Free public instrument from GAGE
The Content Provenance Checker
As of September 2026 this ledger holds 28 records across 5 jurisdictions: 21 verified at a primary source, 1 reported by a secondary source, 0 announced with no document yet, 2 searched and absent, and 4 open questions. By kind: standard 8, binding law 7, platform or model provider 9, open question 4.
Check a file
Drop an image, a video, an audio file or a PDF. It is read here in your browser and never uploaded. You get what the file declares: whether a Content Credentials manifest is embedded, the IPTC digital source type, the creator tool. You do not get a real or fake verdict, because no file can give one.
Drop a file here
JPEG, PNG, WebP, MP4, MOV, HEIF, WAV, GIF, TIFF, MP3, SVG or PDF
Where the checker looks, format by format, and the specification section each rule was read from
Every rule is from the C2PA technical specification, version 2.4, read at spec.c2pa.org on 15 September 2026, with the Appendix A or clause 11 section beside it. One rule the specification delegates to a paid ISO text (the two byte identifier inside a JPEG APP11 segment) is deliberately not relied on; the checker uses the specification's own validator rule instead and says so here rather than shipping a byte nobody read.
| Format | Where a manifest store lives | Section |
|---|---|---|
| JPEG | APP11 marker segments (0xFFEB) whose payload is a JUMBF superbox labelled c2pa; a store may span several contiguous segments | A.3.1, 18.5.3, 15.12.3.1 |
| PNG | an ancillary private chunk of type caBX, recommended before IDAT | A.3.2 |
| WebP, WAV, BWF, AVI | a RIFF chunk with the identifier C2PA, the last sub chunk of the first RIFF header chunk | A.3.7 |
| GIF | an application extension block 0x21 0xFF, block size 0x0B, identifier C2PA_GIF, authentication code 0x010000, before the first image descriptor | A.3.8 |
| MP4, MOV, M4A, HEIF, HEIC, AVIF | a uuid box with extended type D8FEC3D6-1B0E-483C-9297-5828877EC481 after ftyp and before mdat and moov, with an 8 byte merkle offset before the store | A.5.1, A.5.3 |
| MP3, FLAC | an ID3v2 General Encapsulated Object (GEOB) frame whose MIME type is application/c2pa | A.3.4, 11.4 |
| TIFF, DNG, TIFF based RAW | an IFD entry with tag 52545 (0xCD41) of type 7, in the last main IFD | A.3.6 |
| an embedded file stream with Subtype application/c2pa and AFRelationship C2PA_Manifest, referenced from the catalog AF entry | A.4.1, A.4.2.1 | |
| SVG | a Base64 c2pa:manifest element inside metadata, namespace http://c2pa.org/manifest | A.3.3 |
| Any XMP | a dcterms:provenance key points at an external manifest only; Iptc4xmpExt:DigitalSourceType carries the IPTC digital source type | 11.5, 15.5.2.1, 18.3 |
| BMP | not covered; the specification requires an external manifest | 11.3, A.1 |
The digital source type vocabulary is read from cv.iptc.org, definitions verbatim. Two of its terms declare generative AI outright (trainedAlgorithmicMedia, compositeWithTrainedAlgorithmicMedia); algorithmicallyEnhanced does not, and the checker says which is which rather than treating every algorithm word as a confession.
- 28
- Records
- 21
- Verified at the source
- 2
- Announced or absent
- 4
- Open questions
5 jurisdictions, 52 primary sources
1 more reported, primary not reached
0 announced with no document, 2 searched and absent
Posed, sourced, not answered
As of 15 September 2026 the GAGE Content Provenance Checker records 21 verified instruments, 1 reported at a secondary source, 0 announcements without a document, 2 absences and 4 open questions, across 5 jurisdictions. Counts are a floor, not a ceiling: an instrument the ledger has not found is not on it.
Why this ledger exists
Guessing gives way to provenance, and provenance is only as good as what was embedded
Whether a picture looks real stops being useful as synthetic media improves. What replaces it is a record of where a file came from: a signed manifest, a declared source type, a watermark a platform can read. Those records only exist if someone embedded them, survive only if nothing stripped them, and prove only what the signer claimed.
