Build1 publisher3 min readPublished
C2PA proves who signed, not what was true: Content Credentials are provenance, not AI detection
The standard signs a chain of assertions about capture and edits. It does not verify the scene in front of the lens, and a missing manifest tells you almost nothing.
The Engineer · Build desk
Drafted by a language model from the sources cited here and checked against its claim ledger before publication. How we use AISend a correction
What happened
- The Coalition for Content Provenance and Authenticity (C2PA) publishes a standard for attaching a signed history to an image, video or audio file: what device or tool produced it, what edits were applied, and in what order.
- C2PA started as a joint effort between Adobe, Microsoft, the BBC, Intel and Sony, and now includes most major camera and software vendors in some capacity.
- The specification defines Content Credentials: a structured, cryptographically signed manifest that travels with a media file and records its provenance.
- A Content Credentials manifest is built from a chain of assertions, each one signed and each one referencing the state of the file before that assertion was made.
- A typical chain for a photograph might include a capture assertion from the camera recording device model and timestamp, an edit assertion from an editing tool recording a crop and a colour adjustment, and a final assertion from a publisher recording that the image was prepared for distribution.
Compiled by The EngineerSomething wrong?How this is made
Why it matters
The Coalition for Content Provenance and Authenticity publishes a standard for attaching a signed history to an image, video or audio file: what device or tool produced it, what edits were applied, and in what order [2]. The effort began with Adobe, Microsoft, the BBC, Intel and Sony and now includes most major camera and software vendors in some capacity [3], which means product teams are increasingly being asked to wire it in as an AI detector. That is the wrong job for it.
The mechanics are worth reading before the marketing. A Content Credentials manifest is a structured, cryptographically signed record that travels with the file [4], built from a chain of assertions, each one signed and each referencing the state of the file before that assertion was made [5]. For a photograph, a typical chain is a capture assertion from the camera carrying device model and timestamp, an edit assertion from an editing tool recording a crop and a colour adjustment, and a publisher assertion recording that the image was prepared for distribution [6]. The manifest also stores a cryptographic hash of the pixel data at each stage [7], so if the file is altered after the last signature outside a C2PA-aware tool, the hash no longer matches and a verifier can tell the chain is broken without knowing what the edit was [8].
That is a real guarantee, and it is narrower than the one people want. Per the specification's own framing, an unbroken chain proves that a specific set of signers made specific claims about the file's history and that the file has not changed since the last signature; it does not prove those claims are accurate [9]. A capture assertion says this device, running this firmware, captured this data at this time [10]. Point that camera at a monitor playing synthetic video and it will faithfully sign a capture assertion that is true at the sensor level and silent about the scene [11].
The chain is also only as reliable as its weakest signer, and every signer is trusted to have told the truth about its own step [1]. A generative tool that signs its output as AI-generated is giving you verifiable disclosure; a tool or operator that omits that assertion, or strips the manifest, produces a file with no credentials at all, indistinguishable to a casual viewer from one that predates the standard [12]. Signature checking rests on a certificate authority structure, with certificates issued to manufacturers, vendors and publishers that meet the coalition's conformance requirements [17], verified the way TLS is verified [18]. So the security property you inherit is bounded by both the least honest conformant signer and the issuance process behind that certificate [19].
Then there is the asymmetry that breaks any detection rule keyed on absence. Manifests are metadata, and metadata survives re-encoding, cropping and platform uploads inconsistently [13]. Platforms that support Content Credentials preserve them deliberately, while tools that were never built for C2PA drop them, the way EXIF has been stripped for twenty years with no adversarial intent [14]. A missing manifest could mean the file predates the standard, passed through an unaware tool, was stripped to hide its origin, or was never captured media at all [15], and a stripped manifest looks exactly like one that was never attached because the file is undisclosed synthetic output [16]. Absence is not evidence [20].
Instrument your own pipeline for manifest survival rather than assuming it [13][14], treat a present, valid chain as a claim about signers rather than about reality [9], and write the policy so that missing credentials route to human review instead of a verdict [15].