// GLOSSARY · C2PA

C2PA

The open standard behind Content Credentials — a signed, tamper-evident record of a file's origin and edit history, embedded in its metadata.

Last verified · 2026-10-04 · by Moe Ameen

What it is

C2PA stands for the Coalition for Content Provenance and Authenticity, the cross-industry standards body — and, by extension, the open technical specification it publishes. That specification defines Content Credentials: a cryptographically signed record, called a manifest, that travels inside a media file and states verifiable facts about where the file came from and what has been done to it. Each fact in the manifest is an "assertion" — the device or software that created the file, the generative model that produced it, the edits applied, a timestamp — and the whole bundle is signed with an X.509 certificate so that any tamper with the pixels or the claims breaks the signature. The practical pitch is simple: instead of guessing whether an image is real or AI-made by squinting at it, you read a signed receipt attached to it.

Mechanically, C2PA combines standard cryptographic hashes (SHA-256) with a signed manifest stored in a metadata block embedded in the file — JUMBF for JPEGs and most formats. This is the "hard binding": the credential is physically carried by the file. Because metadata is easy to strip, the spec also defines "soft bindings" — a perceptual fingerprint or invisible watermark that lets a stripped file be matched back to its credential in a cloud registry. The combination is marketed as "Durable Content Credentials," because the hard binding alone does not survive the places content actually travels. C2PA is deliberately not a watermark and not an AI detector: it certifies that a signed claim has not been altered since signing, not that the claim is true, and not whether the content is AI-generated unless an assertion says so.

That last distinction is the one most coverage flattens. A C2PA signature proves integrity and attribution — "this manifest was signed by this key and hasn't changed" — but it says nothing about whether the assertions are honest. A manifest claiming human authorship can be cryptographically valid over pixels a model generated; the signature only vouches that the claim came from a particular signer and survived intact. Provenance is a chain of custody, not a truth oracle, and C2PA is best understood as the first link that makes the chain readable rather than as a verdict on reality.

The history

The coalition formed in February 2021 to merge two parallel efforts: Adobe's Content Authenticity Initiative (CAI), launched in 2019, and Project Origin, a news-provenance initiative from Microsoft and the BBC. The founding members were Adobe, Arm, BBC, Intel, Microsoft, and Truepic. The first version of the Content Credentials specification shipped on January 26, 2022, and the spec has iterated steadily since — reaching version 2.4 in April 2026 — while being fast-tracked toward recognition as an ISO standard (ISO 22144). By 2026 the steering committee had grown to include Amazon, Google, Meta, OpenAI, Sony, Publicis Groupe, and TikTok alongside the founders.

What pushed C2PA from a working group into a creator-facing reality was a tight run of 2026 adoption and a regulatory deadline. On the hardware side, cameras from Leica, Sony, Nikon, and Canon shipped C2PA signing (Fujifilm and Panasonic have joined the coalition but had not shipped firmware support as of late 2026), and Google's Pixel 10 began embedding Content Credentials in photos by default. On the platform side, TikTok joined the steering committee in July 2026 — alongside longer-standing members Meta, Google, Amazon, OpenAI, Sony, and Publicis Groupe — and LinkedIn began showing a clickable "CR" provenance icon on credentialed images. The regulatory accelerant was the EU AI Act's Article 50, whose transparency rules took effect August 2, 2026, requiring synthetic media to be marked in a machine-readable, detectable format — a requirement C2PA is positioned to satisfy. In the same period, security researchers probed the standard's edges: David Buchanan's work showed that the specification's "exclusions" feature — which lets byte ranges be omitted from the signed hash — could be weaponized to exclude an entire file from coverage while keeping a valid signature and a real trusted timestamp, and that common verifiers did not flag it. Provenance moved into public view and under public scrutiny at the same time.

