An editor spent several days working with a contributor who was not who they claimed to be.
In 2023, The Irish Times published an opinion column after the contributor exchanged edits with the desk, offered personal anecdotes and supplied research links. Less than 24 hours later, the article was removed.
The editor later said the text and byline photo may have been produced, at least partly, with generative AI.
This happened years before the EU AI Act’s transparency rules took effect, but it exposes a problem that matters even more now.
Human review can be real while the origin of what is being reviewed remains uncertain.
Under the EU AI Act, human review and editorial responsibility matter for AI-generated text published on matters of public interest. But saying “an editor reviewed it” does not, by itself, preserve what they reviewed, what changed, or which version they ultimately accepted.
A stronger record connects the submitted version, meaningful edits, responsible editor, approval time and final published copy.
Numbers can keep those events tied to the same asset history, so the review remains inspectable after publication.
Editorial review tells us someone took responsibility.
Provenance tells us exactly what they took responsibility for.
https://t.co/Nyn707VlVC
The EU AI Act is introducing clearer transparency expectations for AI-generated and manipulated content.
But the ultimate goal is not simply to prove that a label was added.
It is to make sure the evidence still exists when someone needs to verify the claim.
https://t.co/Ii1IoUBgqg
A customer sends support one image and asks:
"Was this generated by your system?"
A policy page saying "our outputs are marked" cannot answer that question for this file.
Article 50 asks providers to make generated outputs detectable. Customer support still needs to connect that obligation to the output the customer actually received.
Support needs a record tied to the output itself:
which product and model produced it
which exact file was delivered
what signal should have been present
which tool checked it
what result came back
why the check was unsupported or inconclusive, if it was
That is the difference between a company-wide promise and a file-level answer.
Numbers Verify Engine can inspect supported C2PA paths. Numbers ID and Asset Profile can keep that result connected to the output and its handoff.
A detected mark is still only one signal. It does not prove truth, ownership, or compliance. And a missing mark does not prove the work was human-made.
Run the supported verification path here:
https://t.co/rh6PI67YBE
Start with the file.
Your platform rarely reviews the file a creator originally made.
It reviews the copy created during upload.
That copy may have been resized, compressed, transcoded, or stripped of metadata before it reaches moderation. It can look identical to the original while being a different file underneath.
This changes the question. It is no longer only:
"Did the original have a mark?"
It is:
"What evidence applied to the copy we actually accepted, rejected, or sent for review?"
The EU AI Act requires machine-readable marking on the provider side. But one thing most people missed, the receiving platform still needs to explain its own decision on the transformed copy.
https://t.co/Nyn707VlVC
Keep the original asset, uploaded copy, transformation, check result, and final decision connected. If the signal could not be checked, record that too.
Numbers ID can identify the relevant copies. Asset Profile can connect the transformation, supported verification result, and decision.
The mark can help at intake.
The receipt is what lets the platform explain its decision later.
If the risk is before publication, verify:
1. contributor identity
2. sources checked
3. reviewed version
4. responsible editor
If the risk is after distribution, verify:
1. delivered file ID
2. edit or validation result
3. recipient chain
4. withdrawal state
5. replacement state
The Irish Times hoax broke the first path. The 2024 Princess of Wales photo kill broke the second.
Numbers does not prove identity or truth. It keeps the review record and distribution trail inspectable after handoff.
An editor spent several days working with a contributor who was not who they claimed to be.
In 2023, The Irish Times published an opinion column after the contributor exchanged edits with the desk, offered personal anecdotes and supplied research links. Less than 24 hours later, the article was removed.
The editor later said the text and byline photo may have been produced, at least partly, with generative AI.
This happened years before the EU AI Act’s transparency rules took effect, but it exposes a problem that matters even more now.
Human review can be real while the origin of what is being reviewed remains uncertain.
Under the EU AI Act, human review and editorial responsibility matter for AI-generated text published on matters of public interest. But saying “an editor reviewed it” does not, by itself, preserve what they reviewed, what changed, or which version they ultimately accepted.
A stronger record connects the submitted version, meaningful edits, responsible editor, approval time and final published copy.
Numbers can keep those events tied to the same asset history, so the review remains inspectable after publication.
Editorial review tells us someone took responsibility.
Provenance tells us exactly what they took responsibility for.
https://t.co/Nyn707VlVC
A photo kill is not one delete button.
If an edited image is withdrawn after distribution, the proof object is not the image. It is the withdrawal trail.
Use these four fields before you trust the cleanup:
1. delivered asset ID
2. recipient or channel
3. kill notice or validation result
4. replacement asset ID, if one exists
If one field is missing, you cannot show which desk kept the old file, which system honored the kill, or whether the replacement inherited the wrong context.
AP's 2024 Princess of Wales incident is the simple example. The hard part was not saying do not publish. The hard part was carrying that state across feeds, desks, and later copies.
Numbers can keep the asset reference, the state change, and the later replacement linked as evidence without redistributing the withdrawn image.
https://t.co/Nyn707VlVC
One family photo triggered a global photo kill.
