Evergreen
How Creators Can Build an Authenticity Record
Preserve originals, context, edits, AI use, rights, publication history, and corrections in one practical authenticity record for every important asset.
How Creators Can Build an Authenticity Record
A creator builds an authenticity record by preserving the original asset, assigning it a stable identifier, recording capture or generation context, documenting meaningful edits and AI assistance, retaining rights and consent evidence, and linking the exact published version to its corrections.
Content Credentials can strengthen that record when supported. They do not replace the underlying files, private documentation, backups, or editorial judgment.
The goal is not to publish every detail. It is to retain enough evidence that a later reviewer can understand where an asset came from, how it changed, and which public statements remain accurate.
Begin before capture or generation
Decide what evidence the project may need before the camera rolls or the prompt is submitted. A personal illustration and a documentary interview carry different risks. A brand campaign involving a real person's likeness needs different consent and disclosure records from an abstract generated background.
Create a project identifier and a location for source files. Record the responsible person, date, intended use, rights status, and any privacy or safety restrictions. If location data or a source identity could endanger someone, preserve it only in a protected record and publish a safer summary.
This separation between private evidence and public disclosure is essential. Authenticity should not become an excuse to expose a confidential source, home address, device serial number, or sensitive creation location.
Preserve the source as a source
Keep the original file in the form produced by the device or system. Do not overwrite it with a retouched export. Store later versions separately and connect them through the project identifier.
The NDSA Levels of Digital Preservation organize preservation around storage, fixity and data integrity, information security, metadata, and file formats. A solo creator does not need an institutional repository to apply the principle. Important files should exist in more than one controlled location, and their integrity should be checkable.
A cryptographic checksum is useful because it identifies a particular byte sequence. If the checksum changes, the file changed. The checksum does not tell you whether the picture is honest, but it can show whether the preserved source is the same file you recorded earlier.
flowchart LR
A["Original asset"] --> B["Stable ID and checksum"]
B --> C["Protected source storage"]
B --> D["Working copy"]
D --> E["Edit and AI-use record"]
E --> F["Published export"]
F --> G["URL, date, and public disclosure"]
G --> H["Correction and replacement history"]
Record how the asset was made
The useful detail depends on the medium. A photograph may need capture date, device or camera, operator, location at an appropriate precision, subject consent, and the event being documented. Audio may need participants, recording environment, microphone or platform, and whether noise removal or voice synthesis was used. Generated media may need the provider, model name, model version if available, prompt, reference inputs, seed or settings when exposed, generation time, and subsequent edits.
Do not describe an AI-assisted asset as simply "made with AI" if the distinction matters. A fully generated spokesperson, a camera photograph with object removal, an image whose background was extended, and a manually written article whose grammar was reviewed by a model represent different processes.
The IPTC Photo Metadata Standard 2025.1 includes fields for AI prompt information, prompt writer, AI system, and system version. It also maintains digital source type vocabulary. Those fields can improve interoperability in photographic workflows, but ordinary metadata can still be edited or stripped.
Keep an edit history that a human can understand
A useful edit record names the source version, output version, tool, operator, time, and material action. "Color correction and crop" is more informative than "edited." "Generated replacement sky using Tool X, then manually masked the horizon" is more informative than a generic AI label.
The record should distinguish changes that affect presentation from changes that affect the depicted facts. Exposure correction, noise reduction, and resizing may preserve the scene's meaning. Removing a person, changing a sign, replacing speech, or moving an object may change what the audience believes happened.
Where the tool supports Content Credentials, preserve the signed provenance and inspect it before publication. Confirm that the displayed record matches the workflow you intended to disclose. A valid credential is helpful only if the viewer can interpret the relevant assertion.
Connect rights and consent to the asset
Keep releases, licenses, commissioned-work terms, source permissions, attribution obligations, and likeness consent with the project record. Record restrictions as well as permission. A person may agree to appear in one campaign without agreeing to a synthetic double, perpetual voice clone, or unrelated endorsement.
This guide cannot define the required consent for every jurisdiction or use. The practical rule is to make the authorization retrievable and specific enough that a reviewer can tell what was allowed. High-risk or commercial uses involving identity should receive jurisdiction-specific legal review.
