SecurityTechInsider AI security & governance
EN/ NL
Governance

Why a C2PA label does not prove a deepfake is real: what you should record instead

C2PA manifests can show file history but cannot prove authenticity. Here is how to build a verification workflow around provenance signals for deepfakes.

9 September 2026 4 min
Illustration for this article: Why a C2PA label does not prove a deepfake is real. A shaft of hard daylight crossing a raw concrete soffit, dust suspended in the beam.
Provenance labels must be verified through independent checks and documented oversight, not treated as proof of authenticity. Image: SecurityTechInsider — original editorial illustration

You must treat provenance labels as one input to a verification workflow, not as conclusive proof of authenticity. Build your checks around independent archives, cryptographic logging and adversarial testing, and document which signals you tested and how you reached your conclusion.

The prompt is an analysis of 9 September 2026 of provenance signals and deepfake verification workflows, which argues that C2PA manifests show file history but cannot prove whether synthetic media reflects reality. A security study from the University of Maryland, Baltimore County identified structural weaknesses in the C2PA standard that make it unsuitable for high-stakes environments such as court cases, financial reporting or investigative journalism. In our assessment, this is the crux for professionals who must be able to trust synthetic media: provenance answers who signed what and when, not whether that content matches reality.

What does a C2PA label actually tell you?

C2PA is an open standard that cryptographically binds signed assertions to a media file: its origin, how it has been edited and whether it has remained unchanged since signing. That is valuable information about file history. It does not, however, establish whether the content is authentic or whether it depicts reality. A manifest can show that a file was signed by a particular entity at a particular time. It cannot show that the entity was truthful, that the signing process was secure against compromise, or that the underlying content was not synthetic before the signature was applied.

Which failure modes does provenance alone leave unaddressed?

  • Compromised signing keys — an attacker who obtains the private key of a legitimate signer can create false manifests that appear authentic.
  • Pre-signature synthesis — synthetic media can be created and signed before distribution, making the manifest cryptographically valid but the content fabricated.
  • Manifest stripping and replacement — provenance data can be removed from a file or replaced with false claims in contexts where verification is weak.
  • Signer impersonation — an attacker can create a manifest under a false identity that resembles a trusted source.
  • Absence of attestation — missing provenance does not prove content is inauthentic; it may simply mean no one signed it.

What controls must you be able to demonstrate in a verification workflow?

  1. Document your verification process per workflow — record which provenance signals you checked, which independent sources you consulted and what adversarial testing you performed.
  2. Maintain cryptographic logs of all checks — create an immutable record of when each piece of synthetic media entered your systems and which verification steps were applied.
  3. Test provenance claims against independent archives — cross-reference file history against sources outside your control to detect tampering or false claims.
  4. Establish human editorial oversight — assign responsibility for the final decision on authenticity to a named individual or team, documented in writing.
  5. Define escalation triggers — specify the conditions under which you halt use of content pending further investigation or external review.

How do the EU AI Act guidelines position provenance in practice?

The European Commission's guidelines on Article 50 of the AI Act require that deepfakes and other AI-generated content be clearly labelled and, where feasible, provided with technical provenance signals such as watermarks or metadata. Critically, those same guidelines position those signals as part of a broader transparency and governance framework that includes detection, human editorial oversight and logging. The legislator appears already to treat provenance as one layer in a control structure, not as the final piece. That is the shape of what you must be able to demonstrate under the AI Act without relying on a single technical mark of approval.

What does operational reality show about provenance in use?

Deepfake videos have been deployed at scale in fraudulent advertising campaigns despite the existence of moderation and authenticity mechanisms. The practical conclusion is that it comes down to how an organisation checks campaigns and source material and how quickly it responds when provenance or authenticity is in doubt. A label that should have been present does not help if no one checks whether it holds up or is missing. The speed and scale at which synthetic media can be distributed means that human oversight must be embedded in your workflow, not added after the fact.

Tooling can make provenance signals, logs and checks visible across your workflows and help you record which synthetic content entered your systems and how it was tested. The professional final verdict on authenticity remains with you. No standard, label or platform can transfer that responsibility.

Sources: This article draws on reporting and guidance from Carringtonjournal, University of Maryland, Baltimore County (UMBC), Coalition for Content Provenance and Authenticity (C2PA) and European Commission.

Marit Halversen

Written by

Marit Halversen

Covers AI governance and regulatory design, with a focus on how compliance obligations land on architecture rather than on paperwork.