Reading progress0 %

    INSIGHT

    Content Credentials: How digital content proves its origin and why that has mattered since August 2, 2026

    Alexander HolzAlexander Holz

    Content Credentials based on the open C2PA standard serve as reliable proof of origin for your media. Acting as a digital passport, they link visible AI labels with machine-readable metadata into tamper-evident documentation. You control at a granular level which asset information is included, for full transparency and clear attribution. That is how you meet the AI Act transparency obligations in force since August 2, 2026, implement your own labeling standards across your company, and set your content apart from unlabeled media and cheap AI slop. Learn how the technology works and how a single upload at on:mint gives you complete verifiability.

    Content Credentials: How digital content proves its origin and why that has mattered since August 2, 2026

    What are Content Credentials?

    A Content Credential is a cryptographically signed proof of origin based on the open C2PA standard. It documents who created a piece of digital content and what happened to it afterward.

    Such a record works like a digital passport: it travels with the asset itself and cannot be altered without leaving a trace. At on:mint, Content Credentials are created automatically from a single upload.

    Why the origin of digital content suddenly matters

    Markets only work as long as quality remains visible. The economist George Akerlof showed in the 1970s what happens otherwise. In a used-car market where buyers cannot tell good cars from cars with hidden defects ("lemons"), the decline plays out in four stages:

    • Quality is invisible: buyers cannot tell good cars and defective ones apart.
    • Prices level out: buyers will only pay average prices.
    • The good sellers leave: those selling real quality withdraw from the market.
    • The market tips: only the defective cars remain, prices keep falling, and eventually nobody buys at all.

    For this analysis of asymmetric information, Akerlof received the Nobel Prize in Economics in 2001.

    Since the rise of generative AI, the same mechanism has taken hold of the market for digital content. Generative AI produces images, text, video, and audio in any quantity, increasingly indistinguishable from originals made by hand. Anyone looking at a photo or an illustration today can no longer read from the result how it was made.

    When nobody can prove what is real, trust in quality erodes, and so, eventually, does the willingness to pay for anything. Including the piece that took weeks of work.

    Why digital content needs proof of origin: originals, AI production, and the human contribution

    Proof of origin for digital content is relevant for three categories:

    • The original without AI: content made by hand, whose making can no longer be read from the result.
    • High-quality AI-assisted production: the framing of "real original versus mass-produced AI output" falls short, because a third category is growing between the two.
    • The human creative share in that production: concept, selection, composition, and post-processing that go into an AI-assisted work.

    A media agency that integrates AI tools into its pipeline puts substantial work into concept, selection, composition, and post-processing. It wants to be able to show how its work came about.

    This has a legal dimension. Under German copyright law, protection extends only to a person's own intellectual creation (Section 2(2) of the German Copyright Act, UrhG). Purely machine-generated content remains outside that protection. Anyone claiming rights in an AI-assisted work has to document their own creative contribution without gaps.

    Why does a quality signal only work if it can't simply be claimed?

    There is one way out of a lemons market where buyers cannot tell good products from defective ones: credible quality signals. A signal is credible only if it cannot simply be asserted.

    The peacock demonstrates the principle. Its tail costs energy and makes it visible to predators. A weak animal cannot afford that display. A peacock fanning its tail proves its strength instead of claiming it.

    For food, the ingredient list and the nutrition label play this role. Buyers don't have to tour the factory; they read what is inside and where it comes from. Digital content lacked a signal like that.

    Content Credentials close the gap: a machine-readable ID attached to the asset, documenting its origin, for all three categories. What cost does in nature, cryptography does here. It makes the record verifiable by anyone and any tampering with it visible.

    Article 50 AI Act: who has to label what, and by when?

    The transparency obligations under Article 50 of the AI Act have applied since August 2, 2026. Providers of generative AI systems must mark their outputs in a machine-readable way; deployers must disclose, for deepfakes and certain AI-generated texts, that the content was artificially generated or manipulated.

