Guide
What Is C2PA? Content Credentials Explained (2026)
A plain-English 2026 guide to C2PA and Content Credentials: what a manifest actually contains, how hard and soft bindings work, where the standard has reached in 2026, how to check a file's credentials in under a minute, what the April 2026 security analysis found, what the Nikon certificate revocation showed about the trust model, and the honest limits of signed provenance.
Quick answer: C2PA is an open technical standard for recording where a piece of digital content came from and what has happened to it since, and Content Credentials is the consumer-facing name for the signed record itself. A Content Credential is a cryptographically signed data structure attached to a file that lists the device or software that created it, the edits applied, and — optionally — the identity of the creator, in a form that cannot be altered without breaking the signature. The specification is maintained by the Coalition for Content Provenance and Authenticity, a Joint Development Foundation project affiliated with the Linux Foundation, whose steering committee includes Adobe, Amazon, the BBC, Google, Meta, Microsoft, OpenAI, Publicis Groupe, Sony, TikTok and Truepic (C2PA). The current release is version 2.4, published April 2026 (C2PA specification). The caveat that governs everything below, and it is not a small one: a security analysis published on 23 April 2026 by researchers at UMBC, Hacker Factor and the NSA examined C2PA versions 2.2 to 2.4, documented six classes of weakness, and concluded that the standard “should not yet be relied upon for high-stakes uses” (Golaszewski et al.). Content Credentials are the strongest provenance signal generally available in 2026. They are not yet proof.
This guide covers the standard itself — what is in a manifest, who runs it, where it has reached, and where it breaks. It is the signed-metadata half of the provenance story; the invisible-signal half, covering how statistical watermarks such as SynthID work, is what is AI watermarking. For tools that guess at AI origin from the pixels instead, with their much worse record, see best AI image detectors and how AI detectors work.
What C2PA is, and the three names people confuse
Three things share this territory and get used interchangeably. Keeping them apart makes everything else easier.
| Name | What it is |
|---|---|
| C2PA | The Coalition for Content Provenance and Authenticity — the standards body — and, by extension, the technical specification it publishes |
| Content Credentials | The consumer-facing brand for the signed provenance record a C2PA implementation produces, and the name of the specification as of the 2.x series |
| Content Authenticity Initiative (CAI) | Adobe’s advocacy and community programme promoting adoption; it does not own the specification |
A fourth, less visible body matters too: the Creator Assertions Working Group (CAWG), now hosted at the Decentralized Identity Foundation, which maintains the optional identity and licensing specifications that sit on top of the core standard.
C2PA is governed as a project of Joint Development Foundation Projects, LLC, affiliated with the Linux Foundation (C2PA). The first public draft appeared in 2021.
What is actually inside a Content Credential
This is what determines what the technology can and cannot prove. The specification defines a nested structure.
| Component | Specification definition |
|---|---|
| Manifest store | ”A collection of C2PA Manifests that can either be embedded into an asset or be external to its asset” |
| Manifest | One or more assertions, a single claim, and a claim signature |
| Assertion | ”A data structure which represents a statement either made (or ‘created’) by the signer or simply gathered at claim generation-time, concerning the asset” |
| Claim | A structure referencing a set of assertions “and the information necessary to represent the content binding” |
| Claim signature | ”The digital signature on the claim created using the private key owned by a signer” |
| Ingredient | A component asset used to compose or derive the current one, recorded through the ingredient assertion |
Definitions quoted from the C2PA technical specification 2.4.
The practical shape: assertions are the facts, the claim bundles them, and the signature makes the bundle tamper-evident. Edit the file without a conforming tool and the binding breaks; edit the manifest and the signature fails. The specification defines 28 standard assertion types, including c2pa.actions (what was done to the asset), c2pa.ingredient (what it was made from), c2pa.hash.data (the content binding), c2pa.metadata, c2pa.thumbnail and c2pa.timestamp.
Hard bindings and soft bindings
The binding is how a manifest is tied to the bytes it describes, and there are two kinds. The distinction explains most of C2PA’s behaviour in the real world.
