C2PA Content Credentials · AI Act Art. 50 · one asset and what was made from it
The media-provenance desk.
A photograph, a frame, a cut: each file is fingerprinted on this device, its Content Credentials found and read where it carries them, and how it came to be declared by you — captured, made, or made with a model. Each stage is sealed with a time bracket and the parent it came from, so the chain from capture to the published asset holds when a platform has stripped every manifest. From 2 August 2026 Art. 50 of the AI Act asks that generated content be marked and a deepfake disclosed; the lines open where your declaration says a model was involved. Files never leave this browser.
1 · Who you are
The role says which Art. 50 duty is yours: a provider marks (50(2)); a deployer discloses a deepfake (50(4)); a newsroom is a deployer when it publishes generated content.
2 · The asset at this stage
Drop the file here, or choose it. JPEG, PNG, WebP, MP4/MOV/HEIC, PDF — anything; the fingerprint is the SHA-256 of the bytes.
3 · What holds, what is open, what contradicts
4 · The chain on this desk, and the credential page
Every sealed stage, newest first. Publishing takes the chain that ends in the selected parent (or the newest seal) and opens a page any link or code can reach: the stages, the fingerprints, the declarations, the manifests' readings — every stamp checked in the viewer's browser, no file.
This desk reads a C2PA manifest; it does not validate one — the signature, the trust list and the hash binding are a C2PA validator's to check, and the page says "found and read", never "valid". The declaration is yours; the seal fixes that it was made at that time. Not legal advice.