Technical Whitepaper · Authorship · Content Credentials

HumanMark: Authorship by Commitment, Not Watermark

A specific human can commit to exact bytes. That is the defense of human ideas against statistical AI stains, against "AI touched this file," and against a future in which a vendor's detector is the gate to being believed.

Author Daniel Uribe, Founder and CEO, GenoBank.io
Date August 15, 2026
Software HumanMark 1.1.0 · AGPL-3.0-or-later
Standard ERC-8356 Content Credentials profile
Stack GenoBank.io · C2PA · Sequentia 15132025
Version 1.0
Status. Live reference implementation. HumanMark 1.1.0 on GitHub. ConsentGrant on Sequentia at 0xC1F0E978FF99263ade7dC81a7E6222BBd926c025, Bind covering manifestCommitment. Verifier at explorer.sequentias-test.genobank.io/HumanMark.
1.1.0
HumanMark
66
Engine tests
50
SNP bloom
15132025
Sequentia chain

1. Abstract

Abstract

Anthropic has announced that future Claude models will emit a statistical text watermark, a SynthID-Text pattern in low-stakes token choices, so that anyone with the vendor's key can assign a probability that Claude was involved in a passage. The company is applying the mark globally to comply with the EU AI Act, and it will ship a detection API. The same announcement attaches a C2PA Content Credential to supported image files saying the file was made or processed with Claude. The watermark, on Anthropic's own account, cannot distinguish "Claude wrote this" from "Claude heavily edited this," and it carries no author identity.

That is a vendor-keyed stain. It is not an authorship proof. HumanMark is the inverse primitive. A file is authored by a human when three things hold at once: the exact bytes are salted into a content commitment, the author's wallet EIP-712-signs that commitment over the ERC-8356 ConsentGrant domain, and, for genomic work, a 50-SNP bloom from the author's vault matches. The C2PA claim is sealed first. Bind is signed after that seal and covers manifestCommitment, so a relayer cannot swap the claim. Public works mint no grant and are permanent. Works that carry a subject's data ride a revocable grant. A conforming verifier applies restrictive-wins: on-chain status and X.509 validity must both stand, or there is no valid provenance claim.

This whitepaper situates HumanMark against Claude's text watermark, against stylometric "AI detectors," and against a social rule that is already forming: treat any file an AI touched as second-class thought. Authorship is a claim a person makes, in public, over bytes they will stand behind. It is not a probability that a lab assigns to a sentence.

2. Two Claims About a File

Every file that will matter in the next decade will be asked one of two questions. The first question is who stands behind these bytes. The second is whether a model was involved. Those questions look related. They are not the same question, they do not have the same answerer, and they do not have the same political consequence.

The first question is an authorship claim. A named person, or a named laboratory acting for a named subject, commits to exact bytes and can be asked to open that commitment later. Journals, courts, regulators, and patients already know how to weigh a signed claim. The second question is a participation stain. A vendor, holding a secret key, reports that its model was likely involved at some point. Schools, platforms, and agencies will treat that report as a filter. The filter does not name an author. It names a tool.

GenoBank.io builds the first question. HumanMark is the local half of that answer. ERC-8356 is the on-chain half. C2PA is the portable claim envelope. Together they let a human say: these exact bytes are mine, this is the consent that still governs them, and a verifier who cannot open both the content commitment and the sealed manifest has no provenance to honor.

Design claim

A watermark answers "was this vendor's model involved." HumanMark answers "which human committed to these bytes." The second question is the one that protects ideas. The first question, once it becomes an institutional gate, is how a civilization starts treating thought as contraband.

3. What Claude's Text Watermark Is

Anthropic's 2026 note, How Claude's text watermark works, is unusually honest about the mechanism, and that honesty is useful. Large language models pick the next token from a list of candidates. Where several candidates are equally good ("overcast" or "grey"), the choice is settled by randomness. SynthID-Text, published by Google DeepMind in Nature in 2024 and belonging to the family Scott Aaronson proposed in 2022, replaces that arbitrary randomness with a keyed function of a few preceding words. The reader sees nothing. There are no hidden characters and no extra tokens. Anyone who holds the key can later score a passage for consistency with the choices Claude would have made, and assign a probability that Claude was involved.

