C2PA and Link Building

C2PA and Link Building: Provenance as a 2027 Trust Signal

TL;DR

Provenance standards sign artifacts. A link is not an artifact — it is a relation between three parties, and the one holding the signing key is not the one who knows how the placement was arranged.

The C2PA assertion vocabulary describes how a thing was made: creative work, actions, ingredients, AI involvement, capture metadata. There is no assertion for consideration. And by specification, every assertion is optional — no assertion is mandatory.

The web already ran this experiment. rel=sponsored shipped in September 2019 as a machine-readable declaration of commercial intent, and Ahrefs finds it correctly applied by 4.2% of sites for paid links. The failure mode was never forgery. It was silence.

Voluntary disclosure only unravels when non-disclosure is informative. An undeclared editorial link and an undeclared paid link are byte-identical, so silence pools the honest with the concealing and the unravelling stalls. The unsigned web will not become suspect. It will become uninformative.

What provenance genuinely changes is not detection but deniability. Signed, timestamped, identity-bound records turn a backlink profile from a stock into a dated ledger, auditable years later — and the audit that matters is not run by a search engine.

The operating rule for 2027 is short: buy only what you would be content to have signed, and keep the acquisition record, because someone is going to ask for it.

The pitch: provenance will finally clean up the link graph

The argument has been forming across the trade press for about a year, and it goes like this. Content provenance is arriving as real infrastructure — an ISO standard, a conformance programme, a trust list of accredited signers, and verified-agent identity at the network layer. Once publishers are cryptographically identifiable and their pages carry signed manifests, the anonymity that made link manipulation possible evaporates. Verified publishers become the only link targets worth pursuing, unsigned sites drift into a suspect tier, and for the first time an honest operator can prove that a placement was editorial.

It is a coherent story, and it lands in a year that seems to support it. On 15 May 2026 Google widened its spam policies to cover attempts to manipulate generative responses in Search, explicitly bringing paid citation schemes and engineered mention networks inside the boundary. The June 2026 spam update, by Google’s own confirmation to the trade press, targeted neither link spam nor site reputation abuse — enforcement has moved on to content-level and answer-level tactics, which reads to many as a sign that the link problem is being handed to an identity layer instead.

So the question is worth asking properly rather than dismissing. If provenance becomes a trust signal in 2027, what exactly does it attest to about a link, who signs it, and what changes in the way placements are acquired? The answer is genuinely surprising, and almost none of it is about spam detection.

What would a signed link actually be? There is no such object. C2PA — the Coalition for Content Provenance and Authenticity, the cryptographic provenance standard behind Content Credentials — signs assets: a file, its bytes, and a set of assertions about how it was produced. A signed page could carry a manifest saying who published it and when. Nothing in the standard signs the link — the relationship between two domains, the reason it exists, or the terms under which it was placed. The unit that provenance certifies and the unit that link building trades in are not the same object.

The largest unsigned dataset on the web

Step back from the standard for a moment and look at what the link graph actually is. Several trillion assertions, each one saying roughly this page vouches for that page, and not one of them carrying a record of who decided, on what basis, or whether anything changed hands. No timestamp of intent. No identity of the decision-maker. No consideration field. The entire commercial substrate of search has been built on a dataset with no provenance whatsoever.

Everything the industry recognises as anti-spam machinery is an attempt to reconstruct that missing record after the fact. Damping factors and trust propagation infer editorial intent from graph shape. SpamBrain infers it from patterns. The disavow tool lets a site owner retroactively assert what a link was, years after the fact, with no evidence required. Manual actions apply human judgement where inference failed. Two decades of engineering — and every piece of it exists because the provenance was never captured at the moment of creation.

That framing matters because it changes what a provenance layer would have to do. Search did not lose the provenance of the link graph. It never had it. A standard that arrives in 2027 is not restoring a record that degraded; it is proposing to create one for the first time, on a substrate whose participants have spent twenty years learning that the absence of a record is commercially valuable.

