Content Credentials (C2PA) and Watermarks: What Provenance Labels Can and Cannot Prove
What C2PA content credentials and watermarks actually prove about a file's origin, their structural limits, and why they do not replace source verification.
Content Credentials and Watermarks: What They Prove
Stop before you share. If a video or image has already made you angry or afraid, that is the moment to pause. A C2PA content credential or a digital watermark is not a silver bullet that proves an image is real. What a content credential proves is much narrower: it proves that a chain of editing software recorded the steps used to create or modify a file. If every tool in the pipeline, camera, editor, export filter, supports the C2PA standard, you can see a timestamped log of what happened. But the label says nothing about whether the person, event, or scene depicted ever existed. A fully synthetic image of a politician shaking hands with a foreign leader can carry perfect C2PA metadata showing it was made in Photoshop. That metadata is true. The editing record is genuine. The handshake never happened.
What the C2PA Standard Actually Records
The Manifest Inside the File
The Coalition for Content Provenance and Authenticity (C2PA) publishes a specification, version 1.4 as of 2024, that defines how to embed a manifest in a media file. That manifest is a machine-readable log. It records the identity of the signing party, a device maker, a software vendor, or a platform, the time of signing, and a hash that links the manifest to the exact bytes of the file. When you open an image in a C2PA-aware viewer, you see a credential that lists every action taken with a compliant tool. Crop. Filter. Export settings. This is the chain of custody for the digital file itself.
But note what is not in the manifest: the content of the scene, the intent of the editor, or the truth of the depicted event. The C2PA record is a statement about how a file was processed, not about what the world looked like when the shutter clicked. Adobe Firefly has embedded content credentials in every output since 2023, and Photoshop has supported them since version 25.0 in September 2023. OpenAI added C2PA metadata to DALL-E 3 images in February 2024 and to Sora video outputs later that year. Meta began labelling AI-generated images on Facebook, Instagram, and Threads in April 2024 using C2PA credentials plus its own internal classifiers. None of these companies claim the credential verifies the factual accuracy of the scene. They claim it records the editing history.
- C2PA spec version: 1.4 (2024)
- Supported media types: JPEG, PNG, AVIF, HEIF, WebP, SVG, PDF, MP4, M4A, WAV (10 types)
- Adobe Firefly C2PA: All outputs carry credentials (2023, present)
- OpenAI DALL-E 3 C2PA: Added 2024-02-08
- OpenAI Sora C2PA: Embedded in video outputs (announced 2024-02-15)
- Meta AI labelling: Started 2024-04-05, using C2PA and internal classifiers
- Google 'About this image': Launched 2023-05-10, displays C2PA metadata when present (2024)
- Adobe Photoshop C2PA: Available since Photoshop 25.0 (2023-09)
What a Content Credential Cannot Prove
The Gap When the Label Is Missing
Here is the limit that matters: a content credential only exists if every tool in the chain wrote it. If you take a photo with a camera that does not support C2PA, or open it in an older version of software that never heard of the standard, the file has no credential. The absence of metadata proves nothing. An open-source generative model like Stable Diffusion embeds no C2PA data at all by default. A user can generate a photorealistic deepfake and the output arrives with zero provenance information. The label is not lying. It is absent. An absent label is not a verdict of authenticity, and it is not a verdict of fakery. It is a gap in the record.
How a Credential Gets Stripped
Even when a credential is present, it can be stripped. Cropping an image, resaving it in a non-compliant format, or compressing it through a social media upload can remove the manifest entirely. A screenshot of a C2PA-verified image does not carry the original metadata unless the screenshotting tool preserves it, which most do not. The realistic failure case is not a clever attacker forging a credential. It is a mundane copy-paste that erases the credential. You can be looking at a picture that was once properly credentialed and now shows nothing, with no way to know the difference.
