
- 01C2PA is the de facto cryptographic content-provenance manifest. Adoption now spans major camera makers, image editors, generative AI platforms, and browser preview surfaces.
- 02A C2PA manifest carries producer identity (signed), capture / generation context, every editing operation applied, and a cryptographic chain across them.
- 03C2PA proves chain of custody. It does NOT prove the content depicts the truth. A genuine photo of a staged event still carries an authentic chain. Communicate accordingly.
- 04Action this year: if you produce or transform media, attach C2PA. If you consume media, expose provenance metadata to users. Customers will start asking by Q3.
The Coalition for Content Provenance and Authenticity (C2PA) defines a cryptographic provenance manifest that travels with media. Cameras, image editors, generative AI tools, and increasingly browsers can attach and verify these manifests.
What a C2PA manifest contains
- 01Producer identity (signed, tied to a verifiable credential)
- 02Capture or generation context (device, model, time, location if permitted)
- 03Editing operations applied (cropped, color adjusted, AI-edited regions)
- 04Cryptographic chain across the operations
What it does not give you
It does not prove a piece of content is true; it proves the chain of custody. A genuine photo of a staged event still carries an authentic C2PA chain. Plan messaging accordingly — provenance is necessary but not sufficient for trust decisions.
What to do this year
If your product produces or transforms media, attach C2PA manifests. If your product consumes media, expose provenance metadata to users. The interoperability story is converging fast and your customers will start asking by Q3.

