Check where an image really came from.

A signed record of who made a file and how it changed. Useful, spreading fast, and easy to strip.

A wax seal pressed onto an envelope
Photo by SHAN LU on Unsplashdithered by Cyborb

Content credentials are a signed, tamper-evident record inside a photo, video or audio file. They say which camera, app or AI tool made the file, when, and how it was edited since. They are built on an open standard called C2PA, and you can check a file for free in about a minute.

The catch: C2PA content credentials prove where a file came from, not whether what it shows is true. And a missing credential proves nothing at all. This guide explains how they work, who supports them as of September 2026, how to check an image, and how they connect to the new AI labeling laws.

The short version
  • Content credentials are signed metadata, based on the open C2PA standard, that record a file’s origin and edit history.
  • Google’s Pixel 10 signs every photo it takes. OpenAI, YouTube, Getty Images and camera apps from Xiaomi and vivo are on the official conformance list.
  • You can check a file for free with the Verify site, Google Photos or the Gemini app.
  • Credentials are easy to lose. A screenshot or a re-upload can strip them, so a missing credential is not a sign of a fake.
  • New rules in the EU and California require machine-readable labels on AI content, and credentials are one common way to provide them.

What are content credentials?

Think of a tamper-evident seal plus a receipt. The seal shows whether the file changed after signing. The receipt shows its history, such as “captured on a Pixel 10” or “edited with an AI tool in Google Photos”.

The standard comes from the Coalition for Content Provenance and Authenticity (C2PA). Its steering committee members are Adobe, Amazon, the BBC, Google, Meta, Microsoft, OpenAI, Publicis Groupe, Sony, TikTok and Truepic. “Content credentials” is the friendly name for the data the standard produces.

Privacy is part of the design. The core standard records tools and edits, not the person behind the camera. Google goes further on the Pixel 10: each signing key is used for exactly one image, so the credentials cannot be used to link your photos to you or to each other.

Who supports C2PA content credentials in 2026?

Support has moved from pilots to shipping products. The clearest public record is the C2PA’s own conformance list, which names products that passed its checks for writing or reading credentials correctly.

219
conformance listings for products that write or read content credentials
C2PA, September 2026
128
companies and organizations behind those listings
C2PA, September 2026
3 billion+
pieces of content TikTok has labeled as AI-generated, using content credentials, watermarks and labeling tools
C2PA, July 2026

Here is where you are most likely to meet them.

WhereWhat happens
Google Pixel 10Pixel Camera signs every JPEG photo, at the highest security level the C2PA currently defines. Google Photos shows credentials and adds them to AI edits
Other phonesXiaomi and vivo camera apps, and Qualcomm’s Snapdragon 8 Elite Gen 5 chip, are on the conformance list
Apple iPhoneApple is not on the C2PA member list. The iPhone 18 Pro introduced Apple Reference Image, Apple’s own verified-photo system, in September 2026
AI generatorsOpenAI, several Google tools, Runway, Stability AI and Amazon Bedrock are listed. OpenAI also adds Google’s SynthID watermark to its images
Stock and mediaGetty Images and iStock have listings for AI-generated and AI-modified images. CBC/Radio-Canada is listed too
VideoYouTube’s processing systems are listed, and Sony’s PXW-Z300 camera records credentials during capture

Treat the list as a floor, not a ceiling. Some cameras and apps write credentials without appearing on it, and new products join most weeks.

How to check an image for content credentials

  1. Upload it to Verify

    Open Verify, the free tool from the Content Authenticity Initiative, and drop in the file. It accepts JPEG, PNG, WebP, HEIC, AVIF, TIFF, MP4, MOV, MP3, WAV, PDF and more. If credentials are present, you see who signed them, which tools were used, and the recorded edits.

  2. Use the apps you already have

    Google Photos shows content credentials in a photo’s About panel. In the Gemini app, you can upload an image and ask whether it is AI-generated. Gemini checks for Google’s SynthID watermark, and in May 2026 Google began adding C2PA checks there too, with Search and Chrome to follow.

  3. Check with the generator’s own tool

    If you suspect a specific AI tool, use its verifier. OpenAI’s public verification tool, launched as a preview in May 2026, checks whether an image or audio file came from ChatGPT, Codex or its API. It looks for both its content credentials and its SynthID watermark.

  4. Read the result carefully

    A valid credential tells you who signed the file and what they recorded. “No content credentials” tells you almost nothing, because most files online still have none. OpenAI’s tool, for example, makes no definitive call when it finds no signal.

