What do PR teams need to know about C2PA and content credentials in 2026?

On 9 October, 2026
12 min

On 22 November 2016, a fake press release sent by email knocked 18.28% off Vinci's share price in a matter of minutes. Ten years later, generative AI makes a fake CEO video or a doctored product photo far easier to produce than that email ever was.

The tech industry's answer is called C2PA, and its visible output is called content credentials. However, most explanations are written for engineers. This guide translates them for communications directors, heads of PR and the teams who publish official content every day.

 

Why read this article 💡
The value you will find in this content is an accessible explanation: C2PA is the open standard, content credentials are the signed label it attaches to a file, and PR teams need them to prove which visuals are really theirs, comply with EU AI Act labeling rules and respond faster to deepfakes.

Key takeaways

  • C2PA (Coalition for Content Provenance and Authenticity) is an open technical standard. Content credentials are the tamper evident record it attaches to an image, a video, an audio file or a document.
  • Content credentials prove where a file comes from and how it was edited. They do not prove that what it shows is true.
  • Adoption is real: more than 6,000 members and affiliates have live applications of content credentials, according to C2PA (February 2026).
  • Since 2 August 2026, the EU AI Act requires deepfakes to be disclosed, and marking obligations for generative AI systems already on the market apply from 2 December 2026.
  • Platforms can strip credentials, so PR teams need an official source of truth and a verification reflex, not just a label.

Table of contents

  1. C2PA, content credentials and related terms at a glance

  2. What are C2PA and content credentials, in plain language?

  3. Why should communications directors care about content provenance now?

  4. Where do content credentials already show up in a PR team's daily work?

  5. What are the limits PR teams should know before relying on C2PA?

  6. How can a PR team get started with content credentials?

  7. Conclusion: provenance is becoming part of the PR toolkit

  8. FAQ

C2PA, content credentials and related terms at a glance

Term What it is Who uses it What it means for PR teams
C2PA An open technical standard for recording the origin and edit history of digital content Software vendors, camera makers, platforms, media groups The common language your tools must speak
Content credentials A digitally signed record attached to a file, often shown with a small "CR" icon Creators, brands, newsrooms, AI tools The label that proves an official visual really comes from you
Invisible watermark A signal embedded in the pixels or the audio itself AI providers, platforms Helps recover the credentials when metadata is removed
Digital Provenance The broader discipline of proving the origin and integrity of any content Organizations, regulators, auditors Extends the logic to press releases, PDFs and financial documents
AI labeling (AI Act article 50) A legal duty to disclose AI generated or manipulated content AI providers and the organizations that deploy them Your AI visuals and synthetic videos need a visible disclosure

What are C2PA and content credentials?

C2PA is the standard, content credentials are the label

C2PA was launched in 2021 by Adobe, Arm, the BBC, Intel, Microsoft and Truepic, and it is hosted under the Linux Foundation. In February 2026, the coalition celebrated five years of existence and released version 2.3 of the specification.

To put it simply, think of food packaging:

  • C2PA is the regulation that defines what a nutrition label must contain and how it is printed.
  • Content credentials are the actual label on a given product, in this case a photo, a video or a document.
  • The "CR" icon is what your audience sees when a platform or a viewer displays that label.

What a content credential actually contains

A content credential is a small package of information, called a manifest, bundled with the file. Typically, it records:

  • Who signed it: the organization or the tool that issued the credential, identified by a digital certificate.
  • When and with what: the date, the camera, the phone or the software used.
  • What changed: crops, resizing, color corrections, redactions or AI generated fills.
  • Whether AI was involved: fully generated, partially edited or captured by a camera.
  • Its ingredients: the source files used to build the final asset.

Because the manifest is cryptographically signed, any modification to the file or to its history breaks the seal. As a result, a viewer can immediately see that something changed after signature.

What content credentials do not prove

This is the point most PR teams miss. The C2PA explainer states it clearly: provenance information alone "cannot tell you whether the digital content is true, accurate or factual".

