Proof

Brand, technology and AI, with the working shown.

No. 02 Provenance

Where a thing came from is becoming part of the thing

Design tokens get a stable format, media gets content credentials, AI gets a management-system standard and software gets a carbon number. Four kinds of provenance a brand now has to keep.

Read
4 min
Stories
4
Get Proof by email
Thousands of pieces of metal printing type heaped in a tray, letters facing every way.
Photograph: Da Nina / Unsplash

From the editor

A file used to be just a file. More and more, it is expected to carry its history with it: which system defined this colour, which tool made this image, which process governs this model, how much carbon this service costs to run.

None of that is new as an idea. What changed is that each now has a published standard, which means a client, a platform or an auditor can ask for it. This issue looks at four.

On the web version of this issue, from the studio: how we measure the carbon intensity of a web product, and a sales assistant that answers only from approved sources.

The Xterra Edze studio

Story 1 of 4, Brand: Tokens with a standard

On 28 October 2025 the Design Tokens Community Group announced the first stable version of its format, 2025.10. It is a vendor-neutral JSON format for the decisions a design system is made of, such as colour, type, spacing and motion, so that design tools, code and documentation can all read one source.

Rows of large wooden printing letters and ornaments in a print shop.
Wood type at Hatch Show Print, Nashville. Before tokens, the type case was the source of truth. Marcus dePaula / Unsplash

A token file carries more than values. It holds types, descriptions and references from one token to another, which is what lets a theme, a sub-brand or a market variant be expressed as a change to a handful of tokens rather than a redraw.

What it changes: a brand system can be handed over as data with a published shape, rather than as a PDF and a component library that drift apart. What we check: that the tokens are the source and everything else is generated from them, not the other way round.

Story 2 of 4, Campaigns: Content credentials

The Coalition for Content Provenance and Authenticity (C2PA) publishes an open technical standard for recording where a piece of media came from and how it was edited. The record travels with the file as Content Credentials.

Content Credentials function like a nutrition label for digital content, giving a peek at the content’s history available for anyone to access, at any time.

C2PA

For a campaign pipeline that mixes photography, illustration and generated imagery, that is a practical question as much as an ethical one: which export settings keep the credentials, which platforms strip them, and how an AI-generated asset is labelled when it ships.

What we check: that provenance survives the last step, meaning the resize, the compression and the upload, because that is where metadata is most often stripped.

Story 3 of 4, AI: A management system, not a model card

ISO/IEC 42001, published in December 2023, specifies an AI management system: the policies, roles, risk and impact assessments and controls an organisation uses to run AI responsibly. Like ISO/IEC 27001 for information security, it is a standard an organisation can be certified against.

It sits well beside the NIST AI Risk Management Framework, released in January 2023, whose four functions, Govern, Map, Measure and Manage, are a useful way to organise the work whichever standard you report against. NIST added a Generative AI Profile, NIST AI 600-1, in July 2024.

Neither framework tells you which model to use. Both ask the same questions in different words: who decided, on what evidence, and who can stop it.

What we check: that every AI system in a programme appears in one register, with an owner, a purpose, the data it touches, its evaluations and the person who can switch it off.

Story 4 of 4, Technology: A carbon number for software

The Green Software Foundation’s Software Carbon Intensity specification, now the international standard ISO/IEC 21031:2024, gives software a rate rather than a total.

SCI = ((E × I) + M) per R
E: energy used (kWh) · I: carbon intensity of that energy · M: embodied emissions of the hardware · R: the functional unit, such as a user or an API call.

The hard part is usually I, not E. The carbon intensity of a grid changes by region and by hour, so the same workload can score very differently depending on where and when it runs. That is also the lever: moving work that can wait to a cleaner region or hour changes the number without touching the code.

Because it is a rate, it rewards efficiency rather than shrinking the business: a service that doubles its users without doubling its emissions improves its score. What we check: that R is something the business already counts, so the number lands in a report someone reads.

Worth reading. The sources behind this issue.

From the studio. Related work and writing.

Proof

Get the next issue. Free, monthly, easy to leave.

One issue a month in your inbox, after you confirm by email. Choose topics if you like, or none for every story.

Choose topics (optional)

We keep your address, any topics you choose, this page and when you agreed, with your IP address and browser as the record of that agreement. Privacy notice

Let’s build what happens next.

Tell us what you’re building. We’ll answer straight.

Book a discovery call

Three ways to start

  1. 01About 2 minutes

    A quick question

    You get A reply from a lead, not a sales queue

  2. 02About 8 minutesMost useful

    A project brief

    You get Options and a first scope after one call

  3. 03About 15 minutes

    A formal RFQ or RFP

    You get Receipt confirmed and a named bid lead

Every engagement starts with a written scope and a quote agreed before work begins. How each package is priced