Content authenticity: Trust requires provenance
It’s Tuesday. Kurt, the company’s content owner, creates an image with AI for a new campaign. He uploads it to the DAM, adds the metadata, and approves it. Eddy needs the image for the website and crops it to 16:9. Sandra resizes it for the online store. For the campaign, Kurt also converts it to WebP. From there, the image makes its way into the newsletter, onto a partner platform, and across social media.
Six months later, Gabi finds the image in the DAM. She sees an approved campaign asset. But can she simply use it? Does she still know where it originally came from?
With AI-generated content, that question suddenly matters. Did Kurt simply write a prompt? Did he upload an existing photo and use AI to modify it? Did Sandra later use Photoshop to add something to the image? We’re not going to dive into copyright law here.
We’re interested in a different question: Six months from now, can we still trace how an asset was created?
That’s what content authenticity is all about.
Content authenticity, not an AI ban
Generative AI makes content creation more accessible. An HR employee needs an illustration for an internal campaign? She can visualize an idea with AI without hiring an agency first. Marketing needs the same campaign for Switzerland, Germany, and France? AI can support the creation of text variations, image adaptations, and localized content. A designer needs more space on the right side of a photo because that’s where a button needs to go? She can extend the background with generative AI. AI speeds up content processes and gives more people the tools to turn ideas into content. So the question isn’t whether we should use AI.
The question is: How do we create trust in content when more and more people and systems can modify it?
For that, we need a chain of trust. An asset shouldn’t lose its provenance every time it goes through another processing step. If Kurt creates an AI-generated image, Eddy crops it, and Sandra later adjusts the colors, we should still be able to trace that history. Technical standards for this already exist.
C2PA: Where did this image come from?
One of the most important standards is C2PA, short for Coalition for Content Provenance and Authenticity. C2PA makes it possible to cryptographically bind information about the provenance and editing history of digital content to the asset. This technology forms the basis for what are known as Content Credentials.
For example:
- Kurt creates an image using an AI tool.
- The asset receives information about how it was created.
- Sandra later opens the image in an editing application and extends the background.
- Eddy then creates a crop for Instagram.
Ideally, we can later trace the sequence:
AI-generated source image → background extended → Instagram crop created
C2PA doesn’t say: “This image is true.”
Instead, the standard helps answer a different question: “What do we know about where this image came from and how it was modified?”
That’s an important distinction.
A chain of trust has to survive editing
Enterprise content is constantly being modified. A 6000 × 4000-pixel product photo is stored in the DAM.
- Eddy creates a square social media crop.
- Sandra needs the same image at 1200 pixels wide for the online store.
- Kurt converts it to WebP for a campaign.
- A partner downloads the image and uses it to create a banner.
Each of these steps may create a new variant.
C2PA can represent these relationships through what are known as ingredients. A new asset can reference a previous asset while documenting additional editing steps. Instead of a single provenance marker, this creates a traceable chain: Original → Edit → Derivative → Delivery
That’s what we mean by a chain of trust.
So what role does the DAM play?
Now let’s get back to Kurt and Gabi.
- Kurt uploads his new AI-generated image to the DAM. There, he might assign the status: AI-generated.
- Sandra uses generative AI to modify an existing product photo. That asset receives: AI-modified.
- Another image may only be used on the Swiss website: Usage restricted.
- And a fourth image has already been reviewed by Marketing: Approved.
The DAM collects all of this information in one central place. AI status becomes a standard part of asset governance, just like approval status, usage rights, copyright, or expiration dates.
Six months later, Gabi doesn’t have to ask Kurt. She can look at the asset and see what she needs to know. C2PA and Content Credentials can complement this governance with technically verifiable provenance information.
Machines need information. People need context.
But that alone doesn’t solve the trust problem. A system can read a C2PA manifest. A person looking at an image on a website usually doesn’t. Or, put another way: Our ID cards contain a lot of information. We still don’t wear them on our foreheads.
That’s why we need both: machine-readable information and clear, understandable information for people.
For example:
- The DAM says: AI-generated
- A delivery system reads that value.
- On the website—where appropriate or required for that use case—a visible label appears, such as “AI-generated image.”
- At the same time, technical provenance information can be preserved or added to the asset.
Machines can understand the asset’s status, while people get the context they need to assess the content and trust the brand behind it.
The EU AI Act brings transparency into the process
Since August 2, 2026, the transparency obligations under Article 50 of the EU AI Act apply. The AI Act distinguishes between different types of content, roles, and use cases. Certain AI-generated or manipulated content is subject to machine-readable marking requirements. In specific scenarios, additional disclosure obligations apply. Companies therefore need to translate these requirements into concrete rules.
Let’s go back to Kurt. He uploads an AI-generated image to the DAM and marks it as AI-generated. From that point on, Kurt shouldn’t have to reconsider the same questions every time the asset is used: Do I need to label this here? Which label should I use? Do I need to add metadata? What applies to the online store? What about the website?
The process should handle those decisions.
DAMlivery: From asset status to delivery rule (to content control)
That’s exactly why we’ve expanded DAMlivery with AI Labeling.
Kurt uploads an AI-generated campaign image and sets its status to AI-generated. DAMlivery reads that status and applies the predefined rules—for example, format, cropping, and labeling.
- Eddy embeds the DAMlivery link on the website. DAMlivery generates the WebP derivative and adds the defined label.
- Sandra needs the same asset at a smaller resolution for the online store. DAMlivery generates that version according to the same governance rules.
- A partner needs the image in another format. The same predefined logic applies again.
Kurt labels the asset once in the DAM. The process handles the rest. And because DAMlivery connects to different DAM systems via APIs, this logic isn’t tied to a specific DAM vendor.
That’s where the real shift in perspective begins: not with the visible AI label, but with the process inside the DAM.
The organization already manages rights, approvals, copyright, usage restrictions, and other asset information there. AI status simply adds another piece of information to the existing content process.
The DAM can now define: “This asset is approved, AI-generated, and may be used on the website and in the online store.”
DAMlivery then translates that information into concrete delivery rules.
No one needs to maintain an Excel spreadsheet. No one needs to keep a work instruction next to their screen. And six months later, Gabi doesn’t have to figure out who created the image in the first place. The information travels with the asset.