- A hard binding is “one or more cryptographic hashes that uniquely identifies either the entire asset or a portion thereof”. It is exact and it is brittle: change a pixel and it no longer matches.
- A soft binding is “a content identifier that is either (a) not statistically unique, such as a fingerprint, or (b) embedded as an invisible watermark”. It is approximate and it survives things a hash cannot.
A hard binding gives certainty about an unmodified file. A soft binding gives a way to find the provenance record again after the file has been re-encoded, cropped or screenshotted. Neither alone is sufficient, which is the reasoning behind durable Content Credentials below.
How it works, end to end
- Capture or generation. A conforming camera, phone or AI model creates the asset and writes an initial manifest — what made it, when, and a hash binding the manifest to the content.
- Editing. A conforming editor opens the file, records the original as an ingredient, adds
c2pa.actionsassertions describing what it did, and signs a new manifest. The manifest store now holds a chain. - Signing. Each manifest is signed with a certificate issued to the signer. Validators check that certificate against the C2PA Trust List.
- Distribution. The file travels. Whether the credential travels with it depends entirely on what handles it next.
- Validation. A reader checks the signature, the certificate, and whether the hash still matches the bytes, then displays the history.
Step 4 is where most of the real-world failure happens, and no amount of cryptography fixes it.
What a validator can actually tell you
People expect a credential check to return “real” or “fake”. It does not, and knowing the actual outcomes is what stops a reader over-reading the result.
| Outcome | What it means | What it does not mean |
|---|---|---|
| Valid manifest, trusted signer | The signature checks out, the certificate traces to the C2PA Trust List, and the bytes match the hash | That the content is truthful, or that it is not AI-generated |
| Valid manifest, untrusted or unknown signer | The cryptography is sound but the certificate is not on the trust list | That the file is fraudulent; plenty of legitimate signers are not listed |
| Manifest present, binding broken | The file has been altered since signing, or re-encoded by something non-conforming | That someone tampered maliciously; a platform re-save does this routinely |
| Certificate revoked or expired | The signer’s certificate is no longer good — though many validators will not tell you this at all | That every image from that signer is fake |
| No manifest | There is nothing to check | Anything whatsoever |
The fourth row is the one the 2026 research is most exercised about, and the fifth is the one readers most often get wrong.
What you actually see in a credential
A well-populated manifest reads less like a certificate and more like a file’s biography. The assertions typically present are:
c2pa.actions— the operations performed: created, opened, colour-adjusted, cropped, resized, placed, AI-generated.c2pa.ingredient— each source asset used to build this one, with its own manifest attached where it had one, which is what produces a chain rather than a single record.c2pa.hash.data— the hard binding tying the manifest to the bytes.c2pa.soft-binding— a fingerprint or watermark identifier, where the implementation supports recovery after stripping.c2pa.metadata,c2pa.thumbnailandc2pa.timestamp— descriptive information, a visual preview of the asset as signed, and time-stamp records.
The ingredient chain is the genuinely interesting part: it is how you can see that a published image was composed from a camera original plus a generative fill, with each step signed by whoever performed it.
How C2PA got here
| Date | Milestone |
|---|---|
| 2019 | Adobe establishes the Content Authenticity Initiative |
| 2021 | C2PA forms and publishes the first public draft of the specification |
| Feb 2024 | Google joins the steering committee |
| May 2024 | OpenAI joins the steering committee |
| Sep 2024 | Meta and Amazon join the steering committee; Google commits to surfacing C2PA data in Search |
| Mid-2025 | Conformance programme launches; the C2PA Trust List replaces the Interim Trust List |
| Aug–Sep 2025 | Nikon launches and then suspends Z6 III signing, revoking all certificates issued |
| 1 Jan 2026 | Interim Trust List frozen to new entries |
| 9 Feb 2026 | Content Credentials 2.3 released; coalition marks five years and 6,000+ members |
| Apr 2026 | Specification 2.4 published; UMBC/Hacker Factor/NSA security analysis published |
| Jul 2026 | Deployment Guidance 1.0 and a new Implementation Guide; TikTok joins the steering committee |
| Aug 2026 | CAWG identity assertion 1.3 ratified |
Sources as cited throughout; timeline entries drawn from C2PA announcements.
