Skip to main content

Free public instrument from GAGE

The Content Provenance Checker

As of September 2026 this ledger holds 28 records across 5 jurisdictions: 21 verified at a primary source, 1 reported by a secondary source, 0 announced with no document yet, 2 searched and absent, and 4 open questions. By kind: standard 8, binding law 7, platform or model provider 9, open question 4.

Check a file

Drop an image, a video, an audio file or a PDF. It is read here in your browser and never uploaded. You get what the file declares: whether a Content Credentials manifest is embedded, the IPTC digital source type, the creator tool. You do not get a real or fake verdict, because no file can give one.

Drop a file here

JPEG, PNG, WebP, MP4, MOV, HEIF, WAV, GIF, TIFF, MP3, SVG or PDF

Where the checker looks, format by format, and the specification section each rule was read from

Every rule is from the C2PA technical specification, version 2.4, read at spec.c2pa.org on 15 September 2026, with the Appendix A or clause 11 section beside it. One rule the specification delegates to a paid ISO text (the two byte identifier inside a JPEG APP11 segment) is deliberately not relied on; the checker uses the specification's own validator rule instead and says so here rather than shipping a byte nobody read.

FormatWhere a manifest store livesSection
JPEGAPP11 marker segments (0xFFEB) whose payload is a JUMBF superbox labelled c2pa; a store may span several contiguous segmentsA.3.1, 18.5.3, 15.12.3.1
PNGan ancillary private chunk of type caBX, recommended before IDATA.3.2
WebP, WAV, BWF, AVIa RIFF chunk with the identifier C2PA, the last sub chunk of the first RIFF header chunkA.3.7
GIFan application extension block 0x21 0xFF, block size 0x0B, identifier C2PA_GIF, authentication code 0x010000, before the first image descriptorA.3.8
MP4, MOV, M4A, HEIF, HEIC, AVIFa uuid box with extended type D8FEC3D6-1B0E-483C-9297-5828877EC481 after ftyp and before mdat and moov, with an 8 byte merkle offset before the storeA.5.1, A.5.3
MP3, FLACan ID3v2 General Encapsulated Object (GEOB) frame whose MIME type is application/c2paA.3.4, 11.4
TIFF, DNG, TIFF based RAWan IFD entry with tag 52545 (0xCD41) of type 7, in the last main IFDA.3.6
PDFan embedded file stream with Subtype application/c2pa and AFRelationship C2PA_Manifest, referenced from the catalog AF entryA.4.1, A.4.2.1
SVGa Base64 c2pa:manifest element inside metadata, namespace http://c2pa.org/manifestA.3.3
Any XMPa dcterms:provenance key points at an external manifest only; Iptc4xmpExt:DigitalSourceType carries the IPTC digital source type11.5, 15.5.2.1, 18.3
BMPnot covered; the specification requires an external manifest11.3, A.1

The digital source type vocabulary is read from cv.iptc.org, definitions verbatim. Two of its terms declare generative AI outright (trainedAlgorithmicMedia, compositeWithTrainedAlgorithmicMedia); algorithmicallyEnhanced does not, and the checker says which is which rather than treating every algorithm word as a confession.

28
Records

5 jurisdictions, 52 primary sources

21
Verified at the source

1 more reported, primary not reached

2
Announced or absent

0 announced with no document, 2 searched and absent

4
Open questions

Posed, sourced, not answered

As of 15 September 2026 the GAGE Content Provenance Checker records 21 verified instruments, 1 reported at a secondary source, 0 announcements without a document, 2 absences and 4 open questions, across 5 jurisdictions. Counts are a floor, not a ceiling: an instrument the ledger has not found is not on it.

Why this ledger exists

Guessing gives way to provenance, and provenance is only as good as what was embedded

Whether a picture looks real stops being useful as synthetic media improves. What replaces it is a record of where a file came from: a signed manifest, a declared source type, a watermark a platform can read. Those records only exist if someone embedded them, survive only if nothing stripped them, and prove only what the signer claimed.

The checker reads a file in your browser and reports exactly what is there. The ledger underneath records what each standard defines, what each platform actually embeds or displays, and what each law requires, so a reader knows what an absence means before treating it as suspicion.

