T09-L05

Create media · Operator

Scale, provenance and rights

Your marketing team publishes an AI-generated image of a person who does not exist. A colleague asks whether the image is labelled, which model produced it, whether the model and reference inputs permitted commercial use, and who approved publication. The exported JPEG contains no visible answer. The generation...

Level
OperatorLevel 5 of 5
Curriculum position
Family 1 · Track 09
Reading time
60 minutes
Reading progress
0%Time on this book
Last revised
Sep 5, 2026

2. The image is public, but the decision is missing

Your marketing team publishes an AI-generated image of a person who does not exist. A colleague asks whether the image is labelled, which model produced it, whether the model and reference inputs permitted commercial use, and who approved publication. The exported JPEG contains no visible answer. The generation history belongs to a former contractor, and the website's image processor may have removed the original metadata.

In the Lab version, the same gap appears when a generated illustration moves from an internal Aster-9 talk into a public paper draft. Nobody intended deception, but readers could mistake the image for observed apparatus or evidence. One missing record now delays communications, publication, and legal review across the team.

At Level 5 Operator, an attractive file is not a releasable asset. You need a policy that classifies the use, proves the rights decision, attaches and verifies provenance, places an understandable disclosure in the final context, names an approver, and still works after the original creator leaves.

3. After this you can

  • Attach verifiable provenance metadata to generated media and retain a durable external record when a channel strips it.
  • Classify synthetic media by portrayal, audience, purpose, jurisdiction, and channel before choosing a disclosure.
  • Decide whether model terms, reference rights, consent, and the intended publication licence support release.
  • Enforce one approval path for external media, including failed-metadata and emergency-withdrawal branches.
  • Hand over the policy and verify it against one actual, safely sourced asset set.

4. Prerequisites

  • T09-L04 · Self-hosted media models, including exact model revisions, source mapping, reviewed outputs, and license checks.
  • T12-L05 · Governance, evidence and handover, including inventory, risk ownership, audit evidence, retention, and the author-has-left test.
  • One actual set of 3–5 related images, audio clips, or videos made from public, synthetic, or explicitly approved inputs. The fictional Aster-9 or Northstar Desk set from T09-L02 is suitable.
  • An approved media editor or generation service and, where available, an approved provenance-capable export or signing route with a current organisation-approved inspection method. Adobe Firefly and C2PA implementations are catalogued options, not required tools or taught workflows in this book.
  • A media owner, rights reviewer, publication approver, technical operator, and substitute operator. One person may fill several roles only if your governance permits it; nobody approves their own unresolved rights exception.
  • Permission to test one staging copy through the real export or publication transformation without making it public, plus about 60 minutes.

Use no participant image, patient material, collaborator manuscript figure, customer asset, employee likeness, voice, logo, unreleased campaign, licensed reference, or confidential prompt unless an accountable owner has explicitly approved that input and this exact transformation and channel. The worked example uses only synthetic geometry and fictional names. Do not create a realistic person merely to test disclosure.

5. The idea in one page

A publication decision has four independent layers. None substitutes for another.

LayerQuestion that must be answeredEvidence
ProvenanceWhat file, process, actor, and edits produced this asset?Signed provenance manifest where supported, output hash, source and run references
DisclosureWhat must the audience understand in this final context?Approved visible or audible wording, placement, language, and channel test
RightsMay these inputs, tools, outputs, and portrayals be used this way?Exact terms and licences, reference permissions, consent, ownership and territory decision
ApprovalWho accepts the remaining risk and can stop or withdraw release?Named approver, dated decision, conditions, expiry, and withdrawal route

Provenance is a chain of claims, not a truth certificate. Signed provenance systems can cryptographically bind a manifest to media and record assertions about origin and edits; C2PA Content Credentials are one catalogued standard for doing so. Verification can show whether that binding remains valid and which signer made the claim. It does not establish that a depicted event happened, that a reference was licensed, that a person consented, or that the signer was honest. Trust the claim only to the extent that you trust its signer and evidence.

