When anyone can generate a photo, a receipt or a "scanned" letter with AI, the useful question changes from "is this real?" to "where did this come from?" Content Credentials, built on the open C2PA standard, are the industry's main answer. Camera makers, Adobe, Google, Microsoft, OpenAI and others now attach or read them, and the EU AI Act's transparency rules have pushed provenance labelling further into the mainstream.
What a Content Credential is
A Content Credential is a signed record, attached to a file, that describes its history:
- Which device or software created it.
- Whether AI generation was involved.
- What edits were made and with which tools.
- Who signed the record (for example, a camera maker or a news organisation).
The record is cryptographically signed, so tampering with it is detectable. Anyone can inspect it with a verification tool such as the Content Credentials inspector.
What it proves and what it does not
Content Credentials prove that this record was signed by this party and the file has not changed since. They do not prove that the content is true. A signed photo can still show a staged scene.
Equally important: the absence of a credential proves nothing. Most files in the world have none, and many platforms strip metadata on upload. Credentials are useful positive evidence, not a fake detector.
Images today, documents next
C2PA started with images and video, and that is still where it is most common. Support for documents is growing:
- The C2PA specification covers PDFs, and some tools can attach manifests to them.
- Document workflows already have a mature, related tool: digital signatures, which prove who signed a PDF and that it has not changed since. See digital signatures vs electronic signatures.
In practice, for a contract or certificate, a digital signature is still the provenance mechanism to look for. For a photo embedded in a report or a scanned receipt, C2PA is the emerging one.
How to check a file
- Upload or drag the image to a Content Credentials verification site, or use a tool that shows them (some photo apps and browsers do).
- Look at the signer and the edit history.
- If AI generation is declared, that is your answer.
- If there is no credential, fall back to other checks: source, context, metadata and common sense. See how to detect tampered PDFs.
Should you add credentials to your own documents?
If you publish photos, reports or official documents that others need to trust, it is worth watching your tools for C2PA support. For everyday business documents, a digital signature remains the practical choice, and keeping originals archived as PDF/A gives you something to compare against.
Takeaway
Content Credentials are a nutrition label for files: useful when present, silent when absent. Use them as one signal for images, rely on digital signatures for documents, and keep checking the source. For the fraud side, see AI-generated fake receipts.