Skip to content

What is C2PA?

Last reviewed: August 2026 · by Ferran Sarrió

C2PA (Coalition for Content Provenance and Authenticity) is an open technical standard, developed as a project of the Joint Development Foundation, for attaching a signed record of origin and edit history to a file. Adobe, Microsoft, Google, OpenAI, camera makers and others use it to embed a "Content Credentials" manifest — a machine-readable statement of what created or edited the file, and whether it was AI-generated.

What a C2PA manifest actually contains

A typical manifest states which software or service created the file (the "claim generator"), a list of actions taken (e.g. "created", "edited"), and — critically for AI content — a "digital source type" field. Values like "trainedAlgorithmicMedia" indicate the content came from a generative AI model. The whole manifest is cryptographically signed, so tampering with it invalidates the signature.

Content Credentials vs C2PA — same thing, two names

"C2PA" is the name of the technical standard; "Content Credentials" is the consumer-facing name Adobe and others use for the same feature. You will see both terms used interchangeably for the same embedded manifest.

The C2PA Trust List and specification versions

The official C2PA Trust List launched in mid-2025, replacing an earlier, temporary "Interim Trust List" that was frozen on 1 January 2026 and no longer accepts new entries. The Coalition actively encourages implementers to move to the 2.x specification series (2.2 through the current 2.4) rather than older 1.x versions — which is part of why a metadata-reading tool needs to keep up with the spec to stay accurate.

The EU AI Act, Article 50

Article 50 of EU Regulation 2024/1689 (the AI Act) became enforceable on 2 August 2026. It requires providers of generative AI systems to mark synthetic outputs (image, audio, video and text) in a machine-readable, detectable format. The European Commission's draft Code of Practice on Transparency names C2PA Content Credentials as an example technical mechanism that can satisfy this — it is not the only way to comply, but it is the one already in wide practical use. This is factual regulatory context, not legal advice; if compliance obligations apply to your organization, consult a qualified professional.

Some products known to support it

Adobe Firefly Google Gemini OpenAI / ChatGPT Microsoft Camera makers (Leica, Nikon, Sony)

Based on the official C2PA Conforming Products List — not an exhaustive list, and support varies by product version.

Common questions

Which companies actually support C2PA?

According to Content Credentials' own published figures, over 500 companies collaborate on the standard, led by Microsoft, Adobe, Intel, BBC, Truepic, Sony, Publicis Groupe, OpenAI, Google, Meta and Amazon. Separately, the official C2PA Conforming Products List shows the large majority of currently-certified products publish under specification 2.2 or newer.

Does every AI-generated image have a C2PA manifest?

No. Whether one is present depends on the tool that created the file and whether it survived any re-export, screenshot, or platform re-upload since — many strip it. Absence of a manifest is not proof an image wasn't AI-generated.

I saw "Google C2PA Core Generator Library" in my own file — what is that?

That's the literal name Google's manifest generator writes into the claim_generator field of the C2PA manifest it creates — it identifies the specific library used to build and sign the manifest, not a separate product.

Want to check a specific photo? Open the C2PA Checker →

We build focused tools for working with modern image formats and image data.

HEIC Digital AVIF Tools Digital Metadata Remover