What Content Credentials Actually Tell You (and What They Don't) : A Journalist's Guide to C2PA

24 August 2026 Authenticity For Journalists

What Content Credentials Actually Tell You (and What They Don't): A Journalist's Guide to C2PA

You've probably seen the small "cr" icon appearing on more images lately — on stock photo sites, in social feeds, sometimes on visuals generated by tools like ChatGPT or Midjourney. It signals that the file carries Content Credentials, the metadata standard built by the Coalition for Content Provenance and Authenticity (C2PA). For newsrooms drowning in AI-generated and manipulated media, this sounds like exactly what's needed — but like any label, it only tells you what it was designed to measure.

🔏
Standard status
C2PA — version 2.3, released January 2026
First public draft in 2021 · now implemented by BBC, CBC/Radio-Canada, OpenAI, Sony and Nikon
2.3
current C2PA specification version, Jan 2026
2021
year the first public C2PA draft was released
2025
Sony launched Camera Verify for press photographers

What Content Credentials actually are

Content Credentials are a form of tamper-evident metadata. When a compatible camera, editing tool, or AI generator creates or modifies a file, it can attach a cryptographically signed record — called a manifest — describing what happened: the device or software used, the timestamp, and any subsequent edits. That claim is directly tied to the file and travels with it wherever it's shared; any application can retrieve the manifest to check who signed it and decide how much to trust that signer.

Crucially, the signature is tamper-evident: if the file is altered by a tool that doesn't preserve the credentials, or if someone strips the metadata out, the chain either breaks or disappears. That's the core design idea — not proving something is "real," but making the history of a file checkable.

Adoption has moved from theoretical to operational. The BBC and CBC/Radio-Canada now attach Content Credentials to media they produce or verify, and OpenAI embeds them on AI-generated images and video to disclose that origin. On the capture side, Sony announced a Camera Verify system for press photographers in June 2025, following earlier moves by Nikon to build C2PA signing into professional cameras and to work with AFP on newsroom verification workflows.

What a badge can and can't tell you

Signal What it means for you
Can tell you
Which tool created it
Camera model, generating AI model, or editing software used at each step.
Can tell you
Edit history
A visible chain of changes, if every tool in the pipeline was C2PA-compliant.
Can tell you
Post-signing tampering
Any pixel change after signing breaks or invalidates the cryptographic seal.
Can tell you
Who is vouching
Not "this is true" — but "this named signer asserts this." Trust depends on who that signer is.
Can't tell you
Real vs. fake
A fully AI-generated image with intact credentials is doing exactly what it should: disclosing its synthetic origin honestly, not hiding it.
Can't tell you
Anything about unlabeled content
Most images online today have no manifest at all. Absence of a badge is not evidence of fakery — it's absence of data.
Can't tell you
Whether the scene itself is genuine
Provenance tracks the file's digital history, not the truthfulness of what's depicted in front of the camera.

"A Content Credentials badge is only as trustworthy as the signer behind it. Verifying an AFP-signed image is a very different confidence level than verifying a credential from an anonymous account."

On why the signer matters more than the badge itself

A practical checklist for the newsroom

Check for the badge first — using a browser extension or an open tool like contentcredentials.org's verify page.
Read who signed it, not just whether it's signed. A known agency or your own newsroom's tools carry far more weight.
Treat missing credentials as neutral, not suspicious. Fall back on your normal verification workflow.
Watch for broken chains. A manifest that flags tampering after signing is a genuine red flag worth investigating.
Don't let a badge replace sourcing. Provenance signals support verification — they don't replace asking who sent you the file, and why.

Why this matters now

Provenance and content authenticity infrastructure is most valuable when adopted end-to-end by high-stakes institutions like newsrooms, election offices, and public agencies, and built into the tools people use every day — but it isn't universal. It won't catch content generated outside authenticated pipelines, and most of the internet's background noise will remain unlabeled for the foreseeable future. That asymmetry is exactly why editorial verification skills remain essential: provenance tooling is a new instrument in the newsroom's kit, not a replacement for it.

Frequently asked questions

Does a Content Credentials badge mean a photo is real?
No. It means a named signer made a verifiable claim about the file's origin and history. An AI-generated image can carry a perfectly valid credential — one that honestly discloses it was AI-generated.
Should I be suspicious of an image with no Content Credentials?
Not automatically. Most content in circulation today has no manifest at all, simply because it passed through a non-compliant tool. Treat the absence as a gap in data, not a red flag, and fall back on standard verification steps.
Can Content Credentials be removed or faked?
They can be stripped — and until recently, routine steps like CDN image resizing could break the chain by accident. They can't be convincingly faked without invalidating the cryptographic signature, which is what makes tampering detectable.
Which newsrooms are already using this?
The BBC and CBC/Radio-Canada attach credentials to media they produce or verify. AFP has worked with Nikon on newsroom verification workflows, and Sony's Camera Verify system launched for press photographers in June 2025.

Who's behind Provenance For Trust

This explainer is published by Provenance For Trust, a platform built by six organisations across journalism, technology, and academic research, supported by the French Ministère de la Culture.

Technology

Provides the technological foundation the platform runs on.

Detection

Contributes the detection layer — identifying AI-generated images, video, audio, and text.

Development

Technology-foresight and development expertise.

Certification

Editorial certification standards, launched by Reporters Without Borders.

Image rights

Image rights and licensing expertise.

Research

Academic research on digital publics and information ecosystems.


Building verification workflows in your newsroom?

Don't wait for a last-minute scramble to secure your publishing pipeline. Talk to us about integrating Content Credentials into your editorial process.

Contact us →

Want to try it yourself? You can already access the beta version of the Provenance For Trust app.

Try the beta →
C2PA Content Credentials Photojournalism Verification AI Transparency Media Trust Provenance For Trust
Précédent
Précédent

Ce que les Content Credentials vous disent vraiment (et ce qu'ils ne disent pas) : le guide du journaliste sur le C2PA

Suivant
Suivant

What Is Content Provenance? Inside C2PA and the Provenance For Trust Toolkit