Sora on signed metadata: a standard applied to every asset
The system card's first provenance bullet names an industry standard, applies it to everything, and describes it as carrying verifiable origin. That is the shortest sentence in this record that lands on the provider duty in its own terms. As of 2026-09-22.
| Point | What the record holds |
|---|---|
| Article 50(2), machine-readable marking | C2PA metadata on all assets, given as verifiable origin through a standard |
| Read from | A system card, a document written to describe behaviour |
| What it does not settle | Whether parties outside the vendor read the manifest in practice |
Inclusion rule. One cell of this generator's entry, quoted from the page the entry names. Coverage, commentary and third-hand summaries are not admitted, in either direction. Order. Fixed order: the cell, the page it came off, then the limit on reading it.
1Naming a standard is what the paragraph is asking for
The marking paragraph wants output marked in a machine-readable format and detectable as generated. It does not name a technology, and it does not have to: the phrase points at a signed record that software can parse, which is exactly what a provenance manifest is.
Most entries in this record reach that column with nothing, because a pricing page had no reason to mention a container. This one reaches it with a named specification, which means the statement can be quoted without inferring a single step.
2All assets is the phrase doing the heavy lifting
Scope is where marking claims usually shrink. A mark applied to some outputs, or to one delivery route, or from one version onward leaves a reader working out which of their files carry it. The bullet here says all assets, with no tier, no flag and no version boundary attached.
That is a stronger statement than several neighbouring entries make, and it is still a statement about what leaves the vendor. What arrives at an audience depends on the route in between, and no vendor sentence can speak for that.
3A manifest is the most informative mark and the easiest to lose
Because the record lives in the container rather than in the pixels, it can carry structure: what produced the asset, when, and what happened to it since, signed so that tampering shows. One bit of provenance is useful; a chain of it is a different class of evidence.
The same property is the weakness. Anything that rebuilds the container without copying the record drops it in silence, and platforms rebuild containers on upload as a matter of course. So this cell describes the strongest available signal and the one most likely to be missing from a delivered file.
- OpenAI Sora (openai.com)C2PA metadata on all assets, listed as providing verifiable origin through an industry standardfirst item under provenance safety tooling
- Article 50(2)Providers must mark synthetic audio, image, video and text in a machine-readable formatincluding general-purpose AI systems
4Sources
Wording taken from the Sora 2 system card at cdn.openai.com, consulted 2026-09-22. All four rows for this generator sit on OpenAI Sora; the same column across every entry is read down on What it asks for. Filed beside it: SynthID on marking at generation, Firefly on content credentials.