Moolam

Concepts

Rules and standards

En esta página

Three published texts decide how AI pictures have to be marked: the EU AI Act, the European Commission's Code of Practice on transparency, and the C2PA standard itself. This page describes those rules as published and says where Moolam sits against them. It is not legal advice.

The marking duty in the AI Act

Article 50(2) of Regulation (EU) 2024/1689 binds providers of AI systems that generate synthetic audio, image, video or text content. They "shall ensure that the outputs of the AI system are marked in a machine-readable format and detectable as artificially generated or manipulated". Paragraph 4 binds deployers instead, and only for deep fakes: a deployer "shall disclose that the content has been artificially generated or manipulated", with a carve-out for evidently artistic, satirical or fictional work. Article 113 of the same regulation dates it: "It shall apply from 2 August 2026".

Moolam is a registry and a verify service. Registering a picture here does not make a provider or a deployer compliant with Article 50, and nothing on this site should be read as saying it does.

The Code of Practice, and which layer Moolam is

The Code of Practice on Transparency of AI-generated Content (European Commission, 10 June 2026) is voluntary. Its signatories commit to "at least two layers of machine-readable marking": digitally signed metadata (Sub-measure 1.1.1) and imperceptible watermarking (Sub-measure 1.1.2). Fingerprinting or logging is an optional further layer, and the Code is plain about its limits: "relying on fingerprinting or logging alone is not considered sufficient to meet the quality requirements specified in Article 50(2) AI Act and in Commitment 3."

LayerWhat Moolam does today
Digitally signed metadataWrites a signed C2PA manifest for every picture it registers.
Imperceptible watermarkingNothing. Moolam does not add a watermark.
Fingerprinting and loggingTwo perceptual fingerprints per picture and a public registry on Monad. By the Code's own words, this layer alone is not enough.

So Moolam is one part of a marking stack, not the whole of it. Anyone marking output to the Code would still need a watermarking layer beside what Moolam writes.

What C2PA asks for, and what it does not

The C2PA specification never mentions a blockchain. The word "blockchain" and the phrase "distributed ledger" appear nowhere in the 2.1 text. TrueScreen's FAQ states it directly: "Does C2PA use blockchain? No. C2PA does not rely on blockchain or any distributed ledger technology... while still providing verifiable provenance through a decentralized trust model based on certificate authorities included in the official C2PA Trust List."

What the standard does define is the soft binding, section 18.9: "if a C2PA manifest is removed from an asset, but a copy of that manifest remains in a provenance store elsewhere, the manifest and asset may be matched using available soft bindings." It also defines a Manifest Repository, section 2.4.4: "A repository into which C2PA Manifests and C2PA Manifest Stores can be placed, and which can be searched using a content binding."

Moolam's registry is one such repository, searchable by the fingerprint of a copy. Putting it on Monad is Moolam's own design choice. The specification does not ask for it and does not sanction it. Fingerprints has the measured numbers for what survives and what does not.

Reserving a picture from AI training

A separate rule governs the other direction: not marking AI output, but a creator refusing to have their work used as training data. Article 4(3) of Directive (EU) 2019/790 makes the text and data mining exception conditional, and says the condition is machine readable: it applies "on condition that the use of works and other subject matter referred to in that paragraph has not been expressly reserved by their rightholders in an appropriate manner, such as machine-readable means in the case of content made publicly available online."

That is context, not a claim. Moolam does not say that writing a statement here is an appropriate reservation in the meaning of that Article, because that is not Moolam's to decide.

What Moolam actually does is two things, and both ship today.

WhereWhat is written
Inside the fileA Creator Assertions Working Group Training and Data Mining assertion, version 1.1, label cawg.training-mining, inside the signed C2PA manifest
On MonadThe same four values and any conditions text, appended with the block's timestamp to MoolamConsent, where only the passport's holder can write and nothing is ever edited

The vocabulary is the standard's, not Moolam's: aiTraining, aiGenerativeTraining, aiInference and dataMining, each allowed, notAllowed or constrained. The contract names the version on chain so a reader never has to guess. The standard also settles the awkward case: "In the absence of additional information, constrained shall be treated as equivalent to notAllowed."

The second row exists because the first can be removed. A platform that recompresses a JPEG throws the manifest away, and the refusal goes with it. The chain copy is not in the file, so it survives that, and it answers for any past date rather than only for today.

The C2PA specification does not ask for this and does not sanction it. It defines the assertion format and a soft binding; putting the same statement on a ledger is Moolam's own design choice, the same as putting the fingerprints there. Nothing in the specification mentions a blockchain, as the section above says.

And none of it enforces anything. The register cannot stop a crawler that ignores it. It makes ignoring it provable, with a date, which is a different and smaller claim. Say how AI may use a picture is the creator's version of this page.

History, not truth

The standard's critics and Moolam's own docs land in the same place. TrueScreen puts it as "C2PA certifies content history, not truth". The trust model says the same of a passport: it proves who registered first, not who made the picture, and for a human photo it is a timestamped claim and nothing stronger. When a record is wrong, the route is a bond and a challenge rather than an argument about the signature, which is what Disputes describes.