Digital Trust Is Becoming More Valuable Than Backlinks

I bought POE in 2017 and timestamped my posts on Po.et's blockchain ledger. The project folded; the idea was just early. Now Google, OpenAI, and Anthropic all mark their output, and cryptographic proof may soon replace links as the trust signal that counts.

At a glance

Key Takeaways

  • Google has spent a decade publicly downgrading links, and the trust function is migrating to corroboration. Gary Illyes has said links aren’t a top-three ranking factor and that Google needs very few of them, while Ahrefs research found branded mentions predict AI visibility better than backlinks, pointing to evidence-based trust rather than vote-based trust.
  • All three major AI labs now mark their output. Google and OpenAI aligned on a dual-layer C2PA plus SynthID model in May 2026 with over 100 billion files watermarked and verification rolling into Search and Chrome, and Anthropic followed in August by watermarking Claude’s generated text worldwide and attaching C2PA metadata to generated files.
  • Regulation fixed the timeline. The EU AI Act’s Article 50 takes full effect August 2, 2026, requiring machine-readable labeling of AI-generated content, with C2PA as the most mature open standard satisfying it.
  • Provenance has real limitations that argue for early competence, not waiting. Metadata stripping, first-mile trust, immature certificate infrastructure, and user apathy are the same growing pains HTTPS survived on its way to becoming the web’s baseline.
  • Publishers can build the proof layer now at near-zero cost. Corroborated author entities, an aggregated authorship page, Content Credentials in the creative workflow, and archived, timestamped original work form a starter stack where every layer strengthens the others.

I’ve spent a good portion of two decades helping trust move around the internet in the form of links. Earning them, analyzing them, occasionally mourning them after a Penguin refresh. The entire economy of my industry was built on a single elegant proxy. A link is a vote, votes signal trust, and trust decides who ranks.

In 2017 I started paying attention to a different idea. A project called Po.et was building an Ethereum-based ledger for timestamping and attributing creative work, running a protocol it called Proof of Existence, and it raised around $10 million in an ICO that August. The following spring it shipped a WordPress plugin that let publishers timestamp their posts on a blockchain, which put it in a small cluster of tools attempting roughly the same thing.

I read those whitepapers more carefully than I’ve read most whitepapers. I installed the plugin and timestamped my own posts. And because I was thoroughly convinced, I bought POE and held it, which is how I learned that being right about a direction and being right about a timeline are two entirely different skills. The token peaked in early January 2018 and spent the years afterward demonstrating what happens to an idea that arrives before its infrastructure. The project eventually wound down, and for a while I filed the whole episode under lessons about my own enthusiasm.

Here’s what I’ve learned in the years since. The idea was right and the infrastructure was wrong, and it took me an embarrassingly long time to separate those two things. Po.et was trying to solve content attribution before a standards body existed, before browsers or search engines could verify anything, before cameras could sign at capture, and before anyone outside a small circle had a reason to care. Every one of those conditions has since changed.

So the past year of intensive research has been about what content provenance looks like now that the infrastructure has caught up: cryptographic signing, verified archives, timestamping, authorship you can prove rather than claim. What I found is camera hardware, browser features, newsroom policy, three major AI labs, and regulation, all converging on the same idea at the same time. The web is getting a trust layer that doesn’t run on votes. It runs on proof.

Here’s what I’ve learned, and why I think this is the most under-covered story in search right now: the marketers who understand the proof layer early are going to own it the way early schema adopters owned rich results. And the window looks a lot like 2012 did for structured data, which is to say, open and closing.

The Backlink Signal Has Been Aging Out, by Google’s Own Account

Let me be precise here, because “links are dead” is the kind of sloppy take that gets people ignored, and it isn’t what the evidence says. The evidence says something more interesting. Links-as-votes degraded as a trust proxy; Google has said so repeatedly on the record, and the trust function links used to serve is being redistributed to other forms of evidence.

