TL;DR
A liability needs a counterparty who can make you pay. An engine declining to cite you is an outcome, not a liability, so the question everyone is asking about signed content is a legal word attached to a ranking problem.
Verification requirements do not follow truth. They follow warranties — they appear wherever somebody has promised something about the contents and can be sued if the promise is false. The open web has no warrantor, which is why it has no verification requirement and will not get one.
The real exposure is exclusion from bounded corpora, and nothing in those gates is opened by a signature. Meanwhile the first genuine liability most publishers will create for themselves is one they sign: an originality warranty they cannot evidence.
The claim, stated fairly
The proposition circulating through 2026 is that unsigned content is on its way to being treated as suspect. It is not a fringe view and the supporting picture is strong. The Content Authenticity Initiative passed 6,000 members in January 2026. C2PA — the Coalition for Content Provenance and Authenticity, whose Content Credentials attach a cryptographically signed record of how a file was made — reached ISO standardisation and shipped specification 2.3 in January and 2.4 in April. A conformance programme and a trust list now exist, with the Pixel 10 the first certified phone. Google surfaces credential data in image details and Photos, OpenAI verifies both C2PA and SynthID marks, TikTok has labelled over 1.3 billion videos, and YouTube labels unmodified footage from compatible hardware as captured with a camera.
Then the law arrived. Article 50 of the EU AI Act became enforceable on 2 August 2026, with Commission guidelines adopted on 20 July and fines reaching €15 million or 3% of worldwide turnover. Providers of generative systems must mark synthetic output in a machine-readable format; deployers must disclose deepfakes and AI-generated text on matters of public interest. A voluntary Code of Practice on transparency of AI-generated content gives signatories a presumption of conformity and leaves non-signatories to demonstrate compliance some other way.
Put that together and the inference looks obvious. Labelling becomes ambient, the labelled becomes normal, the unlabelled becomes the anomaly, and anomaly detection is the one thing these systems are good at. So sign everything, or be quietly discounted.
The inference is wrong, but not for the reason most sceptics give. It is wrong because it uses a legal word to describe a ranking outcome, and the two behave nothing alike.
A liability needs somebody who can enforce it
A liability is an obligation somebody else can compel you to meet. It requires a duty, a breach, a loss, a remedy and a counterparty with standing to pursue you. An answer engine has none of these against a publisher. It owes you nothing, and if it never cites you again there is no forum in which that becomes a claim. That is an outcome, and outcomes are governed by selection rules rather than by rights.
What is a citation liability?
Strictly, there is no such thing. Being uncited is a commercial outcome with no legal counterparty. What does exist is a set of real liabilities sitting nearby — contractual warranties, regulatory duties and professional obligations — that attach to the people who act on unverified content, and occasionally to the people who promised something about it.
The distinction is not pedantry, because the two respond to different interventions. An outcome moves when you change what a selection system prefers, and selection systems are probabilistic and forgiving: weakness on one signal is recoverable by strength on another. A liability moves when you change what you promised or what you can prove. No amount of quality elsewhere discharges a warranty.
Which means the useful question is not whether unsigned content will be penalised. It is: where does a failure of verification actually cost somebody money, and who is that somebody?
Verification follows the promise, not the pixel
Look at every context where content provenance has genuinely shipped rather than been announced, and one feature is shared by all of them: somebody in the chain has made a promise about the contents and is exposed if the promise turns out to be false.
An advertising platform has warranted to its advertisers that creative is what it claims to be, so it reads manifests at upload. A stock library has warranted licensable rights to its buyers, so Getty, iStock and Shutterstock built credential handling into their pipelines. A newsroom has warranted its own output to its readers and its regulator. An AI provider now warrants machine-readable marking to a European market surveillance authority. In each case verification is not a search for truth in the abstract. It is a party managing an exposure it has already accepted.
The open web has no such party. Nobody has warranted anything about a random page, so there is nobody to hold to account, no exposure to manage, and therefore no verification requirement to impose. This is why provenance has repeatedly failed to show up in the one place the industry keeps expecting it: general ranking and general citation. Not because the technology is immature, but because there is no promise there to protect.
