{
  "slug": "content-provenance-for-ai-agents",
  "title": "How to Verify Content Provenance for AI Agents with C2PA",
  "description": "A three-state decision procedure — valid manifest, invalid signature, absent manifest — for what an AI agent's ingestion pipeline should do differently with a web image, an email attachment, or a retrieved document, plus a checklist for wiring a C2PA reader library into that pipeline as a gate before content reaches the model.",
  "kind": "sub",
  "order": 9,
  "target_query": "how to verify content authenticity for AI agents",
  "secondary_queries": [
    "C2PA content credentials for AI agents",
    "verifying media provenance before an agent ingests it",
    "what to do when content has no C2PA manifest",
    "wiring C2PA manifest checks into an ingestion pipeline"
  ],
  "tags": [
    "agents",
    "security",
    "c2pa",
    "content-authenticity",
    "provenance",
    "multimodal"
  ],
  "published": "2026-09-16",
  "updated": "2026-09-16",
  "words": 1774,
  "estimated_tokens": 2359,
  "premium": false,
  "rights": {
    "access": "free",
    "note": "Editorial guides are always free and never part of the licensed corpus.",
    "license": "https://changegamer.ai/license.xml",
    "pricing": "https://changegamer.ai/api/pricing.json",
    "payment": "https://changegamer.ai/api/payment.json"
  },
  "license": "https://changegamer.ai/license.xml",
  "citation": "ChangeGamer (2026-09-16). How to Verify Content Provenance for AI Agents with C2PA. ChangeGamer. https://changegamer.ai/articles/content-provenance-for-ai-agents (updated 2026-09-16).",
  "bibtex": "@misc{changegamer_content_provenance_for_ai_agents, title = {How to Verify Content Provenance for AI Agents with C2PA}, publisher = {ChangeGamer}, year = {2026}, url = {https://changegamer.ai/articles/content-provenance-for-ai-agents}, note = {Updated 2026-09-16}}",
  "canonical": "https://changegamer.ai/articles/content-provenance-for-ai-agents",
  "markdown": "https://changegamer.ai/articles/content-provenance-for-ai-agents.md",
  "takeaways": [
    "A valid C2PA manifest tells an AI agent that someone made a signed provenance claim about a file, not that the claim itself is true.",
    "An absent C2PA manifest proves nothing about a file's origin, because ordinary re-encoding and platform re-uploads strip manifest metadata just as completely as deliberate tampering does.",
    "An invalid or tampered C2PA signature is a materially stronger warning sign than a missing manifest, since a broken signature means the file changed after it was already signed.",
    "Google's Pixel 10 camera, announced in September 2025, became the first mobile camera reported to satisfy C2PA's Conformance Program Assurance Level 2, generating its signature from a hardware-backed secure element rather than software alone.",
    "A signed C2PA manifest says nothing about whether the content it is attached to is safe for an agent to follow as an instruction, because provenance and instruction-safety are separate checks answered by separate controls.",
    "Verifying a media file's C2PA provenance uses an entirely different trust mechanism than verifying a software dependency's supply-chain provenance, since one checks a claim embedded in the file itself and the other checks how a package was built."