The on-record trail is long. At PubCon in 2023, Google’s Gary Illyes said links are not among the top three ranking factors and haven’t been for some time, adding that the industry overestimates their importance. That coverage also includes Duy Nguyen from Google’s search quality team, noting backlinks carry far less impact than in Google’s early years, and John Mueller predicting the weight on links would keep declining. Then in 2024, Illyes went further, remarking that Google needs very few links to rank pages, a statement he half-jokingly confirmed he shouldn’t have said out loud. That same coverage traces the two-decade degradation arc: statistical link-spam detection in the mid-2000s, Penguin in 2012, the 2019 shift to treating nofollow as a hint, and the March 2024 spam documentation update that quietly removed the word “important” from Google’s description of links.

Now the honest complication, because this audience deserves the whole picture. Current AI citation research doesn’t support a simple links-are-over narrative either. SE Ranking’s study of 129,000 domains found referring domains remain the strongest single predictor of ChatGPT citations. Meanwhile, Ahrefs research across 75,000 brands found that branded web mentions, references to you on platforms you don’t control, predicted AI visibility better than backlinks did.

Backlinks tell machines that someone vouched for you. Provenance proves you are who you say you are.

Hold those two findings together, and the synthesis falls out, and it’s the intellectual core of this article: the signal is migrating from links-as-votes to corroboration-as-evidence. Machines increasingly want to establish that you are who you say you are and that independent sources agree. A link is one form of corroboration. A branded mention is another. A review profile is another. And the newest, strongest form, the one this industry hasn’t priced in yet, is cryptographic proof. Links didn’t die. They lost their monopoly.

What Provenance Means

Definitions first, because this vocabulary is about to be everywhere and most of the explainers are written for policy people, not practitioners.

C2PA and Content Credentials. The Coalition for Content Provenance and Authenticity was founded in 2021 by Adobe, Microsoft, the BBC, Intel, Arm, Truepic, and Sony under the Linux Foundation. Its standard, Content Credentials, embeds a cryptographically signed manifest inside a media file recording who created it, with what tool, when, and what edits were applied, including whether AI was involved. Tamper with the file and the signature breaks. It’s the same X.509 certificate model that underpins HTTPS, which is a comparison worth remembering for later.

Hardware signing. This moved from spec to shipping product fast. The Pixel 10 signs every photo at the moment of capture using keys held in its Titan M2 security chip, the first smartphone to do so for all captures, and Leica, Sony, Canon, and Nikon ship C2PA-signing firmware in professional bodies. When the sensor itself signs the file, provenance starts at the point of reality, not the point of upload.

SynthID watermarking. Google DeepMind’s invisible watermark, embedded in AI-generated content at the pixel level. It carries almost no information by itself, but it survives screenshots and re-encodes that strip metadata. Think of C2PA as the rich paper trail and SynthID as the tattoo: complementary, not competing.

Timestamping and authorship verification. The layer closest to what publishers control, giving you independent proof that a specific version of your content existed at a specific time, under a specific identity. I’ve written about the blockchain timestamping side of this before, and it becomes very practical two sections from now.

Watch What They Build: The Provenance Land Grab of 2026

Regular readers know my standing rule: ignore what Google says on stage, watch what it ships. So let’s inventory what shipped, and when you see it all in one place, I think you’ll understand why the nine-year-old idea suddenly has my full attention.

Google joined the C2PA steering committee and said plainly, in its own announcement, that it’s building Content Credentials into its products and co-developing the standard’s security model. That was the opening move. The main event came on May 19, 2026, at I/O, when Google announced in another first-party post that SynthID has now watermarked over 100 billion images and videos plus 60,000 years of audio, that SynthID verification is live in Search and rolling into Chrome, and that C2PA Content Credentials verification is coming to Search and Chrome over the following months. Users can ask Lens, AI Mode, or Circle to Search whether an image is AI-generated, right where they encounter it. The same post announced that Meta will label camera-captured media with Content Credentials on Instagram, and that Pixel’s capture-time signing is expanding from photos to video.

