Back to the episode map

Research Note

Content Credentials and Provenance Research Note

The current C2PA specification is version 2.4, published in April 2026. The source ledger's earlier version 2.2 link is no longer the current specification and should be

Aug 4, 20262 min readBy Dalton Anderson

Content Credentials and Provenance Research Note

The current C2PA specification is version 2.4, published in April 2026. The source ledger's earlier version 2.2 link is no longer the current specification and should be retained only if a version-specific historical claim requires it.

Content Credentials capture provenance in signed manifests. Useful concepts for public explanation are manifest, claim, assertion, ingredient, action, signature, hash, validation, certificate, trust list, and soft binding. The public pages should introduce these terms through an asset journey rather than as an isolated glossary.

Validation answers whether the available C2PA structures and bindings satisfy the applicable rules. Trust evaluation asks whether the signer and certificate chain are recognized under the selected trust model. Neither process determines whether the real-world event or caption is true.

The conformance program evaluates generator and validator products against technical and security requirements. The official C2PA Trust List supports the 2.x series. The Interim Trust List was frozen on January 1, 2026 for new entries, while legacy credentials remain relevant under their earlier trust model.

Embedded manifests can be stripped when a file is rewritten. C2PA supports external manifests and soft bindings, including fingerprint or watermark-based discovery. Those options improve durability but do not guarantee recovery from every derivative.

YouTube provides a public implementation example. Its current documentation says the platform may carry forward a "How this content was made" disclosure when secure Content Credentials indicate that an entire video was made with AI. The behavior is platform-specific and should not be generalized to all fields or uploads.

Truth boundary

A signed, unedited camera file can show a staged scene. An unsigned screenshot can derive from a genuine event. Public language must therefore separate origin evidence, transformation evidence, identity or authorship claims, depiction, and factual truth.

Sources

Follow the evidence.

  1. support.google.com: 14328491support.google.com
  2. iptc.org: iptc standardiptc.org
  3. c2pa.org: faqsc2pa.org
  4. FTC Disclosures 101ftc.gov
  5. eur-lex.europa.eu: ojeur-lex.europa.eu
  6. c2pa.org: conformancec2pa.org
  7. github.com: Z Imagegithub.com
  8. ftc.gov: consumer reviews testimonials rule questions answersftc.gov
  9. FTC: Endorsements, Influencers, and Reviewsftc.gov
  10. deepmind.google: synthiddeepmind.google
  11. iptc.org: IPTC PhotoMetadata 2025.1iptc.org
  12. nist.gov: reducing risks posed synthetic content overview technical approaches digital contentnist.gov
  13. openaccess.thecvf.com: Li Bridging the Gap Between Ideal and Real world Evaluation Benchmarking AI Generated ICCV 2025 paperopenaccess.thecvf.com
  14. asa.org.uk: testimonials and endorsementsasa.org.uk
  15. deepmind.google: prodeepmind.google
  16. arxiv.org: 2507arxiv.org
  17. spec.c2pa.org: C2PA Specificationspec.c2pa.org
  18. ndsa.org: levels of digital preservationndsa.org
  19. deepmind.google: identifying ai generated images with synthiddeepmind.google
Content Credentials and Provenance Research Note