Every row is fetched at its source where the source could be reached, and says so where it could not. The verdict language is the discipline: a reader learns five words once and never has to guess what a row claims.

  • Verified

    The document exists. The ledger fetched it at its publisher and quotes it.

  • Reported, primary not reached

    A reliable secondary source carries it, and the primary document could not be reached. Printed with this label, never as verified.

  • Announced, no document yet

    A body has said it will act. No document exists yet, so the row records the statement and nothing more.

  • Absent

    The ledger searched and found no instrument. The record says where it looked and when.

  • Open question

    No settled answer exists. The ledger poses the question, links the live debate, and does not answer it.

The grid

What the documents state, and where they are silent

For each of the three things a provenance document can do (embed a mark, display or verify one, require one), how many records on the ledger state it and how many are silent.

  • Embeds a mark or manifest

    19 stated, 4 silent, 1 reported.

  • Displays or verifies

    17 stated, 6 silent, 1 reported.

  • What it requires

    14 stated, 9 silent, 1 reported.

Side by side

Every jurisdiction, counted by verdict and by kind

  • United States

    11 records

    Verified
    9
    Reported
    0
    Announced
    0
    Absent
    2
    Open question
    0

    3 binding law, 8 platform or model provider.

  • European Union

    2 records

    Verified
    2
    Reported
    0
    Announced
    0
    Absent
    0
    Open question
    0

    2 binding law.

  • China

    1 record

    Verified
    1
    Reported
    0
    Announced
    0
    Absent
    0
    Open question
    0

    1 binding law.

  • South Korea

    1 record

    Verified
    0
    Reported
    1
    Announced
    0
    Absent
    0
    Open question
    0

    1 binding law.

  • Global

    13 records

    Verified
    9
    Reported
    0
    Announced
    0
    Absent
    0
    Open question
    4

    8 standard, 1 platform or model provider, 4 open question.

Figures of record

Every number on this ledger, with who measured it and when

7 figures, each one printed in the unit its publisher used, beside the publisher and the date it was true. Nothing here is summed across sources, converted between units, or forecast.

  1. 24 products

    validator products. The C2PA conformance programme, the trust list and the conforming products list

    C2PA conforming products list, primary source, as of .

  2. 185 products

    generator products. The C2PA conformance programme, the trust list and the conforming products list

    C2PA conforming products list, primary source, as of .

  3. 209 products

    conforming products listed. The C2PA conformance programme, the trust list and the conforming products list

    C2PA conforming products list, primary source, as of .

  4. 47 products

    Google entries on the C2PA conforming products list. Google: SynthID watermarking, the SynthID Detector, and C2PA in Pixel and Photos

    C2PA conforming products list, primary source, as of .

  5. 2,000,000 users

    unique monthly user floor for a large online platform. The California AI Transparency Act, SB 942 as amended by AB 853

    AB 853, California AI Transparency Act, bill text, primary source, as of .

  6. 5,000 US dollars

    civil penalty per violation. The California AI Transparency Act, SB 942 as amended by AB 853

    SB 942, California AI Transparency Act, bill text, primary source, as of .

  7. 190 organisations

    signatories by the close of July 2026. The EU code of practice on marking and labelling of AI generated content

    Code of Practice on Transparency of AI-generated Content, European Commission, primary source, as of .

The ledger

Every record, newest first

28 records. Each row opens a page carrying the answer, the verdict and what it means, the key facts, the figures with their sources, what it changes for a publisher, a platform or a newsroom, and the sources it was verified against.

