C2PA, Metadata, Watermarks: How Machine-Readable AI Labelling Really Works
The EU Code of Conduct refers to machine-readable labelling. What lies behind C2PA, IPTC DigitalSourceType, and watermarks — and why visible labels alone are not enough.
When people talk about AI labelling, most think of a visible label on the image. That is only half the story. The other half takes place where no visitor looks: inside the file itself. Machine-readable labelling is the aspect targeted by auditors, platforms, and the EU Code of Conduct — and it is refreshingly concrete.
C2PA: Proof of Origin Within the File
The Coalition for Content Provenance and Authenticity (C2PA) — backed by Adobe, Microsoft, Google, Sony, and others — has established a standard that cryptographically signs and records a file’s provenance: Which tool created the content? Was it edited? Who issued the signature? Tools such as Adobe Firefly already write this evidence automatically. The crucial point: the signature can be verified, but not forged without detection. A C2PA record is therefore the strongest form of labelling — proof, not mere assertion.
IPTC DigitalSourceType: The Industry’s Vocabulary
Much simpler, but widely used: the IPTC field DigitalSourceType describes in the metadata how an image was created. The value trainedAlgorithmicMedia means: generated by a trained AI. digitalCapture means: genuine camera shot. This is precisely the vocabulary referenced by the EU Code of Conduct — it is the lowest common denominator for machine-readable labelling.
Watermarks: Invisible Yet Detectable
A third approach: invisible watermarks such as Google’s SynthID, which are embedded directly into the image pixels and are designed to withstand compression or cropping. Their strength is robustness; their weakness is exclusivity — so far, they can mainly be read by the provider themselves.
Why Visible Labels Alone Are Not Enough
- Anyone can remove a visible label — a signed proof of origin cannot be tampered with unnoticed.
- Platforms and search engines read metadata, not image corners.
- Evidential value comes from verifiability: in case of doubt, what is in the file counts.
The Flip Side for Operators
The same standards that enable labelling also make missing labelling visible: an image with a C2PA signature from an AI tool, published without disclosure, documents the gap at the same time. An inventory of your own content reads precisely these traces — and reveals where action is needed.
Free audit
What is actually on your website?
Enter your domain, wait less than a minute — you will see which content shows traces of AI generation. No registration required.
Read more
Art. 50 EU AI Act: Who Must Label AI Content — and What This Means in Practice
The practical guide to labelling obligations: affected content, the operator’s role, and the most common misconceptions.
How to Detect AI-Generated Content — and Why No Single Detector Is Sufficient
Why metadata provides the strongest evidence, classifiers can be misleading — and why, ultimately, a human should make the final decision.
EU AI Act: The 10-Point Checklist for Your Website
From inventory to monitoring: the ten questions every website operator should now be able to answer.
Labelling AI Images: What Is Mandatory, What Is Sensible — and How to Do It Properly
The honest answer to the most common question — and three design rules to ensure your labelling doesn’t look like a warning sign.
Deepfakes on Your Own Website: Why the Operator Is Liable — Not the Creator
The law’s most powerful lever does not target AI providers, but you — and deepfakes arise more quickly than most people realise.
Stock Photos and AI: Why Almost Every Website Contains Unlabelled AI Content
You have never knowingly used AI? Your website probably has — in ways no one expects.