  ],
  "outline": [
    {
      "depth": 2,
      "text": "What does a C2PA manifest actually prove?",
      "anchor": "what-does-a-c2pa-manifest-actually-prove",
      "url": "https://changegamer.ai/articles/content-provenance-for-ai-agents#what-does-a-c2pa-manifest-actually-prove"
    },
    {
      "depth": 2,
      "text": "A three-state decision procedure for agent ingestion",
      "anchor": "a-three-state-decision-procedure-for-agent-ingestion",
      "url": "https://changegamer.ai/articles/content-provenance-for-ai-agents#a-three-state-decision-procedure-for-agent-ingestion"
    },
    {
      "depth": 2,
      "text": "Does a missing manifest mean content was tampered with?",
      "anchor": "does-a-missing-manifest-mean-content-was-tampered-with",
      "url": "https://changegamer.ai/articles/content-provenance-for-ai-agents#does-a-missing-manifest-mean-content-was-tampered-with"
    },
    {
      "depth": 2,
      "text": "How do you wire a C2PA check into an agent's ingestion pipeline?",
      "anchor": "how-do-you-wire-a-c2pa-check-into-an-agent-s-ingestion-pipeline",
      "url": "https://changegamer.ai/articles/content-provenance-for-ai-agents#how-do-you-wire-a-c2pa-check-into-an-agent-s-ingestion-pipeline"
    },
    {
      "depth": 2,
      "text": "Does a valid manifest mean the content is safe to act on?",
      "anchor": "does-a-valid-manifest-mean-the-content-is-safe-to-act-on",
      "url": "https://changegamer.ai/articles/content-provenance-for-ai-agents#does-a-valid-manifest-mean-the-content-is-safe-to-act-on"
    },
    {
      "depth": 2,
      "text": "How does content provenance differ from supply-chain provenance for AI agent dependencies?",
      "anchor": "how-does-content-provenance-differ-from-supply-chain-provenance-for-ai-agent-dependencies",
      "url": "https://changegamer.ai/articles/content-provenance-for-ai-agents#how-does-content-provenance-differ-from-supply-chain-provenance-for-ai-agent-dependencies"
    },
    {
      "depth": 2,
      "text": "Where this leaves you",
      "anchor": "where-this-leaves-you",
      "url": "https://changegamer.ai/articles/content-provenance-for-ai-agents#where-this-leaves-you"
    }
  ],
  "faq": [
    {
      "question": "What should an AI agent do when a file has no C2PA manifest at all?",
      "answer": "Treat the absence of a manifest as evidence that no provenance claim was ever made, not as evidence the content is inauthentic or was deliberately altered, and apply whatever default trust posture the agent already uses for any unlabeled file — ordinary re-encoding, screenshotting, and platform re-uploads strip manifest metadata routinely, with no adversarial intent required."
    },
    {
      "question": "What is the difference between an invalid C2PA signature and a missing manifest?",
      "answer": "An invalid or tampered C2PA signature means a manifest exists but its signature no longer validates against the Conformance Program trust list, which indicates the file was altered after it was signed — a materially stronger warning sign than a missing manifest, which only means no claim was embedded in the first place or one was lost through ordinary re-encoding."
    },
    {
      "question": "Does a valid C2PA manifest mean an AI agent can safely follow instructions found in that content?",
      "answer": "No — a valid C2PA manifest verifies a claim about a file's origin and edit history, but says nothing about whether text riding along with that file, in a caption, embedded metadata, or the pixels themselves, is safe for an agent to treat as an instruction; that question belongs to prompt-injection defense, a separate control from content-provenance verification."
    },
    {
      "question": "Is C2PA content provenance the same thing as supply-chain provenance for AI agent dependencies?",
      "answer": "No — C2PA content provenance verifies a claim embedded inside a media file an agent ingests, such as an image or video, while supply-chain provenance verifies packages, models, and MCP servers at install, load, or connect time using entirely different formats such as SBOMs and SLSA attestations; the two cover different artifact classes and neither one substitutes for the other."
    },
    {
      "question": "Which C2PA library should an agent's ingestion pipeline use to check a manifest?",
      "answer": "Match the library to where the check actually runs: c2pa-rs (Rust, with a C API) or c2pa-python for a backend ingestion pipeline, and the browser- and Node-oriented @contentauth/c2pa-web or @contentauth/c2pa-node bindings for a pipeline that runs client-side, per each library's own published documentation as of the C2PA reference's July 2026 update."