Digital Watermark Detection Limits
How Watermarks Work and Break
Digital watermarks are a different mechanism but share the same structural weakness. Google DeepMind's SynthID, released for image and audio in 2023 and extended to text and video in May 2024, embeds an imperceptible pattern into AI-generated content. The watermark is not visible to the eye, but a detector can read it. The watermark only works if the generating model applies it. An open-source model without SynthID produces no watermark, and a free tool that wraps a commercial API may not enable watermarking. You cannot reverse-engineer a watermark that was never applied.
Watermarks are fragile. A heavy JPEG compression, a resize, a colour-grade, or a screenshot can destroy the pattern. Detection tools like SynthID are available via Google Cloud Vertex AI and a standalone tool, but their accuracy is not perfect. False positives occur, and adversarial cropping can fool them. The takeaway is not that watermarks are useless. They are useful as a signal in the right conditions. They are not a guarantee, and no credible engineer will claim otherwise. Treat any tool that promises to tell you whether an image is AI-generated with extra scepticism. The error rate is real, and the consequences of a wrong answer are high when a reputation is on the line.
How Provenance Labels Fail in Practice
Two Real-World Failures
Consider the failure modes you will encounter. A message forwards a photo of a minister with a caption claiming a scandal. The image has no C2PA credential. A reader thinks, "No credential, must be fake," and dismisses it. The reader is wrong. The absence of a credential is not evidence of fabrication. The photo could be genuine, captured on a camera that does not support C2PA. Conversely, a sophisticated actor could generate a synthetic image and then run it through a C2PA-compliant editor to create a fake editing trail. The credential would say "edited in Photoshop," which is true, but the original content was synthetic. The label is a statement about the tool, not the scene.
Another failure is the source-confusion error. People assume that because a platform like Meta labels something "Made with AI," the content must be false, or because it is unlabelled, it must be true. Both assumptions are wrong. Meta's label is triggered by the presence of C2PA metadata or industry-standard AI indicators, but it does not judge the factual accuracy of the image. A real photo of a flood can be labelled "Made with AI" if an editing tool added generative fill to remove a telegraph pole. The label is a clue, not a verdict. Use it as one input among many in a broader verification process.
C2PA Standard Singapore: Adoption and Gaps
Where Singapore Stands
The C2PA standard in Singapore is still nascent. The Infocomm Media Development Authority (IMDA) published a proposed framework for AI provenance and watermarking through its AI Verify Foundation in May 2024. This is a consultative document, not a binding regulation. As of late 2026, the POFMA Office has not issued a specific C2PA or watermark mandate for online content. The Criminal Procedure Code and the Penal Code cover specific deepfake harms. Section 377BB on non-consensual intimate image sharing and 377BC on threats to distribute were criminalised in May 2019, but these laws target the act of distribution, not the technology of generation.
What You Cannot Rely On
For a reader in Singapore, the practical implication is that you cannot rely on any label to determine truth. The police have issued multiple advisories about AI-generated impersonation scams, including 13 confirmed cases in 2024 involving fake video calls from officials. In those cases, the video was not labelled with any C2PA credential. Even if it had been, the scammer would not have bothered to include it. The verification gap is not a technical one. It is a behavioural one. A provenance label does not replace the need to check the official source. If a video claims to be from the Singapore Police Force, open a new tab, go to the actual SPF website, and look for the advisory there. That is lateral reading, and it works regardless of whether the image has a credential.
AI Image Provenance Label: A Helpful Signal, Not a Verdict
An AI image provenance label is a piece of metadata that says "this file was processed by these tools." It is not a claim about the world. A label can tell you that an image was created in Midjourney or that a photo was edited in Adobe Lightroom. It cannot tell you whether the person in the image was at that location on that date. The only thing that can tell you that is external evidence: news reports, official statements, multiple independent sources.
This is why the "claimed vs real" distinction matters. A viral post may claim a video shows a current event in Singapore, but a reverse image search might show the same footage was used in a different context six months ago. That is not a flaw in the provenance label. The label's absence forces you to do the search. When a C2PA credential is present, it can simplify this process by giving you a starting point. When it is absent, you are not at a dead end. You are at the beginning of a verification process that has existed for decades: find the original source, check the date, look for corroboration across independent outlets, and be willing to say you do not know.
