← Back to blog
·7 min read·Heidi Macomber

The One Tamper-Proof Tool We Have Still Can't Prove Who Wrote This

The EU AI Act requires AI output to be marked, not anchored to a blockchain. A chain proves a file existed at a timestamp, not who created it. Here is why the tamper-proof option cannot prove authorship, and what to do instead.

EU AI ActArticle 50AI RegulationProvenanceBlockchain
Share:

Part 3 of this series ended with an uncomfortable result: the watermarks now required by the EU AI Act do not survive a round of ordinary editing, so they cannot function as courtroom proof. There is an obvious next question. The only truly immutable technology we have is the blockchain. Why aren't we proving provenance with it?

The blockchain is immutable. It also cannot prove provenance. Both things are true at once, and the gap between them is where this whole industry is currently stuck.

What a blockchain record actually proves

A blockchain cannot store an article or an image. It stores a fingerprint of one, called a hash. A hash is a short string produced by feeding the exact file through a mathematical function. Change a single comma and the fingerprint changes completely, with no way to fake the old one.

Anchor that fingerprint to a blockchain and you have proven exactly three things:

  • This exact file existed at this timestamp.
  • This key holder committed it.
  • Nobody can quietly rewrite that record later.

Picture a notary. A notary stamps the exact envelope you bring, dates it, and keeps the record forever. The stamp is genuinely tamper-proof. Here is the catch, and it is the entire problem: the notary certifies the envelope, not the letter inside.

The three gaps

First, garbage in, garbage forever. Anyone can take AI-generated text, hash it, and commit it to a chain. The blockchain will faithfully preserve that record for eternity. It proves the file existed. It says nothing about who or what created it. An immutable record of an unverified claim is not proof. It is a permanent receipt for the claim.

Second, a key is not an identity. A blockchain record says key 0x4f9something committed this file. That statement only means something if you already know who controls the key. Binding cryptographic keys to real-world identities is its own unsolved problem, and it is the same problem C2PA, the content-credentials standard, handles with a list of trusted signers.

Third, and this is the one that connects directly to Part 3: the hash does not travel with edits. A watermark at least attempts to survive editing, and the forensic study showed paraphrasing kills it anyway. An exact hash is stricter still. Paraphrase an article, resize an image, convert a file format, and you have produced a new artifact with a new fingerprint that matches nothing on chain. The blockchain proof covers the original and abandons every version that actually spreads online. Content that goes viral through copies and rewrites is exactly the content you most want provenance for, and it is exactly the content the chain loses.

The camps trying to close the gaps

The industry has split into three approaches, and watching them fight is the fastest way to understand the trade-offs.

The C2PA coalition, backed by Adobe, Microsoft, and camera makers, went with signed manifests that travel with the file. Their specification is careful about what it claims. Verbatim from the official explainer: Content Credentials "do not provide value judgments about whether a given set of provenance data is 'true'," only whether the information is "well-formed and free from tampering" and signed by someone on a known trust list. Their phrase for the design is "tamper-evident." Not tamper-proof. Evidence of tampering, if you know where to look.

The blockchain camp attacks C2PA's weakness: the manifest travels with the file, and anything that travels with the file can be stripped. Numbers Protocol, a company that sells blockchain provenance services, makes the argument concretely: import AI-generated content into a photo editor, export it in another format, and the credentials very likely vanish in the conversion. Their answer is a capture app that registers content on-chain at the moment of creation, so an original record survives even when every copy is scrubbed. Note the source here. This is a vendor describing its own product. The fair reading is that their criticism of C2PA is widely shared while their solution is early.

The research camp is trying to fix the edit problem itself. A February 2026 paper from a team at S&P Global proposes a registry where AI image platforms record a perceptual hash of every generated image at creation time. A perceptual hash is a fingerprint designed to survive small changes: it encodes what an image looks like rather than its exact pixels, so a resized or recompressed copy still matches. The registry lives on a hybrid on-chain and off-chain store, and lookups run by similarity rather than exact match.

It is a serious idea with two hard limits. It covers images, where visual similarity is mathematically cooperative. This series is about text, where a paraphrase preserves meaning while changing nearly every word, and no deployed system matches text that way. And the authors state the scope plainly: the method handles "benign transformations such as resizing, compression, or minor edits." Deliberate rewriting is not a benign transformation.

Why the EU did not just mandate blockchain

The AI Act's marking rules need something that rides along with every generated output automatically, at provider scale, with no extra step a human might skip. A watermark is produced inside the output itself. A blockchain anchor is an action someone must take after the fact, and it never enters the AI answer your customer actually reads.

So the regulator picked the only mechanism that travels with the content, and Part 3 showed that mechanism does not survive editing. The blockchain survives everything and travels with nothing. Nobody has yet built the thing that does both. The camps are converging on a hybrid, credentials riding with the file plus an optional chain anchor as the un-stripable timestamp, and the hybrid still does not establish authorship. Anthropic said as much about its own watermark in a September 1 update to its explainer: a watermark "cannot distinguish 'Claude wrote this' from 'Claude heavily edited this'" and "doesn't say anything about ownership or authorship." If the watermark itself cannot establish authorship, anchoring it to a blockchain adds a timestamp, not an author.

What this means for you

If you were hoping the tamper-proof option would ride to the rescue, the timeline says otherwise. The February 2, 2027 interoperability deadline arrives before any provenance approach has demonstrated it can meet an evidentiary bar.

Your practical moves stay the same as in Part 3, and they work regardless of how this standards fight resolves. Monitor what AI engines say about your business and keep dated records of errors. Save the query, the platform, the answer, and the date. The provenance layer may take years to become usable proof. Your own documentation is evidence you control today, and courts have accepted business records kept in the ordinary course for a long time.

The one-liner to carry out of this piece: the blockchain is a notary, not a witness. It can prove the envelope existed and was never swapped. It cannot tell you who wrote the letter, and it loses track of the letter the moment anyone re-addresses it.

This is Part 4 of the series. Read Part 1: The EU AI Act's August 2 Deadline Just Passed, Part 2: Anthropic's Watermark Arrived. Detection Is Another Story, and Part 3: The Watermark Exists. The Proof Does Not.

Share:

Want to know how your site scores?

PARCEIT's structural audit engine crawls your website and checks all of these signals in under 5 seconds. Find out exactly what AI search engines see.

Run your free audit