Core Concepts

Content Credentials (C2PA) in plain English.

Also known as: C2PA,provenance metadata,content provenance

The one-sentence version

A tamper-evident label attached to an image, video, or audio file recording where it came from and whether AI was used to make or edit it.

Content Credentials are a provenance standard from the Coalition for Content Provenance and Authenticity (C2PA), a group that includes Adobe, Microsoft, Google, OpenAI, the BBC, and camera makers. When a supporting tool creates or edits a file, it attaches a cryptographically signed manifest listing the tool, the actions taken, and in some cases the AI model used. Anyone can inspect that manifest, and any edit by a non-supporting tool breaks the signature, which is itself informative. Adobe Firefly, DALL-E, and several camera bodies already sign their output; social platforms and news organisations are beginning to display the label. Content Credentials do not detect AI content after the fact, which is what AI detectors attempt with mixed success; they record it at the point of creation. Their weakness is coverage: a file with no credentials proves nothing, and metadata can simply be stripped. Regulation in the EU and several US states is pushing platforms and generators toward adopting them, which is why the standard is becoming a practical concern for anyone publishing images.

Read the full guide