Category leaders

Guide

What Is C2PA? Content Credentials Explained (2026)

A plain-English 2026 guide to C2PA and Content Credentials: what a manifest actually contains, how hard and soft bindings work, where the standard has reached in 2026, how to check a file's credentials in under a minute, what the April 2026 security analysis found, what the Nikon certificate revocation showed about the trust model, and the honest limits of signed provenance.

September 30, 2026 · The AI Rankings

Quick answer: C2PA is an open technical standard for recording where a piece of digital content came from and what has happened to it since, and Content Credentials is the consumer-facing name for the signed record itself. A Content Credential is a cryptographically signed data structure attached to a file that lists the device or software that created it, the edits applied, and — optionally — the identity of the creator, in a form that cannot be altered without breaking the signature. The specification is maintained by the Coalition for Content Provenance and Authenticity, a Joint Development Foundation project affiliated with the Linux Foundation, whose steering committee includes Adobe, Amazon, the BBC, Google, Meta, Microsoft, OpenAI, Publicis Groupe, Sony, TikTok and Truepic (C2PA). The current release is version 2.4, published April 2026 (C2PA specification). The caveat that governs everything below, and it is not a small one: a security analysis published on 23 April 2026 by researchers at UMBC, Hacker Factor and the NSA examined C2PA versions 2.2 to 2.4, documented six classes of weakness, and concluded that the standard “should not yet be relied upon for high-stakes uses” (Golaszewski et al.). Content Credentials are the strongest provenance signal generally available in 2026. They are not yet proof.

This guide covers the standard itself — what is in a manifest, who runs it, where it has reached, and where it breaks. It is the signed-metadata half of the provenance story; the invisible-signal half, covering how statistical watermarks such as SynthID work, is what is AI watermarking. For tools that guess at AI origin from the pixels instead, with their much worse record, see best AI image detectors and how AI detectors work.


What C2PA is, and the three names people confuse

Three things share this territory and get used interchangeably. Keeping them apart makes everything else easier.

NameWhat it is
C2PAThe Coalition for Content Provenance and Authenticity — the standards body — and, by extension, the technical specification it publishes
Content CredentialsThe consumer-facing brand for the signed provenance record a C2PA implementation produces, and the name of the specification as of the 2.x series
Content Authenticity Initiative (CAI)Adobe’s advocacy and community programme promoting adoption; it does not own the specification

A fourth, less visible body matters too: the Creator Assertions Working Group (CAWG), now hosted at the Decentralized Identity Foundation, which maintains the optional identity and licensing specifications that sit on top of the core standard.

C2PA is governed as a project of Joint Development Foundation Projects, LLC, affiliated with the Linux Foundation (C2PA). The first public draft appeared in 2021.

What is actually inside a Content Credential

This is what determines what the technology can and cannot prove. The specification defines a nested structure.

ComponentSpecification definition
Manifest store”A collection of C2PA Manifests that can either be embedded into an asset or be external to its asset”
ManifestOne or more assertions, a single claim, and a claim signature
Assertion”A data structure which represents a statement either made (or ‘created’) by the signer or simply gathered at claim generation-time, concerning the asset”
ClaimA structure referencing a set of assertions “and the information necessary to represent the content binding”
Claim signature”The digital signature on the claim created using the private key owned by a signer”
IngredientA component asset used to compose or derive the current one, recorded through the ingredient assertion

Definitions quoted from the C2PA technical specification 2.4.

The practical shape: assertions are the facts, the claim bundles them, and the signature makes the bundle tamper-evident. Edit the file without a conforming tool and the binding breaks; edit the manifest and the signature fails. The specification defines 28 standard assertion types, including c2pa.actions (what was done to the asset), c2pa.ingredient (what it was made from), c2pa.hash.data (the content binding), c2pa.metadata, c2pa.thumbnail and c2pa.timestamp.

Hard bindings and soft bindings

The binding is how a manifest is tied to the bytes it describes, and there are two kinds. The distinction explains most of C2PA’s behaviour in the real world.

A hard binding gives certainty about an unmodified file. A soft binding gives a way to find the provenance record again after the file has been re-encoded, cropped or screenshotted. Neither alone is sufficient, which is the reasoning behind durable Content Credentials below.