In practice, this means:

  • A credential proves that "this photo was published by Company X and cropped in an editing tool". It does not prove that the scene was staged honestly.
  • A file without credentials is not necessarily fake. Many tools and platforms still do not support the standard.
  • Trust ultimately depends on who signed the content. That is why your brand's identity as a signer matters.

Why should communications directors care about content provenance now?

Trust in information is at a historic low

The Reuters Institute Digital News Report 2026 paints a clear picture of the environment your messages land in:

  • Trust in news fell to 37%, the lowest figure since the survey began measuring it in 2015.
  • Concern about fake news rose by 4 points to 62% on average.
  • Trust in answers from AI chatbots stands at only 20% globally.
  • In Western Europe, the report links rising concern to deepfakes, "AI slop" and politically motivated misinformation.

Consequently, audiences are looking for signals that help them decide what to believe. Verifiable origin is becoming one of those signals.

Corporate content is a direct target

For a listed company, a regulated group or a financial institution, the risks are concrete:

  • Fake press releases that move share prices, as the Vinci case showed. The French market authority (AMF) later fined Bloomberg €5 million for relaying the hoax, a penalty later reduced to €3 million on appeal.
  • Synthetic executive videos or voice clones used for fraud, market manipulation or reputational attacks.
  • Doctored crisis visuals, such as a fake photo of an industrial incident shared during a sensitive period.
  • Altered product or ESG imagery that contradicts your official communication.

In each case, the speed of your response depends on one thing: can you prove, quickly and publicly, which version is the original?

Regulation now turns transparency into an obligation

The EU AI Act adds a compliance layer. Our analysis of the EU AI Act article 50 transparency obligations for communications teams covers the details, but here are the essentials:

  • Since 2 August 2026, organizations that publish deepfakes must disclose them clearly.
  • AI generated text published to inform the public on matters of public interest must also be disclosed, unless it has gone through human review and someone holds editorial responsibility.
  • Under the Code of Practice, AI providers must mark outputs with at least two machine readable techniques, such as signed metadata and an invisible watermark.
  • Marking obligations for generative systems already on the market apply from 2 December 2026.
  • Fines can reach the greater of €15 million or 3% of worldwide turnover.

Pro tip 💡
If your team drafts press releases with AI assistance, document the human review step (who reviewed, when, what changed). The editorial exception relies on documented workflows, not on simple assurances.


Where do content credentials already show up in a PR team's daily work?

C2PA is no longer a lab project. In fact, content credentials already appear in tools and channels your team uses:

  • Smartphones and cameras: Google's Pixel 10 adds content credentials to every photo taken with Pixel Camera, and professional video cameras such as the Sony PXW-Z300 sign footage at capture.
  • Creative and AI tools: Adobe applications and major image generators such as OpenAI's attach credentials to the visuals they create or edit.
  • Social platforms: LinkedIn displays a "CR" icon on images that carry credentials, and TikTok became a C2PA steering committee member in July 2026.
  • Media groups: France Télévisions became the first broadcaster to systematically sign its daily news programs with C2PA in 2025.

For PR teams, this changes two things. First, journalists and fact checkers increasingly look for credentials before using a visual. Second, your own official assets can carry proof of origin from the moment they are created. This is precisely why content authenticity works as a reputation insurance in AI answers.


What are the limits PR teams should know before relying on C2PA?

Credentials can be stripped

Many platforms, messaging apps and content management systems remove metadata when a file is uploaded or compressed. C2PA acknowledges this openly and responds with "durable" credentials: a cryptographic link combined with an invisible watermark or a fingerprint, so the original record can be retrieved online.

Adoption is still uneven

  • Not every camera, design tool or digital asset management system supports the standard yet.
  • Not every platform displays the credentials, even when they are present.
  • Therefore, the absence of a credential is not, on its own, evidence of manipulation.

