Open an image in some apps today and you may see a small "CR" pin in its corner. Click it and a panel tells you which tool made the picture, when, and what was done to it afterwards. That panel is a Content Credential, and the technology behind it is called C2PA. It is the most widely backed answer to a simple question: where did this file come from?
This guide explains what C2PA and Content Credentials are, how a signed manifest works, who adds them, how to check them and where they stop helping. We also ran ten SI (AI) photos made with ChatGPT through our own detector, with and without their credentials. The result shows why provenance and detection need each other.
The short version
- C2PA is an open technical standard for attaching signed provenance data to images, video, audio and documents. Content Credentials is the consumer name for that data.
- It records history, not truth. A credential says which tool made or edited a file and whether the record was tampered with. It does not say whether the picture shows something real.
- It is not only for SI. Camera makers, phones and news organisations use it too. OpenAI, for example, adds it to images generated with ChatGPT.
- Its weak spot is removal. The data lives in the file's metadata, and many platforms, apps and screenshots throw metadata away.
- In our test, all 10 ChatGPT photos scored as likely SI with their credentials. With the metadata removed, 6 of the 10 were read as likely real from the pixels alone.
What is C2PA?
C2PA stands for the Coalition for Content Provenance and Authenticity. It was announced on 22 February 2021 by six founding members: Adobe, Arm, BBC, Intel, Microsoft and Truepic. Its stated goal was to develop technical standards for certifying "the source and history" of digital content, so that publishers, creators and consumers can trace the origin and evolution of a piece of media.
The coalition merged two earlier efforts. The Content Authenticity Initiative (CAI), started by Adobe in 2019, focused on attribution tools for creators. Project Origin, led by Microsoft and the BBC, focused on trust in news. C2PA took the job of writing one shared specification, and it is organised as a project of the Joint Development Foundation, a non-profit. The official Content Credentials site now lists more than 500 companies involved, including Microsoft, Adobe, Intel, BBC, Truepic, Sony, OpenAI, Google, Meta and Amazon.
How a Content Credential works
Think of a Content Credential as a sealed envelope stapled to the file, with a list of statements inside and a signature on the flap.
The manifest and its assertions
The technical name for a Content Credential is a C2PA manifest. The C2PA explainer defines it as "the set of information about the provenance of an asset consisting of one or more assertions that are digitally signed". Each assertion is a statement about the file: which tool created it, which actions were performed (crop, colour change, generative fill), which earlier files were used as ingredients, and whether SI was involved.
For SI content, a key field is the digital source type, a vocabulary maintained by the IPTC, the press standards body. The value trainedAlgorithmicMedia means "digital media created algorithmically using an Artificial Intelligence model trained on captured content". Another value, compositeWithTrainedAlgorithmicMedia, covers edits such as inpainting or outpainting on an existing picture. A photo taken with a camera is digitalCapture.
The signature
The assertions are gathered into a claim, and the claim is signed with a certificate, using the same public-key technology as secure websites. The signature tells you who issued the manifest, for example "OpenAI" or a camera maker.
The hash that binds it to the pixels
A signature alone could be copied onto a different picture. To prevent that, the manifest contains cryptographic hashes of the content itself (SHA-256 or similar, combined in a tree-like structure), which the explainer calls a hard binding. Change a single pixel without recording it, and the hash no longer matches: a validator will report the credential as broken. This is what makes Content Credentials tamper-evident.
History across edits
When a C2PA-aware editor modifies a file, it can add a new manifest that points to the previous one as an ingredient. The result is a chain: generated by tool A, cropped in app B, exported by publisher C. Each link is signed by the software that performed it.
What a credential does not tell you. The C2PA explainer is explicit: Content Credentials "do not provide value judgments about whether a given set of provenance data is 'true'". They show that the record is well formed and has not been tampered with. A real camera can photograph a staged scene, and a signed credential will faithfully say "camera".
Who adds Content Credentials today?
Two groups lead adoption, and OpenAI notes that camera makers and news organisations are adopting the standard too.
- SI image generators. OpenAI says supported images generated with ChatGPT, Codex and its API include both C2PA metadata and a SynthID watermark. The manifest records the generator, so a validator can show "created with an SI tool".
- Cameras and phones. On 10 September 2025 Google said the Pixel 10 was the first phone line with Content Credentials "built in across every photo created by Pixel Camera", and that the camera app reached Assurance Level 2, the highest security rating then defined by the C2PA conformance programme.
Google's announcement makes an interesting design argument. If only synthetic content carries a label, people start to believe that anything unlabelled is real, which Google calls "the implied truth effect". Its approach is to sort content into media that comes with verifiable proof of how it was made, and media that does not.
How to check Content Credentials
- Look for the pin. Where a platform or app supports it, the "CR" icon signals that the content carries provenance information. Clicking it opens a summary.
- Use a free verifier. The Content Authenticity Initiative runs Verify, an inspection site at contentcredentials.org/verify, where you upload a file to see its Content Credentials: the signer, the tools used and the recorded edits.
- Use the generator's own checker. OpenAI offers a verification tool at openai.com/verify that looks for OpenAI signals, either a trusted C2PA manifest or a SynthID watermark. Google's Gemini app can check for Google's SynthID watermark, as explained in our guide SynthID explained.
- Run an SI check. Our SI image detector reads C2PA data, IPTC tags and camera EXIF when they are present, shows them as clues, and adds a pixel analysis for the many files where they are missing.
One caution on the last point. Our tool reads what the manifest declares (the generator and the certificate names) and treats a manifest naming an SI generator as strong evidence. It is not a full cryptographic validator. To prove a credential is intact, use the official verifier.