How it works, end to end

  1. Capture or generation. A conforming camera, phone or AI model creates the asset and writes an initial manifest — what made it, when, and a hash binding the manifest to the content.
  2. Editing. A conforming editor opens the file, records the original as an ingredient, adds c2pa.actions assertions describing what it did, and signs a new manifest. The manifest store now holds a chain.
  3. Signing. Each manifest is signed with a certificate issued to the signer. Validators check that certificate against the C2PA Trust List.
  4. Distribution. The file travels. Whether the credential travels with it depends entirely on what handles it next.
  5. Validation. A reader checks the signature, the certificate, and whether the hash still matches the bytes, then displays the history.

Step 4 is where most of the real-world failure happens, and no amount of cryptography fixes it.

What a validator can actually tell you

People expect a credential check to return “real” or “fake”. It does not, and knowing the actual outcomes is what stops a reader over-reading the result.

OutcomeWhat it meansWhat it does not mean
Valid manifest, trusted signerThe signature checks out, the certificate traces to the C2PA Trust List, and the bytes match the hashThat the content is truthful, or that it is not AI-generated
Valid manifest, untrusted or unknown signerThe cryptography is sound but the certificate is not on the trust listThat the file is fraudulent; plenty of legitimate signers are not listed
Manifest present, binding brokenThe file has been altered since signing, or re-encoded by something non-conformingThat someone tampered maliciously; a platform re-save does this routinely
Certificate revoked or expiredThe signer’s certificate is no longer good — though many validators will not tell you this at allThat every image from that signer is fake
No manifestThere is nothing to checkAnything whatsoever

The fourth row is the one the 2026 research is most exercised about, and the fifth is the one readers most often get wrong.

What you actually see in a credential

A well-populated manifest reads less like a certificate and more like a file’s biography. The assertions typically present are:

The ingredient chain is the genuinely interesting part: it is how you can see that a published image was composed from a camera original plus a generative fill, with each step signed by whoever performed it.

How C2PA got here

DateMilestone
2019Adobe establishes the Content Authenticity Initiative
2021C2PA forms and publishes the first public draft of the specification
Feb 2024Google joins the steering committee
May 2024OpenAI joins the steering committee
Sep 2024Meta and Amazon join the steering committee; Google commits to surfacing C2PA data in Search
Mid-2025Conformance programme launches; the C2PA Trust List replaces the Interim Trust List
Aug–Sep 2025Nikon launches and then suspends Z6 III signing, revoking all certificates issued
1 Jan 2026Interim Trust List frozen to new entries
9 Feb 2026Content Credentials 2.3 released; coalition marks five years and 6,000+ members
Apr 2026Specification 2.4 published; UMBC/Hacker Factor/NSA security analysis published
Jul 2026Deployment Guidance 1.0 and a new Implementation Guide; TikTok joins the steering committee
Aug 2026CAWG identity assertion 1.3 ratified

Sources as cited throughout; timeline entries drawn from C2PA announcements.

Where the standard has reached, as of September 2026

ItemStatus
Current specificationVersion 2.4, April 2026; version 2.3 launched 9 February 2026 alongside the coalition’s five-year milestone
MembershipMore than 6,000 members and affiliates with live applications
Conformance programmeLaunched mid-2025; requires adherence to the specification, the Certificate Policy and the Security Requirements document
Trust listThe C2PA Trust List replaced the Interim Trust List in mid-2025; the ITL was frozen to new entries on 1 January 2026
Implementation guidanceContent Credentials Deployment Guidance 1.0 published 8 July 2026; a new Implementation Guide announced 31 July 2026
GovernanceTikTok elevated from General Member to the Steering Committee on 28 July 2026
Identity layerCAWG identity assertion version 1.3 ratified 17 August 2026
ISO standardisationNot published. See below

Sources: C2PA announcements, C2PA conformance, Content Credentials Deployment Guidance 1.0, CAWG identity assertion 1.3, Andy Parsons, CAI.

One nuance worth noting rather than smoothing: the specification site lists 2.4 as the current release, while the conformance programme page still frames its requirements against 2.3. Implementers should check which version a given conformance claim is made against.

