Provenance used to be an ethics conversation held after the work. It is becoming a procurement one held before it: platforms, broadcasters and an increasing number of client legal teams now ask what an asset carries, and answering "nothing" is a slower answer than it used to be.
What a manifest contains
A C2PA manifest is a cryptographically signed record embedded in the asset. It states which tool created it, what actions were performed, by which software, and — where the signer chooses — by whom. Each step is signed, so altering the file without re-signing makes the mismatch detectable.
The important property is tamper-evidence rather than tamper-proofing. Anybody can strip a manifest. What they cannot do is change the asset and keep a valid one, which means the absence of credentials is itself a signal in a world where their presence is common.
What it proves and what it does not
| C2PA CAN SHOW | C2PA CANNOT SHOW |
|---|---|
| Which tools touched the file, in order | That the content is true or accurate |
| That the file has not changed since signing | That an unsigned file is fake |
| That a generative step was declared | That an undeclared generative step did not happen elsewhere |
| Who signed, where an identity was attached | That the signer is honest |
| That an edit history is internally consistent | What was in the frame before it was photographed |
The right-hand column matters because credentials are frequently oversold. A manifest is a chain of custody. Chains of custody are extremely useful and they have never established that the thing in the evidence bag is what somebody claims it is.
Where it survives and where it does not
- Survives: editing in tools that implement the standard, export in supporting formats, delivery through platforms that preserve metadata.
- Does not survive: a screenshot, a re-encode by a tool that does not implement it, most social platform re-compressions, and anything that passes through a person’s phone.
- Partially survives: some platforms preserve the credential and surface it in an inspector; others preserve it in the file and display nothing.
The practical consequence is that credentials work well for asset delivery and business-to-business trust, and poorly as a consumer-facing signal in a feed. Anyone planning a campaign around consumers checking credentials is planning around a behaviour that does not exist.
Credentials, watermarking and disclosure are three things
They get collapsed constantly and they solve different problems.
Credentials sign the file’s history and are readable by software. Watermarking marks the pixels or the audio and survives some transformations that destroy metadata, at the cost of being either visible or statistically detectable rather than certain. Disclosure is a statement to the audience, in language, and is the one with legal weight attached.
A serious workflow uses all three for different reasons: credentials for the chain of custody, watermarking for what survives a screenshot, and disclosure because since August 2026 EU transparency obligations under Article 50 require it for synthetic content qualifying as a deepfake, and platform policy and advertising codes frequently require more.
Deciding at brief stage
- Ask whether the client, the platform or the broadcaster requires provenance. If any of the three does, it is a deliverable and it changes the toolchain.
- Check the toolchain end to end. One tool in the middle that strips metadata breaks the chain, and finding that out at delivery is expensive.
- Decide what identity is attached to the signature. A studio signature and a brand signature carry different implications and both are choices.
- Write the disclosure position at the same time, because they are decided together and only one of them is legally load-bearing.
- Record all of it in the deliverable specification, so nobody discovers the requirement during the final week.
Where provenance sits alongside the UK, EU and platform labelling positions, as one decision path per campaign.
THE DISCLOSURE CHECKLIST →