    Providers and deployers: two roles, two obligations

    Article 50 of the AI Act separates two roles. Providers of AI systems that generate synthetic audio, image, video, or text content must ensure that the outputs are marked in a machine-readable format and detectable as artificially generated or manipulated (Article 50(2) AI Act). This includes general-purpose AI systems.

    Deployers must disclose that a deepfake has been artificially generated or manipulated. The same applies to AI-generated text published to inform the public on matters of public interest (Article 50(4) AI Act). This disclosure must be clearly recognizable to humans, for instance through a visible or audible label.

    What deadlines apply to the labeling obligation?

    The machine-readable marking obligation has applied since August 2, 2026; existing systems have to follow by December 2, 2026. In detail, the deadlines differ by role and by when a system entered the market:

    • New generative AI systems: machine-readable marking required as of August 2, 2026 (Article 113 AI Act).
    • Existing systems: providers that placed their system on the market before August 2 have until December 2, 2026 to comply. This transition period was introduced by the AI Omnibus (Regulation (EU) 2026/1744), which entered into force in late July 2026: it adds the new Article 111(4) to the AI Act, which is why older versions of the legal text do not yet contain it.
    • Deployers' disclosure obligations: as of August 2, 2026, with no transition period.

    Which marking technique satisfies Article 50 AI Act?

    The separation of roles is decisive for choosing the right tools. Disclosure by deployers is an editorial task: a perceptible notice on the content, which machine-readable marking alone does not replace. Machine-readable marking, in turn, is a technical task, and it has to hold even when content is copied, compressed, or passed along.

    An industry standard for this is currently taking shape. None is mandated: the AI Act mentions watermarks, metadata identifications, and cryptographic proofs of provenance only as examples. So far, C2PA has the broadest support.

    Steganographic watermarks, which sit invisibly at the pixel level, are not yet part of the standard toolchain. They would be a natural fit, precisely because they preserve a marking even when metadata is lost.

    The Commission's guidelines from July 2026 state it plainly: at the current state of the art, no single technique meets all four requirements that Article 50(2) AI Act places on marking, namely to be effective, interoperable, robust, and reliable. The accompanying Code of Practice draws the conclusion. It requires its signatories to deploy at least two different marking techniques at the same time, so that their weaknesses offset each other.

    on:mint has signed this Code of Practice as a third-party provider of a marking and detection solution. The AI Act explicitly provides for such codes of practice: the Commission assesses whether adherence to them is suitable for fulfilling the obligations under Article 50(2) and (4) AI Act (Article 50(7) AI Act, as amended by the AI Omnibus).

    The Code allows relying on third-party solutions for marking and using their documentation as part of your own evidence. Anyone marking with on:mint works along the practices on:mint has committed to. Ultimate responsibility for fulfilling Article 50(2) AI Act remains with the provider of the AI system.

    And deployers? For them, the technical layer is not an obligation, but it is an opportunity. Anyone can place a visible label by hand; on its own, it proves nothing. Whoever additionally anchors their labeling to the asset via the C2PA standard can demonstrate at any time that they labeled correctly. Content Credentials thus become the documentation of every digital asset, AI-generated or not.

    Where does the AI labeling obligation end? Three gaps in the AI Act

    The AI Act's labeling obligation does not cover every deceptively real piece of content. Three gaps remain, and they explain why transparency needs a second layer:

    • Only AI systems within the meaning of the AI Act: the obligations are tied to the law's definition of an AI system (Article 3(1) AI Act). Deceptively real manipulations created with purely rule-based software are not covered.
    • Personal use is exempt: the disclosure obligation does not apply to deployers in purely personal, non-professional use (Article 2(10) AI Act). The guidelines explicitly cite deepfakes that private individuals spread on social media as an example. The provider's machine-readable marking remains; the perceptible label is missing.
    • Exemptions in the law itself: for evidently artistic, creative, satirical, or fictional works, disclosure is softened: it has to be made in a way that does not hamper the display or enjoyment of the work. AI-generated text is exempt entirely if it has undergone human review or editorial control and someone holds editorial responsibility for it (Article 50(4) AI Act).

    Seeing unlabeled content therefore tells you nothing definitive. It may be authentic, or it may simply be lawfully unlabeled. The labeling obligation alone will hardly contain deepfakes.