The ISO position, which is widely misreported

C2PA is frequently described as “an ISO standard”. As of 30 September 2026 it is not, and the public records disagree about where exactly it sits.

The safe statement: ISO 22144 is in development and has not been published. Any page or vendor telling you Content Credentials is already an ISO standard is ahead of the record.

Where you will actually meet Content Credentials

Adoption is real but uneven, and it is strongest at the two ends — generation and capture — and weakest in the middle, where files are distributed.

LayerExamplesNotes
AI generatorsChatGPT, Codex and the OpenAI API images carry C2PA metadata plus a SynthID watermark (OpenAI)OpenAI states coverage “can vary by product, model, export path, file type”
PhonesGoogle Pixel 10 signs images with C2PA credentials (CAI)Capture-side support in a mainstream phone
CamerasSony’s PXW-Z300 ships with Content Credentials support; Nikon’s Z6 III programme is currently suspended (below)Capture-side support is early and, in one case, withdrawn
Creative softwareAdobe’s tools; Content Authenticity for EnterpriseAdobe originated the CAI in 2019
SearchGoogle surfaces C2PA metadata in “About this image” across Google Images, Lens and Circle to Search (Google)Announced 17 September 2024
AssistantsThe Gemini app checks both Content Credentials and SynthID when asked to verify a file (Google)Roughly 10 image checks per rolling 24 hours
Social platformsTikTok reads C2PA Content Credentials and writes them into content made with its own tools (TikTok)Announced 19 November 2025; 1.3 billion videos labelled to date

How to check a file’s Content Credentials

Three routes, all free, all under a minute.

  1. Ask the Gemini app. Upload the file and ask whether it was created or edited by AI. Gemini checks Content Credentials and SynthID and reports what it finds. Google caps this at roughly ten image checks per rolling 24 hours, with a 100MB file limit, advises against uploading screenshots or collages, and says Content Credentials checks run on the web and Android, with iOS to follow.
  2. Use a C2PA reader. Any conforming inspector will display the manifest chain if one survives on the file.
  3. Use the generator’s own verifier. For suspected OpenAI output, openai.com/verify checks for both the C2PA metadata and the SynthID watermark, and OpenAI offers a verification API for volume.

A separate and much cheaper check sits alongside these: open the file in any viewer that shows XMP and look for the IPTC Digital Source Type property. The recommended value for generative output is trainedAlgorithmicMedia, and C2PA has integrated digitalSourceType into its own specification (IPTC). A file that declares itself this way is a strong lead, though a declaration can be written by anyone. For the full procedure when there is no credential to read, see how to tell if an image is AI-generated.

What a Content Credential proves — and what it does not

It proves: that a specific signer, holding a specific certificate, asserted a specific set of facts about this content at a specific point, and that the bytes have not changed since. That is a real and useful thing, and it is more than any classifier can offer.

It does not prove:

How it compares with the other ways of answering the same question

Four technologies claim to tell you whether content is AI-generated or authentic. They are not interchangeable, and the differences are structural rather than a matter of quality.

ApproachWhat it isStrengthFails whenOur coverage
C2PA Content CredentialsSigned metadata attached to the fileCryptographically verifiable; records a full edit chainMetadata is stripped, a signer is compromised, or no credential was ever attachedThis page
Invisible watermarkingA statistical signal embedded in the content itselfSurvives screenshots, crops and re-encodingHeavy editing, paraphrase or translation; only covers providers that markAI watermarking
Visible labelsA badge or corner mark aimed at the viewerImmediately legible to a humanCropped, toggled off, or simply never appliedCovered in the watermarking guide
Classifier detectorsSoftware guessing from the pixels or proseWorks with no cooperation from the generatorConstantly; independent audits show serious false-positive ratesAI image detectors, AI detectors

The ranking by evidential strength runs top to bottom. A credential is a record someone signed; a watermark is a signal someone embedded; a label is a claim someone displayed; a detector score is a guess nobody vouched for. Terms used here are defined in our AI glossary.

C2PA is also explicitly not a rights-management system. The coalition states that Content Credentials “are not a form of DRM” and “record and preserve the provenance of digital media without limiting its use”. Relatedly, in January 2026 C2PA clarified that its specification contains no standard assertion for text and data mining — so a Content Credential is not a machine-readable AI-training opt-out, whatever some coverage implies.

