Insights
C2PA: Verify The Provenance And Transparency Of Digital Content.

A huge amount of AI-generated content is published every day. As a result, it is becoming increasingly difficult to determine exactly where digital content comes from, whether AI was used, and what edits have been made.
From August 2026, transparency requirements under the EU AI Act apply. Certain AI output must be marked in a machine-readable way as artificially generated or manipulated. To meet these transparency requirements, organizations need to be able to provide insight into the provenance of certain AI-generated or manipulated content. One technology that can help organizations do this is C2PA (Coalition for Content Provenance and Authenticity), an open technical standard for recording and verifying the provenance of digital content.
Quick navigation:
- What Is C2PA?
- How Does C2PA Work?
- C2PA Or Watermark?
- C2PA And The EU AI Act.
- What Does C2PA Mean For Organizations?
- How Does Squadra Help With AI Act Compliance And C2PA?
What Is C2PA?
C2PA (Coalition for Content Provenance and Authenticity) is an open technical standard designed to record and provide insight into the provenance and history of digital content. This includes images, videos, audio, and text-based documents.
C2PA uses so-called Content Credentials. These are digital data associated with a content file and can contain information about, for example, the creator, the software used, and the edits made to the file. They can also record whether and how AI was used to create or modify the content.
The goal of C2PA is to create greater transparency and trust around digital content. As generative AI is increasingly used to create digital content, it is becoming more difficult to establish where that content comes from. C2PA provides a standardized way to keep the necessary information available throughout the lifecycle of a file.
C2PA is not a tool or platform in itself. It is a technical standard that can be implemented by different software applications and services. This allows different systems to use the same method to record and verify information about the provenance and modifications of content.
Importantly, C2PA does not claim that the contents of a file are automatically reliable. The standard only provides insight into where content came from, what actions were performed on it, and whether the recorded provenance information (information about the provenance and editing history) has been altered after signing. It therefore says nothing about the content itself.
How Does C2PA Work?
C2PA works with so-called Content Credentials: digital data associated with content that contains information about its provenance and history. This can include the creator, the software used, and the edits made to the file.
When content is created or modified using a C2PA-enabled tool, this information can be recorded in what is known as a manifest. This manifest contains the provenance information of the content and is cryptographically signed. This makes it possible to verify later whether the recorded information has been altered after signing.
When content is subsequently edited again, new actions can also be added to the provenance. This creates a verifiable history of the different steps the content has gone through. For example, an AI-generated image could record that it was created by an AI model, subsequently edited in an image-editing program, and then published by a user.
Users can then access the Content Credentials using a compatible tool. This provides insight into where the content was created, what happened to it, and whether AI played a role in its creation or modification.
C2PA Or Watermark?
An important point to consider is the difference between C2PA and a traditional watermark. Both visible and invisible watermarks are already commonly used to indicate whether content was created with the help of AI. Unlike watermarks, C2PA directly associates provenance information with a file and cryptographically signs that information.
A watermark mainly indicates whether something is AI-generated or not. C2PA provides insight into the where, when, with what, who, and how. Watermarks and C2PA are therefore not mutually exclusive and can be used alongside each other. C2PA is not a replacement for every type of watermark.
| Visible watermark | Invisible watermark | C2PA | |
|---|---|---|---|
| Indicate AI use | v | v | v |
| Record provenance | Limited | Limited | v |
| Editing history | x | Limited | v |
| Cryptographically verifiable | x | Not necessarily | v |
| Visible to user | v | x | Via viewer |
C2PA is therefore not a universal replacement for watermarks. The choice of technology depends on the intended purpose. If you want to directly inform users about AI use, a visible watermark may be appropriate. If you also want to record and verify the provenance and history of content, C2PA can be a valuable addition.
For organizations that produce large amounts of AI-generated content, a combination of both approaches may therefore be the most effective: visible transparency for users and machine-readable provenance for systems that process or verify the content.
C2PA And The EU AI Act.
The rise of generative AI brings not only new opportunities, but also new responsibilities. The European Union is responding with the EU AI Act , which includes transparency requirements for certain types of AI-generated and manipulated content.
As of August 2026, the transparency requirements set out in the AI Act apply. For providers of AI systems that generate synthetic audio, images, video, or text, this means, among other things, that the output must be marked in a machine-readable way as artificially generated or manipulated. Certain deepfakes and AI-generated content relating to matters of public interest are subject to additional transparency requirements. This makes it clearer when content has been generated or manipulated by AI.
C2PA can help organizations address these requirements from a technical perspective. With Content Credentials, information about the provenance and use of AI can be associated with content in a standardized and machine-readable way. This allows systems and users to access and verify this information later.
However, C2PA is not part of the AI Act, and using it does not automatically mean that an organization complies with the AI Act. C2PA is a technical standard that can be used to support certain transparency requirements. Whether an organization complies with the AI Act depends on the specific application, the AI system being used, and the organization’s role in that context.
C2PA Is Not AI Act Compliance In Itself.
It is important to distinguish between legislation and technology. The AI Act determines which transparency requirements apply, while C2PA provides a technical way to record information about the provenance and creation of content.
A machine-readable C2PA marking is not sufficient in every situation. The AI Act contains different requirements depending on the type of content and how it is used.
For organizations, C2PA should therefore primarily be viewed as part of a broader approach to AI transparency, content governance, and compliance. It is important to first determine which requirements apply to the organization and then identify which technical solutions are best suited to meet them.
What Does C2PA Mean For Organizations?
For organizations using AI to create or modify content, having insight into the provenance of that content is becoming increasingly important. C2PA can help by recording information about AI use and modifications in a standardized way.
This requires attention to the entire content chain. Consider the different AI tools, PIM and DAM systems, and publishing channels that process content before it reaches the customer. Organizations should therefore assess whether provenance information remains available throughout this chain.
It is also important to determine in advance which information should be recorded, who is responsible for it, and how this information will be managed. C2PA can therefore become part of a broader approach to AI transparency and content governance.
From AI Generation To Transparent Content
C2PA gives organizations the ability not only to create AI-generated content, but also to provide insight into how that content was created and which steps were taken afterwards. This can help increase transparency toward customers, partners, and other users, while preparing organizations for the growing role of AI in content creation.
How Does Squadra Help With AI Act Compliance And C2PA?
The use of AI brings not only new opportunities, but also new responsibilities. Organizations need to be increasingly able to demonstrate how AI is being used and how AI-generated content is created. Squadra helps organizations apply AI in a responsible, transparent, and controlled way, with attention to the requirements and responsibilities arising from the AI Act.
This goes beyond technology alone. Squadra helps organizations establish the processes, data, and governance needed to apply AI reliably and at scale. When it comes to AI Act compliance, Squadra also helps organizations understand which requirements are relevant and how they can address them from both a technical and organizational perspective.
Ready to Use AI Intelligently and Responsibly?
Harness the power of AI to create content faster, without losing control over transparency and compliance. Squadra helps organizations apply AI in a practical and responsible way and prepare for the evolving requirements of the AI Act.
Get in touch with us and discover what Squadra can do for your organization.