Anthropic states the limits in the same document. The detector answers only "What is the likelihood this was partly written by Claude?" It does not confirm that a human wrote the rest. It cannot see another vendor's watermark. Short samples carry too few choices to score. Factual passages and exact code have fewer places to hide a mark. Proofreading of human prose leaves little for the watermark to attach to. A complete rewrite removes it. A light edit generally does not. A Claude translation is fully watermarked, because every word is Claude's choice. The watermark carries no user, organization, or chat identity. Detection will be offered as an API. Image files of supported types receive a C2PA Content Credential saying the file was made or processed with Claude: a signed note in metadata, not a hidden stain, still answering involvement rather than authorship.

The legal trigger is the EU AI Act and the July 2026 Code of Practice on Transparency of AI-Generated Content, with about 190 signatories. As of 2 August 2026 the Act requires AI providers serving the EU market to mark AI-generated content. Anthropic is applying the watermark globally at launch because it does not yet have a durable way to scope it by region.

Those facts are enough. They do not need to be inflated. A vendor-keyed, invisible, globally applied statistical pattern, scored by a vendor API, that rises in confidence as a passage gets longer, and that cannot tell writing from heavy editing, is already a new kind of public record about human work.

4. The Geometry of "AI Touched This File"

The Orwellian risk is not that Anthropic's current watermark encodes a name. The company says it does not, and there is no reason in the published method to doubt that. The risk is the social object the watermark creates: a durable, machine-readable suspicion that a tool was present, issued by the toolmaker, consumed by every institution that wants a cheap purity test for human thought.

Once that object exists, four properties do the rest of the work.

Asymmetry of keys. The author cannot inspect, revoke, or counter-sign the mark. The vendor can. Detection is a service. Services have terms, rate limits, outages, and customers. A journal that outsources "is this human" to a vendor API has given that vendor a quiet veto over whose sentences count.

Collapse of use into origin. Anthropic states, correctly, that a watermark cannot distinguish "Claude wrote this" from "Claude heavily edited this." Institutions will not hold that distinction. They will hold a slider. A scientist who asks a model to tighten grammar, a patient who asks a model to translate a clinic letter, a founder who asks a model to rephrase a paragraph, all become "AI-touched." The more useful the tool is, the more of a person's working life falls on the wrong side of the slider.

Global application of a regional statute. The EU asked for marking of AI-generated content. The implementation is a worldwide stain, because the vendor cannot yet scope it. A writer in Palo Alto, a clinician in Guadalajara, and a student in Nairobi inherit a European transparency rule as an invisible property of their English. Law that cannot be scoped becomes infrastructure. Infrastructure that cannot be scoped becomes a default census of tool use.

The second-class file. "AI touched this file" is already a workplace and classroom rule. It will become a platform rule and then a procurement rule. A watermark is the cheapest way to enforce it at scale. Files that trip the detector will be down-ranked, bounced from submission portals, or marked for extra scrutiny. Files that do not trip it will be treated as clean, including machine text from vendors that have not shipped a mark, and including human text that a detector has not yet learned to hate. The innocent and the unmarked are not the same set.

The surveillance primitive

A secret-keyed statistical census of human sentences, scored by the company that sold the pencil, is how a society starts treating ideas as a controlled substance. The author is not identified. The author's standing is. That is enough to chill the work that most needs a tool: the rare-disease letter, the first draft in a second language, the patient who is trying to understand a report about their own body.

Stylometric detectors such as Pangram are a related, worse object. They have no vendor key. They hunt phrasing tells ("this is not X, it is Y"; an excess of "quietly"). They are already used as workplace and classroom police. They are not authorship proofs either. They are taste police with a confusion matrix. HumanMark does not compete with them on their field. It changes the field.

5. HumanMark: Authorship by Commitment

HumanMark proves a file was authored by a human by making the human do the one thing a watermark never asks: stand behind exact bytes, in public, with a key the human holds.

