
By Dom Guinard, C2PA Strategic Advisor and Tony Rodriguez, CTO at Digimarc
Content Credentials, an open technology developed under the C2PA standard, enable content creators to add “nutritional facts,” or metadata, to online assets so consumers can fact check them and assess trustworthiness. This blog explores that while C2PA can be implemented exclusively by adding metadata, this approach renders the metadata easily removed by common workflows. For more durable C2PA manifests, content creators should embed watermarks into digital content so manifests can be quickly recovered, if they ever get detached.
With the rise of generative artificial intelligence (GenAI), the risk of media manipulation has never been higher. The technology is so good, it’s nearly impossible for content consumers to discern with confidence what online images, video, and other content are real and can be trusted. It’s a nagging uncertainty that impacts every sphere of life today.
Re-establishing trust in digital content in the age of GenAI is critical, and it’s why the C2PA standard was created. Designed to tackle the issue of trust by tracking the origin and history of online assets via Content Credentials, the technology allows content creators to add provenance data to original digital assets in a standardized manner so content consumers can get instant access to answers to questions such as: How was this made? Who created it? Is it AI-generated? When was it created? And how was it edited?
C2PA is a powerful solution to the trust and authenticity challenges of the AI age, and it’s on track to become one of the major tools companies can use to disclose the origin of their content. In fact, in August 2026, Google announced their C2PA support in nearly 40 of their products, producing tens of billions of assets across images, video, audio and documents. Similarly, after OpenAI and Google Gemini, Anthropic announced their use of C2PA to mark AI-generated content in September 2026.
C2PA also has its limitations, which is why complying with the base standard is often not enough to provide a durable solution in real-world contexts. Why? Because C2PA manifests are attached as metadata to an asset, not embedded into the asset itself. As a result, the metadata can be easily stripped from a digital asset by a malicious actor using an online tool, or even by common tools and platforms. Examples include:
For any organization that must comply with the EU’s new Artificial Intelligence Act, this also poses a compliance challenge. The law mandates a minimal implementation of provenance data, but in a way that satisfies the robustness and reliability criteria of the EU AI Act: specifically, the information must be robust enough to resist common workflows (such as posting media on social media).
This is where digital watermarks come to the rescue. How? By strengthening C2PA by creating a more persistent link between the digital asset and its manifest. By simply embedding an imperceptible digital watermark into an image, video or audio track that references the manifest, it’s easier for any content consumer to quickly recover the manifest, should it ever get detached.
Specifically, if a manifest does get detached, the digital watermark embedded in the pixels or bits of the asset can be used as a reference to recover the missing manifest. For a quick primer on how this works, watch this video:
https://youtu.be/U0UfWq9RxUM?si=PdcyKZwSYQIaABku
Equally important, because the watermark is embedded into the bits of the asset, it follows it around, wherever it’s shared, posted, or reposted, or if the asset is saved into a different format. This makes manifests more durable, compliant with the EU AI Act, and effective restorers of digital trust.
Digimarc, the leader in embedded authentication technology trusted by the world's central banks, has been co-chairing the C2PA task force responsible for this work (i.e., addressing durability) since its inception. In addition to specifying how to signal that a digital watermark has been added to an asset, the C2PA standard also supports a decentralized standard API (called a Soft Binding Resolution API) that allows for the retrieval of a C2PA manifest when it has been lost. In other words, if a manifest gets detached, the watermark embedded in the asset can be used to recover the missing manifest.
Rather than trying to define a one-size-fits all watermarking technology, C2PA supports several digital watermarks technologies listed in a machine-readable list. The list includes both proprietary watermarks, such as Digimarc’s Provenance & Authenticity technology (which was first to be supported) and open-source technologies. This variety gives implementers a choice between “light” open-source algorithms (which are typically free to implement) or more secure, enterprise-grade technologies (such as Digimarc’s) that be deployed across uses cases (such as combining leak detection or brand IP monitoring with C2PA manifest recovery using a single digital watermark).
This standard C2PA + digital watermark framework also allows technologies to interoperate, as Adobe and Digimarc illustrated a few months ago with the implementation of their respective technologies into their C2PA Chrome Extensions.
The big takeaway is this: Strong implementations of the C2PA standard together with digital watermarks result in more durable manifests that persist even after social media posting and format changes. The way to achieve this is to embed digital assets with a digital watermarking element. Without it, there’s a significant risk that content provenance and attribution will be short-lived.
It’s important to note that the maturity and technical sophistication of digital watermarks can vary significantly, impacting watermark durability and usability. For example, open-source watermarks may be free or low cost, but because the code base is open, they are typically easier to remove. They can also be too sensitive to transformations (such as cropping) or too visible or audible for corporate marketing and branding.
Enterprise-grade digital watermarks address these limitations. For example, Digimarc’s digital watermarks, backed by 30 years of innovation and hundreds of registered patents:
Businesses that successfully implement enterprise-grade C2PA + digital watermarking are better prepared for compliance with new and upcoming regulations like the EU AI Act (see our first post in this series). C2PA is also shaping up to serve as the backbone of digital media provenance, authentication, and licensing, so durable implementations with digital watermarks set companies up for emerging opportunities such as rights management and programmatic licensing.
Learn More About Enterprise-Grade C2PA
To make sure your organization is equipped to implement C2PA + digital watermarks—and be prepared to take advantage of emerging opportunities created by making your C2PA implementation durable—visit us online.