Try it on a single link. Take any placement pointing at your domain from before 2020 and attempt to establish, from evidence rather than memory, who proposed it, what was agreed, and whether any consideration passed. For most organisations the honest answer arrives inside a minute: there is no way to find out. The page may still be live and the anchor text still visible, but the fact that would determine how the link ought to be treated was never written down by anybody, on either side of it.

A link is a relation, and provenance signs artifacts

Every provenance scheme in production assumes a tidy alignment: the signer is the author, the author is the subject, and the asset is the thing being described. A camera signs a photograph it took. An editing tool signs the file it modified. Signer, subject and artifact collapse into one, which is precisely why the cryptography is clean.

Three parties, one key, and it is held by the wrong one

A link breaks that alignment in a way no amount of specification work can repair. The publisher holds the signing key and controls the page. The beneficiary is a company on another domain entirely, with no key, no control, and a strong interest in how the relationship is characterised. And in most commercial placements there is a third party — an agency, a marketplace, a PR desk, a specialist practitioner — who arranged the transaction, knows the terms, and signs nothing at all, because they do not own the page and do not own the beneficiary’s domain either.

So the party with the most complete knowledge of a placement is structurally excluded from attesting to it. The party with the key knows they published something and may not know what the arrangement was two hops upstream. The party with the incentive to misdescribe it is the only one who cannot sign. This is not a gap in the standard; it is what happens when you apply a two-party data model to a three-party transaction.

A concrete version. A manufacturer briefs an agency, the agency approaches a trade title through a freelance contributor, and the contributor’s article names the manufacturer and links to a product page. Four organisations touched that link. The only one able to sign anything about it is the trade title, whose honest account is that a contributor filed a piece — true, complete as far as it goes, and silent on everything upstream of the byline.

The Attestation Gap

Laying the parties out against what each one knows, can prove, and never says makes the shape of the problem concrete — and shows why adding cryptography to the arrangement changes less than it appears to.

PartyWhat they knowWhat they can proveWhat a signature changes
The publisher (holds the key)That they published it, and usually who askedIdentity, page contents, date — everything except whyTheir identity becomes non-repudiable. Their motive stays unstated.
The beneficiary (you)What was paid, briefed and promisedNothing on the publisher’s page — no key, no controlNothing on the page. Your own records become the only account.
The intermediary (agency, marketplace, network)Everything: terms, consideration, the other clients on the same listNothing, and is asked for nothingNothing whatsoever. The best-informed party never signs.
The engine (the reader)Only what is on the page and in the graphNothing directly; it infers from shape and patternIdentity resolution improves. The commercial question is untouched.

Read the third column. The knowledge and the key sit in different rows, and the row with the most knowledge has neither a key nor an obligation. No cryptographic improvement moves information between rows — that is a contracting problem, not a signing one.

There is no assertion for consideration

Even setting the parties aside, the standard has a vocabulary problem that is rarely mentioned in the marketing. Look at what a C2PA manifest can say. The assertion types cover the creative work, the actions performed on the asset, the ingredients composed into it, whether AI was involved in its creation, and the capture metadata. That is a production-history vocabulary. It describes how a thing was made.

Link building is not about how a thing was made. It is about what relationship produced it — who approached whom, what was agreed, and whether money moved. The standard has no word for that, and adding one would not help, because of a detail in the specification that deserves far more attention than it gets: all assertions are optional. No single assertion is mandatory. A manifest with a valid signature, a clean certificate chain and a trusted timestamp can assert almost nothing and still verify perfectly.

This is the point at which the whole proposition inverts. Verification confirms that the assertions present were made by the signer and have not been altered. It says nothing about the assertions that are absent. A cryptographically flawless manifest on a paid placement is entirely consistent with a manifest that simply omits the payment — and the verifier cannot distinguish that from a manifest on an editorial piece, because both are silent in exactly the same way.

