AI image provenance is usually argued after the file has already escaped.
C2PA and c2patool move that argument earlier. The standard is for signed Content Credentials on media, and the CLI can read, add, and inspect manifests on image, audio, and video files. TrustMark sits nearby: open watermarking code for images, with examples for encoding, decoding, removal, and tying watermark presence into a C2PA manifest.
I read this as an operator-owned provenance rail, not a magic trust badge. The tradeoff is more certificates, manifests, and media-pipeline plumbing. The upside is that AI output does not have to leave your stack as a naked file with no signed history.
https://c2pa.org/
https://opensource.contentauthenticity.org/docs/c2patool/
https://opensource.contentauthenticity.org/docs/trustmark/
If you generate images or video with local models, are you signing provenance at creation time, watermarking, doing both, or waiting until platforms force it?
#SovereignAI #LocalAI