Embedded provenance is valuable but fragile in delivery. Re-encoding, screenshots, social platforms, document conversion, copy-and-paste, or an optimisation service may remove or invalidate it. Keep an external release record keyed by the final file's SHA-256 hash, and test the exact channel output. If embedded credentials are lost, the policy either blocks publication or permits a documented fallback: visible disclosure plus the external record and a repair owner. It must never silently call missing metadata “verified.”

Disclosure is contextual. “Made with AI” may be insufficient when the important fact is that a realistic person, voice, event, place, result, or product demonstration is synthetic. Put disclosure where the audience encounters the media; a hidden metadata field is not a visible label. Use plain language, preserve it in crops and reposts, and add accessible text or an audible statement where needed. A generated abstract divider and a realistic synthetic executive video do not deserve the same review tier.

Rights do not collapse into one model licence. Check the generation service terms or exact model-weight licence, the code licence where relevant, every reference and training/customisation input, likeness and voice consent, trademarks and depicted works, output terms, employer or contractor ownership, and the licence you intend to grant downstream. “Open weights,” “royalty-free,” a paid plan, and possession of a file are not blanket permissions. A non-commercial restriction blocks commercial use even when the software around the model is permissively licensed.

Indemnification is contractual risk allocation. Its scope may depend on the product, account, territory, approved features, notice, cooperation, exclusions, caps, and unmodified use. It does not create rights in an input, guarantee copyright in an output, cure missing consent, or make a prohibited use permissible. Record the exact agreement and the contract owner's interpretation; never replace the rights review with a vendor marketing sentence.

Current-law check — last verified 2026-09-04: Rules depend on jurisdiction, role, content, purpose, and publication date. The EU AI Act transparency regime is in application, and Article 50 distinguishes provider duties to mark certain generated outputs in machine-readable form from deployer disclosure duties for deepfakes and certain public-interest text, with stated qualifications and exceptions. An invented-person marketing illustration is not automatically a “deep fake” under every definition merely because it is synthetic. Check the current consolidated text, Commission guidance, local law, platform rules, advertising rules, research or publisher policy, and your organisation's counsel for the actual asset. The policy below adopts a broader operational disclosure floor; it is not a legal conclusion.

6. The worked example: one release gate that survives export

Create one document named media-policy-and-application.md. It is the single artifact for this book. It contains the policy first and its completed application to one actual set second. References may point to controlled evidence files, but do not split the finding into separate policy and audit artifacts.

Write the policy header before reviewing assets

Copy and complete this header:

Policy ID and revision: MEDIA-RELEASE-1 / [revision]
Policy owner: [role and named owner]
Rights reviewer: [role and named owner]
Publication approver: [role and named owner]
Technical provenance operator: [role and named owner]
Substitute operator: [role and named owner]
Applies to: generated or materially AI-altered image, audio, and video
Channels: internal, conference, publication, website, social, advertising, press
Jurisdictions/audiences reviewed: [record]
Effective and next-review dates: [record]
Primary legal/policy sources checked with dates: [URLs or controlled references]
Stop authority: any reviewer may hold; only the approver may release
Withdrawal owner and route: [record]
Evidence location and retention: [authorised location and period]

The next review date matters because legislation, platform labels, publisher rules, model terms, and signing trust lists change. A policy copied forever is not an operating control.

Establish a risk route

Use this minimum classification in both framings:

RouteTrigger examplesRequired outcome
A: internal draftClearly illustrative, no realistic identity or factual implication, approved inputsRecord provenance and rights; mark draft; no external release
B: ordinary externalAbstract generated illustration or edited asset with no realistic portrayalRights pass, metadata attempt and verification, visible contextual disclosure, named approval
C: heightened portrayal or claimRealistic person/voice, real place or event, public-interest content, advertisement, scientific/result-like image, material synthetic alterationSpecialist rights/legal or research-integrity review, explicit disclosure design, consent and claim evidence, senior approval
D: prohibited or unresolvedNon-commercial model for commercial channel, unclear reference rights, missing consent, deceptive evidence, unverifiable owner, prohibited model useDo not publish; replace inputs, regenerate on an approved route, or abandon the asset

The policy states that external publishing tools accept only approved assets from the release register. A generation folder, chat download, local reviewed-output folder, or cryptographically valid provenance record is not itself an approved source. Bulk publishing must fail closed when the register row, final hash, disclosure, or approver is missing.

