Learn

TrustNets and C2PA: building content you can actually trust

A TrustNet is a secure tunnel for sharing important content so recipients can trust it has not been tampered with. The enabling technology, per Gartner's Dave Aron, is C2PA, the Coalition for Content Provenance and Authenticity, which attaches a verifiable label showing who created a piece of content and whether it is authentic, like a nutrition label for media.

The internet is the wild west

The strength of the internet is also its weakness. As Gartner’s Dave Aron, co-author of World Without Truth, puts it: “anyone can publish anything. Truth, lies, great content, terrible content.” For most posts that is fine. For the content your business depends on, your earnings release, your CEO’s statement, your annual report, it is a problem. How does anyone receiving it know it is genuinely from you, and unaltered?

TrustNets: secure tunnels for important content

Aron’s answer is what he calls TrustNets: “virtual tunnels through the internet where, if you want to communicate some important content safely, like say your annual report, you’ll be able to do that through the mechanisms of a TrustNet.” It is not a walled-off internet. It is a way to wrap verifiable trust around the specific content that matters, so a recipient can be confident of its origin and integrity. He predicts the concept will “become commonplace.”

C2PA: a nutrition label for content

The technology underneath is C2PA, the Coalition for Content Provenance and Authenticity. Aron describes it as “stamping a label much like food in the supermarket will have a nutrition label”, a secure record of “the provenance, i.e. who created this content”, and “the authenticity, any details about it.” It travels with the file, so a verified piece of content carries proof of where it came from.

This is already arriving in hardware and platforms. Aron notes the Google Pixel 10 and Sony news cameras “now support C2PA content credentials”, and that LinkedIn applies this kind of labelling too. The provenance layer is being built into the tools that create and distribute content.

Provenance is half the job

Here is the important distinction for any leader building a defence. Provenance proves your own content is real. It does nothing about the synthetic media and coordinated narratives created against you. As Aron frames TrustOps, there are two jobs: grounding the information you rely on and publish, and debunking the false narratives in the market. C2PA and TrustNets are powerful tools for the grounding half. They are not a detection system for the debunking half. (We unpack the full operating model in building TrustOps for the AI era.)

That is where AI Uniti fits, and the two halves reinforce each other. Provenance establishes what is authentically yours; narrative threat intelligence watches for what is being manufactured about you. Signal scores the coordination behind a campaign and raises explainable alerts early. Content-authenticity detection is on our roadmap as a corroborating signal: when a coordinated cluster is amplifying synthetic media, authenticity confirms the media and behaviour confirms the campaign, a stronger, more defensible verdict than either alone, and the kind of combined defence Unite is built to coordinate. Ground your own content with C2PA. Watch the open web with behavioural detection. You need both, which is exactly what the 90-day preparedness plan sequences.

Provenance proves your content is real. Behavioural detection catches what is being faked about you. See how Signal covers the second half, or book a 15-minute demo.

Frequently Asked Questions

What is C2PA?

C2PA (Coalition for Content Provenance and Authenticity) is an open standard for attaching a secure, verifiable label to digital content, recording its provenance (who made it) and authenticity. Gartner's Dave Aron likens it to a nutrition label for media. Devices like the Google Pixel 10 and Sony cameras already support it.

What is a TrustNet?

A TrustNet, per Aron, is a virtual tunnel for communicating important content so recipients can trust it has not been tampered with, wrapping verifiable trust around high-stakes material such as annual reports.

Does C2PA stop deepfakes and disinformation?

Not on its own. C2PA proves your own content is authentic (the grounding job). It does not detect synthetic media or coordinated campaigns created against you (the debunking job), which needs detection and behavioural monitoring.

How should we start with content provenance?

Begin with your highest-stakes content, such as quarterly and annual reports, and apply provenance standards like C2PA. Pair it with monitoring of the open web so you cover both halves of TrustOps.

See Signal by AI Uniti detect the coordination behind an attack 6 to 12 hours before conventional monitoring.