ai-safety-provenance-and-audit · prepared

C2PA Content Credentials evidence boundaries

C2PA 2.4 provenance facts that distinguish cryptographic integrity and signer trust from factual truth, completeness, identity, and the absence of credentials.

version 1.0.0freshness currentobserved 2026-08-26T15:38:00Z

resource.provenance.c2pa-content-credentials-evidence
sha256:b1ce67840fb56045784c0a82bf0e8c6b79c163c129fb777ef92b8385f9b617f4

Open canonical machine JSON →

Evidence-backed facts

  1. A C2PA Content Credential is a cryptographically bound manifest containing signed assertions about an asset's origin, modifications, and other provenance information. informative
  2. C2PA validation can establish that provenance is associated with the asset, well formed, signer-linked under a trust model, and free from tampering; it does not establish that the content or every assertion is true, accurate, or factual. informative
  3. C2PA provenance can be incomplete and metadata can be removed, so a verifier should record which manifest and bindings were checked instead of assuming a complete asset history. informative
  4. The absence of Content Credentials is not proof that media is untrustworthy, and the core specification focuses on content provenance rather than directly establishing a human or organizational identity. informative