One follow-up worth recording, because announcements and shipping dates are different things. The Gemini piece landed on schedule, and SynthID verification did reach Search. As I publish this, roughly three months after a commitment measured in months, I can find no public confirmation that C2PA verification has gone live natively in Chrome or Search. You can verify Content Credentials in Chrome today, but only through opt-in extensions like Digimarc’s open-source build on the official C2PA library or Adobe’s Content Authenticity extension.

The same day, OpenAI joined the C2PA steering committee and committed to embedding SynthID alongside the Content Credentials it already attaches to generated media, with Nvidia, Kakao, and ElevenLabs adopting in the same wave. Two rival AI labs, publishing on the same day, converged on the same dual-layer verification stack.

Then in August 2026, the third lab moved, and this one lands closer to home for anyone who publishes words rather than pictures. Anthropic signed the EU AI Act’s Article 50(2) Code of Practice on Transparency of AI-Generated Content and began marking Claude’s output with two techniques: an imperceptible watermark woven into generated text, and C2PA-signed provenance metadata attached to generated files. Models launched on or after August 2, 2026 carry it from launch, and the marking applies across every Claude surface and cloud partner worldwide, which is a choice rather than an obligation, since Article 50 only binds systems used inside the EU. OpenAI has reportedly held text-watermarking capability for years without deploying it, which means Anthropic went first on the modality that matters most to publishers.

Meanwhile, the newsrooms moved. BBC, AP, Reuters, AFP, The New York Times, and The Wall Street Journal are actively signing content, and wire desks have begun treating unsigned imagery of major events with suspicion. And regulation fixed the timeline: the EU AI Act’s Article 50 takes full effect August 2, 2026, requiring machine-readable labeling of AI-generated content, with C2PA the most technically mature standard that satisfies it.

When the answer engines, the newsrooms, the camera makers, and the regulators all converge on the same verification stack in the same year, that’s not a trend. That’s infrastructure.

Step back and look at the board. The two dominant answer engines, the major camera manufacturers, the wire services, the biggest social platform, and the regulators all converged on the same verification infrastructure inside roughly one year. I’ve been in this industry long enough to know what that pattern means, because I watched it with HTTPS: optional, then expected, then a ranking consideration, then simply the baseline nobody discusses.

What Text Watermarking Means for People Who Publish Words

Everything above concerns pixels. Cameras, images, video, files. Text marking is the part that touches the actual workflow of most people reading this, so it’s worth being precise about what it does and doesn’t establish.

The mark is statistical, woven into word choice rather than attached as metadata, and it travels with copied text. It can persist through some editing, though heavy paraphrasing, translation, or very short excerpts degrade it. More importantly, a detected mark says the content was processed by Claude, which is a different claim from saying a machine wrote it. Anthropic is refreshingly direct about this in its own documentation: people use these tools to proofread, translate, and summarize, so a mark can land on work whose ideas and sentences originated with a human. The absence of a mark proves even less, since it might mean an older model, a heavily edited passage, or stripped metadata.

Two practical consequences for publishers. First, if your editorial workflow touches an AI assistant at any stage, your published text may now carry a signal you didn’t put there, and the public detection tooling hasn’t shipped yet, so you can’t currently check. Second, and more useful for the argument I’m making here, marking makes your own demonstrated authorship worth more, not less, as it spreads across labs and modalities. Marking establishes what a machine touched. It says nothing about what you made, when you made it, or whether you made it first. That gap is precisely what provenance fills, and it’s getting wider as marking gets better.

The Honest Limitations, Because You Deserve Them

If you’ve read my recent work, you know I refuse to sell a technology without naming its weaknesses, and provenance has real ones. Anyone pitching it as a solved problem is ahead of the evidence.

Start with the pattern the Chrome delay above illustrates, because it’s the structural problem rather than a Google problem. Signing keeps outpacing verification. Cameras sign at capture, three AI labs mark their output, newsrooms sign their photos, and the number of places an ordinary person can actually check any of it grows more slowly than the number of things being signed. Provenance only pays off at the moment somebody verifies, and that moment is still the bottleneck.