Digital Watermark Detection Limits and the AI Realism Trap
Why Fragility Matters First
Digital watermark detection limits are not a detail to learn after you get burned. They are the entire story. A watermark is a fragile pattern that can be destroyed by resizing, re-encoding, or screenshotting. Even the best detector will miss a watermark that has been compressed out of existence. Here is the trap: because watermarks are invisible, a reader might assume their absence means the content is authentic. That is exactly the wrong conclusion. The right conclusion is that you have no signal at all. Rely on other methods.
The Pixels Are Not the Tell
The AI realism trap is the deeper problem. Our mental model of "fake" media still assumes that it looks fake, glassy eyes, weird hands, blurry text. Generative AI from 2024 onward can produce photorealistic images that pass the visual Turing test. The tell is not in the pixels. It is in the context. A video of a public figure saying something controversial could be a deepfake, or it could be a real clip from a private event. The only way to know is to check the source, the date, and the surrounding context. Do not ask "could this have been faked?" Ask "who published this, and what is their track record?" The first question leads you down a rabbit hole of impossible technical analysis. The second question is answerable and takes thirty seconds.
What Fact-Checkers and Platforms Do With C2PA
A Starting Point, Not a Conclusion
Fact-checking organisations have begun to experiment with C2PA, but they treat it as a starting point, not a conclusion. Snopes announced in July 2024 that it would display content credentials on its pages when available. The BBC's verification unit, BBC Verify, began showing C2PA provenance information on selected content from March 2024. Both organisations use the credential to show their own editing process, not to prove that the events they cover happened. The credential on a BBC report says "this video was edited by BBC Verify using these tools and following this process." It does not say "this event occurred."
This is the key distinction between a provenance label and a verification verdict. A provenance label is a transparent account of how a file was created. A verification verdict is a judgement about the truth of a claim. The first is a technical record. The second is a journalistic one. When you see a C2PA credential on a news article, it tells you the outlet is being transparent about its methods. It does not tell you that the outlet is correct. You still have to read the article, check the sources, and decide for yourself. Tools like Truepic's Lens SDK embed C2PA credentials at the point of capture on some cameras, which is useful for authenticating that a photo was taken by a real camera at a real location. Even that can be fooled by a determined attacker with physical access to the device.
| Claimed | Real | Example |
|---|---|---|
| C2PA credential proves authenticity | C2PA credential proves editing history, not factual accuracy | Image labelled 'Edited in Photoshop' still shows a fake event |
| Watermark proves AI generation | Watermark only proves the specific model embedded it, and can be removed | Open-source models produce no watermark at all |
| Platform label means 'false' | Platform label means 'AI was involved in creation', not 'this is false' | Real photo with generative fill gets 'Made with AI' label |
| Deepfake scam is always sophisticated | Most deepfake scams are amateurish and rely on lack of verification | Fake SPF call video uses poor lip-sync but works on the unwary |
| POFMA corrects all falsehoods | POFMA is a legal mechanism with specific scope, not a fact-checker | A false claim about a private individual is outside POFMA's scope |
| No label means authentic | No label means you have no signal, so you must verify externally | An unbranded screenshot of a news article could be genuine or fabricated |
What the Absence of a Label Means
When a file has no C2PA credential and no watermark, you have two options. The first is to treat it as unverified and stop there. The second is to verify it through external means. Only the second option teaches you anything. The absence of a label is not a clue. It is a vacuum. A screenshot of a tweet that has no metadata could be a real tweet screenshotted before the metadata was stripped, or it could be an edited fake. Without the original, you cannot know. But you can search for the quoted text, check the original account, or look for coverage in established news outlets. That is lateral reading. It is the only reliable method.
