Read the specification at its stated level
C2PA's April 2026 version 2.4 adds new asset support, assertions, live-video and cryptographic clarifications, plus an AI Disclosure Assertion. The specification is a technical framework for recording provenance claims; it does not make a claim true merely because the file carries a valid structure. Its new crJSON representation is explicitly described as a derived view for evaluation, interoperability testing, and reporting, not an independently verifiable input format. For film delivery, this supports a disciplined interpretation: a credential can be valuable evidence about a recorded claim and its integrity path, but it is not a verdict on whether a depicted event happened, whether an actor consented, or whether a production has cleared rights. [s1]
Audit the copy that will actually leave post
Create a delivery audit with four states: credential present and validates; present but does not validate; absent; or not checked. Record the exact file name, export version, hash if the production uses one, verifier used, check date, and the claim being relied on. Repeat the check after each consequential transcode, platform ingest, or editorial rewrap where the team can obtain the file. This is not a demand to add credentials to every asset; it is a demand not to infer survival from an earlier check. The 2026 C2PA additions give teams more expressive fields, including AI disclosure, but more fields create more reasons to distinguish a machine-readable assertion from a reviewable delivery fact. [s1] [s2]
Do not collapse conflicting signals into confidence
A March 2026 preprint by Nemecek and colleagues demonstrates what it calls an integrity clash: a valid C2PA manifest can assert human authorship while pixels bear an AI watermark, with each signal passing its own check. The authors report constructed metadata-washing workflows and propose a cross-layer audit. It is a preprint, not a standard or legal finding, but it gives a useful production caution. If a technical marker, credential, visual history, or source record points in different directions, preserve the conflict and escalate it. Do not turn one valid signal into permission to ignore another. The appropriate response is a better description of uncertainty, not a confident label. [s2]
Provenance has a boundary
This procedure cannot prove authorship, consent, factual truth, or regulatory compliance. It cannot compel a distribution platform to preserve metadata, and it does not validate claims an issuer has made outside the credential. For releases that may fall under Article 50, the European Commission's guidance also distinguishes technical marking from a deployer's audience-facing disclosure duty. Keep provenance review, editorial transparency, and rights records as connected but separate tracks. The point of an audit is not to create a badge; it is to retain honest information about what the team knows at delivery. [s1] [s2] [s3]
Diagram provenance
Original Screen Method editorial diagram, prepared 2026-09-19 from the cited evidence. This is an explanatory synthesis, not a product interface, documentary image or test result. No third-party artwork copied; no external image permission required for this drawing.
- Exported file Audit the exact copy that will leave post.
- Credential state Present-valid, present-invalid, absent, or not checked.
- Cross-signal review Preserve conflicts between metadata, watermark, and source record.
- Release record Keep provenance and audience disclosure distinct.
Sources & limits
Technical editorial guidance, not a C2PA conformance test, forensic examination, legal opinion, or assertion that any platform preserves provenance metadata.
- Coalition for Content Provenance and Authenticity — C2PA Technical Specification 2.4
Source date: 2026-04-01. Retrieved 2026-09-19. 2.4 changes, AI Disclosure Assertion, and the stated non-verifiable role of crJSON.
- arXiv / authors — Authenticated Contradictions from Desynchronized Provenance and Watermarking
Source date: 2026-03-02. Retrieved 2026-09-19. The preprint's integrity-clash framing, constructed metadata-washing examples, and cross-layer audit proposal.
- European Commission — Transparency obligations under Article 50 of the AI Act
Source publication date not established. Retrieved 2026-09-19. The Commission's distinction between machine-readable provider marking and audience-facing deployer disclosure.
Preparation: 2026-09-19. Site publication: not yet published. Source dates are not publication dates for this article.