    }
  ],
  "body": "An AI agent that pulls an image, video clip, audio file, or attached document from the open web has no default way to know whether that file carries a verifiable claim about where it came from — a C2PA manifest, if one is present, is that machine-checkable signal, and what the agent does next should depend on which of three distinct states the manifest is actually in. This is a related but additional operator-security concern — content-ingestion authenticity — not a ninth item folded into the [agent security operations](/articles/agent-security-operations) pillar's own eight-discipline stack; it sits at the point where a specific class of external input, a media file, enters an agent's context, distinct from the credentials, code execution, and dependencies the pillar's eight disciplines cover. The [C2PA content credentials](/resources/c2pa-content-credentials) reference covers the standard's own mechanics — the manifest, claim, and assertion structure, plus the trust-list verification chain. This article is the decision procedure and pipeline checklist built on top of that mechanism: what an agent's ingestion step should do differently across a valid manifest, an invalid one, and no manifest at all.\n\n## What does a C2PA manifest actually prove?\n\nA C2PA manifest proves that someone or something made a signed claim about a file's origin and edit history — it does not, by itself, prove that claim is accurate, and a missing manifest proves nothing at all in either direction. The C2PA content credentials reference states the operating principle directly: \"A valid manifest is evidence of a provenance claim, not proof the content is authentic; a missing or invalid one is evidence of nothing, since the metadata is routinely stripped by re-uploads and format conversions.\" Under the current published spec, version 2.4, a manifest bundles a signed claim — bound to the file's own hash — with a list of typed assertions: the capture device or generative tool used, edit actions taken, source \"ingredients,\" and whether AI produced or altered the asset. The claim's signature is checked against a Conformance Program trust list of recognized certificate authorities, not accepted on the strength of the manifest simply existing. A manifest can also carry a CAWG (Creator Assertions Working Group) identity assertion — a related but separate creator-attribution layer inside the same file — worth checking only once the base provenance claim itself already validates, not as a substitute for that validation.\n\n## A three-state decision procedure for agent ingestion\n\nAn agent's ingestion pipeline needs three distinct responses, not one, because a valid manifest, an invalid signature, and an absent manifest are three different pieces of information about a file, not three severities of the same signal.\n\n| State | What actually happened | What the agent should do |\n\n|---|---|---|\n\n| Valid, verified manifest | A claim was made and its signature checks out against the Conformance Program trust list | Attach the manifest's assertions (capture device, edit history, AI-generation flag) as metadata the agent can weigh; still treat it as a claim, not ground truth |\n\n| Present but invalid or tampered signature | The file was altered after the manifest was signed, or the signature doesn't match the trust list at all | Treat as an active tamper signal, not a neutral gap — flag for review or block, since this is stronger evidence of interference than no manifest at all |\n\n| No manifest present | No claim was ever embedded, or one was stripped somewhere along the way | Treat as \"no claim was made\" and apply whatever default trust posture the agent already uses for any unlabeled file, not a downgrade specific to C2PA absence |\n\nThat third state plays out differently across ingestion surfaces. A web image fetched directly from a publisher's own site is the best case for an intact manifest, since it hasn't passed through a resize-and-re-encode step; the same image pulled from a social platform or a screenshot has often already lost it. An email attachment has typically passed through at least one mail gateway's re-encoding, so a missing manifest there is the expected case, not a red flag on its own. A retrieved document is the surface to hedge hardest on: the C2PA reference's own confirmed scope is images, video, and audio, not document formats — unless a pipeline has separately confirmed C2PA embedding support for the exact document format in use, treat the absence of a manifest on a PDF or office file as simply outside the standard's current scope, not as an authenticity signal at all.\n\n## Does a missing manifest mean content was tampered with?