What a credential proves, and what it does not

A valid credential tells you
  • Which camera, app or AI tool signed the file
  • When it was signed, and which edits were recorded
  • That the file has not been altered since signing
  • Whether an AI tool made or edited it, if that tool recorded it
It cannot tell you
  • Whether the scene is true, staged or taken out of context
  • Who stood behind the camera, unless they chose to add it
  • Anything at all once the credential is stripped
  • That an unlabeled file is fake

Credentials travel as metadata, and metadata is fragile. OpenAI says so plainly: it can be stripped, lost through uploads and downloads, or broken by format changes, resizing and screenshots.

The C2PA’s answer is durable credentials. An invisible watermark in the pixels, or a fingerprint of the content, lets a checker find the original record even after the metadata is gone. That is why OpenAI now pairs its credentials with a SynthID watermark.

A credential can also be honest about a lie. A real camera pointed at a staged scene produces a real credential. So the signer matters as much as the signature: a photo signed by a newsroom’s camera means more than one signed by an app you have never heard of.

Content credentials and AI labeling laws

Two sets of rules now push AI tools toward machine-readable labels, and content credentials are one common way to provide them.

  • The EU AI Act. Its transparency rules apply from August 2, 2026. Providers of generative AI must mark their output as AI-made in a machine-readable way, and deepfakes must be clearly labeled. Systems already on the market before that date have until December 2, 2026 to add the marking. Our EU AI Act guide for small builders covers who must do what.

  • California’s AI Transparency Act. Since August 2, 2026, generative AI services with more than one million monthly users must embed hidden disclosures, offer a visible label as an option, and provide a free detection tool. Fines are $5,000 per violation, and each day counts as a new violation.

California goes further in later years. Large online platforms must detect provenance data and show it to users from January 1, 2027. Makers of capture devices, such as cameras, must let users include these disclosures in what they capture, by default, from January 1, 2028.

For anyone who publishes AI images, the practical upshot is simple. Keep the credentials your AI provider adds, and make sure your own tools do not strip them.

If you publish images, keep the credentials

Publishing with provenance0 of 5

FAQ

Can content credentials be faked?

Changing a signed file breaks the signature, and checkers compare signing certificates against the C2PA trust list. But a real camera pointed at a staged scene produces a real credential. Credentials prove origin and history, so always ask who signed.

Does a screenshot keep content credentials?

No. A screenshot is a new file without the original metadata. A watermark such as SynthID can survive where metadata does not, which is why some providers now use both.

Does my iPhone add content credentials?

Apple takes a different route. It is not on the C2PA member list, and its support page for the new Apple Reference Image feature does not mention C2PA. Reference images are opt-in on the iPhone 18 Pro and Pro Max, and checking one needs Apple’s Photos app on iOS 27, iPadOS 27, macOS 27 or later.

Is a content credential the same as a watermark?

No. A credential is signed metadata that travels with the file and can hold a detailed history. A watermark is an invisible signal woven into the pixels or sound. It carries less information but survives more edits, so the strongest setups use both.

Do social networks show content credentials?

Some use them. TikTok labels AI content using content credentials, watermarks and other tools, and Google is bringing checks to Search and Chrome. Many sites still strip metadata on upload, so check the original file when it matters.

Next, learn how to spot a deepfake when there is no credential to check, or find out whether AI text detectors work at all.

Sources
  1. FAQs, C2PA
  2. Conformance program, C2PA
  3. Conforming products list, C2PA, September 2026
  4. Membership, C2PA
  5. C2PA welcomes TikTok to its steering committee, C2PA, July 2026
  6. How Pixel and Android are bringing a new level of trust to your images with C2PA Content Credentials, Google, September 2025
  7. Making it easier to understand how content was created and edited, Google, May 2026
  8. Advancing content provenance for a safer, more transparent AI ecosystem, OpenAI, May 2026
  9. Use Apple Reference Image to capture photos and verify they were taken on iPhone 18 Pro, Apple, September 2026
  10. The state of content authenticity in 2026, Content Authenticity Initiative, January 2026
  11. Verify, Content Authenticity Initiative
  12. New California AI disclosure rules become operative, Morgan Lewis, August 2026
  13. AB-853 California AI Transparency Act, California Legislative Information
  14. AI Act: regulatory framework for AI, European Commission
  15. Regulation (EU) 2026/1744 (Digital Omnibus on AI), EUR-Lex, July 2026
cyborb.ai

Stop reading about it. Build it.

Describe what you want in plain words. Cyborb plans the work, writes and runs the code, makes the assets, and puts the result online.

Download Cyborb

Free to start. No card required.