    Trust in digital content needs a second, complementary layer: certifying authentic assets, expressly including AI-assisted work. on:mint labels the artificial and certifies the authentic.

    This flips the logic. What used to be a quality signal for early movers becomes a legal obligation for part of the market and, for everyone else, the yardstick against which content is measured. That leaves the question of how proof of origin works technically, without creatives having to become cryptographers.

    What is C2PA?

    C2PA (Coalition for Content Provenance and Authenticity) is the open industry standard for documenting the origin and editing history of digital content, backed by Adobe, Microsoft, Google, the BBC, Sony, and OpenAI, among others. The standard defines how provenance information is cryptographically signed and linked to a file. Publicly, this is known as Content Credentials: the name under which platforms and tools display the provenance data.

    Behind this sits a shift in perspective. Detecting artificial content is an arms race between detectors and generators, and every model generation moves the line again. C2PA starts before the forgery: the content carries its own record of creation, cryptographically signed and verifiable by anyone. Don't detect. Prove.

    What is a C2PA manifest?

    A C2PA manifest is the signed data record that holds the provenance information. It is embedded directly into the file and consists of three building blocks.

    Assertions are the individual statements about the content: tool, time, AI involvement, editing steps. The type of creation, such as "captured with a camera" or "fully AI-generated," is also recorded there as a standardized entry.

    The claim bundles these statements and ties them to the specific file via a cryptographic hash. That is the hard binding: a checksum that changes completely if even a single pixel changes. This manifest verifiably belongs to exactly this file.

    The claim signature is the digital signature underneath, made with an X.509 certificate of the kind you know from encrypted websites. Anyone reading the manifest sees what is being claimed and who is claiming it. And that nothing has changed since it was signed.

    In practice, a verification tool displays a C2PA manifest roughly like this:

    Field
    Example entry
    Issuer
    on:mint, certificate verified
    Signed on
    July 14, 2026, 09:41 UTC
    Type of creation
    Not AI-generated
    Captured with
    Sony Alpha 7 IV
    Edits
    Crop, color correction
    Chain
    1 prior version, signed by Adobe Photoshop
    Binding
    SHA-256 hash of the file content

    No secret knowledge, no black box: a signed list of statements that any verification tool can display.

    The manifest grows with the file. If someone edits the image in a C2PA-enabled application such as Photoshop, a new manifest is created that references the previous one as an ingredient: the provenance chain. Camera X captured, tool Y cropped, AI tool Z retouched. Every stage signed, every stage verifiable. The chain thereby also documents the creative human share in an AI-assisted work: it shows where AI was involved and what came from human hands.

    Why does the provenance chain break, and why is that intentional?

    A C2PA manifest cannot be altered unnoticed, only removed. When the provenance chain breaks, that is the consequence of this security promise.

    A photographer shoots with a C2PA-enabled camera: manifest no. 1. She develops the image in Photoshop: manifest no. 2, with no. 1 as an ingredient. Then a colleague crops the image with a tool that does not support C2PA. No new manifest is created, the old one no longer matches the hash of the altered file, and the chain breaks. There are three typical places where this happens:

    • Tools without C2PA support that modify a file without writing a new manifest.
    • The screenshot.
    • The platform upload: many platforms strip all metadata on upload anyway, manifest included.

    This is not a design flaw. Tampering with the history breaks the signature, and the break shows up in every verification. The standard deliberately accepts this trade-off: better no record than a forged one.

    What it cannot do on its own is lead back to the record once the manifest is gone. The photographer's image is not one bit less real after the platform upload. It just can no longer prove it. That gap calls for a second safeguard.

    Soft binding: how a watermark keeps the proof of origin findable

    A soft binding is a durable spare key to the C2PA manifest. It proves nothing, but it makes the record recoverable when metadata is lost. The C2PA specification knows two variants: content-based recognition patterns (perceptual hashes), which recognize an image even in altered form, and invisible watermarks.

