Responsible AI, Disclosure & ComplianceTransparency law, content provenance and Gulf rules · Lesson 8 of 11

Content Credentials (C2PA), watermarks and provenance

Article · 17 min · 9 min lecture

Video lecture

Content Credentials (C2PA), watermarks and provenance

13 chapters · about 9 min · full transcript

Coming soon

Chapter 1 of 13

Content Credentials and watermarks

  • From 'is it fake?' to 'where from?'
  • How C2PA works
  • Watermarks and fingerprints
  • Check your own files

The narrated lecture is in production

Every chapter is scripted and ready. Browse the chapters and read the full transcript now — the video will appear here when it’s published.

Chapters

From "is it fake?" to "where did it come from?"

Detecting AI content by looking at it is a losing game: models improve faster than detectors. The industry's answer is provenance: attaching a verifiable record of where a file came from and how it was changed. For marketers this matters three ways: platforms read provenance to apply AI labels automatically, regulators (the EU AI Act's Article 50(2), California's AI Transparency Act) expect generative tools to mark outputs, and clients increasingly ask agencies to preserve it.

The three layers of provenance

LayerWhat it isStrengthWeakness
Metadata manifest (C2PA Content Credentials)A cryptographically signed record attached to the file: who made it, with what tool, what actions (created, edited, AI-generated)Rich, verifiable, tamper-evidentEasily stripped by screenshots, re-encoding or some platforms
Invisible watermarkA signal hidden in the pixels or audio (for example Google's SynthID)Survives many edits and re-uploadsUsually only the vendor can detect it; says less about history
FingerprintA perceptual hash stored in a database, used to look up a file's manifestRecovers provenance after strippingNeeds a lookup service

The C2PA approach combines them into durable Content Credentials: a manifest for detail, plus a watermark or fingerprint that points back to it if the metadata is stripped.

How C2PA works, briefly

C2PA (the Coalition for Content Provenance and Authenticity) publishes an open technical standard. Its specification is on the 2.x series (version 2.4 was released in April 2026). A manifest contains:

  • Assertions: statements about the asset, such as actions taken (c2pa.created, c2pa.edited), the tool used, and the digital source type. The IPTC value trainedAlgorithmicMedia means the content was created by a generative model; compositeWithTrainedAlgorithmicMedia means AI elements were combined with other content.
  • A claim bundling those assertions, with a hard binding (a cryptographic hash of the content, so any change breaks the match).
  • A signature from a certificate. Validators check the certificate against a trust list.

Each edit in a C2PA-aware tool can add a new manifest that references the earlier ones as ingredients, building a chain of history.

Crucial limitation: a valid manifest proves who signed what claims, not that the content is true. A real photo can be staged; a signed AI image is still AI. And no manifest proves nothing: most files lose metadata somewhere along the way.

Who supports it (check current status)

  • Creation: many generative tools attach Content Credentials to outputs (Adobe Firefly and OpenAI's image generation, for example). Some cameras and phones sign captures, including models from Leica, Sony and Nikon and Google's Pixel 10 series; Samsung marks some AI-edited images.
  • Platforms: YouTube, Meta, TikTok and LinkedIn read C2PA signals in different ways (see Module 3). Many platforms still strip the metadata from the file they serve, even when they use it to apply a label.
  • Watermarks: Google's SynthID marks content from Google's models and has a detection portal; other vendors use their own schemes.

Hands-on 1: inspect a file from the command line

# c2patool: open-source CLI from the Content Authenticity Initiative (contentauth/c2pa-rs, cli folder).
c2patool campaign_hero.jpg              # manifest store as JSON, or an error if none is present
c2patool campaign_hero.jpg --detailed   # full detail including validation results
c2patool campaign_hero.jpg --info       # short summary of the file's manifest info

Or drag the file into a public Content Credentials verify tool (linked from contentcredentials.org) for a visual history.

Hands-on 2: check a folder of exports in Python

This script flags which exported assets still carry Content Credentials and whether any manifest declares AI generation. Use it in your delivery checklist before files go to a client or platform.

# pip install c2pa-python
import json
import sys
from pathlib import Path

import c2pa

AI_TYPES = ("trainedAlgorithmicMedia", "compositeWithTrainedAlgorithmicMedia")


def inspect(path: Path) -> dict:
    try:
        with c2pa.Reader(str(path)) as reader:
            store = json.loads(reader.json())
    except c2pa.C2paError.ManifestNotFound:
        return {"file": path.name, "credentials": False, "ai_declared": None}
    except c2pa.C2paError as err:
        return {"file": path.name, "credentials": "error", "detail": str(err)}

    text = json.dumps(store)
    return {
        "file": path.name,
        "credentials": True,
        "ai_declared": any(t in text for t in AI_TYPES),
        # newer SDKs report "validation_state" (e.g. Valid, Trusted, Invalid); older ones list "validation_status" issues
        "validation_state": store.get("validation_state"),
        "validation_issues": len(store.get("validation_status") or []),
    }


if __name__ == "__main__":
    folder = Path(sys.argv[1] if len(sys.argv) > 1 else "exports")
    for f in sorted(folder.iterdir()):
        if f.suffix.lower() in {".jpg", ".jpeg", ".png", ".webp", ".mp4", ".mov", ".wav", ".mp3"}:
            print(inspect(f))

What to do with the results:

  • credentials: False on a file that had them at generation: your export settings are stripping metadata. Turn on "include Content Credentials" or "keep metadata" in your editor and re-export.
  • ai_declared: True: make sure the asset register and the platform disclosure match.
  • validation_state of Invalid, or validation_issues greater than zero: the file changed after signing or the certificate is not trusted; investigate before relying on it.

Worked example: an agency's provenance-preserving pipeline

A Dubai agency produces AI-assisted product visuals for a GCC retailer that also sells into the EU. It sets a rule: generate in tools that attach Content Credentials, edit in a C2PA-aware editor, export with credentials on, run the Python check on the delivery folder, and record results in the asset register. When a platform later auto-labels one visual as AI-generated, the client is not surprised: the register already says so, and the agency can show the chain of edits.

Measuring success

  • Share of delivered AI-assisted files that still carry valid Content Credentials (target: all, unless a platform or client explicitly requires otherwise).
  • Mismatches between asset register, manifest and platform label (target: zero).
  • Vendor list up to date with each tool's marking method (metadata, watermark or both).

Pitfalls

  • Treating a missing manifest as proof that content is real.
  • Treating a valid manifest as proof that content is true.
  • Screenshotting assets for delivery, which throws away all provenance.
  • Stripping metadata "for file size" without realizing it removes the trust signal.

Key takeaways

  • Provenance asks where content came from; it is more durable than trying to spot fakes by eye.
  • C2PA Content Credentials are signed manifests; watermarks and fingerprints help them survive stripping.
  • A valid manifest proves who signed which claims, not that content is true; a missing one proves nothing.
  • Keep credentials through your export pipeline and check deliveries with c2patool or c2pa-python.

Check your understanding

Quick questions to lock in the lesson. They don’t count towards your certificate.

  1. A file you download from a social platform has no Content Credentials. What can you conclude?
  2. Which C2PA digital source type indicates content created by a generative model?
  3. Why combine a watermark or fingerprint with a C2PA manifest?

Put it into practice

Run c2patool or the Python checker on five of your recent AI-assisted exports, note which lost their Content Credentials, and fix the export setting responsible.

Enrol for free to save your progress

Reading is always free. Enrol to keep your place, take the final assessment and earn a verifiable certificate.