logo
|
Blog
    INSIGHT

    Where content loses its origin

    A photo or a piece of music travels far enough on the internet and, at some point, nobody can say who made it — or whether anyone made it at all. C2PA is the standard built to address that. Here is what it is and why it matters, with diagrams and the vocabulary you'll run into.
    muse blossom's avatar
    muse blossom
    Aug 11, 2026
    Where content loses its origin
    Contents
    Why this is coming up nowWhat C2PA isThe problem starts hereWhat C2PA recordsA manifest alone isn't enoughWhat the reader actually seesThe vocabularySo what do you do about itA note on why we wrote this

    Why this is coming up now

    Not long ago, "is this photo real?" was a specialist's question. Now it's everyone's. Generation tools became ordinary, and the line between what was made and what was captured stopped being visible.

    Regulation followed. Article 50 of the EU AI Act requires machine-readable marking of AI-generated content from August 2026. California has had a comparable obligation in force since January. Distribution platforms are tightening their own policies alongside.

    Requiring a marking is settled. How to mark is the harder part, and it falls apart if everyone does it differently. A record left by an Adobe tool has to be readable by Google and checkable by YouTube for any of it to be worth doing. C2PA is the common format that came out of that problem.


    What C2PA is

    It stands for the Coalition for Content Provenance and Authenticity. Adobe, Microsoft, Google, the BBC, Sony and Nikon are among the members, and the specification is now moving through formal standardisation.

    What it does is simple enough. It attaches a résumé to the file. Who made it, when, with what, and what edits it has been through since — recorded in a form that cannot be forged.

    One common misreading. C2PA does not rule on whether content is true. It records where content came from and what it has been through. The judgement stays with whoever reads the record.


    The problem starts here

    Content doesn't stay where it was made. It gets edited, compressed, dropped into someone else's project, exported again. A little of the original information falls away at each step.

    In practice the break most often happens at platform upload. Most services re-compress whatever is uploaded into their own format, and the ancillary data riding along with the file is frequently discarded in the process. It's ordinary handling meant to save bandwidth. The origin goes out with it.’


    What C2PA records

    The record C2PA attaches to a file is called a manifest. Roughly, it holds this:

    The signature is what makes this work. Anyone can type "I made this" into a file. Nobody can forge a signature — and whether that signature came from an issuer worth trusting is something the verifier checks automatically.

    Why a separate timestamp. The certificate used for signing expires. Without a timestamp, everything signed with that certificate flips to "verification failed" the moment it does. Content outlives certificates, so something has to bridge the gap.


    A manifest alone isn't enough

    Look at the first diagram again. A manifest is data attached to the file. When a platform re-compresses and drops the ancillary data, the manifest goes with it.

    Which is why, in practice, layers get stacked.

    Together they behave like this. Where the manifest survives, you read the full history straight off it. Where re-compression has stripped it, the watermark is still in the signal and at least tells you where the content came from. Where neither exists — older material, anything from before marking was common — identification makes an estimate.

    The standard covers this pairing directly. Recovering a detached manifest through a watermark or a fingerprint is called soft binding.


    What the reader actually sees

    Google is building this checking into Search and Chrome. Adobe has applied it across its tools. Camera makers have started writing the record at the moment of capture. The point is an environment where a reader can check without installing anything.


    The vocabulary

    Term

    What it means

    C2PA

    Coalition for Content Provenance and Authenticity

    The technical standard for recording and verifying where content came from — and the name of the body that maintains it.

    Provenance

    The record of where content came from and what it has been through. Distinct from a ruling on whether it is true.

    Manifest

    The signed record of that history, stored alongside the file. The core unit of C2PA.

    Assertion

    An individual claim inside a manifest — "generated with AI", "captured on 3 August 2026", and so on.

    Content Credentials

    The reader-facing name for C2PA. Think of C2PA as the specification and Content Credentials as what you see when it has been applied.

    Watermark

    A mark carried in the content signal itself. Not a visible logo — a signal placed where people don't notice it.

    Hard binding

    Tying the record to the file by a hash of the content. Change anything and the two no longer match.

    Soft binding

    Tying them by a watermark or fingerprint instead, so the record can be recovered after the file has been altered.

    Trusted timestamp

    Proof of when a signature was made, so it stays valid after the signing certificate expires.

    Conformance

    The process of having a product checked against the standard's requirements. Products that pass are listed publicly. Worth keeping distinct from "certification" — the words are not interchangeable here.


    So what do you do about it

    If you make content and send it out, the order is roughly this.

    • Find where the break happens. Export, platform upload, client delivery — knowing which step drops the information is the starting point.

    • Decide where to write the record. Not at every moment of creation, but on the files that actually leave the building.

    • Don't rely on one layer. A manifest on its own disappears with the first re-compression.

    • Check the regulatory calendar. What is required, and when, differs by market.

    If you remember one thing. Origin data cannot be added retroactively. Anything you ship today without it stays without it, permanently. The gap accumulates the longer you wait.


    A note on why we wrote this

    We build audio and image watermarking, and C2PA-based origin verification. We wrote this less as a product introduction than because there is very little material on the subject in Korean, and not a great deal of plain-language material in any language. The regulation and the standard are both moving quickly, and sharing the concepts seemed worth doing on its own.

    If something here is wrong, or there's a topic you'd want covered, let us know and we'll fix it in a follow-up.


    Accurate as of August 2026. The C2PA specification and the relevant regulations are both being revised continuously — check current documents before acting on any of this.


    ✉️

    "Start preparing for AI content watermarking now. MuseBlossom's ContentsDefence protects image content through a single API — audio, video, and document support are in active development."

    Explore Contents Defence

    Contact : contact@museblossom.com

    Share article
    Contents
    Why this is coming up nowWhat C2PA isThe problem starts hereWhat C2PA recordsA manifest alone isn't enoughWhat the reader actually seesThe vocabularySo what do you do about itA note on why we wrote this

    MUSEBLOSSOM

    RSS·Powered by Inblog