Another big problem is metadata stripping. Many platforms and delivery pipelines still strip C2PA manifests during upload and transcoding, which means signed content frequently arrives in front of viewers with its credentials gone.

There’s also what researchers call the first-mile problem. A credential proves that a recognized device or tool signed a file at a certain time. It cannot prove the camera was pointed at what the caption claims. Provenance verifies the chain of custody, not the truth of the scene.

The trust infrastructure is young and occasionally breaks. Nikon added C2PA signing to the Z6 III, discovered a signing vulnerability, and had to revoke every certificate those cameras had issued, invalidating their credentials. Growing pains, documented in the same adoption analysis above. The newest layer arrived with the newest gap, too: Claude’s text watermarking shipped before any public detection tool did, which leaves a mark almost nobody can currently verify. And there’s plain human apathy: even where credential badges display, most users don’t click them yet.

Here’s why none of this changes my conclusion. Every trust infrastructure the web has ever adopted looked exactly like this in its early years, HTTPS very much included: patchy support, broken certificates, user indifference. The limitations are an argument for building competence early, while mistakes are cheap and the field is empty. They are not an argument for waiting.

Provenance Meets E-E-A-T: The Part You Control

Most of what I’ve described so far concerns media files, cameras, and platforms. So let me bring it home to the thing every publisher reading this controls completely: authorship.

E-E-A-T has always had an awkward secret, which is that most of its signals are claims. A bio claims experience. A byline claims authorship. An about page claims a history. The provenance shift is the move from claimed identity to demonstrated identity: author entities corroborated across independent platforms, original work that carries verifiable timestamps, a public record of what you published and when, and how it changed. This is the machine-verifiable version of Experience and Trust, and it slots directly into the Trust Stacking layer of my authority framework, where each piece of evidence corroborates the others until the identity becomes expensive to fake.

Concretely, that means your Person schema and sameAs profiles agreeing with each other everywhere they appear, your original research carrying independent proof of priority, and your revision history being something you can show rather than assert. Which brings me to the part where I stopped theorizing.

What I’m Testing Right Now: WP ContentLedger

Regular readers know I don’t like recommending things I haven’t run in production, so for the past stretch of this research I’ve been building the publisher side of the provenance stack as a WordPress plugin. Nine years after running someone else’s version of this idea and watching it fold, that’s either persistence or a personality defect. It’s called WP ContentLedger, and it’s not yet a public release. I want to walk through its architecture here, not as a pitch, but because it’s the clearest way I know to make this article’s ideas concrete.

The design principle is layered corroboration, the same principle running through everything above. A WordPress publication date is useful, but it’s an editable field. A web archive proves a URL was publicly accessible, but says nothing about authorship. A content hash proves whether something changed, but needs an independent timestamp to prove when a version existed. No single layer proves everything, so the plugin refuses to ask any single layer to.

Every published version generates a deterministic content manifest: canonical URL, author, publisher, dates, revision details, and SHA-256 fingerprints, with each new manifest referencing the previous one’s hash so revisions form a tamper-evident chain. The public page gets submitted to the Internet Archive with capture verification, so accessibility is attested by a party that isn’t me. The manifest hash gets anchored to the Bitcoin blockchain through the OpenTimestamps protocol, producing a downloadable proof that this exact version existed before a verifiable point in time. And the whole history publishes to a public, machine-readable ledger built on Schema.org vocabulary, which ties this article back to the machine-readability arguments I’ve made before: provenance that machines can’t parse is provenance that machines can’t reward.

Now the same candor I demanded of C2PA. Timestamps prove a manifest existed at a time; they do not make a legal determination of copyright ownership. Your article is never placed on the blockchain, only a cryptographic commitment to it. And no plugin, mine included, can guarantee rankings or claim a direct E-E-A-T boost, because Google has never confirmed consuming any of these signals for ranking. What I can tell you is what I designed for, which is a transparent, portable publishing history that readers, partners, and machines can independently inspect. Portable is the operative word. The receipts remain verifiable with standard open tools even if you uninstall the plugin, because evidence that depends on a vendor isn’t evidence; it’s a subscription.

