Content Credentials Prove Capture, Not Authorship
Francis Okafor
On this page
- A manifest is a chain of custody, not a claim about truth
- Who ships Content Credentials hardware in 2026
- The pug in the jet
- The second product is a costume
- Douyin ships both products in one interface
- The strongest objection: this protects institutions, and signed images still lie
- What nobody is selling
- Tools referenced
- Sources
The Authors Guild will sell you a certification mark for ten dollars. Since 2 March 2026 any author published in the United States can register a book as Human Authored, pay the fee and put the badge on the copyright page. Members pay nothing. The criterion is narrow and unusually well drafted: the text was written by people, except for a de minimis amount such as spellcheck. Research with a model is fine. Outlining with a model is fine. Generating the prose is not.
Ten dollars. That is one end of this market. At the other end sits a Leica M11-P at $9,195, the first production camera to write Content Credentials into the JPEG before it reaches the card. Both are sold as proof of human. They are not the same product, and the gap between them is the whole argument.
A manifest is a chain of custody, not a claim about truth
A C2PA manifest is a bundle of assertions bound to a cryptographic hash of the file's bytes and signed by a certificate. Assertions can record the capture device, a claimed or trusted timestamp, and a list of actions: placed, cropped, colour adjusted. Ingredient assertions link back to earlier manifests, so an edit history becomes a chain rather than a single stamp.
The specification has matured fast. Version 2.3 is dated 5 January 2026, version 2.4 is current, and the version 2 family has been fast-tracked toward ISO 22144 as a draft international standard. JPEG Trust already absorbed version 1 into ISO/IEC 21617-1:2025. On 1 January 2026 the old Interim Trust List froze, replaced by the C2PA Conformance Program with graded assurance levels for generator products, validator products and certificate authorities. The Content Authenticity Initiative passed 6,000 members by January 2026.
Read the specification instead of the press release and the claim is modest. This signer, holding this certificate, asserts that these bytes have this history. That is worth a great deal in a newsroom intake queue. It is not the thing most people think they are buying.
Point a signed Leica at a 4K monitor displaying a generated render and you get a cryptographically perfect photograph of a lie.
Who ships Content Credentials hardware in 2026
Leica went first, announcing the M11-P on 26 October 2023 with a secure chipset holding a trusted certificate. Sony has shipped signing across Alpha bodies and put Content Credentials into the PXW-Z300 video camera. Canon enabled C2PA on the EOS R1 and EOS R5 Mark II, then on 11 May 2026 announced its Authenticity Imaging System, a managed service that issues photographer certificates centrally and applies trusted timestamps, rolling out first across Europe, the Middle East and Africa. Reuters did the technical testing.
The most consequential move was Google's. The Pixel 10, launched August 2025, signs every JPEG that leaves Pixel Camera. Signing keys are generated and held in the Titan M2 security chip, the cryptography runs in the Tensor G5 image pipeline, and Pixel Camera was certified at Assurance Level 2, the highest the Conformance Program currently defines. On-device trusted timestamps mean an image stays verifiable after the certificate expires, even if the phone was offline at capture.
Notice the shape of that list. Secure elements, managed certificate authorities, silicon in the image signal path. This is capital equipment and platform infrastructure. It is not a ten dollar badge, and it never will be.
The pug in the jet
In early September 2025 the researcher Adam Horshack found that the Nikon Z6 III's in-camera multiple exposure function would combine an AI-generated image with a real frame and sign the composite. The proof of concept was a pug flying a fighter jet, carrying a valid signature. Nikon suspended its Authenticity Service on 5 September 2025 and subsequently revoked every certificate it had issued. Images signed during that window are no longer usable as provenance.
The cryptography did not fail. The camera signed what the sensor pipeline handed it, which is precisely what it promised to do. The promise was just far narrower than the word authenticity implies.
This is the fault line the whole category is built on. Proving where a file came from and proving that a person made the decisions are different problems with different solutions. Point a signed Leica at a 4K monitor displaying a FLUX render and you get a cryptographically perfect photograph of a lie. Every validator in the world will pass it. That is not a bug in C2PA. It is the boundary of what a signature over bytes can mean.
The second product is a costume
Where cryptographic provenance is absent, and it is absent almost everywhere, the fallback is a classifier guessing from pixels or token statistics. That guess is soft, and softness creates a market.