\n\nNo — a missing C2PA manifest does not mean content was tampered with, because ordinary re-encoding, screenshotting, and platform re-uploads strip manifest metadata just as completely as deliberate stripping does. This is why the decision procedure above treats an absent manifest as \"no claim was made,\" not as reduced trust relative to a valid one: conflating the two would flag the overwhelming majority of ordinary web content as suspect, at a point where capture-time signing is only beginning to spread. Google's Pixel 10 camera, announced September 2025, is the first mobile camera reported to satisfy the C2PA Conformance Program's Assurance Level 2, generating its signature from a hardware-backed Titan M2 secure chip rather than an app running after the fact. OpenAI embeds C2PA metadata in ChatGPT- and API-generated images specifically because that metadata is so easily lost to re-encoding or screenshots, pairing it with a SynthID watermark as a fallback rather than relying on the manifest alone. As of September 2026, expect the base rate of manifest-carrying content on the open web to keep rising as this kind of capture-time and generation-time signing spreads, not to already be the norm.\n\n## How do you wire a C2PA check into an agent's ingestion pipeline?\n\nWiring a C2PA check into an agent's ingestion pipeline means running a reader library against every incoming file before it reaches the model, not auditing manifests after the fact. A working gate needs six pieces in place:\n\n- **Pick a reader library matched to where ingestion happens.** `c2pa-rs` (Rust, plus a C API) or `c2pa-python` for a backend pipeline; the browser- and Node-oriented `@contentauth/c2pa-web` or `@contentauth/c2pa-node` bindings for a pipeline that runs client-side, per each library's own published documentation.\n\n- **Place the check inline, before the model sees anything.** The reader runs as a gate the file has to pass through, so a routing decision — allow, flag, or block — happens before the content is ever added to the model's context, not as a log entry written after the fact.\n\n- **Validate the signature against the trust list, not just presence.** A manifest that exists but fails trust-list validation routes to the invalid branch of the decision procedure above, not the valid one — checking only \"is a manifest there\" collapses two states the procedure needs kept apart.\n\n- **Parse the assertion list into structured fields.** Capture device or generative tool, edit history, and the AI-generation flag should reach downstream logic as separate fields, not get collapsed into one pass/fail boolean the rest of the pipeline can't reason about individually.\n\n- **Attach the resulting state as forwarded metadata.** Valid, invalid, or absent should travel with the content to whatever step or model consumes it next, rather than being checked and then silently discarded once the gate has run.\n\n- **Log every invalid-signature result specifically.** That state is the active tamper signal the decision procedure treats differently from a routine absence, and it is the one worth an operator's attention when it shows up.\n\n## Does a valid manifest mean the content is safe to act on?\n\nNo — a valid, verified C2PA manifest says nothing about whether the content it's attached to is safe for an agent to follow as an instruction, because provenance and instruction-safety are separate questions answered by separate controls. A signed image can still carry adversarial text in a caption, in embedded metadata outside the manifest itself, or rendered directly into the pixels, and a valid manifest verifies only the claim about the image's origin and edit history — it says nothing about whether text riding along with that image should be treated as data or as a command. [Defending an AI agent against prompt injection](/articles/prompt-injection-defense-in-depth-for-agents) covers the patterns that keep untrusted content from steering an agent's actions regardless of where that content came from. Run a C2PA check and a prompt-injection defense as two separate, non-substitutable gates on the same piece of ingested media, not one standing in for the other.\n\n## How does content provenance differ from supply-chain provenance for AI agent dependencies?\n\nContent provenance and supply-chain provenance verify two different artifact classes using two entirely different trust mechanisms, not two flavors of the same check. The C2PA content credentials reference draws this exact line itself: supply-chain provenance work — SBOMs, SLSA build levels, in-toto and Sigstore signing — covers build-time provenance for software artifacts, models, and MCP servers, while a C2PA manifest covers provenance embedded in a media file itself, a different artifact class, format family, and trust mechanism entirely. [How to verify supply-chain provenance for AI agent dependencies](/articles/supply-chain-provenance-for-ai-agents) covers the package-install-time, model-load-time, and MCP-server-connect-time gates that check what a dependency declares it contains and whether it was built the way its publisher claims; nothing in that playbook checks whether a JPEG an agent just downloaded carries a signed claim about its own history, and nothing in the decision procedure above checks whether a package's build matches its bill of materials. Route a dependency through the supply-chain gates and a media file through the C2PA decision procedure above — treating either as a substitute for the other leaves the artifact class it doesn't cover completely unchecked.