AI How to spot AI generated text, images and video
Content Credentials: the provenance label on a picture
What C2PA Content Credentials are, what the little label on an image actually proves, where the chain breaks, and how to check a file yourself.
The short answer
- A Content Credential is a signed history attached to a file, listing the tool that made it and the edits applied, and it proves the file has not changed since that signature.
- It says nothing about whether the scene is real: a genuine camera photographing a fake on a screen produces a perfectly valid credential.
- A missing credential means nothing, because screenshots, re compression and unsupporting editors strip the data routinely.
- You check one by clicking the pin icon on the image, or by dropping the original file into a verification tool that shows the signer and the listed actions.
- Adoption covers some cameras, editors, generators and platforms rather than all of them, so treat a credential as useful extra information rather than a test any file should pass.
A Content Credential is a signed record that travels inside a file and says where the file came from: which camera or app produced it, when, and what has been done to it since. When you see the small "cr" pin on a picture, clicking it opens that record. What it proves is narrow and specific: that this exact set of pixels matches a history signed by a particular piece of software, and that nothing has changed since the signature. What it does not prove is that the scene in the photograph happened.
That gap between the two is where almost every misunderstanding lives, so it is worth knowing exactly what is inside one of these labels and how far you can lean on it.
What is actually inside a Content Credential
The underlying technology is called C2PA, published by an industry coalition of camera makers, chip makers, software companies and news organizations, and it is working its way through formal standards bodies. Content Credentials is the name used in the interface. A credential is a manifest embedded in the file, and it has three parts.
- Assertions. The individual statements. The capture device model, the date and time, a thumbnail, whether a generative tool was involved, and a list of actions taken: cropped, color adjusted, object removed, generated from a prompt. Location and creator identity can be included, but they are optional and often left out on purpose.
- A binding to the pixels. A cryptographic hash of the file content. Change one pixel and the hash no longer matches, so the credential reports as broken rather than quietly describing a different image.
- A signature. The whole bundle is signed with a certificate belonging to the tool or the organization that created it, in the same general way a website certificate works. A validator can check that the signature is intact and see who issued the certificate.
When an image is edited, the editing tool does not overwrite the old manifest. It records the earlier file as an ingredient and adds a new signed manifest on top. A file can therefore carry a chain: captured by this camera, opened in that editor, this generative fill applied, exported here. That chain is the whole point.
What it proves and what it does not
A signature answers one question: did the named signer really make these statements about this exact file, and is the file unchanged since. It cannot answer whether those statements are true about the world.
| Question | Can a Content Credential answer it? | Why |
|---|---|---|
| Has this file been altered since it was signed? | Yes | The hash of the pixels is covered by the signature |
| Which tool exported it, and what edits were listed? | Yes, as claimed by that tool | The manifest lists the actions and who signed them |
| Was a generative model involved? | Usually, if the tool participates | Generators that support this add an assertion saying so |
| Is the scene in the picture real? | No | A real camera can photograph a screen, a print or a staged event |
| Is the caption accurate? | No | Nothing in the manifest describes what is happening in the frame |
| Who took it? | Only if an identity assertion was added and verified | Most credentials name a device or an app, not a person |
| Does the absence of a credential mean AI? | No | Most files everywhere carry no credential at all |
That last row is the one people get wrong most often. Provenance data is an assertion you can gain, never a test you can fail. The same asymmetry undermines every automated shortcut in this area, which is why a detector score cannot substitute for it either, as explained in why a detector percentage is not evidence.
Where the chain breaks
Metadata is fragile in ways most people never think about, and the credential is metadata.
- Screenshots. A screenshot is a new file made of pixels on a screen. It carries no history of the thing it captured. This is how the majority of images travel online, and it destroys provenance completely.
- Re encoding on upload. Platforms resize, recompress and strip metadata to save bandwidth. Some now preserve and display credentials, many do not, and messaging apps are the worst offenders.
- Tools that do not participate. Open a credentialed image in an editor with no support, save it, and the record is gone with no warning.
- Deliberate removal. Anyone who wants the credential gone can strip it in seconds. There is no protection against this and there was never meant to be.
- A truthful signature over a false scene. Photograph a convincing fake on a monitor with a credentialed camera and you get a genuine, valid credential attached to a lie about reality.
