Digital Provenance: AI policies are being left behind in the fast turnaround GenAI media production world.
The metadata often starts real. The compliance officer did their job. Neither one survives the asset's actual journey.
Ask most GRC or IT leaders whether their organisation has an AI usage policy, and the answer is yes. Ask whether that policy actually governs the images and video circulating through the business - and the honest answer, for almost everyone, is “Um, yeah?”. The surprising part isn't that the intent was missing at the start. Often it wasn't. The surprising part is how completely that intent evaporates on the way out the door.
This is the next layer of the rich media blind spot: not the absence of a policy, but the absence of a mechanism that lets it survive the asset's actual lifecycle. And nowhere is that gap more visible right now than in content provenance.
The metadata that starts real
Provenance information often does get captured, right at the point of creation. Commission a photographer for a shoot, and their equipment embeds their details into the file automatically — creator, capture date, device, sometimes licence terms — before anyone in the organisation has done anything at all. Bring that asset into a properly governed DAM, and the platform holds that information, surfaces it, makes it queryable. On paper, and often in practice, this is policy working exactly as designed: the compliance officer wrote the rule, the creative supplier did their part, the platform made the knowledge clear and identifiable.
So far, so governed.
Where it actually breaks
The failure isn't at capture, and it isn't inside the DAM. It happens at the boundary the asset crosses every single day: the moment it's resized, re-exported, repurposed into a new format, or pushed out to a new platform for actual market-facing use. Most standard image and video processing pipelines strip embedded metadata at exactly this step. Not maliciously — it's a routine side effect of how transcoding works. The credential goes in cleanly at creation. It falls out somewhere in the ordinary, constant business of turning a governed master asset into the dozens of derivative versions a real campaign actually uses.
The result: the original file, sitting inside the DAM, can prove exactly where it came from. The evolved, market-facing version of that same asset - the one actually reaching a channel, a partner, or the public - usually can't. It's the same content, one step removed, and it arrives with none of the provenance the original had. Lost in translation, asset by asset, thousands of times a week.
There are organisations that have solved as a long term compliance audit trail - but notice where. Regulated industries with the budget and mandate for deeply planned chain-of-custody processes - wagering, financial services, parts of government - build the systems that preserve this information end to end, because the cost of not doing so is existential. However it is a knowledge trail across systems – not a core provenance play that enriches the assets itself. So there is still a gap. Outside of this regulated industry forensic knowledge chain (and for everyone else) the market-facing asset arrives naked in the world, with no way to prove what the DAM already knew about it thirty seconds earlier.
This gap is now getting attention well beyond any single vendor's marketing. Gartner has named digital provenance one of its strategic technology trends for 2026. The World Economic Forum has separately flagged AI-generated content watermarking as a top emerging technology this year. Two of the most-cited forecasting bodies in the industry, arriving at the same conclusion independently, in the same year.
The industry's response is a standard called C2PA — Content Credentials — built by a coalition that includes Adobe, Microsoft, the BBC, and Intel. A cryptographically signed manifest travels inside the file, recording who made it, when, what tools were used, and every meaningful edit since capture. Tamper with the file, and the signature breaks. It's real, backed by real infrastructure, and moving into production — camera manufacturers are shipping it at the point of capture, major AI platforms are attaching it to generated content. It is, in other words, exactly the mechanism the photographer example already relies on informally. And it is exactly as vulnerable to being stripped out the first time the asset gets touched downstream.
Why this keeps happening — and why it's not a training problem
This isn't a failure of policy-writing, and it isn't a failure of individual diligence — the photographer did their job, the DAM did its job. It's structural. Enterprise data governance has spent two decades building itself around structured data — financial records, HR systems, CRM — because that data comes with fields a policy can attach to, and because that data doesn't get algorithmically transformed a dozen times on its way to being used. Rich media does. Every resize, every re-export, every platform handoff is a point where the connective tissue between the asset and its own history can be - and routinely is - severed.
Without enrichment that survives transformation, not just enrichment at ingest, there is nothing for a policy to govern once the asset leaves its original, well-behaved form. The policy exists in the abstract. The derivative asset exists as an opaque blob of pixels with no memory of where it came from. The two never actually meet, precisely at the point where the asset is doing the most public-facing work.
That's true of provenance specifically, and it's true of the wider set of obligations most rich-media AI policies gesture at: consent records, licence and copyright status, right-of-erasure requests, retention schedules, security classification. Every one of these depends on the same missing step: the information has to persist through every transformation the asset goes through, not just exist once at the start.
What this actually looks like in an audit
If a regulator, a legal team, or a customer asked your organisation to prove the provenance of a specific image used in an external publication — where it came from, whether it was AI-generated or captured, whether the person in it consented, whether the licence was still current at the time of use - could you produce that answer today, for the actual market-facing version of the file, not the master sitting safely in the DAM?
For most organisations, the honest answer is a shrug. Not because no one cared, and not because nothing was ever captured. Because the mechanism to carry that information through every transformation the asset went through on its way to publication was never built. The policy covers the intent. The original file even had the evidence. The version that's actually out in the world doesn't.
That gap is the rich media blind spot in its most concrete form: a governance obligation that is real, documented, briefly true at the source — and unenforceable the moment the asset does the one thing every rich media asset does constantly, which is change shape.
Closing the gap
None of this requires abandoning the AI policy that's already been written, or distrusting the photographers, creators, and platforms doing their part correctly at the start. It requires making sure the knowledge they capture doesn't die at the first transcode. That means one of two playbooks needs to come into being:
1. Governance metadata - provenance, consent status, licence terms, classification - is carried through every derivative and every export automatically, re-attached or re-verified as the asset transforms, not just recorded once and hoped for; or,
2. The blockchain provides a public, immutable record of the above, and the file doesn’t need to carry the actual data – it just needs to be indelibly connected to the blockchain record. Public, known, irrefutable. No one is onto this, but it's the NFT play, commercialised for public facing media assets at scale.
Until these mechanisms exists, the policy document, the DAM, and the actual asset out in the world will keep occupying three different realities. One says the organisation is covered. One has the receipts. The third - the one everyone else actually sees - has neither.