What is C2PA? Content credentials and provenance for AI-made ads
By HyperKnown TeamPublished September 1, 2026
Every piece of AI-generated media now faces the same two questions: how was this made, and did anyone consent to it? Provenance standards answer the first, and C2PA has become the one the industry settled on. This piece explains what it is, where it is actually deployed in 2026, and how it connects to the consent side of AI advertising.
What is C2PA?
C2PA, the Coalition for Content Provenance and Authenticity, is an open technical standard for attaching verifiable metadata to media files stating how they were created and edited. The attached record is called a content credential. Founded by Adobe, Microsoft, Intel, Arm, the BBC and others, the coalition now includes Google, Sony, OpenAI, and most major camera and platform companies.
How do content credentials work?
A content credential is a cryptographically signed manifest that travels with the file. It records assertions: which device or tool created the media, whether AI generation was involved, and what edits were applied along the way. Each step in the chain adds its own signed entry, so the finished asset carries an inspectable history rather than a single claim. Anyone can check a credential with free tools such as Content Credentials Verify; a broken or missing signature is itself information.
The standard does not judge content. A credential on an AI-generated ad does not say the ad is good or true; it says, verifiably, that it was AI-generated, by which tool, and what happened to it afterward. That neutrality is why competitors as unlike as news agencies and generative-AI companies can share it.
Who has adopted C2PA?
- Cameras and phones. Leica shipped the first camera with built-in content credentials, and signing at capture has spread through professional bodies from Sony, Nikon, and Canon, plus recent Google Pixel phones and Samsung flagships.
- Creation tools. Adobe's Photoshop, Lightroom, and Firefly attach credentials, as do Microsoft's and Google's image-generation tools; OpenAI adds credentials to DALL-E and Sora output.
- Platforms. TikTok labels AI-generated uploads using C2PA data and has applied such labels to over a billion videos; YouTube, Meta, and LinkedIn read or surface content credentials on uploaded media.
- News organizations. The BBC, Reuters, AFP, and other major newsrooms sign output or run provenance pilots, since authenticity is their product.
- The spec itself. C2PA 2.3, released in December 2025, extended signing to live streams, closing one of the larger gaps.
Why does provenance matter for AI ads?
Because disclosure stopped being optional. Article 50 of the EU AI Act, applying since August 2026, requires AI-generated or manipulated media that resembles real people and could pass as authentic to be disclosed at first exposure, and major ad platforms run their own synthetic-media labeling rules. C2PA's AI assertions are the machine-readable way to carry that disclosure with the asset instead of bolting a caption onto each placement. The law map covers the full regulatory picture.
There is also a softer reason: retrieval. Answer engines and platforms increasingly prefer media whose origin they can verify. An ad with a clean provenance chain is legible to the systems deciding what to show and what to bury, and that legibility compounds as more of the pipeline signs its work.
What are the limits?
Provenance is young. Credentials can be stripped when platforms re-encode uploads, most phone cameras still do not sign at capture, and a file without a credential proves nothing either way. Signing infrastructure has had growing pains, including certificate incidents that paused individual implementations. The honest summary: C2PA tells you how signed media was made, coverage is expanding fast, and it is already the standard every regulation and platform policy points at, but it is a chain that is only as good as its weakest unsigned link.
How does provenance connect to likeness licensing?
Content credentials answer how media was made. A likeness license answers who agreed to appear in it. An AI ad with a real person needs both: the C2PA-style provenance record for disclosure, and the consent record proving the person authorized this specific use.
This is why HyperKnown treats rights documentation as a provenance problem. Every production starts from an identity-verified creator and a per-project approval, generating consent receipts and license records designed to sit alongside C2PA-style credentials, so a finished ad can answer both questions in a machine-checkable way. The brand workflow piece shows where those records come from.
Adoption facts checked September 1, 2026 against C2PA's published materials and platform announcements. The C2PA site tracks current members and spec versions.
Frequently asked questions
Is C2PA a watermark?
No. A watermark hides a mark inside the pixels or audio; a content credential is signed metadata attached to the file. The approaches complement each other, and some tools apply both, since watermarks survive metadata stripping and credentials carry far richer, verifiable detail.
Does C2PA prove content is real or trustworthy?
No. It proves how signed content was made and by what tool, verifiably. An AI-generated file with an honest credential passes verification; the credential simply tells you it is AI-generated. Judging the content remains the viewer's job.
Does a content credential satisfy the EU AI Act's disclosure rule?
It is the leading technical route to compliance, and the Commission's guidance points toward machine-readable marking. Deployers still need disclosure to be perceivable to viewers at first exposure, so platform labels or visible marks ride on top of the embedded credential.
Can content credentials record likeness consent?
The standard records provenance assertions about creation and editing rather than legal agreements, but the two are designed to travel together: a production's credential can reference the rights documentation held by the licensing platform, which is the model HyperKnown's consent receipts follow.
License verified real people
See how brands use HyperKnown to license real, consenting humans for AI-generated video.
For brandsKeep reading
The AI likeness law map: NO FAKES, ELVIS Act, right of publicity, EU AI Act
The key laws on AI use of a real person's face and voice, mapped by jurisdiction: state digital-replica statutes, the NO FAKES Act, and the EU AI Act's rules.
How brands get consent for AI-generated people: the compliant workflow
A step-by-step consent workflow for using real people's likenesses in AI-generated ads: what to document, which rules apply, and why stock avatar terms don't cover you.