The partial answer to stripping is a second, invisible layer: a watermark in the pixels plus a perceptual fingerprint registered in a searchable store, so a validator can look up a file that lost its metadata and recover the original manifest. This survives compression and cropping better than metadata does, though heavy editing still defeats it.
How to check a file yourself
- Look for the pin icon in the corner of the image, in the platform or app displaying it. Clicking it shows the summarized history.
- If there is no icon, get the original file rather than a screenshot of it. Ask the sender for the file as it left their camera or app, or download it directly instead of copying the image out of a page.
- Drop that file into a public verification page run by the coalition behind the standard, or into any editor that supports credentials. You will see the signer, the listed actions and whether the signature validates.
- Read the actions, not just the presence of the badge. "Created using a generative model" and "composited from two images" are the interesting entries, and they sit inside the detail view rather than on the badge.
- Check who signed it. A credential signed by an unknown organization is worth much less than one signed by a camera maker or a known publisher, and a validator will tell you if the certificate does not chain to a recognized list.
- For raw detail, a command line metadata tool will show the embedded provenance block directly, which is useful when you want to see the whole manifest rather than a friendly summary.
When the file has no credential, which will be most of the time, you are back to ordinary judgment about the image itself and about who is showing it to you. The practical checks for that are in how to tell whether an image was generated by AI, and for a clip in circulation, what still gives away AI video. Provenance and judgment work best together: one tells you about the file, the other tells you about the picture.
Why the standard matters beyond fakes
Spotting fakes is the headline use, but the quieter uses may matter more. A newsroom can show readers that a photograph came out of a staff camera and was only cropped and color corrected. A stock library can record that an image was generated rather than shot, which changes what a buyer is allowed to do with it and connects to the messy question of what copyright covers in AI output. A photographer can attach a machine readable statement of authorship and preferences about training use to their work, though whether anyone honors that is a separate matter from whether the file records it.
It also gives generator makers a way to mark their own output. Many image tools now write a credential saying a model was involved, which is more honest and more durable than hoping people recognize the giveaways in the way image generators build a picture. If you publish that output commercially, the credential is also a record of what you used, which matters for the disclosure questions in using AI images legally.
What to do with this today
Treat credentials as a bonus, not a workflow. Adoption is partial: some cameras and phones sign captures, some editors maintain the chain, some platforms display the pin and many strip it. You will meet far more files without credentials than with them for years yet.
Three habits are worth forming now. When an image matters, ask for the original file rather than the version that has been through three chat apps, because the original is the only copy that can still carry a history. When you publish your own work, keep credentials switched on in the tools that offer it, since it costs you nothing and gives the next person something to check. And when a picture is being used to prove a claim, remember that the strongest evidence is usually not in the file at all: it is whether other people photographed the same event from other angles, which is the reasoning set out in how to check a viral claim before passing it on.
Common questions
What does the cr icon on an image mean?
It means the file carries a Content Credential you can open. Clicking the pin shows a summary: the app or device that signed it, the date, and the actions recorded, including whether a generative model was used. The icon only tells you a record exists. You still have to read the record, because a credential can perfectly well say that the image was generated from a prompt.
Does a photo without Content Credentials mean it is AI generated?
No, and treating it that way will mislead you constantly. The overwhelming majority of images online have no provenance data, either because the device never added any or because it was stripped along the way. Screenshots, social uploads and messaging apps remove it as a matter of routine. Absence is the normal state, not a warning sign.
Can Content Credentials be faked or removed?
Removing them is trivial and anyone can do it. Forging one is much harder, because the manifest is signed with a certificate and a validator checks both the signature and whether the issuer is recognized. The realistic attack is not forgery but honest signing of dishonest content: pointing a credentialed camera at a screen showing a fake produces a valid credential.
Do screenshots keep Content Credentials?
No. A screenshot creates a new image from what was on your display, with no connection to the original file, so the entire chain is lost. If provenance matters, obtain the original file from the source or download it directly rather than capturing what you see. This is the single most common way credentials disappear in everyday use.
How do I add Content Credentials to my own photos?
Look for the setting in the tools you already use. Some recent cameras can sign images at capture, and several editing and publishing applications offer a credentials option that records your edits and, if you want, a verified identity. Once it is on, keep your workflow inside applications that support the standard, because a single save in one that does not will drop the chain.