RecordVerdictWhereKindVerified
May the absence of Content Credentials be treated as suspicion?CPS-2026-0028Open questionGlobalOpen question
Who answers for a manifest that is signed and false?CPS-2026-0027Open questionGlobalOpen question
Does a watermark survive re encoding?CPS-2026-0026Open questionGlobalOpen question
Is a stripped manifest evidence of tampering?CPS-2026-0025Open questionGlobalOpen question
The COPIED Act, S. 1396 in the 119th CongressCPS-2026-0024VerifiedUnited StatesBinding law
The TAKE IT DOWN Act requires no provenance markCPS-2026-0023AbsentUnited StatesBinding law
South Korea's AI Basic Act and its labelling dutyCPS-2026-0022Reported, primary not reachedSouth KoreaBinding law
China's Measures for Labelling AI Generated Synthetic ContentCPS-2026-0021VerifiedChinaBinding law
The California AI Transparency Act, SB 942 as amended by AB 853CPS-2026-0020VerifiedUnited StatesBinding law
The EU code of practice on marking and labelling of AI generated contentCPS-2026-0019VerifiedEuropean UnionBinding law
EU AI Act Article 50(2): machine readable markingCPS-2026-0018VerifiedEuropean UnionBinding law
Anthropic: no published provenance markCPS-2026-0017AbsentUnited StatesPlatform or model provider
Cameras that sign at captureCPS-2026-0016VerifiedGlobalPlatform or model provider
Microsoft: Content Credentials on Azure OpenAI imagesCPS-2026-0015VerifiedUnited StatesPlatform or model provider
YouTube: a C2PA manifest can trigger the AI label by itselfCPS-2026-0014VerifiedUnited StatesPlatform or model provider
TikTok: reading Content Credentials to label uploadsCPS-2026-0013VerifiedUnited StatesPlatform or model provider
Meta: AI labels built on C2PA and IPTC metadataCPS-2026-0012VerifiedUnited StatesPlatform or model provider
Adobe and the Content Authenticity InitiativeCPS-2026-0011VerifiedUnited StatesPlatform or model provider
Google: SynthID watermarking, the SynthID Detector, and C2PA in Pixel and PhotosCPS-2026-0010VerifiedUnited StatesPlatform or model provider
OpenAI: Content Credentials, SynthID and a verification toolCPS-2026-0009VerifiedUnited StatesPlatform or model provider
What a manifest says when the content was generated by AICPS-2026-0008VerifiedGlobalStandard
JUMBF, ISO/IEC 19566-5:2023, the box format under every manifestCPS-2026-0007VerifiedGlobalStandard
The IPTC Digital Source Type vocabularyCPS-2026-0006VerifiedGlobalStandard
JPEG Trust, ISO/IEC 21617CPS-2026-0005VerifiedGlobalStandard
Content Credentials at ISO: ISO/CD 22144CPS-2026-0004VerifiedGlobalStandard
The C2PA conformance programme, the trust list and the conforming products listCPS-2026-0003VerifiedGlobalStandard
Where a C2PA manifest actually sits in each file formatCPS-2026-0002VerifiedGlobalStandard
The C2PA technical specification, version 2.4CPS-2026-0001VerifiedGlobalStandard

Answers

What people ask the Content Provenance Checker

Can this checker tell me whether an image is AI generated?

No, and nothing can from the pixels alone. It tells you what the file declares about itself: whether a Content Credentials manifest is present, what the IPTC digital source type says, and what the creator tool field says. A file with no declaration proves nothing either way, because most files carry none and a stripped manifest leaves no trace. The checker never validates a signature; the official validator does that.

Which platforms and model providers embed Content Credentials?

7 of 9 platform records on the ledger state that they embed a manifest or a mark as of September 2026: Cameras that sign at capture; Microsoft: Content Credentials on Azure OpenAI images; TikTok: reading Content Credentials to label uploads; Meta: AI labels built on C2PA and IPTC metadata; Adobe and the Content Authenticity Initiative; Google: SynthID watermarking, the SynthID Detector, and C2PA in Pixel and Photos; OpenAI: Content Credentials, SynthID and a verification tool. The embed, display and require dimensions on each record page quote the platform's own document.

Which laws require AI content to be marked?

7 laws on the ledger: The COPIED Act, S. 1396 in the 119th Congress (United States, verified); The TAKE IT DOWN Act requires no provenance mark (United States, absent); South Korea's AI Basic Act and its labelling duty (South Korea, reported, primary not reached); China's Measures for Labelling AI Generated Synthetic Content (China, verified); The California AI Transparency Act, SB 942 as amended by AB 853 (United States, verified); The EU code of practice on marking and labelling of AI generated content (European Union, verified); EU AI Act Article 50(2): machine readable marking (European Union, verified). Each record quotes what must be marked, by whom and from when.

Does the checker upload my file?

No. The file is read by your browser and nothing leaves it: no upload, no storage, no server. The only thing sent is a single anonymous signal that the checker was used, and that carries no file data.

What does the specification actually define?