Provenance follows the promise, not the pixel.
| Setting | Who has promised what | Who pays if it is false | What actually gets you in |
| Open-web answer SIGNATURE IRRELEVANT | Nobody. No warranty exists anywhere in the chain. | Nobody. You are simply not cited. | Independent corroboration and retrievability. |
| Ad and creative review SIGNATURE READ | The platform, to its advertisers, that creative is what it claims to be. | The platform first, then you under the insertion order. | A pipeline that carries the manifest intact, plus account standing. |
| Licensed panel or data deal SIGNATURE IRRELEVANT | The publisher, to the engine, that supply is lawful and continuous. | The publisher, contractually. | A signed commercial agreement. There is no other door. |
| Restricted research or procurement list SIGNATURE IRRELEVANT | The buyer, to its own board or regulator, that its process is sound. | The buyer, through its governance. | Accreditation, named accountability, institutional standing. |
| Your own client contract SIGNATURE DECISIVE | You, to your customer, about originality, rights and disclosure. | You, up to the indemnity cap and sometimes beyond it. | Records you can produce on the day you are asked. |
Read the last column down. In four of the five settings, a cryptographic signature is either irrelevant or secondary, and the thing that admits you is a relationship somebody was willing to underwrite. Only in the row where you are the one who promised does a signature become decisive — and there it is decisive because it is evidence, not because it is a ranking signal.
How to tell whether a gate reads manifests
This is worth establishing empirically rather than assuming, because the answer determines whether a signing budget is defensible at all. A gate that reads provenance says so in its submission requirements, rejects or labels assets at upload rather than after review, and publishes a verification endpoint or a supported-format list. A gate that does not read provenance asks instead for a named contact, an accreditation number or a completed self-declaration form. Two minutes with a submission portal usually settles it. The same distinction applies to machine-readable feeds supplied into product and specification databases: some validate cryptographic assertions, most validate identity and schema conformance and never look at a manifest at all.
The shape of the risk is exclusion, not demotion
This reframes what publishers should actually be worried about. Demotion is a continuous penalty inside a system that is still considering you. Exclusion is a membership decision taken before consideration begins, and membership decisions have no partial credit: you are on the list or you are not, and being excellent is not a route back in.
Bounded corpora have been multiplying quietly for eighteen months. Restricted research modes let a user confine a sweep to trusted sites. Voice assistants answer from licensed panels of a few hundred contracted outlets. Enterprise retrieval systems index an approved internal set. Specification portals, framework agreements and approved-supplier directories decide which sources feed a professional decision. Each of these is a corpus with a boundary, and each boundary exists because somebody inside it has accepted an exposure.
For example, a manufacturer’s specification portal that feeds product data to engineers is not curating for quality in the abstract. It is curating because if a specifier builds to bad data, the portal operator is in the complaint. That is the whole mechanism, and it explains why these gates ask for a named editor, a review process and a corrections policy rather than for a certificate.
The United Kingdom has taken a different route to the same destination, and it reinforces the point rather than complicating it. There is no domestic equivalent of a statutory marking duty. What exists instead is a set of regulators that act on the accountable party: the Advertising Standards Authority on misleading claims regardless of how the creative was produced, the Competition and Markets Authority on fake reviews and misleading practices under the Digital Markets, Competition and Consumers Act 2024, and Ofcom on regulated broadcast and online safety duties. None asks what tool made the file. All ask who is responsible for the claim. Any specialist running this work for UK clients will find that the compliance conversation is about accountability structures, not about file formats, and that the two jurisdictions converge on the same demand from opposite directions.
You cannot sign the pages that describe you
There is a more basic problem with a signing strategy, and it is arithmetical. Muck Rack’s May 2026 analysis put earned media at around 84% of all AI citations. Independent grounding studies put a similar share of brand mentions on third-party domains. Whatever the exact figure in your category, the majority of the material an engine reads when it answers a question about you sits on domains you do not own, cannot sign, and in many cases cannot even contact.
A signing programme therefore has a hard ceiling that can be calculated before a penny is spent.
The signable share
Signable share = sources on domains you control ÷ all distinct sources cited in answers about you.
Run 40 to 60 buyer-intent prompts across the engines that matter in your category, collect every distinct cited source, and mark each one: yours, or somebody else’s.
Whatever that fraction is, it is the absolute upper bound on what any provenance investment can touch. Typical results in professional categories fall between 12% and 25%, which means a signing programme is being asked to move a fifth of the evidence and none of the rest.
The number is worth calculating precisely because it is so rarely calculated. Firms approve provenance budgets on the implicit assumption that their own estate is what gets read. It is not, and the same arithmetic applies to every on-site intervention: schema, author markup, disclosure notices. They all operate inside the signable share. This is the quiet reason that earned placements and backlinks keep outperforming technical measures in citation studies — not because the technical work is bad, but because it is confined to a minority of the evidence by construction.
Does signed content get cited more?
