What Is C2PA? Content Credentials Explained for Fashion Teams

Back to blog
Table of contents

Updated September 2026. Reading time: about 7 minutes. General information, not legal advice.

If you have read anything about AI image rules in Europe, you have met the acronym: C2PA. It appears in vendor decks, in compliance memos, in every serious discussion of how AI content gets marked. And yet most explanations are written by engineers for engineers. This one is written for the people who buy, commission and publish fashion imagery, because you do not need to implement C2PA to work with it. You need to understand what it proves, what it does not, and what to ask of the platforms that implement it for you.

Where this fits in the bigger picture: C2PA is the main technology behind the machine-readable half of the EU's two-disclosure system. The legal framework around it is covered in our complete Article 50 guide.

The idea in one sentence

C2PA attaches a signed, tamper-evident statement to a media file that says what the content is, who vouches for it, and when. That is the whole concept. Everything else is the machinery that makes such a statement trustworthy.

The name stands for Coalition for Content Provenance and Authenticity, the industry body behind the open standard. You will also see the consumer-facing name Content Credentials: same technology, friendlier label. The standard is not owned by any single vendor, and the major AI developers, camera makers and software companies participate in it. That neutrality is precisely why regulators and procurement teams treat it as the reference.

What is actually inside a manifest

The signed statement travels inside the file in a block called a manifest. One file, one manifest. Opening it up, a manifest holds three kinds of information.

  • Assertions: what this content is and how it came to be. For an AI image: that it was generated or modified by an AI system, and by which one. The standard allows richer detail, such as the tool and the type of operation, but does not force it. What a given platform chooses to include varies, which is worth asking about.
  • A signature: a cryptographic signature from the organisation vouching for those assertions. The signature is made with a certificate issued by a certificate authority, the same kind of infrastructure that secures websites. If a single pixel or metadata field changes after signing, verification fails and the tampering is visible.
  • A timestamp: an independent proof of when the signature was made, issued by a timestamp authority. This matters more than it sounds: it is what keeps a manifest verifiable years later, after the signing certificate itself has expired.

The trust list, or why some marks verify and others do not

Anyone can technically sign a file. What makes a signature meaningful is whether verification software trusts the certificate behind it. C2PA maintains trust lists: the sets of certificate authorities and timestamp providers that conforming verifiers accept. A manifest signed outside those lists will show up as untrusted or simply fail to verify, no matter how well-formed it is.

For a fashion team, this turns into one concrete procurement question: is your platform's signing certificate anchored in the C2PA trust infrastructure, and can they show you a file that verifies in a public, independent checker? A yes with a demonstration is worth more than any paragraph in a sales deck.

What C2PA proves, and what it does not

C2PA can proveC2PA cannot do
That a specific organisation vouched that this content is AI-generatedDetect AI content that nobody marked in the first place
That the file has not been altered since signingSurvive every platform: re-encoding often strips metadata, manifest included
When the statement was made, independently of anyone's wordIdentify who is behind unmarked or stripped content
A verifiable chain when edits are properly recordedGuarantee legal compliance by itself: visible labelling is a separate duty


The right-hand column is not a list of flaws. It is the reason the EU's framework layers techniques instead of trusting one: the invisible watermark exists because metadata gets stripped, and the visible label exists because humans do not read manifests. C2PA is the strongest layer for proof, not a force field.

Why this standard, and not something simpler

Plain metadata fields saying "AI-generated" have existed for years and cost nothing. The problem is that anyone can write them, anyone can remove them, and nothing reveals the removal. The EU's Code of Practice describes the marking layer as signed and timestamped attestation, and unsigned metadata cannot meet that description: there is no one vouching, nothing tamper-evident, no independent time. C2PA is, today, the only open standard with a real certificate infrastructure, public specifications and an ecosystem of verifiers behind that requirement. That is why it keeps appearing in every serious conversation, even though no law names it.

Five questions to ask any image platform

  • 1. Do your exports carry a C2PA manifest by default, or is it something we must switch on?
  • 2. Is your signing certificate anchored in the C2PA trust infrastructure, and are your timestamps from a trusted authority?
  • 3. What do your manifests actually assert: system name, provider, timestamp, operation type?
  • 4. What happens to the marks after our own edits and after platform re-encoding, and what survives?
  • 5. How can we, or a regulator, or anyone, verify one of your files independently?

A platform that answers all five in writing is treating provenance as infrastructure. A platform that answers none is treating it as marketing. The difference will matter the day someone asks you to prove how an image was made.

Next in the series: what happens to these marks when an image meets the real internet. The answer explains half of the EU's regulatory design.

How would you rate this article