JournalAI & Society

Field guide / 6

Content Credentials can verify an image's history. They cannot tell you it is true

C2PA can verify a signed chain of provenance, but it cannot decide whether the scene, caption, or claim is true. Here is how to read the signal without overtrusting it.

Sep 3, 20266By ISH Team
Content Credentials can verify an image's history. They cannot tell you it is true
Advertisement

Content Credentials can verify an image's history. They cannot tell you it is true

Imagine a photograph arrives with a neat green badge. Its Content Credential is valid. The signature checks out, the pixels match the signed record, and the publisher appears on a trust list. What does that prove?

Quite a lot about the file. Much less about the event shown inside it.

That distinction matters as provenance systems move into cameras, editing software, newsrooms, and social platforms. C2PA 2.4, published in April 2026, added a JSON-derived representation for testing and reporting, repository receipts, and an environmental sustainability assertion. In July, the coalition published new guidance for identifying synthetic and non-synthetic content. Implementation is advancing. The way we read the results needs to catch up.

Follow the chain, not the badge

A Content Credential is a provenance record bound to a digital asset. Its manifest can carry assertions about where an asset came from, which tools changed it, what ingredients went into it, and whether AI was involved. Cryptographic hashes connect the record to the file. A digital signature lets a validator check whether the signed claims were altered and which credential signed them.

A verifier can therefore ask specific questions. Is the manifest well formed? Does the file still match its binding? Does the signature validate? Is that signer trusted under the selected trust list? Which edits and ingredients were disclosed?

These are checks of integrity and attribution. They are not fact-checks. The C2PA explainer says provenance information alone cannot establish whether digital content is true, accurate, or factual.

A credential may show that a known newsroom signed a photograph after a crop and colour adjustment. It cannot establish that the caption interprets the scene correctly. It cannot reveal a staged event outside the frame. It cannot prove the claimed location simply because someone signed a location assertion. Cryptography can expose tampering with a claim. It cannot make the claim honest.

“Valid” has several layers

The interface problem is familiar. People often read a browser padlock as “this site is safe,” although TLS mainly protects a connection and authenticates an endpoint. A Content Credentials badge can suffer the same fate: a complicated signal gets flattened into a verdict.

Four separate questions sit behind that reassuring mark:

  1. Is a credential present?
  2. Is it cryptographically valid for this asset?
  3. Is the signer trusted by the validator's trust policy?
  4. Have the signed claims been corroborated outside the credential?

The credential system can answer the first three. The fourth requires reporting, investigation, or domain knowledge.

The reverse mistake is to distrust every file without a credential. C2PA is opt-in, and the coalition warns against treating unsigned media as false by default. Credentials can also disappear when a platform strips metadata or a file passes through software that does not preserve it. Soft bindings, including watermarks or fingerprint lookup, may reconnect an asset to a remotely stored manifest, but only where the relevant systems support discovery.

A five-step check for journalists and readers

When a disputed image or video carries Content Credentials, use them as the start of the investigation.

  1. Open the validation details. Do not stop at an icon. Look for hash mismatches, signature failures, unsupported fields, partial interpretation, and the trust status of the signing credential.
  2. Read the assertions. Record the stated creation method, tools, edits, ingredients, timestamps, and AI-related source types. Note what is missing as carefully as what is present.
  3. Identify the signer. A valid signature from an unfamiliar source proves continuity from that source. It does not supply a reputation.
  4. Test the story against the world. Check time, place, landmarks, weather, shadows, people, earlier uploads, and the frames before and after a clip. Seek evidence independent of the asset and its publisher.
  5. Keep the original. Screenshots, transcoding, and social-media downloads can remove or break provenance data. Preserve the source file and its hash whenever the evidence may matter later.

NIST's report on synthetic-content transparency makes the broader point: provenance tracking, watermarking, labels, and synthetic-media detection complement one another, but their value depends on robustness, adoption, and whether people understand the signals. No single method settles the truth of a piece of media.

Build interfaces that show their work

Developers should expose the four states separately: credential present, asset valid, signer trusted, and claims corroborated. A plain-language details panel is more useful than a badge that silently merges them.

Validation also needs room for uncertainty. C2PA 2.4 says older implementations should, where practical, preserve a manifest's integrity when they encounter unknown constructs and indicate partial interpretation instead of failing without explanation. A product that hides “partially understood” behind “verified” discards information its users need.

Publishers can strengthen the evidence by keeping provenance intact across capture, editing, and publication. Adding a manifest only at final export may still identify the publisher, but a documented chain gives an investigator more testable history. Originals matter too. If a platform strips metadata or a later edit breaks the binding, the newsroom should still be able to produce the signed source.

For teams handling media through api.ish.chat, a credential can be one structured input in a larger review pipeline. Source checks, forensic tools, retrieval, and human judgment still have jobs to do. The same habit of separating evidence from conclusion runs through our source-reading methodology and our examination of the people omitted from AI provenance records.

A signed evidence bag, not a ruling

The strongest promise for Content Credentials is the narrower one. They can make parts of a file's history portable, tamper-evident, and inspectable. They can help establish who signed what and whether it changed afterward. That is valuable infrastructure.

Treat a valid credential like a sealed evidence bag. Check the seal, read the inventory, establish who packed it, and then investigate the event it claims to contain.

Primary sources

#C2PA#Content Credentials#media literacy#synthetic media#provenance
Advertisement

Keep reading

Related stories

Browse the archive