AI DetectiveArticle 50(2) and C2PA overview →

Practical guide · C2PA provenance

Can C2PA be added after the fact?

A record added later can truthfully describe the later signing step. It is not a time machine: it cannot prove how an older file was originally created.

Sometimes a team finds a library of older AI images, videos or audio files and asks: “Can we add C2PA now?” A C2PA record can be added as part of a later workflow, but that later record is not the same as provenance captured when the content was made.

This is technical information, not legal advice. A lawyer can assess whether a particular legal obligation applies to a particular service.

What a later record can say honestly

A signing step can record that a named organisation handled or issued a particular file at a later date. That can be useful operationally. It may also record a known edit or export. But the file was already in existence before that step, so the new record cannot independently establish which AI system, prompt or process created the original file.

Simple ruleMark content in the workflow where it is created or first issued. A record attached later describes the later action — not an unobserved earlier creation.

Why this matters for AI content

AI detectors cannot reliably reconstruct a file’s origin after the event. A JPEG may have been copied, resized, stripped of metadata or exported through several tools. Even a confident-looking detector result is not signed provenance. That is why the robust place to add machine-readable marking is the generation or controlled delivery workflow, before the file starts moving between people and systems.

Older files are still worth mapping

Do not quietly treat an archive as if it had always been marked. Instead, separate it from new output:

  1. Identify the source system and date range where you can do so from reliable records.
  2. Keep any original exports and existing provenance records unchanged.
  3. Describe a later C2PA action as a later action, with its date and scope.
  4. Put the signing point into the workflow for every new file going forward.
  5. Test the delivered copy, not only the source file.

This gives a clear boundary: what is known about older material, and what is technically evidenced from the new workflow onward.

Test the route people actually use

Even when the record is placed at the right point, an image optimiser, CMS, CDN, download endpoint or social platform can create a version without it. Keep one source file and compare it with the file a user receives. Our workflow-test record guide lists the useful evidence to keep.

One practical next step

Choose one current generation route and one real download or publishing route. Check both endpoints separately. If the source is marked and the delivered copy is not, the issue is a technical hand-off to fix — not something a visible watermark can solve.

Start with the next file, not a guess about the last one

We can check a source file and the delivered copy separately, then show where a record is present and where the workflow loses it.

Check a file freeinfo@aidetective.eu