In March 2024, Kensington Palace released a Mother's Day image of Catherine, Princess of Wales. AP, Reuters, AFP and Getty withdrew it after finding signs of manipulation that breached newsroom standards. AP did not say the scene was fake. The delivered file could not clear its verification bar.
A provenance workflow should preserve three objects: source capture, edited export and distribution decision.
Numbers Verify Engine can inspect supported C2PA Content Credentials on the file a newsroom actually receives. Numbers ID and Asset Profile can connect that result to earlier versions. Capture SDK can record the validation and any later kill notice.
This does not judge whether an edit is acceptable.
It gives editors the version history needed to make that judgment.
https://t.co/Nyn707VlVC
Saying that something has been reviewed is weaker than showing them a review record.
This week we traced contributor origin, editorial accountability, and version history after the photo kill.
Read:
https://t.co/eq3NZeqfY8
One family photo triggered a global photo kill.
In March 2024, Kensington Palace released a Mother's Day image of Catherine, Princess of Wales. AP, Reuters, AFP and Getty withdrew it after finding signs of manipulation that breached newsroom standards. AP did not say the scene was fake. The delivered file could not clear its verification bar.
A provenance workflow should preserve three objects: source capture, edited export and distribution decision.
Numbers Verify Engine can inspect supported C2PA Content Credentials on the file a newsroom actually receives. Numbers ID and Asset Profile can connect that result to earlier versions. Capture SDK can record the validation and any later kill notice.
This does not judge whether an edit is acceptable.
It gives editors the version history needed to make that judgment.
https://t.co/Nyn707VlVC
There’s an interesting second-order effect here: watermark removers may actually raise the compliance bar.
EU AI Act asks for marking to be robust and reliable relative to the state of the art. If removing one signal becomes trivial, relying on that signal alone becomes harder to defend.
So this may turn into an arms race between marking and removal. Which is exactly why provenance probably cannot live in a single watermark. It needs multiple layers and a verification trail that still exists after someone attacks the file.
The 74% adoption figure is interesting, but the 17% saying AI actually improved their designs might be even more important.
As AI becomes part of architectural practice, “AI was used” won’t tell us much. The useful record is where it entered the process, what it changed, and what was ultimately reviewed and approved by the architect.
That provenance may matter far more than a label on the final render.
One part of this that’s easy to underestimate is what happens after generation.
A model can mark an output correctly, then one export, crop, CMS upload or platform conversion removes the signal.
So in practice, AI compliance becomes a handoff problem too. The evidence needs to remain verifiable after the content leaves the model that created it.
“Origin” has several layers.
So knowing a dataset existed in a verifiable state is useful. But for AI governance, teams may also need to show where the data came from, who created it, what rights or consent travelled with it, and what happened to it afterwards.
That’s why provenance is necessary as thechain of evidence.
The interesting part is procurement may end up stricter than the law itself.
The AI Act doesn’t literally require a consent receipt for every training record. But once a buyer asks “where did this come from, what rights came with it, and can you prove it?”, a dataset without that trail becomes much harder to defend.
Provenance stops being metadata at that point. It becomes part of the commercial value of the dataset.
The uncomfortable part of the Irish Times case is that humans were involved.
There were several days of exchanges, edits, anecdotes and research links. And it still turned out to be a deliberate deception.
That distinction matters under the EU AI Act.
“Human reviewed” cannot just mean someone touched the document. The Commission’s guidance talks about reviewing the substance, fact-checking the information and assessing whether the sources can be trusted.
So the useful record is not simply:
Reviewed: yes.
It is: which version was reviewed, what claims and sources were checked, what materially changed, who approved it, and who took responsibility for publishing it.
Numbers can keep that review history connected to the content itself.
A checkbox says it was reviewed.
A record shows what “reviewed” actually meant.
An editor spent several days working with a contributor who was not who they claimed to be.
In 2023, The Irish Times published an opinion column after the contributor exchanged edits with the desk, offered personal anecdotes and supplied research links. Less than 24 hours later, the article was removed.
The editor later said the text and byline photo may have been produced, at least partly, with generative AI.
This happened years before the EU AI Act’s transparency rules took effect, but it exposes a problem that matters even more now.
Human review can be real while the origin of what is being reviewed remains uncertain.
Under the EU AI Act, human review and editorial responsibility matter for AI-generated text published on matters of public interest. But saying “an editor reviewed it” does not, by itself, preserve what they reviewed, what changed, or which version they ultimately accepted.
A stronger record connects the submitted version, meaningful edits, responsible editor, approval time and final published copy.
Numbers can keep those events tied to the same asset history, so the review remains inspectable after publication.
Editorial review tells us someone took responsibility.
Provenance tells us exactly what they took responsibility for.
https://t.co/Nyn707VlVC
A fake byline photo passed beside a fake contributor.
