Agentic editing changes media faster than a human provenance review can follow. An assistant can generate a product image, restore a source photograph, swap a face, crop for six platforms, compress the results, and add a logo in one automated workflow.

At the end, viewers may want to know where the asset came from and what happened to it. Two technologies are often proposed as the answer: C2PA Content Credentials and SynthID. They are complementary, not interchangeable.

C2PA carries signed claims and edit history alongside an asset or through a linked manifest. SynthID places an imperceptible signal inside supported Google-generated content. One is primarily a provenance framework; the other is a watermarking and detection system. A production pipeline benefits from understanding both—and from recognizing what neither can prove.

C2PA records signed assertions and relationships

The Coalition for Content Provenance and Authenticity publishes an open technical standard. Version 2.4 defines structures for claims, assertions, digital signatures, ingredients, actions, and validation. The consumer-facing term “Content Credentials” is commonly used for implementations of this provenance approach.

A creator or tool can sign a manifest stating information such as who or what created an asset, which ingredients it used, and which transformations occurred. A verifier can test the signature, check whether bound data changed, and inspect the chain of assertions.

That is more useful than an editable text field because tampering can invalidate the cryptographic relationship. It also supports derivatives: a new edit can cite the prior asset as an ingredient and add a new signed action.

But C2PA does not act as a truth machine. A valid signature establishes that a named signer made a claim and that associated data validates; it does not guarantee that the signer is trustworthy, that a caption is factually correct, that a subject consented, or that an edit is harmless. Verification software should report what validates and what does not, rather than labeling the entire image “true” or “fake.”

Credentials can be embedded in a file or recovered through supported cloud and soft-binding mechanisms. If a platform strips metadata, the embedded manifest may disappear even though the pixels remain. That is one reason a missing credential must not be interpreted as evidence of deception.

SynthID hides a signal in generated content

Google DeepMind’s SynthID embeds invisible digital watermarks into AI-generated images, audio, text, and video in supported Google products. Detection looks for that signal later.

For images and video, Google says the watermark is designed to remain detectable after common modifications such as cropping, filters, frame-rate changes, and lossy compression. For audio, the robustness targets include noise, MP3 compression, and speed changes. The watermark is intended to be imperceptible to people while still machine-detectable.

This gives SynthID a different survival profile from file metadata. A platform can re-encode an image and remove its attached manifest while some pixel-level watermark signal remains. Yet detection is not universal. It depends on content generated through supported paths, access to a compatible detector, signal strength, and the transformations applied.

No SynthID result does not mean “human-made.” The asset may come from another model, a Google path without that signal, an older product, or a transformation that weakened detection. Likewise, a positive result says something about generation provenance, not whether a use is legal, consensual, or factually accurate.

Meta Content Seal adds another watermark layer

Meta announced Content Seal alongside Muse Image in July 2026. Meta says images generated with Muse in Meta AI and meta.ai receive the invisible watermark, designed to survive cropping, compression, resizing, and screenshots. A detection tool is in preview.

Meta describes Muse Video as an early preview that is coming soon and says Content Seal will extend to video in the future. It would be inaccurate to claim that the current video preview already has broadly deployed Content Seal support.

Content Seal reinforces a market trend: providers are developing their own robust signals for generated media. That can improve accountability, but multiple watermark ecosystems also mean detection may require vendor-specific tools and policies. An editor should preserve signals it does not fully understand rather than deliberately attempting to remove them.

Why signed history and watermarks work better together

A watermark can survive when metadata is stripped, but it generally conveys less rich history. A C2PA manifest can describe models, tools, ingredients, edits, and signers, but an embedded copy can be lost during ordinary distribution.

Layer the two when the generation path supports them. Retain the provider watermark in the media. Create a C2PA-compatible or equivalent signed manifest that records the original generation and every meaningful transformation. Keep an internal immutable ledger and source hashes so the organization can investigate when public signals are missing.

The layers answer related questions:

Only the first two are primarily technical provenance mechanisms. A complete trust decision needs the others.

Agentic edits can break or complicate the chain

An agent does not necessarily know which operation preserves a watermark or credential. Cropping changes the pixel area. Restoration synthesizes detail. Face swapping changes identity. Logo addition covers pixels. Compression and transcoding rewrite the container. Screenshotting discards original file structure.

Before editing, inspect available credentials, watermark labels, metadata, and source hashes. Store the original as an immutable ingredient. After each material step, create a new derivative record rather than overwriting the source.

The record should name the operation, tool and version, parameters that are safe to retain, time, operator or agent, source hash, output hash, and approval. For a multi-stage agent run, avoid reducing six transformations to “AI edited.” Viewers and auditors need to distinguish color correction from identity replacement.

If a tool can carry forward a valid C2PA ingredient relationship, use it. If the export path cannot, keep an external manifest and add a visible disclosure appropriate to the context. Do not copy an old signature onto new pixels as though the signer approved the derivative.

After editing, test supported detectors and validate the new credential. Record the result as an observation, not a guarantee. A watermark that survives one crop setting may fail after another platform re-encodes the output.

Restoration raises a special authenticity question

Old-photo restoration often removes scratches, reconstructs faces, colorizes scenes, and invents detail that was never captured. The output can look more documentary than it is.

Preserve the scan as the historical source. Label the restored image as a derivative and describe substantive synthesis. When possible, provide a comparison or access to the original. Do not present generated texture as recovered evidence.

If a source has no credential because it predates the standard, that absence is expected. The new workflow can still sign a claim that a particular scan was used and that restoration occurred. Provenance begins where reliable documentation begins; it does not need to fabricate an older chain.

Identity edits demand disclosure beyond provenance

Face swaps and character replacements can make a real person appear in a scene they never entered. A technically perfect edit history does not satisfy consent or prevent deception.

Require authorization for the source and target identities, script, context, territory, and publication. Use a visible label when viewers could otherwise form a materially false belief. Preserve provenance for investigators, but design disclosure for ordinary people who will never open a credential viewer.

Logos have a different risk. Adding a mark can imply sponsorship or ownership. Confirm brand authorization and avoid covering existing provenance indicators. If the logo is used as a visible AI disclosure, make placement robust across platform crops.

Extending provenance through Medux processing

Medux media tasks are separate processing operations that Codex or Claude can call after MCP configuration. They should be represented as new stages in the asset lineage, not as invisible transport through a native provenance integration.

For the Codex old-photo restoration workflow, hash and retain the source scan, record the restoration request and Medux task ID, and label the result as restored. If the output adds or changes details, preserve that fact in the derivative record.

For the Claude face-swap workflow, link the source and target assets, their consent records, the approved context, task ID, and final output. Validate any available credentials again after the identity-changing edit and add a clear disclosure.

For the Codex logo workflow, save the authorized logo version and placement parameters. Check whether the operation or subsequent compression stripped embedded metadata, and issue a new provenance record for the branded derivative.

Do not claim that Medux preserves C2PA or SynthID for every operation unless the specific current tool documentation and output validation establish it. The safe workflow assumes that cropping, restoration, swapping, compression, and watermarking may alter signals, then tests and records what actually survived.

Provenance is strongest when it is a chain of accountable claims, not a single badge. Watermarks, signed credentials, lineage, consent, and visible disclosure each cover a gap the others leave open.