A file is authored by a human when three things hold at once:

  1. the exact bytes are hashed and salted into a content commitment,
  2. the author's wallet EIP-712-signs that commitment, and
  3. for genomic work, a 50-SNP bloom fingerprint from the author's vault matches.

That is the opposite of AI-content watermarking, which says only that a model was generated-from or involved. HumanMark says a specific human committed to these bytes. The salt stays in a local ledger and is disclosed only when someone must open the commitment. The wallet signature is the author's, checked with ERC-1271 so a smart account can sign. The DNA bloom is a commitment, never the raw calls. The portable object is a small JSON prove bundle plus a sealed C2PA sidecar. The on-chain object is an ERC-8356 binding.

For a public paper, a blog post, or an EIP, there is no consent grant and no subject. Authorship is permanent. Bind is signed with revocable = false and a zero subject. Nothing is minted. For a clinical or genomic work, Bind is signed by the subject, revocable = true, and bindContent records the binding against an active grant whose scope leaf is the content commitment. Withdrawal of that grant deactivates the binding. Withdrawal of consent is not erasure of authorship. The two graphs stay two graphs.

6. Design Principles

Principle 1. The author holds the key. Bind is an EIP-712 signature over the existing ConsentGrant / 1 domain. The author can refuse to sign. The author can sign a different tuple. A vendor cannot apply HumanMark to a file the author did not commit to.

Principle 2. Bytes, not style. The commitment is keccak256(salt || sha256(content)) with a 32-byte salt. A paraphrase is a different file. A watermark hunts a statistical accent. HumanMark binds a hash. That is why a complete rewrite defeats a watermark and why it also requires a new HumanMark. Honesty about bytes is the point.

Principle 3. Bind covers the sealed claim. An earlier ceremony put Bind inside the hashed C2PA claim, so the manifest hash did not exist at signing time. That was a ceremony error. Bind is an attestation of the sealed claim, not a field inside it. manifestCommitment sits in the typed data. A relayer that swaps the C2PA after signing fails SignatureChecker.

Principle 4. Consent and authorship are different graphs. C2PA keeps the ingredient graph. ERC-8356 keeps the consent graph. Revoking a grant does not rewrite any manifest. A public work has no grant to revoke.

Principle 5. Privacy is a correctness property. The raw biocid:// URI is hashed into Bind as a string and is never stored on chain. Salts stay off chain. SNP calls never leave the vault. Genomic formats cannot be blessed into a public work.

Principle 6. Open tools, protected BioNFTs. HumanMark, BioFS, the ERC-8356 profile, and the C2PA assertion shapes are open, because no serious clinical or genomic user will put their most sensitive data on a black-box authorship gate. BioNFT commercialization (biosample and biodata tokens found by DNA fingerprint) stays with GenoBank.io. The screwdriver is public. The lock is the product.

7. Architecture

HumanMark is a thin local engine with no third-party Python dependencies. It screens a path, records a keccak content commitment that matches ConsentGrant.sol, and emits a prove bundle. biofs humanmark attest and biofs humanmark bind are the product verbs. GenoVault in the browser is where the author's wallet actually signs. The Sequentia explorer at /HumanMark is the public verifier. The BioFS MCP lets an agent such as Claude read permissions, provenance, and ownership through the C2PA tags and the on-chain binding, without receiving raw genomic bytes on a laptop.

The commitment scheme is fixed by the on-chain verifier:

contentCommitment  = keccak256(abi.encodePacked(salt, sha256(content)))
manifestCommitment = keccak256(abi.encodePacked(manifestSalt, sha256(manifest)))

Both salts are 32 bytes. abi.encodePacked of two bytes32 values is concatenation. Ethereum keccak-256 is not NIST SHA-3. HumanMark, biofs, and ConsentGrant must agree on this or nothing verifies. The engine pins keccak against Ethereum test vectors and pins EIP-712 against the canonical Ether Mail example.

