Detection vs. provenance: what the Orélien case teaches us about C2PA, CAWG and the AI Act

September 2026 Analysis Content Provenance 101

A bestselling French novel, an anonymous accusation and an AI detector's score: the recent controversy around Thelyson Orélien's "C'était ça ou mourir" shows why a probability is not proof. Florian Barbaro, PhD, CEO of UncovAI, a Provenance For Trust member, put it plainly to Le Parisien: a score is a lead, not a verdict.

In brief: AI detectors estimate, they don't know. Provenance standards (C2PA and CAWG) provide evidence about what happened to a piece of content and who stands behind it. And since 2 August 2026, Article 50 of the EU AI Act makes marking and labelling of AI-generated content a legal obligation, not a nice-to-have.

What happened, and what the case shows

Thelyson Orélien's novel C'était ça ou mourir became one of the literary season's biggest names. An anonymous account then claimed the book was not written by a human, relying on the score of an AI detector. Asked by Le Parisien, Florian Barbaro explained why such a claim needs caution.

According to his analysis, these tools don't "know" anything. They pattern-match: trained on large volumes of text, they scan it paragraph by paragraph looking for statistical fingerprints. The main weakness is false positives. Writers working in a language that is not their mother tongue are flagged more often, because simple sentences and a limited vocabulary can look "robotic" to a machine.

The lesson is not that detection is useless. It is that a detector output is an indication to investigate, never a conclusion. When a career or a work's reputation is at stake, an estimate is not enough.

Source: Polémique sur le roman de Thelyson Orélien : comment fonctionnent ces détecteurs d'IA dans un texte, Le Parisien, 23 September 2026.

Detection estimates. Provenance documents.

Detection looks at a finished piece of content and guesses how it was made. Provenance works the other way around: it records how the content was made, as it is made, in a form that can be checked later. The two are complementary, and neither replaces the other.

Approach What it tells you Limit
AI detection A statistical estimate that content may be AI-generated Can be wrong, especially on short, simple or non-native writing; not proof
C2PA What happened to a file: tools used, edits, AI involvement, tamper-evident signature Proves integrity and history, not who is behind it
CAWG Who claims to have made it, through verifiable identity assertions Depends on C2PA; adds identity, not history
AI Act, Art. 50 What providers and deployers must mark and disclose Sets duties; needs technical standards to be applied in practice

C2PA: the technical history of a piece of content

C2PA (Coalition for Content Provenance and Authenticity) defines a manifest attached to a file: a tamper-evident record of the tools used, the edits made and whether AI was involved at any stage. The cryptographic signature breaks if the file is altered without the manifest being updated. C2PA is most mature for images, video and audio, and adoption in newsrooms is moving from pilots to production: at the Media Provenance Summit in Bergen, AFP, the BBC, CBC/Radio-Canada and Paris Match presented their work on C2PA-signed content.

CAWG: who stands behind the content

CAWG (Creator Assertions Working Group) builds on the C2PA manifest and adds verifiable identity. Organisations such as newsrooms and publishers can rely on X.509 certificates, while individual creators can rely on identity claims aggregators. In a case like the Orélien controversy, identity is the missing piece: a verifiable statement from the author or publisher about how the work was produced carries far more weight than an anonymous accusation or a detector score.

Not sure how the two fit together? Read our explainer C2PA vs. CAWG: What's the Difference?

AI Act compliance: what Article 50 requires

Article 50 of the EU AI Act, on transparency obligations, has applied since 2 August 2026. It splits responsibilities between two roles:

  • Providers of generative AI systems must mark their outputs in a machine-readable format so that they can be detected as artificially generated or manipulated (Article 50(2)). Generative systems already on the market before 2 August 2026 have until 2 December 2026 to meet this marking requirement.
  • Deployers must disclose deepfakes and AI-generated text published to inform the public on matters of public interest, unless the text has undergone human review or editorial control by someone who holds editorial responsibility (Article 50(4)).

The Commission has assessed the voluntary Code of Practice on Transparency of AI-generated Content as an adequate way to demonstrate compliance with these marking and labelling obligations. Signing it is optional, but organisations that do not sign will need to show compliance by other means.

Two points matter for media and publishing. First, the AI Act sets obligations but does not mandate a specific technical standard: C2PA metadata, alongside complementary techniques such as watermarking, is how these obligations can be met in practice. Second, the Article 50(4) duty on AI-generated text targets content published to inform the public on matters of public interest. A novel generally falls outside that scope. In other words, for creative works, voluntary and verifiable provenance is the only reliable way for an author or a publisher to document how a work was made.

What this means for newsrooms, publishers and fact-checkers

  • Never publish an accusation on a score alone. Treat detector output as a lead and look for corroborating evidence.
  • Document your production process. Sign content with C2PA and attach a verifiable identity with CAWG where your workflow allows it.
  • Map your Article 50 duties. Identify whether you are a provider, a deployer or both, and where AI-generated content appears in your output.
  • Combine layers. Metadata, watermarking and detection each have limits; used together, they produce stronger evidence.

Where Provenance For Trust fits

Provenance For Trust is an innovation programme led by TrustMyContent, UncovAI, the Journalism Trust Initiative (launched by Reporters Without Borders), CEPIC, l'Atelier and Sciences Po Paris's médialab. It delivers a toolkit of technical solutions, methodology and expertise to guarantee the authenticity, traceability and credibility of information, across six themes: certification, copyright, authenticity, AI transparency, typosquatting and anti-scraping. Its members cover both sides of this story: detection expertise on one side, provenance and certification on the other.


Frequently Asked Questions

Can an AI detector prove that a text was written by AI?
No. Detectors produce a statistical estimate based on patterns, and they can generate false positives, notably on writing by non-native speakers. A score should be treated as a lead to investigate, not as a verdict.
What is the difference between C2PA and CAWG?
C2PA records what happened to a file (tools, edits, AI involvement) and detects tampering. CAWG adds verifiable identity on top of the C2PA manifest, showing who claims to have made the content.
Since when does Article 50 of the AI Act apply?
Since 2 August 2026. Generative AI systems already on the market before that date have until 2 December 2026 to comply with the machine-readable marking requirement of Article 50(2).
Does the AI Act require C2PA?
No specific standard is mandated. The Act requires machine-readable marking and disclosure, and C2PA metadata is one of the practical ways to meet these obligations, together with complementary techniques such as watermarking.
Does the AI Act require novels to be labelled as AI-generated?
The text-labelling duty in Article 50(4) applies to AI-generated text published to inform the public on matters of public interest, so a novel generally falls outside it. This is a general reading, not legal advice; check your specific situation with a legal professional.
Newsroom, publisher, agency or fact-checking team? Help shape the toolkit in our workshops.
Join the collective
C2PA CAWG AI Act Article 50 AI Detection Content Provenance Digital Trust
Précédent
Précédent

Détection vs provenance : ce que l'affaire Orélien nous apprend sur C2PA, CAWG et le RIA

Suivant
Suivant

Media Provenance Summit 2026 in Bergen: C2PA in Newsrooms