(C) Alec Muffett's DropSafe blog. Author Name: Alec Muffett This story was originally published on allecmuffett.com. [1] License: CC-BY-SA 3.0.[2] metadata – Dropsafe 2025-08 15-20 years ago we had a reasonable, common understanding that making data tamperproof or copy-resistant by law and/or to enforce artificial scarcity, was problematic. Identity credentials or basic copyright, fine, but Digital Rights Management (DRM) locked people out of their stuff, added friction to both legitimate & illegitimate usage, and hampered open source; now it’s back to save us from AI, and it’s bad. For context: broadly I think that it’s better to add metadata to authentic things to prove their authenticity or provenance, rather than to do something silly like demand that fake things should be labelled as “fake” — simply because there are so many more fake things in the world than authentic. However: labels are labels, we don’t need to get into that argument right now. But — whatever happens — we wouldn’t legally forbid people, platforms and products from removing those labels. After all, the important thing is that an authentic thing can eventually be checked for authenticity if/where necessary, correct? You wouldn’t want to reinvent legislative DRM, right? AB 853: California AI Transparency Act Nope. California says “more DRM please!”. Apparently yet another well-intended-but-actually-goofball piece of legislation, the draft California AI Transparency Act (extract below) says, if I am reading this right: if your app or your platform serves more than 2 million (distinct? globally?) people per year then you are not permitted to strip-out C2PA provenance manifests and any other provenance tags that MAY be included in shared images so to stay legal you therefore MUST register your app with The Coalition for Content Provenance and Authenticity (C2PA) in order to be issued with secret per-app cryptographic keys that enable “legal” mutations (such as image resizing) to be performed and noted in the C2PA manifest …and, of course, you’ll have to work out how to stop people futzing with those keys in open source clients, maybe even prevent them sending content which has had the tags stripped, and/or obligate addition of tags before content is shared What about Signal, then? “Adding metadata to images” is likely something which Signal will never do, and I can’t imagine that it would alternatively be very happy about being forced to swallow and send full-sized images from user to user by default — images which in pursuit of speed and performance are currently heavily resized and recompressed. God knows what would happen to video, I have no idea. There’s also an interesting sop in the legislation re: personal information. Clearly someone has had a go at making it okay to strip personally identifiable information from images: A large online platform shall not … strip any … data that is not reasonably capable of being associated with a particular user and that contains EITHER information regarding the type of device, system, or service that was used to generate a piece of digital content OR information related to content authenticity, … or digital signature from content uploaded or distributed on the large online platform AND IT … shall not … retain any … provenance data that contains EITHER personal information OR unique device, system, or service information that is reasonably capable of being associated with a particular user … from content shared on the large online platform And the text is clearly aimed at centralised platforms like Facebook without end-to-end encryption being an issue: Summary This draft law is broken-as-designed. It makes metadata-avoidant apps (e.g. Signal) break the law It forces proliferation of likely (if unobviously) trackable data, even in privacy-forward apps It messes with application architecture, burdening apps with secrets management / user hostility / protecting data from the user, and hampers open-source tools (mastodon, anyone?) Grade: D- you should know better than this. References https://calmatters.digitaldemocracy.org/bills/ca_202520260ab853 Bill Text SEC. 2.Section 22757.3.1 is added to the Business and Professions Code, to read:22757.3.1. (a) A large online platform shall do both of the following: (1) Use a label to disclose any machine-readable provenance data detected in content distributed on the large online platform that meets all of the following criteria: (A) The label indicates whether provenance data is available. (B) The label indicates the name and version number of the GenAI system that created or altered the content, if applicable. (C) The label indicates whether any digital signatures are available. (D) The label is presented in a conspicuous manner to users. (2) Allow a user to inspect any provenance information in an easily accessible manner. (b) A large online platform shall not do any of the following: (1) Strip any system provenance data or digital signature from content uploaded or distributed on the large online platform. (2) Retain any personal provenance data from content shared on the large online platform. …and… [END] [1] URL: https://alecmuffett.com/article/tag/metadata [2] URL: https://creativecommons.org/licenses/by-sa/3.0/ DropSafe Blog via Magical.Fish Gopher News Feeds: gopher://magical.fish/1/feeds/news/alecmuffett/