Skip to main content
IP Copyright

Creators and Photographers: Prove You Made It Before It Gets Scraped

In short

AI crawlers strip metadata in seconds. Sealing an image at export creates a dated, globally recognized record proving you made it, before it turns up in someone else's feed or training set.

Your image leaves your camera roll once. After that it moves through a phone, a laptop, a content calendar, an Instagram post, a client email thread, and eventually the open web, where an AI crawler can pick it up in seconds. Once it is scraped, screenshotted, reposted, or pulled into a training set, the file that reaches other people rarely still has your name attached to it. EXIF data gets stripped on upload. Compression removes metadata. A repost strips the caption. What is left is a picture that looks like nobody made it.

For photographers and creators, that is not a hypothetical problem anymore. Stock libraries, dataset scrapers, and social aggregators pull images at scale, and a single viral repost can put your work in front of millions of people who have no idea it is yours. If a dispute ever comes up, whether it is a stolen client photo, an AI company that trained on your portfolio, or a competitor lifting your work for their own feed, the question is always the same: can you prove, with a specific date, that the file existed and that you made it.

Under the Berne Convention, copyright protection attaches the moment a work is created, in every one of the treaty's member countries, with no registration required. That is good news in principle. In practice, automatic protection only helps you if you can show, later, exactly when a specific file existed and that it came from you. A JPEG or RAW file with no metadata and no paper trail does not do that on its own. Courts, platforms, and licensing bodies want evidence, not a general legal principle.

This is the gap creators keep running into. The law already protects your work. What is missing is a record, made at the moment of creation, that stands up when someone else claims the image or when an AI system has already trained on it and there is nobody left to ask.

Seal the file the moment you export it, not after it goes viral

The fix is not complicated, but the timing matters. Instead of uploading a finished image and hoping nobody strips the metadata, seal the file the moment you export it, before it goes anywhere. A qualified electronic timestamp, as defined under the EU's eIDAS Regulation, creates a cryptographic record of a specific file existing at a specific moment, issued by a regulated trust service provider. That record does not depend on the platform you post to, and it survives the image being copied, cropped, screenshotted, or reposted a hundred times over, because the seal is tied to the original file, not to whatever caption or metadata happens to travel with a copy of it.

This is the evidentiary base layer under everything else: proof of possession of a specific file at a specific time. It answers the first question anyone will ask you if your work turns up somewhere you did not put it.

Why "recognized in one country" is not good enough anymore

Here is the part that matters most for anyone whose work moves internationally, which is nearly every working creator today. A dispute over a scraped image rarely stays inside one jurisdiction. Your photo might be shot in Zurich, licensed to a client in New York, and scraped by a training pipeline that could be running anywhere. If your only proof of authorship is tied to a single country's registration system, it can leave you stuck arguing jurisdiction before you even get to argue the facts.

A sealed record built on a Swiss qualified timestamp works the other way around. It is built to be globally recognized proof, not a claim that only holds up locally and has to be re-established every time it crosses a border. That asymmetry, proof that travels with the file instead of proof that stops at a border, is the difference between a record you can actually use and one that just sits in a folder looking official.

Making the content itself traceable, without exposing the file

A timestamp proves you had the file. It does not, on its own, help you find out if someone else is using your content, or if an AI system trained on it. That is a separate problem, and it needs a separate piece: a content hash, generated from the image itself and registered into a public, searchable database, following the ISCC (International Standard Content Code) approach. The hash lets your content be matched and tracked for infringement or AI-training licensing purposes without ever exposing the original file to anyone doing the search. Nobody can reverse a hash into your photo. They can only confirm a match against it.

For creators specifically, this is the piece that starts to matter as AI companies face more scrutiny over what they trained on. The EU AI Act requires providers of general-purpose AI models to keep, and in some cases publish, a sufficiently detailed summary of the training data they used. Separately, the EU's Copyright in the Digital Single Market Directive gives rightholders a way to reserve their works from text and data mining under Article 4, provided the reservation is expressed in a machine-readable way. A registered content hash is exactly the kind of machine-readable signal that framework is built around. Sealing the file proves you made it. Hashing the content is what makes it findable later, on your terms.

