Imagine you're a detective investigating counterfeit currency. You have two completely different crime scenes: one where the bills were printed on a press (direct generation), and another where someone wrote detailed instructions that a legitimate printing machine then followed (code rendering). The physical bills might look identical, but the forensic evidence — ink chemistry vs. instruction paper trails — lives in totally different places. This paper maps both crime scenes but doesn't dust for fingerprints. The committed claim: AI-produced visuals arrive through two fundamentally distinct production routes — direct pixel/frame generation (Stable Diffusion, DALL-E, Sora) and LLM-driven code that is then rendered (matplotlib plots, SVG graphics, Manim animations, agent-composed workflows) — and the provenance community has been treating them as one problem when they are structurally two. The paper builds a taxonomy that distinguishes passive detection, message-recovery watermarking, and authenticated provenance across both routes, organized by production stage. There is no ladder to climb here in the traditional sense. The paper explicitly states it 'reports no experiments and claims no new theorems.' It reviews existing watermarking methods — image-space (StegaStamp, Tree-Ring), video-space, source-code-level, and rendering-aware approaches — and organizes them into a stage-based framework. It documents actual API interfaces for Claude, OpenAI, and rendering tools like matplotlib and Manim. The value proposition is cartographic, not competitive: here is the territory, here are the blank spots. Architecturally, the framework spans the full stack. For direct generation, intervention points include latent-space watermarks (modifying diffusion noise patterns), decoder-level marks, and post-hoc pixel-space stamps. For the code route, the intervention points shift radically: you can watermark the source code itself (variable naming, whitespace patterns), the intermediate representation (SVG structure, plot parameters), or the final rendered output. The paper's key structural insight is that code-route provenance has access to a semantic layer — the code — that direct generation lacks entirely, creating different tradeoff surfaces for robustness, capacity, and detectability. Integrity is the wrong lens for this paper, and that's fine as long as you know what you're reading. The appendix contains 'elementary calculations' and 'documentation and source inspection' — not benchmarks. The ten research questions posed (identifiability under format conversion, fair cross-stage comparison, synchronization for video watermarks, private authentication of production events) are well-scoped but untested. This is a grant proposal dressed as a paper, which is a legitimate genre if you don't mistake it for results. The milestone question is where this framework's value will be tested. The provenance problem is accelerating: C2PA adoption is growing but covers only cooperating producers, not adversarial ones. The paper identifies the gap between 'this image has a watermark' and 'this image was produced by this specific agent workflow at this timestamp' as the key frontier. Concrete next numbers would be something like: recoverable payload capacity across format conversions (current best ~256 bits for images; code-route theoretical capacity is much higher but undemonstrated), or robustness rates under adversarial screenshot-and-repost pipelines. The obvious experiment not run is a head-to-head comparison: take the same visual output produced via both routes, apply best-available watermarking at each production stage, then run both through a realistic degradation pipeline (screenshot, resize, JPEG compression, social media repost). The authors clearly have the technical background to design this. My read: this is a (c) situation — they're establishing the conceptual territory first and will run experiments in follow-up work. The paper reads as a deliberate land-grab on a research agenda before the space gets crowded.