9 October 2026International edition
Vol. I · No.
9 October 2026
AI in Fashion
DAILY
The daily briefing on AI in the fashion business
Where fashion meets artificial intelligence.
Design & Product · Stories

Content credentials and C2PA explained for fashion imagery

C2PA is an open standard for embedding tamper-evident metadata in images to prove provenance and disclose AI use. Brands can label generated or edited imagery using Adobe tools or conformant software.

camera studio set up
Photo: Alexander Dummer / Unsplash

KEY TAKEAWAYS Summary by the editors

  1. C2PA version 2.4 was released in April 2026 and supports widely used image formats including JPEG, PNG, TIFF and WebP.
  2. As of May 2026, 54 products from 31 companies have passed C2PA conformance, including Adobe, Google and OpenAI tools.
  3. Since 2 August 2026, the EU AI Act requires a disclosure label on AI-generated or AI-changed images.
  4. Providers must mark AI outputs with at least two machine-readable techniques, such as digitally signed metadata plus imperceptible watermarking.

What is C2PA and how does it work?

C2PA stands for Coalition for Content Provenance and Authenticity, a project of the Joint Development Foundation, an affiliate of the Linux Foundation. Content Credentials are cryptographically signed metadata structures that provide a verifiable record of a digital asset's provenance and modification history. C2PA was founded in February 2021 by Adobe, Arm, BBC, Intel, Microsoft and Truepic.

The C2PA standard for Content Credentials is currently on version 2.4, released in April 2026. Version 2.4 introduced a new AI disclosure assertion for machine-readable AI transparency information. The technical specification defines how to create, embed and verify manifests that record who created content, what tools were used, whether AI was involved and every edit since capture.

For images, the specification supports widely used formats including JPEG, PNG, TIFF and WebP. An assertion is a data structure representing a statement made by the signer concerning the asset, and forms part of the C2PA manifest. The specification lists 20 standard assertions that can be used in a manifest.

Who supports C2PA in 2026?

Members and supporters include Google, Meta, OpenAI, Sony, Nikon and Leica, while the Content Authenticity Initiative that promotes the standard reported more than 6,000 members in January 2026. Steering committee members include Adobe, Amazon, BBC, Google, Meta, Microsoft, OpenAI, Publicis Groupe, Sony, TikTok and Truepic.

The C2PA conformance programme launched on 4 June 2025, and since its launch 54 products from 31 companies have passed conformance as of 14 May 2026. The C2PA Interim Trust List remained operational through 31 December 2025, and on 1 January 2026 the interim list was frozen with no new entries added.

How can brands label generated or edited images?

Fashion brands can attach Content Credentials to imagery using conformant software. Adobe has integrated Content Credentials across its creative tools, including Photoshop, Lightroom and Firefly. Users enable Content Credentials in the Preferences panel in Lightroom and can attach their name, social media handle and list of edits via a digital signature when exporting a JPEG.

Storage methods include publishing to Content Credentials cloud, attaching to files or attaching and publishing to cloud. Content Credentials are supported in all file formats except PSD and PSB. In Photoshop, users select Window then Content Credentials (Beta) and select Enable Content Credentials.

Verification is available via verify.contentauthenticity.org, a free, publicly available verification tool that accepts uploaded files and displays their Content Credentials. The tool indicates whether credentials are present, valid and trusted.

What do EU transparency rules require?

Since 2 August 2026, the EU AI Act (Regulation EU 2024/1689) requires a disclosure label on AI-generated or AI-changed images under Article 50. Article 50 says that any AI-generated or AI-changed image that could look real must carry a machine-readable disclosure that is easy to detect, with the rule starting on 2 August 2026.

On 17 December 2025, the European Commission published the first draft of the Code of Practice on marking and labelling AI-generated content, a voluntary code establishing technical standards for watermarking and detecting synthetic media ahead of the transparency obligations becoming legally binding on 2 August 2026. As no single technique currently ensures compliance with Article 50(2), the Code requires providers to mark AI outputs with at least two machine-readable techniques, such as digitally signed, tamper-evident metadata plus imperceptible watermarking.

The Commission has finalised three EU icons, for fully AI-generated content, for AI-modified content and a basic icon supplemented by an interactive second layer. Normal editing is exempt, meaning colour correction, cropping and background cleanup on a real photographed product, while fully AI-generated product scenes, fake models and AI-invented backgrounds need a machine-readable label.

What are the limits of C2PA?

Content Credentials are not foolproof. A validator working from an outdated trust list may display manifests signed with revoked credentials as valid, and independent testing published in April 2026 found the same image labelled valid by one tool and invalid by another. You are not prevented from changing an image that has Content Credentials, but if you do, the credentials are no longer valid unless you change it using a tool that updates and re-hashes the credentials.

Many platforms and tools strip embedded metadata during upload or export. When credentials are removed, verification tools cannot detect whether an image originally carried a manifest. The system relies on voluntary adoption by creators, publishers and platforms, and images created before C2PA adoption or outside conformant workflows carry no provenance data at all.

Where can brands verify Content Credentials?

The primary verification method is verify.contentauthenticity.org, where users upload a file and the tool indicates whether Content Credentials are present and whether they are valid or trusted. Valid means the Content Credential is cryptographically intact and neither it nor the digital content has been tampered with, but the signer may not be on the C2PA Trust List, while Trusted means the Content Credential is intact and the signer is on the C2PA Trust List.

Google says SynthID verification has reached Gemini and is expanding to Search and Chrome, with C2PA Content Credentials verification rolling out in Gemini, Search and Chrome. In 2025, the C2PA launched a standardised icon, a small "cr" symbol, that platforms can display alongside content carrying valid credentials.

Frequently asked questions

Can C2PA Content Credentials be removed from an image?

Yes. Content Credentials are embedded metadata that can be stripped when an image is re-saved in non-conformant software, uploaded to platforms that remove metadata or exported in formats that do not support manifests. Adobe offers an option to publish credentials to a cloud repository alongside embedding them in files to provide a recovery path when embedded copies are stripped.

Does the EU AI Act require all fashion brands to label AI-generated images?

Since 2 August 2026, the EU AI Act requires a disclosure label on AI-generated or AI-changed images under Article 50. Normal editing such as colour correction, cropping and background cleanup on real photographed products is exempt, while fully AI-generated product scenes, fake models and AI-invented backgrounds need a machine-readable label.

Which cameras support C2PA Content Credentials at capture?

The Leica M11-P, released in late 2023, was the first camera in the world to embed C2PA Content Credentials at capture. Sony joined with the Alpha 7 V, released in December 2025, and the Alpha 7R VI, released in June 2026. Canon introduced a C2PA-compliant Authenticity Imaging System in May 2026. As of August 2026, no Fujifilm camera signs at capture, and Panasonic Lumix firmware updates through 2026 have not included C2PA.

Researched and drafted with AI support, reviewed and released by the editorial team.

EN DE FR IT

Stories