\n\n## Where this leaves you\n\nRoute every media file an agent ingests through the three-state decision procedure above before it reaches the model. A valid, trust-list-verified manifest is evidence of a claim to weigh, not ground truth to accept; an invalid signature is an active tamper signal to flag or block; and an absent manifest is evidence of nothing, handled the same as any other unlabeled file. Wire the check in as an ingestion-time gate using a reader library matched to where the pipeline runs, and log every invalid-signature result specifically, since that's the state actually worth an operator's attention. Keep provenance and safety as separate gates on the same content: pair this check with [prompt-injection defense](/articles/prompt-injection-defense-in-depth-for-agents) for what the content might try to make the agent do, and keep it distinct from [supply-chain provenance verification](/articles/supply-chain-provenance-for-ai-agents) for the dependencies the agent itself runs on. For the eight operator-side disciplines this concern sits alongside, see the [agent security operations](/articles/agent-security-operations) pillar.",
  "cluster": {
    "id": "agent-security-operations",
    "title": "Agent security operations",
    "description": "How to defend an AI agent deployment from the operator side — secrets and credential hygiene, prompt-injection defense in depth, sandboxing, supply-chain provenance, least privilege, audit trails, incident response, and rate/abuse controls — not buyer-side fraud and not reliability-framed guardrails.",
    "status": "complete",
    "pillar": {
      "slug": "agent-security-operations",
      "title": "How to Secure AI Agents in Production",
      "description": "Credential hygiene, prompt-injection defense in depth, sandboxing choices for code execution, supply-chain provenance, least privilege, audit trails, incident response, and rate/abuse controls — eight operator-side defenses against an adversarial actor or a compromised dependency, not against ordinary load or failure.",
      "kind": "pillar",
      "order": 0,
      "html": "https://changegamer.ai/articles/agent-security-operations",
      "markdown": "https://changegamer.ai/articles/agent-security-operations.md",
      "json": "https://changegamer.ai/api/articles/agent-security-operations.json"
    },
    "articles": [
      {
        "slug": "credential-hygiene-for-ai-agents",
        "title": "How to Manage Secrets for AI Agents in Production",
        "description": "Why single-agent credential issuance is not the whole secrets problem: auditing which tool servers and MCP connectors hold credentials on an agent's behalf, treating provider-side prompt caches as a disclosure surface, and the named frameworks — OWASP's Secrets Management Cheat Sheet, Twelve-Factor config, and the OWASP GenAI project — that govern the rest.",
        "kind": "sub",
        "order": 1,
        "html": "https://changegamer.ai/articles/credential-hygiene-for-ai-agents",
        "markdown": "https://changegamer.ai/articles/credential-hygiene-for-ai-agents.md",
        "json": "https://changegamer.ai/api/articles/credential-hygiene-for-ai-agents.json"
      },
      {
        "slug": "prompt-injection-defense-in-depth-for-agents",
        "title": "How to Defend an AI Agent Against Prompt Injection",
        "description": "A decision framework for matching Action-Selector, Plan-Then-Execute, Dual LLM, and the other named architectural patterns to a task's actual blast radius, including when to compose two patterns together and when none of them is worth the overhead.",
        "kind": "sub",
        "order": 2,
        "html": "https://changegamer.ai/articles/prompt-injection-defense-in-depth-for-agents",
        "markdown": "https://changegamer.ai/articles/prompt-injection-defense-in-depth-for-agents.md",
        "json": "https://changegamer.ai/api/articles/prompt-injection-defense-in-depth-for-agents.json"
      },
      {
        "slug": "choosing-a-sandbox-for-ai-agent-code-execution",
        "title": "How to Choose a Sandbox for AI Agent Code Execution",
        "description": "A two-axis framework — trust in the code's source crossed with the blast radius of a successful escape — for picking an isolation layer, choosing among six hosted sandbox APIs, and hardening the harness around whichever one you pick.",
        "kind": "sub",
        "order": 3,
        "html": "https://changegamer.ai/articles/choosing-a-sandbox-for-ai-agent-code-execution",
        "markdown": "https://changegamer.ai/articles/choosing-a-sandbox-for-ai-agent-code-execution.md",
        "json": "https://changegamer.ai/api/articles/choosing-a-sandbox-for-ai-agent-code-execution.json"
      },
      {
        "slug": "supply-chain-provenance-for-ai-agents",