Through my testing across my own properties, the interesting effects so far are less about algorithms and more about posture. Original research with a public provenance trail is easier to defend, easier to cite, and easier to distinguish from the AI-generated flood. I’ll publish concrete findings as they accumulate, including the null results.

A Starter Provenance Stack for Publishers

You don’t need to buy anything, including from me, to start building this competence. Based on my experience, here’s the sequence that compounds.

Start with identity. Complete Person and Organization schema, with sameAs pointing to profiles that corroborate each other, one canonical name everywhere. This is free, and it’s the foundation every other proof attaches to.

Then aggregate the evidence: an authorship page that collects your verifiable footprint, publications, appearances, credentials, in one machine-readable place.

Then add capture-side credentials where your tooling allows: the Adobe pipeline preserves Content Credentials through editing, and if you shoot original imagery, hardware that signs at capture now exists at consumer prices.

Then protect your original work with archiving and timestamping. The manual path costs nothing: Save Page Now for an independent archive record, protocols like ScoreDetect for a blockchain-anchored timestamp. If you publish on WordPress at volume, that’s the workflow WP ContentLedger automates, but the manual version teaches you exactly what the proofs mean, and I’d recommend doing it by hand at least once for that reason.

None of these moves is expensive. All of them compound, because provenance is cumulative by nature: every signed, timestamped, corroborated piece makes the next one more credible.

The Next Evolution After HTTPS

I keep returning to the HTTPS comparison because I lived through it and the cadence is precise. A cryptographic trust technology, initially dismissed as overkill for ordinary sites. Browser vendors building it into the interface. A search engine gently rewarding it. Regulators and platforms hardening it into a requirement. And then one day it’s simply the floor, and the sites that waited are doing a stressful migration while the early movers are doing nothing at all.

Provenance is on that arc, and the regulators are already writing the enforcement chapter with a deadline measured in weeks. I’m not telling you the algorithm rewards content signing today; I have no evidence it does, and I won’t pretend otherwise. I’m telling you the infrastructure being built around search makes verifiable trust the direction of travel, and that direction has been visible in what Google ships for over a year to anyone watching the builds instead of the blog posts.

I’ll be publishing my provenance experiments as an ongoing thread, including the failures, because that’s the only kind of research worth reading. If you’re testing content signing, timestamping, or authorship verification on your own properties, I’d genuinely love to compare notes. The practitioners running experiments right now are the ones who’ll write the playbook everyone else buys in two years.

Frequently asked questions

Questions, answered

Direct answers on C2PA, Content Credentials, backlinks in the AI era, and adding provenance to your own site.

What are C2PA Content Credentials?

Cryptographically signed manifests embedded in media files that record who created the content, with what tools, when, and what edits were applied, with any tampering breaking the signature.

Do backlinks still matter for SEO and AI citations?

Yes, referring domains remain the strongest single predictor of ChatGPT citations in current research, but Google has repeatedly downgraded links on the record, and branded mentions now predict AI visibility better, so links are one corroboration signal among several rather than the privileged one.

What does the EU AI Act require for content labeling?

Article 50, fully effective August 2, 2026, requires machine-readable marking of AI-generated content, which is why Claude models launched on or after that date now embed watermarks in generated text and attach C2PA metadata to generated files, with C2PA the most mature open standard on the file side.

How do I add provenance signals to my website?

Start with a corroborated Person and Organization schema, preserve Content Credentials throughout your creative workflow, and archive and timestamp the original work using Save Page Now and a tool like ScoreDetect, either manually or via automation.

Can Content Credentials be faked or removed?

Manifests can be stripped by screenshots, re-encoding, and many platform pipelines, which is why they’re increasingly paired with invisible watermarks like SynthID, but a valid credential can’t be forged without breaking its cryptographic signature.

Brian Winum

Written by Brian Winum

Digital marketing veteran, partner at MAXBURST and MAXPlaces, and creator of LLMS Amplifier and Authority Amplifier.

Get new posts by email

No fluff. No spam. Just the useful stuff.