Skip to content

What is C2PA? The invisible passport that will accompany every image

Rather than trying to detect fakes, the idea is the opposite: sign the authentic. Here is how the standard that is becoming mandatory from California to Europe works.

Advertisement
The logic flip 🔄
For years, the goal was to detect fakes: analysing an image to spot signs of artificial generation. That's a losing race, because every advance in generators invalidates the detectors. C2PA tackles the problem the other way round: rather than unmasking the fake, it signs the genuine. Every piece of content then carries its own certificate of origin.

Since 2 August, this standard is no longer a voluntary initiative: it becomes the technical reference for legal obligations, as we saw with the California law coming into force. Here's how it works, explained simply.

What the acronym means

C2PA stands for Coalition for Content Provenance and Authenticity. It's an industry consortium that includes Adobe, Microsoft, the BBC, along with camera manufacturers and several media outlets.

Its purpose is to define a standard format for attaching a verifiable history to a file: who created it, with what tool, when, and what modifications it underwent afterwards. This is called provenance, by analogy with the art market, where a work's value depends on the traceability of its journey.

The mechanism, in three ideas

A manifest attached to the file. At creation, the tool adds a block of information to the file describing its origin. A camera can record the brand, model and date of capture. An image generator records the system's name and version.

A cryptographic signature. This is the essential point. The manifest is digitally signed, like an official document bearing a stamp. Any modification to the content or the manifest invalidates the signature. So you can't claim a generated image is a photograph without the tampering becoming detectable.

A cumulative history. Each compatible tool adds its own link. A photo taken by a camera, edited in software, then cropped retains the trace of all three steps. You don't just read the origin, but the entire journey.

The passport analogy 🛂
A passport doesn't prove you're a good person. It proves that an identifiable authority has verified your identity, and the stamps tell where you've been. C2PA works the same way: it doesn't establish that an image is true or beautiful, it establishes who produced it, with what, and what it has undergone since. The judgement remains yours, but you judge on the evidence.

Two levels of marking

The California law distinguishes between two mechanisms that shouldn't be confused.

Latent disclosure is invisible and machine-readable. It's the mandatory marker, designed to be permanent or extraordinarily difficult to remove. It doesn't alter the image as you see it.

Manifest disclosure is the visible label like AI-generated content. Providers must offer the option to add it, but the user remains free to apply it or not.

This distinction matters: the first mechanism serves verification, the second serves immediate transparency. A piece of content can therefore be invisibly marked without displaying any label on screen.

The limitations, which you should know

The absence of a marker proves nothing. This is the most important limitation. Content without a signature may be authentic, come from a non-compatible tool, or have lost its metadata while passing through a platform that strips it. You get positive verification, not negative proof.

Robustness isn't absolute. A marker must survive compression, cropping, a screenshot. The best techniques often manage this, but a sufficiently aggressive transformation can destroy the information.

Open models escape the system. A system downloaded and run locally can be configured to sign nothing, as we noted regarding open-weight models. Someone deliberately trying to deceive won't use a service that tracks them.

Text isn't covered. Watermarking text without degrading it remains technically very difficult, and the California law therefore excludes textual outputs.

What to take away

C2PA doesn't solve the problem of deceptive synthetic content, and its promoters don't claim it does. What it builds is an infrastructure of verifiable trust for everything that goes through official channels: the major platforms, newsrooms, camera manufacturers.

In the long run, the most interesting effect could be the opposite of what one might imagine. It won't so much be that AI content gets marked, but that authentic content can prove it. In a world where generating a realistic image costs nothing, the ability to demonstrate that a photo really comes from a camera, at a given place and time, becomes the scarce resource. The passport isn't for spotting impostors: it's for those who aren't one.

Advertisement