On 22 November 2016, a fake press release sent by email knocked 18.28% off Vinci's share price in a matter of minutes. Ten years later, generative AI makes a fake CEO video or a doctored product photo far easier to produce than that email ever was.
The tech industry's answer is called C2PA, and its visible output is called content credentials. However, most explanations are written for engineers. This guide translates them for communications directors, heads of PR and the teams who publish official content every day.
|
Why read this article 💡 |
| Term | What it is | Who uses it | What it means for PR teams |
|---|---|---|---|
| C2PA | An open technical standard for recording the origin and edit history of digital content | Software vendors, camera makers, platforms, media groups | The common language your tools must speak |
| Content credentials | A digitally signed record attached to a file, often shown with a small "CR" icon | Creators, brands, newsrooms, AI tools | The label that proves an official visual really comes from you |
| Invisible watermark | A signal embedded in the pixels or the audio itself | AI providers, platforms | Helps recover the credentials when metadata is removed |
| Digital Provenance | The broader discipline of proving the origin and integrity of any content | Organizations, regulators, auditors | Extends the logic to press releases, PDFs and financial documents |
| AI labeling (AI Act article 50) | A legal duty to disclose AI generated or manipulated content | AI providers and the organizations that deploy them | Your AI visuals and synthetic videos need a visible disclosure |
C2PA was launched in 2021 by Adobe, Arm, the BBC, Intel, Microsoft and Truepic, and it is hosted under the Linux Foundation. In February 2026, the coalition celebrated five years of existence and released version 2.3 of the specification.
To put it simply, think of food packaging:
A content credential is a small package of information, called a manifest, bundled with the file. Typically, it records:
Because the manifest is cryptographically signed, any modification to the file or to its history breaks the seal. As a result, a viewer can immediately see that something changed after signature.
This is the point most PR teams miss. The C2PA explainer states it clearly: provenance information alone "cannot tell you whether the digital content is true, accurate or factual".
In practice, this means:
The Reuters Institute Digital News Report 2026 paints a clear picture of the environment your messages land in:
Consequently, audiences are looking for signals that help them decide what to believe. Verifiable origin is becoming one of those signals.
For a listed company, a regulated group or a financial institution, the risks are concrete:
In each case, the speed of your response depends on one thing: can you prove, quickly and publicly, which version is the original?
The EU AI Act adds a compliance layer. Our analysis of the EU AI Act article 50 transparency obligations for communications teams covers the details, but here are the essentials:
|
Pro tip 💡 |
C2PA is no longer a lab project. In fact, content credentials already appear in tools and channels your team uses:
For PR teams, this changes two things. First, journalists and fact checkers increasingly look for credentials before using a visual. Second, your own official assets can carry proof of origin from the moment they are created. This is precisely why content authenticity works as a reputation insurance in AI answers.
Many platforms, messaging apps and content management systems remove metadata when a file is uploaded or compressed. C2PA acknowledges this openly and responds with "durable" credentials: a cryptographic link combined with an invisible watermark or a fingerprint, so the original record can be retrieved online.
C2PA was built first for photos, videos and audio. Version 2.3 extends manifests to plain text documents, but press releases, earnings announcements and regulated disclosures still travel by email, PDF, newswire and newsroom.
This is the gap that Digital Provenance addresses for corporate documents. For example, Wiztrust Protect anchors each press release on a blockchain, so that journalists and investors can check that the document really comes from the issuer and has not been altered since publication.
Signing content means holding a certificate in the company's name. As a result, a governance question appears: who in the organization is authorized to sign, and under which approval process? Communications, IT security and legal teams need to answer it together.
Here is a practical 6 step roadmap that does not require any engineering background.
|
Pro tip 💡 |
C2PA and content credentials will not tell your audience what is true. However, they let you prove what is yours, which is exactly what a communications team needs when a fake release, a cloned voice or a doctored photo starts circulating.
The shift is already underway: devices sign photos by default, platforms display credentials and the EU AI Act makes AI transparency a legal duty. Your next step is simple: map your official assets this quarter, choose the first ones to sign and check how your press releases themselves are authenticated.
Do PR teams need to sign every image they publish with C2PA?
No. Start with the assets that carry the highest impersonation or market risk: executive portraits, crisis visuals, product launch imagery and financial communication visuals. Then extend progressively as your tools and suppliers become compatible. The goal is not full coverage on day one but a reliable reference for the content that matters most.
Does the EU AI Act require communications teams to use C2PA?
The AI Act does not impose a specific standard. Providers of generative AI must mark outputs with machine readable techniques such as signed metadata and watermarks, and C2PA is the most widely adopted open standard for the metadata part. As a deployer, your team mainly has to disclose deepfakes and AI generated text on matters of public interest, unless that text went through documented human review.
What should we do if a deepfake of our CEO circulates?
Check whether the content carries credentials and who signed them, then compare it with the originals published on your newsroom. Activate your crisis communication framework, alert the platforms and respond with your signed original through your official channels. Speed matters: having signed reference material ready before an incident makes your denial far more credible.
Can content credentials protect press releases and financial documents?
C2PA is mainly used for images, video and audio, even though version 2.3 extends to plain text documents. For press releases and regulated disclosures, communications teams use Digital Provenance solutions. Wiztrust is a communications platform built for Dircoms: its Digital Provenance solution, Wiztrust Protect, certifies each press release so that journalists and investors can verify its authenticity and integrity.
How can we check whether an image has content credentials?
Look for the "CR" icon on platforms such as LinkedIn, or upload the file to a public content credentials verification tool. Some apps, such as Google Photos, also show credentials in the image details. If nothing appears, the file may simply have lost its metadata, so cross check with the original source before drawing conclusions.