When anyone can generate an image, provenance is the proof.
AI can now produce a convincing photo of an event that never happened. The defence isn't spotting the fake — it's being able to trace where a real photo came from. This guide explains content provenance, the C2PA Content Credentials standard, and how to capture proof that survives scrutiny.
For a century, a photograph was treated as evidence by default. Generative AI ended that. A realistic image of a car crash, a flooded street, or a signed document can now be produced in seconds, and the human eye is no longer a reliable judge. The burden has quietly flipped: increasingly, the person with the real photo is the one who has to prove it.
Regulators are moving on one side of this. From 2 August 2026, the EU AI Act's transparency rules (Article 50) require organisations that generate AI content to disclose and mark it as machine-made. That tackles labelling the synthetic. It leaves the other half open — when something genuinely happened, how does the person who was there show their photo is authentic? That isn't labelling AI output; it's provenance for authentic capture, and it's a problem every driver, inspector, adjuster, and journalist now shares.
C2PA is an open technical standard for content provenance, maintained by the Coalition for Content Provenance and Authenticity — a group that includes Adobe, Microsoft, Sony, Nikon, and the BBC. When a photo carries a Content Credential, it holds a tamper-evident record of its origin and edit history that any compatible tool can read and check.
Think of it as a nutrition label for a photo: it doesn't judge whether the content is "good," it just lets you see where it came from and whether it was altered. For the full plain-English explainer, see What is C2PA / Content Credentials? →
From strongest to weakest signal.
Drop the image into a C2PA reader — Adobe's Verify tool, the Content Credentials pin in Chrome, or verify.contentauthenticity.org. If a credential is present and intact, you can see the source and whether the image was edited. This is the strongest available signal.
Some capture tools issue a public verification URL — for example verify.trustampcamera.com — that shows the server-anchored time and location of capture. It survives even when a platform strips metadata, because the record lives on a server, not in the file.
Reverse image search for earlier copies, and treat burned-in timestamps or a visible watermark as decoration, not proof — both are trivial to fake. Absence of any provenance isn't proof of fakery, but it means you're trusting the source, not the photo.
Everything above is verification after the fact. But you can't verify a provenance record that was never created. A timestamp and GPS overlay added by a photo app is editable text; EXIF is editable text; a caption is editable text. The only proof that holds up anchors the time and place off the phone and seals the exact image at the instant of capture — somewhere the photographer can't quietly rewrite.
That's what Trustamp does. Shoot a photo and it records a server-verified timestamp (our clock, not your phone's) and your real GPS, then witnesses that time and place to our server — never the image, and no fingerprint of it. Later you share a public verify link and anyone can confirm the when and where, without installing anything. For the image itself, turn on C2PA and Trustamp seals it with an open Content Credential on your phone, so Adobe, Chrome, and any C2PA tool can confirm the pixels weren't altered. Trust List certification is in progress, so those tools confirm the credential today and will show the issuer as trusted once it completes.
There is no single reliable tell — modern AI images defeat most visual checks. The dependable signal is provenance, not inspection: look for Content Credentials (C2PA) attached to the file, which record where an image came from and whether it was edited. Adobe's Verify tool, Chrome, and contentauthenticity.org can read them. Absence of credentials doesn't prove a photo is fake, but a valid credential from a source you trust is the strongest evidence you can get.
Provenance is the recorded history of a piece of content: who captured or created it, when, where, and what was done to it afterward. For photos, the open C2PA standard stores that history in a tamper-evident "Content Credential" so anyone can check it. It flips the question from "does this look real?" to "can I trace where this came from?" — which is far harder to fake.
Yes, trivially. EXIF timestamps and GPS tags are free-text fields any editor can rewrite, and most social platforms strip them entirely on upload. That is exactly why a screenshot of "date and location" burned into a photo is not proof. Real proof anchors the time and place to something independent of the phone, and seals the image itself in a tamper-evident credential — neither of which a caption can fake.
Two parts. The moment you witness a photo, Trustamp issues a public verify link that confirms the server-anchored time and location — anyone can open it, no app needed. For the image itself, turn on C2PA and Trustamp seals it with an open Content Credential on your device, so Adobe Verify or Chrome can confirm the pixels were not edited. Our C2PA Trust List certification is in progress (T1 → T3), so those tools confirm the credential today and will show the issuer as trusted once it completes.