Where the standard has reached, as of September 2026
| Item | Status |
|---|---|
| Current specification | Version 2.4, April 2026; version 2.3 launched 9 February 2026 alongside the coalition’s five-year milestone |
| Membership | More than 6,000 members and affiliates with live applications |
| Conformance programme | Launched mid-2025; requires adherence to the specification, the Certificate Policy and the Security Requirements document |
| Trust list | The C2PA Trust List replaced the Interim Trust List in mid-2025; the ITL was frozen to new entries on 1 January 2026 |
| Implementation guidance | Content Credentials Deployment Guidance 1.0 published 8 July 2026; a new Implementation Guide announced 31 July 2026 |
| Governance | TikTok elevated from General Member to the Steering Committee on 28 July 2026 |
| Identity layer | CAWG identity assertion version 1.3 ratified 17 August 2026 |
| ISO standardisation | Not published. See below |
Sources: C2PA announcements, C2PA conformance, Content Credentials Deployment Guidance 1.0, CAWG identity assertion 1.3, Andy Parsons, CAI.
One nuance worth noting rather than smoothing: the specification site lists 2.4 as the current release, while the conformance programme page still frames its requirements against 2.3. Implementers should check which version a given conformance claim is made against.
The ISO position, which is widely misreported
C2PA is frequently described as “an ISO standard”. As of 30 September 2026 it is not, and the public records disagree about where exactly it sits.
- The ISO catalogue record lists ISO/CD 22144, “Authenticity of information — Content credentials”, at stage 30.99 under ISO/TC 171/SC 2, with the project approved on 28 October 2024 and no publication date (ISO).
- ANSI’s webstore lists a ISO/DIS 22144:2025 draft (ANSI).
- ASIS&T reported on 19 March 2025 that the DIS went through the ISO Fast-Track process under ISO/TC 46/SC 9 and drew a “No” vote with comments (ASIS&T).
The safe statement: ISO 22144 is in development and has not been published. Any page or vendor telling you Content Credentials is already an ISO standard is ahead of the record.
Where you will actually meet Content Credentials
Adoption is real but uneven, and it is strongest at the two ends — generation and capture — and weakest in the middle, where files are distributed.
| Layer | Examples | Notes |
|---|---|---|
| AI generators | ChatGPT, Codex and the OpenAI API images carry C2PA metadata plus a SynthID watermark (OpenAI) | OpenAI states coverage “can vary by product, model, export path, file type” |
| Phones | Google Pixel 10 signs images with C2PA credentials (CAI) | Capture-side support in a mainstream phone |
| Cameras | Sony’s PXW-Z300 ships with Content Credentials support; Nikon’s Z6 III programme is currently suspended (below) | Capture-side support is early and, in one case, withdrawn |
| Creative software | Adobe’s tools; Content Authenticity for Enterprise | Adobe originated the CAI in 2019 |
| Search | Google surfaces C2PA metadata in “About this image” across Google Images, Lens and Circle to Search (Google) | Announced 17 September 2024 |
| Assistants | The Gemini app checks both Content Credentials and SynthID when asked to verify a file (Google) | Roughly 10 image checks per rolling 24 hours |
| Social platforms | TikTok reads C2PA Content Credentials and writes them into content made with its own tools (TikTok) | Announced 19 November 2025; 1.3 billion videos labelled to date |
How to check a file’s Content Credentials
Three routes, all free, all under a minute.
- Ask the Gemini app. Upload the file and ask whether it was created or edited by AI. Gemini checks Content Credentials and SynthID and reports what it finds. Google caps this at roughly ten image checks per rolling 24 hours, with a 100MB file limit, advises against uploading screenshots or collages, and says Content Credentials checks run on the web and Android, with iOS to follow.
- Use a C2PA reader. Any conforming inspector will display the manifest chain if one survives on the file.
