← AI Detective
EXAMPLE — this is an illustrative sample audit of a fictional client (Example Studio Ltd), to show what a real audit contains. The technical results below are genuine: produced with AI Detective's working C2PA tools, not made up.

Content-provenance audit · Step 1

Does your AI imagery carry a mark that reaches the user?

A review of an AI image studio's workflow in light of EU AI Act Article 50(2).

Example client
AI image studio
Date
10 Sep 2026
By
AI Detective · Vahitalu OÜ
Volume
~2000 files/month
Summary

The studio is a provider of generative AI — the Article 50(2) marking duty falls on it directly, deadline 2 December 2026. Key finding: even where a mark is added, it does not reach the user — the delivery pipeline (resizing, social media) strips it. We proved this below with a real file: a marked file lost its mark after one ordinary resize.

01 Example client profile

A typical target client: a studio that produces AI images at volume and delivers them onward into clients' channels.

Tools
DALL·E 3, FLUX, Midjourney
Output
Product images, campaign visuals, video
Channels
Clients' websites, Meta, marketplaces
Also
Text captions, descriptions

02 Findings

Four representative files run through the AI Detective pipeline. Every C2PA result is genuine tool output.

File / stageSizeC2PA markSource typeState
original output
(unmarked)
476 KBnoneunprovable
AI image
marked
604 KBpresenttrainedAlgorithmicMediaValid
same image after
CDN / social media
139 KBSTRIPPEDunprovable
real photo
certified
604 KBpresentdigitalCaptureValid

03 Key finding: the mark doesn't survive delivery

The same file, three stages. The middle step — an ordinary 1080 px resize and re-compression, exactly what every CDN and social platform does — erased the mark completely. Real tool output.

1 · Marked

604 KB
C2PA PRESENT
trainedAlgorithmicMedia
Valid

2 · CDN resizes

1080 px, recompressed
ordinary step
every platform does it

3 · Reaches the user

139 KB
C2PA STRIPPED
no JUMBF data
unprovable

This is why the question is not "whether to mark" but "where in the workflow to mark, and how to keep it so it reaches the user". That is the work we do.

04 Further findings in the studio's workflow

05 Two honest caveats

Chain of trust

The "Valid" in the example means the signature is internally correct — full public trust needs the C2PA conformance programme (step 3). Without it the mark is technically right, but a validator may not recognise it.

The mark doesn't live everywhere

As proven, re-compression strips the mark. The proof always stays in the source file, which the studio keeps — that is your defence in a dispute. Some platforms (LinkedIn, TikTok) preserve it; Meta reads it and shows an "AI info" label.

06 Recommendation

1

Audit

This document: workflow, obligation and gaps assessed.

✓ done in the example
2

Marking built into the workflow

Automatic marking in the studio's output, consistent across every tool, so each new file comes out marked — and provable even after delivery.

ready to start
3

Trusted certificate + monitoring

C2PA conformance programme and monthly verification/renewal, so the mark is publicly recognised and never expires.

pending