Guide
Strategy
Both
Content Credentials is C2PA's name for signed metadata that records how an image or video was made and edited — including whether AI was involved. Platforms like TikTok and Meta read that metadata on upload to automatically detect and label AI content, but it's a voluntary technical standard, not law, and it's distinct from the EU AI Act's legal labeling duty. The honest limitation: most platforms strip the metadata itself from the file even while using it to apply their own label first.
Content Credentials is the name C2PA (the Coalition for Content Provenance and Authenticity) gives to signed metadata that records how an image, video or audio file was made and edited — including whether AI was involved, which tool did it, and when. Platforms like TikTok and Meta read that metadata at upload and use it to automatically recognise and label AI-generated content, with no action required from whoever posted it. It's important to keep this distinct from the EU AI Act's Article 50: C2PA is a voluntary technical standard built by an industry coalition, not the law itself — and, as covered below, most platforms actually strip the credential back out of the file even while using it to apply their own label first.
C2PA is an open technical standards project run under the Joint Development Foundation, a US-based non-profit. It formed in February 2021, when Adobe's own Content Authenticity Initiative (CAI) — started in 2019 to promote transparency about digital content — merged with Microsoft, the BBC and Truepic's parallel effort, Project Origin. The result was one shared technical specification instead of two competing ones.
The technical core is a "manifest": a block of cryptographically signed metadata embedded directly in the file itself (typically inside a JUMBF container) that can record which device or application created the file, what edits were subsequently made, the timestamp, and — the part most relevant here — whether an AI tool was involved in generating or altering the content. Because the manifest is cryptographically signed, it can in principle be verified independently of wherever the file ends up, using a tool such as C2PA's own "Verify."
It's a common mistake to treat "AI labeling" as one single thing. In practice there are two separate layers that often work together but aren't identical:
| C2PA / Content Credentials | EU AI Act, Article 50 | |
|---|---|---|
| What is it? | A voluntary, technical industry standard for metadata | Binding EU law |
| Who's behind it? | A coalition of technology and media companies (see below) | The EU legislature (the European Parliament and the Council) |
| Who has to comply? | No legal duty — it's up to each platform or tool whether to implement the standard | Providers and deployers of AI systems, per Article 50 |
| What happens if it's ignored? | Nothing legal — at worst the standard loses relevance if too few adopt it | Fines of up to €15 million or 3% of global turnover |
| How do they relate? | Can be used as the technical means of meeting Article 50(2)'s machine-readable marking requirement | Doesn't itself specify which technical standard must be used for that marking |
In other words: a company can satisfy Article 50's machine-readable marking requirement using C2PA metadata — but C2PA exists and is used entirely independently of EU law too, because platforms like TikTok found it useful to adopt long before Article 50 took effect.
Per C2PA's own website (checked 26 August 2026), the coalition's steering committee has eleven named members: Adobe, Amazon, the BBC, Google, Meta, Microsoft, OpenAI, Publicis Groupe, Sony, TikTok and Truepic. TikTok was most recently promoted to the steering committee on 27 July 2026, having previously been a general member — per C2PA's own announcement, TikTok will now help "guide the technical development and scale content provenance standards worldwide." Beyond the steering committee, both C2PA and Adobe's affiliated Content Authenticity Initiative describe a much broader circle of member organisations, but independent sources don't agree on the precise total — some cite a few hundred, others several thousand, depending on whether CAI's wider membership is counted in. That figure is deliberately not repeated here as a settled fact.
TikTok announced on 9 May 2024 that it had become the first video-sharing platform to implement C2PA's Content Credentials technology — per its own announcement, this let the platform "instantly recognize and label" AI-generated content (AIGC) as the metadata became more widespread across the industry. TikTok has since upgraded to full steering-committee membership (27 July 2026) and states it has labeled over 3 billion videos as AI-generated using a combination of Content Credentials, self-serve labeling tools and invisible watermarking. TikTok's own Symphony ad-creation suite goes a step further and automatically applies its own "AI-generated" label to everything it produces — see TikTok Symphony explained for the details.
Meta announced in February 2024 that it would use "industry standard AI image indicators" — in practice, embedded metadata such as C2PA and the related IPTC format — to recognise and label AI-generated image content across Facebook, Instagram and Threads. From 1 July 2024, Meta consolidated its own labeling under the name "AI Info," while a separate "Imagined with AI" label is used specifically for photorealistic images made with Meta's own AI features. Meta itself joined C2PA's steering committee in September 2024. The practical result: an ad or post can end up labeled as AI-generated even if the person who posted it never disclosed that themselves — because Meta reads the metadata automatically at upload, as covered in the synthetic UGC ads article.
