Research Note
Content Credentials and Provenance Research Note
The current C2PA specification is version 2.4, published in April 2026. The source ledger's earlier version 2.2 link is no longer the current specification and should be
Content Credentials and Provenance Research Note
The current C2PA specification is version 2.4, published in April 2026. The source ledger's earlier version 2.2 link is no longer the current specification and should be retained only if a version-specific historical claim requires it.
Content Credentials capture provenance in signed manifests. Useful concepts for public explanation are manifest, claim, assertion, ingredient, action, signature, hash, validation, certificate, trust list, and soft binding. The public pages should introduce these terms through an asset journey rather than as an isolated glossary.
Validation answers whether the available C2PA structures and bindings satisfy the applicable rules. Trust evaluation asks whether the signer and certificate chain are recognized under the selected trust model. Neither process determines whether the real-world event or caption is true.
The conformance program evaluates generator and validator products against technical and security requirements. The official C2PA Trust List supports the 2.x series. The Interim Trust List was frozen on January 1, 2026 for new entries, while legacy credentials remain relevant under their earlier trust model.
Embedded manifests can be stripped when a file is rewritten. C2PA supports external manifests and soft bindings, including fingerprint or watermark-based discovery. Those options improve durability but do not guarantee recovery from every derivative.
YouTube provides a public implementation example. Its current documentation says the platform may carry forward a "How this content was made" disclosure when secure Content Credentials indicate that an entire video was made with AI. The behavior is platform-specific and should not be generalized to all fields or uploads.
Truth boundary
A signed, unedited camera file can show a staged scene. An unsigned screenshot can derive from a genuine event. Public language must therefore separate origin evidence, transformation evidence, identity or authorship claims, depiction, and factual truth.
Sources
Follow the evidence.
- support.google.com: 14328491support.google.com
- iptc.org: iptc standardiptc.org
- c2pa.org: faqsc2pa.org
- FTC Disclosures 101ftc.gov
- eur-lex.europa.eu: ojeur-lex.europa.eu
- c2pa.org: conformancec2pa.org
- github.com: Z Imagegithub.com
- ftc.gov: consumer reviews testimonials rule questions answersftc.gov
- FTC: Endorsements, Influencers, and Reviewsftc.gov
- deepmind.google: synthiddeepmind.google
- iptc.org: IPTC PhotoMetadata 2025.1iptc.org
- nist.gov: reducing risks posed synthetic content overview technical approaches digital contentnist.gov
- openaccess.thecvf.com: Li Bridging the Gap Between Ideal and Real world Evaluation Benchmarking AI Generated ICCV 2025 paperopenaccess.thecvf.com
- asa.org.uk: testimonials and endorsementsasa.org.uk
- deepmind.google: prodeepmind.google
- arxiv.org: 2507arxiv.org
- spec.c2pa.org: C2PA Specificationspec.c2pa.org
- ndsa.org: levels of digital preservationndsa.org
- deepmind.google: identifying ai generated images with synthiddeepmind.google