8 records of kind standard are on the Content Provenance Checker as of September 2026: What a manifest says when the content was generated by AI; JUMBF, ISO/IEC 19566-5:2023, the box format under every manifest; The IPTC Digital Source Type vocabulary; JPEG Trust, ISO/IEC 21617; Content Credentials at ISO: ISO/CD 22144; The C2PA conformance programme, the trust list and the conforming products list; and 2 more. Each has its own page with the verdict, the facts, the sources it was checked against and the date.

What does the law require to be marked or disclosed?

7 records of kind binding law are on the Content Provenance Checker as of September 2026: The COPIED Act, S. 1396 in the 119th Congress; The TAKE IT DOWN Act requires no provenance mark; South Korea's AI Basic Act and its labelling duty; China's Measures for Labelling AI Generated Synthetic Content; The California AI Transparency Act, SB 942 as amended by AB 853; The EU code of practice on marking and labelling of AI generated content; and 1 more. Each has its own page with the verdict, the facts, the sources it was checked against and the date.

What does a platform or model provider actually embed, display or verify?

9 records of kind platform or model provider are on the Content Provenance Checker as of September 2026: Anthropic: no published provenance mark; Cameras that sign at capture; Microsoft: Content Credentials on Azure OpenAI images; YouTube: a C2PA manifest can trigger the AI label by itself; TikTok: reading Content Credentials to label uploads; Meta: AI labels built on C2PA and IPTC metadata; and 3 more. Each has its own page with the verdict, the facts, the sources it was checked against and the date.

What has nobody settled?

4 records of kind open question are on the Content Provenance Checker as of September 2026: May the absence of Content Credentials be treated as suspicion?; Who answers for a manifest that is signed and false?; Does a watermark survive re encoding?; Is a stripped manifest evidence of tampering?. Each has its own page with the verdict, the facts, the sources it was checked against and the date.

What do the verdicts mean?

Verified: the document exists and the ledger fetched it at its publisher. Reported: a reliable secondary source carries it and the primary could not be reached. Announced: a body said it will act and no document exists. Absent: the ledger searched and found nothing, and the search is written into the record. Open: a question nobody has settled, posed and not answered.

How current is the Content Provenance Checker?

Every record carries the date it was last verified; the ledger as a whole was last verified 15 September 2026 and holds 28 records with 52 primary sources. A change moves the record's own date and appears on the changelog, so a reader who cited a row can see whether it moved.

Every surface

Cut the ledger the way you need it

By jurisdiction

By kind

Every record page

Take the data

The whole dataset, free, in two formats

Licensed CC BY 4.0. Use it in an article, a paper, a slide or a product. The only condition is attribution, and the citation page gives you the line to paste.

How the ledger is built, what the verdicts mean, and what the gate refuses: the method page. Every change, dated: the changelog. The kinds on the shelf: standard, binding law, platform or model provider, open question. Something missing or wrong is a bug, and we want to hear about it. Whether your own content must carry a mark is answered by the AI Content Labeling Checker. The state deepfake laws are on the US Synthetic Media Law Atlas. Why guessing fails is the lesson of Real or AI. If the file is of you and you did not consent, start at Deepfake Response.

Cite this page

Free to reuse under CC BY 4.0, with attribution.

In a sentence
According to the GAGE Content Provenance Checker (as of 15 September 2026), content provenance checker.
APA
GAGE (Global Academy of Generative-AI Education). (2026). Content Provenance Checker. Content Provenance Checker. Retrieved 15 September 2026, from https://www.gage.academy/tools/content-provenance-checker
MLA
"Content Provenance Checker." Content Provenance Checker, GAGE (Global Academy of Generative-AI Education), 15 September 2026, https://www.gage.academy/tools/content-provenance-checker.
Chicago
GAGE (Global Academy of Generative-AI Education). "Content Provenance Checker." Content Provenance Checker. Last modified 15 September 2026. https://www.gage.academy/tools/content-provenance-checker.
Permalink
https://www.gage.academy/tools/content-provenance-checker

Last updated . Every record re verified . The ledger is checked monthly, first Monday, and the same day for any C2PA specification release.

24 products

GAGE briefings tell you which AI regulation deadlines are coming, what they actually require of you, and when a program opens.