It is worth picturing what a signed article on a publisher’s site would actually say. Something close to this: the page was produced in this content management system, by this organisation, on this date, with these images composed into it, one of which was edited with these tools. Every element of that is true, verifiable, tamper-evident — and irrelevant to the only question a reader of the link graph wants answered. The manifest describes the manufacture of the page in forensic detail and the commercial arrangement behind it not at all.

The omission rule. A signature attests to what it contains and is silent about what it leaves out. A valid manifest is evidence of an assertion, never evidence of completeness. Any provenance claim about a link should therefore be read as a statement about the signer, not a description of the transaction — and treated with the same caution you would apply to any other self-issued document.

We already ran this experiment, in 2019

The web has had a machine-readable declaration of commercial intent for links since September 2019, when Google introduced rel=sponsored for paid and affiliate placements alongside rel=ugc for user-generated content, and converted nofollow from a directive to a hint. It is not cryptographic, but it is exactly the thing a provenance layer would add: a structured, standardised, one-attribute disclosure of the relationship behind a link, published by the party who controls the page.

Seven years on, Ahrefs finds rel=sponsored correctly applied by 4.2% of sites for paid links. The earlier crawl-scale research put usage at rounding-error levels across the general web. This is a genuine natural experiment, and it deserves to be read carefully rather than dismissed as apathy, because the failure has a specific shape. Nobody forges a nofollow. There is no black market in counterfeit link attributes, no tooling for stripping them, no adversarial research on defeating them. The attribute simply does not get added.

Silence, not forgery

That distinction is the heart of the matter. Cryptography is a defence against forgery: it makes an assertion attributable and tamper-evident. It has nothing at all to say about omission. Signing the pages of the 4.2% would produce a more trustworthy record of an already-honest disclosure, and would leave the other 95.8% precisely where they are — publishing valid, verifiable, entirely silent manifests.

The incentive has weakened further since. A 2025 Semrush study of a thousand domains found nofollow and dofollow links correlating almost identically with AI search visibility, at 0.340 and 0.334 — a result consistent with what practitioners tracking the relationship between links and AI Overviews have reported independently. The one declaration the web actually has is now largely immaterial to the systems that increasingly decide visibility. Declaring costs something and buys progressively less, which is not a promising starting condition for a voluntary regime.

Why voluntary disclosure does not unravel here

There is a well-established result in information economics that predicts the opposite of what the link graph does, and understanding why it fails is more useful than any amount of speculation about adoption curves. The disclosure principle — the unravelling result — says that voluntary disclosure tends to become complete. The best types disclose to separate themselves. Silence is then read as bad news, so the next-best disclose to escape the pool, and the process cascades until only the worst type stays quiet. Markets for used cars, restaurant hygiene ratings and product energy labels all show versions of it.

The condition that fails

Unravelling needs three conditions: the receiver must know the sender holds the information, the disclosure must be verifiable, and disclosing must be cheap. The link graph satisfies the first and the third comfortably. It fails the second in a specific and instructive way — not because a declaration cannot be verified, but because its absence cannot be interpreted.

An undeclared editorial link and an undeclared paid link are identical objects. Same markup, same rendering, same graph position. When a publisher stays silent, that silence contains an honest editorial mention, a favour between old colleagues, a placement bought through a niche-edit marketplace, and a footer swap from 2014 — all in the same pool, all indistinguishable. Unravelling requires that stepping out of the pool improves how you are read. Here, staying in it costs nothing, because the pool is enormous and overwhelmingly innocent.

Which produces the conclusion that reverses the cluster’s own premise. The received wisdom about provenance is that unsigned content becomes suspect as signing spreads. For links, that is close to backwards. The unsigned portion of the graph will not become suspect, because it contains most of the honest web. It will become uninformative — a very large pool in which the signal cannot be extracted, no matter how good the cryptography around its edges gets.

