CAWG identity assertion 1.2: who made it, not whether it is AI

A CAWG identity assertion says which named actor stands behind an asset. It does not say the asset is AI-generated. What Sume stores that you can pair with it.

4 min readSume
All posts

A CAWG identity assertion lets a named actor document their relationship to an asset. It answers who is vouching for the media, not whether the media was made by AI. Version 1.2 was ratified by the Decentralized Identity Foundation on 15 December 2025. Sume's docs do not describe writing a CAWG assertion into outputs.

Which question answers what

From the specification page, the assertion is about a named actor, an identity claims aggregation and X.509 certificates with COSE signing. Treat the rows as the questions each layer answers.

Provenance questions and where each is answered (read 2026-10-04)
QuestionAnswered bySume writes it?
Who is vouching for this asset?CAWG identity assertion 1.2Not in the docs
Was it made with generative AI?A digital source type such as trainedAlgorithmicMediaNot in the docs
Which Sume job produced the file?Job record and idempotency keyYes, on the job
What note did the caller attach?metadata object on the requestYes, stored on the job, not sent to the provider

What you can attach today

Image requests take a metadata object that is stored on the job and not sent to the provider. A caller can use it to note a disclosure decision and a reviewer, then keep that record next to the job. It is a note in your own records, not a signed assertion embedded in the file.

curl -X POST https://api.sume.com/v1/images \
  -H "Authorization: Bearer $SUME_API_KEY" \
  -H "Content-Type: application/json" \
  -H "Idempotency-Key: label-demo-001" \
  -d '{
    "model": "openai/gpt-image-2.5",
    "prompt": "A product photo of a ceramic mug on a wooden table",
    "image_size": { "width": 1536, "height": 1024 },
    "metadata": { "disclosure": "ai_generated", "reviewed_by": "editor-17" }
  }'

Checking the file before signing

Video inspect reads probe facts and stills from a clip owned by the workspace, and never re-encodes it. That lets a reviewer check what a file contains before someone signs for it.

Plain summary

  • Identity says who. Source type says how it was made.
  • Sume does not embed CAWG or C2PA data in output files, per its docs.
  • Keep job ids and metadata with the signed manifest you build elsewhere.

Sources

Related posts

More in Use cases

All Use cases posts

Written by Sume