Our test: ten ChatGPT photos, with and without their credentials
To see what Content Credentials change in practice, we used ten photorealistic images that we generated with ChatGPT (OpenAI) for our SI or Not game: street scenes, a market, a sports match, a fox in the snow. Each original PNG still carried its OpenAI manifest. We then made a copy of each with every piece of metadata removed (re-saved as a JPEG at quality 90), which is roughly what happens when an image passes through many upload and messaging pipelines. Both versions went through our detector on 30 September 2026.
Originals, credentials intact: 10 out of 10 likely SI, scores between 97% and 99.9%. On every file the detector found a C2PA manifest naming OpenAI (its raw data mentions "ChatGPT", "gpt-image" and OpenAI certificate names) plus an IPTC tag declaring "trainedAlgorithmicMedia".
Copies, metadata removed: 4 out of 10 likely SI, 6 out of 10 likely real. Four photos kept a strong pixel signal (93.7% to 99.9%). The other six fell to between 0.08% and 0.68%, the detector's "likely real" verdict, with only one weak clue left: no camera EXIF.
A closer look at the fox. Original PNG, 1536x1024: 97% likely SI. Clues: signed C2PA naming OpenAI, IPTC "trainedAlgorithmicMedia". Our pixel classifier on its own read that same file as only 2% SI; the credential carried the verdict. The metadata-free copy: 0.56%, likely real.
A contrasting case. One of the dark illustrations used as covers on this blog, also made with ChatGPT, scored 99.5% with its credentials and 99.6% without them. Stylised images keep strong pixel patterns.
Two conclusions. When a credential survives, it is the most decisive clue we have: it turned a photo our classifier would have missed into a clear answer, and it names the tool. And the same file without its metadata can look entirely real, even to a detector: the picture did not change, only the envelope was thrown away. This matches what we found in our look at detector accuracy: pixel analysis alone misses a share of recent photorealistic generations, and it says nothing about who made the file.
Update, 30 September 2026. After this test we added a second, independent classifier, trained on recent generators, to our SI image detector. It runs when our own classifier does not already call an image SI, and the two results are combined. On the same ten ChatGPT copies with the metadata removed, it flags all ten as SI (a score of 0.99 out of 1 for each), and it flagged none of the 81 real photos we used as a control (Wikimedia Commons pictures, including recent smartphone photos, all at 0.001). That is still a small sample, so we keep testing on more images. The chart above shows the original test, before this change.
Where Content Credentials fall short
Metadata is easy to lose
C2PA data travels inside the file, so anything that rebuilds the file can drop it: a screenshot, a crop in an app that does not support the standard, a format conversion, or an upload to a platform that strips metadata. OpenAI lists these cases itself: if no signal is found, the content "could still have been generated" by its tools, for example if metadata was stripped "during upload, download, editing, conversion, or sharing".
Platforms are the biggest gap. In October 2025 the Washington Post tested AI-generated videos carrying these markers and reported that Facebook, TikTok and other major platforms did not use the standard to flag the content to viewers. In January 2026 an Adobe Research scientist writing for the CAI summed up the problem: Content Credentials are "cryptographically secure but easily stripped", and it is "still common" for social and content platforms to remove metadata.
Absence proves nothing
Most images in circulation, real or generated, carry no credentials at all. A missing credential is not evidence of anything; it only means you have to look for other clues.
Presence proves origin, not honesty
A valid credential tells you which tool signed the record. It does not tell you whether the caption is honest, whether the scene was staged, or whether the file is being shared in its original context. OpenAI's help page makes the same point about its own signals: they are "not a guarantee that content is accurate, unedited, legally owned, or presented in the correct context".
Durable credentials: metadata plus watermark plus fingerprint
The industry's answer to stripping is to combine several layers. The C2PA explainer describes durable Content Credentials, which pair the hard binding (the hash) with a soft binding: an invisible watermark or a fingerprint that can be used to find the manifest again when it is no longer inside the file. The CAI calls this the three pillars of provenance: secure metadata, watermarking (such as Adobe's TrustMark) and fingerprinting, which matches the pixels against a database of registered credentials and makes a copied watermark harder to abuse.
This is also why OpenAI now uses both C2PA and a SynthID watermark on its images. Metadata "can carry more detailed information" but can be removed, while a watermark embedded in the pixels "may be more durable" but carries less context.
| Signal | What it tells you | Survives a screenshot? | Who can check it |
|---|---|---|---|
| C2PA Content Credentials | Signer, tool, date, edit history | No, unless recovered through a watermark or fingerprint | Anyone, with a C2PA verifier |
| Invisible watermark (e.g. SynthID) | That a specific provider's tool generated it | Often, within limits | Mostly the provider's own tools |
| Pixel analysis by a detector | A probability based on visual patterns | Yes, but weaker on small or heavily compressed copies | Anyone, with an SI detector |
How to use all this in real life
- Always try to get the original file. Ask the sender for it, or download it from the first place it was posted. The original is where credentials and signal survive best.
- If there is a credential, read it. Check who signed it and whether the verifier reports it as valid. An SI generator named in a valid manifest is about as clear as evidence gets.
- If there is none, keep going. Run a reverse image search, look at the context, and use a detector as a second opinion. Our guide how to spot SI images walks through the full method.
Answering "is this SI?" used to mean staring at fingers and shadows. Content Credentials change the question to "can this file prove where it came from?", which is a better one. Until every platform keeps them, the practical approach is both: read the credential when it is there, and check the pixels when it is not.