Press releases are not just images

C2PA was built first for photos, videos and audio. Version 2.3 extends manifests to plain text documents, but press releases, earnings announcements and regulated disclosures still travel by email, PDF, newswire and newsroom.

This is the gap that Digital Provenance addresses for corporate documents. For example, Wiztrust Protect anchors each press release on a blockchain, so that journalists and investors can check that the document really comes from the issuer and has not been altered since publication.

Someone must own the signature

Signing content means holding a certificate in the company's name. As a result, a governance question appears: who in the organization is authorized to sign, and under which approval process? Communications, IT security and legal teams need to answer it together.


How can a PR team get started with content credentials?

Here is a practical 6 step roadmap that does not require any engineering background.
c2pa-roadmap-6-steps-en


Pro tip 💡
Start with executive portraits and crisis visuals. They are the assets most often impersonated, and signing them delivers the fastest return on effort.

 


Conclusion: provenance is becoming part of the PR toolkit

C2PA and content credentials will not tell your audience what is true. However, they let you prove what is yours, which is exactly what a communications team needs when a fake release, a cloned voice or a doctored photo starts circulating.

The shift is already underway: devices sign photos by default, platforms display credentials and the EU AI Act makes AI transparency a legal duty. Your next step is simple: map your official assets this quarter, choose the first ones to sign and check how your press releases themselves are authenticated.


FAQ

Do PR teams need to sign every image they publish with C2PA?

No. Start with the assets that carry the highest impersonation or market risk: executive portraits, crisis visuals, product launch imagery and financial communication visuals. Then extend progressively as your tools and suppliers become compatible. The goal is not full coverage on day one but a reliable reference for the content that matters most.

Does the EU AI Act require communications teams to use C2PA?

The AI Act does not impose a specific standard. Providers of generative AI must mark outputs with machine readable techniques such as signed metadata and watermarks, and C2PA is the most widely adopted open standard for the metadata part. As a deployer, your team mainly has to disclose deepfakes and AI generated text on matters of public interest, unless that text went through documented human review.

What should we do if a deepfake of our CEO circulates?

Check whether the content carries credentials and who signed them, then compare it with the originals published on your newsroom. Activate your crisis communication framework, alert the platforms and respond with your signed original through your official channels. Speed matters: having signed reference material ready before an incident makes your denial far more credible.

Can content credentials protect press releases and financial documents?

C2PA is mainly used for images, video and audio, even though version 2.3 extends to plain text documents. For press releases and regulated disclosures, communications teams use Digital Provenance solutions. Wiztrust is a communications platform built for Dircoms: its Digital Provenance solution, Wiztrust Protect, certifies each press release so that journalists and investors can verify its authenticity and integrity.

How can we check whether an image has content credentials?

Look for the "CR" icon on platforms such as LinkedIn, or upload the file to a public content credentials verification tool. Some apps, such as Google Photos, also show credentials in the image details. If nothing appears, the file may simply have lost its metadata, so cross check with the original source before drawing conclusions.

Latest Articles

9 October 2026

What do PR teams need to know about C2PA and content credentials in 2026?

On 22 November 2016, a fake press release sent by email knocked 18.28% off Vinci's share price in a matter of minutes. Ten years later, generative AI makes a fake CEO video or a doctored productfalse
12 min
6 October 2026

LLM brand visibility: How can comms directors monitor it? The 4 KPIs to track in 2026

Value Box 💡This content is a direct answer to the question in the title: comms directors monitor LLM brand visibility with a stable panel of prompts, tested repeatedly across several AI models,false
13 min
2 October 2026

What is the EU AI Act article 50 transparency obligations for communications teams?

A synthetic video of your CEO, an AI voice over for your results webcast, a "photo" of a plant that was never shot. Until this summer, publishing any of these without a word of explanation was afalse
12 min

Would you like more information?

Paris
28, rue des petites écuries
75010 Paris

New York
110 Wall Street
NY 10005 – USA

© 2026 Wiztrust – Legal Notice – Privacy Policy