Publishers have a content provenance problem, but C2PA is only part of the conversation
Content provenance is no longer a conversation we can “circle back to” later. If we’re not willing to make these decisions for ourselves now, we’re not going to like what everyone else decides on our behalf.
BY LIZ MOOREHEAD, HEAD OF CONTENT AT BEELER.TECH + ERIK SVILICH & MATT KAMINSKY AT ENCYPHER
Whenever I think about the discourse surrounding C2PA for too long, my left eye starts to twitch. My doctor would likely tell me that’s because an unchecked Diet Coke addiction isn’t an adequate solution for staying hydrated.
He’s not wrong. Technically. But deep down, I know Diet Coke is only part of the problem. The other part is that this whole “content provenance” conversation is deeply strange… and it’s bothering me.
Every single day, publishers are watching the economic scales of their content tip even more out of their favor — and we all know why. AI “solutions” can ingest, summarize, excerpt, repackage and serve information to would-be visitors without ever sending them back to the publishers who created it in the first place. And that same AI-generated content is also getting cheaper and easier to produce.
So, readers, advertisers, platforms, and publishers are all trying to figure out (with admittedly varying degrees of interest) how to tell what came from where, who owns what, and which players are trying to skirt attribution entirely without anyone noticing.
🔎 Get the latest: Subscribe to The Traffic Report, our weekly newsletter
This sounds like a big deal.
To me, at least. (OK, and also to Rob.)
Because if you can’t establish provenance (e.g., ownership) of your own work in a way that’s unfalsifiable, what do you really offer as a publisher or media company aside from digital real estate for ads, and the ability to make AI platforms smarter (and richer) without credit or them having to pay you for it?
Enter stage left, the aforementioned “deeply strange” part.
Unfortunately, the vast majority of the conversations I hear about content provenance or C2PA seemingly lack what I would consider to be an appropriate amount of urgency.
In fact, most of the industry chatter around this topic can be summarized as:
“Well, we should probably do something. Those compliance deadlines are coming up.”
Which is exactly why I recently sat down with Matt Kaminsky and Erik Svilich of Encypher. Erik is the founder and CEO of Encypher, author of C2PA’s text specification published earlier this year, and co-chair of the C2PA text provenance task force. Matt is Encypher’s CCO, so he comes at this topic with deep experience in both publishing and ad tech.
Together, we wrestled with the following questions:
- Why do publishers still have trouble making content provenance a priority?
- What can C2PA actually solve for, and where does it still fall short?
- What is the content provenance business case for trust, advertising, and protecting the economic value of content?
- And how much are publishers already losing because content provenance can only get movement as a compliance initiative?
Some of these questions have pretty straightforward answers, even if they’re uncomfortable.
🔎 From Rob Beeler: Publishers need receipts, C2PA may be one way to get them
Others get messier the second you walk back into the current reality of publishing, where everything is on fire, we’re all juggling 47 “equally” important priorities, our resources are dipping into the negative, and every new initiative needs to win a 10-round fist fight to even be considered.
And somehow, in the middle of all that, this is still the conversation we can no longer “circle back to” later.
Because if we’re not willing to make these decisions for ourselves now, we’re not going to like what everyone else decides on our behalf.
C2PA is the mechanism, but the real conversation is content provenance
The technical debates about C2PA are necessary (and we’re going to talk about them), but we first need to establish that C2PA and content provenance are not interchangeable terms.
Content provenance is the looming, existential, solutions-agnostic question:
How do publishers and media companies establish their content actually belongs to them? More specifically, how do they prove that they own their content, what happened to it along the way, and what rights or identity information should travel with it?
C2PA, on the other hand, is a potential answer to that question.
As Erik explained it, C2PA provides open-source infrastructure for embedding and reading information associated with digital content. It gives the industry a common technical mechanism that publishers, platforms, AI companies, and others can use to carry provenance information with an asset.
🔎 Read more: Publishers, chasing revenue at all costs is, well, costing you
What publishers ultimately want to do with that infrastructure is where the whole thing gets tricky, and that’s for a couple of reasons:
- Rights and licensing aren’t native C2PA features.
- Organizational identity isn’t native to it either.