This is why the "claimed vs real" framework matters so much. A message may claim that a video was taken in Singapore, but the real origin is a different country. A post may claim a fact was verified by a government agency, but the agency's official website has no such advisory. A tool may claim to detect AI with high accuracy, but the real false positive rate is higher than advertised. The label, whether it is a C2PA credential or a watermark, is just another claim. It is a claim made by the file itself. It is not a claim made by an independent third party. The only way to move from claimed to real is to check the original source. That almost always means leaving the page.
The Structural Limits of Source Transparency
What the File Cannot Tell You
Even when a C2PA credential is present and verifiable, it only tells you about the digital file. It does not tell you about the person who created it, the context in which it was shared, or the intention of the sharer. A deepfake of a politician saying something false might have been created by an adversary who used a C2PA-compliant tool. The credential will truthfully record that the adversary edited the video. It will not tell you that the politician's face was swapped. Source transparency is not the same as source verification. One is a property of the file. The other is a property of your investigation.
Build the Habit, Not the Toolset
Stop looking for a technical silver bullet. There is none. Instead, build a habit: when you see a surprising image or video, assume nothing. Open a new tab and search for the exact scene described in the caption. If it is a real event, a reputable news outlet will have covered it. If it is a fake, a fact-checking site like Snopes or the Singapore government's Factually portal will likely have a debunk. The absence of a label is not a reason to trust it less. The presence of multiple independent sources is a reason to trust it more. This is the durable skill, and it will outlast any watermark or credential standard.
Why This Matters for Singapore's Media Literacy
Singapore's Media Literacy Council (MLC) and the government's Factually portal both emphasise the same principle: do not share before you check. The MLC is an independent charity that runs public education campaigns, and this site is not affiliated with it. The MLC's guidance is technology-agnostic because the technology changes too fast. A C2PA credential that works today may be obsolete in two years. The habit of checking the original source will always be current.
The legal framework in Singapore provides a backstop, not a substitute. POFMA can compel a correction or removal of false statements, but it is a slow process and not designed for real-time verification. The Penal Code criminalises specific malicious acts like non-consensual intimate image sharing, but it cannot undo the harm of a viral deepfake. The law is a deterrent, not a verification tool. For a reader, the most useful thing you can do is internalise this: a believable image is not the same as a verified fact. Your scepticism is the only tool that cannot be faked.
How to Use Reverse Image Search When Labels Fail
Run the Search
Reverse image search is the single most effective technique for verifying an image when C2PA metadata is absent. Upload the image to Google Images, TinEye, or Yandex and see where it has appeared before. If it is a real photo from a new event, it will have few or no results. If it is a recycled image from an old event, you will see the original context. This is not a perfect method. A skilled forger can manipulate search results. But it is fast, free, and reliable enough for most cases.
Watch Your Privacy
The limitation is privacy. Uploading a suspicious image to a public site may reveal your identity or location if the image contains geotags or if you are logged in. Use a private browsing window and consider whether the image contains personal information. For a reader in Singapore facing a forwarded message on WhatsApp, the usual move is to save the image and do a reverse search from your phone's gallery. The risk is low for a public figure's photo. Be cautious with images that might be intimate or embarrassing. The verification is not worth exposing yourself or others.
What About Text and Audio Deepfakes?
Text Is a Different Problem
C2PA is not limited to images. The specification supports MP4, M4A, and WAV files, which means video and audio can carry provenance metadata. Text is a different problem. You cannot watermark text the way you watermark an image, because text is just a sequence of characters. SynthID for text embeds a pattern of word choices that a detector can recognise, but it has a high false positive rate and can be defeated by retyping or paraphrasing. Meta's labelling does not cover text at all.
Audio and the OTP Test
For audio, the situation is slightly better. SynthID for audio embeds an imperceptible frequency pattern that survives most compression. But if a deepfake is generated by a model that does not use SynthID, there is no watermark to find. The same rule applies to every format: the absence of a label is not evidence of authenticity. The only reliable approach is to ask whether the content matches what you know from other sources. A voicemail claiming to be from your bank asking for an OTP is a classic scam, regardless of whether the voice is a real recording or a cloned one. The request for the OTP is the red flag, not the audio quality.