The checker reads a file in your browser and reports exactly what is there. The ledger underneath records what each standard defines, what each platform actually embeds or displays, and what each law requires, so a reader knows what an absence means before treating it as suspicion.
Every row is fetched at its source where the source could be reached, and says so where it could not. The verdict language is the discipline: a reader learns five words once and never has to guess what a row claims.
Verified
The document exists. The ledger fetched it at its publisher and quotes it.
Reported, primary not reached
A reliable secondary source carries it, and the primary document could not be reached. Printed with this label, never as verified.
Announced, no document yet
A body has said it will act. No document exists yet, so the row records the statement and nothing more.
Absent
The ledger searched and found no instrument. The record says where it looked and when.
Open question
No settled answer exists. The ledger poses the question, links the live debate, and does not answer it.
The grid
What the documents state, and where they are silent
For each of the three things a provenance document can do (embed a mark, display or verify one, require one), how many records on the ledger state it and how many are silent.
Embeds a mark or manifest
19 stated, 4 silent, 1 reported.
Displays or verifies
17 stated, 6 silent, 1 reported.
What it requires
14 stated, 9 silent, 1 reported.
Side by side
Every jurisdiction, counted by verdict and by kind
United States
11 records
- Verified
- 9
- Reported
- 0
- Announced
- 0
- Absent
- 2
- Open question
- 0
3 binding law, 8 platform or model provider.
European Union
2 records
- Verified
- 2
- Reported
- 0
- Announced
- 0
- Absent
- 0
- Open question
- 0
2 binding law.
China
1 record
- Verified
- 1
- Reported
- 0
- Announced
- 0
- Absent
- 0
- Open question
- 0
1 binding law.
South Korea
1 record
- Verified
- 0
- Reported
- 1
- Announced
- 0
- Absent
- 0
- Open question
- 0
1 binding law.
Global
13 records
- Verified
- 9
- Reported
- 0
- Announced
- 0
- Absent
- 0
- Open question
- 4
8 standard, 1 platform or model provider, 4 open question.
Figures of record
Every number on this ledger, with who measured it and when
7 figures, each one printed in the unit its publisher used, beside the publisher and the date it was true. Nothing here is summed across sources, converted between units, or forecast.
- 24 products
validator products. The C2PA conformance programme, the trust list and the conforming products list
C2PA conforming products list, primary source, as of .
- 185 products
generator products. The C2PA conformance programme, the trust list and the conforming products list
C2PA conforming products list, primary source, as of .
- 209 products
conforming products listed. The C2PA conformance programme, the trust list and the conforming products list
C2PA conforming products list, primary source, as of .
- 47 products
Google entries on the C2PA conforming products list. Google: SynthID watermarking, the SynthID Detector, and C2PA in Pixel and Photos
C2PA conforming products list, primary source, as of .
- 2,000,000 users
unique monthly user floor for a large online platform. The California AI Transparency Act, SB 942 as amended by AB 853
AB 853, California AI Transparency Act, bill text, primary source, as of .
- 5,000 US dollars
civil penalty per violation. The California AI Transparency Act, SB 942 as amended by AB 853
SB 942, California AI Transparency Act, bill text, primary source, as of .
- 190 organisations
signatories by the close of July 2026. The EU code of practice on marking and labelling of AI generated content
Code of Practice on Transparency of AI-generated Content, European Commission, primary source, as of .
The ledger
Every record, newest first
28 records. Each row opens a page carrying the answer, the verdict and what it means, the key facts, the figures with their sources, what it changes for a publisher, a platform or a newsroom, and the sources it was verified against.
Answers
What people ask the Content Provenance Checker
Can this checker tell me whether an image is AI generated?
No, and nothing can from the pixels alone. It tells you what the file declares about itself: whether a Content Credentials manifest is present, what the IPTC digital source type says, and what the creator tool field says. A file with no declaration proves nothing either way, because most files carry none and a stripped manifest leaves no trace. The checker never validates a signature; the official validator does that.