- Use the generator’s own verifier. For suspected OpenAI output, openai.com/verify checks for both the C2PA metadata and the SynthID watermark, and OpenAI offers a verification API for volume.
A separate and much cheaper check sits alongside these: open the file in any viewer that shows XMP and look for the IPTC Digital Source Type property. The recommended value for generative output is trainedAlgorithmicMedia, and C2PA has integrated digitalSourceType into its own specification (IPTC). A file that declares itself this way is a strong lead, though a declaration can be written by anyone. For the full procedure when there is no credential to read, see how to tell if an image is AI-generated.
What a Content Credential proves — and what it does not
It proves: that a specific signer, holding a specific certificate, asserted a specific set of facts about this content at a specific point, and that the bytes have not changed since. That is a real and useful thing, and it is more than any classifier can offer.
It does not prove:
- That the content is true. A signed photograph of a staged scene is a signed photograph. Provenance records the chain of custody, never the honesty of what was in front of the lens.
- That the content is not AI-generated. An AI generator can be a conforming signer. A valid credential from an image model says exactly that: a model made this.
- Who the person behind it is. The core specification is deliberately silent on this — C2PA states that it “does not support attribution of content to individuals or organizations, so that it can remain maximally privacy-preserving” (C2PA). Named attribution only appears if a creator opts into a CAWG identity assertion.
- Anything at all, when absent. This is the most consequential point on the page. Most content has never carried a credential, and content that did routinely loses it.
How it compares with the other ways of answering the same question
Four technologies claim to tell you whether content is AI-generated or authentic. They are not interchangeable, and the differences are structural rather than a matter of quality.
| Approach | What it is | Strength | Fails when | Our coverage |
|---|---|---|---|---|
| C2PA Content Credentials | Signed metadata attached to the file | Cryptographically verifiable; records a full edit chain | Metadata is stripped, a signer is compromised, or no credential was ever attached | This page |
| Invisible watermarking | A statistical signal embedded in the content itself | Survives screenshots, crops and re-encoding | Heavy editing, paraphrase or translation; only covers providers that mark | AI watermarking |
| Visible labels | A badge or corner mark aimed at the viewer | Immediately legible to a human | Cropped, toggled off, or simply never applied | Covered in the watermarking guide |
| Classifier detectors | Software guessing from the pixels or prose | Works with no cooperation from the generator | Constantly; independent audits show serious false-positive rates | AI image detectors, AI detectors |
The ranking by evidential strength runs top to bottom. A credential is a record someone signed; a watermark is a signal someone embedded; a label is a claim someone displayed; a detector score is a guess nobody vouched for. Terms used here are defined in our AI glossary.
C2PA is also explicitly not a rights-management system. The coalition states that Content Credentials “are not a form of DRM” and “record and preserve the provenance of digital media without limiting its use”. Relatedly, in January 2026 C2PA clarified that its specification contains no standard assertion for text and data mining — so a Content Credential is not a machine-readable AI-training opt-out, whatever some coverage implies.
The April 2026 security analysis
The most careful assessment of C2PA’s weaknesses comes from security researchers rather than from its critics in the press. A paper published on 23 April 2026 by Enis Golaszewski, Neal Krawetz, Alan T. Sherman, Edward Zieglar and colleagues at UMBC, Hacker Factor and the NSA examined versions 2.2 to 2.4 and documented six classes of weakness (arXiv 2604.24890).
| Weakness | What it means |
|---|---|
| Timestamps can be altered undetected | Nothing in the signed data references the timestamp |
| Revocation is often not checked | Many validators accept signatures made with compromised or revoked keys |
| Validators disagree | The paper’s demonstration has Adobe Inspect reporting revoked certificates as valid while Verifieddit reported them invalid, on the same file |
| Exclusion ranges leave parts of a file unsigned | Modified GPS coordinates in a Pixel 10 Pro image went undetected by the Proofmode validator |
| Credentials expire | An Arizona Secretary of State image validated in January 2025 and failed validation a year later, which the authors note conflicts with legal retention requirements |
| The conformance programme is weak | It lacks security requirements and source-code review |
The paper’s own demonstration includes a Nikon Z6 III used to sign AI-generated images. Which brings us to the case that makes all of this concrete.
