For AI companies & generative-AI builders

Provenance you can prove,
not just declare

AI companies that build models and generative products have to show two things: how a given piece of content was made, and what a model was trained on with the right to use it. Swiss Trust Layer applies a qualified electronic seal and a qualified timestamp to the records behind those claims, so an output log, a training-data manifest, a licence or a consent record becomes a dated, tamper-evident version rather than a statement after the fact.

Under EU AI Act Art. 50 , generative-AI providers must mark AI-generated content in a machine-readable way and deployers must disclose it. Those transparency obligations apply from 2 August 2026. From that date, an unsupported claim is not on its own a compliance answer.
What Article 50 requires, in full →

Provenance record sealed

Tamper-evident, dated e-Seal

Valid
Output / recordMarked + logged
Training-data manifestSealed + dated
TimestampQualified, RFC 3161
IntegrityTamper-evident

The point: provenance you can prove in front of a regulator, not just declare.

What an AI company actually has to prove

A model or app builder now sits under two kinds of scrutiny at once. Regulators want AI output marked and disclosed. Rights holders, partners and courts want to know what a model was trained on and whether the company had permission to use it. Both questions come back to records, and records are only as good as the proof that they existed on a given date and were not changed later.

Across a normal build cycle that means keeping defensible records of:

  • Output logs that tie a generated result to a dated record
  • Training-data manifests that list the datasets behind a model version
  • Licences and rights agreements covering that training data
  • Consent records for voice, likeness or image used in a product
  • Model cards and technical documentation, version by version

Each of these can be questioned later by a regulator, a rights holder or a court. That is why the way a record is fixed matters as much as the record itself.

What "trust me, we made it" costs you

The transparency test

From 2 August 2026, the transparency obligations in the EU AI Act require generative content to be marked and disclosed, and they sit alongside a growing expectation that AI companies can show what a model was trained on. A record with an editable date field and no independent proof does not clear that bar on its own.

EU AI Act Art. 50 (Regulation (EU) 2024/1689) · transparency obligations apply from 2 August 2026

When a record cannot be independently trusted, the cost lands in three places:

  • A provenance claim backed only by an internal note or an editable file can be challenged, which puts the company in a weak position with a regulator or a rights holder.
  • Without a qualified timestamp, proving that a manifest or a consent record existed on a given date and was not altered afterwards falls back on server logs and testimony, which is slow and uncertain.
  • C2PA metadata on its own can be stripped or re-created, so a provenance signal that travels with the file may simply not be there when someone needs to check it.

A qualified timestamp under eIDAS Art. 41 carries a legal presumption of the time and integrity of the data. That presumption shifts the burden of proof to whoever disputes the record.

C2PA metadata alone vs a sealed record

C2PA content credentials and a sealed record are not rivals. C2PA describes how content was made and travels with the file. A qualified seal and timestamp add the part C2PA does not provide on its own: a tamper-evident, dated record that holds when someone has a reason to question it.

What matters for provenanceC2PA metadata aloneSwiss Trust Layer sealed record
Tamper-evidentSelf-asserted, can be re-createdCryptographically sealed, tamper-evident
Carries a legal presumptionNoQualified timestamp, eIDAS Art. 41
Independently court or regulator verifiableNot by itselfYes, by any PDF reader or court expert
Survives metadata strippingNo, metadata can be removedYes, the proof lives in the sealed record
Dated proof the record existedNot binding on its ownQualified timestamp fixes the date

Complements C2PA, does not replace it

Keep publishing C2PA content credentials on your content. Seal the underlying records so that when the metadata is stripped or disputed, you still hold a dated, tamper-evident version under ZertES SR 943.03 and eIDAS. See the compliance hub.

How Swiss Trust Layer fits your workflow

Swiss Trust Layer does not run its own cryptographic key infrastructure. Every seal is backed by Swisscom Trust Services, an accredited qualified trust service provider in Switzerland.

Step 01

Upload the record

An output log, a training-data manifest, a licence set or a consent record. The original file stays under your control the whole time.

Step 02

Seal and timestamp

A qualified electronic seal and a qualified timestamp are applied through Swisscom's accredited trust service infrastructure.

Step 03

Verifiable proof

The sealed record carries the seal, the timestamp and long-term validation data, verifiable by any PDF reader or court expert.

The sealing uses PAdES and CMS formats, international standards defined by ETSI and recognised across jurisdictions. This is cryptographic proof, not a signature image or a metadata tag, so a court expert or any PDF reader can verify it independently, now and in the future.

