What are Content Credentials (C2PA)?
Content Credentials are a signed record attached to an image or video that says who made it, with what tool, and whether AI was used. They follow the C2PA standard, whose steering committee includes Adobe, Google, Meta, Microsoft, OpenAI and TikTok. OpenAI attaches them to its AI images, Adobe may attach them to its generative AI content, and LinkedIn and TikTok read them. They can be stripped, so keep them intact and never rely on them as your only AI label.
What a Content Credential is
C2PA stands for the Coalition for Content Provenance and Authenticity. It publishes an open standard for attaching a manifest to a file: a set of statements about the file’s origin and edits, digitally signed so that tampering shows. Content Credentials is the public name for that record.
LinkedIn shows a C2PA icon on images and videos that carry credentials. Clicking it shows whether AI generated or edited the content, the app or device used, who created it, who signed the credential, and when it was signed.
The C2PA’s own explainer states the limit: provenance information alone cannot tell you whether content is true or accurate. It tells you where a file says it came from, and who vouches for that.
| Value | Meaning |
|---|---|
| trainedAlgorithmicMedia | Created by an AI model trained on captured content |
| compositeWithTrainedAlgorithmicMedia | A real image changed with generative AI, such as by inpainting or outpainting |
| compositeSynthetic | A composite with at least one generative AI element |
| algorithmicallyEnhanced | Corrected by an algorithm without changing the main content, such as noise reduction |
| digitalCapture | Captured by a digital camera or recorder |
Who adds them and who reads them
| Company | What it does | Source |
|---|---|---|
| OpenAI | Adds C2PA metadata and a SynthID watermark to supported images from ChatGPT, Codex and the API | OpenAI help page, September 2026 |
| Adobe | May attach Content Credentials to content made or changed with its generative AI features; its user guidelines forbid removing them | Adobe guidelines, updated May 15, 2026 |
| Embeds a SynthID watermark in every image its Gemini API generates | Gemini API documentation | |
| Shows a C2PA icon and the credential details on images and videos that carry them | LinkedIn help page | |
| TikTok | Labels AI content uploaded from some other platforms by reading Content Credentials, and attaches credentials to its own content | Announced May 9, 2024 |
| Meta | Reads C2PA and IPTC signals to apply its "AI info" label; for content only edited with AI, the label sits in the post menu | Updated September 12, 2024 |
| Google Merchant Center | Requires AI-generated product images to keep AI metadata such as IPTC DigitalSourceType, and says not to remove it | Image requirements page |
Metadata can be stripped; watermarks sit in the pixels
Metadata travels in the file, so anything that rewrites the file can drop it. The C2PA explainer says credentials can be removed, and OpenAI says platforms, editing tools and file conversions can remove them. A watermark such as Google’s SynthID is hidden in the image itself and can survive some edits, but it carries less detail.
The standard’s answer is durable credentials: a watermark or fingerprint lets a service find the original credential in the cloud after the metadata is gone. The EU Code of Practice asks AI providers to use two layers for the same reason, signed metadata plus an invisible watermark.
| Signal | Where it lives | Good at | Weak at |
|---|---|---|---|
| C2PA metadata | Inside the file, signed | Detail: tool, time, who signed, edits | Lost when a file is converted or uploaded to a service that strips metadata |
| Invisible watermark, such as SynthID | In the pixels | Surviving cropping, filters and compression, according to Google | Carries little detail; you check it with the maker’s own tool, such as the Gemini app for SynthID |
| Visible label | On the image | People see it without any tool | Can be cropped out or covered |
The laws behind them
- EU. Article 50(2) of the AI Act requires AI providers to mark outputs in a machine-readable way from August 2, 2026; tools already on the market before then have until December 2, 2026. A brand showing a deepfake needs a visible label as well, because the Commission says hidden marks do not count as disclosure. See the EU AI Act guide.
- EU Code of Practice. Signatory providers commit to write a ban on deliberately removing their marks into the terms their users accept.
