Every engineering team that reads the EU AI Act's marking obligations has the same first reaction: we can build this. The C2PA SDK is open source, watermarking models are published research, and a sprint later you are stamping manifests and writing rows to a database. So why would anyone pay a third party for content marking and audit?
Because compliance is not about doing the work. It is about proving, later, to someone who does not trust you, that the work was done — and that is a fundamentally different engineering problem.
The self-attestation problem
Your marking logs live in your database, on your infrastructure, administered by your team. When a regulator, a court or a counterparty asks "was this asset marked when it was published in March?", a row in your own database proves nothing: you could have written it yesterday. Auditors call this self-attestation. Courts treat it as weak evidence. It is the compliance equivalent of grading your own exam.
The fix is structural, not procedural: evidence has to be anchored outside your control — append-only cryptographic chains, timestamps signed by an independent authority, storage that rejects overwrites. That machinery is exactly what nobody builds for an internal tool, because on day one it looks like over-engineering. On audit day, it is the entire point.
The maintenance treadmill
Marking is a moving target:
The C2PA specification evolves, and interoperability with platforms and verification tools evolves with it.
Watermark robustness is an arms race. Detection models improve, removal attacks improve, and a watermark that was state of the art in 2024 is not one in 2026.
Signing keys need real key-management discipline — KMS or HSM custody, rotation, and certificate chains that verifiers accept.
Timestamping means operating against a timestamp authority, pinning its certificates, and handling its key rollovers without breaking historical verification.
Building this once is a project. Keeping it audit-grade forever is a permanent tax on your roadmap, paid in engineers, for a capability your customers will never see.
Separation of duties is the feature
There is a reason financial audits are not performed by the finance team being audited. An evidence trail maintained by the same organisation whose conduct it documents has an inherent conflict of interest — however honest the team. Independence is not a nice-to-have on top of the system; it is the property that makes the evidence worth anything.
What "third party" does not have to mean
The common objection is data governance: we cannot ship our media to a vendor. Agreed — and you don't. The Artemis marking plane deploys inside your own infrastructure: your content is marked where it lives, and never leaves. Only cryptographic fingerprints — hashes, a few hundred bytes per asset — reach the evidence layer, where they are chained, anchored daily via an independent RFC 3161 timestamp authority, and preserved in write-once storage. Your signing keys stay in your own KMS or HSM. You get independence of evidence without surrendering custody of content.
The arithmetic
A credible in-house build is months of specialist engineering followed by permanent upkeep — cryptography, media pipelines, key management, audit tooling. Artemis starts at €249 per month, every capability included. But the decisive number is a different one: with Article 50 already in force, provable history only accumulates from the day you start. A backlog of marking can be cleared any time. A backlog of evidence cannot — it can only be missing.
Mark your content where it lives. Let an independent system prove it. Book a pilot.