There is no published evidence that any general answer engine treats a cryptographic signature as a positive ranking or citation input, and no engine has claimed one. Where provenance demonstrably changes an outcome, it is at an upload gate or a licensing checkpoint, not in the assembly of an answer.
A broken signature is worse than no signature
Now the part that turns a well-intentioned programme into an actual liability.
An unsigned file is uninformative. It contains no assertion, so a reader learns nothing from its silence. A file whose manifest is present but broken is a different object entirely: it carries a failed verification, and failed verifications get acted on. This is not hypothetical. Analyses of 2026 ad-platform workflows document the mechanism plainly — genuine photographs captured on credential-enabled cameras, edited in credential-enabled software, and uploaded through credential-aware pipelines can be flagged as AI-generated because the chain breaks in transit, while synthetic images whose manifests were written at the point of generation and never re-encoded pass cleanly.
Transcoding breaks chains. So do content management systems that regenerate derivatives, image optimisation layers, format conversion and most social upload paths. The failure is silent when it happens and only visible at the far end, where somebody else’s classifier draws the wrong conclusion. The irony is worth sitting with: the more of your photography is genuinely captured rather than generated, the more of it passes through the steps that destroy manifests.
The broken-chain rule
Never sign what your pipeline cannot carry end to end. Verify a manifest at every stage it passes through — export, upload, transcode, publish, syndicate — and if any stage strips or invalidates it, do not sign that asset class at all.
Silence is neutral. A failed check is a finding. Signing without pipeline control converts an absence of evidence into evidence of a problem, which is the one outcome the whole exercise was meant to avoid.
There is a familiar shape to what is happening here. An industry hears that an absent signal might be penalised, cannot find evidence either way, and spends heavily on remediation nobody asked for. That is the same reflex that produced a decade of unnecessary submissions to the disavow tool from sites that had never received a manual action, and the pattern of research into how backlinks actually feed AI Overviews suggests the same lesson: the measured drivers of citation have been corroboration and standing, consistently, across every study that has looked. Signing out of fear is a remediation programme aimed at a penalty nobody has observed.
The liability you will actually acquire is one you sign
While the industry watches for a penalty that is not coming, a real exposure has been arriving through the post. Standard-form contract libraries now carry AI representations and warranties for non-AI services: clauses in which a supplier represents either that its services use no AI at all, or that they use only identified AI subject to specific conditions. Sample language in circulation has a company warranting that it does not and will not generate, use or rely on AI in delivering its products or services. Buyer-side templates add representations about training data, rights clearance and disclosure, usually carved out of the general liability cap alongside the intellectual property indemnity.
These clauses are spreading through ordinary commercial agreements: agency retainers, contract publishing deals, marketing services agreements, supplier frameworks. They are frequently signed by people who have never audited what their own team produced last quarter, and often cover past work through a renewal that carries forward.
Unsigned content is not a liability. A warranty about unsigned content is.
The asymmetry matters. Nobody can force you to prove how a page was made. But once you have promised how it was made, the burden of proof reverses, and the party asking is a customer with a contract rather than an engine with a preference. This is where provenance stops being marketing infrastructure and becomes evidence — and where the cost of not having it is denominated in pounds rather than in impressions.
What a warranty actually demands
Three things, none of which is a certificate. A dated record of what was produced and how. A named person who reviewed it. A disclosure schedule listing the exceptions. Firms that can produce those documents negotiate the clause; firms that cannot either refuse the contract, accept an uninsurable exposure, or sign and hope. The third option is common and is the single largest unpriced risk in commercial content operations going into 2027.
What the law asks for is a person, not a certificate
Article 50 is the clearest available evidence for the argument, because it is the first binding rule in this area and it is worth reading for who it names. The marking duty falls on providers of generative systems. The disclosure duties fall on deployers — the businesses publishing the output. Nothing in it obliges a publisher of ordinary web content to certify anything about how a page was made, and content published before 2 August 2026 does not need retroactive labelling.
The exception is the one publishers should read twice. Where AI-generated text is published on matters of public interest, disclosure is required — unless the content has undergone human review and a natural or legal person holds editorial responsibility for it. That carve-out is the whole thesis in statutory form. The remedy the regulation offers for unverifiable machine output is not a cryptographic proof. It is a named human being who has accepted responsibility.
The same instinct shows up in every gate described above. Specification portals, professional panels and framework agreements ask who the editor is, what the review step was and how corrections are handled. They are asking for a warrantor, because a warrantor is who they will call. Businesses operating across European markets will meet this first, but the pattern is not jurisdictional. It is structural.
