Measured finding · Apache-2.0 · signed run of 13 August 2026 · C2PA manifest survival

The marking that proves content is AI-generated does not survive one ordinary save.

EU AI Act Article 50 requires generated content to be marked machine-readably — effective, interoperable, robust and reliable. It applies from 2 August 2026, with penalties up to €15M or 3% of worldwide turnover. The regime assumes the marking persists. We measured whether it does.

Across 12 marked assets and 9 measured transforms (signed run, 13 August 2026)

0 of 12 assets survived

(0 of 12 marked assets kept an intact embedded C2PA manifest (0 of 108 measured cells); clustered 95% interval 0 to 24.25%, computed at n=12 assets; one-sided 95% Clopper–Pearson upper bound 22.1%)

A marking is scored SURVIVED only when its binding still validates against the asset it is attached to. A marking present but whose binding no longer validates is scored DESTROYED, not SURVIVES. The identity control passes; an ordinary re-encode, resize, crop or format change does not.

click to launch eu

Measurement Lens

Measurement Lens

Frozen corpus · live axis · deterministic

never auto-resolved

Every transform, and what happened

TransformWhat it isManifest
identity (control)no modificationsurvived
JPEG re-encode q90an ordinary re-savedestroyed
JPEG re-encode q70an ordinary re-savedestroyed
JPEG re-encode q50an ordinary re-savedestroyed
resize 50%downscaledestroyed
crop 10%5% off each edgedestroyed
strip metadataremove APPn/COM — pixels bit-identicaldestroyed
format → PNGcontainer changedestroyed
format → WebPcontainer changedestroyed
screenshot-equivalentsimulated capture: rasterise + rescale + PNGdestroyed
format → HEICno encoder available hereUNMEASURED

JPEG quality is irrelevant — q90, q70 and q50 identically destroy the binding, because the manifest is metadata, not pixels. Predicted before the run: had q90 survived where q50 did not, the harness would have been measuring pixel similarity and would have been wrong.

The limits, stated first

The interval is clustered, not per-cell. The independent unit is the asset, not the cell. Nine transforms of the same signed asset are not nine observations — they are one deterministic fact restated nine times. If a hard binding breaks at q90 it breaks at q50 for the identical reason. Survival is counted per cell (0 of 108) but the interval behind it is computed at the asset level: clustered 95% interval 0 to 24.25%, computed at n=12 assets; one-sided 95% Clopper–Pearson upper bound 22.1%.

The residual uncertainty is not sampling noise. A hard binding is a cryptographic hash over asset bytes, so re-running any cell reproduces the identical outcome with probability 1. The bound quantifies generalisation to unseen assets and transforms — external validity, nothing else.

One transform is modelled. Screenshot-equivalent simulates a screen capture rather than taking one. The modelling is conservative: a real screenshot discards the container entirely.

Our certificate is a private root, not on the C2PA trust list — so issuer_resolvable fails in every cell including the control. That is a property of our credential, not damage from a transform. Survival is about binding integrity, not trust-list membership.

Not tested: soft binding (watermarks) and cloud manifest recovery. Both exist precisely because embedded manifests do not survive. Named as missing rather than passed.

What this finding is not

It is not “C2PA is broken.” C2PA does exactly what it specifies.

It is not “Article 50 doesn’t work.” The Article says “as far as is technically feasible” — this measures what that phrase costs in practice.

It is not “provenance is useless.” A detached sidecar recovers the disclosure, which is what Article 50(2) asks for. It never recovers the binding.

We publish a measurement. Others draw conclusions.

The result that matters more

A manifest lifted from a completely different asset still reports signature_valid = survived. Only binding_intact catches the transplant — measured, not assumed.

So a verifier that reports “signature valid” without reporting the binding is telling you almost nothing. If you are buying a provenance product, that is the question to ask it.

Earlier runs, not the headline

Earlier unsigned 20-asset run, 29–30 July 2026. 20 marked assets, the same C2PA embedded and sidecar configurations, 180 measured cells: 0 of 20 assets survived (0 of 180 measured cells); one-sided 95% Clopper–Pearson upper bound 13.9%. Status: unsigned; its result file is not published on councilof.ai.

Earlier unsigned preprint run, 30 July 2026. 15 assets × 7 transforms = 105 cells, mixed binding types including a soft watermark: the preprint reports 18 of 105 cells surviving (17.14%). Status: unsigned; its per-cell data is not published on councilof.ai, so the figure cannot be re-derived here.

These are different experiments. Their figures are not the signed result and are never averaged with it. Until 15 September 2026 this page headlined the preprint figure and described it as the durability of a watermark; the signed run tested no watermark.

Reproduce it: python3 provbench.py --selftest then python3 provbench.py. Harness Apache-2.0; every survival figure on this page is recomputable from the signed provbench.json (verify offline: python3 sign.py --verify provbench.json).

ProvBench measured status

0 of 12
marked assets kept an intact embedded C2PA manifest (signed run, 13 August 2026)
measured
0 / 108
measured cells survived; the interval is computed at n=12 assets, not per cell
measured
signed
the result file is Ed25519-signed; verify offline with sign.py --verify provbench.json
measured

source: Signed ProvBench run, 13 August 2026 (/packs/eu-article-50/provbench.json)

FAQ

Frequently asked questions

Content provenance — what is measured, what is still open.

What is content provenance measurement?

Testing whether content carries verifiable origin information — signed manifests, C2PA-style credentials — and whether those markers survive real-world transformations such as re-encoding, cropping and re-upload.

What are the current measured results?

In the signed run of 13 August 2026, 0 of 12 marked assets kept an intact embedded C2PA manifest (0 of 108 measured cells; clustered 95% interval 0 to 24.25%, computed at n=12 assets). A marking present but whose binding no longer validates is scored DESTROYED, not SURVIVES — embedded C2PA bindings do not survive an ordinary re-save, and a detached sidecar recovers the disclosure but never the binding. No watermark was tested. The signed file is /packs/eu-article-50/provbench.json.

Does a provenance marker prove content is true?

No. Provenance shows where content came from and whether it was altered — not whether its claims are accurate. Our records measure the marker, not the truth of the content.

Why does provenance matter for the EU AI Act?

Article 50 requires AI-generated content to be labelled in a machine-readable way. Provenance measurement tells you whether your labelling actually survives contact with the real internet.