Skip to content
BTW

How to document Sora work for client delivery

Sora's shutdown makes archiving a practical priority. Check the export route, retain your original clips and identify which production details you can still recover.

Published July 22, 2026. Updated September 6, 2026.

Sora's web and app experiences ended on 26 April 2026. The Videos API and Sora 2 aliases and snapshots are scheduled for removal on 24 September 2026, following developer notification on 24 March. As checked on 6 September, OpenAI still documents a content export route after the app shutdown. That API date is not a published data-deletion deadline.

OpenAI's Sora 2 system card described C2PA metadata, a visible moving watermark on first-party downloads, internal origin detection and opt-in cameo controls. Those are origin and safety measures, not a complete production account. Inspect the credentials actually present in your archived file, and keep prompts, selected takes, approvals and relevant likeness permissions separately.

Embedded Content Credentials do not disappear merely because the generation service closes. Preserve the original file and its verification result, then connect it to the context your team retained. A file hash helps compare exact copies; by itself it does not establish a creation date, permission or the causal relationship between an input and an output. Mark reconstructed details and unknowns clearly.

What Sora stores on its side

  • The Sora 2 system card describes C2PA metadata on all assets in its first-party provenance tooling. Source
  • The Sora 2 system card describes a visible moving watermark on videos downloaded from sora.com or the Sora app. Source
  • OpenAI described internal detection tools for assessing whether video or audio came from its products. Source
  • The Sora 2 system card describes explicit opt-in consent and likeness controls for cameos. Source
  • OpenAI notified developers on 24 March 2026 that the Videos API and the Sora 2 model aliases and snapshots would be removed from the API on 24 September 2026. Source
  • OpenAI's discontinuation guidance still directs users to sora.chatgpt.com/sunset to request an export. It places permanent deletion after any final export window, without specifying a deletion date. Source

What gets lost without your own record

  • App closure and data deletion are separate events. Request the available export and inspect its contents before deciding which prompts, iterations or library details need reconstruction.
  • The visible moving watermark identifies a clip as Sora output, but it says nothing about which account, prompt, or settings produced it.
  • C2PA metadata lives inside the file, so any downstream re-encode by a platform or an editing pipeline can leave the delivered copy with weaker provenance than your original download.
  • The system card describes internal detection tools, not a public client verification service. Do not promise a later origin lookup based on that description.
  • Cameo opt-in controls are not a substitute for checking the permissions relevant to a particular client delivery. Keep the clearance records you actually obtained.

The documentation checklist for Sora

  1. Open sora.chatgpt.com/sunset and select Export; OpenAI says it will email you when the export is ready. Save and inspect the package alongside your delivered clips.
  2. For each client clip, retain available prompts, generation dates, the surface used and approvals. Label estimates or reconstructed details instead of presenting them as original records.
  3. Keep the original download unmodified and store its hash to compare exact copies. Link edited delivery versions separately.
  4. Inspect the Content Credentials of the download with a C2PA verification tool while you still have the original, and file the verification result next to the clip.
  5. If a clip uses a cameo, archive the relevant likeness clearance with the delivery, including whose likeness was used and the permission's scope and date.
  6. Record when you obtained the export and which details it contains, so another team member can distinguish archived evidence from missing context.

Behind The Workflow gives this Sora record a practical home: keep an asset with the prompt, model, references, versions and decisions your team adds. Upload or explicitly capture the available details, fill the gaps, and review the record before handoff. BTW does not automatically reconstruct an external generation history or verify reference rights.

For teams delivering into the EU, the marking inside a Sora file helps with the provider-side machine-readable marking described by Article 50(2). Where a finished image, audio or video qualifies as a deep fake, Article 50(4) separately requires the deployer to disclose that it was artificially generated or manipulated. The Act does not prescribe an internal production log, but a dated project record helps the team show what it generated, what it disclosed and when, even after the originating tool disappears.

Describe what each piece of evidence supports. A verified credential reports its signed assertions. A saved approval records the decision it contains. A hash comparison checks file identity. These are useful together, but none automatically proves every production claim. Keep the original evidence and state which context remains unavailable.

Frequently asked questions

Does the C2PA metadata in a Sora download prove which prompt I used?

Do not infer the prompt from an origin label. Inspect the assertions present in that file, then retain any available prompt history and approval records alongside it. A Sora origin credential is not a complete generation or review log.

Can the provenance signals disappear from my delivered clip?

Re-encoding or other processing can remove embedded metadata. Service closure alone does not remove a credential from an unchanged file. Keep the original download and inspect the credential on the actual delivery copy as well.

Can OpenAI confirm later that a clip came from Sora?

The system card describes internal detection tools without offering a public origin-lookup service. Do not promise clients that OpenAI will verify a clip later. Preserve the original file, its available credentials and your production records.

Sora is being shut down. What happens to the work I already delivered?

Your downloaded clips remain usable. OpenAI still documents content export after the app shutdown; request it now and inspect what it contains. Permanent deletion follows any final export window, and the current guidance gives no exact deletion date.

I used a cameo in a client spot. Is the consent stored anywhere I can show?

The system card describes cameo opt-in controls, but that description does not establish the scope of permission for your client spot. Retain the relevant clearance and check what the actual export contains.

Do Sora's watermark and metadata satisfy the EU AI Act for my delivery?

They help with the provider-side machine-readable marking described by Article 50(2). If the finished content qualifies as a deep fake, the deployer still has a separate disclosure duty under Article 50(4). A delivery record is not prescribed by the Act, but it gives the team evidence of what was generated and how the disclosure was handled.

Test one Sora handoff

Use the original clip, the prompt you retained, and any consent record. The test is whether a teammate can continue from the selected version without reconstructing the session.

  1. Add the chosen output to a BTW project and review its production details. Use upload, the browser extension or a supported connected account, then complete the context this shot needs.
  2. Attach the relevant references and a revised version, then record what changed and which version was accepted.
  3. Review the record as the person receiving the work. Keep missing information explicit and share only the fields agreed for delivery.

Related guides