
C2PA
C2PA is a technical standard that stores the origin of images, videos, and audio files within the file itself in a tamper-proof way. This makes it possible to trace which device or program created a recording and who edited it afterward.
When you see a photo on the internet, you rarely know where it came from. It could have been taken with a camera, heavily edited, or generated entirely by a computer program. C2PA is a jointly agreed technical set of rules that records exactly this history within the file itself. Cameras, editing programs, or AI tools each write short entries into the file: what was done, when, and by which program. These entries are digitally sealed, so that any later change becomes noticeable. The name stands for “Coalition for Content Provenance and Authenticity,” an alliance of technology and media companies such as Adobe, Microsoft, Google, Sony, and the BBC.
Why the origin of images has become a problem
Today, images, voices, and videos can be generated with a simple text prompt. What used to take hours of work on a computer now takes seconds and costs almost nothing. As a result, the value of an image as evidence declines. A photo no longer reliably shows that something actually happened.
The usual reflex is to say that fakes simply need to be detectable. But detection programs only guess with probabilities and are often wrong. They are also constantly being outpaced by new generators. C2PA turns the question around. Instead of hunting for fakes, it makes genuine recordings verifiable.
For news agencies, courts, insurers, and public authorities, this is a very concrete interest. A photo of damage without proof of origin is worth little. Laws are playing a role here too: the EU’s AI Act requires that artificially generated content be labeled. C2PA is the standard that many companies intend to use to technically implement this obligation.
The digital seal within the file
Every stage in the life of a file attaches an entry. The camera notes the time and model, the image-editing program notes the crop, an AI tool notes that it generated parts of the content. Together, these entries form a chain, similar to a stamp booklet in which each station adds its own stamp.
To prevent anyone from forging a stamp after the fact, each entry is signed using a cryptographic method. Cryptographic means: a check value is calculated from the content and encrypted with a secret key. If someone changes the image or the entry, the check value no longer matches, and the software reports a break in the chain. The key belongs to the manufacturer, not to the user.
One important point is often misunderstood. C2PA does not say whether an image shows the truth. It only says who did what with it. And the chain is not indestructible: anyone who takes a screenshot or sends the image through a program that doesn’t recognize C2PA loses the entries. A missing seal is therefore not proof of a fake.
Content Credentials in cameras, apps, and search results
Under the name “Content Credentials,” the standard is already appearing in products. Adobe Photoshop can write the entries, and image generators such as OpenAI’s DALL·E and Google’s models mark their outputs with them. DSLR and mirrorless cameras from Leica, Nikon, Sony, and Canon can sign photos directly at the moment of capture.
This is usually made visible as a small icon at the edge of the image, often a circle with the letters “cr”. Clicking it shows the list of editing steps. Google displays such information in image search, as do LinkedIn and a number of news portals.
In business news, C2PA mainly comes up in the context of regulation and platform liability. When authorities enforce labeling requirements for AI content, platforms need a technical method to comply. Watermarks embedded in the image itself, such as Google’s SynthID, are also used for this purpose. The two approaches are not mutually exclusive: the watermark survives screenshots, while the C2PA entries tell the full story.