Web3

An AI-generated image is beginning to serve as an identification card: How California is rewriting its content source system.

The credibility of images is no longer solely determined by visual inspection. Generation tools, modification records, source documentation, and manual review are becoming the new essential documents that news organizations must retain.

By Kevin Guo
10 min

(Image caption) The Governor of California officially signed the California Artificial Intelligence Transparency Act into the state legislature, symbolizing that responsibility for origin has been formally incorporated into the legal obligations of generative AI products.


The source file beyond the screen

When an image circulates online, what's first seen used to be the picture itself: who's in it, where it happened, how clear it is, and whether it's enough to make readers stop and take a second look. News editors cared about its accuracy, designers cared about its aesthetics, and social media platforms cared about its ease of sharing. As for how it was generated, what tools were used, and whether it was cropped or modified, these questions remained in the background for a long time, often without being fully recorded.

With the advent of AI-generated images, this habit has begun to fall behind reality. An image that looks like a photograph may come from a real camera or may be entirely generated from text prompts; it may be a media illustration or a scene-based photograph. The human eye is increasingly unable to bear the responsibility of judgment alone, and the source of content needs to be written into the document itself, remaining in readable, verifiable, and accountable materials.

California incorporates source responsibility into AI products

Against this backdrop, California's *California AI Transparency Act* officially took effect on August 2, 2026. Originally named SB 942, the law, after being amended by AB 853, postponed its original implementation date of January 1, 2026, by seven months. Governor Newsom, upon signing the law, acknowledged that while the intent was good, implementation would be difficult, and requested the state legislature to supplement it with supporting legislation before it took effect.

The law primarily applies to providers of generative AI systems with over one million monthly active users, requiring them to provide free detection tools that allow users to determine whether images, videos, or audio were created or modified by their system and to output detectable source material. From January 1, 2027, the obligation will be further expanded to large online platforms, requiring them to detect whether their distributed content contains compliant source material.

This isn't a law that only applies to tech companies. It will impact journalism, the film industry, political advertising, public communication, educational materials, corporate reporting, and media copyright management. For media organizations that produce content daily using text, images, materials, and AI tools, it will change the way we understand the credibility of content.

(Image description) The free detection tool interface provided by the AI system allows users to instantly determine whether an image was created or modified by the system and to read verifiable source information.


The EU and California gave signals around the same time.

At this point in time, California isn't the only one taking action. Article 50 of the EU's Artificial Intelligence Act, which mandates transparency, will also apply from August 2, 2026, requiring generative AI systems to machine-readable tagging of synthesized audio, images, videos, and text, and to ensure that the content can be identified by detection tools.

The European Commission published the "Code of Practices on Transparency of AI-Generated Content" on June 10 this year, and released the final guidance on July 20. The two documents are different in nature: the former is a voluntary tool, while the latter is a formal interpretation of the scope of legal obligations; however, the disclosure obligation under Article 50 itself will not lose its enforceability simply because the code is voluntary.

California regulators mentioned in multiple explanatory documents that setting the effective date of August 2nd was precisely to align with the EU's schedule. The fact that regulators in both jurisdictions released their respective documents around the same time is more noteworthy than the individual laws themselves.

This serves as a clear reminder for the news industry: AI content needs source records, users need evidence to verify it, and media and platforms cannot treat transparency as a dispensable ethical option.

Why GFM must take this matter seriously

For GFM, this news carries far more weight than typical regulatory updates. GFM generates articles, images, and multilingual content daily. If this content is to enter a viable licensing market and become a valued and transferable asset, the traceability of its origin often determines whether a work can be traded even earlier than its price itself.

An AI-generated image, if it only contains the image itself and does not record the generation tool, generation time, whether it has been manually modified, what materials were referenced, or what version it was published in, has almost no ability to prove itself in the event of a copyright dispute or question of authenticity. It is also difficult for media organizations to use it to negotiate licensing cooperation.

California's legislation has shifted the responsibility for traceability from an internal editorial practice to a legal obligation at the product level. This serves as a reminder to all organizations that rely on AI-driven content production: the credibility of content can no longer depend solely on the statements made at the time of publication; it also requires a chain of evidence stored in the system.

(Image caption) C2PA content source and authenticity certificate are bound to the image in the form of encrypted signature, recording the generation tool, modification record and verification status, becoming the new draft of news images in the AI era.


C2PA provides tools, but cannot replace judgment.

The issue of sourcing in news photography didn't begin with AI. Photographer, time, location, caption, and copyright ownership have long supported the professional order of news photography and protected the rights of photographers and news agencies.

C2PA, or Content to Source and Authenticity Alliance, was initiated in 2021 by organizations such as Adobe, BBC, and Intel, attempting to extend this logic to the AI era. It uses encrypted signatures to bind the generation tool, modification history, and the content itself together, ensuring that an image or video retains a readable credential of its origin.

However, technical issues cannot be ignored. An independent security analysis of the C2PA 2.2 specification this year pointed out that the current specification still has vulnerabilities in areas such as credential revocation mechanisms and verification result consistency, and has not yet fully achieved its claimed security goals. Researchers suggest that regulators and users treat it as a technology still evolving, rather than a mature solution that can be relied upon alone.

