Skip to content
WatermarkAudit

Content provenance

Find out what a file actually says about where it came from.

Drop in an image, PDF, or video and read its C2PA content credentials: who signed it, when, whether it has been altered since, and whether it declares that AI was involved.

Drop a file here to check its credentials

or

JPEG, PNG, WebP, AVIF, TIFF, SVG, PDF, MP4, MP3 and more. Up to 64 MB. The file stays on your device — verification runs in your browser.

What this proves, and what it doesn't

Provenance tooling is only useful if it is honest about its limits. Here is exactly what a result from this page means.

A valid signature is strong evidence

If a manifest validates, the file has not changed since it was signed, and you know which certificate signed it. That is a real cryptographic guarantee, not a probability score.

No credentials proves nothing

Most files carry no manifest at all. Resizing, screenshotting, re-encoding, and nearly every social platform strip C2PA metadata. Absence is the default state of the internet, not a red flag.

A declared origin is a claim, not a detection

When a manifest says AI was involved, that is the producing software disclosing it. Nothing here independently detects AI. The claim is only as trustworthy as the certificate behind it.

Why files started carrying this

Article 50 of the EU AI Act became enforceable on 2 August 2026. It requires providers of generative AI to mark synthetic output in a machine-readable format, so that it can be detected as artificially generated. For systems already on the market before that date, the marking requirement applies from 2 December 2026.

In practice this has produced two different mechanisms, and they are routinely confused with each other.

Signed metadata on files
The C2PA standard, attached to generated images and documents. Cryptographically verifiable, and readable by anyone — which is what this page does. It is also easy to strip, deliberately or accidentally.
Watermarks inside text
A statistical signal woven into word choice at the model level. It survives copy-and-paste and some editing, because it lives in the text itself rather than in a metadata field.

A mark tells you a file was processed. It does not tell you who wrote it.

This distinction matters more than any single result on this page. Text that a person wrote and then ran through a model for grammar corrections carries the same watermark as text the model wrote outright. A C2PA manifest declaring AI involvement behaves the same way — it records that a tool touched the file, not the proportion of human effort in it.

Treating a mark as proof of authorship produces false accusations against people who did nothing wrong. If you are using provenance signals to make a decision about someone's work, treat them as one input to a human review, never as a verdict.