There is a small MIT-licensed project on GitHub called deai-image, last updated 23 February 2026, three stars, no company behind it. Its pipeline has seven stages: strip EXIF and C2PA metadata, add film grain, shift colour, blur then sharpen to disturb DCT coefficients, resize, recompress as JPEG, clean up residue. It claims 35 to 45 percent success on light settings and 65 to 80 percent on heavy against detectors including Hive and Illuminarty. Read that list again. Every stage is a deliberate injection of flaw.
On the text side the same idea is a subscription business. Undetectable AI currently runs from $5 a month billed annually for 10,000 words up to $21.25 a month for 50,000. Dozens of competitors sit in the same $8 to $16 band. What they sell is perplexity. Detectors flag text that is statistically too smooth, which is also why Liang and colleagues found in 2023 that seven detectors misclassified an average of 61.3 percent of TOEFL essays by non-native English writers as machine-generated. The humanizer adds hedges, ragged sentence lengths and the occasional retained typo.
So the second product is not proof of human. It is the aesthetic of human, sold by the month. Manufactured imperfection, priced below the cost of a cinema ticket.
Douyin ships both products in one interface
Since 1 September 2025, China has required both. The Measures for Labelling of AI-Generated Synthetic Content and the mandatory standard GB 45438-2025 oblige providers to attach an explicit visible label and an implicit machine-readable one. I read the standard in Chinese rather than in summary, and the detail that stays with me is what the implicit label carries: the service provider's code, a content identifier and a generation timestamp. There is no field for a person. The regime marks the machine, deliberately and completely.
The result is visible in any Shenzhen commute. Scroll Douyin and you will meet two different strings. When the platform reads a valid implicit label it shows 作品含AI生成内容, this work contains AI-generated content. When its own detector fires on content with no metadata it shows 疑似使用了AI生成技术,请谨慎甄别, suspected use of AI generation technology, please judge carefully. One is a read. The other is a guess. Same feed, same font, and almost nobody notices which one they are looking at.
Europe reached the same split from the opposite direction. Article 50 of the AI Act became applicable on 2 August 2026, requiring providers of systems generating synthetic audio, image, video or text to mark outputs in a machine-readable format, with a Code of Practice confirmed as an adequate compliance route.
None of it survives contact with how people actually move images. Forward a photo through three WhatsApp groups in Lagos and it arrives recompressed, downscaled and metadata-free. Instagram and X strip credentials on upload. LinkedIn and TikTok preserve them. Provenance dies at the first re-encode, and re-encoding is what the internet does for a living.
The strongest objection: this protects institutions, and signed images still lie
The sharpest critique of C2PA is not technical. It is about who the system is for. The World Privacy Forum's September 2025 analysis by Kate Kaye and Pam Dixon documents it carefully. Trust lists are governed by the entities large enough to sit at the table, and the C2PA steering committee is Adobe, Amazon, BBC, Google, Intel, Meta, Microsoft, OpenAI, Publicis Groupe, Sony and Truepic. C2PA's own harms modelling concedes that manifests may carry sensitive information, that at-risk creators can be exposed by metadata, and that government-issued certificates could be used to persecute journalists. Identity assertions were pulled out of the core specification in January 2024 and pushed to a separate working group for exactly these reasons.
The engineering objections are just as serious. In April 2026 Golaszewski, Krawetz, Sherman and colleagues published the first independent formal-methods analysis of C2PA and concluded that the specifications fail to meet their claimed security goals. Timestamps can be replaced without detection. Conforming validators frequently skip revocation checks, and more than six months after Nikon's revocation the researchers found Adobe Inspect still reporting a revoked signature as valid while another validator called it invalid. Data placed in exclusion ranges, including GPS, is unprotected. Certificates expire well inside ordinary legal retention windows.
All of it stands. Two answers, neither of them comfortable. First, chain of custody has always been institutional. A signed image can be a lie in exactly the way a notarised affidavit can be perjury, and nobody proposes abolishing notaries. Provenance narrows the space of undetectable fraud. It was never going to close it.
Second, the institutional bias is a governance decision rather than a property of signatures. Nothing in the manifest format requires a trust list curated by eleven companies. An independent photographer in Kano can self-sign today. What she cannot do is get any validator to treat her certificate as meaningful. The asymmetry is not cryptographic. It is social, and it is the part nobody is funding.
