Automate Digital Content Provenance & Compliance.
Create. Sign. Verify. Preserve. Prove.
Authentrail scans your digital assets, verifies existing provenance, adds cryptographically verifiable C2PA credentials where appropriate, and preserves audit-ready evidence across jurisdictions.
Private beta: 25 files per batch, 50 MB per file. No credit card.
Unmarked AI content is now a regulatory liability.
As of August 2026, providers of generative AI systems must ensure outputs carry machine-readable marking, while deployers have their own disclosure duties for deepfakes and certain AI-generated text on matters of public interest. Non-compliance with the transparency obligations can draw administrative fines of up to €15 million or 3% of total worldwide annual turnover.
The operational problem is bigger than any one statute: campaign libraries mix client-supplied, AI-generated and edited assets, and when a client, regulator or procurement team asks where a given asset came from, manual checks across thousands of files can't answer. Provenance you can prove — and evidence you can produce years later — is what closes that gap.
Bring your own certificate
Upload your CA-issued X.509 certificate — manifests are signed in YOUR name, and your organization is the attesting party.
Human-origin attestations
For what no scanner can prove: named, signed declarations recorded in the audit trail.
Multi-region verdicts
EU, UAE, and US rules evaluated simultaneously on every asset — one scan, all exposure.
Honest detection
We document exactly what is detectable — and what isn't. No claims a stripped file can't support.
From non-compliant to fully audited in three steps.
- STEP 01
Batch Ingestion & Scanning
Upload your campaign assets or scan published URLs. Authentrail parses images, PDFs, and videos for existing C2PA signatures, XMP/IPTC declarations, and generator fingerprints (DALL-E, Midjourney, Firefly, Stable Diffusion).
- STEP 02
Cryptographic Remediation (The 1-Click Fix)
Stop sending assets back to the design team. Authentrail automatically injects missing machine-readable C2PA manifests into flagged files, signing them with a trusted PKI certificate.
- STEP 03
Legal-Grade Audit Trails
Download a timestamped, branded PDF receipt covering your entire batch. Hand the report to your clients, risk officers, or regulatory bodies to demonstrate compliance.
Batch #4821 — Q3 Campaign
4 assets scanned · 2 require a C2PA manifest
| File | AI-Generated | Status | Regions |
|---|---|---|---|
| q3-launch-hero-01.jpg | Yes | Non-compliant | EUUAEUS |
| banner-set-mj-04.png | Yes | Non-compliant | EUUS |
| product-shot-dslr.jpg | No | Recommended | EU |
| social-carousel-02.jpg | Yes | Remediated | EUUAEUS |
Don't take our word for it — verify it yourself.
Both artifacts below come straight out of the product. Inspect them with tools we don't control.
Sample signed asset
Drag the file into Adobe's public Content Credentials verifier — the C2PA manifest, AI disclosure, and timestamp are all inspectable.
You'll see an "issuer couldn't be recognized" notice: this sample is signed with our demo certificate, which isn't on the C2PA trust list. The signature itself is valid and tamper-evident. In production your assets are signed with your organization's CA-issued certificate — which is exactly what the notice is checking for.
Sample audit report (PDF)
The exact deliverable: per-asset legal basis, per-region verdicts, human-origin attestations, KDP declaration guidance.
Built by Nexus Technology.
Scan an image right now. No account.
Drop any PNG, JPG, or WebP below. It runs the same detection stack the product uses — C2PA manifest parsing, XMP and generator fingerprints, per-region verdicts. The file is read in memory and discarded; nothing is stored.
Drop an image here
PNG, JPG, or WebP · up to 10 MB · 10 scans per hour
Results appear here: whether a C2PA manifest is present and its signature verifies, which detector flagged AI generation, and what each jurisdiction requires as a result.
No image handy? Download the sample signed asset above and drop it in.
Built for the global compliance patchwork.
Laws change; the underlying question doesn't: can you prove where your content came from and what happened to it? Authentrail evaluates assets against applicable requirements — it does not claim every asset is legally required to carry a signature.
EU AI Act — Article 50
Evaluate AI-generated content against applicable transparency requirements, remediate missing machine-readable provenance where appropriate, and preserve evidence of your provenance controls.
