The Record and the Decision
The redirect that saved the piece and the re-encode that shrank the file sit next to each other in the chain, both correctly signed.
Vishal Sood was a founding member of Typeface and runs R&D there as President. He joined on the thesis that the next generation of enterprise software would be autonomous systems that hold context and orchestrate workflows instead of tools that people operate. He spent nearly two decades at Microsoft before that, where we overlapped for years and then lost touch. Last month he published Taste as Infrastructure, arguing that you cannot encode taste, because the act of writing the rule down is what moves the target.
I told him I wanted to write a response. He sent back a sharper question than the one I had planned to answer. As agents start writing for humans, he wrote, provenance stops being “where did this come from” and becomes “is the author a person or a model, and does that line even hold.” He got there from content operations. I have been working the same argument from media infrastructure.
The line does not hold. What matters more is what its collapse exposes, which is a limit on what the provenance stack was ever scoped to record. The systems work. They record a true thing that gets less sufficient every quarter.
Two records, one of them built
Two different records are in play, and they are not versions of each other. Process history is what happened. Who touched the asset, when, with which tool, under which credential, and what transform they applied. Decision history is where a person changed the trajectory of the work. One of those is built, signed, and interoperable. The other is not.
C2PA is better than the shorthand criticism of it suggests. The specification does not stamp an asset once at birth and call it finished. A manifest can reference the ones before it as ingredients, so a file can carry a chain rather than a single signature, and a prompt or a seed image handed to a model gets recorded as an input to ingredient. A standard manifest is required to carry an actions assertion. The 2.4 release added a dedicated AI disclosure assertion for machine-readable transparency about AI involvement.
Watch what the standard is building toward. The disclosure work, the source types that mark trained algorithmic media, the identity extensions that bind a named person or organization to an asset. All of it aims at the axis Vishal named. Was a model involved, and who stands behind the result. Regulation is pushing the same direction. The EU AI Act requires AI-generated content to be marked in a machine-readable format, with the obligation landing on August 2 and a transitional period into December for systems already on the market. C2PA is the obvious vehicle for it.
The specification is not ignoring his question. It is investing in it, release after release. None of that investment moves toward significance.
Which step changed the outcome
Walk an actual pipeline. A person sets an intent. An agent drafts two thousand words. The person reads it, kills the framing, and redirects. The agent rewrites against the new direction. Brand rules run over the output and repair what broke. Someone senior reads the result, says one section is soft, and it gets sharpened.
Most of that can be recorded. Tool, timestamp, credential, transform, whether a model was involved. Now ask the record which of those steps changed the outcome.
It has no answer, and the reason is structural. Every entry sits at the same height. The redirect that saved the piece and the re-encode that shrank the file sit next to each other in the chain, both correctly signed, indistinguishable in significance. The record is flat, and flatness is a property it has whether it holds six entries or six thousand.
Volume is not what changed. Media supply chains were never sparse. Ingest, conform, transcode, QC, versioning, packaging, localization, delivery, most of it never mattered creatively. What changed is that the consequential steps used to be taken by the same people taking the routine ones, so a name on a record carried an implication about judgment. Agents break that association. A name on a step says less every year about whether anybody decided anything.
A standards engineer would say the manifest is not trying to answer that question. That is exactly right, and it is the whole argument. This is a claim about scope rather than a complaint about implementation. We built a rigorous record of process, we are about to start asking it questions about contribution, and it was never designed to hold that answer.
Six words
An agent writes two thousand words. A person changes six of them, and those six are the reason the piece works.
Try to record that. Edit count says the contribution was trivial. Token ownership says three tenths of one percent. Time spent says four minutes. Approval checkpoints say one approval, identical to every other approval logged that week. Reviewer comments come closest and remain a proxy, because a comment records that someone spoke rather than that what they said changed the work. I cannot prove those six words mattered either. There is no measurement that isolates the moment judgment enters a piece of work, and I am not proposing one.
The vocabulary is not the missing part either. Approval, sign-off, creative direction, editorial intervention, material contribution. Every production operation in this industry records some version of it already, in comments and ticket histories and approval queues and the memory of whoever ran the room. Decision history exists everywhere as workflow exhaust and nowhere as durable provenance. It gets written down constantly and it never travels with the asset.
Vishal has the same problem from the other end. He wrote in June that a dashboard cannot see failure or breakthrough, because both are judgments about the work and the dashboard only counts motion. That is flatness in a different instrument. His metric, judgment density, counts how many human judgment calls get spent per thousand outputs. He says outright that he has not settled how to count it. He is trying to measure the thing nobody has anywhere to put.
A field is not a semantics
The obvious answer is to add an assertion. The specification permits custom assertions, so nothing technical stops someone from defining a judgment claim and signing it tomorrow. That answer mistakes a container for an agreement.
Finding somewhere in the manifest to store the claim is the easy part. The hard parts are who is entitled to assert that a decision mattered, what precisely they are asserting, whether that assertion survives an organizational boundary, and whether anyone downstream has reason to trust it. Process assertions work because the industry already agreed what a transcode is. There is no comparable agreement about what a consequential judgment is, and you cannot sign your way to one.
That gap has a particular cost here, because attribution in this business is not a courtesy. Credit gets negotiated, contested, and arbitrated, and it runs on records. Those records are about to describe machine-assisted work in more detail than they ever described human work, and they will be more precise about which tool ran than about whether anyone made a call. What follows in contracts and residuals is a separate fight with its own institutions. The record comes first, and the record is flat.
What the chain still owns
None of this is an argument for less provenance. The strongest objection to everything above is that agent proliferation makes the existing record more valuable, and that objection is correct.
If four systems touched an asset before it reached me, I care enormously about which four. That is a question about accountability. Which model was in the chain, whether an unapproved tool got access, who signed for what, and where to look when something goes wrong. Custody, liability, audit, and security all run on process history, and every one gets harder as the number of non-human actors climbs. The manifest chain is the right answer to those questions.
Infrastructure accretes. It rarely replaces. A decision record would sit above the process record and depend on it. Two layers, two jobs, neither substituting for the other.
What does not carry forward
The process is the part agents are taking over. It is being automated at volume, and it is also the only part the record knows how to describe.
What stays with a person is the intervention. The redirect, the six words, the moment somebody with judgment changed where the work was going. That is the scarce input, and it is the one thing the manifest has no grammar for.
Which matters most later, when the work gets inherited. Somebody opens this file in five years, or something does, and the lineage is right there. Every tool, every transform, every signature, all of it verifiable. What will not be there is why the work became this version instead of another one. That reasoning does not survive the handoff, because nobody ever built anywhere to put it.