Those things can be layered onto the standard, but implementing C2PA by itself does not suddenly give a publisher a complete system for protecting, tracking, licensing, and monetizing its work. Erik was careful about that distinction throughout our conversation, particularly because Encypher has built technology addressing some of those gaps.
And yes, there are some gaps.
C2PA generally signs the whole asset, but that’s not how content travels
Let’s say that I had a C2PA solution in place that would establish the content provenance of this article, with Beeler.Tech as the publisher and myself as the author.
C2PA generally signs the asset as a whole, which is great until we all remember that’s rarely how written content travels around the internet. You might find a quote in here you really dig, so you copy and paste it to LinkedIn. Or you could find a section you fundamentally disagree with, so you Slack a screenshot of it to someone along with the message of: “LOL get a load of this idiot.”
See the problem?
Sure, there are people who share content assets in their entirety. In a meaningful percentage of cases, however, content travels as curated fragments and excerpts instead. And since C2PA typically only applies to a complete asset, those fragments become free agents, with no verifiable content provenance to speak of.
“The C2PA embedding is one time, at the end of the article,” Erik told me. “If someone wants part of it, I’m not going to copy the whole article. I’m just going to copy the part that’s important to me.”
AI retrieval works almost the same way: pulling the bits and pieces that are the most relevant to a search query, rather than porting everything over. And sometimes, there’s a bit of hallucination added in for good measure. Just to keep things spicy.
🔎 Read more: Publishers, chasing revenue at all costs is, well, costing you
That’s a fairly significant gap if your product is text, a medium whose natural state on the internet is being excerpted, quoted, summarized, syndicated, screenshotted, scraped, fed into systems, and otherwise removed from the tidy confines of the original URL.
Encypher has built its own technology to make provenance persist at a more granular level, but both Matt and Erik agree that C2PA itself should neither be dismissed for failing to solve every provenance problem nor oversold as though it already does.
Organizational identity also runs into a similar wall
One of the most seductive and easy ways to explain provenance to publishers is:
“You can put your stamp on your work.”
But even that’s a complicated thing to say.
C2PA doesn’t communicate to the world that it’s your stamp by default. Sure, the stamp can exist, and even be valiantly defended against would-be digital content poachers. You still need to put the infrastructure in place to tell the rest of the ecosystem whose name is on that stamp.
At the core C2PA level, Erik explained, the identity associated with a signature belongs to the signing tool. So if a publication uses a third-party tool, the basic signature identifies that tool, not automatically the publisher whose content it is. A companion standard, CAWG, can add organizational identity, but support across validators is fragmented.
This is where Encypher is doing some exciting stuff, by the way.
They’ve open-sourced their validator SDK with support for organizational identity in part because Erik estimates only a small number of companies currently support organizational identity alongside C2PA at all, and he isn’t aware of another one that is both open and free.
Of course, there are other limitations:
- Platforms and CDNs can strip manifests.
- Erik noted that support is growing across major platforms, but that support remains inconsistent.
Oh, and then there’s my personal favorite — C2PA in no way forces shady players to participate. If someone creating crappy or deceptive content has absolutely zero interest in telling you how that content came into existence, C2PA isn’t going to force them to become good content citizens by claiming their work.
🔎 Read more: Ad ops is where other people’s bad decisions become emergencies
So this is not the glorious arrival of The One Provenance Standard To Rule Them All… and in the 1s and 0s bind them.
C2PA is content provenance infrastructure, and it’s important infrastructure at that. Adoption is on the rise, and it’s capable of supporting a lot more than the narrow compliance conversation happening around it.
But that compliance thing is where we revisit my “deeply strange” comment from the beginning once more.
Somehow, our mission-critical content provenance problem became a compliance project
When I first started reading about C2PA and provenance, my interest in it was pretty personal.
I’m a writer. In fact, I started my career in journalism at the Annapolis, Maryland-based Capital Gazette and The Baltimore Sun. Then, in a zippy twist of fate, that column led to my current work as a content strategist. So, for the past decade, I’ve worked with leaders and brands to help them build things (movements, communities, businesses, fatter pipelines) with words, ideas, research, videos, original reporting, expertise, or other types of intellectual property.
Right now, my work can be scraped, absorbed, summarized, repackaged, and monetized by somebody else. A somebody else who didn’t spend hours interviewing subject matter experts, outlining, researching, and questioning life choices when faced with random bouts of not being able to write a single fucking coherent sentence for two hours straight.
