Skip to main content
IP Copyright

A Timestamp Proves a File Existed. It Doesn't Prove Who Made It. Now the Gap Is Closed.

In short

A qualified electronic timestamp proves a file existed, unaltered, at a given moment. It has never proven who made it. MyCopyright closes that second gap by binding the sealed record to a passport-verified identity, so a dispute that turns on who, not just when, has an answer.

A Timestamp Proves a File Existed. It Doesn't Prove Who Made It. Now the Gap Is Closed. — Swiss Trust Layer

Priya runs a two-person design studio out of Zurich. In June 2026 she sent a client a full icon set and packaging concept for a beverage launch, sealed the working files the same afternoon, and waited for a signed contract that never quite arrived. In August the client shipped the packaging under a different name, credited to an in-house designer who joined the team in July. Priya still had her sealed file. Its qualified timestamp showed, beyond argument, that the exact set of icons existed on her machine on the date she said it did. What it could not do, on its own, was tell anyone that Priya, specifically, was the person who made it.

A qualified electronic timestamp proves two things and only two things: that a given file, byte for byte, existed at a specific moment, and that nothing about it has changed since. It does not carry a name. It was never built to. Under eIDAS Article 41, a qualified timestamp enjoys a legal presumption of the accuracy of that date and the integrity of that data, which is a real and useful thing to hand a court. It says nothing about who held the file, who created it, or who is standing behind the claim. That second question, who, is the one MyCopyright on Swiss Trust Layer answers, by binding the sealed record to a passport-verified identity rather than leaving it to sit next to an unlabelled file.

What a qualified timestamp actually proves

The mechanism behind a Swiss Trust Layer seal is a qualified electronic timestamp: the file is hashed, the hash is time-stamped by a qualified trust service, and the result is bound to the exact byte sequence of the file at that moment. Change one pixel of Priya's icon set afterward and the hash no longer matches; the seal breaks visibly rather than silently. Under eIDAS Art. 41, that qualified timestamp is presumed accurate as to date and time, and the data it covers is presumed intact, across all EU member states. That presumption is why a sealed file holds up better in a dispute than an email attachment or a cloud-storage "last modified" date, which carry no such legal weight and can be altered without leaving a visible trace.

None of this, however, answers who. A timestamp is bound to a file, not to a face, a passport, or a legal name. Two people could each hold a sealed copy of the same working file and the timestamp alone would not distinguish between the one who made it and the one who received it in an email and sealed it an hour later. That gap sat open on Swiss Trust Layer for as long as sealing existed without an identity layer attached to it.

The gap nobody mentions: existence without identity

This is not a flaw specific to Swiss Trust Layer. It is true of every timestamping standard, every notarization stamp, and every blockchain hash anyone has ever pointed a creator toward. A cryptographic proof of existence tells a court when a file was in a particular state. It was never designed to tell a court whose hands it passed through, and creators who lean on "I timestamped it" as their whole case are answering half the question a dispute actually asks. A Swiss IP dispute that turns on exactly this gap, who made it versus when it existed, commonly runs into six figures before it settles: industry estimates from the Swiss Arbitration Association put the average cost of a Swiss IP dispute at CHF 150,000 to 400,000, largely because so much of the fight is spent establishing facts that a stronger record would have settled on day one.

Priya's file existing on a given date was never in dispute once she produced the certificate. What she had no way to prove, cheaply and in advance, was that the file was hers to begin with, made by her hands, under her name, and not simply passed to her by someone else moments before sealing.

How the register closes it: a passport check binds the seal to a person

MyCopyright, open on Swiss Trust Layer this week, adds the missing half. Alongside the qualified timestamp and the file hash, a user completes a KYC identity check: a technical procedure that verifies a natural person using their passport document and the security features it carries, run by Swisscom Trust Services rather than by Swiss Trust Layer itself. That check happens once, tied to the account, and from that point every sealed record the account produces carries both proofs together: the file existed, unaltered, at this moment, and this specific, passport-verified person is the one who sealed it. Neither proof substitutes for the other. A timestamp without an identity is a fact about a file with nobody attached. An identity without a timestamp is a person with no record of what they made or when. Held together, the two answer the question a dispute actually asks: not just when, but who.

None of this touches the separate content-label system for disclosing AI involvement in a piece of work, which is its own set of rules and gets its own explanation another day. The identity check described here is about who is standing behind a sealed record, independent of how the underlying content was produced.

What this looks like end to end

  1. Seal the file. Upload the finished work to Swiss Trust Layer. The platform hashes it and applies a qualified electronic timestamp, presumed accurate under eIDAS Art. 41, bound to that exact file state.
  2. Complete the identity check once. The KYC process verifies the account holder against their passport document, run by Swisscom Trust Services. It is done once per account, not once per file.
  3. Every later seal carries both. From then on, each sealed record produced by that account holds the timestamp for the file and the verified identity of the person behind it, together, in one certificate.

Had MyCopyright existed when Priya sealed her icon set, the certificate her lawyer sent the client would not have stopped at "this file existed on this date." It would have said, in the same certificate, that the file existed on that date and that a passport-verified Priya, not an anonymous account, was the one who produced it. That second sentence is the one that turns a technical fact into a claim nobody on the other side of the table can wave away. A timestamp gets you halfway there. The register was built to close the rest of it.

See what the register actually records in the MyCopyright launch post, or read the full mechanism on how it works.

Protect your work with Swiss Trust Layer AG

Seal your intellectual property with a court-proof e-Seal backed by Swisscom Trust Services.

Book a Free Demo

Related Articles

Where the AI Copyright Cases Actually Stand, and What None of Them Decide for You
IP & Copyright

Four cases get lumped together as "the AI copyright cases." They are not one case, and none of them has ruled on whether training a model on your work without permission is infringement. Here is where Andersen, NYT v. OpenAI, Getty v. Stability, and Bartz v. Anthropic actually stand, and what creators can prove regardless of how or when any of them lands.

September 22, 2026Read Article
The Moment Before an Engineer Walks Out the Door Is the Moment That Matters
IP & Copyright

IP risk does not start with a resignation letter. It concentrates in the weeks before, in private repos, personal emails, and unmerged branches nobody flagged as company records. Sealing source code, design docs, and prototypes as routine work, not just at launches, is what keeps a startup's ownership provable regardless of who leaves when.

September 21, 2026Read Article
OpenAI, Google and Nvidia Back Content Credentials. That Still Isn't Evidence in Court
IP & Copyright

Content Credentials now ship from ChatGPT images, from professional cameras and soon from Chrome itself. That makes provenance readable at scale. It does not make a manifest something a court presumes to be accurate about who made a work and when.

September 17, 2026Read Article
The AI Act Makes Your Opt-Out Their Obligation. It Still Isn't Your Proof
IP & Copyright

The EU AI Act tells model providers to go looking for your opt-out and to respect it once they find it. That obligation is real and it is theirs. What it can't do is answer the question a dispute puts to you: what did you make, and when.

September 15, 2026Read Article
A German Appeal Court Threw Out a Copyright Opt-Out Because a Machine Couldn't Read It
IP & Copyright

A notice in your terms of use tells a human reader you object to AI training. A German appeal court has held that a reservation in that form doesn't satisfy Article 4(3) DSM, because the crawler it addressed was never able to read it.

September 14, 2026Read Article