Which platforms and model providers embed Content Credentials?
7 of 9 platform records on the ledger state that they embed a manifest or a mark as of September 2026: Cameras that sign at capture; Microsoft: Content Credentials on Azure OpenAI images; TikTok: reading Content Credentials to label uploads; Meta: AI labels built on C2PA and IPTC metadata; Adobe and the Content Authenticity Initiative; Google: SynthID watermarking, the SynthID Detector, and C2PA in Pixel and Photos; OpenAI: Content Credentials, SynthID and a verification tool. The embed, display and require dimensions on each record page quote the platform's own document.
Which laws require AI content to be marked?
7 laws on the ledger: The COPIED Act, S. 1396 in the 119th Congress (United States, verified); The TAKE IT DOWN Act requires no provenance mark (United States, absent); South Korea's AI Basic Act and its labelling duty (South Korea, reported, primary not reached); China's Measures for Labelling AI Generated Synthetic Content (China, verified); The California AI Transparency Act, SB 942 as amended by AB 853 (United States, verified); The EU code of practice on marking and labelling of AI generated content (European Union, verified); EU AI Act Article 50(2): machine readable marking (European Union, verified). Each record quotes what must be marked, by whom and from when.
Does the checker upload my file?
No. The file is read by your browser and nothing leaves it: no upload, no storage, no server. The only thing sent is a single anonymous signal that the checker was used, and that carries no file data.
What does the specification actually define?
8 records of kind standard are on the Content Provenance Checker as of September 2026: What a manifest says when the content was generated by AI; JUMBF, ISO/IEC 19566-5:2023, the box format under every manifest; The IPTC Digital Source Type vocabulary; JPEG Trust, ISO/IEC 21617; Content Credentials at ISO: ISO/CD 22144; The C2PA conformance programme, the trust list and the conforming products list; and 2 more. Each has its own page with the verdict, the facts, the sources it was checked against and the date.
What does the law require to be marked or disclosed?
7 records of kind binding law are on the Content Provenance Checker as of September 2026: The COPIED Act, S. 1396 in the 119th Congress; The TAKE IT DOWN Act requires no provenance mark; South Korea's AI Basic Act and its labelling duty; China's Measures for Labelling AI Generated Synthetic Content; The California AI Transparency Act, SB 942 as amended by AB 853; The EU code of practice on marking and labelling of AI generated content; and 1 more. Each has its own page with the verdict, the facts, the sources it was checked against and the date.
What does a platform or model provider actually embed, display or verify?
9 records of kind platform or model provider are on the Content Provenance Checker as of September 2026: Anthropic: no published provenance mark; Cameras that sign at capture; Microsoft: Content Credentials on Azure OpenAI images; YouTube: a C2PA manifest can trigger the AI label by itself; TikTok: reading Content Credentials to label uploads; Meta: AI labels built on C2PA and IPTC metadata; and 3 more. Each has its own page with the verdict, the facts, the sources it was checked against and the date.
What has nobody settled?
4 records of kind open question are on the Content Provenance Checker as of September 2026: May the absence of Content Credentials be treated as suspicion?; Who answers for a manifest that is signed and false?; Does a watermark survive re encoding?; Is a stripped manifest evidence of tampering?. Each has its own page with the verdict, the facts, the sources it was checked against and the date.
What do the verdicts mean?
Verified: the document exists and the ledger fetched it at its publisher. Reported: a reliable secondary source carries it and the primary could not be reached. Announced: a body said it will act and no document exists. Absent: the ledger searched and found nothing, and the search is written into the record. Open: a question nobody has settled, posed and not answered.
How current is the Content Provenance Checker?
Every record carries the date it was last verified; the ledger as a whole was last verified 15 September 2026 and holds 28 records with 52 primary sources. A change moves the record's own date and appears on the changelog, so a reader who cited a row can see whether it moved.
Every surface
Cut the ledger the way you need it
By jurisdiction
By kind
Every record page
- CPS-2026-0028: May the absence of Content Credentials be treated as suspicion?