This conclusion doesn't mean we should abandon tools like C2PA, but media organizations need to understand that encrypted signatures are not a foolproof solution.

Social media platforms may cause proof of origin to disappear.

The vulnerability of the source system also stems from the dissemination environment itself. A study of the X platform, within six days of the release of GPT-image-2, compiled 10,217 images that users self-identified as being generated by the model. The research team also found that the platform systematically stripped C2PA content credentials during the image upload process.

This means that the moment an image leaves the generation tool and enters a social media platform, the encrypted source record may have already disappeared.

This serves as a very real warning to news organizations. Model companies can provide credentials, and platforms can provide tags, but after images have been downloaded, compressed, screenshotted, forwarded, and re-uploaded, the original material is likely to be incomplete. If media outlets want to protect themselves, they cannot completely delegate the responsibility of verification to model companies or platforms. Maintaining their own content ledger is far more reliable.

(Image caption) A diagram illustrating the systematic stripping of C2PA content credentials during the uploading process on social media platforms, revealing the vulnerability of source materials that may disappear instantly in the dissemination chain.


Google Earth's Real-World Warning

An incident at the end of July provided a more intuitive example.

On July 30, Alphabet's Google launched an AI image generation feature based on the Nano Banana 2 model on the Google Earth web version, allowing users to generate historical reconstructions or urban planning scenarios using text prompts on real satellite, aerial, and 3D data. Less than a day after its launch, on July 31, Google announced the withdrawal of this feature, citing that some users had generated and shared screenshots of content that might violate policies, including sensitive scenes such as refugee camps and nuclear power plants tested by researchers.

In its statement, Google specifically noted that the generated images themselves are watermarked as AI-generated and will not appear in the main public view of Google Earth. The problem is that once screenshots circulate beyond the tool's control, the platform's internal security design becomes difficult to maintain.

Geographical imagery, news photos, disaster scenes, and public construction data—content carrying a special level of trust—cannot be verified solely by assessing the credibility of the images themselves once AI overlays them with fictional scenarios. Location, time, platform origin, and generation status must all be examined together.

This issue is also very relevant to GFM. In the future, any images accompanying images related to cities, energy facilities, ports, disasters, or public policy that are AI-generated or illustrative must be clearly labeled. They can have journalistic aesthetics and help readers understand institutional issues, but they cannot be used as genuine news photographs.

Reuters Connect shows another way

The media licensing infrastructure is also being adjusted accordingly. Reuters' Screenocean video archive was integrated into Reuters Connect on July 24 this year, which is positioned as a unified platform integrating text, images, videos and charts from Reuters and hundreds of partner media outlets.

This step, viewed alongside the transparency legislation in California and the EU, presents two sides of the same picture: the former requires content to bear source and attribution, while the latter requires content to be searchable and authorized. If the media can connect these two aspects, articles, images, and historical archives will have a longer commercial lifespan, rather than simply sinking into databases after publication.

Source materials address the issue of credibility, while authorized platforms address the issue of distribution. Only by combining the two can content potentially become a long-term asset.

(Image caption) The interface state of Google Earth's web version AI image generation function, which was quickly reverted after its launch, highlights the difficulty of extending the platform's internal security design to the spread risk beyond screenshots when geographical images and sensitive scenes are superimposed with fictional content.


GFM needs to establish its own photo archive.

Specifically, regarding GFM's own workflow, what can be established now is the backend metadata field for images and AI content: generation tool and model version, generation date and operator, original prompt words, source of reference materials, tool and modifier for manual modification, whether it is an illustration or a real news image, corresponding published article and language version, image description and authorization scope, and whether third-party commercial reuse is allowed.

These sections do not need to be fully displayed below the image captions. Readers need to know the basic nature of the images; the complete record remains in the internal asset system for partners and authorized clients to review when needed.

Accumulating this information now will make it much easier to deal with regulatory reviews or promote content assetization a few years later than to fill in the gaps afterward.

In the past, the news industry mostly handled copyright disputes by waiting for the content to be disseminated and problems to arise before pursuing legal action, which was costly and difficult to prove. The logic behind the latest legislation in California and the European Union is to embed disclosure obligations into every stage of generation, editing, distribution, and verification, allowing source information to flow along with the content.

This aligns with the compliance logic of the financial industry. Every transaction leaves a traceable chain of records, existing before any problems arise. Financial media have long reported on the construction of such compliance infrastructure, and now content production itself faces similar requirements. For an organization like GFM, which positions itself as an institutional media infrastructure, this is both a reporting topic and a matter of concern regarding its own operational standards.

Content assets must first leave their source.

An AI image is beginning to carry identity information, which on the surface is a compliance issue; for GFM, it is also a reminder: the first value of content comes from the reader seeing it, and the second value comes from being able to prove how it was created, who reviewed it, and how it can be used many years later.

Technical standards will be revised repeatedly, C2PA vulnerabilities will be patched, and the pace of regulation will be adjusted. However, preserving the source information now is always more worthwhile than patching it later.

Disclaimer

The legal provisions and effective dates mentioned in this article are all quoted from publicly available documents from the California legislature and official EU guidelines. For specific applicability, please refer to the final official text and professional legal advice. This article does not constitute legal advice.