Tying it to a real person, and building in a way back

None of this is worth much if the proof cannot be tied to an actual, verified human, and if you lose access to your own record the moment you lose a password. Identity verification (KYC) ties the seal and the hash to a specific real person, not an anonymous account or a bot, which matters if you ever need to assert the claim in front of a court or a platform's takedown team. And because losing a device or a credential should not mean losing years of proof, a proper setup includes an escrow recovery path: your identity can be re-verified in person by a local, KYC'd agent even if every digital credential is gone, so the record survives you losing access to it.

Three places this actually shows up

A marketplace or stock site lists your photo under someone else's name. Without a sealed, dated record made before the listing appeared, you are arguing your word against theirs.

A dataset audit, your own or a journalist's, surfaces your work inside an AI training corpus you never agreed to. A registered content hash is what lets you demonstrate the match without handing over your entire portfolio to prove the point.

A client dispute breaks out over who owns the final delivered files after a shoot. A timestamp made at export, before delivery, settles the timeline before it becomes a he-said-she-said conversation.

What this looks like in practice

For a working photographer or creator, the workflow is simple to describe even if the underlying cryptography is not.

  • Finish editing the image.
  • Seal it before you post it, share it with a client, or upload it anywhere, so the timestamp predates every copy that will ever exist of that file.
  • Register a content hash so the image itself, not just your possession of it, is trackable if it turns up in a scraped dataset or a stolen repost.
  • Keep the sealed record somewhere separate from your working files, and make sure the identity behind it is verified, so the proof is not just sitting on the same drive that could get lost or disputed.

This will not stop a scraper from taking your image. Nothing fully does, and anyone promising otherwise is not being straight with you. What it does is put you in a position where, if your work turns up in a place you never put it, you are not starting from zero. You have a timestamped, globally recognized record that the file existed, and a searchable hash that connects it back to you without ever handing over the original.

Swiss Trust Layer is built for creators and photographers who need exactly this: a sealed, verifiable record of a file's existence, tied to a real identity, made the moment the work is finished rather than after it has already been copied a hundred times. If your portfolio, your client deliverables, or your published work has ever ended up somewhere you did not put it, start sealing new work before it leaves your hands and see how the record holds up.

Protect your work with Swiss Trust Layer AG

Seal your intellectual property with a court-proof e-Seal backed by Swisscom Trust Services.

Book a Free Demo

Related Articles

Cloud Storage Isn't Custody: What Identity-Verified Escrow in Switzerland Actually Changes
IP & Copyright

Dropbox, Google Drive, a shared company folder: all of them grant access to whoever holds the login, not to whoever is entitled to the file. Identity-verified escrow works differently. Recovery is tied to a KYC-verified person, held in Switzerland, independent of any cloud provider.

September 25, 2026Read Article →
Where the AI Copyright Cases Actually Stand, and What None of Them Decide for You
IP & Copyright

Four cases get lumped together as "the AI copyright cases." They are not one case, and none of them has ruled on whether training a model on your work without permission is infringement. Here is where Andersen, NYT v. OpenAI, Getty v. Stability, and Bartz v. Anthropic actually stand, and what creators can prove regardless of how or when any of them lands.

September 22, 2026Read Article →
The Moment Before an Engineer Walks Out the Door Is the Moment That Matters
IP & Copyright

IP risk does not start with a resignation letter. It concentrates in the weeks before, in private repos, personal emails, and unmerged branches nobody flagged as company records. Sealing source code, design docs, and prototypes as routine work, not just at launches, is what keeps a startup's ownership provable regardless of who leaves when.

September 21, 2026Read Article →
OpenAI, Google and Nvidia Back Content Credentials. That Still Isn't Evidence in Court
IP & Copyright

Content Credentials now ship from ChatGPT images, from professional cameras and soon from Chrome itself. That makes provenance readable at scale. It does not make a manifest something a court presumes to be accurate about who made a work and when.

September 17, 2026Read Article →
The AI Act Makes Your Opt-Out Their Obligation. It Still Isn't Your Proof
IP & Copyright

The EU AI Act tells model providers to go looking for your opt-out and to respect it once they find it. That obligation is real and it is theirs. What it can't do is answer the question a dispute puts to you: what did you make, and when.

September 15, 2026Read Article →