Who answers for a manifest that is signed and false?
A C2PA signature proves that a named key signed these bytes. It does not prove the statements inside are true. No standard or law in this ledger says who is liable when a validly signed manifest asserts something false, and the trust model decides only whether a signature verifies and whether its signer is on a list.
The verdict
Open question
No settled answer exists. The ledger poses the question, links the live debate, and does not answer it.
Key facts
What the sources say
- Record ID
- CPS-2026-0027
- Kind
- Open question
- Jurisdiction
- Global
- Last verified
- Added
- The C2PA trust model is expressed as validation states: well formed, valid and trusted, each about signatures, certificates and lists rather than about the truth of an assertion.
- The conformance programme holds products to the Certificate Policy and the Security Requirements, and can act on a certificate, which is a remedy against a signer and not a remedy for a reader.
- China's Measures forbid forging a label and route consequences through existing administrative law, without creating a liability rule for a signed but false claim.
- California attaches a civil penalty to a covered provider that fails to include a compliant latent disclosure, which is a penalty for absence rather than for falsity.
- The European code of practice gives signatories an evidential benefit for following its measures; it does not allocate liability for a false marking.
What it changes
For a publisher, a platform or a newsroom
Say the narrow thing in your interface. The sentence a reader can rely on is that this file carries a manifest signed by a named party, and that the named party asserted the history shown. Everything beyond that is a judgement about the signer, which is an editorial and contractual matter. If provenance forms part of a commercial promise you make, put the warranty in the contract, because the standard does not supply one.
Sources
What this record was verified against
- C2PA Technical Specification 2.4, Trust Model and ValidationPrimary · 15 September 2026
- C2PA ConformancePrimary · 15 September 2026
Related
Records that sit beside this one
The C2PA conformance programme, the trust list and the conforming products list
Global · verified 15 September 2026
The programme holds generator products, validator products and certification authorities to the specification, the Certificate Policy and the Security Requirements.
China's Measures for Labelling AI Generated Synthetic Content
China · verified 15 September 2026
Article 5 requires service providers to add an implicit label in the file metadata of generated synthetic content, carrying attribute information, the provider's name or code and a content number.
The California AI Transparency Act, SB 942 as amended by AB 853
United States · verified 15 September 2026
SB 942 requires a covered provider to include a latent disclosure conveying the provider's name, the system name and version, the time and date of creation or alteration, and a unique identifier.
May the absence of Content Credentials be treated as suspicion?
Global · verified 15 September 2026
OpenAI states that if no metadata or watermark is detected "the tool will not make a definitive conclusion about whether the image was generated with OpenAI tools since provenance signals can in some cases be stripped".
Does a watermark survive re encoding?
Global · verified 15 September 2026
Google states that the image and video watermark is "designed to stand up to modifications like cropping, adding filters, changing frame rates, or lossy compression".
Is a stripped manifest evidence of tampering?
Global · verified 15 September 2026
OpenAI states that C2PA metadata "can be stripped, lost through uploads and downloads, or broken by transformations like file format changes, resizing, or screenshots".
Cite this record
Free to reuse under CC BY 4.0, with attribution. The record ID CPS-2026-0027 is permanent and is never reused.
- In a sentence
- According to the GAGE Content Provenance Checker (as of 15 September 2026), who answers for a manifest that is signed and false?.
- APA
- GAGE (Global Academy of Generative-AI Education). (2026). Who answers for a manifest that is signed and false?. Content Provenance Checker. Retrieved 15 September 2026, from https://www.gage.academy/tools/content-provenance-checker/records/CPS-2026-0027-who-answers-for-a-false-manifest
- MLA
- "Who answers for a manifest that is signed and false?." Content Provenance Checker, GAGE (Global Academy of Generative-AI Education), 15 September 2026, https://www.gage.academy/tools/content-provenance-checker/records/CPS-2026-0027-who-answers-for-a-false-manifest.
- Chicago
- GAGE (Global Academy of Generative-AI Education). "Who answers for a manifest that is signed and false?." Content Provenance Checker. Last modified 15 September 2026. https://www.gage.academy/tools/content-provenance-checker/records/CPS-2026-0027-who-answers-for-a-false-manifest.
- Permalink
- https://www.gage.academy/tools/content-provenance-checker/records/CPS-2026-0027-who-answers-for-a-false-manifest
Last updated . Every record re verified . The ledger is checked monthly, first Monday, and the same day for any C2PA specification release.
Back to the full ledger, or every record for Global and every open question record.
GAGE briefings tell you which AI regulation deadlines are coming, what they actually require of you, and when a program opens.