State AI Transparency & Provenance Laws
Stay ahead of the evolving state landscape — California's AI Transparency Act (SB 942, operative August 2026) and Utah's Digital Content Provenance Standards Act (effective January 2027).
AI Governance & Digital Content Integrity
Establish verifiable provenance and audit trails supporting UAE AI governance, cybersecurity and enterprise requirements — including the National Cyber Security Policy for AI and government content-integrity initiatives.
Saudi Arabia — AI Governance & Content Integrity
Support provenance, transparency and auditability within Saudi Arabia's evolving AI governance environment.
All four rule sets are evaluated on every scan — EU and US as compliance verdicts, UAE and Saudi Arabia as governance and procurement-readiness advisories. Assets arrive by upload or published-URL scan — S3/R2 and DAM integrations are on the roadmap.
Who relies on Authentrail?
Marketing & Advertising Agencies
Audit massive campaign libraries before handing work to corporate clients. Establish provenance across client-supplied, AI-generated and transformed assets.
Your clients may ask where their AI content came from — months or years later. Authentrail makes sure you can answer, with a chain of custody from intake to delivery and evidence that survives staff turnover and tool changes.
Telecom & Messaging Platforms
Make provenance a publication gate for RCS, messaging and digital advertising — detect missing or invalid provenance before content reaches your network.
Media Publishers
Verify the provenance of content before publication and preserve an auditable record of what was published.
Enterprise Risk Teams
Establish a final provenance and compliance gate for outgoing corporate communications.
Government & GovTech
Provide verifiable provenance and audit evidence for AI-assisted media and digital communications.
Article 50 transparency obligations apply since 2 August 2026.
Simple pricing, built around batches.
Free
€0
Evaluate the full workflow on real assets.
- 100 assets scanned / month
- Top-up packs: €29 per extra 250 assets, one-time
- 25 files per batch · 50 MB per file
- 1 seat
- C2PA scan, inject & attest
- EU · US · UAE · KSA verdicts
- Audit PDFs in 5 languages
- Demo signing certificate
- 30-day file retention
Agency
Most popular€299/mo
For teams shipping client campaigns every week.
- 2,500 assets scanned / month
- 200 files per batch · 500 MB per file
- 5 seats
- BYOC signing — your own X.509 certificate
- Full API access
- Named attestations (dashboard + API)
- 90-day file retention
- Compliance Evidence Archive add-on (€99/mo)
- Annual: €2,990/yr (~17% off)
- Priority email support
Enterprise
Custom
For risk teams, GovTech and multi-brand groups.
- Compliance Evidence Archive included (7 years)
- Custom volumes, batch sizes & seats
- Multiple signing identities per group
- HSM / KMS-backed signing (roadmap)
- SSO / SAML via identity provider
- Custom retention & data residency
- DPA & security review support
- Dedicated support with SLA
Upgrades are live. Workspaces created during the private beta keep their free-tier access — upgrade only when you need BYOC signing, API access, or higher volumes.
EU data residency
Processed and stored on EU infrastructure (Finland).
30-day retention
Uploads and remediated files auto-purge; your audit trail persists.
Keys encrypted at rest
BYOC private keys are AES-256-GCM encrypted; hardware-backed signing is on the roadmap.
Frequently asked questions
EU AI Act Article 50, C2PA Content Credentials, and AI provenance — answered.
What does EU AI Act Article 50 require for AI-generated content?
Article 50 of the EU AI Act (Regulation 2024/1689) creates distinct duties: providers of generative AI systems must ensure AI-generated or manipulated content is marked in a machine-readable format, while deployers have disclosure obligations for deepfakes and certain AI-generated text on matters of public interest. It does not require every digital asset to carry a signature. C2PA Content Credentials are a practical mechanism for the machine-readable marking, per the European Commission's July 2026 guidelines. The obligations apply since August 2, 2026.
What are the penalties for publishing unmarked AI content in the EU?
Non-compliance with the AI Act's transparency obligations can draw administrative fines of up to €15 million or 3% of total worldwide annual turnover, whichever is higher. Deployers — including marketing agencies publishing on behalf of clients — carry their own obligations, separate from the model provider's.
What is a C2PA manifest (Content Credentials)?
