Blog

Why a C2PA label does not prove a deepfake is real: what you should record instead

C2PA manifests can show file history but cannot prove authenticity. Here is how to build a verification workflow around provenance signals for deepfakes.

· By

A sealed paper certificate with a loupe lies beside an open logbook where a hand makes pen notes, next to a printed video still of a face.
A C2PA seal shows who signed what, not whether the image is real; verification requires additional logging and checks.Image: IamVera.ai — original editorial illustration

No. Provenance standards such as C2PA show who signed what and when, not whether an image reflects reality; therefore treat provenance as one layer in a broader verification workflow with independent archives, cryptographic logging and adversarial testing, not as conclusive proof.

The occasion is an analysis that CarringtonJournal.com published on 15 August 2026 under the title The C2PA Security Gap and the Future of Synthetic Evidence. Those pieces summarise a security study from the University of Maryland, Baltimore County (UMBC) of 23 April 2026, which describes structural weaknesses in the C2PA standard. For anyone who has to be able to trust synthetic media in a legal, financial or public context, the practical message is: a provenance label is useful, but not conclusive proof.

What does a C2PA manifest prove and what does it not prove?

C2PA is an open standard from the Coalition for Content Provenance and Authenticity. According to the C2PA specification version 2.3, a manifest cryptographically binds signed assertions to a media file: where it comes from, how it has been edited and whether it has remained unchanged since signing. That is valuable, but it reaches no further than the file history.

  • Does: which party signed which assertion, and whether the file was altered afterwards.
  • Does: a chain of editing steps, as long as each step is signed correctly.
  • Does not: whether the image reflects reality. A camera also signs a manipulated scene if the manipulation takes place before the recording.
  • Does not: whether the signer is acting in good faith or has control of the key.

In our assessment this is the crux for professionals: provenance answers the question who signed what, and when, not the question whether this matches reality.

Which weaknesses did the UMBC security research find in C2PA?

The UMBC security research concludes that the current specification is not suitable for high-stakes environments, such as court cases, financial reporting or investigative journalism. The researchers point, among other things, to these points:

  • Timestamps fall outside the signed data and can therefore be changed unnoticed. When something appears to have been created is thus not reliably established from the manifest alone.
  • Manipulation before signing is not prevented. If a deepfake arises before the recording or signing, the file carries a valid manifest.
  • Certain metadata is not cryptographically bound to the signed content, which undermines the promise of tamper detection.

CarringtonJournal.com places this in the context of the ongoing debate about the proposed Federal Rules of Evidence 707 and 901(c) on authenticating AI-manipulated evidence. The lesson that follows is not that C2PA is worthless, but that a label cannot count as decisive proof. Anyone who takes seriously the distinction between what you must be able to demonstrate about AI content treats provenance as input, not as a final verdict.

How do regulators under the EU AI Act view provenance signals?

The European Commission describes in its guidelines on Article 50 of the AI Act that deepfakes and other AI-generated content must be clearly labelled and, where feasible, provided with technical provenance signals such as watermarks or metadata. Those same guidelines, however, position those signals as part of a broader transparency and governance framework, with detection, human editorial oversight and logging.

Our editorial reading of that: the legislator appears already to treat provenance as one layer in a control structure, not as the final piece. That fits with what you practically have to do to mark AI content under the EU AI Act without relying on a single technical mark of approval.

What does the deepfake fraud involving Gisele Bündchen teach about verification in practice?

According to reporting by heise.de, deepfake videos of model Gisele Bündchen were used in Instagram advertisements in Brazil. The incident shows the operational reality: even where moderation and authenticity mechanisms exist, attackers can deploy synthetic media at scale.

The practical conclusion is that it comes down to how an organisation checks campaigns and source material and how quickly it responds when provenance or authenticity is in doubt. A label that should have been present does not help if no one checks whether it holds up or is missing.

How do I set up a verification workflow that goes beyond a provenance label?

Treat provenance signals as one input in a documented verification process. In our assessment these components belong in a workflow for sensitive or high-trust contexts:

  1. Gather the available provenance signals (C2PA manifest, watermarks, platform metadata) and note explicitly what they do and do not prove.
  2. Maintain independent ground-truth archives and cryptographically logged recording moments, so that you are not fully dependent on a single signal in the file itself.
  3. Test your provenance pipeline adversarially: try to alter timestamps and metadata to see whether your checks notice this.
  4. Record per workflow how synthetic media is checked, approved and monitored, and who gives the final verdict.
  5. Make visible where residual risk and remaining trust decisions lie, rather than hiding them behind a label.

You can find more depth on this subject in our topic hub on AI verification and auditability. In that context a verification layer such as Vera is relevant, not as a new provenance standard, but as a console that can make provenance signals, logs and checks visible per workflow. Vera can help to show where synthetic content enters your systems, which provenance claims come with it and how those were tested; how you make verification steps and sources visible is supporting in this. The professional final verdict remains with the user.

Sources and references

  1. The C2PA Security Gap and the Future of Synthetic EvidenceCarringtonJournal.com · 2026-08-15
  2. Security Analysis of the C2PA Content Provenance StandardUniversity of Maryland, Baltimore County (UMBC) · 2026-04-23
  3. C2PA Specification Version 2.3Coalition for Content Provenance and Authenticity (C2PA) · 2026-07-10
  4. Guidelines on Transparency Obligations for Providers and Deployers of AI Systems under Article 50 AI ActEuropean Commission · 2026-07-20

Sources: The article draws on the C2PA analysis by CarringtonJournal.com, the UMBC security research, the C2PA specification v2.3, the European Commission's Article 50 guidelines and heise.de reporting on the Bündchen deepfake fraud.

← All articles in this topic ← All articles