A provenance record is not a truth machine

Knowing where something came from doesn’t tell you if it’s true

March 7, 2026
provenance media knowledge

A photograph can be genuine and misleading at the same time. It can show a real moment and leave out what happened right before it. And a synthetic image can be clearly labeled and useful, like an architectural render. Where something came from matters, but it doesn’t tell you what it means.

This is getting more important as convincing media gets easier to produce. We need better records of where things came from, and we shouldn’t ask those records questions they can’t answer.

The C2PA Content Credentials specification is clear about this. Its explainer says it deals with the provenance of content and the integrity of the claims attached to it, and that it makes no judgment about whether the content is good, bad or true.

It sounds like a technical detail until you picture someone seeing a reassuring badge next to an image. What do they think was verified? That a specific signer made a statement? That the record wasn’t altered? That the scene happened as described? Those are separate claims, and the badge covers only some of them.

Citations have the same problem, and it’s much older. A footnote shows you the way to the evidence. It doesn’t promise that the author understood the source or that the source supports the sentence. A long bibliography can hide weak reasoning if nobody clicks the links.

For creative work, provenance is useful in other ways too. It can show who collaborated, keep the connection between a design and its sources, and help another person continue the work. If I got a generated design with a record of its inputs, transformations, human decisions and material tests, the record wouldn’t prove the design is good. But when it fails, I’d know much faster which decision to go back to.

There are good reasons not to demand full exposure. A source may need privacy, an artist may want to stay anonymous, and many tools don’t keep a complete history. Missing credentials aren’t proof of deception, and a system that treats them that way would punish a lot of legitimate work.

What I’d want from an interface is simple: tell me what’s known, who is asserting it and where the record ends.

I try to hold my own writing to the same standard, and it’s harder than it sounds. The link should lead to the evidence for the claim I’m making. When I add my own interpretation, I should say so, and when the evidence is limited, the citation shouldn’t hide it.