Over the past month we worked through qualified signing from several directions: what the workflow involves, how timestamps carry evidential weight, where AI provenance rules are heading, and how proof of authorship works in places where qualified signing is not available. This brings those threads together.
If you read nothing else, read the next section. Most confusion about electronic signatures comes from treating four different things as one thing.
Four instruments, four jobs
A qualified electronic signature identifies a person and expresses their intent to be bound. It is the electronic equivalent of signing your name. Under Article 14 paragraph 2bis of the Swiss Code of Obligations, a qualified electronic signature is equivalent to a handwritten signature, and eIDAS establishes the same position across the EU.
A qualified electronic seal identifies an organisation rather than a person. It answers the question of which entity issued a document. Seals matter for anything issued in a company's name over long periods, such as certificates, statements, and announcements, because they survive staff turnover.
A qualified timestamp establishes when a document existed in a specific form. It says nothing about who signed it or whether they agreed to it. Its job is time, and under eIDAS it carries a legal presumption as to the accuracy of the date and time it records.
Copyright proof is different again. Copyright arises automatically on creation under the Berne Convention, in every member state, without registration. You already hold the right. What you usually lack is evidence of when you created the work, and a sealed timestamped record supplies that.
These are answers to different questions. A signature does not prove a date. A timestamp does not prove agreement. Choosing the wrong one is how organisations end up with documents that look protected and are not.
Which one do you need
Start from what would be disputed.
- If someone might deny agreeing to terms, you need a signature.
- If someone might question whether your organisation issued a document, you need a seal.
- If someone might claim you produced something later than you say, you need a timestamp.
- If someone might claim your work is theirs, you need dated proof of creation.
Many documents need more than one. A sealed certificate combines a seal and a timestamp. A signed contract that may later be challenged on timing combines a signature and a timestamp. We walked through how these assemble in the qualified signature workflow, start to finish.
Why qualified is not the same as electronic
Most electronic signature tools produce something legally weaker than a qualified signature, and the difference only becomes visible under challenge. A basic electronic signature is admissible but carries no presumption, which means the party relying on it has to prove it is genuine. A qualified signature reverses that: the presumption operates in its favour, and the party disputing it carries the burden.
That distinction is the entire practical argument, and we set it out in what happens when a signed contract is challenged and compared the tooling in DocuSign versus qualified signing. Not everything needs qualified treatment. We looked at where basic signing is genuinely sufficient in five documents that only need basic e-signatures.
Time, and why it is treated separately
Timestamps get less attention than signatures and carry more weight than people expect. The reason is that a timestamp from an accredited authority is evidence produced by a third party with no interest in the outcome, which is a materially different thing from a date recorded by the party relying on it.
We covered the evidential mechanics in what a qualified timestamp does to the burden of proof, and addressed a common substitute in blockchain timestamps versus qualified signatures. The short version on blockchain: anchoring a hash to a public chain proves a document existed, but it does not identify a signatory, and it does not carry the statutory presumption that a qualified timestamp does under eIDAS.
Provenance, AI, and what is arriving
The largest change this year is not to signing but to disclosure. EU AI Act Article 50 introduces transparency obligations for AI generated content, taking effect on 2 August 2026. Organisations producing synthetic media will need to mark it, and the practical question becomes how that marking is evidenced.
Content credentials are part of the answer and not all of it, which we examined in why C2PA content credentials are not enough on their own. Credentials travel with a file and can be stripped from it. A sealed, timestamped record does not depend on the file retaining its metadata.
Where qualified signing is not available
Qualified signatures depend on accredited providers operating under a recognised legal framework, and that infrastructure does not exist everywhere. Copyright proof does, because Berne membership is close to universal. That asymmetry is genuinely useful for anyone operating across markets, and we set it out in why copyright proof works even where qualified signing does not. For the UAE specifically, we covered the local position in signing legally in the UAE with UAE Pass.
The one thing worth doing
Pick the document type in your organisation that would cause the most damage if its authenticity, authorship, or date were successfully disputed. It is usually not a contract. It is often a certificate, a drawing set, a specification, or a published statement, which is where we ended this month with verifiable certificates and sealed announcements.
Then ask what you could actually prove about it today, using evidence that does not depend on your own systems. That gap is the work.
You can verify any sealed document at swisstrustlayer.com/validate, without an account.