C2PA is the open technical standard from the Coalition for Content Provenance and Authenticity, backed by Adobe, Microsoft, Google, and the BBC among others. A C2PA manifest is a cryptographically signed block of metadata embedded in a file that records how the content was created — including whether AI was involved — using the IPTC digitalSourceType vocabulary. Anyone can verify a signed asset independently at verify.contentauthenticity.org.
How do I add C2PA metadata to AI-generated images in bulk?
Upload a batch to Authentrail (up to 25 files per scan via the dashboard, or stream via the API). Assets flagged as AI-generated without valid provenance can be remediated in one click: Authentrail injects a signed, RFC 3161-timestamped C2PA manifest declaring the content AI-generated, and returns the signed files ready to publish.
Does the EU AI Act apply to companies outside the European Union?
Yes. Like the GDPR, the AI Act applies based on where the output is used, not where the publisher sits. An agency in Dubai or New York that publishes AI-generated campaign content reaching EU audiences falls under Article 50. Authentrail evaluates every asset against EU, UAE, and US rules simultaneously so multinational teams see all exposure at once.
Can Authentrail detect AI images that have no watermark or metadata?
Authentrail detects C2PA manifests, XMP digitalSourceType declarations, and generator fingerprints left by tools like DALL-E, Midjourney, Adobe Firefly, Stable Diffusion, and ComfyUI. No scanner can prove a fully stripped image is human-made — which is exactly why the workflow includes named human-origin attestations: a signed declaration by your team member, recorded in the audit trail, for assets whose provenance is technically unknowable.
How do I comply with Article 50 for AI-generated text?
Raw text cannot carry cryptographic metadata — copy-paste strips everything. Article 50(4) instead requires a disclosure for published AI-generated text on matters of public interest. Authentrail's text disclosure log records the disclosure with a SHA-256 content hash, the responsible person's name, and a timestamp, and includes it in your audit report.
Which US states require AI content disclosure?
California's SB 942 (AI Transparency Act) requires provenance disclosures for generative AI content, and Utah has enacted digital content provenance standards; other states have bills in progress. Authentrail tracks the state patchwork and evaluates assets against California SB 942 as the strictest current baseline.
Why does Adobe's verifier say the Content Credential issuer couldn't be recognized?
That notice means the signing certificate isn't on the C2PA known certificate list — it says nothing about whether the signature is valid or the file tampered with. Verifiers show it for any issuer outside the trust list, including our demo certificate. The fix is signing with a CA-issued certificate from a C2PA-participating authority (such as DigiCert) — which is what Authentrail's bring-your-own-certificate setup is for, and why the recognized issuer shown to the world is your organization, not us.
Can we sign C2PA manifests with our own certificate?
Yes — bring your own certificate (BYOC) is the recommended setup. Your organization uploads its own CA-issued ES256 X.509 certificate, so manifests are signed in your name and your organization is the attesting party. Keys are encrypted at rest, and hardware-backed signing via your own KMS or HSM is on the roadmap.
Do PDFs support C2PA Content Credentials?
The C2PA reference implementation does not yet support embedding manifests in PDF. Authentrail instead writes the machine-readable disclosure into the PDF's XMP metadata using the same IPTC digitalSourceType vocabulary — satisfying Article 50's machine-readable requirement and readable by Adobe tooling.
Does an Authentrail audit report help with Amazon KDP AI declarations?
Yes. Amazon KDP requires publishers to declare AI-generated content when submitting books. Authentrail's audit report includes a KDP declaration guidance section that maps your batch's scan results — AI-generated images, disclosed AI text — directly onto the KDP questionnaire's answers.
Why not just use Adobe Content Credentials or open-source C2PA tools?
Those tools can create provenance. Authentrail governs what happens across the entire asset lifecycle — including assets created elsewhere, missing provenance, multiple jurisdictions, remediation, publication decisions and long-term evidence. The AI Act is one regulatory driver; the underlying problem is proving where digital content came from and what happened to it, across large, messy, multi-client workflows.
How is an audit trail useful if a platform strips my metadata?
Social platforms and CDNs routinely strip embedded metadata on upload. The timestamped audit report proves your assets were compliant at the moment of delivery — which is the obligation you can actually control. Authentrail also lets you re-scan published URLs to check whether provenance survived the pipeline.
Stop guessing. Start verifying.
Run a batch through Authentrail and see exactly where your library stands — free during the private beta.
Enterprise needs? .