How it behaves across platforms

PlatformBehavior
Google (Gemini, Pixel, SynthID)The most complete stack. Gemini output and Pixel 10 camera photos embed C2PA credentials, paired with the invisible SynthID watermark as a soft binding so provenance can be recovered even after metadata is stripped. This visible-optional, machine-readable-mandatory pairing is the template other vendors are converging on.
Adobe (Photoshop, Firefly)The originator via the Content Authenticity Initiative. Firefly generations and Photoshop edits can attach and extend Content Credentials, recording the edit chain assertion by assertion. Adobe also runs the public Content Credentials Verify tool that reads a manifest back from a file or image.
TikTok, Meta, LinkedInThe consumption layer. These platforms read C2PA on upload to apply their own AI labels, and LinkedIn surfaces a clickable CR icon. But most social pipelines strip the metadata block on upload or transcode — so a credential often does not survive the trip, which is why soft bindings and cloud registries exist.
Cameras (Leica, Sony, Nikon, Canon)Capture-time signing. Leica's SL3-S was an early mover, and Sony, Nikon, and Canon followed with C2PA-capable bodies via firmware; Fujifilm and Panasonic are coalition members but had not shipped signing firmware as of late 2026. The signature is applied in the device at the moment of capture, anchoring the "this is a real photograph" end of the provenance chain for photojournalism and stock.
EU AI Act (Article 50)Not a tool but the legal driver. From August 2, 2026, providers of generative systems must mark synthetic audio, image, video, and text in a machine-readable, detectable format, and deployers must disclose deepfakes. C2PA is one of the standards that can satisfy the machine-readable requirement, which is accelerating its adoption.

Concrete examples

  • A press photographer shoots on a C2PA-capable Leica, and the camera signs each frame at capture. A wire editor later reads the Content Credentials to confirm the image is an unedited photograph from that device before running it — provenance used to authenticate, not to flag AI.
  • A designer generates an image in Adobe Firefly, retouches it in Photoshop, and exports it. The C2PA manifest now carries an edit chain: "generated by Firefly," then "edited in Photoshop," each assertion signed. Anyone with the Content Credentials Verify tool can read that history from the file.
  • A creator posts a Pixel 10 photo to a social platform. The platform strips the metadata on upload, so the hard-bound credential is gone — but because Google pairs C2PA with the SynthID soft binding, a detector can still match the stripped file back to its registered provenance. The example of why soft bindings exist.
  • A brand runs an AI-assisted blog, carousel, and persona video through Kompozy in one week. Each generator writes its own provenance differently and each destination platform reads it differently, so the brand turns on the TikTok and YouTube AI-generated-content disclosure toggle in Settings → Publishing rather than trusting any single credential to carry through intact.

Common mistakes

  • Treating a valid C2PA signature as proof the content is real or human-made. The signature proves the manifest was signed by a particular key and has not changed — it does not vouch that the assertions are true. A cryptographically valid manifest can still claim human authorship over AI-generated pixels.
  • Assuming Content Credentials survive social media. Most platforms strip the metadata block on upload or transcode, so a hard-bound credential frequently does not make it through the exact distribution channels where provenance matters most. Without a soft binding to recover it, the receipt is gone.
  • Confusing C2PA with a watermark. C2PA is signed metadata attached to a file (a hard binding); a watermark like SynthID is embedded in the pixels or waveform. They are complementary layers, not the same mechanism — C2PA is the record, the watermark is the recovery path when the record is stripped.
  • Confusing C2PA with an AI detector. A detector guesses whether content is AI-made from statistical cues and can false-positive. C2PA reads a claim the creating tool deliberately signed. Only the latter is close to decisive, and only when a credential is actually present and intact.
  • Believing the absence of a credential means the content is suspect. Credentials are still unevenly applied and easily stripped, so most honest content has none. A missing credential is the default, not a red flag.

