Blog

Enterprise-Grade C2PA for Durable Content Provenance

October 08, 2026

By Dom Guinard, C2PA Strategic Advisor and Tony Rodriguez, CTO at Digimarc

Summary

Content Credentials, an open technology developed under the C2PA standard, enable content creators to add “nutritional facts,” or metadata, to online assets so consumers can fact check them and assess trustworthiness. This blog explores that while C2PA can be implemented exclusively by adding metadata, this approach renders the metadata easily removed by common workflows. For more durable C2PA manifests, content creators should embed watermarks into digital content so manifests can be quickly recovered, if they ever get detached.

Key Takeaways

  • With the rise of generative AI, the risk of media manipulation has never been higher.
  • The C2PA standard restores trust in digital content by enabling anyone to see its creation history, editing steps, and source data. But this metadata is removed by routine workflows.
  • By embedding a digital watermark into an image, video, or audio track that references the C2PA manifest, consumers can quickly recover the metadata.
  • Implementers can choose between “light” open-source algorithms or enterprise-grade technologies (such as Digimarc’s) that are typically more robust and secure and can drive multiple use cases such as leak detection, usage monitoring, or content attribution.

C2PA: A Proven Path to Content Provenance for Digital Assets

With the rise of generative artificial intelligence (GenAI), the risk of media manipulation has never been higher. The technology is so good, it’s nearly impossible for content consumers to discern with confidence what online images, video, and other content are real and can be trusted. It’s a nagging uncertainty that impacts every sphere of life today.

Re-establishing trust in digital content in the age of GenAI is critical, and it’s why the C2PA standard was created. Designed to tackle the issue of trust by tracking the origin and history of online assets via Content Credentials, the technology allows content creators to add provenance data to original digital assets in a standardized manner so content consumers can get instant access to answers to questions such as: How was this made? Who created it? Is it AI-generated? When was it created? And how was it edited? 

Adoption Has Gone Mainstream

C2PA is a powerful solution to the trust and authenticity challenges of the AI age, and it’s on track to become one of the major tools companies can use to disclose the origin of their content. In fact, in August 2026, Google announced their C2PA support in nearly 40 of their products, producing tens of billions of assets across images, video, audio and documents. Similarly, after OpenAI and Google Gemini, Anthropic announced their use of C2PA to mark AI-generated content in September 2026.

But C2PA Has a Weakness: Durability

C2PA also has its limitations, which is why complying with the base standard is often not enough to provide a durable solution in real-world contexts. Why? Because C2PA manifests are attached as metadata to an asset, not embedded into the asset itself. As a result, the metadata can be easily stripped from a digital asset by a malicious actor using an online tool, or even by common tools and platforms. Examples include:

  • Loading an image to a social network.
  • Sending a video via an instant messaging app.
  • Editing an image with a (mobile) app.
  • Taking a screenshot can strip C2PA manifests from digital assets.

For any organization that must comply with the EU’s new Artificial Intelligence Act, this also poses a compliance challenge. The law mandates a minimal implementation of provenance data, but in a way that satisfies the robustness and reliability criteria of the EU AI Act: specifically, the information must be robust enough to resist common workflows (such as posting media on social media).   

The Solution? C2PA + Digital Watermarks

This is where digital watermarks come to the rescue. How? By strengthening C2PA by creating a more persistent link between the digital asset and its manifest. By simply embedding an imperceptible digital watermark into an image, video or audio track that references the manifest, it’s easier for any content consumer to quickly recover the manifest, should it ever get detached.

Specifically, if a manifest does get detached, the digital watermark embedded in the pixels or bits of the asset can be used as a reference to recover the missing manifest. For a quick primer on how this works, watch this video: 

https://youtu.be/U0UfWq9RxUM?si=PdcyKZwSYQIaABku 

Equally important, because the watermark is embedded into the bits of the asset, it follows it around, wherever it’s shared, posted, or reposted, or if the asset is saved into a different format. This makes manifests more durable, compliant with the EU AI Act, and effective restorers of digital trust.

Support for Digital Watermarking Is Built Into C2PA

Digimarc, the leader in embedded authentication technology trusted by the world's central banks, has been co-chairing the C2PA task force responsible for this work (i.e., addressing durability) since its inception. In addition to specifying how to signal that a digital watermark has been added to an asset, the C2PA standard also supports a decentralized standard API (called a Soft Binding Resolution API) that allows for the retrieval of a C2PA manifest when it has been lost. In other words, if a manifest gets detached, the watermark embedded in the asset can be used to recover the missing manifest.

Rather than trying to define a one-size-fits all watermarking technology, C2PA supports several digital watermarks technologies listed in a machine-readable list. The list includes both proprietary watermarks, such as Digimarc’s Provenance & Authenticity technology (which was first to be supported) and open-source technologies. This variety gives implementers a choice between “light” open-source algorithms (which are typically free to implement) or more secure, enterprise-grade technologies (such as Digimarc’s) that be deployed across uses cases (such as combining leak detection or brand IP monitoring with C2PA manifest recovery using a single digital watermark).

This standard C2PA + digital watermark framework also allows technologies to interoperate, as Adobe and Digimarc illustrated a few months ago with the implementation of their respective technologies into their C2PA Chrome Extensions. 

Implementing C2PA + Digital Watermarking

The big takeaway is this: Strong implementations of the C2PA standard together with digital watermarks result in more durable manifests that persist even after social media posting and format changes. The way to achieve this is to embed digital assets with a digital watermarking element. Without it, there’s a significant risk that content provenance and attribution will be short-lived.

Open-Source or Enterprise-Grade Watermarks?

It’s important to note that the maturity and technical sophistication of digital watermarks can vary significantly, impacting watermark durability and usability. For example, open-source watermarks may be free or low cost, but because the code base is open, they are typically easier to remove. They can also be too sensitive to transformations (such as cropping) or too visible or audible for corporate marketing and branding.

Enterprise-grade digital watermarks address these limitations. For example, Digimarc’s digital watermarks, backed by 30 years of innovation and hundreds of registered patents: 

Businesses that successfully implement enterprise-grade C2PA + digital watermarking are better prepared for compliance with new and upcoming regulations like the EU AI Act (see our first post in this series). C2PA is also shaping up to serve as the backbone of digital media provenance, authentication, and licensing, so durable implementations with digital watermarks set companies up for emerging opportunities such as rights management and programmatic licensing.

Learn More About Enterprise-Grade C2PA

To make sure your organization is equipped to implement C2PA + digital watermarks—and be prepared to take advantage of emerging opportunities created by making your C2PA implementation durable—visit us online.

You May Also Like

Learn more
Gift Card Industry’s Last Big Security Innovation Was 15 Years Ago. That’s Why Fraud Is Exploding.
Blog

The Gift Card Industry’s Last Big Security Innovation Was 15 Years Ago. That’s Why Fraud Is Exploding.

Learn more
Gift Card Draining Blog
Blog

Card Draining Is No Longer a “Gift Card Scam.” It's Becoming a Distinct Fraud Category, and That Changes Everything

leadership-team