Where verification will land next
If the warranty test is right, it also predicts where verification requirements appear next, and the prediction is specific. Look for surfaces where an intermediary has begun accepting responsibility for an outcome rather than merely displaying information. Agent-executed purchasing is the clearest candidate: the moment a platform completes a transaction on a user’s behalf it has assumed an exposure that a list of blue links never carried, which is why the economics of an agentic browsing visit look so different from those of a click. Licensed training and grounding arrangements are the second candidate, because the sources that train and ground a model are contracted, and a contract is a promise with a signature block already attached.
What will not happen, on this reading, is a general open-web preference for signed material. There is no party in that transaction with an exposure to manage, and building the machinery would cost a great deal to protect nobody in particular.
Where this argument is weakest
The strongest counter is that all of this is a description of an early adoption curve rather than a permanent structure, and that curves of this kind flip fast.
Once credential display is ambient on the surfaces where images are consumed — and it substantially already is, across Google image details, Photos, TikTok, YouTube and X — the absence of a credential stops being neutral and starts being conspicuous. Platforms do not need a warranty to run an inference; they need a base rate. When most photographs from professional sources carry credentials, an uncredentialed press image from an unfamiliar domain becomes a reasonable thing to down-weight, and no regulator or contract is required to make that happen. The mechanism I have described as absent could arrive purely as platform policy.
That is correct for images in news and social contexts, and it is likely to arrive faster than most publishers expect. Four things bound it.
First, text has no equivalent and cannot acquire one. Every mark on text is destroyed by the paraphrase that synthesis performs by design. This is not an implementation gap; it is what summarisation is. The statutory duty for text reflects that reality by asking for editorial responsibility instead of marking.
Second, the base rate makes a filter unusable. Reuters Institute research puts credentials on under 1% of news images. A down-weight applied to the uncredentialed would today apply to essentially the entire supply, which is not a filter but an outage. Adoption must become the majority case before the signal carries information, and the documented false-positive mechanism means the first casualties of an early filter are real photographs from careful publishers.
Third, every shipped deployment labels the synthetic rather than rewarding the authentic. Labels, disclosures and detection tooling are pointed at generated material because that is where the regulatory and reputational pressure sits. A disclosure regime and a preference regime are different machines, and only the first has been built.
Fourth, the recommended action does not change. Grant the counter in full and the correct response is still to secure a pipeline for the asset classes that pass through gates that read manifests, and to earn membership of bounded corpora everywhere else. Nobody’s route into a licensed panel or a specification portal improves because their images are signed.
What this changes about acquiring links
Screen destinations for a warrantor
The most useful new prospecting question is not what a site’s authority score is. It is whether anybody at that destination has promised anything about what they publish. A masthead with a named editor, a published corrections policy, a membership rule or a regulatory registration has a warrantor. A site with no named accountability has none, and that difference predicts which destinations survive the arrival of gated corpora. Sources without a warrantor are exactly the ones a portal, a panel or a procurement list will decline to admit, and a placement inside an excluded source is worth whatever the open web pays for it and nothing more. Run the test on your current target list alongside your competitor backlink analysis and expect a meaningful minority to fail it.
Treat inclusion as an acquisition target
Membership of a bounded corpus is a link-building objective that most programmes have never written down. Trade body directories, specification portals, framework listings, licensed aggregators, professional registers and approved-supplier lists all admit sources on relationship and accreditation grounds, which is the same work as earning an editorial placement conducted with a different counterparty. It sits alongside the more familiar routes — listicle placements, launch platform listings, technical community coverage — but it behaves differently, because a gate does not degrade. You are either in the corpus or invisible to everyone reading from it. Assets that earn their way in on utility rather than persuasion travel well here, which is why interactive calculators and tools remain one of the few formats a technical panel will admit on merit alone.
Build the accountability furniture first
A named editor of record, a dated review log and a published corrections policy with a stated turnaround are the cheapest items on this list by a wide margin, and they are what the gates actually check. They also happen to be what discharges the statutory text duty. Any team that has already invested in technical SEO groundwork for link acquisition will recognise the shape: unglamorous infrastructure that does nothing on its own and unlocks everything downstream. Track it the way you would link velocity across a profile — as a standing property of the estate rather than a project.
One warning on tooling. The verification and monitoring products in this space report on your own domains, because that is what they can access, and the platforms that track this work inherit the same boundary. Every one of them measures inside your signable share. Nothing sold as a provenance dashboard tells you anything about the 80% of cited evidence that lives elsewhere, and a clean internal report is entirely compatible with being described badly everywhere that matters.
