C2PA is an open standard for attaching a signed record of where an image came from to the image file itself. Content Credentials is the public name for that record. The letters stand for the Coalition for Content Provenance and Authenticity, the group that writes the specification, and the record it defines is called a manifest: a short statement of which software made the claim, what was done to the picture, and who signed it.
The signature matters more than anything else in it. Change one byte of the image after signing and the manifest no longer checks out.
What a manifest on a real AI image says
Specifications describe fields. It is easier to see them in a file, so here are two AI images from our own test set, read with ExifTool on 23 September 2026.
The first is a Google-made JPEG of 806,499 bytes. Its manifest takes 6,026 of them, under 1% of the file, in a single APP11 segment. The claim generator, the field that names the software writing the record, reads Google C2PA Core Generator Library. Two actions follow. The first is c2pa.created, with the description “Created by Google Generative AI.” The second is c2pa.edited, described as “Applied imperceptible SynthID watermark.” Both carry the digital source type trainedAlgorithmicMedia, the IPTC term for media produced by a trained model. After the assertions comes a hash of the rest of the file, and after that the signature itself, which C2PA builds with COSE and an X.509 certificate, the same certificate machinery that secures websites.
The second file is more interesting because it has a history. It carries two manifests. The earlier one was written by OpenAI Media Service API, names ChatGPT as the software agent with the version string gpt-image, and records three actions dated 20 September 2026: c2pa.created, c2pa.converted and c2pa.watermarked.unbound. The later one is Google’s again, with the same created and SynthID lines as the first file, and it lists the OpenAI manifest as an ingredient with the relationship inputTo. As we read it, a ChatGPT image went into a Google tool and came out carrying both records. Together they take 31,620 bytes, close to 5% of a 647,162-byte file.
That chain is the part of C2PA most explainers skip, and it is the part that makes it useful.
A manifest can say a picture started in one company’s generator and was changed in another’s, and each company signs only its own step. The fields worth reading, in the order we look at them:
- The claim generator, because it tells you who is making the statement.
- The actions, and any
digitalSourceTypeon them, because that is where “made by AI” is actually written down. - Ingredients, if there are any.
- The signature: who issued the certificate and when it was signed. Among its guiding principles, the specification says C2PA specifications “SHOULD NOT provide value judgments about whether a given set of provenance data is ‘good’ or ‘bad,’” so a valid signature proves the record is intact, and nothing about whether the scene happened.
One thing the OpenAI manifest does not tell you is which watermark it means. The action name says a watermark was applied. OpenAI announced in May 2026 that its images now carry SynthID, but the manifest itself doesn’t name it.
Where it sits in the file
In a JPEG the manifest goes in APP11 segments, in a PNG in a caBX chunk, and in a WebP in a chunk named C2PA. Each is a separate block from the pixels, which is why it can be deleted without touching the picture; the byte-by-byte version is in our guide to removing Content Credentials. Adobe also says Firefly credentials may be stored in its public Content Credentials cloud, so for those images a copy can exist away from the file.
Who writes it by default
OpenAI started in February 2024, signing DALL·E 3 images from ChatGPT and the API, with mobile following on 12 February. Google added C2PA to images from Nano Banana Pro (Gemini 3 Pro Image) in the Gemini app, Vertex AI and Google Ads in November 2025, and said more products would follow. Adobe Firefly applies Content Credentials automatically when the pixels are entirely Firefly-generated. Microsoft said in May 2023 that it would sign Bing Image Creator images to the C2PA standard. Midjourney went a different way: in May 2023 it committed to the IPTC Digital Source Type field, a plain metadata marker with no signature.
We don’t know whether images from the older Nano Banana model (Gemini 2.5 Flash Image) carry a manifest. Google’s announcement names only the Pro model, and we haven’t had a clean sample to check. Which tools write what is compared side by side in the generator-by-generator table.
Why a screenshot ends it
A manifest lives in the file, so anything that makes a new file without copying it across drops it. OpenAI said this itself when it launched: metadata like C2PA “can easily be removed either accidentally or intentionally,” and “actions like taking a screenshot can also remove it.” We saw the same thing with an ordinary re-save. Converting the 806,499-byte Google JPEG with macOS’s built-in sips tool gave a 267,546-byte JPEG with no manifest at all, and with the image data re-compressed.
The pixels are a different matter. A screenshot copies what the picture looks like, and an invisible watermark such as SynthID is part of what it looks like. So the record saying “SynthID applied” disappears while the mark itself can stay, which is the split the three-layer explainer is about.
C2PA’s answer is durable Content Credentials: pair the manifest with an invisible watermark and a fingerprint of the image, keep a copy of the manifest online, and look it up again when the embedded one is gone. The specification calls these soft bindings. We haven’t tested whether a stripped image of ours gets matched back to its manifest this way, and we haven’t found published figures on how often it happens.
The CR icon on LinkedIn
LinkedIn reads manifests and shows them. Its help page says image and video content “cryptographically signed using C2PA Content Credentials will be noted with the C2PA icon,” which most people know as the CR badge, and that clicking it shows details such as the app or device used, who issued the credential and when. Every viewer sees it. An AI image with no manifest gets no icon, which is the weakness of labelling from metadata.
Our view is that a manifest is strong evidence when it is there and no evidence at all when it isn’t. A platform that labels on metadata alone will miss every screenshot of an AI image, and it will also flag a real photo whose editor wrote an AI action into the record, because that is what the record says.
Sources
- C2PA Technical Specification 2.1 (claim generator, actions, signature)
- PetaPixel: DALL-E images now carry C2PA (8 February 2024)
- Google: AI image verification in the Gemini app (Nano Banana Pro and C2PA)
- Adobe: Content Credentials in Firefly
- PCWorld: Microsoft to sign Bing Image Creator images with C2PA (May 2023)
- IPTC: Midjourney and Shutterstock adopt the Digital Source Type field
- Content Authenticity Initiative: Durable Content Credentials
- LinkedIn Help: Content credentials
- PetaPixel: OpenAI adds SynthID to its images (20 May 2026)