Editorial Series: The Trust Stack: Architecture, Identity & the Battle for Authentic Media — Part IV of V
Target Question: How can people tell what humans and AI contributed—and what each participant may do?
Direct Answer: Identity tells us who or what is acting. Provenance records origin and history. Authenticity tells us whether evidence is credible. None grants authority. Trustworthy human–AI systems need explicit capabilities: permission for a specific actor to perform a specific action on a specific asset, within limits, until expiry or revocation—checked again where the action becomes consequential.
The internet is learning to attach receipts to media. Content Credentials can record who signed an asset, which tools touched it and which transformations were declared. Verifiable credentials can package claims in tamper-evident form. Secure capture can strengthen the first link in the chain.
These advances are easy to overread. A receipt can show that a camera captured an image; it cannot decide whether a publisher may distribute it. A credential can identify a person; it cannot decide whether that person may license a likeness. A provenance trail can record AI participation; it cannot decide whether the output may train another model.
The missing question is not only “What happened?” It is “What may happen next?”
A “verified” badge often collapses six ideas:
C2PA says valid provenance does not establish that content is true. W3C Verifiable Credentials likewise says verifiability does not make the claim true; a verifier still applies policy. These limits show where provenance ends.
“Human-made” and “AI-generated” are too crude. A work may be human-captured, AI-denoised, editor-approved and institution-published. A better record can express human.captured, human.authored, human.approved, ai.assisted and ai.generated.
These claims preserve contribution without pretending every contribution grants a right. “Human approved” says approval occurred. It does not prove the approver had authority, that approval covered this distribution or that it remains valid.
Provenance claims describe context. Capabilities govern action.
A capability makes the operating agreement inspectable:
OAuth Rich Authorization Requests (RFC 9396) supports structured authorization; its payment example specifies action, amount, currency and recipient. The HCI move is to make that precision understandable. “Allow access” is not enough. “Allow this agent to publish this approved version to two channels before Friday, with no paid promotion” is closer to meaningful consent.
Permission should not be checked once and remembered forever:
The system executing an action must enforce the rules. A polished interface cannot compensate for a backend that treats old approval as ambient authority. Before execution, people should see what will happen, which authority permits it, what could exceed scope and how to stop or revoke it.
An Authority Layer can bind human-readable intent to machine-enforceable capability. APP can help agents request, carry and prove scoped authority. It should complement—not replace—identity and provenance: C2PA describes asset history; a credential conveys a claim; the authority layer answers whether a proposed action is permitted now.
Blockchain is optional. It may help when parties need a shared revocation, rights or settlement record without one operator. If one accountable service can enforce policy, a signed registry may be simpler. The requirement is explicit authority, not a chain.
Capability systems add complexity. People can approve carelessly. Policies can encode unfair power. Revocation may not undo distributed copies. Offline systems may use stale state. Interoperability can fail.
Use plain-language scope first, precise details when needed, safe defaults, short lifetimes and visible history. Reusable policies should cover low-risk actions; interruption belongs at exceptions and irreversible consequences.
The badge is not useless. It is incomplete.
Good human–AI interaction cannot stop at telling people what happened. It must show who may act, on what, for how long and under which limits—and let people withdraw authority before the next consequential step.
A badge preserves context. A capability governs action.
A model where origin records (provenance) are coupled with explicit, scoped, time-bound, and revocable permissions (capabilities) governing what actors may do with an asset.
No. Content Credentials and C2PA manifests record origin and transformation history; they do not convey authorization or legal permission to distribute, license, or execute actions.
Identity proves who or what an actor is. Authority specifies what that actor is permitted to do in a specific context on a specific asset.
No. Blockchain is optional for multi-party decentralized settlement or public revocation, but signed registries and centralized policy enforcement layers can execute capability checks without a distributed ledger.
© Gerardo I. Ornelas
Systems architect, founder, and advisor for governed AI and trusted visibility.