Primary sources: EU AI Act, Regulation (EU) 2024/1689 · C2PA specification · eIDAS Regulation 910/2014 · ZertES SR 943.03 (fedlex.admin.ch)

Where sealed provenance pays off

The same qualified seal covers the records an AI company is most likely to be asked about, from a single generation log to the licence set behind a whole model.

Model output and generation logs

Seal a log of what a model produced, with a qualified timestamp that fixes when the record existed, so an output can be traced back to a dated, unaltered record rather than a claim after the fact.

Training-data manifests

A sealed manifest of the datasets behind a model version gives a tamper-evident record of what the model was trained on and when that record was fixed, useful when a regulator or counterparty asks.

Licence and rights records

Seal the licences and rights agreements that cover your training data. A dated, tamper-evident record shows you held the right to use the material at the time the model was built.

Consent records

For voice, likeness or image used in a generative product, a sealed consent record proves you had permission, with a qualified timestamp for the date consent was given.

Model cards and documentation versions

Seal each version of a model card or technical documentation so there is no later argument about which version was published or relied on at a given point.

Audit and regulator response

When an authority or partner asks how a piece of content was made or what a model was trained on, a sealed, dated record answers with evidence rather than an internal note.

Backed by Swisscom Trust Services

Accredited qualified trust service provider

ZertES and eIDAS

Qualified seal and timestamp with legal presumption

Complements C2PA

Tamper-evident record beneath the metadata

AI provenance, common questions

What does the EU AI Act require AI companies to do about AI-generated content?

Under Article 50 of the EU AI Act, providers of generative AI must ensure AI-generated output is marked in a machine-readable way, and deployers must disclose content that is AI-generated or manipulated. These transparency obligations apply from 2 August 2026. Swiss Trust Layer does not make a company AI Act compliant, but a sealed, timestamped record is defensible evidence that supports these transparency and provenance obligations.

Do C2PA content credentials meet the requirement on their own?

C2PA content credentials carry provenance metadata and help show how content was made, but on their own they are not tamper-proof legal proof. The metadata can be stripped from a file or re-created, and it is self-asserted, so a court or regulator does not recognise it as binding evidence by itself. A qualified seal plus a qualified timestamp complements C2PA by adding a tamper-evident, dated record that does not depend on metadata staying attached.

How does a sealed record help with training-data provenance?

AI companies increasingly need to show what data a model was trained on and that they had the right to use it. Sealing a training-data manifest or a licence set produces a dated, tamper-evident version of that record. If the question comes up later, you can show when the record existed and that it was not altered, which is stronger than a document with an editable date field.

Does a sealed record make my company AI Act compliant?

No. Compliance depends on how you build, document and disclose your systems across the whole regulation. What a sealed, timestamped record does is give you defensible evidence for the transparency and provenance parts: a dated, tamper-evident record of an output log, a training-data manifest, a licence or a consent record. It supports the obligation, it does not replace the wider compliance work.

How is a qualified timestamp different from just saving a file with a date?

A file date or a metadata field can be edited, and it is self-asserted, so it carries little weight if someone disputes it. A qualified timestamp under eIDAS Article 41 carries a legal presumption of the time and integrity of the data, which shifts the burden of proof to whoever challenges the record. That is the difference between an internal note and admissible evidence.

Seal the records behind your model

Create an account and seal your first record in minutes, or book a short setup call and we will walk through how it fits your provenance and disclosure workflow.

Want the timestamp detail? How qualified timestamps work→

Quick Answers

What does the EU AI Act require AI companies to do about AI-generated content?

Under Article 50 of the EU AI Act (Regulation (EU) 2024/1689), providers of generative AI must mark AI-generated output in a machine-readable way, and deployers must disclose content that is AI-generated or manipulated. These transparency obligations apply from 2 August 2026. From that date, an unsupported claim that a company made a given piece of content is not on its own a compliance answer.

Are C2PA content credentials enough on their own?

C2PA content credentials help by carrying provenance metadata, but on their own they are not tamper-proof legal proof. C2PA metadata can be stripped from a file or re-created, and it is self-asserted, so it is not something a court or regulator recognises as binding evidence by itself. A qualified electronic seal plus a qualified timestamp complements C2PA by adding a tamper-evident, dated record.

How does a sealed record help prove training-data provenance?

AI companies increasingly need to show what data a model was trained on and that they had the right to use it. A qualified electronic seal and qualified timestamp on a training-data manifest, a licence set or a consent record produce a dated, tamper-evident version that fixes when the record existed and shows it was not altered afterwards. That is defensible evidence supporting transparency and provenance obligations.