But they can still take all the credit and the traffic that belongs to me, if they so choose.
These are the kind of content provenance nightmares that send me running straight to my therapist.
She loves me when I’m angry and billable.
Which is why I find it so bizarre that we’ve reached this moment and one of the strongest forces pushing for C2PA adoption appears to be… compliance. We’re doing it because we have to, not because there’s a strong desire to do so, which makes no sense.
When I asked Erik and Matt about this, they both pointed to education as a major reason C2PA hasn’t moved faster. Erik said that, until more recent regulatory pressures — the EU AI Act, as well as California’s landmark AI Transparency Act that took effect on August 1, 2026 (a first in the United States) — the incentives simply weren’t there.
Yes, companies now have a reason to act, but that reason has also shaped the way many of them understand the technology.
🔎 Get the latest: Subscribe to The Traffic Report, our weekly newsletter
It goes into the compliance bucket, not the “fighting for the soul of original content and media” bucket.
Tragically, we all know what happens to things in the compliance bucket — they sit there until the deadline gets close enough to start ruining somebody’s week. Then they do just enough to check the “See? We did it, now leave us alone” box. I don’t say that in judgment; I’ve been that person.
“People have been thinking about it as, ‘We just need to do this for compliance,’” Erik said. “And of course people are going to drag their feet until the deadline.”
But there’s a larger reason for his frustration.
C2PA has commercial applications many aren’t considering at all
Matt and Erik say they are already having meetings with publishers who understand the pitch. The publishers see the potential for authentication, rights, AI-use telemetry, trust, and revenue.
In fact, in Encypher’s early advertising pilot, Erik said publishers are seeing roughly up to $15 in additional revenue for every $100 in ad spend, while integration itself is free for publishers. (Of course, he was careful to qualify that number: the pilot is early, and Encypher gets paid as part of the transaction. But that’s a nice return.) Encypher also offers a free WordPress plugin for publishers that want to test implementation without building from scratch.
Yet a meaningful number of those publisher conversations go cold, even after initial enthusiasm. Because the moment a content provenance priority has to travel upward to decision-makers, momentum tends to die.
Why? Publisher-side people who see the risk are often being asked to make the case to stakeholders who are looking at a much broader, more revenue-oriented set of priorities, budgets, and near-term pressures. And if content provenance can’t be translated into something that connects directly to revenue, risk, or the bottom line, it’s easy for it to get pushed behind a priority that’s more shareholder-friendly.
Once again, publishers don’t have an innovation problem. They have a prioritization problem inside organizations where decision-makers are more motivated by revenue, growth, and shareholder value.
I’ve heard versions of this across enough publisher conversations that I don’t think it’s fair to reduce what Matt and Erik are seeing to publishers being shortsighted, and neither do they.
Ad ops sees what’s possible nearly all the time, but it’s not enough
Even when they see potential or solutions they want to fight for, they’re often trapped by the reality of their day-to-day pressures and mandates.
Instead of having the space or autonomy to make the changes they want to see, many of them have to go back into organizations dealing with traffic declines, layoffs, AI strategy, pricing, identity, programmatic pressure, privacy, subscription challenges, revenue targets, platform changes, internal silos, and 15 other supposedly existential problems, several of which may actually deserve that label.
Erik described it pretty perfectly at one point: “Their houses are burning down and we’re just another person telling them what to do.”
That’s the environment into which content provenance is trying to introduce itself.
🔎 Read more: Publishers, we don’t serve readers or advertisers, we serve shareholders
So when someone says, “This could protect your content, improve trust, help with licensing, give advertisers more confidence, and potentially create revenue,” I understand why the immediate response from a publisher executive might be:
“Don’t get me wrong, that sounds fantastic. But what does it do for the business right now, and what am I supposed to stop doing to prioritize it?”
This kind of triage has consequences. Particularly since content provenance doesn’t sit politely on its side of the family station wagon, without ever brushing up against those other challenges. Truthfully, it runs through most of them.
Erik says that people still want legitimate journalism and still care where information comes from, and the data agrees with him. More than 6,000 respondents across the United States, the United Kingdom, and Norway said yes, content provenance information makes a brand more trustworthy.
That’s a good thing, because:
- Readers may spend more time with sources they trust.