The Bind typed data, after the 15 August 2026 decision that Bind covers the manifest, is:

Bind(
  bytes32 contentCommitment,
  bytes32 manifestCommitment,
  string  biocid,
  bool    revocable,
  bytes32 ingredientsRoot,
  bytes32 subjectCommit,
  bytes32 snpBloom,
  uint256 nonce
)

The domain is ConsentGrant / 1, with chain id and verifying contract. There is no second EIP-191 scheme. biocid is a string, so EIP-712 includes keccak256(bytes(biocid)) and the raw URI never reaches state. That is what stops an attestor from swapping the URI after the author has signed.

8. Binding Ceremony

The order is normative, because it is what prevents an attestor from swapping the content, the URI, the permanence path, or the sealed C2PA after the author has signed.

  1. The attestor computes contentCommitment.
  2. The C2PA claim is assembled (content hash, ingredients, subject, grant pointer, biocid) without the EIP-712 Bind, and the claim generator produces its X.509 signature over those finalized bytes.
  3. manifestCommitment is computed over those finalized bytes with an independent salt.
  4. The author (public work) or the subject (clinical work) signs Bind. The signature covers both commitments, the biocid, the revocable flag, the ingredients root, the subject commit, and the 50-SNP bloom.
  5. For a clinical work, grant is called with scopeRef equal to the content commitment (or a Merkle root containing it), and bindContent records the binding against that grant. For a public work, no grant is created.

A C2PA X.509 author assertion or a CAWG identity assertion, if present, is a separate signature. It is not this Bind. Bind lives on chain and in the prove bundle. It is not written back into the hashed claim.

Relayer hole, closed

A contract that stores manifestCommitment without putting it inside Bind lets a relayer substitute a different sealed claim after the author has signed. HumanMark 1.1.0 and ConsentGrant 0xC1F0E978…c025 reject that substitution. bindContent also rejects a zero manifest.

9. Restrictive-Wins

A conforming verifier, given content, the disclosed salts, the manifest, and an optional grant, treats the failure of any check as no valid provenance claim. The on-chain status and the X.509 result combine restrictive-wins. This lattice is normative in ERC-8356. It is not a companion note.

On-chain statusX.509 / C2PAVerifier output
ACTIVE, or no grant (public work)validvalid provenance
ACTIVE, or no grantuntrusted, revoked, or expiredno valid claim
REVOKED_BY_SUBJECT / RENOUNCED / TERMINATED / EXHAUSTED / SUPERSEDEDvalidno valid claim
any terminal statusuntrusted, revoked, or expiredno valid claim

SUPERSEDED is as restrictive as REVOKED_BY_SUBJECT. Untrusted and revoked are both invalid for this lattice. A public work has no on-chain grant row; only the X.509 and disclosure checks apply, and its claim is permanent.

10. Screening as a Human Gate

HumanMark is also a folder gate. Before a file earns a prove bundle it is screened for unredacted PHI and for raw genomic or clinical formats. A clean public paragraph, including an author's own @genobank.io address and operator biowallet on an allow-list, can be SAFE. A document with an unredacted patient SSN, a third-party email, or a labelled IP is BLOCKED until the author redacts it or blesses it with a written reason. Any genomic or clinical format (.vcf, .bam, .fastq, .cram, .ped, .bim, .fam, .dcm, .sqlite, and the rest) is BLOCKED and can never be blessed to a public work. It enters the vault as genomic, gated by consent.

That gate is the opposite of a stylometric detector. It does not ask whether the prose "sounds like" a model. It asks whether these bytes are safe to publish as a public authored work, and whether the person who wants to sign them is willing to put a reason on a blessing. The local Ed25519 key that signs the prove bundle is tamper-evidence for the JSON. It is not the author's wallet key. Wallet recovery is secp256k1, on chain or in biofs.

11. DNA Authorship Without Publishing DNA

For genomic work, HumanMark can carry a 50-SNP bloom commitment inside Bind. The bloom is computed the same way biofs fingerprint computes a VCFFingerprint: a compact commitment over a fixed panel, never the raw calls. Zero bytes mean the work is not DNA-bound. Non-zero bytes mean a later disclosure can show that the author's vault produces the same bloom. The calls stay in the vault. The chain stores 32 bytes.

