AI DetectiveArticle 50(2) and C2PA overview →

Practical guide · workflow evidence

What to record in a C2PA workflow test

A C2PA test is only useful if you can later show which file took which route. Here is a short technical record that makes that possible.

A C2PA record can show that a particular file carried a signed provenance record. But a useful technical check needs a second thing: a clear note of which file travelled through which route, and when you checked it.

This is not legal advice. Whether Article 50(2) applies to a particular service is for legal advice. This guide is about making a technical test repeatable and understandable later.

Keep the two files apart

Save the source file exactly as it left the generation or marking step. Then save the delivered copy: the one a real user downloaded, received by email, or got after your CDN, CMS or export step.

Why this mattersA positive result on the source file proves something about that source file. It does not automatically prove that a later WebP, JPEG, video export or platform copy still has the record.

Write down the route, not just the result

For each test, record the date, file type, source filename, delivered filename and the steps between them. “Generated in our app → image CDN → customer download” is far more useful than “C2PA checked OK”. Include the relevant settings or version if a conversion service, CMS or API was involved.

Keep the verification result with the files

Run both files through a C2PA-aware file check and keep the result alongside the copies. AI Detective’s free file check is a practical first screen for supported images, video, audio and PDFs up to 8 MB. It verifies what is in the file; it does not decide retrospectively whether ordinary unmarked content was made by AI.

Repeat after a meaningful change

Repeat the same route after changing image optimisation, export code, storage, a CDN, a CMS plugin or the signing setup. That keeps a one-off test from becoming an outdated assumption. Our OpenAI workflow guide explains why an original marked image is not enough, and the social-media guide covers common platform changes.

A small record is enough to start

  1. Test date and person responsible.
  2. Source and delivered copies, with file types.
  3. The exact route and relevant configuration.
  4. Verification result for each copy.
  5. The next retest date or trigger.

The honest target is a file marked at source and a delivery path you can demonstrate, not a promise that the record survives everywhere.

Start with two real files

Compare one source file with the copy your user actually receives. Then keep the result with the route notes.

Check a file freeAsk about a workflow check