The obvious retort is that plenty of disclosure regimes on the web do work, which sharpens the point rather than blunting it. Advertising labelling under the UK Advertising Standards Authority’s rules, affiliate disclosure requirements, and the fake-review provisions of the Digital Markets, Competition and Consumers Act 2024 — enforceable by the Competition and Markets Authority since April 2025, with penalties reaching 10% of global turnover — all achieve declaration rates that rel=sponsored never approached. None of them managed it with cryptography. They managed it by making non-disclosure an offence with a named enforcer and a number attached. Where pooling has been broken on the open web, it has been broken by obligation. If link disclosure ever becomes real, it will arrive from a regulator rather than a standards body.

What provenance actually changes: deniability dies

None of the above means nothing changes. It means the change lands somewhere other than where it is being advertised. The specification strongly recommends that a manifest signature carry a trusted timestamp proving the signature existed at a given date. Combine that with a certificate chain resolving to an accredited signer and you get something the web has never had at scale: a dated, identity-bound, non-repudiable record that a specific publisher published a specific page containing a specific link on a specific day.

That converts a backlink profile from a stock into a ledger. Today, a competitor backlink analysis returns a set of current states: the link exists, or it does not. Under a provenance layer it returns dated assertions by identifiable parties, each one persisting as evidence long after the page changes, the agency contract ends, or the link is quietly removed. Nothing about that helps an engine decide whether the placement was bought. It helps anyone reconstructing, years later, what happened.

The audit that matters is not run by a search engine

The industry’s risk model has been shaped almost entirely by one counterparty. Penalties, devaluations, recoveries, technical clean-up work — the threat is always Google, and the remedy has always relied quietly on the ephemerality of evidence. Pages get deleted. Agencies get replaced. Records go with the laptop of whoever ran the programme in 2019. You could always say, more or less honestly, that you did not know.

A durable, dated, third-party-signed record removes that, and it removes it asymmetrically. It removes it for you, because your name is in the anchor and on the destination. It does not remove it for the intermediary, who still signs nothing. And the parties most likely to read such a record are not search engineers: they are acquirers running technical due diligence, procurement teams screening suppliers, regulators examining disclosure in a regulated sector, and opposing counsel in a dispute. Those readers do not devalue links. They price risk, and they do it retrospectively.

THE RETROSPECT TEST

Run every meaningful placement in your profile through one question: if the full acquisition record for this link were published tomorrow — signed, dated, with the consideration attached — what happens? Sort into four bands and act on each differently.

Publishable. You would be content for the record to be public. Editorial merit, a documented brief, no consideration or clearly-disclosed consideration. This is the only band that is unambiguously an asset in 2027. Grow it.

Explainable. Consideration changed hands and the arrangement was ordinary and defensible, but it was never declared on the page. Fixable and cheap to fix: request the attribute, log the request, keep the reply. The cost of fixing rises the longer it waits.

Deniable today. You would rather it were not published, and your current protection is that no record exists. Price this band as a liability with a falling discount rate, not as an asset, and stop adding to it.

Unknowable. You cannot reconstruct how it was acquired at all — a legacy agency, a departed employee, an inherited domain. This is usually the largest band and the one nobody counts. Size it before you do anything else; an unquantified band cannot be reported, defended or sold.

The forcing question. Not is this link risky, but could you produce the acquisition record if a buyer’s lawyer asked for it on a Tuesday? If the honest answer is no for most of the profile, the provenance problem you have is your own, and it exists whether or not the standard ever reaches your sector.

The consequence nobody has priced: accreditation shrinks the prospect list

There is a second-order effect that matters more to acquisition budgets than any of the detection arguments. A trust list is a list. Somebody maintains it, somebody decides the criteria, and somebody is excluded. The conformance programme already issues certificates carrying an assurance level corresponding to the scrutiny a product passed — the machinery for tiering signers exists and is being used.

If engines lean on accredited publisher identity, the addressable universe of citable publishers stops being everyone with a domain and becomes everyone an accreditation body recognises. That is not a spam-filtering change; it is a supply constraint. Scarce accredited supply raises prices, advantages incumbents, and disadvantages exactly the small independent publishers and specialist trade outlets that currently offer the best value per placement — including, incidentally, most of the regional and vertical press that campaigns aimed at European markets depend on.

