How to Check an Image’s Content Credentials: A 6-Step Media Provenance Check

When an image looks suspicious, “Does it look AI-generated?” is usually the wrong first question. A better question is: Can I verify where this file came from and what happened to it?

Content Credentials, based on the C2PA standard, are designed to provide tamper-evident provenance information for digital media. They can record information about creation, editing, tools, and other parts of an asset’s history. But they do not, by themselves, prove that what an image depicts is true.

1. Look for the Content Credentials indicator

The Content Credentials pin signals that provenance information is available for a piece of content. On a supported site or application, opening that indicator can reveal information such as how the asset was created and what edits were recorded.

If there is no visible indicator, do not conclude that the image is fake. C2PA adoption is optional, and valid media can exist without Content Credentials.

2. Use a verifier when you have the original file

If you can obtain the actual image file, use a Content Credentials verifier such as the verification tool linked from ContentCredentials.org. A validator can inspect the asset’s C2PA data and perform checks on the manifest, signature, assertions, and content bindings.

Whenever possible, verify the original downloaded file rather than a screenshot. Screenshots, platform re-encodes, and other transformations may remove or separate provenance information.

3. Check who or what signed the credential

A valid credential is not automatically a trustworthy claim. Check the signer and the product or service that generated the credential. C2PA’s trust model depends on cryptographic validation plus the consumer’s judgment about the signer and the information being asserted.

C2PA also operates a Conformance Program and Trust List for products and certificate authorities that meet its requirements. Those signals can help you assess the implementation behind a credential.

4. Read the creation and edit history carefully

Do not stop at a green or valid status. Read the available provenance details. Depending on the credential, you may see creation actions, editing actions, the tools involved, or information indicating whether generative AI was used.

C2PA’s 2026 guidance describes machine-readable ways to distinguish content that was generated, modified, or otherwise processed with AI. The exact information available still depends on what the signer chose to include and what the workflow preserved.

5. Treat missing credentials as “unknown,” not “fake”

Metadata can be stripped intentionally or accidentally. C2PA supports mechanisms such as soft bindings, including watermarking or fingerprinting, that can help rediscover associated provenance data in some workflows. Even so, absence of a credential is not proof of manipulation.

The safest label for an image with no verifiable provenance is often simply: provenance not established.

6. Separate provenance from truth

This is the most important step. Content Credentials can help establish facts about an asset’s origin, history, and integrity. They cannot determine whether the scene itself is accurate, whether a caption is misleading, or whether an event happened as claimed.

After checking provenance, verify the underlying claim separately. Compare the image with reliable reporting, official records, original context, timestamps, locations, or other independent evidence appropriate to the claim.

A compact provenance checklist

  1. Indicator: Is a Content Credentials signal present?
  2. File: Can you inspect the original asset rather than a screenshot?
  3. Validation: Does a verifier successfully validate the credential?
  4. Signer: Who or what signed it, and is that source meaningful to you?
  5. History: What creation, editing, or AI-use information is actually recorded?
  6. Gaps: Are there missing steps or stripped provenance?
  7. Truth check: Does independent evidence support the real-world claim?

The key rule: provenance can strengthen your evidence about a file’s history, but it is not a substitute for fact-checking.

Sources

Fact-check date: September 27, 2026.

Language: English · 한국어 · 日本語 · Deutsch