Blog

C2PA metadata: what AI provenance tags reveal about images

C2PA metadata: what AI provenance tags reveal about images

A new metadata block is appearing on photographs and AI-generated images: a C2PA metadata manifest, signed cryptographically, recording where the image came from, what software produced it, what edits have been made to it, and whether any part of it was generated or modified by an AI model. The Coalition for Content Provenance and Authenticity (C2PA) standard is now embedded in Photoshop, in Adobe Firefly, in Google's Pixel cameras, in Microsoft's Bing image search, in OpenAI's image outputs, and in a growing list of stock libraries and news organisations. Understanding what it actually contains, and what it leaks, is now part of normal image hygiene.

What a C2PA manifest holds

A C2PA manifest is attached to an image as a JUMBF box (a standard container format) inside the file. For JPEGs and HEIC, that is a separate metadata block alongside EXIF. For PNGs, it is an iTXt chunk. For PDFs and MP4 video, it sits in equivalent positions.

The manifest contains assertions: structured statements about the image. The standard set includes:

  • c2pa.actions: every edit performed since the manifest was created — cropping, colour correction, AI generation, AI inpainting, AI upscaling, format conversion. Each action is timestamped.
  • c2pa.ingredients: any source images or models used to produce this one. AI-generated images list the model (Stable Diffusion XL 1.0, DALL-E 3, Firefly Image 3) and, optionally, the prompt.
  • c2pa.creator: the human or organisation that produced the image, if claimed. This can be a verified identity (a press credential, a Truepic identity, an Adobe account) or anonymous.
  • c2pa.thumbnail: a small preview, baked in. Useful for verifying the manifest applies to the visible image; less useful when the thumbnail itself preserves an earlier draft you did not mean to share.
  • Hash of the image bytes, signed by the producer's certificate. Any tampering with the image after the manifest is created breaks the signature, but does not remove the manifest.

What it tells the world

For a press photographer using a C2PA-enabled camera, the manifest is a feature: it certifies that this image came out of this camera at this time, was edited by this software, and has not been altered since. Newsrooms increasingly require it for submissions. Stock libraries verify it on upload.

For everyone else, the same manifest is a small dossier. It tells the recipient:

  • That the image was generated by AI, even if the generator removed obvious tells.
  • Which AI model produced it.
  • What prompt was used, if the producer chose to embed it (some platforms do this by default).
  • That the image was retouched in a specific application, on a specific date.
  • That an earlier version of the image was different in specific ways — even if the manifest does not store the earlier image itself, the action log records the operations.
  • The verified identity of the producer, if attached.

A photograph posted to social media as "straight out of camera" with a C2PA manifest showing twelve edits in three different applications loses that claim immediately for any reader who checks. An AI-generated image submitted to a contest that prohibits AI work is identifiable to any judge with a C2PA reader extension installed.

What is not yet settled

C2PA is moving fast and three things are unresolved.

Stripping versus tampering

Removing a C2PA manifest is not tampering — it is just removing the manifest. The image stays valid; it simply no longer carries the provenance. Some platforms now flag images that arrive without a manifest where one would be expected, but most do not yet. Whether that becomes the norm is a policy question, not a technical one.

Privacy of the producer

A signed manifest can be linked to a real identity. For some workflows that is the point. For others — a journalist photographing a source, an activist documenting a protest, a private person editing a photo for a personal site — an attached identity is a leak. The standard supports anonymous producers, but most consumer applications default to identifying ones.

Embedded prompts

Some AI image generators embed the prompt the user supplied into the manifest. For a publishing workflow that is helpful auditability. For a casual user who wrote a prompt they did not want a stranger reading, it is a leak nobody flagged.

What to do with C2PA-tagged files

If the manifest is part of the value of the image — press attribution, stock-library certification, AI disclosure — keep it. If it is not, strip it. C2PA manifests can be removed in any tool that re-emits the image without copying the JUMBF block forward. The cleaner on the homepage strips C2PA alongside EXIF, IPTC and XMP, and shows you what the manifest contained before it removes it. For most personal use of AI-generated images, that visibility is what people are missing: the manifest answers questions about your image you did not realise it could be asked.

Provenance is a useful tool when you are claiming credit for a piece of work. It is a quiet liability when the file is meant to speak for itself.