- Subscribers have a stronger reason to remain loyal to a publication whose work they can authenticate.
- Advertisers have more confidence in the environment around their ads when they can verify what they’re buying against.
Erik describes this as a virtuous cycle, but that’s also where the catch is: somebody has to start the cycle. And publishers are understandably struggling to prioritize content provenance ahead of all those downstream gains that are much easier to champion on a CFO-ready spreadsheet.
Then there’s the advertising angle
Matt pointed to an emerging argument that content provenance could become another signal buyers evaluate in the bidstream, alongside things like IVT and viewability. Encypher has worked on infrastructure designed to push provenance into that environment.
This point becomes even more interesting when you consider that publishers are struggling with the opposite problem: legitimate content being misclassified.
Matt brought up the example of a well-known publication whose content had been flagged in a way that caused CPMs on the affected page to fall far below the rest of the site. His argument was straightforward — if a publisher has a way to verify that an asset is legitimate and authentic, content provenance can become part of defending the economic value of that inventory rather than merely establishing who made an article for philosophical reasons.
Again, none of this means one technology suddenly “solves publishing.” But it makes the idea that provenance belongs “somewhere near the bottom” of a future compliance roadmap look increasingly short-sighted.
Instead, publishers and media companies need to start asking themselves a tougher question.
“How much are we already losing because of a lack of content provenance?”
Solutions will come and go, and standards will most certainly evolve. Heck, C2PA itself is going to keep changing, and Erik is the first person who will tell you there are things about it that can be improved.
The bigger question is what happens if the industry never gets serious about content provenance at all.
So, I asked them.
Erik went first.
“Ultimately, people aren’t going to be able to tell what’s real and what’s not. They’re not going to be able to distinguish legitimate news from AI news.” He also pointed to the economic side of that same problem: content publishers have “put blood, sweat, and tears into” can be absorbed elsewhere without the publisher being paid for it.
🔎 Read more: Publishers, chasing revenue at all costs is… well, costing you
Matt’s answer was grimmer.
“I see publications shutting down. It’s already happening.”
He talked about publishers he knows whose businesses once made millions and now make substantially less as AI overviews take traffic that once would have reached their sites. “I have publisher friends that actually have had to sell their sites for a hell of a lot less than they wanted because they can’t even turn the lights on anymore.”
The implied trust architecture publishers have relied upon doesn’t exist anymore
For years, digital publishing operated in an environment where the URL did a tremendous amount of invisible work. It told the reader where they were, carried the publisher’s brand, contained the ad inventory, gave analytics systems something to measure, and created a reasonably understandable relationship between producing information, attracting an audience, and monetizing that audience.
That relationship has long since fractured.
Content no longer has to remain on the publisher’s property to create value for someone else. Increasingly, it doesn’t. And there are those banking on it staying that way.
As a result, publishers are being forced into a question the old web allowed them to avoid:
When your content leaves your site, what still belongs to you?
Its creator? Its publication? Its rights? Its history? Its licensing terms? Some mysterious “reliable record” that this was yours before it got chopped up, scraped, summarized, fed into a model, or turned into something somebody else gets to monetize?
C2PA may be part of the answer to this whole content provenance thing. But it’s not the whole answer, and pretending otherwise would be a reductive interpretation of a more complicated issue.
But waiting for one perfect system to arrive before treating content provenance as a serious business priority may be its own mistake.
Because the provenance problem is already here.
If you’re a publisher or media company, that means you’re likely already losing money over it.
So you’d better get a grip on the ownership of your content, before someone else does… and turns a profit at your expense.