There is a further wrinkle for anyone operating across borders. Accreditation regimes are national or regional in practice even when the underlying standard is international, so a publisher entirely credible in its own market may be absent from a trust list maintained elsewhere. A campaign built on local trade press in one country and then evaluated against an accreditation list drawn up in another will look thinner than it is, for reasons that have nothing to do with the quality of the placements.

Should I only pursue links from C2PA-verified publishers? No — not in 2026, and probably not in 2027. Verification status is not currently an input to any ranking or citation system, and restricting a prospect list to accredited signers today would shrink it dramatically for no measured return. The defensible version of the idea is softer and cheaper: when two prospects are otherwise comparable, prefer the one with resolvable institutional identity, because that is the attribute most likely to become scarce and therefore expensive later.

Haversham Learning: 2,140 links, 312 records

Haversham Learning is a UK vocational training provider with revenue of £18.4M and 130 staff, selling accredited courses to employers across construction, logistics and facilities management. In January 2026 it entered an acquisition process. The buyer’s technical due diligence asked a question the marketing team had never been asked in thirteen years: for the backlink profile, please supply the acquisition records.

The profile held 2,140 referring domains accumulated since 2013 across four agency relationships. They could produce a record — a brief, an invoice, an email thread, anything dated — for 312 of them. Of the remainder, roughly 890 were plainly organic: directories, aggregators, academic pages, press pickup. Around 610 came from three agency periods with no surviving documentation of any kind. The final 328 shared enough infrastructure and outbound-link characteristics to be flagged by the buyer’s advisers as consistent with paid placement networks.

The deal completed. It completed with a £340,000 indemnity holdback tied to twelve-month organic traffic retention, priced against a risk nobody could size because 85% of a thirteen-year investment could not be described, let alone defended. No search engine had ever penalised them. The cost arrived through the balance sheet.

Fourteen weeks of remediation followed. A forward ledger was built first — every new placement logged with date, publisher, named contact, consideration, brief, attribute applied and a dated screenshot — which took a fortnight and is now the cheapest part of the programme. The Retrospect Test was then run across the 938 non-organic domains. Forty-one landed in the unknowable band while also being visible and commercially significant. Publishers were contacted on all 41; 22 replied; 9 confirmed a historic paid arrangement that had never been declared. Seven added the attribute on request, and two removed the link rather than label it.

The prospecting screen changed at the same time, to a single question borrowed from the test: would we be content to have this signed? Cost per placement rose 34% and volume fell by about 60%. Rankings did not move in the measurement window, which is the honest result. What did move was citation presence — a standing panel of 96 answers across four engines went from naming Haversham in 12 to naming them in 27 over five months, because the placements that survived the new screen were the ones stating something specific enough to be restated. The holdback was released early, in July, once the ledger was accepted as evidence of a governed programme.

The negatives are worth more than the headline. The ledger costs about six analyst-hours a month indefinitely. Two long-standing publishers refused to add attributes, and one of them was the single best referrer by traffic in the profile; that link was kept and the ambiguity documented rather than resolved, which is the correct answer and an uncomfortable one. The exercise produced no ranking movement at all in five months. And the largest cost was political: the person who had run the 2018–2021 programme had left the business, so the reconstruction read internally as blame allocation, and two colleagues declined to participate in it.

The strongest objection: provenance as identity resolution

The best counter does not defend voluntary disclosure at all. It says the framing is wrong. Provenance will not arrive as publishers declaring their commercial arrangements; it will arrive as infrastructure. Certificate chains, accredited signer identity and verified-agent access mean an engine never needs anyone to declare that a link was paid for. It observes that forty domains share a signing identity, a hosting fingerprint, a registration pattern and an outbound-link profile, and it draws the obvious conclusion. Provenance is not the disclosure. It is the identity resolution that finally makes the inference reliable — and that does clean the graph.