Build the rights decision in layers

For every asset family, complete one rights matrix before attaching a publication licence:

Asset IDs and final channel:
Creator/contractor and employment assignment:
Generation service, account/plan, feature, model or exact weight revision:
Service terms or weight licence URL, version/date checked, permitted use:
Code licence if self-hosted:
Reference/input IDs, creators, licences or permission records:
Person/voice/likeness present? Consent scope and record, or not applicable:
Marks, products, artworks, locations, datasets, or factual claims depicted:
Human-authored contributions and editable master:
Output ownership/use-rights conclusion by jurisdiction:
Publication licence offered to the audience:
Indemnity agreement reference, scope owner, exclusions noted:
Decision: pass / hold / prohibited
Reviewer, date, conditions, and recheck trigger:

Do not say that the model licence automatically “passes through” to every output. Some licences regulate model use; some service terms allocate output rights; input rights remain separate; copyright status can vary by jurisdiction and the extent of human authorship. If the organisation cannot confidently license an output under the intended terms, publish under narrower terms that it can support, obtain advice, replace the asset, or do not publish.

Attach provenance, then verify the delivered bytes

Retain the T09-L02/T09-L04 source record: stable asset ID, source or prompt references, exact model/service route, settings, generation time, editor actions, reviewers, and hashes. Before external release, use the organisation-approved provenance route to attach a signed manifest to the final master where that route supports one. At minimum, the record should communicate that the asset is AI-generated or AI-edited, identify the responsible organisation or approved signer, record the creation tool or action without exposing secrets or personal prompt content, and link to a safe policy or provenance record where supported.

Do not place private prompts, participant identifiers, customer names, local paths, credentials, or confidential model details in public metadata. Signed metadata can make an accidental disclosure durable.

Use an organisation-managed signing identity and key lifecycle for production. A development certificate is acceptable only for an isolated interoperability test and must not be represented as a publicly trusted production signature. Record tool version, trust configuration, certificate owner, expiry, rotation, revocation route, and the operator allowed to sign.

Inspect the final master with the current approved verifier. Record the implementation and version, and retain its complete inspection result. If the approved route exposes a command-line interface, follow the current documentation for that installed release rather than copying a command from this book. C2PA implementations, including c2patool, are catalogued examples only; neither they nor Adobe Firefly are required to complete the policy exercise. A passing record identifies the asset, manifest or equivalent record, assertion about generated or edited content, signer or trust result, and validation status. Preserve warnings; do not paraphrase them into “valid.” Compute SHA-256 for the exact signed file using an approved platform tool and enter it in the release register.

Now send a staging copy through every transformation used by the real channel: resize, crop, document insertion, website optimisation, video transcode, or social scheduler. Download the delivered result, hash it, and inspect it again. Record one of these exact outcomes:

embedded-valid | embedded-present-with-warning | embedded-absent | invalid

If it is absent or invalid, stop and apply the policy's approved fallback. The external record must identify the delivered hash and its relationship to the signed master. Keep the visible disclosure attached to the media. Escalate a transformation that repeatedly strips credentials to the channel owner rather than teaching publishers to ignore the check.

Lab framing: public Aster-9 figure set

Apply the policy to 3–5 actual Aster-9 geometric illustrations created in T09-L02 or regenerated through the controlled route from T09-L04. They contain no people, real apparatus, measurements, paper excerpts, journal marks, or findings. The intended channels are a public talk and a manuscript draft.