What nobody is selling
Both products dodge the demand that actually exists. Nobody wants to verify a hash. What people want is to be believed without argument, and that has never been a technical property. It used to be a property of institutions that were expensive to counterfeit: a masthead, a byline, a wire desk that would fire you for staging a frame.
Cryptographic provenance rebuilds a thin slice of that at the level of the file. Manufactured imperfection sells the appearance of it for five dollars a month. The uncomfortable arithmetic is that the second market is currently larger, cheaper to enter and much better at closing.
Which leaves one detail worth sitting with. The Authors Guild mark has a property the Leica does not. It is a legal assertion attached to a name. Register a book as Human Authored when a model wrote the prose and you have signed a falsehood, with no secure element involved and no validator to fool. Enforcement is a lawsuit, not a signature check. It may turn out that the cheapest proof of human anyone has built is simply the willingness to be sued for lying about it.
Tools referenced
FLUX, reviewed here: FLUX review.
Runway, reviewed here: Runway review.
Wan 2.2, reviewed here: Wan 2.2 review.
Qwen-Image, reviewed here: Qwen-Image review.
ElevenLabs, reviewed here: ElevenLabs review.
ChatGPT, reviewed here: ChatGPT review.
Sources
C2PA Conformance Program and trust list transition: https://c2pa.org/conformance/
Google: Pixel and Android bring C2PA Content Credentials to images: https://blog.google/security/pixel-android-trusted-images-c2pa-content-credentials/
Canon introduces C2PA-compliant Authenticity Imaging System, 11 May 2026: https://global.canon/en/news/2026/20260511.html
PetaPixel: Nikon suspends C2PA functionality on the Z6 III: https://petapixel.com/2025/09/05/nikon-suspends-c2pa-functionality-on-the-z6-iii-due-to-authentication-issue/
Golaszewski et al., Verifying Provenance of Digital Media: Why the C2PA Specifications Fall Short (arXiv, April 2026): https://arxiv.org/html/2604.24890v1
World Privacy Forum: Privacy, Identity and Trust in C2PA: https://worldprivacyforum.org/posts/privacy-identity-and-trust-in-c2pa/
Authors Guild expands Human Authored certification to all US authors: https://authorsguild.org/news/human-authored-certification-expands-to-all-authors/
China: Measures for Labeling of AI-Generated Synthetic Content (translation): https://www.chinalawtranslate.com/en/ai-labeling/
Frequently Asked Questions
What do Content Credentials actually prove?
Content Credentials, defined by the C2PA specification, prove that a specific signer holding a specific certificate attested to a set of assertions bound to a cryptographic hash of the file's bytes. Those assertions can cover the capture device, a claimed or trusted timestamp, and a recorded list of edit actions. They do not prove that a human made the creative decisions, that the scene in front of the lens was real, or that the content is true. A camera with C2PA enabled will sign a photograph of a screen displaying an AI-generated image, and that signature will validate correctly.
Which cameras and phones sign photos with Content Credentials in 2026?
The Leica M11-P, announced on 26 October 2023 at $9,195, was the first production camera to embed a C2PA manifest at capture. Google's Pixel 10, launched in August 2025, signs every JPEG produced by Pixel Camera, with keys held in the Titan M2 security chip and the app certified at C2PA Assurance Level 2. Canon enabled C2PA on the EOS R1 and EOS R5 Mark II and announced its managed Authenticity Imaging System on 11 May 2026, rolling out first in Europe, the Middle East and Africa. Sony ships Content Credentials on Alpha bodies and the PXW-Z300. Nikon shipped C2PA on the Z6 III in 2025, then suspended the service in September 2025 and revoked every certificate it had issued.
Can Content Credentials be stripped or faked?
Stripping is trivial. Re-encoding, screenshotting or uploading to a platform that rewrites images removes the manifest, and C2PA treats absent credentials as unknown rather than as evidence of manipulation. Instagram and X strip credentials on upload, while LinkedIn and TikTok preserve them. Faking is harder but demonstrated: in September 2025 a researcher used the Nikon Z6 III's in-camera multiple exposure function to merge an AI-generated image with a real frame and obtain a validly signed file. A April 2026 security analysis by Golaszewski and colleagues additionally found that timestamps can be replaced without detection and that conforming validators often skip certificate revocation checks, so revoked signatures can still display as valid.