C2PA is a cryptographic standard that can prove where a photo came from. OpenAI, Adobe, Google, and camera manufacturers are all adopting it. And it has a serious real-world problem: social platforms strip the metadata on upload, which means credentials vanish from the images where fake-photo scams actually happen. Here's the full picture.
C2PA stands for Coalition for Content Provenance and Authenticity. It's an open technical standard, not a product or a company. The standard defines how to embed a Content Credential — a cryptographically signed manifest — directly into an image, video, or audio file at the moment it's created or generated.
The credential records the chain of custody: what tool created it (a Canon camera, Adobe Photoshop, OpenAI's DALL-E), when, what edits were applied, and by whom. Each step in the chain is signed with a cryptographic certificate, so you can verify that the credential hasn't been tampered with after the fact. Think of it like a notarized receipt that travels with the file.
| Who has adopted C2PA (as of 2026) | What they sign |
|---|---|
| OpenAI (DALL-E, ChatGPT) | All AI-generated images |
| Adobe (Firefly) | AI-generated images; Photoshop edits |
| Google (Imagen / SynthID) | Invisible watermark (related but different approach) |
| Microsoft (Azure AI) | Generated content from Azure AI services |
| Canon, Nikon, Leica | Photos captured by C2PA-enabled cameras |
| Associated Press, AFP | Newswire images published through C2PA-aware workflows |
On May 19, 2026, OpenAI announced a dual-layer approach: C2PA metadata plus a SynthID-style invisible watermark embedded in the image pixels. The pixel-level watermark survives some operations that strip metadata — cropping, color adjustments — though it doesn't survive JPEG recompression or significant resizing.
Here is the central real-world limitation of C2PA: every major social platform strips image metadata — including C2PA credentials — when you upload a photo.
Instagram, X/Twitter, Facebook, WhatsApp, Reddit, and TikTok all reprocess uploaded images. At minimum they re-compress to reduce file size. In the process, EXIF data, IPTC data, and XMP metadata — where C2PA credentials live — are discarded. The platforms don't have a way to read C2PA credentials yet, and they don't preserve metadata they don't understand.
This means:
This is where C2PA is today. The platforms are aware of the issue. The C2PA specification includes a soft binding approach that can survive some processing, and platform-side C2PA verification is on several companies' roadmaps. But as of mid-2026, credentials don't survive the social media upload pipeline.
The metadata-stripping problem is severe for consumer social media use cases. It's less severe for controlled professional workflows where the chain of custody is never broken:
Authenticated photojournalism
The Associated Press and AFP are working toward C2PA-credentialed newswire distribution. If you see a credentialed AP photo published through a C2PA-aware news platform, the chain of custody from camera to publication is verifiable. This is C2PA's strongest current use case.
Legal and insurance proceedings
A photo captured and submitted directly from a C2PA-enabled camera, without going through social media, can carry its credential intact. For insurance claims, accident documentation, or legal evidence where the file is submitted directly, a valid credential is useful authentication.
Enterprise content management
Organizations using Adobe Creative Cloud, where C2PA metadata is preserved through the editing workflow, can track the provenance of marketing materials and brand assets. C2PA-aware DAM (digital asset management) systems can flag images that lack credentials or have had credentials modified.
EU AI Act Article 50 enforcement began on August 2, 2026. The provision requires providers of AI systems that generate synthetic content to ensure outputs are marked in a machine-readable format. This applies to images, audio, and video generated by AI systems operating in the EU market.
The regulation doesn't mandate a specific technical implementation — both C2PA metadata and pixel-level watermarking (like Google's SynthID) are compliant approaches. Major AI image generators (OpenAI, Adobe, Stability AI, Midjourney) are all working toward compliance, though enforcement mechanisms and penalty structures are still being finalized by national regulators.
The practical effect: EU-based AI image generators must mark their outputs. Non-EU generators serving EU users technically fall under the regulation if they're actively targeting the EU market. The metadata-stripping problem remains unaddressed by the regulation — Article 50 requires marking at generation, not preservation through distribution.
These two approaches answer different questions:
| C2PA / Content Credentials | Statistical AI image detection (FauxSpy, etc.) | |
|---|---|---|
| Question answered | "Where did this come from?" | "Does this look AI-generated?" |
| Works on social media images | No — metadata stripped | Yes |
| Requires generator cooperation | Yes | No |
| Works on pre-C2PA images | No | Yes |
| Authenticated chain of custody | Yes — cryptographically verified | No — probabilistic only |
| Works in a browser extension | Emerging (some implementations) | Yes — right-click any image |
| Best use case | Journalism, legal, enterprise | Social media, dating profiles, marketplaces |
C2PA (Coalition for Content Provenance and Authenticity) is an open standard that embeds a cryptographically signed provenance record — called a Content Credential — into image, video, and audio files. It records who created the file, when, and with what tool. Members include Adobe, Microsoft, Google, OpenAI, Sony, and Nikon.
Not reliably, because social platforms strip image metadata on upload. A C2PA credential present on an AI-generated image when it leaves the generator is gone after upload to Instagram, X, or Facebook. C2PA is most useful for controlled workflows where the chain of custody is never broken — journalism, legal proceedings, enterprise asset management — not for verifying images encountered on social media.
As of 2026: OpenAI (DALL-E, ChatGPT images), Adobe (Firefly), Microsoft (Azure AI services). Google uses SynthID — a related invisible watermark embedded in pixel data rather than metadata. On May 19, 2026, OpenAI announced a dual-layer approach combining C2PA metadata with SynthID-style pixel watermarking. Canon, Nikon, and Leica are adding C2PA to camera firmware for photojournalism use cases.
Article 50 (enforcement began August 2, 2026) requires EU AI providers to mark AI-generated synthetic content in a machine-readable format. Both C2PA metadata and pixel-level watermarking are compliant approaches. The regulation covers images, audio, and video generated by AI systems operating in the EU market. It does not resolve the metadata-stripping problem — marking at generation is required, but preservation through distribution is not addressed.
C2PA is valuable when the chain of custody is controlled: authenticated newswire photography, legal evidence, enterprise content management. For profile photos, marketplace listings, and dating app pictures — where the image has passed through at least one platform that strips metadata — C2PA provides no practical signal. Statistical AI image detection (which analyzes pixel data rather than metadata) is the relevant tool for those cases.
Statistical detection works on any image, including ones with no metadata at all. Right-click, check, get a result in under a second.
🕵️ Add to Chrome — Free 🦊 Add to Firefox — Free