Adobe has built Content Credentials into Photoshop since 2021 (including via generative fill), and per C2PA-affiliated sources, both Google (the Pixel 10 phone, August 2025) and Sony (the Camera Verify system for select cameras, June 2025) have built in support on the capture side — meaning the metadata can be added at the moment a photo or video is created, not only when AI later edits it.
The most practically useful thing to know about Content Credentials is also the part rarely mentioned: most major social platforms strip the C2PA metadata back out of the file when content is uploaded and recompressed into the platform's own format — even while using that same metadata to apply their own visible label before it's removed. The US think tank RAND Corporation addressed this directly in a June 2026 analysis, "Overpromising on Digital Provenance and Security": C2PA's success depends on the entire chain — from capture to display — consistently honouring the standard, which RAND argues is unrealistic in an open ecosystem where most platforms recompress all uploaded content for technical and bandwidth reasons.
In practice: if you upload a photo with intact Content Credentials to Instagram, Instagram can show a label based on the metadata it read at upload — but if another user then downloads that same photo from Instagram, the signed, verifiable metadata is gone. The evidence rarely survives the journey user-generated content typically takes across platforms and reshares — exactly the situation where an independent, verifiable source would be most valuable. C2PA-affiliated researchers (including Collomosse et al., published in IEEE Computer Graphics and Applications) are working on technical fixes — invisible watermarks and "perceptual fingerprints" designed to survive even when the metadata itself is stripped — but that remains active research, not a finished, widely deployed solution in 2026.
IF you use an AI editing tool that supports C2PA (Photoshop's generative fill, for example) → the metadata is added automatically, but don't assume it survives a later upload to Instagram, Facebook or X — see the limitation above.
IF you need to prove to a third party that an image or video is genuine (not AI) → keep the original file with its intact Content Credentials manifest somewhere outside the platform, rather than relying on the platform's own copy.
IF you're unsure whether your content will be auto-labeled by Meta or TikTok → assume it might be, regardless of whether you disclosed it yourself, because both platforms read metadata automatically at upload.
IF you need to satisfy a legal disclosure duty (Article 50, for example) → don't treat a platform's automatic, C2PA-based label as sufficient on its own. Work through the decision framework in the Article 50 article instead — that's a separate legal assessment.
In our view, the important point for a brand isn't whether a platform can technically detect AI content via C2PA — it's that you shouldn't treat a platform's automatic labeling as your only compliance documentation. Whether content gets labeled depends on whether the tool that made it supports the standard at all, and on whether the platform reads and displays it correctly — two links in the chain no brand controls. Our recommendation is to treat your own, active disclosure of AI use as the default, and a platform's automatic C2PA-based labeling as a backstop, not the other way round. This is our operational view, not a claim that C2PA is useless.
C2PA (the Coalition for Content Provenance and Authenticity) is the coalition and the standard. Content Credentials is the name for the actual signed metadata the standard defines and embeds in a file.
No. C2PA is a voluntary technical standard; Article 50 is binding law. C2PA metadata can be used to satisfy the technical side of Article 50(2), but the law doesn't specifically require C2PA, and C2PA doesn't replace a deployer's own disclosure duty under Article 50(4). See the Article 50 article.
No. Per repeated independent research and RAND Corporation's June 2026 analysis, most major platforms, including Instagram and X, strip the signed metadata on upload, even while using it to show their own label first.
No — C2PA isn't a legal duty you have to comply with. What you do need to manage is your own disclosure duty under applicable law (Article 50 or ordinary ad-disclosure rules, for example); C2PA is a technical layer some of your tools and the platforms you use may support in the background.
They're related but not identical. Symphony applies its own visible "AI-generated" label directly to its own output; C2PA is the underlying, more general metadata standard TikTok also uses to recognise AI content from other sources. See TikTok Symphony explained.
Make Influence's platform and tracking model is built for collaborations with real creators, not for generating or verifying AI content. We follow developments around C2PA because it's relevant to the brands and creators we work with, but it isn't a technology we implement in our own tracking.
Make Influence
Find creators with real audience data, run collaborations in one place, and see clicks and sales per creator while the campaign is live.
Book a demoCreate accountMake Influence
Apply to campaigns from brands that are actively looking, follow your own clicks and sales, and get paid without chasing invoices.
Create creator profileMore creator guidesMake Influence
Briefs, agreed terms, tracking links and results sit together — so brands and creators see the same numbers.
See how it worksBrowse the Academy