Democracies cannot defend an election they cannot see clearly. When a voter cannot verify whether a video is real, the election is lost before the polls open — not to any single lie, but to the impossibility of trusting any claim at all. Cryptographic hardware-level watermarking is the only mechanism that restores a verifiable chain of authenticity from the moment a photon hits the sensor, and it should be mandated.
Three points anchor this position. First, the technology is not speculative — it is proven and already standardized. The C2PA specification already defines cryptographically signed provenance manifests with hard bindings (tamper-evident hashes) and soft bindings (invisible watermarks that survive cropping, resizing, and metadata stripping on social platforms) (C2PA specification, C2PA explainer). Mandating it at the silicon level simply moves watermarking from optional metadata to tamper-resistant default.
Second, the regulatory direction is already set. The EU AI Act's Article 50 already requires machine-readable marking of AI-generated content and labeling of deepfakes, in force from 2 August 2026 (European Commission, Article 50 guidelines). A camera-level mandate is the logical completion of a trajectory regulators have already accepted.
Third, hardware-level signing empowers citizens rather than surveilling them. Provenance is not tracking: the watermark proves what a device captured and when; it does not reveal who held the device. It is a shield for the voter, not a lens on the voter.
I concede the costs honestly. Absolute digital anonymity takes a real dent, and open-source hardware faces a genuine compliance burden. But these are negotiable design constraints, not fatal flaws — watermarking can be specified openly, audited publicly, and standardized across vendors. What cannot be negotiated is a shared reality. Without it, no right survives.