- California. The AI Transparency Act (Business and Professions Code, chapter 25), operative August 2, 2026, requires AI providers with more than 1,000,000 monthly users to embed hidden disclosures naming the provider, the system and version, the time of creation and a unique ID, to offer users a visible label option, and to offer a free detection tool. Fines are $5,000 per violation per day. Large online platforms take on duties from January 1, 2027, and makers of cameras and other capture devices from January 1, 2028.
- Contracts and platforms. Adobe’s guidelines forbid removing Content Credentials, and Google Merchant Center requires AI metadata to stay on product images. See Google Shopping image rules.
Should a brand use them?
Use them as a record, and add a visible label where one is needed. Keep the credentials your AI tool adds, because Google Merchant Center requires the metadata and the EU Code asks providers to forbid stripping it. The US industry body IAB also asks advertisers to attach C2PA metadata to AI-involved ad assets in its August 2026 framework. Do not count on credentials alone to tell people an image is AI-made: they stay hidden until someone opens them, and the EU requires a label people can see.
- Test one file end to end, from the AI tool through editing and compression to your store or ad platform, and see whether the metadata survives.
- Open a finished file on the Content Authenticity Initiative’s Verify site to see what is left.
- Keep the original AI output with its credentials next to the edited final.
- Never run AI images through tools built to remove provenance marks.
- Add a visible label wherever the law or the platform asks for one.
- For Google Shopping listings, keep the IPTC DigitalSourceType tag.
Questions people also ask
- Can Content Credentials be faked?
- The signature shows who signed a credential and whether the file changed since. It cannot show that the signer told the truth, which is why the C2PA says provenance alone cannot tell you whether content is accurate. Trust depends on who signed.
- Do Content Credentials prove I own an image?
- No. OpenAI’s help page says provenance signals are not a guarantee that content is accurate, unedited, legally owned or shown in the right context. Ownership depends on copyright law and your tool’s terms; see who owns AI-generated images.
- Will platforms label my ad automatically?
- Sometimes. Meta and TikTok read C2PA and IPTC signals and can add their own AI labels, and LinkedIn shows a C2PA icon. If the metadata was stripped, they may not. Each platform’s ad rules are in the ad labeling guide.
- What is SynthID?
- Google DeepMind’s invisible watermark for AI content. Google embeds it in every image its Gemini API generates, and OpenAI’s help page says OpenAI images carry SynthID too. You can ask the Gemini app whether an image was made or edited with Google AI.
Where Overs fits
Overs exports each campaign with a record of the prompt, model and reference pictures behind every photo. Keep that record with the image files, next to whatever credentials the image model attached.
Free for 40 photos a month. The AI that makes the photos is billed separately, on your own key, with no markup from Overs.
Sources
- C2PA: Coalition for Content Provenance and Authenticity
- C2PA: About
- C2PA: Specification 2.2 explainer
- OpenAI Help Center: Provenance signals (Content Credentials, SynthID) in OpenAI-generated content
- Adobe: Generative AI User Guidelines (updated May 15, 2026)
- Google AI for Developers: Image generation with the Gemini API
- Google DeepMind: SynthID
- LinkedIn Help: Content credentials
- TikTok Newsroom: Partnering with our industry to advance AI transparency and literacy (May 9, 2024)
- Meta Newsroom: Our approach to labeling AI-generated content and manipulated media (updated September 12, 2024)
- IPTC: Digital Source Type vocabulary
- Google Merchant Center Help: Image link [image_link]
- California Legislative Information: Business and Professions Code, Division 8, Chapter 25 (AI Transparency Act)
- European Commission: Code of Practice on Transparency of AI-Generated Content (full text, PDF)
- EUR-Lex: Regulation (EU) 2024/1689, the Artificial Intelligence Act
- IAB: AI Transparency and Disclosure Framework V2 (August 2026, PDF)
- Content Authenticity Initiative: Verify