Wrivio
Get Wrivio
6 min readBy Wrivio Team

Content Credentials Are Coming for Text: What Provenance Marking Means for Writing

The transparency obligations in Article 50 of the EU AI Act took effect on 2 August 2026, and one of them requires that AI-generated or AI-manipulated content carry machine-readable provenance signals. The standard most often named as satisfying that is C2PA, published by the Coalition for Content Provenance and Authenticity.

C2PA started as an image and video standard. Its 2.3 specification, released in late 2025, extended it toward unstructured text among other things. Camera manufacturers sign at capture, major platforms have labelled content at scale, and a large software vendor began adding credentials to office content in early 2026.

So the reasonable question, from someone who just used a tool to fix the tone of an email: does my message now need a watermark?

Almost certainly not, and the reasoning is worth having because it will come up.

What The Obligation Actually Targets

Article 50’s marking requirement is aimed at synthetic content: material generated or substantially manipulated by AI where a person encountering it could be misled about its origin. Deepfakes are the paradigm case. Images, audio, and video are where the harm and the standard both mature first.

An email you drafted, had a tool rewrite for register, read, edited, and sent under your own name is not synthetic content in that sense. You are the author, you approved every word, and nobody is misled about who is communicating with them. The narrower reading is set out in AI disclosure obligations in 2026.

Where it does bite for text-adjacent work: chatbots that people interact with directly, and content published as if produced by a person when it was machine-generated end to end without meaningful human involvement.

The line is roughly authorship. If a human decided what to say, took responsibility for it, and can defend every sentence, the AI was a tool. If a system produced and published it without that, the disclosure question is live.

What Content Credentials Do And Do Not Prove

Worth understanding properly, because the technology is regularly oversold.

What it does. A credential is a cryptographically signed manifest attached to a file, recording what was done to it and by which software. It is tamper-evident: alter the content and the signature no longer validates.

What it does not do. It does not prove the content is accurate, fair, lawfully owned, or being shown in context. A valid credential on a false statement is a valid credential on a false statement.

The critical asymmetry. A missing credential is not evidence of AI generation. Credentials get stripped by ordinary operations: copying text out of a document, pasting into a message, screenshotting, or any tool that does not preserve the metadata. For text in particular, which moves between applications by copy and paste constantly, stripping is the normal case rather than the exception.

That last point is what limits provenance marking for text specifically. An image travels as a file. A paragraph travels as characters in a clipboard, and characters do not carry manifests.

Why This Will Not Become An Email Requirement

Three practical reasons, in addition to the legal reading above.

The transport does not support it. Email, chat, and document body text are copy-and-paste surfaces. Any marking scheme survives only as long as nobody copies the text, which is not a workable assumption.

The signal would be useless. If every message that touched a spelling checker, a grammar tool, or a rewrite carried a marker, the marker would appear on essentially all professional correspondence and would tell a reader nothing.

It answers the wrong question. What a recipient cares about is whether the sender stands behind the content, not which software touched it. A message you approved is your message regardless of how you got the wording.

This is also the reason detection tools do not resolve the question. They are unreliable in both directions, and what they measure is not what anyone actually wants to know, as covered in AI detectors at work: what they actually prove.

Where This Does Matter To You

Three cases, all narrow and all real.

Published marketing content generated end to end. If a machine wrote it and it goes out under a brand with no meaningful human authorship, both the legal question and the professional norm point toward disclosure.

Customer-facing chatbots. If people can mistake it for a person, Article 50 requires telling them. This is the clearest deployer-side obligation for ordinary businesses.

Images and media you generate. This is where marking is mature, where tooling exists, and where the obligation is least ambiguous.

For everything else, the norm question is separate from the legal one, and worth deciding deliberately. Should you disclose you used AI to write an email works through it.

Writing The Position Down

If someone asks what your policy is, the useful answer distinguishes assistance from generation.

Before:

We’re monitoring AI transparency requirements and will implement content credentials where required by law.

After:

Correspondence and documents authored by our staff, where AI was used for editing or rewriting, are not marked. The author is the author and takes responsibility for the content.

Published content generated end to end by AI is labelled as such.

Our customer-facing chat assistant identifies itself as automated at the start of every conversation.

The second version tells someone what you actually do, in three lines they can check. The first defers a decision and gives a client nothing.

A Wrivio Context for policy statements could say:

Rewrite this as a clear external policy statement. Neutral register, complete sentences. Each line must state what we actually do, not what we intend to do. Keep every standard name, regulation name, and date exactly as written. Do not add commitments, certifications, or future intentions that are not in the original.

Press Ctrl+Shift+Space, paste the draft, and check the diff. The specific risk here is a rewrite converting a description into a commitment, which is how a policy statement becomes a promise you did not mean to make.

Common Questions

Do I need to add a content credential to an email I rewrote with AI?

No. Article 50’s marking obligation targets synthetic content that could mislead about its origin, not text you authored, reviewed, and sent under your own name.

Does missing provenance metadata mean content is AI-generated?

No. Credentials are routinely stripped by copying, pasting, and screenshotting, so absence proves nothing. Only a valid credential carries information.

Does C2PA prove content is true?

No. It is tamper-evident provenance about what was done to a file and by which software. Accuracy, ownership, and context are outside what it can attest.

Where does provenance marking actually matter today?

Images, audio, and video, where the standard is mature and the misleading-origin risk is highest, plus chatbots that must identify themselves as automated.

Download Wrivio for Windows to keep authorship where it belongs, with a word-level diff so you can see and approve every change before it goes out.