The honest take

C2PA is the most important standard in content provenance and also the one most people misunderstand, because the word "authenticity" in the name promises more than the cryptography delivers. The signature is a seal on a claim, not a judgment on reality — it tells you a specific signer made a specific statement and nothing has been altered since, which is genuinely useful and genuinely narrow. The failure mode I watch creators and editors fall into is treating a green checkmark as "this is real," when all it ever meant was "this claim is intact." The 2026 security probes drove the point home: a file can carry a valid signature and a real trusted timestamp and still have had its entire contents excluded from the hash. Provenance is a chain of custody you read, not a verdict you trust blindly.

For a working creator the honest takeaway is that C2PA is becoming infrastructure you will be judged against, not a feature you have to master. Platforms are starting to read it to apply AI labels, cameras and generators are starting to write it, and the EU AI Act is making the machine-readable version a legal expectation. [Kompozy](/) sits on the publishing side of that reality: it generates across text, image, and video — each landing in its own provenance regime — and gives you a per-platform AI-generated-content disclosure toggle (TikTok, YouTube) in Settings → Publishing, so you comply with each platform's own disclosure rules instead of depending on a fragile metadata block to survive the upload. The durable lesson outlasts any single standard: disclose at publish, let the work stand on its quality, and treat provenance as a receipt you attach, not a reputation you outsource.

Frequently asked questions

What is C2PA?

C2PA is the Coalition for Content Provenance and Authenticity — a cross-industry standards body — and the open technical specification it publishes. That spec defines Content Credentials: a cryptographically signed manifest embedded in a media file that records verifiable facts about the file's origin and edit history, so the content's provenance can be checked rather than guessed.

What is the difference between C2PA and Content Credentials?

C2PA is the standard and the organization; Content Credentials is the consumer-facing name for what the standard produces — the signed provenance record attached to a file. In practice the terms are used almost interchangeably, but strictly, C2PA is the specification and Content Credentials is the manifest it defines.

Does C2PA prove content is real or not AI-generated?

No. A valid C2PA signature proves that the manifest was signed by a specific key and has not been altered since — integrity and attribution, not truth. The assertions inside the manifest state what was done to the file, and one of them may say it was AI-generated, but the cryptography itself does not certify whether any claim is honest or whether the content is real.

Do C2PA Content Credentials survive social media uploads?

Often not. The credential is carried in a metadata block that many platforms and CDNs strip or overwrite on upload and transcoding, so the hard-bound record frequently does not make it through. The standard addresses this with "soft bindings" — a fingerprint or invisible watermark that lets a stripped file be matched back to its provenance in a cloud registry.

Who uses C2PA in 2026?

Adoption is broad. Cameras from Leica, Sony, Nikon, and Canon sign at capture (Fujifilm and Panasonic have joined the coalition but had not shipped signing firmware); Google Pixel 10 embeds credentials by default; generators like Adobe Firefly and Google Gemini write them; and platforms including TikTok, Meta, and LinkedIn read them to apply AI labels. The steering committee includes Adobe, Amazon, Google, Meta, Microsoft, OpenAI, Sony, and TikTok.

Is C2PA the same as a watermark?

No. C2PA is signed metadata attached to the file — a record you read back. A watermark like SynthID is a signal embedded in the pixels, frames, or waveform that survives editing. They are complementary: C2PA is the provenance record, and the watermark is often the recovery path that lets provenance be re-found after the metadata is stripped.

Related terms

  • AI content watermark — An umbrella term for any signal that marks content as AI-generated: a visible badge, an invisible SynthID mark, a C2PA metadata record, or a text watermark.
  • Visible AI watermark — An on-file badge — like Gemini's corner sparkle or a 'Made with AI' label — that shows a viewer content is AI-generated, unlike an invisible SynthID mark.
  • AI text watermarking — A hidden statistical signal embedded in an AI model’s word choices as it writes, letting a detector later confirm the text was machine-generated.
  • Likeness detection — Platform technology that scans uploads for a specific enrolled person’s face or voice and flags AI-generated content using their identity, so they can review it or request removal.
  • AI slop — Low-quality, generic media mass-produced by generative AI with little human oversight, and now the content audiences and platforms increasingly reject.
Related deep guides

← All terms · Get started →