That is authorship bound to a body, which is the one thing a text watermark will never be, and the one thing a laboratory already knows how to take seriously. It is also why HumanMark belongs in the GenoBank.io stack rather than as a generic "AI detector." The same patents that underwrite BioNFT search (US 11,915,808 B1, issued 27 February 2024; US 11,984,203 B1, issued 14 May 2024) are the commercial object. The authorship tools stay open so a lab will put clinical data on them.

12. Comparison Matrix

Property Claude SynthID-Text Stylometric detector C2PA alone HumanMark + ERC-8356
Question answeredLikelihood Claude was involvedLikelihood "this sounds like a model"Who signed a claim envelopeWhich human committed to these bytes
Key holderVendorDetector vendorX.509 subjectAuthor wallet (ERC-1271)
Visible to the authorNoNoYes, if they sealed itYes: they sign Bind
Author can refuseNo, if they used the modelN/AYesYes
Distinguishes edit from writeNoNoOnly if the claim says soBinds exact bytes; a new edit is a new commitment
Revocable consentNoNoNo (authorship is not consent)Yes, grant-bound works
On-chain statusNoNoNobindContent, isBindingActive
DNA-bound authorshipNoNoNo50-SNP bloom in Bind
URI swap after signingN/AN/ADepends on the claimBlocked: biocid is inside Bind
Manifest swap after signingN/AN/AN/ABlocked: manifestCommitment is inside Bind
Institutional failure modePurity test for tool useFalse positives as disciplineClaim without consent statusAuthor must actually sign

C2PA is necessary and not sufficient. Anthropic's own image path uses C2PA to say Claude processed a file. That is a vendor involvement assertion riding an open standard. HumanMark uses the same standard as an envelope for a human involvement assertion, then binds that envelope to a revocable or permanent on-chain status. The standard is not the enemy. The missing principal is.

13. Worked Scenarios

A public paper the author will stand behind

Daniel Uribe writes a technical paragraph on a laptop. HumanMark screens it SAFE. A C2PA claim is sealed without Bind. He signs Bind from his wallet over the content commitment and the manifest commitment, revocable = false, zero subject. bindContent records a permanent public work on Sequentia. A reader who opens the salts can verify the bytes. A reader who does not have the salts can still see that a wallet committed to a commitment. No grant NFT is minted. Grant id 0 is the spec for this case.

A clinical report a subject can withdraw

A molecular report about a patient is screened as genomic. It cannot be blessed to a public work. The subject signs Bind with revocable = true. A grant is minted whose scope leaf is the content commitment. An annotation vendor receives READ through that grant. When the subject withdraws, isBindingActive becomes false. The C2PA claim still says who authored the report. The consent graph says the report may no longer be used. Restrictive-wins tells every honest verifier to treat the provenance claim as gone for access purposes.

A human draft an AI merely proofread

A clinician writes a letter, then asks Claude to fix grammar. Anthropic's watermark, on Anthropic's account, may or may not fire, depending on how many tokens Claude chose. A school or a journal that treats any watermark hit as "AI-written" will punish the clinician for using a pencil. HumanMark does the adult thing. The clinician reviews the bytes, and if those bytes are still the letter they will stand behind, they sign Bind. If Claude rewrote the letter into something they will not stand behind, they do not sign. The signature is the act of authorship. The watermark is a rumor about a tool.

An agent that must read provenance without taking the file

A conversation on Claude.ai is granted READ through BioFS MCP against a biocid. The agent calls humanmark.verify. It receives permissions, the content commitment, the binding status, and the C2PA tags. It does not receive BAM or VCF bytes on the laptop. The watermark path has no equivalent: there is no way for an agent to ask "does the subject still consent" of a SynthID score.

14. What HumanMark Does Not Claim

HumanMark does not detect AI. A model that emits a file the author then signs has produced bytes a human chose to adopt. That is authorship in the only sense a court or a journal can use: someone took responsibility. A watermark that fires on those same bytes has reported a tool. Both facts can be true. Only one of them names a person.