The April 2026 security analysis

The most careful assessment of C2PA’s weaknesses comes from security researchers rather than from its critics in the press. A paper published on 23 April 2026 by Enis Golaszewski, Neal Krawetz, Alan T. Sherman, Edward Zieglar and colleagues at UMBC, Hacker Factor and the NSA examined versions 2.2 to 2.4 and documented six classes of weakness (arXiv 2604.24890).

WeaknessWhat it means
Timestamps can be altered undetectedNothing in the signed data references the timestamp
Revocation is often not checkedMany validators accept signatures made with compromised or revoked keys
Validators disagreeThe paper’s demonstration has Adobe Inspect reporting revoked certificates as valid while Verifieddit reported them invalid, on the same file
Exclusion ranges leave parts of a file unsignedModified GPS coordinates in a Pixel 10 Pro image went undetected by the Proofmode validator
Credentials expireAn Arizona Secretary of State image validated in January 2025 and failed validation a year later, which the authors note conflicts with legal retention requirements
The conformance programme is weakIt lacks security requirements and source-code review

The paper’s own demonstration includes a Nikon Z6 III used to sign AI-generated images. Which brings us to the case that makes all of this concrete.

The Nikon case: what happens when a signing key goes bad

In August 2025 Nikon launched the Nikon Authenticity Service, letting the Z6 III sign photographs with Content Credentials at capture. It is the clearest real-world test the trust model has had, and it failed.

The timeline, as reported by PetaPixel:

Three things about this deserve to be carried forward, because they are properties of the system rather than of Nikon.

First, revocation does not reliably propagate. Many validation tools do not check revocation by default, so images signed with the revoked certificates can still validate cleanly. Horshack filed a GitHub issue asking open-source validators to make revocation checking the default. This is the same finding the UMBC paper reached independently.

Second, the manufacturer cannot fix it alone. As PetaPixel puts it, there is “no way to prevent online validation tools from validating C2PA-signed images, even from cameras that have had their certification revoked”. The strength of the guarantee depends on every downstream validator, not on the issuer.

Third, the attack was not against the cryptography. The signature worked perfectly. The camera was persuaded to sign the wrong thing. That is the general shape of the risk: a conforming signer that can be tricked produces a genuinely valid credential for false content.

Durable Content Credentials: the answer to stripping

The single most common complaint about C2PA is that metadata gets removed — by a screenshot, a re-save, a format conversion, or a platform re-encoding an upload. OpenAI states this plainly about its own files: Content Credentials “can sometimes be removed by platforms, editing tools, or file conversions”.

The CAI’s answer is durable Content Credentials, which combine three technologies rather than relying on metadata alone (Andy Parsons, CAI, 8 April 2024):

  1. Secure metadata — the signed manifest, which “cannot be altered without leaving evidence of alteration”.
  2. Watermarking — a hidden signal that survives cropping, rotation and screenshotting.
  3. Fingerprinting — a numerical descriptor derived from the pixels or waveform, allowing a match against a stored record even after modification.

Each is individually weak. Metadata can be stripped, watermarks can be degraded or spoofed, fingerprint matches are probabilistic. Together, as the CAI argues, “the three form a unified solution that is robust and secure enough to ensure that reliable provenance information is available no matter where a piece of content goes”. When the metadata is gone, the watermark recovers an identifier pointing at the stored credential and the fingerprint confirms the match.

This is also why the hard-binding and soft-binding distinction in the specification matters: soft bindings are the hook that makes recovery possible.

C2PA and the law

EU AI Act Article 50 became enforceable on 2 August 2026. It requires providers of systems generating synthetic text, audio, images or video to ensure outputs are marked in a machine-readable, detectable format wherever technically feasible, with an additional disclosure duty for deepfakes.

The law is deliberately technology-neutral. It does not mandate C2PA, or SynthID, or any named scheme — which is why the industry response is a mix of signed metadata, statistical watermarks and visible labels. C2PA is one compliant answer among several, and the most auditable of them, but adopting it is a choice rather than a legal requirement.

Should you turn Content Credentials on?

