C2PA Explained: What It Is, and What It Doesn't Prove

How C2PA's Content Credentials work, what a manifest can and can't tell you, and why a valid mark doesn't by itself satisfy your disclosure duty.

Last updated 2026-09-12.

What C2PA actually is

C2PA (the Coalition for Content Provenance and Authenticity) is a technical standard — backed by Adobe, Microsoft, Intel, Google, OpenAI, and others — for attaching a signed, tamper-evident record to a piece of media: a "manifest" embedded in the file that can record how it was created or edited, by what tool, and by whom. When you hear "Content Credentials," that's C2PA's consumer-facing name for the same thing.

It's a voluntary industry standard, not an EU AI Act requirement by name — the Act requires machine-readable marking (Article 50(2)) without mandating a specific technology, and C2PA happens to be the most widely adopted way providers currently choose to meet that.

What a manifest can tell you

When present and cryptographically valid, a C2PA manifest can show a chain of "assertions" — claims about the file's history: which tool created it, what edits were made, and whether the signature still matches the file's current bytes (confirming it hasn't been altered since signing).

What a missing manifest does NOT tell you

This is the part people get backwards most often: the absence of a C2PA manifest does not prove content is AI-generated, and its presence does not prove it isn't. Many real cameras and platforms never embed one in the first place. Many social platforms and messaging apps strip metadata on upload as a matter of routine, C2PA manifests included. A photo with no manifest could be a real, unedited photograph from a camera that simply doesn't support the standard — or it could be an AI image run through a tool that doesn't sign its outputs, or one that had its manifest deliberately or accidentally stripped.

This is exactly why signator.ai treats provenance, detection, and disclosure as three separate findings, never blended into one score — a missing manifest is one data point, not a verdict.

Why a valid manifest still doesn't satisfy your disclosure duty

Even a fully valid C2PA manifest, correctly signed by the provider, doesn't satisfy a deployer's Article 50(4) disclosure duty if the content is a deepfake. The provider's machine-readable mark (Art. 50(2)) and the deployer's clear, perceivable disclosure to viewers (Art. 50(4)) are separate obligations on separate parties — see our provider vs. deployer guide. A manifest sitting in a file's metadata, invisible to an ordinary viewer, doesn't meet the "clearly and perceivably, at first exposure" bar the deployer's duty requires.

How signator.ai uses C2PA

Our provenance check reads any C2PA manifest present and reports exactly what it finds — or honestly reports that none was found — as one of three independent findings alongside AI detection and the disclosure assessment. Run a check to see all three side by side for a specific image.

This guide is informational, not legal advice — see our Terms. Want to check a specific image? Try signator.ai.