Git Blame Isn’t Enough: Buildi... Note
DZone.com

Git Blame Isn’t Enough: Building Verifiable Provenance for AI-Generated Code

AI-generated software requires provenance that persists beyond transient interactions. Existing code reviews do not reveal the originating model, influencing prompts, or execution context. Provenance bridges this gap by treating code generation as a traceable supply chain event. This concept aligns with established standards like W3C PROV for modeling provenance and SLSA for software artifact production verification. A key principle is separating authorship from provenance, as provenance describes origins, not ownership. Legal ownership of AI-generated content is determined by copyright law and contractual agreements, not solely by the generation process. The U.S. Copyright Office emphasizes the need for significant human authorship for copyrightability. Provenance serves as evidence for attribution and accountability. It supports audits and reviews by providing a verifiable history. Ultimately, provenance ensures transparency in the AI software development lifecycle.