The Nikon case: what happens when a signing key goes bad
In August 2025 Nikon launched the Nikon Authenticity Service, letting the Z6 III sign photographs with Content Credentials at capture. It is the clearest real-world test the trust model has had, and it failed.
The timeline, as reported by PetaPixel:
- 27 August 2025 — the service launches.
- Shortly after, researcher Adam Horshack finds that the camera’s multiple-exposure mode can be used to sign fraudulent images. He gets a wholly AI-generated image of a pug in a pilot’s outfit validated as an authentic Nikon capture.
- 4 September 2025 — Nikon discovers “a technical issue” with the provenance recording function and suspends the service, one week after launch.
- Nikon then invalidates every certificate issued in that window, stating that “the authenticity credentials attached to these images are no longer valid and cannot be used as proof of provenance”.
Three things about this deserve to be carried forward, because they are properties of the system rather than of Nikon.
First, revocation does not reliably propagate. Many validation tools do not check revocation by default, so images signed with the revoked certificates can still validate cleanly. Horshack filed a GitHub issue asking open-source validators to make revocation checking the default. This is the same finding the UMBC paper reached independently.
Second, the manufacturer cannot fix it alone. As PetaPixel puts it, there is “no way to prevent online validation tools from validating C2PA-signed images, even from cameras that have had their certification revoked”. The strength of the guarantee depends on every downstream validator, not on the issuer.
Third, the attack was not against the cryptography. The signature worked perfectly. The camera was persuaded to sign the wrong thing. That is the general shape of the risk: a conforming signer that can be tricked produces a genuinely valid credential for false content.
Durable Content Credentials: the answer to stripping
The single most common complaint about C2PA is that metadata gets removed — by a screenshot, a re-save, a format conversion, or a platform re-encoding an upload. OpenAI states this plainly about its own files: Content Credentials “can sometimes be removed by platforms, editing tools, or file conversions”.
The CAI’s answer is durable Content Credentials, which combine three technologies rather than relying on metadata alone (Andy Parsons, CAI, 8 April 2024):
- Secure metadata — the signed manifest, which “cannot be altered without leaving evidence of alteration”.
- Watermarking — a hidden signal that survives cropping, rotation and screenshotting.
- Fingerprinting — a numerical descriptor derived from the pixels or waveform, allowing a match against a stored record even after modification.
Each is individually weak. Metadata can be stripped, watermarks can be degraded or spoofed, fingerprint matches are probabilistic. Together, as the CAI argues, “the three form a unified solution that is robust and secure enough to ensure that reliable provenance information is available no matter where a piece of content goes”. When the metadata is gone, the watermark recovers an identifier pointing at the stored credential and the fingerprint confirms the match.
This is also why the hard-binding and soft-binding distinction in the specification matters: soft bindings are the hook that makes recovery possible.
C2PA and the law
EU AI Act Article 50 became enforceable on 2 August 2026. It requires providers of systems generating synthetic text, audio, images or video to ensure outputs are marked in a machine-readable, detectable format wherever technically feasible, with an additional disclosure duty for deepfakes.
The law is deliberately technology-neutral. It does not mandate C2PA, or SynthID, or any named scheme — which is why the industry response is a mix of signed metadata, statistical watermarks and visible labels. C2PA is one compliant answer among several, and the most auditable of them, but adopting it is a choice rather than a legal requirement.
Should you turn Content Credentials on?
If you are a photographer or journalist: yes, where your camera or phone supports it, and keep the original files. A credential is worth most on work whose authenticity may later be questioned. Do not present it as proof — present it as a record.
If you publish AI-generated images: yes, and leave the credential intact on export. The disclosure is the point, and Article 50 is now enforceable in the EU.
If you are building a product that validates credentials: check revocation by default. That single decision addresses a weakness raised by both the UMBC paper and the Nikon incident, and many validators currently skip it.