That is the version of the argument that bites, and it is substantially correct. Four things bound it.

  • It is still inference, with the same false positives. Identity resolution sharpens pattern detection; it does not convert it into attestation. A local newspaper group, a university’s departmental sites, a franchise estate and a trade association’s member directory all look like a network at the identity layer, because they are one. Better resolution raises confidence in a judgement that remains a judgement.
  • It detects networks, not payments. The cheap end of manipulation leaves a shared-infrastructure signature. The expensive end — one payment to one genuinely independent publisher with real editorial staff and no shared anything — leaves none. Identity resolution is most effective against the tactics that already work least well, and blind against the ones that work best, which is the wrong way round.
  • The chokepoint is a supply constraint before it is a filter. Whoever curates accreditation decides who counts as a publisher, and that decision will be lobbied exactly as ranking guidance has been lobbied for fifteen years. The first-order effect on a link programme is not fewer spam links; it is a smaller, dearer prospect list.
  • The actions are invariant. Under both futures you keep acquisition records, you buy what you would be content to have signed, and you prefer publishers with resolvable identity at equal merit. Nothing in the operating rules depends on which way the infrastructure goes.

Read plainly, the objection changes who gets caught rather than what you should buy. That is a meaningful change for anyone still running the tactics of 2016, and close to no change at all for anyone building a profile they would be willing to publish.

What to do on Monday

Eight items. None of them require a view on whether the standard reaches link building at all, which is the point of choosing them.

  • Start the forward ledger this week. Date, publisher, named contact, consideration, brief, attribute applied, dated screenshot. It is a fortnight of setup and it is the single highest-return item here.
  • Size the unknowable band before anything else. Count the placements for which no acquisition record exists. That number is the finding, and it is almost always larger than anyone expects.
  • Adopt one prospecting question. Would we be content to have this signed? Apply it before authority metrics, alongside the screens already in your prospecting stack.
  • Fix the explainable band while it is cheap. Request the attribute, log the request, keep the reply. A documented refusal is worth more than an undocumented compliance.
  • Stop treating disavow as a record. It is an instruction to one engine, not evidence of anything, and it will not answer a due-diligence question about how a link was acquired.
  • Prefer resolvable institutional identity at equal merit. Registers, regulators, trade bodies, academic and standards publishers — the segment least likely to be excluded by any accreditation regime and, usefully, the segment that already carries weight in statistical and evidence-led coverage.
  • Brief for restatable specifics, not mentions. The placements that survived the Haversham screen earned their keep because they stated something quotable, the same property that makes data assets and calculators and evidence-carrying listicle placements outperform a bare link.
  • Report the ledger upward once a quarter. To finance and legal, not only to marketing. It is a governance artefact now, and the audience that will eventually ask for it does not sit in your team.

The honest summary of C2PA and link building in 2027 is that the standard will not adjudicate the link graph, because it has no vocabulary for the only fact that matters, no obligation to disclose it, and no signature from the party who knows it. What it will do is make records durable — and durable records are neutral. They protect a programme that was run properly and they document one that was not, with equal fidelity and no expiry date. The strategic response to that is not technical. It is to build the kind of link profile you would be happy to have signed, dated and read aloud in three years, and then to keep the paperwork proving you did.

For the mechanics of acquiring that profile, the strategy hub covers the acquisition side, while what a backlink actually is and does, how PageRank sculpting fares in 2026, crawl behaviour on JavaScript-rendered links, machine-readable feeds and API surfaces, training-corpus presence, agentic browsing and the value of a click, developer-community placements and sector-specific campaigns in recruitment and HR tech each cover a piece of the work that a ledger makes defensible.

Leave a Reply

Your email address will not be published. Required fields are marked *

Content Credentials Previous post Content Credentials for Publishers: Will Signed Content Win More Citations?
Authenticity Premium Next post The Authenticity Premium: First-Hand Experience as the Scarce Citable Input