The "About This Image" Feature and Other Tools
What Google's Tool Shows
Google's "About this image" feature, launched in May 2023 and expanded in 2024 to show C2PA metadata when present, is a useful starting point. Access it by clicking the three dots on a Google Images result or by using the Google app. It shows when the image was first indexed, whether it has been used in fact-checking articles, and the C2PA credential if one exists. This is not a verdict. It is a good source of context.
The Danger of Tool Over-Trust
Do not over-trust this tool or any single piece of software. A common failure mode is using one AI detection tool, getting a high-confidence result that the image is fake, and treating that as definitive. Detection tools have false positive rates, and the rate changes as new models are released. Use them as one input among many. If the detection tool says "AI," but the image matches a live news event from a reputable agency, the tool is probably wrong. Trust the evidence, not the gadget.
What to Do When You Are Still Unsure
You have checked for a C2PA credential, run a reverse image search, read the comments, and you still cannot tell if the image is real. What now? Say "I do not know" and refuse to share it. Sharing an unverified image is not a neutral act. It amplifies the content, gives it reach, and contributes to the very problem you were trying to solve. Every time you share something with a comment like "is this true?", you spread the falsehood before an answer arrives.
Instead, wait. Check back in a few hours. Fact-checking sites like Snopes, Factually, and the BBC will likely have covered it if it is viral. The more sensational the claim, the faster the debunk. If you cannot find a confirmation, the safest assumption is that the claim is unverified. This is not the same as concluding it is false. It is concluding that you have not verified it. The difference matters because it keeps you honest. A curriculum of "Source, Understand, Research, Evaluate" is taught in Singapore's schools, but you do not need a formal framework to apply it. Just ask: who published this, and would they know? If the answer is "my uncle forwarded it," you do not have a source.
A Practical Checklist for Your Next Verification
Before you share anything that seems surprising, run it through this checklist. First, who is the original source? Not the person who forwarded it, but the person who created it. If you cannot name the original source, stop. Second, does the content match what established outlets are reporting? If a video claims a politician is dead, but no news site has it, it is probably false. Third, what does the digital footprint of the content tell you? Has it appeared before in a different context? A reverse image search answers this in seconds. Fourth, what is the motivation of the person sharing it? If they are trying to provoke an emotional reaction, they are not acting in good faith.
Fifth, and most importantly, are you willing to be wrong? If the answer is no, you are not verifying. You are confirming what you already believe. Do the work. Open a new tab and check. The ten minutes you spend now could save you from being the person who spread a deepfake to a thousand people.
Frequently Asked Questions
Does a C2PA credential prove an image is real?
No. A C2PA credential proves the file was edited with a chain of C2PA-compliant tools. It does not prove the event depicted occurred. A synthetic image generated and then edited in Photoshop can carry a perfectly valid credential.
Can a watermark be removed from an image?
Yes, often easily. Cropping, resizing, heavy JPEG compression, or a screenshot can destroy an imperceptible watermark like Google DeepMind's SynthID. If the model that generated the image did not apply a watermark, as with many open-source models, there is nothing to remove.
If an image has no C2PA metadata, is it fake?
No. The absence of metadata is not evidence of tampering. Many cameras and editing tools do not support C2PA, and a simple screenshot or download from most social media platforms strips metadata. An absent label is a gap in the record, not a verdict.
Are AI detection tools reliable?
No. Tools marketed as AI-content detectors have false positive rates, and their accuracy varies by model and input. A single detector's verdict is not reliable. Use multiple methods and prefer external verification like reverse image search and lateral reading.
What is the best way to verify a deepfake video?
Do not rely on visual inspection. Check the source of the video, search for the same event on reputable news sites, and use reverse image search on still frames. If the video claims to be from a government official, go directly to the official's verified account and look for the same statement.