Detection asks a file to prove, after the fact, what made it. Provenance asks a file to carry that answer with it from the moment it is created. The second approach has a structural advantage the first cannot match: it does not have to outguess whatever model gets built next, only record honestly what actually happened at the moment of creation.
Key takeaways
A detector is a statement about the past: it was built by studying how existing models tend to generate content, and it can only recognize what it was shown. Canada’s own federal Voluntary Code of Conduct effectively concedes the point — it asks a manager of a public-facing system to build “a reliable and freely available method to detect content generated by the system, with a near-term focus on audio-visual content (e.g., watermarking),” language that frames detection as a near-term priority rather than a solved, permanent capability. (ised-isde.canada.ca) Every new generation technique released after a detector ships is, by construction, untested against it. Nothing about better funding or more training data changes that ordering — a detector can only ever be built from examples of models that already exist, which means the newest generation technique on the market is, by definition, always the one every existing detector has never seen.
C2PA’s Content Credentials standard does not try to infer origin from the finished artifact at all — it records origin as the artifact is made. The coalition describes it as providing “an open technical standard for publishers, creators and consumers to establish the origin and edits of digital content,” a record that functions “like a nutrition label for digital content, giving a peek at the content’s history available for anyone to access, at any time.” (c2pa.org) That is a fundamentally different question from the one a detector answers: instead of asking a model to guess what an image is, made from a fixed set of examples of what past images looked like, it asks the creation tool to simply state what it did, once, at the moment it did it.
The coalition is explicit that this does not solve authenticity for every case. Content Credentials’ own site states: “While there will continue to be bad actors who seek to label synthetic content as authentic, our goal is to provide good actors with a way to demonstrate the authenticity of their content.” (contentcredentials.org) That is an admission, in the standard’s own words, that provenance is not a universal fix: a bad actor who never attaches a credential, or who strips one after the fact, is not caught by the system — they are simply unlabeled, exactly as they would have been before the standard existed. Provenance changes what a cooperating creator can prove; it does not force an uncooperative one to reveal anything.
SynthID’s own design already leans toward the provenance model rather than the after-the-fact-detection model, even though it is usually described as a detection tool. Google’s own description is that the watermark for an image or video is “added the moment content is created” — a record made at the point of generation, not a pattern inferred from the finished file afterward. (deepmind.google) The most credible identification tools available today, in other words, already work by recording something true at creation rather than by guessing something plausible afterward — which is the same structural choice C2PA makes, implemented at a different layer.
Canada’s Centre for Cyber Security explains why the choice actually matters, not just which method is more elegant: “Content not clearly identified as being AI-generated can result in the spread of misinformation, disinformation and confusion.” (cyber.gc.ca) That statement describes exactly the gap detection cannot close and provenance is built to: identification has to exist before the content spreads, not be reconstructed afterward by a tool trying to guess. A detector that is eventually right about an image that has already circulated for a week has already failed at the one thing that mattered — stopping the confusion before it started, which only a record made at creation can do.
Two newsroom workflows verify the same submitted photo. Workflow A runs it through a generic “AI or not” detector trained on last year’s models. Workflow B checks for a Content Credentials pin or a SynthID watermark recorded at the moment of creation. Workflow B either finds a real, dated record — a positive, attributable answer — or finds nothing, which is an honest “unknown.” Workflow A produces a confidence score measured against models that may already be a generation out of date, which is confidence pointed in the wrong direction: it is most likely to be wrong exactly when the underlying technology has moved fastest, which is always.
Canada’s own attempt at a binding rule for any of this did not survive Parliament. Bill C-27 would have enacted the Artificial Intelligence and Data Act alongside a rewrite of federal privacy law, but Parliament’s own record of the bill shows it was still “at consideration in committee in the House of Commons” when the 44th Parliament’s first session ended on January 6, 2025, and it was never reintroduced. (parl.ca, LEGISinfo — Bill C-27) That leaves the voluntary code, and whatever a creation tool chooses to record on its own, as the only Canadian instruments actually operating in this space right now — provenance is not just an adoption problem in principle, it is the only real option currently in front of a Canadian business.
Related: the detection side of this comparison in detail, the mechanism behind a provenance-style watermark, why provenance’s own adoption problem is real
Not entirely. Provenance only works where the creator chose to record it and the record survived to the copy being checked. Where neither is true, some form of after-the-fact assessment — even an imperfect one — is still the only option available.
That is an adoption question, not a technical one — C2PA’s own site frames its progress as a “collaboration with hundreds of companies,” which is itself an acknowledgment that the standard only works where it has been implemented, and implementation is still uneven across tools and platforms.
It is proof of what the record states about origin and edits, nothing more. Content Credentials’ own framing is that the tool lets a good actor demonstrate authenticity — it does not evaluate whether the content itself is accurate, fair, or otherwise trustworthy.
Nothing sourced here rules that out, but the structural asymmetry described above doesn’t depend on any particular detector’s quality — it applies to any detector trained against a fixed set of past examples, checked against a field that keeps producing new ones. A better detector shifts where the line falls; it does not remove the fact that there is a line, and that provenance recorded at creation was never subject to it in the first place.
Building a content pipeline around provenance from the start beats trying to verify authenticity after publication.