Detection asks a statistical question: does this file look generated? Provenance asks a cryptographic one: what does this file's own signed history say about where it came from? The second question, when it can be answered, is far stronger — and C2PA is the standard that answers it.
What C2PA actually is
C2PA is a specification from the Coalition for Content Provenance and Authenticity, the group behind the Content Credentials label you now see on some images. It defines a manifest: a small, cryptographically signed record embedded in the file describing how that file came to exist.
A manifest typically contains:
- Assertions — claims about the file: captured on this camera model at this time, or generated by this tool from this prompt, or edited with these operations.
- Ingredients — references to the files this one was made from, so a chain can be walked backwards through each edit.
- A hash of the content — binding the claims to these exact pixels.
- A signature from a certificate belonging to the camera maker, software vendor or publisher.
Because the manifest hashes the content and is signed, you cannot alter the image and keep a valid manifest, and you cannot forge a manifest without the signer's private key. Change one pixel and validation fails.
What it proves — and what it does not
A valid manifest proves that a specific signer asserted a specific history for these exact bytes. That is genuinely powerful and it is also narrower than most people assume.
- It does not prove the claim is true. It proves who made the claim. Trust flows from the signer's identity, exactly as with a TLS certificate.
- It does not prove a photo is real. A camera with C2PA support can be pointed at a screen displaying a generated image. The manifest will honestly record a genuine capture of a fake scene.
- Absence proves nothing at all. This is the big one. Most files in the world have never carried a manifest, and most platforms strip metadata on upload. A screenshot removes it instantly.
That last point is why provenance can never replace detection. In practice you will check a hundred files and find a manifest on a handful. For the rest you need forensic analysis — see how to spot AI-generated images.
Who writes Content Credentials today
Adoption is real but patchy. Some professional cameras sign at capture. Adobe's tools write and preserve credentials through an edit. Several major generative tools attach a manifest declaring that the output is synthetic — which is arguably the most useful application of the standard, because it labels the thing people most want labelled. A number of platforms display the Content Credentials icon when one survives upload.
The gaps are equally real: most phone cameras, most messaging apps and most social uploads either never write a manifest or strip it on re-encode.
Watermarks are a different thing
Invisible watermarking embeds a signal in the pixels themselves rather than in the metadata, so it survives screenshots and re-encoding far better. The trade-off is that it carries much less information — typically just "this came from us" — and it degrades under heavy crops and edits. Watermarks and manifests answer different halves of the question, which is why a serious check looks for both.
How to read a provenance result properly
- Is a manifest present? Usually no. Move on to forensics without drawing a conclusion.
- Does it validate? A present-but-invalid manifest is a strong signal the file was altered after signing — far more interesting than no manifest at all.
- Who signed it, and do you trust them? A manifest signed by an unknown certificate is a claim from a stranger.
- Does the claim match the file? A manifest saying "captured on camera" alongside EXIF written by a desktop editor and a generator string in the bytes is the most informative outcome you can get.
- What do the other layers say? Provenance is one of four; it does not outvote the rest when it merely reports absence.
Making your own provenance when the file has none
You cannot retroactively prove where someone else's file came from. What you can do is prove everything that happened after it reached you — and in insurance, legal and marketplace disputes that is usually the contested part.
That means: hash the file with SHA-256 the instant it arrives, store the original untouched, write every subsequent action to an append-only log that no one can edit or delete, and export a certificate carrying the hash so any third party can confirm the file they hold is the file you examined.
Stronger still is to control the capture. A one-time link that opens the device camera directly, hashes the result before it leaves the phone and records the capture context removes the window in which a file could be swapped for another.
You can inspect any file's credentials below, or open the C2PA verifier.