A photograph you see online may be accompanied by the words “Content Credentials” or a small information icon. This mark is not an automatic endorsement declaring that the image is unquestionably real. It indicates that a record concerning the file’s origin and processing history, created using the open C2PA standard, is cryptographically bound to the file. The record may show which device or software created the content, which edits were declared, and whether the creator marked the use of artificial intelligence.

Ask the right question first

Researcher comparing the source, editing, and verification stages of an image on a screen

When examining an image, ask three separate questions instead of “Is this real?” Is the record attached to the file technically valid? Is the person or organization that published the record trustworthy? Can the event shown in the image be corroborated with independent evidence? C2PA primarily helps with the first two questions. Even if a camera produced a signed record at the correct time, the event in front of the device may have been staged. Conversely, a photograph without credentials may still be real: resizing by social networks, taking a screenshot, or using an application that strips metadata may have removed the record.

Find the most original copy of the file available

Editor independently verifying an event by examining different photographs of it side by side

Instead of a social media screenshot, examine the file on the publisher’s website, the download link provided by the photographer, or the news agency’s original delivery. Cropped copies or copies passed through a messaging app may lose important information. Before uploading an image to a verification service, consider whether it contains sensitive material. Uploading a private family photograph or identity document to a third-party service is inappropriate. If possible, use a trusted local inspection tool and read the service’s privacy terms.

Read the Content Credentials record step by step

First, look at the verifier’s technical result, such as “valid,” “verified,” or similar wording. This result indicates whether the cryptographic link between the manifest and the file has been preserved. Then examine the organization that signed the record and the certificate’s chain of trust. Do not stop at seeing a familiar brand name; check whether the verifier links that name to a trusted publisher.

Next, read the processing timeline. Steps such as the initial capture, export, cropping, color adjustment, or a generative AI operation may be displayed as separate actions. The word “edited” is not proof of deception on its own: reframing and exposure adjustment are also edits. What matters is whether the change affects the image’s meaning and at which stage the chain of records begins. If only the final editing application created a record, the file’s earlier history may be unknown.

Do not confuse three critical findings

A valid signature provides technical confidence that the associated data has not been unexpectedly altered since the record was created. A verified identity may show that the signing party can be linked to a particular person or organization. The factual accuracy of the content, however, must be investigated separately using information from the scene, other images, the date, weather, location, and trusted news sources. Do not reach a definitive judgment when only one of these three layers has a positive result.

A record that appears invalid does not automatically prove manipulation either. File conversion, an incompatible editor, or a broken download chain may have affected it. Read the verifier’s details section to see which asset does not match. If possible, find the publisher’s original version of the same content and examine the two files separately.

Interpret the AI label correctly

If an action record indicates that generative AI was used, examine the scope of that use. The entire image may have been generated, only the background may have been extended, or a small object may have been removed. The absence of a label does not guarantee that “AI was not used”: some tools do not create records, and credentials can become detached from the file. C2PA is not a deepfake detector; it is infrastructure for carrying a declared history of origin and changes.

Establish a second channel for news verification

Investigate text, road signs, and distinctive structures in the image as separate clues. Use reverse image search to find older versions and compare the claimed date with the first publication date. If the news is important, match the same event against images from different news organizations, official statements, and, where possible, direct sources in the field. The file’s C2PA result should be only one column in this table of evidence.

Write your findings in measured terms, such as “the record is valid and the publisher is recognized,” “no credentials; origin uncertain,” or “the record and file do not match.” Use labels such as “fake” or “definitely real” only when supported by independent evidence. This approach helps you build a verification routine that does not blindly accept a new trust symbol but understands what it proves and where it remains silent.