The marking obligation
The workspace's three switches — whether, for what, and when the visible label is binding.
A workspace can make the visible label binding. The switches for it sit under Settings → „Defaults“, below the label defaults — for owners and admins only.
Not to be confused with the defaults above them: those say what a new output starts with. The obligation says what is no longer possible without a label.
The signed-in product speaks German, so its labels and messages are quoted in German throughout, with the English rendering in italics.
The three switches
„Label verpflichtend“ (Label required) — the main switch. Below it stands what it means: „Ohne Label sind betroffene Derivate nicht herunterladbar.“ (Without a label, affected derivatives are not downloadable.)
„Nur KI-Assets“ / „Alle Assets“ (AI assets only / All assets) — the scope.
„Schon beim Anlegen verweigern“ (Refuse at creation) — moves the check from the download to the save.
The lower two are greyed out while the main switch is off. They stay keyboard-focusable, so screen readers can read out the explanation beside them.
The rule
The obligation applies when „Label verpflichtend“ is on and either the scope is „Alle Assets“ or the asset carries an AI provenance according to its manifest. With the main switch off, the scope is not read.
"AI provenance" is not a guess. It means exactly two defined provenance values, taken from the manifest unchanged — verstag does not infer and does not look at the picture.
From that follows the most important difference between the two scopes: „Alle Assets“ also covers assets whose provenance was never established — everything neither identified as AI nor evidenced as non-AI.
„Alle Assets“ applies retroactively
Switching to „Alle Assets“ locks outputs that already exist. Derivatives without a label that were downloadable yesterday are blocked from the moment you save. The interface says so in a warning line under the choice.
Two subtleties:
- The warning line appears every time you open the page while the obligation is on and the scope is „Alle Assets“ — not only at the moment of switching.
- It does not appear while the obligation is off — not even with „Alle Assets“ selected.
The switch gets a line of its own in the audit trail.
What is judged at download time is the provenance the derivative received when it was created — not a freshly read asset provenance.
What is blocked and what is not
The download of a derivative without a label is refused, and the user reads: „Die Kennzeichnungsvorgabe dieses Arbeitsbereichs verlangt ein sichtbares Label.“ (This workspace's marking policy requires a visible label.)
Two things are not blocked — the obligation applies to the rendered image, not to its record:
- The C2PA manifest stays downloadable even where the derivative is blocked.
- The original stays downloadable.
A refused download leaves no row in the Content Credentials record. A permitted download, by contrast, records which policy it was judged under: whether the derivative carried a label, whether the obligation applied, and with which scope.
What you see of it in the editor
The label switch disappears entirely once the obligation applies to that asset. In its place stands: „Das Label ist durch die Tenant-Policy vorgeschrieben — ohne Label bleibt dieses Derivat nach dem Rendern nicht herunterladbar.“ (The label is required by the tenant policy — without one this derivative stays undownloadable after rendering.)
Under the obligation the label is not merely unswitchable but actively switched on — even where the stored default says off. Only "on" is ever forced, never "off", and only where a label family exists at all.
The batch applies a coarser rule
The batch wizard reads only the main switch and ignores the scope. With the obligation on, the label is fixed on for the whole batch.
Its note always says AI assets, whatever the scope: „Das Label ist durch die Tenant-Policy vorgeschrieben — KI-Assets ohne Label bleiben nach dem Rendern nicht herunterladbar.“
A cell that fails the obligation keeps its result and changes its status chip to „Fertig, nicht herunterladbar“ (Done, not downloadable). The reason stands beside it: „Kennzeichnungspflicht — Download ohne Kennzeichnung ist gesperrt.“
In a ZIP export a blocked file is listed by name with its reason in a
HINWEIS.txt inside the archive.
The block is re-evaluated on a retry — the workspace may have relaxed the obligation in the meantime.
The third switch
„Schon beim Anlegen verweigern“ is off by default. Without it, derivatives without a label are produced as normal and only their download is refused; with it, the save already fails, with „Für dieses Asset ist ein Label verpflichtend.“ (A label is required for this asset.)
In the normal flow it does not fire, because the editor and the batch lock the switch on under the obligation anyway.
Video never reaches the policy
A video derivative always carries a label — the video editor does not show the switch. So the policy is not handed to the video editor.
What applies with nothing saved
The obligation answers "required" where no entry exists or it is damaged. A workspace has to opt out explicitly.
Scope and creation block answer „Nur KI-Assets“ and off.
Reading the policy is permitted to every role, unlike the settings themselves.
The record
Each of the three changes writes its own row, under its own name, and only where the value changed:
- „Label-Pflicht geändert“ · detail:
optional → enforced - „Label-Geltungsbereich geändert“ · detail:
ai → all - „Label-Sperre beim Anlegen geändert“ · detail: „Nein → Ja“ (No → Yes)
The first two show the technical values, the third German words.