    The watermark is steganography: the technique of embedding information invisibly and machine-readably into content, directly into the pixels. Unlike the deliberately fragile hard binding, such a signal survives copies, screenshots, re-encoding, and cropping. In return, it proves nothing; it identifies.

    It acts as a lookup key: through the soft binding resolution defined in the specification, the complete, signed manifest can be restored from a manifest repository, even when the file has long been circulating without metadata.

    Cryptography delivers the proof; steganography keeps it findable. Only together do Content Credentials become durable. This combination is known as Durable Content Credentials.

    The practical catch: the specification only describes how a watermark is used for recovery. It does not ship the embedding itself, and the common C2PA toolchain produces manifests without watermarks. Anyone stopping at the standard workflow loses the record at the first metadata stripping. on:mint delivers both from a single source: the hard binding that proves, and the soft binding that keeps the proof findable.

    Behind this is a fundamental decision: the record lives in the asset itself. Anyone entrusting provenance data to third-party infrastructure is betting that platforms will preserve metadata and support standards. A watermark in the pixels does not depend on that good behavior; it travels inside the content.

    Together with anchoring in a public registry that sits outside every copy, this creates a record that depends on no third party. This is the stack on:mint builds.

    One upload, seven steps: how Content Credentials are created at on:mint

    At on:mint, you upload a file and check a box. The seven steps behind it run automatically, and the result is a permanently verifiable Content Credential.

    That checkbox is the affidavit, your own declaration about how the content was created, for instance "created without AI." It is co-signed with an advanced electronic signature and thus documented in a legally reliable way.

    Everything else runs without you: no setup, no crypto knowledge. At launch, this applies to images and documents; audio and video will follow.

    Step 1: Digital fingerprint

    on:mint calculates a SHA-256 hash of the exact file. Even the smallest change to the content would produce a completely different value. This fingerprint is later anchored publicly; the file itself never is.

    Step 2: Content-addressed storage

    The original is transferred and stored in encrypted form (TLS 1.3, AES-256). The address where it sits is derived from the content itself, technically again via a hash: the content identifier, CID for short.

    A classic file path points to a location whose content can be swapped or overwritten. With a CID, that doesn't work. If a single bit changes, a new address is created. Anyone who knows the CID sees exactly the same content on:mint received.

    The original stays private; only the fingerprint becomes public. The state the fingerprint describes thus remains available, unchanged, as a reference: as evidence of what you uploaded and when, and for comparison if a copy or a disputed version surfaces later.

    Step 3: AI analysis

    An ensemble of several detection models examines the content down to the pixels and estimates what share of it is AI-generated or AI-modified, rather than giving a blanket yes or no.

    The result serves as a plausibility check on your affidavit before it is signed: if the analysis matches your declaration, both are documented together in the credential. If they diverge, you are notified. The entry about the type of creation goes into the manifest in line with the standard.

    Step 4: C2PA manifest

    If your file already carries Content Credentials, say from a compatible camera or from Photoshop, on:mint reads the existing provenance chain and continues it. If the file arrives without C2PA data, on:mint generates a full manifest from existing metadata and the results of the previous steps. Existing material, too, receives a standards-compliant ID this way.

    Signing is done with the X.509 certificate of a certificate authority that appears on the official C2PA trust list. That is the difference between "unknown issuer" and a verified signer.

    The signed manifest is embedded into the file and additionally kept in the manifest repository, the basis for any later recovery.

    Step 5: Invisible watermark

    on:mint weaves a steganographic provenance marker directly into the content: the soft binding to the manifest.

    If a platform strips the metadata later, the way back stays open: via the watermark, the complete, signed credential is restored from the repository through soft binding resolution, even after a screenshot or re-encoding.

    Step 6: Anchoring in the public ledger

    The fingerprint is written into a public, decentralized registry, a kind of digital ledger (technically, a public blockchain). A single transaction bundles thousands of assets, and you get the proof for your asset back individually. That keeps anchoring economical even for large libraries.

    The result is a permanent, publicly verifiable timestamp: this asset existed at this moment in exactly this state. Nobody can alter or backdate the entry after the fact, not even on:mint. That makes the documentation tamper-evident. Whoever anchored first can prove it.