If you are a photographer or journalist: yes, where your camera or phone supports it, and keep the original files. A credential is worth most on work whose authenticity may later be questioned. Do not present it as proof — present it as a record.

If you publish AI-generated images: yes, and leave the credential intact on export. The disclosure is the point, and Article 50 is now enforceable in the EU.

If you are building a product that validates credentials: check revocation by default. That single decision addresses a weakness raised by both the UMBC paper and the Nikon incident, and many validators currently skip it.

If you are deciding whether something is real: treat a valid credential as strong evidence about origin, verify it in more than one validator if anything turns on it, and treat a missing credential as no evidence at all. For the wider procedure, including what to do when there is no credential to read, see how to tell if an image is AI-generated; for the detection tools themselves, see best AI image detectors. For faces and video specifically, see best deepfake detectors.

Five things people get wrong about C2PA

These recur often enough to be worth stating flatly.

  1. “No Content Credential means it is AI.” It means nothing. The overwhelming majority of images online have never carried one.
  2. “A Content Credential means it is a real photograph.” AI image generators are conforming signers. A valid credential from one records that a model made the file.
  3. “C2PA is an ISO standard.” ISO 22144 is in development and unpublished as of 30 September 2026.
  4. “C2PA stops my work being used for AI training.” The specification has no standard text-and-data-mining assertion, as the coalition itself clarified in January 2026.
  5. “The signature is unbreakable, so the credential is trustworthy.” The Nikon case broke nothing cryptographic. The camera was persuaded to sign an AI-generated image, and the resulting credential was mathematically perfect and completely false.

Frequently asked questions

What is C2PA?

C2PA is the Coalition for Content Provenance and Authenticity, and the open technical standard it publishes for recording where digital content came from and how it has been edited. The standard defines a cryptographically signed data structure, branded Content Credentials, that travels with a file and records the device or software that created it, the edits applied, and optionally the creator’s identity. It is governed as a Joint Development Foundation project affiliated with the Linux Foundation, and its steering committee includes Adobe, Amazon, the BBC, Google, Meta, Microsoft, OpenAI, Publicis Groupe, Sony, TikTok and Truepic. The current specification is version 2.4, published April 2026.

What are Content Credentials?

Content Credentials are the signed provenance record that a C2PA implementation attaches to a file, and the consumer-facing name for the standard as of its 2.x series. Technically, a credential is a manifest containing one or more assertions (the facts about the asset), a claim that bundles them, and a claim signature made with the signer’s private key. Assertions can record what tool made the file, what actions were performed on it, what source assets it was composed from, and a hash binding the manifest to the actual bytes. Alter the file or the manifest and the signature no longer validates, which is what makes the record tamper-evident.

Is C2PA an ISO standard?

Not yet, despite frequent claims otherwise. As of 30 September 2026 the ISO catalogue lists ISO/CD 22144, “Authenticity of information — Content credentials”, at stage 30.99 under committee ISO/TC 171/SC 2, with the project approved in October 2024 and no publication date. ANSI lists a 2025 draft international standard, and ASIS&T reported in March 2025 that the fast-tracked DIS drew a “No” vote with comments. The records disagree on the detail but agree on the substance: it is in development and has not been published.

Does a Content Credential prove an image is real?

No. It proves that a specific signer asserted specific facts about the file and that the bytes have not changed since. It cannot tell you whether what the camera was pointed at was staged, and it cannot tell you the content is not AI-generated — an AI image generator can be a conforming signer, and a valid credential from one simply records that a model made the file. The 23 April 2026 security analysis by researchers at UMBC, Hacker Factor and the NSA concluded that C2PA “should not yet be relied upon for high-stakes uses”. Treat a valid credential as strong evidence about origin, not as a verdict on truth.

Why do Content Credentials disappear from images?

Because the credential is metadata attached to the file, and a great deal of ordinary handling discards metadata. A screenshot creates a new file with no manifest. Re-saving in another application, converting formats, or uploading to a platform that re-encodes images can all strip it. OpenAI states this about its own output, noting that Content Credentials “can sometimes be removed by platforms, editing tools, or file conversions”. This is why the absence of a credential proves nothing, and why the CAI is pushing durable Content Credentials, which pair the metadata with a watermark and a fingerprint so the record can be recovered after stripping.