Read more from Liz Moorehead
[{"id":5536,"link":"https:\/\/www.beeler.tech\/2026\/08\/27\/content-provenance-c2pa-challenges-matt-kaminsky-erik-svilich-encypher\/","name":"content-provenance-c2pa-challenges-matt-kaminsky-erik-svilich-encypher","thumbnail":{"url":"https:\/\/www.beeler.tech\/wp-content\/uploads\/2026\/01\/BT_STACK_exemplar_below_1_2560x1440.jpg","alt":""},"title":"Publishers have a content provenance problem, but C2PA is only part of the conversation","postMeta":[],"author":{"name":"Liz","link":"https:\/\/www.beeler.tech\/author\/liz\/"},"date":"Aug 27, 2026","dateGMT":"2026-08-27 15:41:52","modifiedDate":"2026-08-27 17:28:13","modifiedDateGMT":"2026-08-27 17:28:13","commentCount":"0","commentStatus":"closed","categories":{"coma":"<a href=\"https:\/\/www.beeler.tech\/category\/editorials\/\" rel=\"category tag\">Editorials<\/a>","space":"<a href=\"https:\/\/www.beeler.tech\/category\/editorials\/\" rel=\"category tag\">Editorials<\/a>"},"taxonomies":{"post_tag":"<a href='https:\/\/www.beeler.tech\/tag\/below-the-fold\/' rel='post_tag'>Below the Fold<\/a><a href='https:\/\/www.beeler.tech\/tag\/liz-moorehead\/' rel='post_tag'>Liz Moorehead<\/a>"},"readTime":{"min":16,"sec":44},"status":"publish","excerpt":"Content provenance is no longer a conversation we can \"circle back to\" later. If we're not willing to make these decisions for ourselves now, we're not going to like what everyone else decides on our behalf."},{"id":3980,"link":"https:\/\/www.beeler.tech\/2026\/05\/18\/publishers-failing-fast-in-ad-ops\/","name":"publishers-failing-fast-in-ad-ops","thumbnail":{"url":"https:\/\/www.beeler.tech\/wp-content\/uploads\/2026\/01\/BT_STACK_exemplar_below_2_2560x1440-1.jpg","alt":""},"title":"Publishers: 'failing fast' in ad ops only works if someone's writing it down","postMeta":[],"author":{"name":"Liz","link":"https:\/\/www.beeler.tech\/author\/liz\/"},"date":"May 18, 2026","dateGMT":"2026-05-18 13:54:19","modifiedDate":"2026-08-27 15:39:32","modifiedDateGMT":"2026-08-27 15:39:32","commentCount":"0","commentStatus":"closed","categories":{"coma":"<a href=\"https:\/\/www.beeler.tech\/category\/editorials\/\" rel=\"category tag\">Editorials<\/a>","space":"<a href=\"https:\/\/www.beeler.tech\/category\/editorials\/\" rel=\"category tag\">Editorials<\/a>"},"taxonomies":{"post_tag":"<a href='https:\/\/www.beeler.tech\/tag\/below-the-fold\/' rel='post_tag'>Below the Fold<\/a><a href='https:\/\/www.beeler.tech\/tag\/liz-moorehead\/' rel='post_tag'>Liz Moorehead<\/a><a href='https:\/\/www.beeler.tech\/tag\/the-stack\/' rel='post_tag'>The Stack<\/a>"},"readTime":{"min":8,"sec":22},"status":"publish","excerpt":"I'm tired. A lot of my friends in ad ops are tired. We keep being asked to absorb the same preventable problems on behalf of organizations that have decided learning isn't worth the time it takes."},{"id":3498,"link":"https:\/\/www.beeler.tech\/2026\/04\/02\/the-trust-famine-inside-publishing-is-now-a-business-problem\/","name":"the-trust-famine-inside-publishing-is-now-a-business-problem","thumbnail":{"url":"https:\/\/www.beeler.tech\/wp-content\/uploads\/2026\/01\/BT_STACK_web_below_2560x1440.png","alt":""},"title":"The trust famine inside publishing is a business problem, not a disposable moral argument","postMeta":[],"author":{"name":"Liz","link":"https:\/\/www.beeler.tech\/author\/liz\/"},"date":"Apr 2, 2026","dateGMT":"2026-04-02 15:29:12","modifiedDate":"2026-08-27 15:37:33","modifiedDateGMT":"2026-08-27 15:37:33","commentCount":"0","commentStatus":"closed","categories":{"coma":"<a href=\"https:\/\/www.beeler.tech\/category\/editorials\/\" rel=\"category tag\">Editorials<\/a>","space":"<a href=\"https:\/\/www.beeler.tech\/category\/editorials\/\" rel=\"category tag\">Editorials<\/a>"},"taxonomies":{"post_tag":"<a href='https:\/\/www.beeler.tech\/tag\/below-the-fold\/' rel='post_tag'>Below the Fold<\/a><a href='https:\/\/www.beeler.tech\/tag\/liz-moorehead\/' rel='post_tag'>Liz Moorehead<\/a><a href='https:\/\/www.beeler.tech\/tag\/the-stack\/' rel='post_tag'>The Stack<\/a>"},"readTime":{"min":12,"sec":34},"status":"publish","excerpt":"We know trust matters.