    And unlike the manifest, this entry cannot be stripped; it sits outside every copy.

    Step 7: Finality

    on:mint waits for the public registry's confirmation and verifies the entire record end to end. From this point on, your Content Credential can be checked independently, by anyone, at any time, without an account and without having to ask on:mint.

    The result: proof of origin on three layers

    The three layers back each other up where one alone fails. The signed C2PA manifest delivers the cryptographic proof. The watermark keeps it findable when metadata is lost. The public registry delivers the timestamp that nobody controls, not even the issuer.

    Behind them sits the content-addressed original as a reference for any later comparison. All at the price of a single upload.

    What can you actually do with a Content Credential?

    A Content Credential works in four places: on platforms such as LinkedIn, in the public Provenance Explorer, in recognition across the web, and as a carrier of machine-readable terms of use.

    Visibility on platforms

    On LinkedIn, content with Content Credentials displays the Cr symbol. One click reveals the provenance data and, thanks to the trust certificate, a verified issuer instead of a warning. "Some image in the feed" becomes content with documented origin, right where your customers see it.

    Public check in the Provenance Explorer

    Anyone can check any on:mint credential in the Provenance Explorer, no account needed. Recipients of a file, newsrooms, business partners, courts: one link is enough, and the documented history is laid open. The record also travels inside the file. Whoever passes on the asset passes on the ID.

    Recognition across the web

    The browser extension recognizes your content registered with on:mint wherever it appears, even when metadata was removed long ago. Watermarks and content-based matching make your assets findable; comparison against the content-addressed original makes the attribution reliable.

    Data contracts: terms of use that travel with the file

    on:mint can extend Content Credentials with machine-readable statements about how an asset may be used: license, scope of use, contact for rights inquiries, reservations such as opting out of AI training. The answer to "May I use this?" thus moves into the file itself. For rights holders, that means clear attribution of authorship and usage rights, documented on the asset. For users, it means clarity about rights at a glance. And because the statements are machine-readable, crawlers and AI agents can read them, too, before they process an asset.

    Beyond these four places of use, a Content Credential has a regulatory function. on:mint supports providers of generative AI systems with machine-readable marking under Article 50(2) AI Act, documentation included.

    The deployers' perceptible label under Article 50(4) AI Act is built in as well: on:mint automatically applies the AI label in the on:mint design to the asset and documents the labeling process itself, cryptographically signed and steganographically anchored. The proof of labeling flows directly into the Content Credentials.

    The bottom line: proving what's real becomes a competitive edge

    Back to Akerlof. A lemons market collapses because nobody can credibly signal quality. The flood of synthetic content devalues one thing above all: the unsupported claim. Your work keeps its value once it can show it.

    Origin thus moves from nice-to-have to standard equipment. Between a work with verifiable provenance and an image without an ID lies the same difference as between the labeled product on the shelf and the unmarked can: one can be checked, the other has to be believed.

    That holds for the original as much as for high-quality AI production. Value emerges where the path of creation is documented and the documentation cannot be altered after the fact. The AI Act accelerates this development.

    At the same time, the labeling obligation produces a paradoxical side effect. The more routinely AI content carries a label, the more people will read the unlabeled content as especially real. Drawing that inference is an easy way to be wrong: the gaps in the labeling obligation let deceptively real content circulate lawfully without a label. No label does not mean no AI.

    The decisive question going forward is therefore not "Is this AI?" It is: "Can I trust where this content comes from?"

    Content Credentials answer exactly that question. They are the quality signal that cannot simply be claimed: a record anyone can verify. This works because several techniques interlock around the open C2PA standard, each covering the others' weak spots. The signature proves. The watermark keeps the proof findable. The public registry secures the independent timestamp. The content-addressed original allows comparison against any copy that turns up. Together, that yields a level of protection and transparency for your media assets that no single technique achieves.

    on:mint's Content Credentials are live. Getting started is deliberately simple and takes a few minutes: you upload your file and check a box. on:mint handles the rest, and the finished credential stays with your asset for good.