Proving Digital Authenticity in the Age of AI
How C2PA and Verifiable Credentials combine to build trust in digital content
As AI-generated images become harder to distinguish from photographs, proving where content came from matters as much as the content itself.

AI can create an image in seconds. But can we prove who created it?
With AI generated images becoming increasingly difficult to distinguish from photographs, proving where an image came from and how it was created is becoming just as important as the image itself.
This is where C2PA and Content Credentials come in.
C2PA can create a cryptographically signed provenance record for an image, capturing information such as who created it, what device or software was used, what edits were made, and whether AI tools were involved. If the signed content or its provenance is tampered with, the verification can detect it.
But provenance tells us only part of the story. We also need to know who the actors behind that provenance actually are.
This is where Verifiable Credentials can add another layer of trust. They can provide additional information about the people or organisations involved in creating or handling an asset, for example, connecting a photographer, journalist, organisation or professional role to the provenance of an image.
Imagine the combination:
- C2PA: What happened to the image?
- Verifiable Credential: Who is the creator or organisation?
- Digital trust: Can we verify both?
Together, these technologies could create a powerful trust layer for images, videos and other digital content, particularly as generative AI makes visual content increasingly difficult to assess by appearance alone.
But the underlying idea goes beyond media. C2PA is fundamentally about provenance, not just images. The same approach can be applied to data and documents, creating a verifiable record of how an asset moves through a process.
Take a bill of lading in a supply chain. As it moves from one party to another, each responsible party could add a new assertion to the C2PA manifest through their Business Wallet. Instead of simply having a document, you could have a verifiable history of what happened to it, which parties were involved, and which steps were taken.
In other words, the question shifts from “Does this look authentic?” to “Can we verify its history?”
The future of content authenticity may not be about detecting what is fake. It may be about being able to prove what is authentic.
A worked example: how a Content Credential exposes an AI edit
The post's LinkedIn carousel walks through a worked example. Transcription:
Picture two near-identical holiday photos, Photo A and Photo B, of the same mountain lake. Only one of them was edited by AI, and the difference is a hot air balloon added to the sky in Photo B.
The Content Credential attached to Photo B reveals its full history:
- Taken with a camera - 14 March, 9:12 in the morning
- Made a bit brighter - in photo editing software
- A balloon was added by AI - the label does not hide this, it just says so
- Published by a newspaper - signed off before it went out
Why can't someone just fake the label? Zoom into the same photo very closely and every pixel carries a cryptographic fingerprint. The fingerprint on the label reads 4F04 F1F3 0A89 4138, while the fingerprint of the photo today reads 8D2B C5FF 5F4F 8950. They do not match: one dot changed and the whole fingerprint changed with it. A computer spots that instantly, even when the human eye never would. That fingerprint is a hash, sealed with a digital signature.
Personal information can also be stored alongside the Content Credential. For example, a Verifiable Credential for a photographer named Anna could confirm:
- Accredited press photographer, still valid today
- Works for a registered news organisation
- Allowed to publish on its behalf
Want to know more?
Curious about how this applies to your organisation, or want to talk to us about a specific use case? Get in touch — we're happy to help.