\u00a0We can feel what its absence does to a culture, a business, a public, an audience.\u00a0We know what it costs when nobody believes anybody.\u00a0Yet we keep clinging to the same systems that profit from distrust, confusion, exhaustion, and dependency."},{"id":3423,"link":"https:\/\/www.beeler.tech\/2026\/03\/27\/ad-ops-is-where-other-peoples-bad-decisions-become-emergencies\/","name":"ad-ops-is-where-other-peoples-bad-decisions-become-emergencies","thumbnail":{"url":"https:\/\/www.beeler.tech\/wp-content\/uploads\/2026\/01\/BT_STACK_web_below_2560x1440.png","alt":""},"title":"Ad ops is where other people\u2019s bad decisions become emergencies","postMeta":[],"author":{"name":"Liz","link":"https:\/\/www.beeler.tech\/author\/liz\/"},"date":"Mar 27, 2026","dateGMT":"2026-03-27 12:21:34","modifiedDate":"2026-08-27 15:37:39","modifiedDateGMT":"2026-08-27 15:37:39","commentCount":"0","commentStatus":"closed","categories":{"coma":"<a href=\"https:\/\/www.beeler.tech\/category\/editorials\/\" rel=\"category tag\">Editorials<\/a>","space":"<a href=\"https:\/\/www.beeler.tech\/category\/editorials\/\" rel=\"category tag\">Editorials<\/a>"},"taxonomies":{"post_tag":"<a href='https:\/\/www.beeler.tech\/tag\/below-the-fold\/' rel='post_tag'>Below the Fold<\/a><a href='https:\/\/www.beeler.tech\/tag\/liz-moorehead\/' rel='post_tag'>Liz Moorehead<\/a><a href='https:\/\/www.beeler.tech\/tag\/the-stack\/' rel='post_tag'>The Stack<\/a>"},"readTime":{"min":12,"sec":20},"status":"publish","excerpt":"For all the ways this job gets flattened by other people, the truth is ad ops people understand more of the business than we usually get credit for."},{"id":2004,"link":"https:\/\/www.beeler.tech\/2025\/10\/01\/publishers-serve-advertisers\/","name":"publishers-serve-advertisers","thumbnail":{"url":"https:\/\/www.beeler.tech\/wp-content\/uploads\/2026\/01\/BT_STACK_exemplar_below_1_2560x1440.jpg","alt":""},"title":"Publishers, we don\u2019t serve readers or advertisers, we serve shareholders","postMeta":[],"author":{"name":"Liz","link":"https:\/\/www.beeler.tech\/author\/liz\/"},"date":"Oct 1, 2025","dateGMT":"2025-10-01 20:52:42","modifiedDate":"2026-08-27 15:37:47","modifiedDateGMT":"2026-08-27 15:37:47","commentCount":"0","commentStatus":"closed","categories":{"coma":"<a href=\"https:\/\/www.beeler.tech\/category\/editorials\/\" rel=\"category tag\">Editorials<\/a>","space":"<a href=\"https:\/\/www.beeler.tech\/category\/editorials\/\" rel=\"category tag\">Editorials<\/a>"},"taxonomies":{"post_tag":"<a href='https:\/\/www.beeler.tech\/tag\/below-the-fold\/' rel='post_tag'>Below the Fold<\/a><a href='https:\/\/www.beeler.tech\/tag\/liz-moorehead\/' rel='post_tag'>Liz Moorehead<\/a><a href='https:\/\/www.beeler.tech\/tag\/publisher-pov\/' rel='post_tag'>Publisher POV<\/a><a href='https:\/\/www.beeler.tech\/tag\/the-stack\/' rel='post_tag'>The Stack<\/a>"},"readTime":{"min":11,"sec":11},"status":"publish","excerpt":"Shareholders want growth at all costs, quarter after quarter. That\u2019s why you see the clutter, the clickbait, the short-term revenue plays. No one thinks this is good for the audience, but no one cares. The only story Wall Street wants to hear is growth."}]