Search the Atlas

Search risks, controls, and glossary terms

AgenticSocietal & Sustainability Governance

Generated-Content Provenance & Authenticity Labelling

Control objective

Generated-Content Provenance & Authenticity Labelling checks that content produced by the AI system carries durable provenance information and is clearly disclosed as AI-generated. This matters because customers, staff, and regulators must be able to tell machine-generated documents, summaries, or messages from human-authored ones, and provenance protects against tampering, misattribution, and downstream misuse of synthetic content. There is no numeric metric or formula supplied; the control is verified by coverage and disclosure. To implement it, attach provenance or watermark metadata (for example following C2PA-style content credentials) to outputs at generation time, propagate it through storage and delivery so it is not stripped, and surface a clear AI-generation disclosure to recipients; log generation events with the provenance identifier as evidence. The threshold is that 100% of generated content carries provenance/watermarking and that AI generation is disclosed. Any gap — content emitted without provenance or without disclosure — constitutes a breach and should trigger remediation such as fixing the generation pipeline to re-apply labels, blocking unlabelled outputs, and verifying that provenance survives downstream processing before release.

Implementation notes

C2PA-style content credentials on generated output; provenance verification on ingested content; disclosure of AI generation.

Risks mitigated

2