If you are deciding whether something is real: treat a valid credential as strong evidence about origin, verify it in more than one validator if anything turns on it, and treat a missing credential as no evidence at all. For the wider procedure, including what to do when there is no credential to read, see how to tell if an image is AI-generated; for the detection tools themselves, see best AI image detectors. For faces and video specifically, see best deepfake detectors.
Five things people get wrong about C2PA
These recur often enough to be worth stating flatly.
- “No Content Credential means it is AI.” It means nothing. The overwhelming majority of images online have never carried one.
- “A Content Credential means it is a real photograph.” AI image generators are conforming signers. A valid credential from one records that a model made the file.
- “C2PA is an ISO standard.” ISO 22144 is in development and unpublished as of 30 September 2026.
- “C2PA stops my work being used for AI training.” The specification has no standard text-and-data-mining assertion, as the coalition itself clarified in January 2026.
- “The signature is unbreakable, so the credential is trustworthy.” The Nikon case broke nothing cryptographic. The camera was persuaded to sign an AI-generated image, and the resulting credential was mathematically perfect and completely false.
Frequently asked questions
What is C2PA?
C2PA is the Coalition for Content Provenance and Authenticity, and the open technical standard it publishes for recording where digital content came from and how it has been edited. The standard defines a cryptographically signed data structure, branded Content Credentials, that travels with a file and records the device or software that created it, the edits applied, and optionally the creator’s identity. It is governed as a Joint Development Foundation project affiliated with the Linux Foundation, and its steering committee includes Adobe, Amazon, the BBC, Google, Meta, Microsoft, OpenAI, Publicis Groupe, Sony, TikTok and Truepic. The current specification is version 2.4, published April 2026.
What are Content Credentials?
Content Credentials are the signed provenance record that a C2PA implementation attaches to a file, and the consumer-facing name for the standard as of its 2.x series. Technically, a credential is a manifest containing one or more assertions (the facts about the asset), a claim that bundles them, and a claim signature made with the signer’s private key. Assertions can record what tool made the file, what actions were performed on it, what source assets it was composed from, and a hash binding the manifest to the actual bytes. Alter the file or the manifest and the signature no longer validates, which is what makes the record tamper-evident.
Is C2PA an ISO standard?
Not yet, despite frequent claims otherwise. As of 30 September 2026 the ISO catalogue lists ISO/CD 22144, “Authenticity of information — Content credentials”, at stage 30.99 under committee ISO/TC 171/SC 2, with the project approved in October 2024 and no publication date. ANSI lists a 2025 draft international standard, and ASIS&T reported in March 2025 that the fast-tracked DIS drew a “No” vote with comments. The records disagree on the detail but agree on the substance: it is in development and has not been published.
Does a Content Credential prove an image is real?
No. It proves that a specific signer asserted specific facts about the file and that the bytes have not changed since. It cannot tell you whether what the camera was pointed at was staged, and it cannot tell you the content is not AI-generated — an AI image generator can be a conforming signer, and a valid credential from one simply records that a model made the file. The 23 April 2026 security analysis by researchers at UMBC, Hacker Factor and the NSA concluded that C2PA “should not yet be relied upon for high-stakes uses”. Treat a valid credential as strong evidence about origin, not as a verdict on truth.
Why do Content Credentials disappear from images?
Because the credential is metadata attached to the file, and a great deal of ordinary handling discards metadata. A screenshot creates a new file with no manifest. Re-saving in another application, converting formats, or uploading to a platform that re-encodes images can all strip it. OpenAI states this about its own output, noting that Content Credentials “can sometimes be removed by platforms, editing tools, or file conversions”. This is why the absence of a credential proves nothing, and why the CAI is pushing durable Content Credentials, which pair the metadata with a watermark and a fingerprint so the record can be recovered after stripping.
What is the difference between C2PA and a watermark?