        "title": "How to Verify Supply-Chain Provenance for AI Agent Dependencies",
        "description": "An operational playbook for three separate trust-boundary gates — package-install time, model-load time, and MCP-server-connect time — that turns SBOM and attestation formats into checks a pipeline can actually run, plus a fail-closed default for the dependency that carries neither.",
        "kind": "sub",
        "order": 4,
        "html": "https://changegamer.ai/articles/supply-chain-provenance-for-ai-agents",
        "markdown": "https://changegamer.ai/articles/supply-chain-provenance-for-ai-agents.md",
        "json": "https://changegamer.ai/api/articles/supply-chain-provenance-for-ai-agents.json"
      },
      {
        "slug": "permission-boundaries-and-least-privilege-for-ai-agents",
        "title": "How to Enforce Permission Boundaries for AI Agents at Runtime",
        "description": "How a least-privilege grant actually gets enforced once an agent is running — the eight named checkpoints, five verdicts, and fail-closed contract in Microsoft's draft Agent Control Specification (ACS), and what happens when the policy engine that enforces the boundary breaks.",
        "kind": "sub",
        "order": 5,
        "html": "https://changegamer.ai/articles/permission-boundaries-and-least-privilege-for-ai-agents",
        "markdown": "https://changegamer.ai/articles/permission-boundaries-and-least-privilege-for-ai-agents.md",
        "json": "https://changegamer.ai/api/articles/permission-boundaries-and-least-privilege-for-ai-agents.json"
      },
      {
        "slug": "audit-trails-for-ai-agents",
        "title": "How to Build an Audit Trail for an AI Agent",
        "description": "A field-by-field forensic playbook for an AI agent audit log: why each of the checklist's seven required fields matters for reconstruction, a worked incident walkthrough, and the real tension between OpenTelemetry's redact-by-default tracing and full audit logging.",
        "kind": "sub",
        "order": 6,
        "html": "https://changegamer.ai/articles/audit-trails-for-ai-agents",
        "markdown": "https://changegamer.ai/articles/audit-trails-for-ai-agents.md",
        "json": "https://changegamer.ai/api/articles/audit-trails-for-ai-agents.json"
      },
      {
        "slug": "security-incident-response-for-ai-agents",
        "title": "How to Respond When an AI Agent Takes a Harmful Action",
        "description": "Why the pillar's cut-credential, stop-instance, export-evidence order is structurally forced rather than a tidy convention, a concrete answer for who holds standing revocation authority, a pre-incident drill for the evidence-export path, and what changes when the compromised credential belongs to a third-party tool server instead of the agent itself.",
        "kind": "sub",
        "order": 7,
        "html": "https://changegamer.ai/articles/security-incident-response-for-ai-agents",
        "markdown": "https://changegamer.ai/articles/security-incident-response-for-ai-agents.md",
        "json": "https://changegamer.ai/api/articles/security-incident-response-for-ai-agents.json"
      },
      {
        "slug": "rate-and-abuse-controls-for-ai-agents",
        "title": "How to Rate-Limit and Cap Spend for Your Own AI Agent",
        "description": "Enforcement mechanics for the two ceilings an agent operator should set before production: where a per-credential tool-call counter has to live to stay correct under concurrent calls, where a spend ceiling gets checked in the tool-call loop, and how to reject out-of-scope tool-call arguments with canonicalization rather than a naive prefix match.",
        "kind": "sub",
        "order": 8,
        "html": "https://changegamer.ai/articles/rate-and-abuse-controls-for-ai-agents",
        "markdown": "https://changegamer.ai/articles/rate-and-abuse-controls-for-ai-agents.md",
        "json": "https://changegamer.ai/api/articles/rate-and-abuse-controls-for-ai-agents.json"
      },
      {
        "slug": "content-provenance-for-ai-agents",
        "title": "How to Verify Content Provenance for AI Agents with C2PA",
        "description": "A three-state decision procedure — valid manifest, invalid signature, absent manifest — for what an AI agent's ingestion pipeline should do differently with a web image, an email attachment, or a retrieved document, plus a checklist for wiring a C2PA reader library into that pipeline as a gate before content reaches the model.",
        "kind": "sub",
        "order": 9,
        "html": "https://changegamer.ai/articles/content-provenance-for-ai-agents",
        "markdown": "https://changegamer.ai/articles/content-provenance-for-ai-agents.md",
        "json": "https://changegamer.ai/api/articles/content-provenance-for-ai-agents.json"
      },
      {
        "slug": "agent-identity-and-authentication-for-ai-agents",
        "title": "How AI Agents Prove Identity and Delegated Authority",
