Overs

What are Content Credentials (C2PA)?

Checked 6 min read

Short answer

Content Credentials are a signed record attached to an image or video that says who made it, with what tool, and whether AI was used. They follow the C2PA standard, whose steering committee includes Adobe, Google, Meta, Microsoft, OpenAI and TikTok. OpenAI attaches them to its AI images, Adobe may attach them to its generative AI content, and LinkedIn and TikTok read them. They can be stripped, so keep them intact and never rely on them as your only AI label.

What a Content Credential is

C2PA stands for the Coalition for Content Provenance and Authenticity. It publishes an open standard for attaching a manifest to a file: a set of statements about the file’s origin and edits, digitally signed so that tampering shows. Content Credentials is the public name for that record.

LinkedIn shows a C2PA icon on images and videos that carry credentials. Clicking it shows whether AI generated or edited the content, the app or device used, who created it, who signed the credential, and when it was signed.

The C2PA’s own explainer states the limit: provenance information alone cannot tell you whether content is true or accurate. It tells you where a file says it came from, and who vouches for that.

ValueMeaning
trainedAlgorithmicMediaCreated by an AI model trained on captured content
compositeWithTrainedAlgorithmicMediaA real image changed with generative AI, such as by inpainting or outpainting
compositeSyntheticA composite with at least one generative AI element
algorithmicallyEnhancedCorrected by an algorithm without changing the main content, such as noise reduction
digitalCaptureCaptured by a digital camera or recorder
IPTC Digital Source Type values, the industry vocabulary used in image metadata to say how an image was made.

Who adds them and who reads them

CompanyWhat it doesSource
OpenAIAdds C2PA metadata and a SynthID watermark to supported images from ChatGPT, Codex and the APIOpenAI help page, September 2026
AdobeMay attach Content Credentials to content made or changed with its generative AI features; its user guidelines forbid removing themAdobe guidelines, updated May 15, 2026
GoogleEmbeds a SynthID watermark in every image its Gemini API generatesGemini API documentation
LinkedInShows a C2PA icon and the credential details on images and videos that carry themLinkedIn help page
TikTokLabels AI content uploaded from some other platforms by reading Content Credentials, and attaches credentials to its own contentAnnounced May 9, 2024
MetaReads C2PA and IPTC signals to apply its "AI info" label; for content only edited with AI, the label sits in the post menuUpdated September 12, 2024
Google Merchant CenterRequires AI-generated product images to keep AI metadata such as IPTC DigitalSourceType, and says not to remove itImage requirements page
From each company’s own pages, checked September 24, 2026.

Metadata can be stripped; watermarks sit in the pixels

Metadata travels in the file, so anything that rewrites the file can drop it. The C2PA explainer says credentials can be removed, and OpenAI says platforms, editing tools and file conversions can remove them. A watermark such as Google’s SynthID is hidden in the image itself and can survive some edits, but it carries less detail.

The standard’s answer is durable credentials: a watermark or fingerprint lets a service find the original credential in the cloud after the metadata is gone. The EU Code of Practice asks AI providers to use two layers for the same reason, signed metadata plus an invisible watermark.

SignalWhere it livesGood atWeak at
C2PA metadataInside the file, signedDetail: tool, time, who signed, editsLost when a file is converted or uploaded to a service that strips metadata
Invisible watermark, such as SynthIDIn the pixelsSurviving cropping, filters and compression, according to GoogleCarries little detail; you check it with the maker’s own tool, such as the Gemini app for SynthID
Visible labelOn the imagePeople see it without any toolCan be cropped out or covered

The laws behind them

  • EU. Article 50(2) of the AI Act requires AI providers to mark outputs in a machine-readable way from August 2, 2026; tools already on the market before then have until December 2, 2026. A brand showing a deepfake needs a visible label as well, because the Commission says hidden marks do not count as disclosure. See the EU AI Act guide.
  • EU Code of Practice. Signatory providers commit to write a ban on deliberately removing their marks into the terms their users accept.
  • California. The AI Transparency Act (Business and Professions Code, chapter 25), operative August 2, 2026, requires AI providers with more than 1,000,000 monthly users to embed hidden disclosures naming the provider, the system and version, the time of creation and a unique ID, to offer users a visible label option, and to offer a free detection tool. Fines are $5,000 per violation per day. Large online platforms take on duties from January 1, 2027, and makers of cameras and other capture devices from January 1, 2028.
  • Contracts and platforms. Adobe’s guidelines forbid removing Content Credentials, and Google Merchant Center requires AI metadata to stay on product images. See Google Shopping image rules.

