Updated September 2026. Reading time: about 6 minutes. General information, not legal advice.
Here is a small experiment anyone can run. Take an AI-generated image that carries a full set of Content Credentials: signed manifest, trusted timestamp, everything done right. Upload it to Instagram. Download it back. Check it again.
The credentials are gone. Not damaged, not partially readable. Gone, along with the rest of the file's metadata, as if they had never existed.
Nothing malicious happened. Understanding why this occurs, and what survives it, explains half of the design of Europe's AI content rules, and it should change how any brand thinks about proving what it published.
Why platforms strip metadata
Every large platform re-processes what you upload. Images are resized, recompressed and converted to the platform's preferred formats, so they load fast on a phone in a lift with one bar of signal. When a platform rebuilds the file, it typically writes a fresh one and carries over the pixels, not the baggage. Camera details, GPS coordinates, editing history: stripped, partly for bandwidth, partly for user privacy, and that policy long predates AI.
The C2PA manifest lives in that same layer of the file. So when re-encoding drops the metadata, the entire signed record goes with it, however carefully it was created. The signature does not break loudly. It simply is not there anymore.
The same fate arrives through more everyday routes: converting a JPG to PNG in the wrong tool, a screenshot (a screenshot is a brand-new image of your screen, born with no history), or a messaging app compressing a photo before sending. As of September 2026, several of the largest social and messaging platforms strip metadata on re-encode, while a smaller group preserves provenance data or displays a badge when credentials are present.
What survives: the layer that lives in the pixels
This is exactly why the EU's Code of Practice refuses to rely on one technique and requires two layers. The second layer, the invisible watermark, is a signal woven into the pixels themselves. It has no separate compartment to be stripped from: wherever the image goes, it goes.
A robust watermark survives recompression, resizing, format conversion and, in many cases, even a screenshot, because the screenshot reproduces the pixels and the signal rides on them. It carries far less information than a manifest, typically enough to say "AI-generated, by this provider's system" rather than a full signed history. But it is still saying it after the manifest has died.
The two layers are not redundancy. They are a division of labour: the manifest is the strong proof while it lives; the watermark is the survivor that keeps answering after distribution has done its worst. What is inside a manifest, and why its signature matters, is covered in our C2PA explainer.
So is everyone's compliance broken?
No, and this is the point most coverage gets wrong. The marking duty in Article 50 applies at generation and publication: the provider must ensure outputs are marked, and the publisher must label deepfake-class content visibly. Neither is responsible for what third-party platforms do to files afterwards, and the law's own drafters knew perfectly well that metadata does not survive distribution. That knowledge is visible in the framework itself: it is why the watermark layer is required, and why providers must offer detection services that can answer "is this yours?" even for a stripped file.
What the stripping problem does change is what you should keep. If the public copy of your image carries no manifest, your proof of having done things properly is your own record: what you exported, when, with which marks. The companies that will answer a regulator's letter in one page are the ones whose platform kept that record for them.
What a brand should take from this
- 1. Do not treat the manifest in your published file as your evidence. Treat it as a courtesy to whoever receives the file intact. Your evidence is the record at export.
- 2. Ask your image platform which of its marks survive re-encoding, and how anyone can check a stripped file. If the answer is only "we embed C2PA," you now know the question they have not answered.
- 3. Remember that your visible-label duty is untouched by any of this. A label on the image survives every re-encode by definition. It is the one disclosure no platform can strip.
The full legal picture, including who carries which duty and when, is in our Article 50 guide.
What we are testing next
General statements about "platforms" only go so far, and behaviour genuinely differs between them. In October we will publish something more useful: a tested, dated survival matrix showing what happens to each marking layer on each major platform, one by one. If you want the short version now: assume the manifest dies in distribution, assume a good watermark lives, and build your records accordingly.