They solve the same problem from opposite directions and are increasingly used together. A C2PA Content Credential is signed metadata attached to the file: rich, precise, cryptographically verifiable, and easy to remove. A watermark is an imperceptible signal embedded in the content itself: carries far less information, cannot be read without the right detector, but survives cropping, re-encoding and screenshotting. In C2PA’s own vocabulary a hash-based credential is a hard binding and a watermark or fingerprint is a soft binding. Our guide to AI watermarking covers the watermark side in depth.
How do I check if an image has Content Credentials?
Three free routes. Upload the file to the Gemini app and ask whether it was created or edited by AI — Gemini checks both Content Credentials and Google’s SynthID watermark, with a limit of roughly ten image checks per rolling 24 hours. Open the file in any C2PA reader, which will display the manifest chain if one survives. Or, for suspected OpenAI output, use openai.com/verify, which checks for the C2PA metadata and the SynthID watermark that OpenAI embeds in images from ChatGPT, Codex and its API. Google also surfaces C2PA metadata in the “About this image” panel across Google Images, Lens and Circle to Search.
Which cameras and phones support Content Credentials?
Support is early and uneven. The Google Pixel 10 signs images with C2PA credentials, and Sony shipped the PXW-Z300 video camera with Content Credentials support. Nikon launched an Authenticity Service for the Z6 III on 27 August 2025 but suspended it on 4 September 2025 after a vulnerability was found, and revoked every certificate issued in that window. Because capture-side support changes quickly and at least one programme has been withdrawn, check the manufacturer’s own current documentation rather than a third-party list.
What happened with the Nikon C2PA vulnerability?
Researcher Adam Horshack found that the Nikon Z6 III’s multiple-exposure mode could be used to make the camera sign fraudulent images, and demonstrated it by getting a wholly AI-generated image validated as an authentic Nikon capture. Nikon suspended the Authenticity Service on 4 September 2025, a week after launch, and invalidated all certificates issued in that period, stating that the credentials on those images “are no longer valid and cannot be used as proof of provenance”. Two structural lessons outlast the incident: many validators do not check certificate revocation by default, so the revoked signatures can still validate; and the attack defeated the camera rather than the cryptography, which is the general shape of the risk.
Does C2PA let me opt out of AI training?
No. In January 2026 C2PA clarified that its technical specification contains no standard assertion for text and data mining, so a Content Credential is not a machine-readable training opt-out. The coalition is also explicit that Content Credentials “are not a form of DRM” and are designed to “record and preserve the provenance of digital media without limiting its use”. Any tool marketing C2PA as a way to block AI training is overstating what the standard does.
Is C2PA required by law?
Not specifically. EU AI Act Article 50 became enforceable on 2 August 2026 and requires providers of generative AI systems to mark synthetic output in a machine-readable, detectable format wherever technically feasible, with extra disclosure duties for deepfakes. The law is technology-neutral: it does not name C2PA, SynthID or any other scheme. C2PA is one of the most auditable ways to comply, but it is a choice, not a mandate, and there is no equivalent United States federal requirement.
Does C2PA identify who took a photo?
Not by default, and this is deliberate. C2PA states that the core specification “does not support attribution of content to individuals or organizations, so that it can remain maximally privacy-preserving”. Named attribution is an optional layer: the Creator Assertions Working Group, hosted at the Decentralized Identity Foundation, maintains an identity assertion — version 1.3 was ratified on 17 August 2026 — that lets a creator cryptographically bind a verified identity and a role such as creator, editor or publisher to specific assertions in a manifest. A creator has to opt into that; it is not part of the base credential.
What is the C2PA Trust List?
The Trust List is the register of certificate authorities whose signing certificates conforming validators should accept, and it is what turns a mathematically valid signature into a meaningful one. The official C2PA Trust List replaced the earlier Interim Trust List in mid-2025, bringing higher security and interoperability requirements aligned to the 2.x specification series; the Interim Trust List was frozen to new entries on 1 January 2026. Getting listed runs through the C2PA conformance programme, which requires adherence to the specification, the Certificate Policy and the Security Requirements document. The April 2026 security analysis criticised that programme for lacking security requirements and source-code review.