What is the difference between C2PA and a watermark?

They solve the same problem from opposite directions and are increasingly used together. A C2PA Content Credential is signed metadata attached to the file: rich, precise, cryptographically verifiable, and easy to remove. A watermark is an imperceptible signal embedded in the content itself: carries far less information, cannot be read without the right detector, but survives cropping, re-encoding and screenshotting. In C2PA’s own vocabulary a hash-based credential is a hard binding and a watermark or fingerprint is a soft binding. Our guide to AI watermarking covers the watermark side in depth.

How do I check if an image has Content Credentials?

Three free routes. Upload the file to the Gemini app and ask whether it was created or edited by AI — Gemini checks both Content Credentials and Google’s SynthID watermark, with a limit of roughly ten image checks per rolling 24 hours. Open the file in any C2PA reader, which will display the manifest chain if one survives. Or, for suspected OpenAI output, use openai.com/verify, which checks for the C2PA metadata and the SynthID watermark that OpenAI embeds in images from ChatGPT, Codex and its API. Google also surfaces C2PA metadata in the “About this image” panel across Google Images, Lens and Circle to Search.

Which cameras and phones support Content Credentials?

Support is early and uneven. The Google Pixel 10 signs images with C2PA credentials, and Sony shipped the PXW-Z300 video camera with Content Credentials support. Nikon launched an Authenticity Service for the Z6 III on 27 August 2025 but suspended it on 4 September 2025 after a vulnerability was found, and revoked every certificate issued in that window. Because capture-side support changes quickly and at least one programme has been withdrawn, check the manufacturer’s own current documentation rather than a third-party list.

What happened with the Nikon C2PA vulnerability?

Researcher Adam Horshack found that the Nikon Z6 III’s multiple-exposure mode could be used to make the camera sign fraudulent images, and demonstrated it by getting a wholly AI-generated image validated as an authentic Nikon capture. Nikon suspended the Authenticity Service on 4 September 2025, a week after launch, and invalidated all certificates issued in that period, stating that the credentials on those images “are no longer valid and cannot be used as proof of provenance”. Two structural lessons outlast the incident: many validators do not check certificate revocation by default, so the revoked signatures can still validate; and the attack defeated the camera rather than the cryptography, which is the general shape of the risk.

Does C2PA let me opt out of AI training?

No. In January 2026 C2PA clarified that its technical specification contains no standard assertion for text and data mining, so a Content Credential is not a machine-readable training opt-out. The coalition is also explicit that Content Credentials “are not a form of DRM” and are designed to “record and preserve the provenance of digital media without limiting its use”. Any tool marketing C2PA as a way to block AI training is overstating what the standard does.

Is C2PA required by law?

Not specifically. EU AI Act Article 50 became enforceable on 2 August 2026 and requires providers of generative AI systems to mark synthetic output in a machine-readable, detectable format wherever technically feasible, with extra disclosure duties for deepfakes. The law is technology-neutral: it does not name C2PA, SynthID or any other scheme. C2PA is one of the most auditable ways to comply, but it is a choice, not a mandate, and there is no equivalent United States federal requirement.

Does C2PA identify who took a photo?

Not by default, and this is deliberate. C2PA states that the core specification “does not support attribution of content to individuals or organizations, so that it can remain maximally privacy-preserving”. Named attribution is an optional layer: the Creator Assertions Working Group, hosted at the Decentralized Identity Foundation, maintains an identity assertion — version 1.3 was ratified on 17 August 2026 — that lets a creator cryptographically bind a verified identity and a role such as creator, editor or publisher to specific assertions in a manifest. A creator has to opt into that; it is not part of the base credential.

What is the C2PA Trust List?

The Trust List is the register of certificate authorities whose signing certificates conforming validators should accept, and it is what turns a mathematically valid signature into a meaningful one. The official C2PA Trust List replaced the earlier Interim Trust List in mid-2025, bringing higher security and interoperability requirements aligned to the 2.x specification series; the Interim Trust List was frozen to new entries on 1 January 2026. Getting listed runs through the C2PA conformance programme, which requires adherence to the specification, the Certificate Policy and the Security Requirements document. The April 2026 security analysis criticised that programme for lacking security requirements and source-code review.

← All guides