HumanMark does not stop a person from signing bytes they did not understand. No signature scheme does. What it stops is the pretense that a vendor score is a substitute for that responsibility.

HumanMark does not put genomic bytes on a laptop, does not store salts or URIs on chain, and does not collapse consent into authorship. A revoked clinical binding is not a deleted paper. A permanent public work is not a consent grant that forgot how to die.

HumanMark does not replace the EU AI Act's marking requirement for model providers. Providers will mark. They should mark in the open, with C2PA, as involvement assertions, and they should not be handed the job of deciding which human sentences still count. HumanMark is what the human side of that bargain looks like.

15. Implementation and Deployment

HumanMark 1.1.0 is published at github.com/Genobank/HumanMark under AGPL-3.0-or-later, with the GenoBank.io house terms (attribution, no trademark license) and a commercial path for closed forks. The engine is pure Python. The product verbs live in biofs-cli. The wallet signature lives in GenoVault and in the Sequentia explorer's Bind on Sequentia button.

The live ConsentGrant on Sequentia (chain 15132025) that implements Bind covering manifestCommitment is 0xC1F0E978FF99263ade7dC81a7E6222BBd926c025. The immediately prior instance, 0x44FAB290563759390A93d613aF3F32b8Cd8E142b, stored a manifest commitment that Bind did not cover and is superseded. The first ContentBound under the new typehash is transaction 0x4432e858adda61e815ebc9981f1b46458f34d17668ba6fdf6bec105547bb5620. The verifier is explorer.sequentias-test.genobank.io/HumanMark.

The Content Credentials profile is an optional subsection of ERC-8356, not a second ERC. A core consent implementation need not implement it. An implementation that does implement it remains a conforming ERC-8356 implementation. The profile, including the restrictive-wins lattice and the Bind-after-seal ceremony, is in ERCS/erc-8356.md on ethereum/ERCs pull request 1921 and in Ethereum Magicians thread 29217, post 9.

The test posture is the same family as the rest of the GenoBank.io consent work: mostly negative. HumanMark currently carries 66 engine tests, including a digest change when manifestCommitment changes and a CLI prove that writes the sealed claim before the bundle. ConsentGrant content-binding tests include a relayer that tries to swap the manifest after Bind and is reverted.

16. Defending Human Ideas

The future that should be refused is easy to describe, because pieces of it are already shipping. A student is bounced from a portal because a vendor API assigned 0.73 to a paragraph a model helped translate. A grant office treats a watermark hit as a research-integrity event. A hospital policy forbids "AI-touched" clinical letters, which in practice forbids every clinician who used a grammar pass. A platform down-ranks any file whose C2PA says a model processed it. None of those institutions can name an author. All of them can punish a toolprint.

The future worth building is also easy to describe, because the parts exist. A person writes. Sometimes a model helps. The person reads the bytes and decides whether those bytes are still theirs. If they are, the person signs. A verifier, a journal, a court, a patient, or another model can check the signature, the commitment, the sealed claim, and, where consent applies, the grant. The record names a human. The record can be withdrawn when the bytes are about someone else's body. The record is permanent when the bytes are a public idea the author will keep.

That is not a nostalgia for unassisted prose. GenoBank.io runs AI agents against consented genomes every day, under Metamorphic Consent, with per-agent EIP-712 signatures and an Intra-LLM BioFilesystem that binds every claim to a biocid. The argument is not that models should be silent. The argument is that models should not be deputized as the census bureau of human sentences.

The human side of the bargain

Let model providers mark their outputs in the open. Let humans mark their commitments with a key they hold. Let consent travel with the bytes that came from a body. Let no vendor API be the last word on whether an idea still counts as a person's.

17. Conclusion

Claude's text watermark is a competent implementation of SynthID-Text, shipped to satisfy a marking rule, honest about what it cannot tell. It is also the wrong primitive for authorship. A vendor-keyed, invisible, globally applied involvement score will be used as a purity test. "AI touched this file" will do the rest.

