C2PA content credentials

C2PA (Coalition for Content Provenance and Authenticity) is a cross-industry standard for embedding cryptographically signed provenance information in images — who created them, what edits were made, by which tools. Metawatch checks every image we fetch for a C2PA manifest, alongside the IPTC scoring.

Images analysed 6,580
With a C2PA manifest 33
% with C2PA 0.5%

C2PA-bearing images over time

Absolute count of images carrying a C2PA manifest across crawl runs.

091827362026-06-032026-07-012026-08-012026-09-012026-10-0151581133Images with C2PA

As a share of all images sampled in each run:

0.00%0.28%0.55%0.83%1.10%2026-06-032026-07-012026-08-012026-09-012026-10-010.10%0.22%0.12%0.16%0.50%% with C2PA

Outcomes

A C2PA manifest can fail validation for very different reasons. We bucket each image we find into one of these outcomes so the headline number stays honest:

OutcomeMeaningImages
valid Cryptographically clean, issuer in our trust list, bytes unmodified. 16
modified Manifest signature verified, but the data hash no longer matches — the image bytes were changed after signing (typically by a CDN re-encode). 3
expired Signing certificate has expired. The image's authenticity claim can't be verified even though the manifest is structurally intact. 0
untrusted_issuer Manifest is structurally fine but the signing certificate isn't in our default trust list. Often legitimate (e.g. Adobe, Canva) — we list them here rather than as outright failures. 3
other_invalid Some other validation failure — see the validation_states breakdown below. 11

Top signers

Issuers of the certificates used to sign the manifests we found.

Signer / IssuerImages
OpenAI OpCo, LLC 9
Adobe Inc. 8
Canva 7
International Press Telecommunications Council 5
Google LLC 2
Comite International des Telecommunications de Presse 1
(unknown signer) 1

Raw validation states

The states returned by the c2pa-rs library before bucketing — useful if you want to drill into a specific failure mode.

StateImages
Invalid 17
Valid 16

Top sites by C2PA images

SiteCountryImages with C2PA
El Comercio (Ecuador) Ecuador 6
IPTC United Kingdom 6
Mauriactu Mauritania 5
Kurdistan 24 Iraq 4
IciLome Togo 2
Expansão Angola 1
Prensa Libre Guatemala 1
NHK News Web Japan 1
Libya Review Libya 1
Despacho 505 Nicaragua 1
Premium Times (Nigeria) Nigeria 1
Rappler Philippines 1
Asia-Plus Tajikistan 1
Turkmenistan: The Golden Age Turkmenistan 1
The Citizen Tanzania 1

Detection uses the c2pa-python binding to the Rust c2pa-rs library. Presence-first: an image is flagged as C2PA-bearing when a JUMBF manifest can be parsed from the file. We record the signing certificate's issuer and the validation state for further analysis, but do not yet introspect individual c2pa.metadata or cawg.metadata assertions (that's planned).