PRE-GEN

What it proves

For providers and their counsel · PRE-GEN v5 · the normative source is PRE-GEN-SPEC.md §10

PRE-GEN is authorization before generation and evidence of it, inside the ecosystem of providers that choose to ask. It is not enforcement on systems that never ask, and it does not decide whether a use is lawful.

SayDo not say
"We query PRE-GEN before generation and keep the signed decisions and receipts.""PRE-GEN guarantees the use is lawful." "Nobody can generate this likeness anymore."

What each object proves

ObjectProvesDoes not prove
DecisionThis registry gave this answer to this exact request, at that time, unchanged sinceThat a licence exists; that the output matched the request; that the use is lawful
LicenceThe subject's key and the registry's key signed these termsUnder managed custody, the subject's own act: the registry holds the key
ReceiptThe provider reported producing this output under this decisionThat the report is true; that every generation was reported
ObservationThe provider reported a use that needed no licenceThat the use happened as reported; anything granted
Audit logAn event is included under a root timestamped outside the registryThat the log is complete; that what it records is true
Registry directoryWhich registry may issue which codes, signed by the steward keyAny right over a person or a work

Refusals and opt-outs

  • An opt-out has priority over every licence in the registry that holds it. Another registry holding the same person is not bound by it in v5.
  • A new opt-out waits 14 days at PRAMPTA before it takes effect, because anyone claiming authority can file one. The subject's owner can pause the subject immediately.
  • From its effective time every new decision refuses. A decision issued earlier stays usable until it expires (300 seconds at PRAMPTA); a cached allow never outlives its expiry.
  • Even a refusal, including a request without valid credentials, comes back as a signed decision you can keep.

Limits to state plainly

  • Systems that never ask — offline, open-weight or non-integrated models — are outside the protocol.
  • Recognition is the provider's job. Authorization is asked for a named subject; resemblance, style or composites without a name are not caught by PRE-GEN.
  • Managed custody (the reference registry today): consent rests on the registry's records, not on a key the subject holds.
  • A false allow from a compromised registry cannot be independently confirmed or ruled out without a verifiable licence and a trusted subject key.
  • One registry in production today (PRAMPTA). Codes from several registries never collide; their rights and opt-outs are not reconciled in v5.
  • C2PA: the signed assertion exists, but an end-to-end C2PA integration has not been tested.
  • Licence sales are paused at PRAMPTA: requests go to the rights-holder and nothing is charged. Decisions and receipts work the same.