Human art or AI art? Here is what a file can actually prove.
Image Passport
Can a file prove a person made it? The tech people point to is Content Credentials, a signed record that travels inside the file, like a passport. Make one, see where it breaks, then check your own images.
1Make a picture with a passport
Pick who made it, sign it, then do what happens to pictures online. Watch the verifier on the right.
Step 1 Β· Who made it?
Step 2 Β· Sign it
Step 3 Β· Then it goes online
Verifier
Stamps, oldest first
What was actually signed
2What a passport can and can't prove
A label proves where a file came from and how it changed. A missing label proves nothing.
Each app that edits the file adds a signed step and points to the version before it.
The signature covers a hash of the image. Change one pixel without re-signing and the check fails.
Screenshots, many uploads and older apps drop the passport. Most real photos online have none.
It proves who holds the signing key. Trust comes from who issued that key, which is why your own key shows a warning.
3Check your own image
Drop a JPEG, PNG or WebP. It reads Content Credentials, checks the signature and the pixel hash, and lists other clues like camera EXIF or AI generator settings. The file stays on your device.
Or try a sample from the C2PA test files
Result
4If you make art
Small things that keep your proof alive.
Export with credentials on
Some editors and cameras can add Content Credentials when you export or shoot. Then your file starts with a signed first stamp.
Keep and share the original
A screenshot or a recompressed upload is a new file with no history. Put the original somewhere you control, like your own site, and keep your layers and drafts.
The fix being built: soft binding
C2PA also defines an invisible watermark or a fingerprint that points to a stored copy of the passport, so it can be found again after a screenshot strips the file.
Sources
- C2PA, the Content Credentials standard and the specification
- IPTC Digital Source Type vocabulary
- Sample files: contentauth/c2pa-rs test fixtures, MIT or Apache 2.0