Metapeek

June 3, 2026

What Is C2PA? Content Credentials, Explained

As AI-generated images have become harder to distinguish from photographs at a glance, the industry has been converging on a metadata-based answer to a very old question: where did this image actually come from? C2PA — the Coalition for Content Provenance and Authenticity — is the leading standard trying to answer that.

What C2PA actually is

C2PA is a technical specification, backed by a coalition that includes Adobe, Microsoft, Intel, the BBC, and Sony, for embedding a signed, tamper-evident history of an image's origin directly into its metadata. Rather than a single "AI generated: yes/no" flag, a C2PA manifest can record a chain of actions — for example, "generated by model X," followed by "edited in application Y," each entry cryptographically signed by the tool that performed it. This is often marketed to end users as "Content Credentials."

Where it lives inside a file

Practically, a C2PA manifest is stored as a metadata block — commonly surfaced through or alongside XMP — embedded in the image file itself. This is exactly the kind of field an EXIF/XMP viewer can surface: if a file was produced by a C2PA-compliant tool, opening it in a metadata checker will show manifest data naming the responsible application or model, rather than leaving you to guess from indirect clues.

The current gap

Adoption is real but far from universal. Some major tools — including Adobe Firefly and some outputs from Microsoft's Bing Image Creator — do attach C2PA data. Many other generators, including a large share of open-source and lesser-known tools, currently attach nothing. And crucially, C2PA data, like any metadata, can be stripped intentionally or lost incidentally when an image is re-saved, screenshotted, or uploaded through a platform that discards metadata during processing.

The practical takeaway is asymmetric: finding C2PA or another explicit generator credential in an image's metadata is strong, verifiable evidence of its origin. Not finding any tells you very little on its own — it could mean a human-made photo, an AI image from a tool that doesn't support C2PA, or a C2PA-tagged image that was later stripped. Use the AI image metadata checker to look for these signals directly in a specific file.