Should a brand use them?

Use them as a record, and add a visible label where one is needed. Keep the credentials your AI tool adds, because Google Merchant Center requires the metadata and the EU Code asks providers to forbid stripping it. The US industry body IAB also asks advertisers to attach C2PA metadata to AI-involved ad assets in its August 2026 framework. Do not count on credentials alone to tell people an image is AI-made: they stay hidden until someone opens them, and the EU requires a label people can see.

  • Test one file end to end, from the AI tool through editing and compression to your store or ad platform, and see whether the metadata survives.
  • Open a finished file on the Content Authenticity Initiative’s Verify site to see what is left.
  • Keep the original AI output with its credentials next to the edited final.
  • Never run AI images through tools built to remove provenance marks.
  • Add a visible label wherever the law or the platform asks for one.
  • For Google Shopping listings, keep the IPTC DigitalSourceType tag.

Questions people also ask

Can Content Credentials be faked?
The signature shows who signed a credential and whether the file changed since. It cannot show that the signer told the truth, which is why the C2PA says provenance alone cannot tell you whether content is accurate. Trust depends on who signed.
Do Content Credentials prove I own an image?
No. OpenAI’s help page says provenance signals are not a guarantee that content is accurate, unedited, legally owned or shown in the right context. Ownership depends on copyright law and your tool’s terms; see who owns AI-generated images.
Will platforms label my ad automatically?
Sometimes. Meta and TikTok read C2PA and IPTC signals and can add their own AI labels, and LinkedIn shows a C2PA icon. If the metadata was stripped, they may not. Each platform’s ad rules are in the ad labeling guide.
What is SynthID?
Google DeepMind’s invisible watermark for AI content. Google embeds it in every image its Gemini API generates, and OpenAI’s help page says OpenAI images carry SynthID too. You can ask the Gemini app whether an image was made or edited with Google AI.

Where Overs fits

Overs exports each campaign with a record of the prompt, model and reference pictures behind every photo. Keep that record with the image files, next to whatever credentials the image model attached.

Free for 40 photos a month. The AI that makes the photos is billed separately, on your own key, with no markup from Overs.

Sources

Checked on September 24, 2026. Prices, specs and rules change; follow the links for the current versions.

  1. 1.C2PA: Coalition for Content Provenance and Authenticity
  2. 2.C2PA: About
  3. 3.C2PA: Specification 2.2 explainer
  4. 4.OpenAI Help Center: Provenance signals (Content Credentials, SynthID) in OpenAI-generated content
  5. 5.Adobe: Generative AI User Guidelines (updated May 15, 2026)
  6. 6.Google AI for Developers: Image generation with the Gemini API
  7. 7.Google DeepMind: SynthID
  8. 8.LinkedIn Help: Content credentials
  9. 9.TikTok Newsroom: Partnering with our industry to advance AI transparency and literacy (May 9, 2024)
  10. 10.Meta Newsroom: Our approach to labeling AI-generated content and manipulated media (updated September 12, 2024)
  11. 11.IPTC: Digital Source Type vocabulary
  12. 12.Google Merchant Center Help: Image link [image_link]
  13. 13.California Legislative Information: Business and Professions Code, Division 8, Chapter 25 (AI Transparency Act)
  14. 14.European Commission: Code of Practice on Transparency of AI-Generated Content (full text, PDF)
  15. 15.EUR-Lex: Regulation (EU) 2024/1689, the Artificial Intelligence Act
  16. 16.IAB: AI Transparency and Disclosure Framework V2 (August 2026, PDF)
  17. 17.Content Authenticity Initiative: Verify