Publish a clear, limited disclosure
The public needs the information that changes how the work will be understood. The private record can remain more detailed.
For a realistic generated scene, disclose that it was generated and that the depicted event did not occur. For a cloned voice, identify whose voice was used and whether that person authorized it. For a materially altered documentary image, describe the change close to the image. A disclosure buried in a general site policy may not correct the impression created by the asset itself.
Platform controls matter in addition to the caption. YouTube requires disclosure when content is meaningfully altered or synthetically generated and appears realistic, including a realistic scene that did not occur or a real person made to say something they did not say. The platform distinguishes those cases from minor aesthetic edits and production assistance.
Preserve the publication and correction trail
Record the exact export checksum, file name, publication URL, publication time, caption, disclosure, and platform setting. If the asset appears in several places, record each version because platforms may transform files or display different labels.
When something changes, do not silently erase the history. Record the reason, replacement asset, correction text, time, and affected locations. Preserve the earlier version privately unless policy or law requires deletion.
That history lets a reviewer answer a question months later: which version did the audience see at that time?
A compact asset record
| Record area | Minimum useful entry | Keep private when needed |
|---|---|---|
| Identity | Project ID, asset ID, owner | Internal system path |
| Source | Original file, checksum, capture or generation time | Exact location, device identifiers |
| Creation | Device or model, operator, material inputs | Confidential prompt, source identity |
| Rights | License, release, consent scope, expiration | Contracts and personal details |
| Changes | Version, tool, operator, material edit | Security-sensitive workflow detail |
| Provenance | Credential file or manifest, signer, validation result | Unpublished source ingredients |
| Publication | Export checksum, URL, date, caption, disclosure | Account access detail |
| Correction | Previous version, reason, replacement, date | Protected legal review |
The table is a starting record, not a universal compliance checklist. The correct depth follows the asset's stakes.
Test the record before you need it
Choose one published asset and try to reconstruct its history without relying on memory. Open the source. Verify its checksum. Find the consent or license. Follow each meaningful edit. Inspect any credential. Match the final export to the public URL and disclosure.
If the chain breaks, fix the workflow at that point. The most common failure is not sophisticated forgery. It is a missing original, an overwritten export, a vague file name, a lost release, or a disclosure that cannot be matched to the published version.
An authenticity record does not guarantee that everyone will trust the work. It gives a responsible creator evidence worth evaluating.
[[What Are Content Credentials]] explains the signed-provenance layer. [[Watermarks Metadata Content Credentials and AI Detectors Compared]] helps choose the right technical signal.
This guide was developed from C2PA, NDSA, IPTC, YouTube, and NIST materials plus the preserved E093 transcript. It is operational guidance, not legal advice. AI assistance was used for research organization, drafting, and validation. Publication remains unauthorized.
Sources
Follow the evidence.
- support.google.com: 14328491support.google.com
- iptc.org: iptc standardiptc.org
- c2pa.org: faqsc2pa.org
- FTC Disclosures 101ftc.gov
- eur-lex.europa.eu: ojeur-lex.europa.eu
- c2pa.org: conformancec2pa.org
- github.com: Z Imagegithub.com
- ftc.gov: consumer reviews testimonials rule questions answersftc.gov
- FTC: Endorsements, Influencers, and Reviewsftc.gov
- deepmind.google: synthiddeepmind.google
- iptc.org: IPTC PhotoMetadata 2025.1iptc.org
- nist.gov: reducing risks posed synthetic content overview technical approaches digital contentnist.gov
- openaccess.thecvf.com: Li Bridging the Gap Between Ideal and Real world Evaluation Benchmarking AI Generated ICCV 2025 paperopenaccess.thecvf.com
- asa.org.uk: testimonials and endorsementsasa.org.uk
- deepmind.google: prodeepmind.google
- arxiv.org: 2507arxiv.org
- spec.c2pa.org: C2PA Specificationspec.c2pa.org
- ndsa.org: levels of digital preservationndsa.org
- deepmind.google: identifying ai generated images with synthiddeepmind.google