Content Credentials are a signed provenance record based on the open C2PA standard. AI providers such as OpenAI or Adobe use it to state that an image was created with AI. The viewer reads the manifest and shows generator, certificate, source type and actions; it does not verify the signature itself.
What a C2PA manifest contains
- Claim generator: the program or service that wrote the manifest.
- Certificate: the organisation that signed. Google shows AI information from C2PA in “About this image” only if the certificate is on the C2PA trust list.
- Actions: such as
c2pa.created,c2pa.edited,c2pa.opened. - digitalSourceType: the same IPTC term as in XMP, such as
trainedAlgorithmicMedia.
C2PA and the EU AI Act
Article 50(2) AI Act requires providers of generative AI to mark their output in a machine-readable way; C2PA is one of the techniques the Code of Practice names. For retailers using such images, the marking does not replace the visible label (guidelines para. 117). A manifest is bound to the file. Changing the image, for example by burning in a label, breaks the signature. That is why our labelling tool does not burn a label into such files.
Limits
Many platforms, stores and CDNs remove C2PA data on upload, so a missing manifest says nothing about provenance. More on the technology in C2PA, IPTC and watermarks.
Frequently asked questions
What are Content Credentials?
Content Credentials is the consumer-facing name for provenance information under the C2PA standard. A manifest describes who created or edited a file and is cryptographically bound to it.
Does the viewer check whether the signature is valid?
No. Trust verification against the C2PA list needs the official library, for example via contentcredentials.org/verify.
Why does my AI image have no Content Credentials?
Not all generators write C2PA, and screenshots, editing or uploads to stores and social networks often remove it. Legacy systems may deliver without marking until 2 December 2026 (Article 111(4) AI Act).
Do I still need to label an image that has Content Credentials?
Yes, if it is a deep fake and you use it (guidelines para. 117).
Sources
Para. refers to the paragraph number in the European Commission's guidelines on Article 50, C(2026) 5054.
- C2PA Technical Specification 2.2Coalition for Content Provenance and Authenticity · Standard · 1 May 2025
- Google Search Central: image metadata (IPTC, C2PA)Google · Platform · 10 Dec 2025
- Code of Practice on Transparency of AI-Generated Content (final version)Europäische Kommission · Code of practice · 10 Jun 2026
- Commission Guidelines on the transparency obligations under Article 50 AI Act, C(2026) 5054 finalEuropäische Kommission · Commission · 20 Jul 2026
- Regulation (EU) 2026/1744 (Digital Omnibus on AI)EUR-Lex · Law · 24 Jul 2026