Classify the set as Route B, unless a realistic edit or result-like composition raises it to Route C. The rights matrix records the original synthetic geometry references, exact generation route and terms, editor's human layout and labels, institutional ownership rule, and intended publication terms. The research-integrity reviewer confirms that captions call the images illustrations and that no figure is numbered or described as experimental evidence.

Use a visible caption such as:

AI-generated conceptual illustration for the fictional Aster-9 workflow;
not experimental apparatus, data, or a research result. Reviewed [date].

The policy does not claim that disclosure makes fabricated evidence acceptable. A generated gel, microscopy field, participant image, instrument trace, or result-like chart enters Route C or D and must follow the journal, institution, funder, discipline, and legal rules for that actual use. When a publisher strips metadata, retain the signed master and delivered-file hash in the release record, keep the caption in the manuscript, and record the publisher transformation outcome.

Company framing: public Northstar Desk asset set

Apply the same skeleton to 3–5 actual Northstar Desk geometric assets from T09-L02. They contain no person, customer, product screenshot, logo, testimonial, certification, or performance claim. The intended channel is a public fictional product-concept page, not a real offer.

Classify the set as Route B. The rights matrix checks the exact service or weight terms for commercial-facing use, the synthetic reference board, contractor assignment if any, output rights, and the terms under which site visitors may reuse the image. The approver verifies that “fictional product concept” remains visible and that no crop implies a released feature.

Use a contextual disclosure such as:

AI-generated conceptual illustration using an original synthetic reference kit.
Northstar Desk is a fictional product concept; no person or customer is depicted.

If the team instead proposes a photorealistic spokesperson, cloned voice, customer scene, real product demonstration, news-like event, or testimonial, move it to Route C. Require specific portrayal consent where a real identity is involved, check advertising and platform rules, test accessible and persistent disclosure, and obtain the named heightened approver. An invented person still needs a deception and advertising review; inventing the face does not make every presentation harmless.

Complete the release register and handover test

For each final asset, add one row to the application section:

FieldRequired recorded value
IdentityAsset ID, set ID, final filename, final-master hash, delivered hash
OriginSource/reference IDs, generation route and date, model/service revision where exposed, edit summary
RightsTerms/licence references and dates, input permissions, consent status, intended licence, reviewer decision
DisclosureExact wording, placement, language/accessibility check, crop/repost behavior
ProvenanceSigning route, signer, inspection outcome for master and delivered copy, warning or fallback
ApprovalRisk route, channel, approver, decision date, conditions, expiry/recheck trigger
OperationsEvidence location, retention, withdrawal route, owner, last channel recheck

Finish with two tests. First, deliberately export one staging copy through a metadata-stripping transformation. The gate must mark it embedded-absent and block or invoke the written fallback; it must not pass because the pixels look identical. Second, give the document to the substitute operator. Without asking the creator, they must locate the final rights decision, verify one asset, identify its disclosure, say who can approve it, and execute the staging withdrawal route. Record both observed results in the same application section.

7. What goes wrong

Export removes the manifest

Symptom: the approved master verifies, but the resized website or presentation copy reports no embedded provenance record.

Fix: inspect the exact delivered bytes, retain a hash-linked external record and visible disclosure, use the approved fallback, and assign the channel owner a dated repair. Never copy the master's result onto a different hash.

A valid signature is treated as permission

Symptom: a signed asset is approved even though its reference image has no generative-use licence or its model is non-commercial.

Fix: keep provenance and rights as separate gates. A signature binds claims; it does not grant reference, model, output, likeness, or publication rights.

Disclosure is decided by the uploader

Symptom: one publisher writes “AI,” another says nothing, and a third places a note on a page users never visit.

Fix: classify the use before production and pre-approve exact wording, placement, accessibility, persistence, and channel behavior. Escalate novel portrayals instead of improvising.

“Non-commercial” enters a commercial channel

Symptom: open weights used for a prototype remain in the workflow when the asset moves to a product page or paid campaign.