ProofSnap cannot prove a person's legal identity. However, it can produce a C2PA Content Credential at capture, register a Numbers ID and preserve an origin record for the file. That gives a newsroom evidence that a contributor photo came through a declared capture workflow instead of arriving as an unexplained upload.
ProofSnap Android and ProofSnap iOS are listed as conformant Generator Products in the C2PA Conformance Program. Numbers Protocol can connect that credential to the asset history, while Capture SDK can place the same step inside a contributor intake flow. Numbers has also used provenance records with Starling Lab in archival work.
Source verification remains the newsroom's job.
At least the file stops pretending it has no past.
Numbers Verify Engine is now listed by C2PA as a conformant Validator Product.
That sounds technical because it is.
A content team receives a Claude-generated PNG from an agency. Anthropic says supported Claude files can carry watermarks and C2PA provenance metadata for its EU AI Act marking workflow.
Then the file gets resized, converted, or stripped of metadata before review.
The useful check is not whether Claude marked the original.
It is whether the C2PA record in the delivered file is present and valid.
C2PA makes provenance portable.
Numbers Verify Engine makes it testable.
The review receipt should keep the delivered file, validation result, timestamp, and file hash together. A missing or broken record is still a result.
Just not the fun one.
Run the check:
https://t.co/wL7o0SCQoQ
A photographer delivers campaign images to a team that also uses AI-generated assets.
The AI images may carry labels or machine-readable markers. The photographer's images may carry no equivalent signal at all.
Then both go through the same workflow: cropping, compression, renaming, CMS uploads, and reposting.
At that point, an image with no AI label does not necessarily prove human origin. It only tells you that the copy in front of you has no detectable AI disclosure.
This is the other side of AI transparency.
As the EU AI Act puts more emphasis on identifying synthetic content, creators and publishers also have a reason to preserve evidence for content that genuinely came from the physical world.
For an important image, that can mean keeping its creator identity, the original capture record, the source reference, significant edits, and the final approved version connected to one verification path.
Capture Cam or ProofSnap can create that origin record at the moment of capture, before the image enters a library where human and synthetic content start to look increasingly similar.
AI disclosure helps tell us what was generated.
Provenance helps us verify what was actually captured.
https://t.co/Nyn707VlVC
A brand approves an AI-generated spokesperson video.
The agency adds a deepfake disclosure and the creator publishes the approved version.
Then someone screen-records it and reposts the clip without the label.
For many people, that repost may be the only version they ever see.
This is where the EU AI Act's transparency rules meet a very practical problem: content does not stay where it was first published.
A label can explain the original post. Provenance can preserve where the clip came from, which version was approved, and what changed as it moved across platforms.
If all of that disappears after one repost, the transparency stopped too early.
https://t.co/Nyn707VlVC
C2PA lists Numbers Verify Engine as a conformant Validator Product. Test the delivered file, keep validation receipts, and carry proof through handoffs.
Read:
https://t.co/ShSgvyBvLq
Which handoff would you verify first?
That's why the useful record should not live only inside the file.
Keep track of which version was approved, whether the AI mark was still detectable, who made the disclosure decision, what transformations happened, and which copy was actually published.
Numbers can connect those events to a persistent NID, so the public asset still has a path back to its provenance even after the file changes.
It doesn't guarantee compliance. It makes the history easier to inspect.
https://t.co/Nyn707VlVC
The image your audience sees can look exactly like the one your team approved, while technically being a different file.
An AI tool generates it. The client approves it. The publisher uploads it, the platform compresses it, and the image still looks the same.
But the machine-readable provenance may not have survived.
That's where EU AI Act transparency gets tricky in practice.
A client hires an agency to create a campaign.
The client provides the brief. The agency decides to use AI to produce part of the work. The final images are approved and handed back to the client for publishing.
Under the EU AI Act, that handoff matters.
The client and the agency may not have the same responsibilities. What matters is who used the AI system, who made the decisions around the content, and how the final asset is published.
That means simply sending over the final image is not always enough.
A few months later, the client may need to know which AI system was used, which version was approved, whether the content needed a disclosure, who made that decision, and what exactly was handed over.
If none of that travels with the asset, the team is left searching through old emails, Slack messages, folders and approval threads.
A better workflow keeps the final asset connected to its production record from the beginning.
For example: which AI system was used, which version became final, who approved it, what transparency decision was made, and where the record can still be checked later.
Numbers Protocol can support that record. Capture SDK can register the asset when it enters the workflow, while NID gives it a persistent reference even after the file leaves the agency’s own systems.
The goal is not to add more paperwork to agency work.
It is to make sure the context does not disappear when the file moves from the agency to the client.
https://t.co/Nyn707VlVC
The EU AI Act can require AI-generated content to carry machine-readable information, while certain content also needs a clear disclosure to the public.
Those are different layers, and they can disappear at different points.
A CMS might strip metadata. A repost might lose the visible label. A screenshot can lose both.
Knowing the original was compliant does not tell you what happened to the copy people actually saw.