        "description": "The two-layer model an autonomous agent needs to pass before any credential-custody or permission question even applies: a cryptographic workload identity proving what it is (SPIFFE/SPIRE, cloud workload identity federation) and a separate delegated-authority grant proving it may act on a human's or org's behalf (OAuth scopes, RFC 8693 token exchange, RFC 8707 audience binding).",
        "kind": "sub",
        "order": 10,
        "html": "https://changegamer.ai/articles/agent-identity-and-authentication-for-ai-agents",
        "markdown": "https://changegamer.ai/articles/agent-identity-and-authentication-for-ai-agents.md",
        "json": "https://changegamer.ai/api/articles/agent-identity-and-authentication-for-ai-agents.json"
      },
      {
        "slug": "data-privacy-and-pii-for-ai-agents",
        "title": "How to Protect PII and Personal Data in AI Agent Pipelines",
        "description": "Why an AI agent expands PII exposure past a bounded API call — large ingested context, external tool calls, persistent memory and logs, provider training risk — and the containment controls, provider data-handling terms, and GDPR/EU AI Act/CCPA compliance boundary that follow from it.",
        "kind": "sub",
        "order": 11,
        "html": "https://changegamer.ai/articles/data-privacy-and-pii-for-ai-agents",
        "markdown": "https://changegamer.ai/articles/data-privacy-and-pii-for-ai-agents.md",
        "json": "https://changegamer.ai/api/articles/data-privacy-and-pii-for-ai-agents.json"
      },
      {
        "slug": "agent-security-operations-checklist",
        "title": "The AI Agent Security Checklist",
        "description": "A go/no-go checklist that turns the agent security operations pillar's eight disciplines, plus content provenance, agent identity, and data privacy, into checkable gates — the specific inventory row, test result, or logged decision that proves each one holds, with a link to whichever sibling article owns its mechanics.",
        "kind": "sub",
        "order": 12,
        "html": "https://changegamer.ai/articles/agent-security-operations-checklist",
        "markdown": "https://changegamer.ai/articles/agent-security-operations-checklist.md",
        "json": "https://changegamer.ai/api/articles/agent-security-operations-checklist.json"
      }
    ]
  },
  "navigation": {
    "pillar": {
      "slug": "agent-security-operations",
      "title": "How to Secure AI Agents in Production",
      "description": "Credential hygiene, prompt-injection defense in depth, sandboxing choices for code execution, supply-chain provenance, least privilege, audit trails, incident response, and rate/abuse controls — eight operator-side defenses against an adversarial actor or a compromised dependency, not against ordinary load or failure.",
      "kind": "pillar",
      "order": 0,
      "html": "https://changegamer.ai/articles/agent-security-operations",
      "markdown": "https://changegamer.ai/articles/agent-security-operations.md",
      "json": "https://changegamer.ai/api/articles/agent-security-operations.json"
    },
    "previous": {
      "slug": "rate-and-abuse-controls-for-ai-agents",
      "title": "How to Rate-Limit and Cap Spend for Your Own AI Agent",
      "description": "Enforcement mechanics for the two ceilings an agent operator should set before production: where a per-credential tool-call counter has to live to stay correct under concurrent calls, where a spend ceiling gets checked in the tool-call loop, and how to reject out-of-scope tool-call arguments with canonicalization rather than a naive prefix match.",
      "kind": "sub",
      "order": 8,
      "html": "https://changegamer.ai/articles/rate-and-abuse-controls-for-ai-agents",
      "markdown": "https://changegamer.ai/articles/rate-and-abuse-controls-for-ai-agents.md",
      "json": "https://changegamer.ai/api/articles/rate-and-abuse-controls-for-ai-agents.json"
    },
    "next": {
      "slug": "agent-identity-and-authentication-for-ai-agents",
      "title": "How AI Agents Prove Identity and Delegated Authority",
      "description": "The two-layer model an autonomous agent needs to pass before any credential-custody or permission question even applies: a cryptographic workload identity proving what it is (SPIFFE/SPIRE, cloud workload identity federation) and a separate delegated-authority grant proving it may act on a human's or org's behalf (OAuth scopes, RFC 8693 token exchange, RFC 8707 audience binding).",
      "kind": "sub",
      "order": 10,
      "html": "https://changegamer.ai/articles/agent-identity-and-authentication-for-ai-agents",
      "markdown": "https://changegamer.ai/articles/agent-identity-and-authentication-for-ai-agents.md",
      "json": "https://changegamer.ai/api/articles/agent-identity-and-authentication-for-ai-agents.json"
    }
  },
  "resources": [
    {
      "slug": "c2pa-content-credentials",
      "html": "https://changegamer.ai/resources/c2pa-content-credentials",
      "markdown": "https://changegamer.ai/resources/c2pa-content-credentials.md",
      "json": "https://changegamer.ai/api/resources/c2pa-content-credentials.json"
    }
  ]
}