Fix: record the exact weight revision and licence against the intended use. Block promotion when terms do not permit it, then replace the route and regenerate from cleared inputs.

Indemnity becomes a substitute for review

Symptom: the release note says “vendor indemnified” but names no agreement, covered feature, exclusion, cap, or contract owner.

Fix: have the contract owner record applicable scope and conditions. Continue checking input rights, consent, output status, disclosure, and prohibited uses independently.

Metadata exposes sensitive process details

Symptom: a public manifest contains a private prompt, participant identifier, employee name, filesystem path, or unreleased project title.

Fix: define public assertion fields before signing, minimise them, inspect the manifest as an unauthenticated reader, and keep restricted detail in the access-controlled external record.

No approver owns the final channel

Symptom: design, legal, research integrity, and marketing each reviewed a part, but nobody can say who released the final crop.

Fix: name one publication approver per channel, preserve specialist holds, bind approval to a final hash, and require reapproval after material edits or channel changes.

The policy leaves with its author

Symptom: only the creator knows the signing key route, licence rationale, disclosure wording, or takedown control.

Fix: maintain primary and substitute roles, secret references rather than secret values, a scheduled handover test, and an observed staging withdrawal. Failed handover blocks release readiness.

8. Do it yourself: apply the policy in 60 minutes

Work on one actual 3–5-item set of public, synthetic, or explicitly approved media. Use one Lab or Company framing; do not create a second artifact for the other framing.

Minutes 0–8: create media-policy-and-application.md. Complete scope, channels, jurisdictions, owners, stop authority, evidence location, retention, withdrawal route, and review dates.

Minutes 8–18: classify the set A–D. Inventory every source, reference, model/service route, edit, person or voice, depicted mark or claim, intended audience, and publication licence. Hold any unknown.

Minutes 18–28: check current primary terms, exact licences, consent or assignment records, publisher/platform policy, and applicable disclosure rules. Record URLs or controlled references, dates, reviewer, conclusion, conditions, and recheck trigger. Do not paste confidential contracts into the artifact.

Minutes 28–38: approve exact visible or audible disclosure and its accessible equivalent. Attach provenance to final masters through the approved signing route, inspect it, retain complete validation outcomes, and hash the exact files.

Minutes 38–47: process a staging copy through the real channel transformation. Download, hash, and inspect the delivered copy. Record absence, warnings, or invalidity honestly and execute the written block or fallback.

Minutes 47–54: complete the release register. Bind every rights, disclosure, provenance, and approval decision to asset IDs, final hashes, channels, owners, and dates. Resolve one safe finding or leave the set held.

Minutes 54–60: inject the stripping test and ask the substitute operator to perform the author-has-left check and staging withdrawal. Record observed results and remove temporary publication access. Do not publish merely to finish the exercise.

9. Exit check

Deliver exactly one artifact: one media-policy-and-application.md written finding covering labelling, licensing, provenance, external approval, withdrawal, retention, and handover, applied to one actual 3–5-item public, synthetic, or explicitly approved asset set.

It passes when every asset has a stable ID and final hash; exact sources and generation route; dated model/service, input, consent, output, and publication-licence decisions; approved contextual disclosure; observed provenance inspection for both master and delivered copy; an honest stripping-test result and fallback; risk route; named rights reviewer and publication approver; decision date and recheck trigger; and an observed substitute-operator handover and staging withdrawal. A held set passes when the policy correctly blocks unresolved rights or provenance and records the owner and next action.

It fails if the artifact contains only a generic policy, screenshots without inspectable results, a claim that signed provenance proves truth or permission, “commercial use allowed” without exact terms and intended use, an indemnity slogan, a disclosure hidden only in metadata, approval not tied to final bytes, fabricated observations, real unapproved media, or a release route that only the creator can operate.

10. Rule to remember

If you cannot say where it came from, do not publish it.

11. Further reading & tools