- CPS-2026-0027: Who answers for a manifest that is signed and false?
- CPS-2026-0026: Does a watermark survive re encoding?
- CPS-2026-0025: Is a stripped manifest evidence of tampering?
- CPS-2026-0024: The COPIED Act, S. 1396 in the 119th Congress
- CPS-2026-0023: The TAKE IT DOWN Act requires no provenance mark
- CPS-2026-0022: South Korea's AI Basic Act and its labelling duty
- CPS-2026-0021: China's Measures for Labelling AI Generated Synthetic Content
- CPS-2026-0020: The California AI Transparency Act, SB 942 as amended by AB 853
- CPS-2026-0019: The EU code of practice on marking and labelling of AI generated content
- CPS-2026-0018: EU AI Act Article 50(2): machine readable marking
- CPS-2026-0017: Anthropic: no published provenance mark
- CPS-2026-0016: Cameras that sign at capture
- CPS-2026-0015: Microsoft: Content Credentials on Azure OpenAI images
- CPS-2026-0014: YouTube: a C2PA manifest can trigger the AI label by itself
- CPS-2026-0013: TikTok: reading Content Credentials to label uploads
- CPS-2026-0012: Meta: AI labels built on C2PA and IPTC metadata
- CPS-2026-0011: Adobe and the Content Authenticity Initiative
- CPS-2026-0010: Google: SynthID watermarking, the SynthID Detector, and C2PA in Pixel and Photos
- CPS-2026-0009: OpenAI: Content Credentials, SynthID and a verification tool
- CPS-2026-0008: What a manifest says when the content was generated by AI
- CPS-2026-0007: JUMBF, ISO/IEC 19566-5:2023, the box format under every manifest
- CPS-2026-0006: The IPTC Digital Source Type vocabulary
- CPS-2026-0005: JPEG Trust, ISO/IEC 21617
- CPS-2026-0004: Content Credentials at ISO: ISO/CD 22144
- CPS-2026-0003: The C2PA conformance programme, the trust list and the conforming products list
- CPS-2026-0002: Where a C2PA manifest actually sits in each file format
- CPS-2026-0001: The C2PA technical specification, version 2.4
Take the data
The whole dataset, free, in two formats
Licensed CC BY 4.0. Use it in an article, a paper, a slide or a product. The only condition is attribution, and the citation page gives you the line to paste.
- ledger.jsonEvery field of every record, the shape documented on the data page.
- ledger.csvOne row per record, figures and facets flattened, for a spreadsheet or a stats package.
How the ledger is built, what the verdicts mean, and what the gate refuses: the method page. Every change, dated: the changelog. The kinds on the shelf: standard, binding law, platform or model provider, open question. Something missing or wrong is a bug, and we want to hear about it. Whether your own content must carry a mark is answered by the AI Content Labeling Checker. The state deepfake laws are on the US Synthetic Media Law Atlas. Why guessing fails is the lesson of Real or AI. If the file is of you and you did not consent, start at Deepfake Response.
Cite this page
Free to reuse under CC BY 4.0, with attribution.
- In a sentence
- According to the GAGE Content Provenance Checker (as of 15 September 2026), content provenance checker.
- APA
- GAGE (Global Academy of Generative-AI Education). (2026). Content Provenance Checker. Content Provenance Checker. Retrieved 15 September 2026, from https://www.gage.academy/tools/content-provenance-checker
- MLA
- "Content Provenance Checker." Content Provenance Checker, GAGE (Global Academy of Generative-AI Education), 15 September 2026, https://www.gage.academy/tools/content-provenance-checker.
- Chicago
- GAGE (Global Academy of Generative-AI Education). "Content Provenance Checker." Content Provenance Checker. Last modified 15 September 2026. https://www.gage.academy/tools/content-provenance-checker.
- Permalink
- https://www.gage.academy/tools/content-provenance-checker
Last updated . Every record re verified . The ledger is checked monthly, first Monday, and the same day for any C2PA specification release.
24 products
GAGE briefings tell you which AI regulation deadlines are coming, what they actually require of you, and when a program opens.