AI trust is expanding into a rights and delegation stack
A seven-month cross-signal study measures the shift from post-hoc detection toward provenance, identity, licensing, delegated agent trust, and regulated workflows.
A broader trust stack is forming beyond AI-content detection
The expansion hypothesis is supported, but the stack is uneven. Detection-first tools account for 32.8% of the mutually exclusive GitHub cohort; structural layers now represent 67.2%. Provenance is the deepest reusable structural layer (25 projects). Rights and licensing remain smaller in open source (0) but expose operational consent, revocation, identity, and compensation mechanisms across 9 reviewed platforms. Delegated agent trust is independently visible in 29 projects and in a production payment protocol, connecting media authenticity to a wider market for verifiable digital action.
Market snapshot
Four independent surfaces describe implementation supply, operational products, policy adoption, and market discourse.
Beyond detection
Share of the mutually exclusive GitHub cohort classified as provenance, rights, delegated trust, or regulated governance.
Rights and trust platforms
Reviewed public products and standards with operational mechanisms.
Platform-policy changes
Official changes across 7 organizations.
Market evidence posts
Subject matches across 11 independent Discovery sources.
From detector to trust stack
Each repository is assigned to one primary architectural role here, so the shares sum to 100%.
The structural shift is not the disappearance of detection. Detection is becoming one input inside a wider system that establishes origin before distribution, binds rights to people, and controls who may act or transact.
Five layers are converging
Implementation depth and independent market discussion do not progress at the same speed.
Detection
89Post-hoc classification of synthetic media and deepfakes.
0 Discovery posts · 0 sourcesProvenance
25Signed origin, edit history, content credentials, and watermark verification.
17 Discovery posts · 8 sourcesRights and licensing
0Consent, likeness and voice licenses, data rights, compensation, and revocation.
3 Discovery posts · 2 sourcesDelegated trust
29Identity, intent, authorization, and transaction controls for agents acting for people.
2 Discovery posts · 1 sourcesRegulated workflows
129Audit trails, approvals, policy enforcement, and accountable use in sensitive processes.
4 Discovery posts · 4 sourcesImplementation dynamics
The open-source surface shows whether trust concepts are becoming reusable software rather than policy language alone.
New subject-filtered GitHub repositories by creation month. July covers 28 days. Categories overlap here because one implementation can combine several trust mechanisms.
Content credentials have crossed into platform infrastructure
These figures demonstrate distribution scale, but measure different things and must not be added together.
TikTok AIGC labels
Reported cumulative labels using Content Credentials, creator labels, and invisible watermarking; not C2PA alone.
Google-marked assets
Images and videos marked across Google generative-media products, alongside 60,000 years of audio.
Google verification uses
Reported uses of SynthID verification before its expansion to Search and Chrome.
Measured provenance policy events
Official platform changes in the frozen policy timeline that explicitly include provenance.
Rights products are becoming operational
The question is shifting from “was this generated?” to “who authorized it, for what use, for how long, and who gets paid?”
Explicit consent
88.9% of reviewed platforms or standards expose this mechanism publicly.
Revocation or removal
55.6% of reviewed platforms or standards expose this mechanism publicly.
Compensation or revenue share
44.4% of reviewed platforms or standards expose this mechanism publicly.
Identity binding
88.9% of reviewed platforms or standards expose this mechanism publicly.
Provenance or audit history
55.6% of reviewed platforms or standards expose this mechanism publicly.
Scope and usage controls
88.9% of reviewed platforms or standards expose this mechanism publicly.
Policy is moving from labels to enforceable controls
A selected lower-bound timeline based only on official organization announcements.
Why these markets belong to one stack
The same primitives recur across media, human identity, community data, agent commerce, and regulated operations.
The common product opportunity is a portable trust record: an inspectable chain connecting identity and origin to permissions, transformations, delegated actions, and economic outcomes.
Representative implementations
High-traction projects from the subject-filtered GitHub cohort.
Cross-source market evidence
Discovery publications validate the market narrative but are not included in the GitHub project counts.
Signals tested by this research
A direct link between AILANTA's early observations and the study's measured findings.
Autonomous Agent Security
This signal matches the published research scope: A seven-month cross-signal study of provenance, identity, licensing, delegated agent trust, and regulated workflows.
AI Content Authenticity
This signal matches the published research scope: A seven-month cross-signal study of provenance, identity, licensing, delegated agent trust, and regulated workflows.
Trusted Agent Payments
This signal matches the published research scope: A seven-month cross-signal study of provenance, identity, licensing, delegated agent trust, and regulated workflows.
AI in Regulated Workflows
Regulated workflows reveal where identity, authorization, provenance, and audit records converge operationally.