a claim about the past. A credential attached at generation is a record.

‍So the practical question for a production is not should we do C2PA but at what point in our pipeline does provenance start. If the answer is anywhere after the asset was made, the answer is not good enough.

That means it belongs at capture and at generation, not at delivery.

The trade nobody makes explicitly

Here is the part that is usually discovered too late.

Generative models vary enormously in what their licences permit, what regions they can be deployed in, and what rights attach to outputs. Some restrictions extend to the generated material itself, not just the software. A model that produces beautiful work may come with terms that make it unusable for a production intending to distribute internationally.

Most productions find this out after the shots are made.

The right time to make that decision is before, and it should be a producer decision rather than an artist one: how strict does the IP position need to be, and what quality are we willing to trade for it. Made deliberately, that is a sensible commercial judgement. Made by accident, it is a problem discovered in delivery.

What we do about it

We built provenance into our pipeline rather than beside it. Content Credentials are applied at generation, carried through the work, and recorded in an auditable ledger, so a production can demonstrate the history of a frame rather than vouch for it.

We also let a producer set the IP posture up front, and we evaluate vendor licence terms as part of assessing whether a model is usable at all — because in our experience the licence is more often the disqualifying factor than the output quality.

None of this is glamorous. It is the difference between a pipeline that survives a rights audit and one that does not.

If your production is using generative tools and nobody has asked these questions yet, get in touch. It is a much cheaper conversation now than later.

Previous
Previous

Introducing The Living Story

Next
Next

VES comes to Cape Town