HumanMark is the author-sovereign answer GenoBank.io can actually run. Exact bytes, a salted commitment, a sealed C2PA claim, a wallet Bind that covers the manifest, a 50-SNP bloom when the work is genomic, and an ERC-8356 status that a verifier must combine restrictive-wins. Public ideas stay permanent. Clinical bytes stay withdrawable. The tools stay open. The BioNFT remains the commercial lock.

A civilization that wants to keep human ideas will ask who will stand behind the bytes. It will not ask a model vendor to guess whether a pencil was in the room.

Operator checklist

  1. Install HumanMark 1.1.0 and set verifying_contract to 0xC1F0E978FF99263ade7dC81a7E6222BBd926c025 on chain 15132025.
  2. Screen with humanmark scan. Do not bless genomic formats to a public work.
  3. Prove with humanmark prove or biofs humanmark attest. Confirm a .c2pa.json exists before Bind, and that the prove bundle carries a non-zero manifest_commitment.
  4. Sign Bind from the author wallet. Relayers may submit. Relayers may not choose the manifest.
  5. Verify on /HumanMark. Treat any failed lattice cell as no valid claim.
  6. Grant an agent READ through BioFS MCP against a biocid://, never against a signed storage URL.
Suggested citation Uribe, D. (2026). HumanMark: Authorship by Commitment, Not Watermark (Technical whitepaper, v1.0). GenoBank.io. https://genobank.io/whitepapers/humanmark/ Software: HumanMark 1.1.0, https://github.com/Genobank/HumanMark Profile: ERC-8356 Content Credentials, ethereum/ERCs pull request 1921, Magicians thread 29217.

18. References

  1. Anthropic. How Claude's text watermark works. 2026. https://www.anthropic.com/news/claude-text-watermark
  2. Dathathri, S. et al. Scalable watermarking for identifying large language model outputs. Nature 634, 818 to 823 (2024). SynthID-Text.
  3. Aaronson, S. My AI Safety Lecture for UT Effective Altruism. 2022. Statistical watermarking of sampling.
  4. European Union. Regulation (EU) 2024/1689 (AI Act), transparency obligations for AI-generated content.
  5. European Commission. Code of Practice on Transparency of AI-Generated Content. July 2026.
  6. C2PA. Content Credentials specification. https://c2pa.org
  7. CAWG. Identity assertion for C2PA. Creator Assertions Working Group.
  8. Uribe, D. ERC-8356: Purpose-Bound Third-Party Data Consent. ethereum/ERCs pull request 1921, 2026. https://github.com/ethereum/ERCs/pull/1921
  9. Uribe, D. Ethereum Magicians discussion for ERC-8356, including post 9 (Bind covers manifestCommitment; restrictive-wins stays in the ERC). Thread 29217. https://ethereum-magicians.org/t/erc-8356-purpose-bound-third-party-data-consent/29217
  10. GenoBank.io. HumanMark 1.1.0. https://github.com/Genobank/HumanMark
  11. GenoBank.io. Open tools, protected BioNFT commerce. HumanMark docs, 15 August 2026.
  12. Uribe, D. The Intra-LLM BioFilesystem. GenoBank.io whitepaper, 1 June 2026. https://genobank.io/whitepapers/intra-llm-biofilesystem/
  13. Entriken, W. and Uribe, D. Biosample permission token with non-fungible tokens. 2020.
  14. Uribe, D. and Waters, G. Privacy Laws, Genomic Data and Non-Fungible Tokens. Journal of the British Blockchain Association, 2020.
  15. United States Patent 11,915,808 B1. Issued 27 February 2024.
  16. United States Patent 11,984,203 B1. Issued 14 May 2024.
  17. W3C. Verifiable Credentials Data Model 2.0. Recommendation, 2025.
  18. Ethereum. ERC-1271: Standard Signature Validation Method for Contracts.
  19. Ethereum. ERC-712: Typed structured data hashing and signing.
  20. GenoBank.io. Sequentia ConsentGrant (Bind covers manifestCommitment). https://explorer.sequentias-test.genobank.io/address/0xC1F0E978FF99263ade7dC81a7E6222BBd926c025
  21. GenoBank.io. HumanMark verifier. https://explorer.sequentias-test.genobank.io/HumanMark