JPEG Trust, ISO/IEC 21617
JPEG Trust is the other published standard in this lane, and it is a framework for judging trust in media rather than a container format. The catalogue entry shows a second edition, ISO/IEC 21617-1:2026, published in August 2026, and shows the 2025 first edition as withdrawn. Parts 2, 3 and 4 remain under development.
The verdict
Verified
The document exists. The ledger fetched it at its publisher and quotes it.
Key facts
What the sources say
- Record ID
- CPS-2026-0005
- Kind
- Standard
- Jurisdiction
- Global
- Last verified
- Added
- ISO/IEC 21617-1:2026, Information technology, JPEG Trust, Part 1: Core foundation, status Published, edition 2, publication date 2026-08, stage 60.60.
- The lifecycle panel on the same entry shows ISO/IEC 21617-1:2025 as withdrawn, so a citation to the 2025 edition is now a citation to a superseded document.
- Part 1 specifies "a framework for establishing trust in media" covering authenticity, provenance, attribution, intellectual property rights and integrity.
- Part 2 trust profiles and reports, Part 3 media asset watermarking and Part 4 reference software are all at draft International Standard stage.
- The JPEG committee's own page states that the framework is built to integrate with JPEG 1, JPEG 2000, JPEG XS, JPEG XL and JPEG AI, and can apply to other modalities.
Dimension by dimension
3 dimensions, each one stated, silent or open
Embeds a mark or manifest, Displays or verifies, What it requires. Stated means the document you can open below says it; silent means the ledger read the document and it does not.
- Embeds a mark or manifestStated
- Part 3, media asset watermarking, is the embedding part and is still a draft.ISO/IEC 21617-1:2026, JPEG Trust, Part 1: Core foundation, primary source, 15 September 2026.
- Displays or verifiesStated
- Trust profiles and trust reports are the display and judgement side, defined in Part 2, also a draft.ISO/IEC 21617-1:2026, JPEG Trust, Part 1: Core foundation, primary source, 15 September 2026.
- What it requiresSilent
- Nothing is required of anyone. It is a published framework, not a mandate.ISO/IEC 21617-1:2026, JPEG Trust, Part 1: Core foundation, primary source, 15 September 2026.
What it changes
For a publisher, a platform or a newsroom
If your house style already cites ISO/IEC 21617-1:2025, update it: that edition is withdrawn and the current one is the 2026 second edition. The distinction worth carrying into an editorial policy is that C2PA gives you the manifest and JPEG Trust gives you a way to express what your organisation counts as trustworthy, which is a profile question and therefore a policy question, not a parsing question.
Sources
What this record was verified against
- ISO/IEC 21617-1:2026, JPEG Trust, Part 1: Core foundationPrimary · 15 September 2026
- JPEG Trust overview, the JPEG committeePrimary · 15 September 2026
Related
Records that sit beside this one
Content Credentials at ISO: ISO/CD 22144
Global · verified 15 September 2026
The ISO catalogue entry reads "ISO/CD 22144" with status "Under development" and stage "CD approved for registration as DIS [30.99]".
The C2PA technical specification, version 2.4
Global · verified 15 September 2026
The specification index at spec.c2pa.org redirects to the 2.4 specification, and requests for versions 2.5, 2.6 and 3.0 return HTTP 404.
May the absence of Content Credentials be treated as suspicion?
Global · verified 15 September 2026
OpenAI states that if no metadata or watermark is detected "the tool will not make a definitive conclusion about whether the image was generated with OpenAI tools since provenance signals can in some cases be stripped".
Who answers for a manifest that is signed and false?
Global · verified 15 September 2026
The C2PA trust model is expressed as validation states: well formed, valid and trusted, each about signatures, certificates and lists rather than about the truth of an assertion.
Does a watermark survive re encoding?
Global · verified 15 September 2026
Google states that the image and video watermark is "designed to stand up to modifications like cropping, adding filters, changing frame rates, or lossy compression".
Is a stripped manifest evidence of tampering?
Global · verified 15 September 2026
OpenAI states that C2PA metadata "can be stripped, lost through uploads and downloads, or broken by transformations like file format changes, resizing, or screenshots".
Cite this record
Free to reuse under CC BY 4.0, with attribution. The record ID CPS-2026-0005 is permanent and is never reused.
- In a sentence
- According to the GAGE Content Provenance Checker (as of 15 September 2026), jpeg trust, iso/iec 21617.
- APA
- GAGE (Global Academy of Generative-AI Education). (2026). JPEG Trust, ISO/IEC 21617. Content Provenance Checker. Retrieved 15 September 2026, from https://www.gage.academy/tools/content-provenance-checker/records/CPS-2026-0005-jpeg-trust-iso-iec-21617
- MLA
- "JPEG Trust, ISO/IEC 21617." Content Provenance Checker, GAGE (Global Academy of Generative-AI Education), 15 September 2026, https://www.gage.academy/tools/content-provenance-checker/records/CPS-2026-0005-jpeg-trust-iso-iec-21617.
- Chicago
- GAGE (Global Academy of Generative-AI Education). "JPEG Trust, ISO/IEC 21617." Content Provenance Checker. Last modified 15 September 2026. https://www.gage.academy/tools/content-provenance-checker/records/CPS-2026-0005-jpeg-trust-iso-iec-21617.
- Permalink
- https://www.gage.academy/tools/content-provenance-checker/records/CPS-2026-0005-jpeg-trust-iso-iec-21617
Last updated . Every record re verified . The ledger is checked monthly, first Monday, and the same day for any C2PA specification release.
Back to the full ledger, or every record for Global and every standard record.
GAGE briefings tell you which AI regulation deadlines are coming, what they actually require of you, and when a program opens.