A worked example: Holbeck Technical Media
Holbeck Technical Media is a Leeds publisher with £6.8m of turnover and 31 staff, producing technical reference content for the building services sector and contract publishing for six manufacturers. It hit all three versions of this problem inside seven months, in the wrong order.
The warranty
In February 2026 its largest client, a controls manufacturer worth £1.1m a year and 16% of revenue, renewed the master services agreement with an AI representation: deliverables free of undisclosed AI generation, all imagery originally captured or licensed with rights records retained, carved out of the liability cap. Holbeck had used AI assistance in drafting across roughly 40% of output for eighteen months. Nobody had asked, so nobody had recorded it. Six weeks of legal work produced a carve-out for pre-existing deliverables, a disclosure schedule and a per-item declaration going forward that adds about twenty minutes to each piece. The 4% fee increase they asked for was refused and absorbed.
The over-correction
The response was to buy a signing workflow: £24,000 in the first year plus eleven minutes an asset. Within three months, three of forty-seven signed photographs uploaded to a client’s ad platform were auto-flagged as AI-generated, because the manifests broke during transcoding. The two genuinely AI-illustrated assets in the same batch passed, their manifests written at generation and never re-encoded. The pictures that were real got flagged; the synthetic ones sailed through. Signing was kept for client ad creative, where the platform demonstrably reads it, and abandoned elsewhere at a write-off of roughly £17,000.
The exclusion that actually cost money
In May 2026 a specification portal used across the sector added an accountability requirement to its content panel: a named editor of record, a documented human review step and a corrections policy. Holbeck was removed pending compliance. Two competitors with formal editorial governance stayed. Their pages remained perfectly visible on the open web and stopped appearing entirely in the portal’s answer layer, which is where specifiers were actually looking. Portal-sourced enquiries fell 31% over the following quarter.
The remedy cost about £14,000 a year: an editor of record named on every page, a review log, and a corrections policy with a five-working-day turnaround. Readmission took eleven weeks and enquiries returned to baseline in the quarter after that. Their signable share, measured across 214 distinct sources cited about them on four engines, was 38 sources, or 18% — which is what the £24,000 signing programme had been aimed at.
The honest ledger includes things they did not want in a case study. Open-web citations did not move at any point in the exercise, and nothing here was ever going to move them. The per-item declaration is permanent overhead and one freelancer resigned rather than sign one. And the editor of record concentrates personal exposure in a single named individual, which required a conversation with their insurer and a change to how that role is contracted — an outcome nobody anticipated when the goal was described as protecting the brand.
What to do on Monday
- Pull every client and supplier contract signed or renewed in the last two years and search for AI, artificial intelligence, originality and provenance. Read what you have already warranted.
- For each warranty you find, ask what document you would produce if asked to evidence it tomorrow. If the answer is none, that is your real exposure, and it is priced in pounds.
- Calculate your signable share on 40 to 60 buyer prompts before approving any provenance spend. It is the ceiling on the whole investment.
- Trace one signed image end to end through your actual pipeline and verify the manifest at every stage. Stop signing any asset class the pipeline cannot carry.
- Name an editor of record, publish a corrections policy with a stated turnaround, and keep a dated review log. This is the cheapest item here and the one gates check.
- List the bounded corpora that feed decisions in your category — portals, panels, registers, frameworks, licensed aggregators — and check your membership status in each.
- Screen your target destination list for a warrantor: named editor, corrections policy, membership rule or registration. Deprioritise the ones with nobody accountable.
- If you publish AI-assisted text on public-interest matters into the EU, record the human review step and who holds responsibility for it. That is what the duty asks for.
The question was pointed at the wrong party
Signed versus unsigned is a real distinction that has been attached to the wrong decision. It does not determine whether an engine cites you, because engines are not in the business of enforcing promises nobody made. It determines whether you can answer a question when a customer, a portal or a regulator asks how something was produced — and those parties ask rarely, in writing, and with consequences attached.
So the practical posture is narrow and unglamorous. Sign the asset classes that pass through gates that read signatures, and only where your pipeline can carry them intact. Refuse warranties you cannot evidence. Name a human. Then spend what is left where most of the evidence about you lives, which is on other people’s domains, in sources somebody else will stand behind. The link building strategies that reach those sources are the same ones they always were, and what link building is fundamentally for has only become more clearly about corroboration and standing rather than about signal count. The 2026 link building statistics worth watching are not adoption curves for a file format.
Nobody will ever sue you for being unsigned. They will only ever hold you to what you said.
